{
  "slug": "sigstore-human-layer",
  "title": "Sigstore proves the pipeline. Nothing proves the person.",
  "summary": "Sigstore and SLSA answer which build system produced an artifact, with real rigour. Neither answers whether a human decided to ship it.",
  "lede": "Keyless signing and build provenance answer a hard question with real rigour: which build system produced this artifact, from which source, at which moment. They do not answer a different question that everyone downstream assumes has been answered. Did a human decide this should ship?",
  "date": "2026-09-23",
  "reading_time": "17 min read",
  "category": "Standards",
  "tags": ["Sigstore", "SLSA", "software supply chain", "in-toto", "provenance", "release engineering", "human approval"],
  "image": "https://cdn.twc.sh/images/igcache/Sigstore%20Human%20Layer/1200_630/blog.jpg",
  "url": "/blog/sigstore-human-layer.html",
  "wordcount": 4304,
  "related": ["human-signed-publish", "who-approved-this-deploy", "agents-minting-credentials"],
  "schema": "Article"
}
