Signed events
Verify issuer, event type, timestamp, subject, and bundle reference.
Planned signed webhooks connect bundle issuance to authorization, execution, review, revocation, and outcome events.
Verify issuer, event type, timestamp, subject, and bundle reference.
Use stable event identifiers and explicit retry semantics.
Attach downstream facts without mutating the original manifest.