# Golden-path proof loop > **Single source of narration** for Track 0070. The CLI (`ledgerful demo --keep`) > prints the same canonical steps from `GOLDEN_PATH_CANONICAL_STEPS` in > `src/commands/demo.rs`. The public web page (ledgerful-web) **mirrors this > document** — do not invent a second script of steps. Self-guided “magic moment”: install → signed transaction → **cryptographic VALID** → openable signed evidence bundle. A stranger can be their own auditor in one sitting. No new crypto primitives — reuses shipped verify modes. ## Honesty (load-bearing) - **Synthetic** invoice-service repo generated by `ledgerful demo` - **Disposable keys** in the demo dir (not your production `~/.ledgerful/keys/`) - **Observe mode** (warns; does not enforce gate blocks) - Same **Ed25519 signatures + chain** mechanics as production - **Not** real business-risk data - The zip is **signed evidence only** — not a certification or compliance attestation ## Two clocks (never average) | Clock | Meaning | How to ship | |---|---|---| | **T_proof** | Binary already installed → VALID + openable bundle | Primary “<3 min” magic-moment claim | | **T_first** | Cold install + T_proof | Show honestly as install-inclusive; “already installed? start at step 2” | Measured values live in the track `review.md` (no invented numbers on the web page). ## Canonical path (already-installed → VALID + openable bundle) ```text # Golden path (already-installed → VALID + openable bundle) # 1. Synthetic signed demo repo + DEMO evidence zip (kept) ledgerful demo --keep --output ./ledgerful-demo # 2. HOME/CWD were restored after demo — crypto follow-ups must run IN the kept dir: cd ./ledgerful-demo # 3. Cryptographic VALID beat (signatures + chain) — brand moment ledgerful verify --signatures --chain # expect: exit 0; summary includes VALID entries and/or "Chain verified" # 4. Retained-head proof (live chain extends or equals export checkpoint) ledgerful verify --signatures --against-export ./ledgerful-DEMO-evidence.zip # expect: exit 0 (live chain extends or equals retained export head) # Honesty: synthetic invoice-service · disposable keys (not production keyring) · # observe mode (warns, does not enforce) · same crypto as production · not real # business-risk data · not a compliance verdict. ``` ### PowerShell (copy-paste) ```powershell ledgerful demo --keep --output .\ledgerful-demo Set-Location .\ledgerful-demo ledgerful verify --signatures --chain ledgerful verify --signatures --against-export .\ledgerful-DEMO-evidence.zip ``` ### Bash (copy-paste) ```bash ledgerful demo --keep --output ./ledgerful-demo cd ./ledgerful-demo ledgerful verify --signatures --chain ledgerful verify --signatures --against-export ./ledgerful-DEMO-evidence.zip ``` ## What you should see (skeptic exit-criteria) - `[DEMO]` markers on demo stdout and DEMO-marked ledger entry summaries - **`CRYPTO VALID — all signatures + chain verified`** (automated inside `demo`) - **`CRYPTO VALID — live chain extends or equals retained DEMO export`** - An openable zip: `ledgerful-DEMO-evidence.zip` (kept with `--keep`) - Gate mode notice: **observe** - Follow-up manual `verify --signatures --chain` / `--against-export` exit 0 - **Honesty:** promoted DEMO ledger entries are **Unverified** (hook promote never sets Verified). `CRYPTO VALID` = signatures + chain integrity, not `verification_status = Verified`. Against-export uses checkpoint (extends-or-equals) semantics; immediate demo equality is a subset. ## What the automated `demo` already does 1. `init` in observe mode + real hook-driven signed commits (ephemeral demo keypair) 2. Optional project checks (`verify --scope fast`) — **suite health only**, quieted; may WARN/FAIL on synthetic code and is **not** the brand moment 3. DEMO evidence zip export 4. **Cryptographic VALID** — `verify --signatures --chain` then `--against-export` on the automated path 5. With `--keep`: repo + zip retained; without `--keep`: VALID was shown, then cleanup (golden path always uses `--keep`) ## Not in this stopwatch - **Public ledger** (`/ledger` WebCrypto on production history) — optional post-success sidebar (“also: verify our production history”), not step 3 of the same clock - **Dashboard** (`ledgerful web start`) — optional; the default skeptic loop is **CLI-only**. By default the session token is written to `.ledgerful/web-session-token` (not printed); use `--print-token=true` only when you need the hex on stdout. Prefer `LEDGERFUL_WEB_TOKEN` or the token file over shell history; empty/short explicit tokens refuse start. `web start --open` signs in via a single-use handoff code (no paste). `--allow-public` requires `LEDGERFUL_WEB_PEER_ALLOWLIST`. - **Control-mapping / certification claims** — parked (0048); this path is signed evidence only ## Install (cold start / T_first) See the install docs (post-0068 truth: brew / scoop / binstall / source). After the binary is on `PATH`, start at step 1 above. ## Related - `ledgerful demo --help` - `ledgerful verify --help` - Track 0039 (demo + export), 0046 (chain hash), 0050 (observe/enforce), 0045 (public ledger)