コンテンツにスキップ

AI distribution evidence pack

最終確認: 2026-08-02
用途: AI 検索、Plugin Directory、MCP Registry、agentic commerce を、掲載から accepted outcome、実入金、継続まで同じ証拠系で運用する

この pack は流通・計測・運用設計用の書式であり、法律、税務、会計、決済、privacy、プラットフォーム規約の個別助言ではない。主体、地域、商品、plan、workspace、role、program、version ごとに一次情報を再確認する。

このファイルに現れる名称、ID、URL hash、query、商品、金額、件数、日付、結果は完全な架空例である。実績、benchmark、提供資格、推奨母数ではない。

raw prompt、会話、氏名、メール、住所、payment credential、OAuth token、secret、注文詳細、銀行口座、顧客秘密をこの公開書式や生成 AI prompt に貼らない。実運用では opaque ID、redacted summary、hash、権限制御された正本への reference を使う。

  • 17 章: AI distribution の状態、証拠、計測、commerce、判断原則。
  • 04 章: SEO、content、attribution、実験。
  • 09 章: 創業者時間、CAC、完全負荷後貢献、cash。
  • 10 章: channel/platform/protocol/agent の責任境界。
  • 11 章: 契約、invoice、payment、更新の商流正本。
  • 12 章: eligible job、品質、安全、accepted outcome、反復価値。
  • 13 章: release SHA、evidence、review、rollback。
  • 15 章: platform dependency、reserve、停止・移行。
  • SQLite companion: stage path、evidence、cutoff、cash を fully synthetic data で検証する。
  1. 書式 1 で一つの motion と損失上限を固定する。
  2. 書式 2 で policy/program/spec の current snapshot を保存する。
  3. 書式 3 で主体・地域・商品・context の eligibility を fail-closed で判定する。
  4. 書式 4 で経路固有の required / optional / N/A stage と最低証拠を宣言する。
  5. 書式 5 で artifact、feed、listing、server、schema の revision を束ねる。
  6. 書式 6 で provider control-plane と公開解決状態を確認する。
  7. 書式 7 で query/listing probe を実行前に固定する。
  8. 書式 8 で probe run を、provider report や first-party event と混ぜずに記録する。
  9. 書式 9 で匿名 upstream から account/order/cash までの結合可能・不能境界を宣言する。
  10. 書式 10 で install/connect/invoke/accepted outcome を運ぶ。
  11. 書式 11 で checkout/payment/order/fulfillment/entitlement を照合する。
  12. 書式 12 で payout、bank cash、refund/dispute、retained contribution を閉じる。
  13. 書式 13 で最初の未達 stage と次の一変更だけを決める。
  14. 書式 14 で Codex の調査・実装・review と人間の attestation を分ける。
motion_contract_id / version:
policy_snapshot_id:
artifact_id / artifact_revision:
journey_id:
stage_event_id:
provider_object_id: opaque | N/A
source_event_id: opaque | N/A
account_id: opaque | UNKNOWN_LINK | N/A
order_id / payment_id / entitlement_id: opaque | UNKNOWN_LINK | N/A
policy_effective_at:
occurred_at:
provider_created_at: N/A — non-provider event | timestamp
recorded_at:
outcome_cutoff_at:
snapshot_as_of:
maturity_at:
environment: TEST | SANDBOX | LIVE
source_revision / causal_sequence:
ingest_sequence:
supersedes_event_id: N/A — first event | exact ID
payload_ref_hash:
signature_status: VERIFIED | FAILED | NOT_APPLICABLE | UNKNOWN
data_class:
owner / reviewer / reviewed_at:
retention_due_at:
  • LIVE 以外を live funnel、cash、fulfillment へ入れない。
  • occurred_at <= outcome_cutoff_at AND recorded_at <= snapshot_as_of を snapshot ごとに評価する。
  • provider order と ingest order を混ぜない。因果順序がない場合は UNKNOWN
  • correction/retraction は元 event を更新せず、新 event と supersession relation で残す。
  • opaque ID や hash は匿名化、合法性、真正性を自動的に証明しない。
field_or_stage:
state: N/A | UNKNOWN | 0 | OBSERVED | FAILED
reason:
evidence_id:
decided_by / decided_at:
recheck_trigger / due_at:
  • N/A: motion contract 上の適用不能。理由・決定者・再確認 trigger が必要。
  • UNKNOWN: 必要だが未観測、期限切れ、矛盾、join 不能。
  • 0: 対象母数と観測範囲が確定し、件数がゼロ。
  • FAILED: 明示した gate や操作が不合格。
  • OBSERVED: 最低 evidence class を満たす positive evidence がある。
E0_INFERENCE
E1_MANUAL_OBSERVATION
E2_PROVIDER_CONTROL_PLANE
E3_VERIFIED_PROVIDER_EVENT
E4_FIRST_PARTY_AUTHORITATIVE
E5_CUSTOMER_OR_BANK_AUTHORITATIVE

上位ほど常に正しいという意味ではない。stage に適した正本かで判定する。BANK_CASH_RECONCILED に E5、PLUGIN_PUBLISHED に E2、ACCEPTED_OUTCOME に E4/E5 のように contract へ最低値を書く。

STOP > NOT_ELIGIBLE > PAUSE > UNKNOWN > READY_TEST > READY_LIVE
  • STOP: active incident、secret/PII leak、違反、payment/fulfillment unsafe、明示的 revoke。
  • NOT_ELIGIBLE: current program の主体・地域・商品・context 外。
  • PAUSE: rate limit、review、stale feed、reconciliation exception、capacity 待ち。
  • UNKNOWN: applicability、version、auth、evidence、join が未確認。
  • READY_TEST: sandbox/conformance のみ許可。
  • READY_LIVE: current eligibility、security、support、commercial owner が揃う。

下位 gate を売上期待や provider promotion で相殺しない。

一 contract は surface × target context × product × cohort × artifact revision

# AI distribution motion contract
motion_contract_id / version:
decision_owner / reviewer:
motion_type: SEARCH_CITATION | OPENAI_PLUGIN | MCP_REGISTRY |
SHOPIFY_CATALOG_UCP | STRIPE_AGENTIC_COMMERCE | OTHER
surface / provider:
target ICP / job:
seller/publisher legal entity:
country / region:
product_type:
commercial model:
owned-channel fallback:
one artifact / offer under test:
primary outcome:
exact denominator:
accepted outcome definition:
commercial owner rule:
attribution rule / version:
known unobservable stages:
cohort_start_at:
outcome_cutoff_at:
initial_snapshot_as_of:
maturity_at:
decision_due_at:
maximum founder minutes:
maximum cash micros / currency:
maximum live journeys / transactions:
support capacity:
one variable changed:
invariants:
guardrails:
continue rule:
change rule:
pause/stop rule:
inconclusive rule:
approved_by / approved_at:
contract_hash:
[ ] protocol availability と program eligibility を分けた
[ ] preview/upcoming を current live revenue へ入れていない
[ ] provider metric を customer outcome に置き換えていない
[ ] 観測不能を denominator から黙って除いていない
[ ] 一つの order/revenue を一 motion だけに帰属させる
[ ] founder time/cash/live exposure の損失上限が本人入力である

書式 2 — Policy / program / protocol snapshot

Section titled “書式 2 — Policy / program / protocol snapshot”
# Policy snapshot
policy_snapshot_id:
provider / program / protocol:
document_title:
source_url:
source_publisher:
source_captured_at:
source_content_hash:
status: CURRENT | PREVIEW | UPCOMING | DEPRECATED | CONFLICTING
effective_from:
effective_until: UNKNOWN | timestamp
announced_at: N/A | timestamp
version / API version / schema URL:
applies_to_entity:
applies_to_region:
applies_to_product:
applies_to_plan/workspace/role:
required approval/invitation:
required auth/permission:
fees or commercial terms ref:
exact fact supported:
fact not supported:
documented unknowns:
conflicting source IDs:
resolution rule:
operational impact:
next recheck trigger / due_at:
reviewer / reviewed_at:

/latest/、help article、dashboard、API が異なる場合、一つに丸めない。実行時に使った contract version と current policy snapshot を両方保存する。

# Eligibility review
eligibility_review_id / version:
motion_contract_id:
policy_snapshot_ids:
publisher/seller identity: PASS | FAIL | UNKNOWN | N/A — reason
organization/project/residency: PASS | FAIL | UNKNOWN | N/A — reason
country/region: PASS | FAIL | UNKNOWN | N/A — reason
product/service category: PASS | FAIL | UNKNOWN | N/A — reason
customer/buyer category: PASS | FAIL | UNKNOWN | N/A — reason
plan/workspace/role: PASS | FAIL | UNKNOWN | N/A — reason
technical endpoint/package: PASS | FAIL | UNKNOWN | N/A — reason
auth/domain/namespace: PASS | FAIL | UNKNOWN | N/A — reason
privacy/terms/support/listing: PASS | FAIL | UNKNOWN | N/A — reason
tax/payment/fulfillment: PASS | FAIL | UNKNOWN | N/A — reason
security/abuse/review capacity: PASS | FAIL | UNKNOWN | N/A — reason
current gate: STOP | NOT_ELIGIBLE | PAUSE | UNKNOWN | READY_TEST | READY_LIVE
gate reason / evidence IDs:
permitted next action:
prohibited next action:
recheck trigger / due_at:
decided_by / decided_at:

Open spec の conformance を country/region PASS に流用しない。日本主体が米国・カナダ限定 program を sandbox で試せても READY_LIVE ではない。

経路の全 canonical stage を並べ、適用性と最低証拠を実行前に決める。

# Stage path
motion_contract_id / path_version:
order | canonical_stage | applicability | minimum_evidence | denominator | source-of-truth
10 | ELIGIBLE | REQUIRED | E2 | target contexts | policy + control plane
20 | ARTIFACT_VALIDATED | REQUIRED | E4 | submitted artifacts | validator
30 | SUBMITTED | OPTIONAL/N/A/... | E2 | ... | ...
40 | APPROVED | ...
50 | PUBLISHED_OR_INDEXED | ...
60 | EXACTLY_RESOLVABLE | ...
70 | SURFACED | ...
80 | CITED_OR_SELECTED | ...
90 | VISITED_OR_INSTALLED | ...
100 | CONNECTED | ...
110 | INVOKED | ...
120 | ACCEPTED_OUTCOME | ...
130 | CHECKOUT_CREATED | ...
140 | PAYMENT_SUCCEEDED | ...
150 | ORDER_CREATED | ...
160 | FULFILLED_OR_ENTITLED | ...
170 | BANK_CASH_RECONCILED | ...
180 | RETAINED | ...
approved_by / approved_at:
path_hash:

stage order は表示順であり、全 event が strict monotone とは限らない。parallel state、late event、reversal は別 event として持つ。

書式 5 — Artifact / feed / server release bundle

Section titled “書式 5 — Artifact / feed / server release bundle”
# Distribution artifact bundle
artifact_id / revision:
motion_contract_id:
release_id / source commit SHA:
content URL / canonical URL:
plugin package version / manifest hash: N/A | value
MCP endpoint / metadata snapshot hash: N/A | redacted origin + hash
server.json version / schema URL/hash: N/A | value
catalog/feed import ID / row count/hash: N/A | value
feed type / mode: N/A | PRODUCT/INVENTORY_PRICE — UPSERT/REPLACE/DELETE
feed source revision / sequence:
upload URL expiry / uploaded_at:
success count / error count / error file hash:
export reconciliation at / data available end:
seller enabled / agent accepted: N/A | OBSERVED | FAILED | UNKNOWN
UCP protocol / capability / payment handler versions: N/A | value
checkout/order schema version: N/A | value
listing name / description revision:
starter prompts / query target revision:
privacy / terms / support revision:
tool annotations / OAuth scopes:
region/product availability:
positive tests passed / required:
negative tests passed / required:
conformance result:
security review:
rollback artifact / procedure:
published contract compatibility:
approved_by / approved_at:
bundle_hash:

live MCP metadata を先に破壊的変更しない。review snapshot と live server release の両方を照合する。

書式 6 — Publication / index / control-plane verification

Section titled “書式 6 — Publication / index / control-plane verification”
# Provider state verification
verification_id:
motion_contract_id / artifact_revision:
provider / environment:
source_state:
source_object_id / version:
provider API/dashboard evidence ref:
exact public lookup URL or request:
HTTP/API status:
resolved name/version/canonical:
row accepted / rejected / unknown:
status: OBSERVED | FAILED | UNKNOWN
observed_at / recorded_at:
source revision / signature status:
payload/screenshot hash:
minimum evidence satisfied: yes | no
what this proves:
what this does not prove:
next dependent stage:
recheck trigger / due_at:
reviewer / reviewed_at:

例: Registry exact search が version を返しても、downstream aggregator 収載・install・invoke は証明しない。catalog import succeeded_with_errors は全 row success ではない。

書式 7 — Query / listing probe contract

Section titled “書式 7 — Query / listing probe contract”
# Probe contract
probe_contract_id / version:
motion_contract_id:
surface / locale / country / device:
account/sign-in/personalization state:
query/listing lookup set:
query selection rationale:
eligible artifact IDs:
run schedule:
maximum repeats:
randomization/order rule:
cooldown / rate-limit rule:
provider-policy compliance:
positive definition:
negative definition:
unknown/error definition:
surface/citation/link distinction:
capture and redaction method:
primary metric / denominator:
explicit non-claims:
outcome_cutoff_at / snapshot_as_of:
approved_by / approved_at:
contract_hash:
- probe observation rate is not impression share
- one citation is not universal ranking
- absence in sampled provider report is not proof of zero citations
- supporting link is not proof that exact page text generated the answer
# Probe run
probe_run_id:
probe_contract_id / version/hash:
query_id / artifact_id:
surface / locale / context:
started_at / completed_at / recorded_at:
run_status: OBSERVED | NOT_OBSERVED | ERROR | UNKNOWN
artifact surfaced: yes | no | unknown
supporting link visible: yes | no | unknown
exact citation visible: yes | no | unknown | unsupported by surface
position/rank: N/A — provider does not define | observed provider metric
result URL refs:
capture hash:
operator / reviewer:
provider report event ID: N/A | exact ID
first-party referral ID: N/A | exact ID
what changed since prior run:
incident/personalization caveat:
supersedes_run_id: N/A | exact ID

manual probe、provider AI report、first-party referral を別 event にし、同じ行へ上書きしない。

書式 9 — Identity / correlation / attribution boundary

Section titled “書式 9 — Identity / correlation / attribution boundary”
# Journey correlation map
journey_id:
motion_contract_id:
commercial_owner:
boundary | upstream ID | downstream ID | link state | evidence | permitted use
provider→landing | opaque | opaque | VERIFIED/UNKNOWN_LINK/N/A | ... | attribution only
landing→account | opaque | opaque | ... | ... | consented analytics
account→checkout | opaque | opaque | ... | ... | commercial operations
checkout→payment | opaque | opaque | ... | ... | reconciliation
payment→order | opaque | opaque | ... | ... | fulfillment
payment/payout→bank | opaque | opaque | ... | ... | cash reconciliation
provider_declared_origin:
first_known_touch:
assist touches:
causal experiment assignment: N/A | assignment ID
incremental claim permitted: yes | no — reason
PII/consent purpose:
retention/deletion rule:
fingerprinting prohibited: yes
duplicate revenue prevention key:
reviewer / reviewed_at:

UNKNOWN_LINK を時刻・金額・IP・browser fingerprint で推定 join しない。

書式 10 — Install / connect / invoke / outcome ledger

Section titled “書式 10 — Install / connect / invoke / outcome ledger”
# Runtime stage event
stage_event_id / journey_id:
motion_contract_id / artifact_revision:
canonical_stage: VISIBLE | INSTALLABLE | INSTALLED | ENABLED |
WORKSPACE_ALLOWED | PROVIDER_CONNECTED | SYNC_ENABLED |
INVOCATION_REQUESTED | TOOL_SELECTED | TOOL_CALLED |
RESULT_RETURNED | ACCEPTED_OUTCOME | REVOKED | UNINSTALLED
source_stage:
target context: plan/workspace/role/region/surface
job_id / job_eligibility: opaque | N/A
tool/skill ID and contract version:
permission class: READ | DRAFT | PRIVATE_WRITE | OPEN_WORLD | DESTRUCTIVE | PAYMENT
human confirmation event: N/A | exact ID
source system / source event ID:
evidence class:
result: OBSERVED | FAILED | UNKNOWN
failure domain:
occurred_at / recorded_at:
signature status / environment:
payload ref hash:
supersedes_event_id:
accepted outcome definition/version:
acceptance evidence ID: N/A | exact ID
customer-visible side effect:
rollback/reversal status:
reviewer / reviewed_at:

uninstall と connector revoke、tool result と accepted outcome、HTTP success と business success を別 event にする。

書式 11 — Checkout / payment / order / fulfillment

Section titled “書式 11 — Checkout / payment / order / fulfillment”
# Commerce chain
commerce_chain_id / journey_id:
motion_contract_id / artifact_revision:
seller / region / product eligibility review ID:
checkout_id / idempotency key:
checkout schema / protocol version:
price book / inventory revision:
currency / amount minor units:
tax / discount / fee breakdown:
buyer review/authorization event:
allowance seller/currency/max/expiry review:
payment_id / provider:
payment state: CREATED | REQUIRES_ACTION | AUTHORIZED | CAPTURED |
SUCCEEDED | FAILED | CANCELED | UNKNOWN
provider event ID / signature:
authoritative read-back at:
PaymentIntent authoritative status / read-back event:
async outcome event ID: N/A | exact ID
BalanceTransaction ID: N/A | exact ID
order_id / persisted_at:
order state:
provider resource mode: SNAPSHOT | DELTA | UNKNOWN
resource version/hash:
webhook delivery ID / merchant action event ID:
subscription mode / current read-back at:
outbox event / fulfillment job ID:
fulfillment type: PHYSICAL | DIGITAL | SAAS | API | SERVICE
fulfillment/entitlement definition:
fulfillment event IDs:
customer acceptance ID:
refund / dispute / cancellation IDs and revisions:
UNKNOWN reconciliation queue ID:
duplicate execution check:
test/live isolation check:
reviewer / reviewed_at:

timeout や network error は UNKNOWN。新 idempotency key で自動再実行せず、provider object と自社 order を read-back する。SPT の used/deactivated、Checkout Session completed、Order webhook delivery は、それぞれ PaymentIntent 成功・銀行着金・顧客受容の代替証拠にしない。

書式 12 — Settlement / reversal / retained contribution

Section titled “書式 12 — Settlement / reversal / retained contribution”
# Cash and retention bridge
bridge_id / commerce_chain_id:
currency / unit: micros
commercial owner:
gross customer consideration:
tax held for remittance:
discount / credit:
refund:
provider / platform fee:
FX / payout fee:
dispute loss / fee:
processor-side net cash:
payout ID / revision / state / amount:
failure balance transaction / trace ID: N/A | value
bank transaction ref hash:
bank amount / received_at:
bank reconciliation state: MATCHED | PARTIAL | FAILED | UNKNOWN
difference / reason:
COGS:
AI / storage / delivery variable cash:
support minutes:
founder rescue minutes:
internal hourly value micros:
allocated channel cost:
net settled contribution:
refund/dispute observation window end:
renewal/retention window end:
maturity state: PROVISIONAL | MATURE | UNKNOWN
retention state / evidence:
retained net settled contribution:
source event IDs:
reviewer / reviewed_at:

銀行着金が既に provider fee 控除後なら fee を再控除しない。gross→net→payout→bank の bridge を合わせる。

# AI distribution weekly decision
review_id:
motion_contract_id / version:
policy snapshot / artifact / path versions:
outcome cutoff / snapshot as-of / maturity:
stage | denominator | observed | failed | unknown | N/A | evidence class
...
first missing required stage:
first guardrail breach:
late/corrected/retracted evidence:
known unobservable stages:
accepted outcomes:
checkout / payment / order / fulfillment:
bank cash / reversal / mature retained contribution:
founder minutes / cash spent / remaining cap:
decision: CONTINUE | CHANGE | PAUSE | STOP | INCONCLUSIVE
decision reason:
one change domain:
unchanged domains:
next evidence to collect:
owner / due_at:
delist/revoke/rollback/customer notice action:
approved_by / approved_at:

最初の未達が eligibility なら copy や checkout を変更しない。outcome 不受容なら traffic を増やさない。

書式 14 — Codex handoff / human attestation

Section titled “書式 14 — Codex handoff / human attestation”
# Codex work brief
change_id:
motion_contract_id:
goal:
authoritative source snapshots:
files/components in scope:
explicitly out of scope:
Codex may:
- retrieve/diff official sources
- draft mappings, schema, fixtures, tests, runbooks
- implement telemetry, signature, dedup, reconciliation
- summarize redacted evidence
Codex must not:
- attest legal/program eligibility
- publish/enable live commerce without exact authorization
- classify inference as provider/customer/bank fact
- ingest raw PII, prompt, credential, bank data into public artifacts
- retry unknown external writes/payments with a new key
done when:
- exact source/version/effective date stored
- positive and negative tests pass
- UNKNOWN/N/A/0 remain distinct
- test/live isolation verified
- rollback/delist/revoke path rehearsed
- human reviewer signs exact artifact hash
human attestation:
program eligibility:
privacy/terms/tax/payment:
external write/payment authority:
accepted outcome:
bank reconciliation:
continue/stop decision:
reviewer / reviewed_at:
release SHA / evidence manifest hash:
[ ] one motion / one artifact / one cohort
[ ] current policy snapshot and exact protocol/schema version
[ ] eligibility gate before implementation and again before live
[ ] route-specific required stages and minimum evidence classes
[ ] provider state, manual probe, first-party event kept separate
[ ] opaque correlation with UNKNOWN_LINK preserved
[ ] webhook signature, dedup, idempotency, outbox, read-back
[ ] test/live isolation and no raw PII/secrets
[ ] payment, order, fulfillment, bank cash, reversal separated
[ ] mature retained contribution and founder time reviewed
[ ] first missing stage selects one change domain
[ ] delist, revoke, rollback, export, customer notice runbook