Skip to main content

tenant-emit

Emit signed governance certificates from a finished run, with no trust required to verify them.

npm i -D tenant-emit

Emit-only by construction

No verify verb, no verifier dependency. The verify/emit boundary is load-bearing, ensuring the emitter stays separate from the verifier.

Operator-key custody

The Ed25519 signing key is an operator-supplied tenant secret held outside the repository and outside any agent's write scope.

Verifiable-but-unsealed

Carries no platform countersign. A tenant-emitted certificate round-trips perfectly offline under tenant-tail.