Mint a consequence, sign it with your own key, and watch it decide.
Point at an admission service. The console asks it what it can prove and shows only that — if it cannot see the service, it says so rather than showing a confident zero.
The steward key is generated in this browser and stays in this browser. Only the public half and your signatures ever cross the wire.
A namespace is a wall. Genesis is a first claim, self-signed by the stewards it names — and a name already claimed cannot be taken. We are the registrar; we hold no steward key, so we can enforce your charter and never forge it.
Take a boundary pack, or write it in plain language. Either way you get a dead object — a name, not a permission. Lumen will refuse to compile a sentence it cannot fully express, because a dropped clause would widen the boundary beyond what you asked for.
Everything above this line proposes. This is the moment a named human makes it law, and it happens on your machine, with your key, under your hand. It cannot be automated away without destroying the product.
Propose a consequence and watch it decide. An ACCEPT returns a receipt anyone can verify with a public key alone — and a REFUSE is signed too, because an honest denial is also a proof.
No decisions yet — nothing has been put to a boundary.
authority_effect: 0. Nothing here governs a real mutation yet. A boundary
decides and traces, and it blocks nothing until a steward deliberately flips enforcement on
the system it guards — a separate, human act.
Known gap, stated plainly: this service’s principal_auth is
open. Anyone can currently ask it to decide. That does not let them
bind anything — binding needs a steward signature the server checks against your charter —
but it does mean your boundary is publicly queryable. Closing it is next.