Canon

TTD Protocol — Verifiable Data Custody & Consent Layer

✧~ TTD Protocol — Verifiable Data Custody & Consent Layer

Linked Companion:'' HELIX_GLYPH_LANGUAGE_(HGL)

🔍 Purpose & Philosophy

TTD defines how data custody, consent, and verifiable attribution work across Helix systems and external agents. Every action is provable, scoped, and auditable:


🧭 Canonical Concepts

Custody (🗄️ storage + 🗝️ auth) — private keys and vault remain inside Helix domains (OVH bare-metal).

Provenance (🧵 trace) — every mutation/event is linked and hash-anchored.

Delegation Token (🚦 gate) — scoped permission with redlines, expiry, and signer.

Receipt (📊 analytics) — result package containing hashes, timestamps, and signers.

CRL (📚 knowledge registry) — append-only revocation list for DTs/shards.

Rotation Manifest (🗓️ schedule) — planned key rollover with grace period.

HOP (💬 dialogue + ⚖️ ethics + 🛡️ safeguard) — human-in-loop override for risk.

🧩 Data Flow

🔍 Agent requests access with a signed DT (🚦 scope + ⏱️ expiry + 🧱 redlines).

✅ Verifier checks signature (🗝️), validity (⏱️), scope (🧱), and revocation (📚).

🧰 Action executes inside custody domain (🗄️); no direct vault exposure.

📊 Receipt is assembled (hashes, artifacts, timings, signer).

🔗 Integration: optional ledger anchor; 📣 notify as configured.

🛡️ If any rule trip: ❌ reject → 💬 HOP (human approval) or 💀 abort per runbook.


🧱 Delegation & Redlines

DT contents (minimum): signer, subject, scope, expiry, redlines, hash, signature.

Redline examples: no_personal_contact • no_live_keys • read_only • sandbox_only (🧱 + 🧪⚖️)

Defaults: shortest necessary ⏱️; read-only unless explicitly widened; production actions require 💬 HOP.

🧾 Receipts

Every DT execution MUST yield a receipt:


🔒 Security & Custody


🗝️ AuthN/Z

Roles and scopes are explicit; missing or stale scope ⇒ ❌.

📚 CRL & Rotation


Conformance

A service is TTD-conformant if it:

validates DTs (signature/scope/expiry/CRL),

executes inside custody,

emits signed 📊 receipts,

honors 🧱 redlines, 💬 HOP, and 💀 abort,

logs to the ledger and exposes metrics (Prometheus) for 📊 SLOs.

See: [Helix-TTD Conformance Checklist](#helix-ttd-conformance-checklist)[Helix-TTD Integration Memo](#helix-ttd-integration-memo)

⏱️ SLO Targets


🧪 Example — Minimal DT

Scope: read+summarize public artifacts (24h)

Redlines: no_personal_contact • sandbox_only

Receipt: “Reviewed public artifacts; published hashes only.”

Outcome: ✅ pass → 📊 receipt hash X; ❌ if redline breached → 💬 HOP or 💀

🧾 Runbooks


🧰 Interop


[HELIX_GLYPH_LANGUAGE_(HGL)](#helix-glyph-language-hgl)[HGL Unified Operational Runbook (Consolidated Perplexity Edition)](#hgl-unified-operational-runbook-consolidated-perplexity-edition)[Our Compute](#our-compute)[Ethos](#ethos) ----Categories:

[Category:Helix-TTD](#category-helix-ttd) [Category:Protocols](#category-protocols) [Category:Custody](#category-custody) [Category:Governance](#category-governance) [Category:HGL Documents](#category-hgl-documents)