1 · Live scan any hostname
Tolljar checks public robots.txt plus RSL associations found in robots, the homepage HTTP Link header, or HTML. This is policy posture — not observed AI traffic.
2 · Start a secure browser session
This MVP uses an HttpOnly browser session cookie. Email is a contact/account label; domain control proof is what grants property authority. Production account recovery/email-login comes next.
3 · Verify domain control
Create a challenge tied to your current browser session, then prove control with DNS TXT or a homepage meta tag. Verification is hostname-specific; Tolljar does not collapse www.example.com into example.com.
4 · Set authoritative AI rights
These controls map conservatively to RSL 1.0. “Open to paid licensing” is stored as Tolljar commercial interest only — it does not silently create a per-use payment obligation.
5 · Hosted Rights Pointer
This is the product shift: do not keep re-uploading license.xml. Your site points once to Tolljar's stable hosted RSL URL. Changes are versioned here and the URL stays the same.
6 · Canonical RSL preview
Local preview uses one <permits type="usage"> and one <prohibits type="usage"> maximum, with space-separated usage tokens. The server-hosted document is canonical.
7 · Rights history
Every authoritative save creates a new version. This is the start of the auditable rights ledger.