History must not be silently rewritten.
Ownership and provenance remain append-only. Corrections preserve prior state and protected evidence.
Foundation / Public Provenance
Public provenance is intended to show an approved, privacy-safe projection of official product history. It is not the protected record itself, and it does not turn a past relationship or public page into current Ownership authority.
Reference only. No real product, owner, event, title, transfer, correction, deletion, evidence, or authoritative provenance record appears here.
Authoritative history / limited public view
Current evidence
The repository defines append-only, privacy-minimized provenance requirements, but contains no ownership datastore, public projection, correction workflow, or active Public Garment Record.
Ownership and provenance remain append-only. Corrections preserve prior state and protected evidence.
Owner labels, public fields, optional history, anonymization, retention, deletion, and legal-hold defaults remain unresolved.
Four distinct layers
A public projection can explain approved history, but it cannot replace the protected record or create authority.
The permanent official product, artist, Edition, configuration, and identity relationships.
The protected authoritative current state and append-only event history.
Exact timestamps, reasons, actors, cases, decisions, and supporting evidence remain restricted.
Only policy-approved labels, safe periods, product states, and relationships may render.
Four event families
These are categories a future authoritative system may record. Their presence here does not mean an event occurred or that every event is public.
Potential public event shape
The exact launch field set requires OD-016 approval. A future projection may use only the minimum approved fields.
A clear approved category, not an internal code.
Username-based or privacy-reduced only where policy requires.
Month and year may be appropriate; exact timestamps remain protected.
Current, historical, corrected, retired, replaced, or another approved label.
Purchase, gift, transfer, exchange, replacement, inheritance, or correction.
A safe predecessor or successor product reference where applicable.
A visible indication that current state was corrected when appropriate.
Required history and profile privacy
Ordinary privacy settings may hide optional Collection or profile modules. They do not erase official facts required for product integrity, safety, law, or audit.
Privacy-preserving default: until OD-016 is approved, no optional Collection, current-owner, or historical-owner fixture renders.
Information boundary
Ownership relationship
A former owner may remain connected to required history, but that relationship does not preserve current-owner controls or private access.
A username-based label may appear where required. The public page itself grants no control.
No transfer, replacement, private Owned Piece, or visibility authority remains merely because history persists.
Stable protected identity preserves history; username reuse must not transfer another account's authority or records.
Public labels may be reduced or anonymized as approved while safe product states and required provenance continue.
Factual correction
A complaint is not proof and correction is not ordinary self-service. An authorized, evidenced workflow must append the correction while protecting prior records and case details.
The public page may identify that a correction occurred where appropriate.
These details stay restricted and are never exposed merely to prove staff acted.
Historical owners are removed only through approved legal or safety authority.
Public promise limits
Public viewing establishes current Ownership, possession, legal title, or seller authority.
A historical owner label preserves current-owner controls or private access.
A public event exposes or proves the complete protected case or evidence.
Provenance guarantees authenticity without the applicable authoritative verification state.
Provenance guarantees condition, value, resale price, investment return, or market demand.
Profile privacy or account deletion automatically erases required product history.
A factual correction silently removes the former record or rewrites rarity.
Every event or owner label will be public in every territory or state.
Readiness / July 2026
These labels describe repository readiness only and are not a live service, product history, legal title, or production-status source.
Content, legal, privacy, and accessibility approval still required.
Fields, labels, defaults, territories, and anonymization remain undecided.
Canonical datastore, API, audit, security, and monitoring are required.
Safe identity projection, verification, privacy, and cache rules are required.
Authority, evidence, reason, notice, appeal, and append-only audit are required.
Retention, holds, anonymization, recovery, and safety exceptions remain open.
SEO, territory, time, language, accessibility, and abuse review remain open.
Related public boundaries
Authenticity explains secure product verification. Privacy and Legal & Trust explain the limits around public presentation.