01
Company & source registry
Who the material came from and what documents it: a company, a project, a publication. Provenance and terms live here, not with the capability.
thesaria
The repository
Six kinds of record, kept apart on purpose. Conflating them is how software teams end up reusing code they were never permitted to reuse.

01
Who the material came from and what documents it: a company, a project, a publication. Provenance and terms live here, not with the capability.
02
A demonstrated behaviour described so a requirement can be matched against it. A capability is not a claim of quality and not a permission to copy.
03
The specific artefact at a specific version. Evidence attaches here. A new version is a new thing to verify; the earlier record is superseded, not erased.
04
Independent review with a stated scope: what was checked, against which version, and what was left unchecked. Absence of evidence is recorded as such.
05
What the terms allow: direct reuse of code, or reference to the pattern only. Held separately from trust, so a well-reviewed asset is never assumed reusable.
06
The assembled output: exact assets and versions, their conditions, the reasons they were selected, and the reasons others were excluded.
Source to build
Open a layer to see what it records and what it refuses to assume. The example values shown are fictional; the repository integration is still in progress.
01 · Source registry — Provenance
Every record starts with a documented source: the company, project or publication it came from, the material that documents it, and the terms that material carries. A capability with no traceable source does not enter the repository.
Example record at this layer: Northwend Systems (fictional) · public engineering write-up. Fictional sample data — no live repository is connected.

The structure described here is the design the product is being built to. The governed registry and its evidence pipeline are not yet connected; the public example runs on fixtures.