Bind and retain the actor, subject, scope, version, operation, evidence and actual resources on which a continuation relies. Compatible Rust types do not prove that two values identify the same occurrence. Compare runtime identities where required, or retain the resource itself behind an appropriate ownership or borrowing boundary.
Why: approving version 7 and later executing version 8 is not continuity. Nor is sending store A's record 7 to store B because their identifier types match.
Consequence: a successor must not silently substitute work. New evidence can be legitimate later input when it refers to the original operation. Recovery preserves that operation and what is known about it. A later visit is admitted again against current facts.
State carriers may own data. Zero-sized markers are optional and appropriate only for distinctions that need no carried data. Construction, mutation, deserialization and cloning must not forge protected progression. Consume a value where local reuse is invalid; seal a surface where arbitrary implementations would forge authority. Keep intended trusted adapter ports open.
Mutable authority, expiry, revocation and stored versions need current checks at the owning boundary. Do not keep a database transaction open across human delay just to retain a Rust type. Persist the right facts and re-establish admission when work resumes.