Provenance
Where a record came from: the company or project, the documentation behind it, and the terms that documentation carries. Provenance is a fact about the source, not a judgement about quality.
thesaria
Evidence & trust
Is it from where it says? May it be reused? Has anyone independent checked it? Is that check still valid? Collapsing these into one score is how bad reuse happens.
Where a record came from: the company or project, the documentation behind it, and the terms that documentation carries. Provenance is a fact about the source, not a judgement about quality.
What the terms allow. Direct reuse of code and reference to a pattern are different permissions, and neither is implied by a good review. A well-evidenced asset can still be reference-only.
Review carried out separately from the proposal, with a stated scope: what was checked, at which version, and what was not. Where evidence is thin, the record says so instead of rounding up.
Whether a record is usable right now. Sources change and reviews age; a record that has drifted is marked degraded and blocked from new packaging until it is re-verified. Prior high trust does not override that.
Requirements, packages and notes belonging to a workspace are designed to stay inside it and not become repository content. Thesaria does not claim to hold private company code.
Semantic similarity suggests candidates. Governed admission is what authorizes them. Nothing becomes usable because it resembles something that already is.
Status
Everything on this page describes how the repository is being designed to behave. The governed registry, the independent review pipeline and the revalidation cycle are still being built, and no production repository is connected to this site yet. We would rather state that plainly than describe a control as though it were already running.

Access is granted by review rather than self-serve sign-up, so that we know who is writing requirements against the repository while it is being built.