Per SLSA Verification: verification + attestation. Requirements include (a) verify provenance attestations + (b) integrate with in-toto + Sigstore + (c) implement verification policy + (d) reject unverified artifacts + (e) integrate with admission control.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.