Reference architecture · AEM on Azure
Packaging to supply chain

Attestation for AEM — one identifier, end to end.

Capstone — the summary

This is the summary of everything below: the asset was never the file — it's the identity and the rights around it.

1 · Purpose. Give each product one identity, created once, on ground you own — so every system, shelf, and screen recognizes the same thing.

2 · Benefit. Dynamic cart and checkout data publishes into a system that is documented and trusted — in real time, on every surface.

3 · The guarantee. The architecture it was built with: permissions you own, decisions signed against your own domain, every step written down. The rules arriving by 2027 are already satisfied — set it up once, and you never redo it.

Where does an AI agent get told no? Here. The Boundary and Trust Framework is an AI-powered decision layer that runs in standard Docker / Kubernetes containers inside your own cloud — beside AEM today, beside any CMS tomorrow. Every permission is a record you own, and every decision is signed and provable against your own domain.

AI never crosses your firewall — it works outside, on structure without substance, and only signed releases come in. Granting, revoking, and auditing access are one-step operations you can see.

Architecture diagram: Adobe AEM Cloud Service and a customer AKS cluster side by side in one Azure region. Xano Enterprise runs as Docker pods on Kubernetes — engine, workers, Redis, Postgres — behind an outbound-only Cloudflare tunnel. AI works on a stage instance outside the firewall; only signed releases cross.
Full vector — zoom freely. Drawn 2026.

Crosses the boundary: releases (inward, signed) · tunnel (outward-only) · egress (allowlisted). Never crosses: rows, secrets, ledger — and no inbound port ever opens. AI touches: stage only.

The premise

A publishing framework built for systems that don't exist yet.

Design a content publishing framework that works for future systems. What you publish today will be read by platforms, registers, and regulations that haven't arrived yet — so identity, rights, and content are minted once, on ground you own, and everything downstream inherits that one decision.

Then create a content strategy that deploys everywhere in real time: publish once, and it reaches every surface — the page, the package, the checkout, and whatever comes next — without redrawing, regenerating, or reprinting a thing.

The middle miles

The supply chain already speaks your data language.

Between the printer and the register, the code is scanned dozens of times — inbound, warehouse, distributor, retail receiving. Each scan is an event: which unit of which product, where, when, in whose custody. Recorded against the same identifier, the chain becomes a ledger — provenance you can show, not assert.

And the standard the industry ratified for exactly this — EPCIS 2.0, GS1's supply-chain event vocabulary — is JSON-LD over the web. The same machine-readable grammar a modern product page already publishes for search engines is what warehouses and trading partners exchange for traceability. One data plane, two audiences: algorithms that rank you, and partners that receive you. A scan ledger that emits EPCIS events is legible to every serious traceability system on earth without a single custom integration.

The calendar

Three regulations, one code.

This isn't a modernization project looking for a sponsor. Three regimes converge on the same printed code:

  1. 2027GS1 Sunrise. Retail point-of-sale transitions to 2D codes — the QR stops being marketing flair and becomes the checkout identifier itself.
  2. FEB 2027EU Digital Product Passport. The battery passport becomes mandatory, textiles follow — product data must be accessible through the data carrier on the item. Same QR, now a legal doorway.
  3. 2026–2027Cyber Resilience Act. Connected products need an evidence chain — what shipped, to whom, under what grant. The ledger behind the code is that evidence.

One code on the box, resolving to one owned domain, with one ledger behind it, satisfies all three. Three codes from three vendors satisfies none of them cleanly — and reprints every time a vendor changes.

The return miles

The chain isn't done until it comes back.

The scan in a customer's kitchen is the identifier's second career: manuals, warranty, authenticity — served in the buyer's language, because the resolver knows the locale even though the ink doesn't. And when a unit comes back, the same code keys the return — the RMA joins the same record that started on the packing line. Artwork to print to logistics to checkout to home to return: the loop closes on one identifier, and every hop of it is a row you can produce on demand.

The next tier is serialization — GS1 Digital Link with a serial number gives every unit its own code, which is what recalls, warranty fraud, and grey-market detection actually require. Same architecture, one more path segment; the product-level plane described here is the prerequisite, not a competing choice.

The position

Narrow stack, one trusted layer at the base.

One thing at the bottom of the supply chain that everything above it depends on — that's the position the mint occupies for product identity: artwork, print, logistics, checkout, returns, all resolving to one attested code.

Everything above that layer stays replaceable — the print vendor, the 3PL, the commerce platform, the resolver's hosting. The one thing that must hold is the thing designed to hold: the identifier, minted once, bound to data you attest, on a domain you own, with a ledger that remembers every scan. Companies that treat the code as artwork will reprint their way through the next decade. Companies that treat it as infrastructure will print it once.