Seal Before the First Call
A system cannot become blind halfway through. If the first worker call receives a seat name that contains the provider, if the artifact filename embeds the model, or if the initial trail event is projected into a judge-visible panel, later redaction is cosmetic. The seal must exist before the first identity-bearing event can cross a viewing boundary.
That makes sealing an ordering problem. Allocate an opaque seat identity, store the real worker binding behind the reveal chokepoint, generate the pre-call artifact address from the run and opaque seat identifiers, and only then call the worker. Every live serving path—including Dad's—gets only masks.
The rule applies to errors too. A provider-specific failure message can identify a worker more reliably than a signature. Raw failure detail stays sealed; participant and spectator surfaces receive only the identity-safe status needed for the next action. Judge packets contain no seat failure state at all.
Unsealing later is therefore controlled disclosure, not reconstruction. The identity was always recorded. The serializer releases the mapping only after the run enters finalized or aborted.