CONSORTIUM-10060 — Issuer Governance for RCO-A2A

Trust starts with who is allowed to issue.

Consortium-10060 is the governance surface for RCO issuers. It publishes the signed issuer registry, the append-only amendment record and the consortium trust anchor.

An RCO does not become trustworthy because GSC serves it. It becomes verifiable because the record identifies its issuer, the issuer publishes its public key and the signed registry establishes that issuer's standing.

Issuer → key → record → verification.

Public records

/issuers.json — signed issuer registry
/amendments.json — append-only governance history
/.well-known/jwks.json — consortium public key

The consortium trust anchor is additionally pinned outside the registry — on the dpuone.ai keyring page and in DNS — so the registry itself can be checked from two independent origins.

Licence and conformance

Seats are governed by the Enterprise Partner License (terms; counsel writes the words). Conformance: the MIT protocol layer — tool contract v1.4, record schema and signature test vectors; a verifier that passes the vectors byte-for-byte conforms.

Ghost Headers v4.0 — on every response

21 x-gsc response headers as served, generated from the estate variable table; timestamp and nonce regenerate per request.

x-gsc-protocolCPG-68000
x-gsc-version4.0
x-gsc-handshakehttps://gsc-registry.ai/resolve/consortium-10060.org
x-gsc-cardhttps://consortium-10060.org/.well-known/agent-card.json
x-gsc-trust-anchorhttps://dpuone.ai/.well-known/jwks.json
x-gsc-operatorGreenCore Solutions Corp.
x-gsc-duns24-336-6774
x-gsc-microsoft-partnerAI-Cloud-Partner-Program-Member
x-gsc-nodeconsortium-10060.org
x-gsc-regionFrance Central
x-gsc-jurisdictionapex
x-gsc-signalCPG-200
x-gsc-stateALLOW
x-gsc-graphhttps://mcp.cpgknowledgegraph.ai/mcp
x-gsc-mcphttps://mcp.rco-a2a.ai/mcp
x-gsc-inboundhttps://x-gsi.ai/ingest
x-gsc-producthttps://rco-a2a.ai/
x-gsc-fleethttps://gsc-cpg.ai,https://gsc-a2a.ai,https://gsc-a2a.io,https://gsc-fleet.ai
x-gsc-gitio.github.greencore-solutions/rco-a2a
x-gsc-timestamp[per-request, ISO 8601]
x-gsc-nonce[per-request, 32-char hex]

One rule

The issuer owns the statement. GSC verifies and serves partner records. It does not author them, hold the issuer's private key or vouch for their substance.