The three rungs
Why the middle level exists at all
Signing an early build puts reputation behind bytes that haven't proven their safety model in the wild — a bankruptcy of the assurance you were buying with that certificate. The unsigned-preview window is where even a security-conscious solo user can develop the verify reflex (hash first, features later) at zero reduction of their safety posture.
Signals of a mature ladder
- Every candidate logs its gate results beside the artifact, not in a promise;
- UpgradeCodes stable across preview → release so your evaluation setup lifts cleanly;
- Downgrades are rejected explicitly with a message, not silent “won't overwrite” — refusal logged is a feature of installers, not a bug;
- VM gates: the tool is installed/repaired/upgraded/uninstalled in a throwaway image before a human is offered it.
This preview sits at rung two, publishing everything rung three will use. The ladder script propagates upward: package manifest → hashes → signing. Every public statement about it is constraint-verified before it ships.