Adopt the recomputability boundary as GH-DEC-2026-007

GH-WP-0003-T04. kings-guard's answer to KG-IN-0003 is adopted: the
posture/maturity line is recomputability, not volatility. Their argument
holds — volatility describes the two categories without partitioning
them, and every case it does not obviously cover becomes an argument at
exactly the boundary §6 exists to keep out of argument. The test is
§9.5's own determinism clause pointed where it had not been pointed.

Added one clause they did not propose, because their framing opens a
loophole: recomputability is assessed over the stated criteria, so a
criterion that dereferences a judgment is deterministic in form and
inferential in substance, and would put an opinion inside an engine
wearing a rule's clothes. A criterion MUST bottom out in evidence about
the subject, not in another party's conclusion about it. A recorded
judgment is evidence that the judgment was made, never that the thing
judged is so — the same distinction §9.6 draws about archives and
GH-DEC-2026-005 draws about valid_now.

All three kings-guard consequences carried, including the constraint they
volunteered against themselves (readiness is not an input to posture) and
their honest limit, which makes §17 load-bearing for the rule.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01WtJBr77gMFLrN93iEevqQJ

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 425128@bnt-lap001
Assistant-Session: f5944d8b-dac4-4e1a-87eb-8b3d8f314a63
This commit is contained in:
tegwick 2026-09-06 08:08:32 +02:00
parent cb9b0b80fc
commit 42e9bcc747
2 changed files with 132 additions and 4 deletions

View file

@ -785,3 +785,126 @@ decided_by: Bernd Worsch
created: '2026-09-06T06:07:34.017316Z'
updated: '2026-09-06T06:07:34.017316Z'
```
## Context
`GH-WP-0003-T04`. v0.7 §9.5 states the maturity half of the boundary — *"Given the
same criteria and the same evidence it MUST return the same level; that determinism
is what makes it an Engine rather than an opinion"*, and *"A criterion that cannot be
evaluated by rule is not yet a criterion."* It does not state the posture half.
Gate House had proposed drawing the line on volatility: posture is fast-moving,
maturity is slow. `kings-guard` answered `KG-IN-0003` with a proposed revision
(`KG-DEC-2026-002`, argued in `kings-guard/docs/PostureMaturityBoundary.md`) rejecting
that line and offering recomputability instead. The commentary was also sent to
`maturity-engine`.
The concern behind the original question stands and is why the line has to be exact:
a second grading authority would be the same shape of mistake as a second decision
point, and §6 says it would arrive the same way — gradually, each time for a good
local reason.
## Decision
**The boundary is recomputability, not volatility.**
> Given the same criteria and the same evidence, recompute. If you MUST get the same
> answer, it is maturity and it belongs in an engine. If you CANNOT promise the same
> answer, it is posture and it belongs in Staff.
The volatility line is withdrawn. `kings-guard`'s argument against it is accepted in
full: volatility is an observation about how a value has behaved, not a definition of
what it is. It fails at both edges — a maturity criterion moves fast when evidence
lands in a burst, and a posture sits unchanged for months on a healthy subject — and,
more seriously, it *describes* the two categories without *partitioning* them. Every
case it does not obviously cover becomes an argument, and arguments at a boundary are
the mechanism §6 exists to prevent.
Recomputability is not a new rule. It is §9.5's own determinism clause pointed at the
one boundary where it had not been pointed, which is why it can be adopted without
enlarging the standard. §9.5 already states the maturity half; the posture half is its
mirror, and the pair partitions: **a criterion that cannot be evaluated by rule is not
yet a criterion; a judgment that can be evaluated by rule is not posture — it is a
criterion sitting in the wrong repository.**
### The addition — criteria must be grounded
Adopted with one clause `kings-guard` did not propose, and the reason is the loophole
their own framing opens.
Recomputability is assessed **over the stated criteria**. That makes it mechanical,
which is its virtue, and it also makes it satisfiable in form by the thing it exists
to exclude. Any judgment can be made to look recomputable by writing a criterion that
dereferences it: *"level 2 iff the reviewer marked the control adequate"* is perfectly
deterministic — recompute it and you get the same answer every time — and it has
smuggled an opinion into an engine wearing a rule's clothes. The engine would then be
grading, deterministically, on someone's judgment, which is precisely the second
grading authority the boundary is drawn to prevent.
Therefore:
> **A criterion MUST bottom out in evidence about the subject, not in another party's
> conclusion about the subject.** A recorded judgment may be evidence *that the
> judgment was made* — a fact with an issuer and a timestamp. It MUST NOT be evidence
> *that the thing judged is so*.
This is the same distinction §9.6 draws between what an archive proves and what it is
read as proving, and the same one this repository applies to `valid_now` in
`GH-DEC-2026-005`: a summary predicate is a fact about the issuer's evaluation, not a
substitute for the evaluation. Without the clause the test is mechanical and
circumventable; with it, the test is mechanical and the circumvention is itself
checkable.
### Consequences carried
The three `kings-guard` names are adopted as stated.
1. **The migration direction is permanent.** Anything called posture that turns out to
be recomputable moves to `maturity-engine` as a criterion; anything in
`maturity-engine` that needs judgment is not yet a criterion and moves back to
Staff. The boundary maintains itself under change because the test applies to each
item rather than to the category.
2. **Two authorities cannot grade the same subject property**, because a property is
either recomputable or it is not, and that fact does not depend on which repository
claims it. The failure becomes structurally prevented rather than conventionally
avoided.
3. **Capability readiness MUST NOT be an input to posture.** Readiness is
deterministic; posture is not; feeding one into the other would make posture partly
recomputable and blur the boundary from the `kings-guard` side. Volunteered by
`kings-guard` as a constraint on itself and accepted as normative.
Consequence 3 also answers the second half of `KG-IN-0003`: tracking kings-guard's
own gaps in `maturity-engine` creates no incident-time dependency, because posture
evaluation never consults readiness. The dependency would exist only if the mistake
consequence 3 forbids had already been made.
### The limit is recorded, not resolved
`kings-guard` flagged, against its own proposal, that *"the same evidence"* is not
well defined anywhere in the estate, so until §17's request-claim and gap-record
schemas exist, recomputability is a thought experiment rather than a check. That is
recorded in the statute alongside the test rather than left in the commentary. A
boundary that is correct but not yet mechanically checkable does beat one that is
checkable and wrong — but a reader is entitled to know which of the two they are
holding. It makes §17 load-bearing for this rule.
The caution is also recorded: *"posture"* has the drift profile *"control plane"* had
— it sounds specific and quietly absorbs whatever sits next to it. §8 exists because
the estate has been bitten by exactly that, and this repository described itself as a
control plane before the re-cut. The recomputability test is a defence against that
drift because it can be applied to a candidate *before* the word is stretched to cover
it. `kings-guard` asked to be held to it rather than trusted about it, and that is the
standing it gets.
No change to §8's three-way split and no §4 catalog change. Posture stays
non-deterministic and stays Staff; the test explains why, which is what was missing.
## Reversal
Revert if the grounding clause proves to exclude criteria the estate needs — that is,
if a legitimate maturity criterion cannot be expressed without dereferencing a
judgment. The falsifier is a concrete criterion, not an argument that one might exist.
The likely candidates are human-attested controls (a policy was reviewed, a drill was
run); the expected resolution is that the *attestation event* is the evidence and the
criterion grades on its existence, freshness, and issuer rather than on its verdict.
If that resolution does not hold for some real criterion, this clause is wrong.

View file

@ -106,10 +106,15 @@ volatility describes the two things without partitioning them, and every case it
not obviously cover becomes an argument at exactly the boundary §6 says must not be
open to argument.
Assess and dispose. If adopted, it carries a constraint kings-guard has already
accepted — capability readiness MUST NOT be an input to posture — and an honest
limit: "the same evidence" is not yet well defined estate-wide, which makes §17
load-bearing for the test.
Disposed as `GH-DEC-2026-007`: **adopted**, with one added clause. Recomputability
is assessed over the stated criteria, so a criterion that dereferences a judgment
("level 2 iff the reviewer marked it adequate") is deterministic in form and
inferential in substance. A criterion MUST therefore bottom out in evidence about the
subject, not in another party's conclusion about it. All three kings-guard
consequences are carried, including the constraint they volunteered against
themselves — capability readiness MUST NOT be an input to posture — and their honest
limit, that "the same evidence" is undefined until §17, is recorded in the statute
beside the test rather than left in the commentary.
```task
id: GH-WP-0003-T05