Skip to content
zHezarFoundation / Public release

Foundation / Public Provenance

Preserve product history. Limit public exposure.

Public provenance is intended to show an approved, privacy-safe projection of official product history. It is not the protected record itself, and it does not turn a past relationship or public page into current Ownership authority.

Reference only. No real product, owner, event, title, transfer, correction, deletion, evidence, or authoritative provenance record appears here.

  1. 01Official identityThe product record begins.
  2. 02Approved eventHistory appends; prior state remains.
  3. 03Protected authorityEvidence and exact detail stay restricted.
  4. 04Safe projectionOnly policy-approved public fields render.

Authoritative history / limited public view

Current evidence

The rules exist. The authoritative history does not.

The repository defines append-only, privacy-minimized provenance requirements, but contains no ownership datastore, public projection, correction workflow, or active Public Garment Record.

Confirmed constraint

History must not be silently rewritten.

Ownership and provenance remain append-only. Corrections preserve prior state and protected evidence.

OD-016 / Draft

Exact public presentation still needs approval.

Owner labels, public fields, optional history, anonymization, retention, deletion, and legal-hold defaults remain unresolved.

Four distinct layers

The public page is the smallest layer—not the source of truth.

A public projection can explain approved history, but it cannot replace the protected record or create authority.

01

Product Identity

The permanent official product, artist, Edition, configuration, and identity relationships.

02

Ownership and provenance record

The protected authoritative current state and append-only event history.

03

Evidence and audit

Exact timestamps, reasons, actors, cases, decisions, and supporting evidence remain restricted.

04

Public provenance projection

Only policy-approved labels, safe periods, product states, and relationships may render.

Four event families

Official history can outlast a sale, a tag, a username, or an account.

These are categories a future authoritative system may record. Their presence here does not mean an event occurred or that every event is public.

Origin and first authority

How official product history begins.

  • Product Identity created
  • Original purchase and first Claim
  • Original owner established
  • First rarity discovery where applicable
Ownership movement

How current authority may change.

  • Gift or private transfer
  • Third-party or official marketplace sale
  • Inheritance when active
  • Transfer reversal through approved process
Physical continuity

How identity continues through physical change.

  • Size exchange
  • Replacement
  • Reissue
  • Token retirement and successor identity
Corrections and account lifecycle

How truth is preserved through exceptions.

  • Ownership or product-state correction
  • Edition or artist correction
  • Deleted-owner hold
  • Deleted-owner open Claim where eligible

Potential public event shape

Useful context without the case file.

The exact launch field set requires OD-016 approval. A future projection may use only the minimum approved fields.

  1. 01

    Event type

    A clear approved category, not an internal code.

  2. 02

    Public owner label

    Username-based or privacy-reduced only where policy requires.

  3. 03

    Privacy-safe time period

    Month and year may be appropriate; exact timestamps remain protected.

  4. 04

    Safe product state

    Current, historical, corrected, retired, replaced, or another approved label.

  5. 05

    General source type

    Purchase, gift, transfer, exchange, replacement, inheritance, or correction.

  6. 06

    Related identity

    A safe predecessor or successor product reference where applicable.

  7. 07

    Correction label

    A visible indication that current state was corrected when appropriate.

Required history and profile privacy

Hiding a profile does not rewrite the product.

Ordinary privacy settings may hide optional Collection or profile modules. They do not erase official facts required for product integrity, safety, law, or audit.

  • Product Identity
  • Authenticity state
  • Edition
  • Claimed rarity where applicable
  • Current Ownership where required
  • Historical Ownership where required
  • Official artist attribution
  • Provenance events

Privacy-preserving default: until OD-016 is approved, no optional Collection, current-owner, or historical-owner fixture renders.

Information boundary

Public history is not public personal data.

Potentially public when approved

Safe product facts and limited relationships.

  • Safe product reference and Product Identity
  • Artist, Artwork, Album, Drop, and Edition
  • Authenticity and revealed rarity
  • Approved current or historical owner label
  • Privacy-safe period, event, state, and relationship
Protected by default

Identity, operations, evidence, and security.

  • Legal identity, contact details, birth date, and address
  • Orders, shipping, payment, and private prices
  • Device, network, scan location, and most recent scanner
  • Exact timestamps, cases, disputes, inspections, and evidence
  • NFC values, internal identifiers, fraud signals, and risk rules

Ownership relationship

Historical association is not current authority.

A former owner may remain connected to required history, but that relationship does not preserve current-owner controls or private access.

Current owner

Canonical authority only through approved state.

A username-based label may appear where required. The public page itself grants no control.

Former owner

Historical label, never current control.

No transfer, replacement, private Owned Piece, or visibility authority remains merely because history persists.

Username change

The relationship must not break.

Stable protected identity preserves history; username reuse must not transfer another account's authority or records.

Account deletion

Authority ends; required history may remain.

Public labels may be reduced or anonymized as approved while safe product states and required provenance continue.

Factual correction

Correct the current state. Keep the audit trail.

A complaint is not proof and correction is not ordinary self-service. An authorized, evidenced workflow must append the correction while protecting prior records and case details.

Public presentation

Current corrected fact and safe correction label.

The public page may identify that a correction occurred where appropriate.

Protected history

Former value, corrected value, evidence, actor, time, reason, and audit reference.

These details stay restricted and are never exposed merely to prove staff acted.

Integrity boundary

No erased prior record, duplicate owner, duplicate token, rewritten rarity, or hidden staff error.

Historical owners are removed only through approved legal or safety authority.

Public promise limits

A provenance page must never claim more authority than it has.

  1. 01

    Public viewing establishes current Ownership, possession, legal title, or seller authority.

  2. 02

    A historical owner label preserves current-owner controls or private access.

  3. 03

    A public event exposes or proves the complete protected case or evidence.

  4. 04

    Provenance guarantees authenticity without the applicable authoritative verification state.

  5. 05

    Provenance guarantees condition, value, resale price, investment return, or market demand.

  6. 06

    Profile privacy or account deletion automatically erases required product history.

  7. 07

    A factual correction silently removes the former record or rewrites rarity.

  8. 08

    Every event or owner label will be public in every territory or state.

Readiness / July 2026

The policy boundary is reviewable. Public records are not active.

These labels describe repository readiness only and are not a live service, product history, legal title, or production-status source.

CapabilityStateRequired before activation
Public provenance principlesPublic reference

Content, legal, privacy, and accessibility approval still required.

Exact public field projectionOD-016 required

Fields, labels, defaults, territories, and anonymization remain undecided.

Authoritative ownership historyFuture gate

Canonical datastore, API, audit, security, and monitoring are required.

Public Garment RecordFuture gate

Safe identity projection, verification, privacy, and cache rules are required.

Correction workflowFuture gate

Authority, evidence, reason, notice, appeal, and append-only audit are required.

Deletion and historical-owner statesPolicy review

Retention, holds, anonymization, recovery, and safety exceptions remain open.

Search, indexing, and localizationValidation required

SEO, territory, time, language, accessibility, and abuse review remain open.

Related public boundaries

Understand history without inventing a record.

Authenticity explains secure product verification. Privacy and Legal & Trust explain the limits around public presentation.