Authority CI/CD Timestamping

This document describes the CI/CD timestamping orchestration added in Sprint SPRINT_20260208_025_Authority_rfc_3161_tsa_client_for_ci_cd_timestamping.

Scope

Runtime status (verified 2026-07-18): this scope is implemented as a bounded Authority library, not as a production-composed workflow. No production host currently calls AddTimestamping, no durable IArtifactTimestampRegistry implementation exists, and no runtime configuration binds PipelineTimestampingPolicyOptions. Release Orchestrator’s optional Evidence Locker seal path is a separate successor contract and does not consume Authority CI/CD timestamp receipts.

Implementation

Policy behavior

Determinism and offline posture

Verification and health boundary

Test coverage

Validation command used: