Lifecycle decisions
Asset governance records creation, review, local trust, and network publication separately. A validated Capsule does not automatically qualify its Gene, Recipe, or Skill for team use.
Decision types
| Decision | Use when |
|---|---|
| Quarantine | Provenance, scope, or evidence is unresolved; retain but exclude from trusted selection |
| Approve | Human review is complete and its outcome must be recorded |
| Promote | The asset may enter trusted local Gene selection |
| Reject | Content or evidence does not meet requirements |
| Revoke | A previously trusted asset has expired or become risky |
| Expire | Evidence or supported versions are outside the maintenance window and need revalidation |
Execute and record
bash
evolver asset-trust show <asset_id>
evolver asset-trust promote <asset_id> --reason "validated for release workflow"
evolver asset-trust revoke <asset_id> --reason "source version is no longer supported"
evolver review --approve <asset_id> "review completed"
evolver review --reject <asset_id> "evidence is insufficient"
Each decision should retain asset ID, before and after state, reason, evidence, operator, time, and replacement. A human review decision takes precedence over later automatic quarantine records without deleting them.
Governance flow
- Start quarantined and verify content addressing and provenance.
- Run validation in the target environment and record both success and failure.
- Separate review and promotion roles for high-impact assets.
- Recheck dependency versions, reuse outcomes, and revocation signals periodically.
- After revocation, notify users, stop automatic recall, and provide a migration path.
Keep states separate
Review approval is not local trust, trust promotion is not network publication, and publication is not proof of continued validity. Dashboards and records should show these states independently.
Related pages
EvoX Docs · Administration · Asset governance