The Custody Envelope Threshold
Abstract
Modern infrastructure depends on externally maintained artifacts: package-registry dependencies, container images, CI/CD actions, Terraform providers, infrastructure modules, developer extensions, model weights, datasets, and emerging AI tool servers. These artifacts are easy for developers to fetch and compose, but difficult for institutions to admit, govern, revoke, or defend after failure. Existing software-supply-chain frameworks largely address producer integrity, secure consumption practices, maturity levels, or attack taxonomies. They do not explain why comparable artifact classes produce divergent institutional outcomes: some are admitted, some proxied, some policy-mediated, some vendor-mediated, some internalized, and some quarantined or rejected. This article proposes the Custody Envelope Threshold : an authority-scaled model of artifact admission. The model has a normative core and a positive prediction. Normatively, an externally maintained artifact is defensible for direct institutional admission only when object identity, ingress path, and revocation capacity are sufficiently closed relative to the execution authority the artifact receives. Positively, the article argues that institutions exposed to repeated audit, incident-response, procurement, customer-assurance, and operational scrutiny tend to converge toward this authorityscaled custody rule over time. Deviations persist, but they appear as governance debt: tolerated in low-scrutiny or immature settings, then proxied, mediated, internalized, quarantined, or rejected when scrutiny rises. The framework is operationalized as a four-condition ordinal instrument: object identity, ingress path, execution authority, and revocation capacity. Its central proposition is that custody requirements scale with delegated authority: a low-authority artifact may be admitted with modest custody controls, while a high-authority artifact requires strong identity, controlled ingress, and fast revocation before it can cross an institutional boundary. The article then adds a governance-selection heuristic grounded in transaction cost economics: when direct custody closure fails, the institution selects the lowest-burden governance mode that appears capable of closing the binding deficit at an acceptable risk/value tradeoff, where burden is shaped by delegated authority, local custody specificity, and the availability of external closure providers. The framework is positioned against SLSA, NIST SSDF, Microsofts Secure Supply Chain Consumption Framework (S2C2F), and existing software-supply-chain attack scholarship. S2C2F is the closest prior practical framework: it is explicitly consumption-focused, contains solution-agnostic practices organized into maturity levels, and emphasizes controlled OSS ingestion. The Custody Envelope Threshold differs by offering a descriptive-predictive model across heterogeneous artifact classes rather than a maturity/practice model for secure OSS consumption. SLSA and NIST SSDF provide integrity and secure-development evidence surfaces; supply-chain attack literature taxonomizes threats and safeguards. This article instead taxonomizes institutional admission responses and explains why different artifact classes bind on different custody conditions.