How changes happen
Anyone may propose a change by issue or pull request against the public repository. Additive data changes — new service_code values, credential types, review sources — are accepted on evidence that real providers need them, and ship in patch releases. Field changes require a minor version, a migration note, and a deprecation window of at least one minor version. The editor records every decision with reasoning in a public DECISIONS log; silence is never a ruling.
What implementers can rely on
Unknown-field tolerance is normative, so additive evolution never breaks a conformant reader. The certification harness is versioned with the spec: a Level 3 badge always names the harness version that awarded it. And the three v0.1 absolutes — server-authoritative slots, the human principal, the demo fence — will not be weakened in any 0.x release.
Licensing
Specification text: CC BY 4.0 — reuse freely with attribution. JSON Schemas, reference Worker and harness: MIT. The UKLSP name and badge designs may only be used against a valid report hash, which is how the badge keeps meaning anything.
Roadmap to v0.2
On the table, in priority order: cancellation and amendment endpoints; a job-completion webhook so certificates flow back to the principal; Know-Your-Agent request signatures; and the second vertical's service codes. Field reports from live bookings decide the order — get involved.