diff --git a/decisions/decisions.md b/decisions/decisions.md index 7b2c9dd..90fe484 100644 --- a/decisions/decisions.md +++ b/decisions/decisions.md @@ -785,3 +785,126 @@ decided_by: Bernd Worsch created: '2026-09-06T06:07:34.017316Z' updated: '2026-09-06T06:07:34.017316Z' ``` + +## Context + +`GH-WP-0003-T04`. v0.7 §9.5 states the maturity half of the boundary — *"Given the +same criteria and the same evidence it MUST return the same level; that determinism +is what makes it an Engine rather than an opinion"*, and *"A criterion that cannot be +evaluated by rule is not yet a criterion."* It does not state the posture half. + +Gate House had proposed drawing the line on volatility: posture is fast-moving, +maturity is slow. `kings-guard` answered `KG-IN-0003` with a proposed revision +(`KG-DEC-2026-002`, argued in `kings-guard/docs/PostureMaturityBoundary.md`) rejecting +that line and offering recomputability instead. The commentary was also sent to +`maturity-engine`. + +The concern behind the original question stands and is why the line has to be exact: +a second grading authority would be the same shape of mistake as a second decision +point, and §6 says it would arrive the same way — gradually, each time for a good +local reason. + +## Decision + +**The boundary is recomputability, not volatility.** + +> Given the same criteria and the same evidence, recompute. If you MUST get the same +> answer, it is maturity and it belongs in an engine. If you CANNOT promise the same +> answer, it is posture and it belongs in Staff. + +The volatility line is withdrawn. `kings-guard`'s argument against it is accepted in +full: volatility is an observation about how a value has behaved, not a definition of +what it is. It fails at both edges — a maturity criterion moves fast when evidence +lands in a burst, and a posture sits unchanged for months on a healthy subject — and, +more seriously, it *describes* the two categories without *partitioning* them. Every +case it does not obviously cover becomes an argument, and arguments at a boundary are +the mechanism §6 exists to prevent. + +Recomputability is not a new rule. It is §9.5's own determinism clause pointed at the +one boundary where it had not been pointed, which is why it can be adopted without +enlarging the standard. §9.5 already states the maturity half; the posture half is its +mirror, and the pair partitions: **a criterion that cannot be evaluated by rule is not +yet a criterion; a judgment that can be evaluated by rule is not posture — it is a +criterion sitting in the wrong repository.** + +### The addition — criteria must be grounded + +Adopted with one clause `kings-guard` did not propose, and the reason is the loophole +their own framing opens. + +Recomputability is assessed **over the stated criteria**. That makes it mechanical, +which is its virtue, and it also makes it satisfiable in form by the thing it exists +to exclude. Any judgment can be made to look recomputable by writing a criterion that +dereferences it: *"level 2 iff the reviewer marked the control adequate"* is perfectly +deterministic — recompute it and you get the same answer every time — and it has +smuggled an opinion into an engine wearing a rule's clothes. The engine would then be +grading, deterministically, on someone's judgment, which is precisely the second +grading authority the boundary is drawn to prevent. + +Therefore: + +> **A criterion MUST bottom out in evidence about the subject, not in another party's +> conclusion about the subject.** A recorded judgment may be evidence *that the +> judgment was made* — a fact with an issuer and a timestamp. It MUST NOT be evidence +> *that the thing judged is so*. + +This is the same distinction §9.6 draws between what an archive proves and what it is +read as proving, and the same one this repository applies to `valid_now` in +`GH-DEC-2026-005`: a summary predicate is a fact about the issuer's evaluation, not a +substitute for the evaluation. Without the clause the test is mechanical and +circumventable; with it, the test is mechanical and the circumvention is itself +checkable. + +### Consequences carried + +The three `kings-guard` names are adopted as stated. + +1. **The migration direction is permanent.** Anything called posture that turns out to + be recomputable moves to `maturity-engine` as a criterion; anything in + `maturity-engine` that needs judgment is not yet a criterion and moves back to + Staff. The boundary maintains itself under change because the test applies to each + item rather than to the category. +2. **Two authorities cannot grade the same subject property**, because a property is + either recomputable or it is not, and that fact does not depend on which repository + claims it. The failure becomes structurally prevented rather than conventionally + avoided. +3. **Capability readiness MUST NOT be an input to posture.** Readiness is + deterministic; posture is not; feeding one into the other would make posture partly + recomputable and blur the boundary from the `kings-guard` side. Volunteered by + `kings-guard` as a constraint on itself and accepted as normative. + +Consequence 3 also answers the second half of `KG-IN-0003`: tracking kings-guard's +own gaps in `maturity-engine` creates no incident-time dependency, because posture +evaluation never consults readiness. The dependency would exist only if the mistake +consequence 3 forbids had already been made. + +### The limit is recorded, not resolved + +`kings-guard` flagged, against its own proposal, that *"the same evidence"* is not +well defined anywhere in the estate, so until §17's request-claim and gap-record +schemas exist, recomputability is a thought experiment rather than a check. That is +recorded in the statute alongside the test rather than left in the commentary. A +boundary that is correct but not yet mechanically checkable does beat one that is +checkable and wrong — but a reader is entitled to know which of the two they are +holding. It makes §17 load-bearing for this rule. + +The caution is also recorded: *"posture"* has the drift profile *"control plane"* had +— it sounds specific and quietly absorbs whatever sits next to it. §8 exists because +the estate has been bitten by exactly that, and this repository described itself as a +control plane before the re-cut. The recomputability test is a defence against that +drift because it can be applied to a candidate *before* the word is stretched to cover +it. `kings-guard` asked to be held to it rather than trusted about it, and that is the +standing it gets. + +No change to §8's three-way split and no §4 catalog change. Posture stays +non-deterministic and stays Staff; the test explains why, which is what was missing. + +## Reversal + +Revert if the grounding clause proves to exclude criteria the estate needs — that is, +if a legitimate maturity criterion cannot be expressed without dereferencing a +judgment. The falsifier is a concrete criterion, not an argument that one might exist. +The likely candidates are human-attested controls (a policy was reviewed, a drill was +run); the expected resolution is that the *attestation event* is the evidence and the +criterion grades on its existence, freshness, and issuer rather than on its verdict. +If that resolution does not hold for some real criterion, this clause is wrong. diff --git a/workplans/GH-WP-0003-statute-v08-amendment-set.md b/workplans/GH-WP-0003-statute-v08-amendment-set.md index cee5c94..19ec79f 100644 --- a/workplans/GH-WP-0003-statute-v08-amendment-set.md +++ b/workplans/GH-WP-0003-statute-v08-amendment-set.md @@ -106,10 +106,15 @@ volatility describes the two things without partitioning them, and every case it not obviously cover becomes an argument at exactly the boundary §6 says must not be open to argument. -Assess and dispose. If adopted, it carries a constraint kings-guard has already -accepted — capability readiness MUST NOT be an input to posture — and an honest -limit: "the same evidence" is not yet well defined estate-wide, which makes §17 -load-bearing for the test. +Disposed as `GH-DEC-2026-007`: **adopted**, with one added clause. Recomputability +is assessed over the stated criteria, so a criterion that dereferences a judgment +("level 2 iff the reviewer marked it adequate") is deterministic in form and +inferential in substance. A criterion MUST therefore bottom out in evidence about the +subject, not in another party's conclusion about it. All three kings-guard +consequences are carried, including the constraint they volunteered against +themselves — capability readiness MUST NOT be an input to posture — and their honest +limit, that "the same evidence" is undefined until §17, is recorded in the statute +beside the test rather than left in the commentary. ```task id: GH-WP-0003-T05