Quarterly cost model as signed data
LIC-0052 ○ Planned Lite and Pro CoreThe quarter's cost lines and the paying-member count live in a signed, expiring, editable document (cost-model), not in code; a new quarter is a new signed version, and an older version is refused (rollback protection)
Depends on: LIC-0001
Flat fee calculator: the quarter's cost split among paying members
LIC-0073 ○ Planned Lite and Pro CoreThe fee is the quarter's cost divided by the paying members, rounded down to a presentable step so the members together never pay more than the cost; there is no opening multiple (ADR-0009, tentative); the price starts high when few members share the cost and falls as paying members grow, never rising with more members; integer arithmetic only, never a percentage of revenue
Depends on: LIC-0001
One flat quarterly fee for every product
LIC-0061 ○ Planned Lite and Pro CoreThe same fee applies to the whole of Simca, Simca Packaging and Simca Logistics included; the signed document carries scope all_products and cannot carry any per-product, per-element, per-role or per-event field
Depends on: LIC-0001
Early members are rewarded by their own bill falling
LIC-0062 ○ Planned Lite and Pro CoreThere is no launch premium, no surplus and no opening multiple; early members pay more only because fewer share the cost, and their bill drops as members join
Depends on: LIC-0001
Your bill has dropped X percent
LIC-0063 ○ Planned Lite and Pro CoreFrom the signed quarterly documents already on the member's machine, the launcher computes how the member's fee changed since the quarter they started (exact integer tenths of a percent), and reports a rise honestly as a rise; nothing is fetched or reported anywhere
Depends on: LIC-0001
Bill change refuses an unsound history
LIC-0064 ○ Planned Lite and Pro CoreEvery document in the history needs both signatures, versions must rise with the quarters, the newest must be current and not rolled back, and a missing starting quarter, mixed currency or mixed mock and real models are refused
Depends on: LIC-0001
No per-member fee ceiling
LIC-0065 ○ Planned Lite and Pro CoreA hard ceiling per member is not wanted: the first members may pay a large share of the cost, which the transparency page states plainly; the 10x-cost ceiling no longer exists (ADR-0009)
Depends on: LIC-0001
Mock cost model can never look real
LIC-0056 ○ Planned Lite and Pro CoreRandom demonstration numbers use the no-currency code XXX, carry MOCK labels and ids and a seed, are refused by the launcher, cannot be turned into a price table, and cannot be signed without an explicit flag
Depends on: LIC-0001
Cost model expires with its quarter
LIC-0057 ○ Planned Lite and Pro CoreA cost model must carry an expiry no later than the end of the following quarter, so a stale breakdown cannot be shown as current
Depends on: LIC-0001
Price table derived from a final cost model
LIC-0058 ○ Planned Lite and Pro StandardA FINAL price table can be derived from a FINAL cost model and a decided (SET) profit threshold; a mock model or a tentative threshold can never reach it
Depends on: LIC-0001
Quarterly transparency view for the website
LIC-0059 ○ Planned Lite and Pro CoreOne generated file with the cost lines, the total, the arithmetic, the resulting flat fee, the fall with member count and an example of a member's bill falling over earlier quarters; the website renders it and does no pricing arithmetic of its own
Depends on: LIC-0001
Two independent signatures on cost and price documents
LIC-0066 ○ Planned Lite and Pro CoreA cost-model or price-tiers document is accepted only with two signatures from two disjoint key sets, made by different people on different offline devices over the same bytes; one stolen or lost key signs nothing that is accepted and the same key cannot be both signers
Depends on: LIC-0001
Single-signature verification is refused for money documents
LIC-0067 ○ Planned Lite and Pro CoreThe ordinary single-signature check refuses the price and cost document types outright, so no code path can accept a price on one signature
Depends on: LIC-0001
Spare signing keys and rotation
LIC-0068 ○ Planned Lite and Pro CoreEach of the two key sets holds an active key and an enrolled offline spare, so a lost or suspect key is replaced by rotating to its spare without lowering the two-signature rule
Depends on: LIC-0001
Revoked signing key is dead in both sets
LIC-0069 ○ Planned Lite and Pro CoreRevocation applies to both key sets and wins over trust; revoking either signer's key invalidates documents it signed
Depends on: LIC-0001
Signing ceremony and key custody (planned)
LIC-0070 ○ Planned Lite and Pro StandardGenerating the four keys offline, choosing the two custodians, recording the public keys and a dry-run rotation is documented in ADR-0008 and still to be done by the owner; no real key exists yet
Depends on: LIC-0001
Revocation and key changes ship with launcher updates (honest limit)
LIC-0071 ○ Planned Lite and Pro StandardTrusted public keys and revocations reach a customer only through a launcher update they choose to apply, because there is no polling; losing both keys of one side stops new documents until a new build carries new keys
Depends on: LIC-0001