Skip to content

Discuss: TWI Charter definition for Workload Provenance #314

@mbronk-intc

Description

@mbronk-intc

This is a follow-up to a TWI Sig meeting at 6/17/2025 [mtg notes] which identified that the following definition:

- **Workload Provenance** is a linkage between a Workload Credential and a trusted entity (e.g., a vendor, developer, or issuer) responsible for the creation and/or attestation of the corresponding Workload.

will require update to move away from perceiving the provenance as a dynamic binding of Workload to Credential, rather a static property of the artifact (be it Workload or Credential itself), established at its instantiation and stable going forward.

This issue is filed to track update of the charter doc to reflect the updated definition. Actual proposal is WIP (will update this to be consistent w/ TWI-wimse docs):

 - **Workload Provenance** is a... `TBD (mention what goes in it, and that it is stable from the time of workload instantiation)`
 - **Credential Provenance** is a... `TBD (mention what goes in it, and that it is stable from the time of credential instantiation).`
 - **Credential Provenance Binding** (? do we need to coin it as +1 term?) is a... `linkage linkage between a Workload Credential and a trusted entities (e.g., an Identity Provider and Verifier responsible for the creation and/or attestation of the corresponding Workload Credential.`

CC: @TheBankster @yogeshbdeshpande @henkbirkholz

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions