Sign container images during the build process and verify those signatures at admission to clusters. Track image provenance back to source repository commits and build pipelines that produced them.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.