PRODUCT MANUAL

Trusted SIC
Controlled Pilot Guide

Role-based guide for tenant onboarding, RP registration, Passkey approval, multi-CA routing, activation, protected signing and evidence operations.

OPERATING JOURNEY

Sixteen governed tasks.

01

Tenant onboarding

Define organization, trust boundary, data residency, operators and evidence retention.

02

Relying-party registration

Register redirect/origin, OAuth client, mTLS identity, scopes and branding.

03

CA/provider connectors

Configure route, credentials, health, eligibility and approved failover.

04

Signer identity mapping

Map OIDC subject and verified identity to signing accounts.

05

Passkey registration

Register credential under the approved RP ID and authenticator policy.

06

Signing profiles

Configure format, algorithm, provider, verifier and evidence policy.

07

Create signing request

Submit hashes, signer, context, approval and expiry.

08

Transaction display

Render document identity, purpose, amount and relying-party facts.

09

Passkey approval

Generate challenge and verify assertion, origin, RP ID and policy.

10

Signature activation

Issue short-lived single-use SAD/authorization.

11

Protected execution

Invoke HSM/QSCD/SAM through the approved provider route.

12

ASiC packaging

Assemble manifest, detached signatures and supporting evidence.

13

Timestamp & validation

Collect TSA, certificate path, OCSP/CRL and report.

14

Status & callbacks

Track asynchronous state and deliver governed notifications.

15

Failure & recovery

Handle expiry, provider outage, partial verification and approved rollback.

16

Audit & support

Export correlated evidence, operational metrics and support package.

ADMINISTRATOR CHECKLIST

  • Approve tenant, RP, provider and profile owners
  • Freeze supported browsers/authenticators and CA routes
  • Configure rotation, revocation, retention and incident contacts
  • Run negative, replay, expiry and failover tests

DEVELOPER CHECKLIST

  • Use idempotency and correlation for every state change
  • Never log document contents, credentials, SAD or private key data
  • Display transaction facts before approval
  • Persist evidence identifiers and verify final state