> For the complete documentation index, see [llms.txt](https://docs.optivalux.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.optivalux.com/technical/lifecycle-and-status.md).

# Lifecycle & Status

This page explains the public-facing status dimensions of a product and how they relate to the protocol's lifecycle.

## Three public dimensions

Every product record exposes three **independent** statuses. They are never merged into a single valid/invalid flag.

### Ownership

| Public state         | Meaning                                                       | Protocol basis                                                                                                            |
| -------------------- | ------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------- |
| **Unclaimed**        | Registered by the brand; no owner has claimed it yet.         | Phase `PROVISIONED` (not yet released) or `CLAIMABLE` (released by the brand); held in brand custody                      |
| **Owned**            | Held by an owner account.                                     | Phase `OWNED`                                                                                                             |
| **Transfer pending** | The owner has authorized a transfer that is not yet complete. | Application view of an outstanding transfer authorization; the protocol phase remains `OWNED` until the transfer executes |

Phase only moves forward: `PROVISIONED → CLAIMABLE → OWNED`. A transfer keeps the phase at `OWNED` with a new owner.

### Certificate standing

| Public state  | Meaning                                      | Protocol basis                  |
| ------------- | -------------------------------------------- | ------------------------------- |
| **Active**    | In good standing                             | `ACTIVE`                        |
| **Suspended** | Temporarily not in good standing; reversible | `SUSPENDED`, with a reason code |
| **Voided**    | Permanently ended; history preserved         | `VOIDED` (terminal)             |

Transitions: `ACTIVE ⇄ SUSPENDED`; `ACTIVE` or `SUSPENDED → VOIDED`. Nothing leaves `VOIDED`.

Rules:

* Claims and transfers require `ACTIVE`.
* Voiding an owned certificate requires the brand security authority and a confirmed suspension held continuously for at least the notice period (protocol floor: 72 hours; production value not yet set).
* A suspension of an owned certificate by anyone other than the brand security authority is **provisional**: it lapses after 14 days unless confirmed, and cannot support a void while unconfirmed.
* Lifting a suspension requires the brand security authority.

### Authentication availability

| Public state                 | Meaning                                                                           |
| ---------------------------- | --------------------------------------------------------------------------------- |
| **Verified**                 | A recent authenticator check matched the registered identity.                     |
| **Verification required**    | Fresh evidence is needed (for example, after recovery bound a new authenticator). |
| **Verification unavailable** | Verification cannot be performed right now.                                       |
| **Recovery available**       | The owner can restore authentication access.                                      |
| **Recovery pending**         | A recovery request is in progress.                                                |

Authentication availability is an **application interpretation of evidence**, not a protocol state. It does not change certificate standing or ownership.

## Protocol verification outcomes (technical)

The protocol design defines these outcome codes. They are **implementation identifiers, not public status labels**; public results use the labels in [Authenticity Evidence](/product/authenticity-evidence.md#verification-results). Verification never alters protocol state.

| Protocol outcome | Meaning                                                                                      | Public presentation                                  |
| ---------------- | -------------------------------------------------------------------------------------------- | ---------------------------------------------------- |
| `AUTHENTIC_TAP`  | Fresh, valid evidence for the bound authenticator; certificate `ACTIVE` and not owner-locked | Authenticator verified                               |
| `LOCATOR_ONLY`   | Reached by QR or static link; public status only; not possession evidence                    | QR opened this product record                        |
| `REPLAYED`       | Valid cryptography, but stale or already-used evidence                                       | Not verified (explained in prose)                    |
| `INVALID`        | Cryptographic verification failed                                                            | Does not match the registered identity               |
| `FLAGGED`        | Certificate suspended (reason shown) or owner-locked                                         | Standing or lost/stolen notice shown with the result |
| `VOIDED`         | Certificate permanently voided (reason shown; history visible)                               | Certificate standing: Voided                         |
| `RETIRED_TAG`    | The tapped authenticator was replaced and retired                                            | Not verified (explained in prose)                    |
| `UNKNOWN`        | No certificate for this authenticator                                                        | Not verified (explained in prose)                    |

## Additional protocol dimensions

The protocol tracks further state that is not a primary public status:

* **Owner lock**: `UNLOCKED ⇄ LOCKED`, set and cleared only by the owner (for example, a lost or stolen report). While locked, no transfer or authenticator replacement is possible.
* **Authenticator binding**: the current authenticator and all retired ones. Retirement is permanent.
* **Recovery Authenticator reservation**: write-once, registered before first ownership, unique to one certificate.
* **Software version pin**: which approved protocol software version governs the certificate, or the protected state used by Protection Mode.
* **Protection Mode request** and **pending Recovery Authenticator recovery**, each with a 14-day minimum period.

Owner and brand applications may surface some of these in future (for example, a lost or stolen indicator). Public terminology for them is not yet established.

## Lifecycle at a glance

```
             register          release            claim
 (none) ───────────────▶ Unclaimed ──────────▶ Unclaimed ─────────▶ Owned ◀─┐ transfer
          (brand custody)  (not yet for sale)   (for sale)                    └──────┘

 Standing (any phase):   Active ⇄ Suspended ──▶ Voided  (terminal; owner and history preserved)
 Recovery (owned):       authenticator A ──▶ authenticator B, A retired; owner unchanged
 Protection Mode (owned): normal software ──▶ protected state; owner and standing unchanged
```


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.optivalux.com/technical/lifecycle-and-status.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
