Revise R3, rule the human-approver question, and correct A-16 and A-17

Four returns arrived overnight, two of them corrections to rules
written yesterday. Both corrections are right.

A-16 GAINS A RIDER. informed-decision pointed out the rule is silent on
who writes the route marker, and the guarantee is only as good as that
party's independence from what the marker asserts. Its own instance is
the weak one: erased versus never-held is written by the party the
evidence is about, so A-16 there reduces to a self-attestation and
GH-DEC-2026-014 section 4 narrows it without removing it. Without the
rider A-16 becomes the thing it exists to prevent — a sound check read
as establishing a property it does not carry. The four instances are
now graded by marker independence rather than listed as equals.

A-17 GAINS A PRECONDITION. It asks which way a case fails, which is
unanswerable where the case cannot be seen. Their commitment-only path
had no failure direction at all as proposed: a reviewer got a blank,
indistinguishable from erased, withheld, lost and never held.
GH-DEC-2026-014 section 4 did not test the direction of failure, it
manufactured one — the right outcome reached without noticing it was a
different operation. So making the distinguishing case observable is a
precondition of applying A-17, not an outcome of it, and A-17 therefore
depends on A-16. Neither dependency was noticed when both were written
a day apart.

GH-DEC-2026-015 revises GH-DEC-2026-012 R3. approval-engine recommended
exactly the option we refused, informed-decision could not comply with
both, changed nothing, and raised it as a finding rather than choosing
— having previously offered to let approval-engine settle R3 and
declined to take that route twice.

Nesting is permitted for this pair. The cycle objection needed mutual
containment and approval-engine's digest structurally excludes
presentation material for an independent reason. But the decisive
ground is that the original ruling worked against its own rule: R3
forbade recomputing the other layer's digest from one's own vocabulary,
and co-reference by identifier left informed-decision canonicalizing
principal and target, two of the five fields in that digest. Nesting
removes the duplication; co-reference manages it. We reached for the
management option while stating the rule that recommends removal.

Conditioned on approval-engine making the exclusion normative and
tested rather than intentional, because the cycle cannot arise here is
a belief and the cycle may not arise here is a rule with an owner —
A-17's precondition applied to our own permission. The ordering
objection is withdrawn as mistaken and the withdrawal is recorded: a
cost accepted from the requester and never checked is how a wrong
reason survives into a ruling.

GH-DEC-2026-016 rules NC-03, which both repositories referred up and
neither benefits from. Where an approval is declared as discharging a
human-in-the-loop control, the approver must be a human principal and
approval-engine must refuse at bind time rather than record it.
Recording the principal type is the auditable half and stops nothing;
an approval control satisfiable by the same class of actor it exists to
check is theatre. Scoped to declared approvals, declared at issue and
never inferred, on approval-engine's own pdp_path shape. One surface
enforcing it is not the property being held — the guarantee would read
as human-approved unless someone used a different client.

Section 5 leaves what makes a principal human to the identity layer and
notes it inherits A-16: refusing a service principal while accepting an
unverified assertion of humanity moves the defect rather than closing
it.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012viPor8WJNCbV64ipwewrm

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 1754332@bnt-lap001
Assistant-Session: 9c8ac536-ff5e-46a3-8ab1-a548bde25fc0
This commit is contained in:
tegwick 2026-09-10 15:21:29 +02:00
parent a5a1bcf537
commit 62c6399ddd
4 changed files with 402 additions and 6 deletions

View file

@ -560,7 +560,29 @@ Instances: `GH-DEC-2026-010` (a decision envelope reads identically whether
`access-engine` issued it or a responder forged it), `GH-DEC-2026-011` (`unknown`
versus `absent` in a stance map), `GH-DEC-2026-013` (a `tenant` claim
directory-asserted about the principal versus registration-supplied about the
client), `GH-DEC-2026-014` (*erased* versus *never held* on an evidence path).
client, and — `key-cape`'s own extension — a third route where nobody asserted a
zone and a profile default supplied it), `GH-DEC-2026-014` (*erased* versus
*never held* on an evidence path).
**Rider — who writes the marker.** A-16 is only as strong as the independence of
the party that writes the route marker from what the marker asserts. Where the
marker is written by the party whose conduct the route describes, **A-16
constrains a defect but not an adversary, and MUST NOT be read as establishing the
distinction against a compromised source.**
The four instances are not equally strong and the register should say so: a
signature by the issuer is independent of the party relying on it; a PEP labelling
its own input gains nothing by mislabelling; a tenant provenance written by the
issuer is independent of the consumer; and an *erased*-versus-*never-held* marker
written by the party the evidence is about is a **self-attestation**. The last
reduces to the residual `informed-decision` has twice been refused credit for
closing, and `GH-DEC-2026-014` §4 narrows it — non-production becomes attributable
— without removing it, because the attribution still rests on that party's own
marker.
Without this rider A-16 becomes the thing it exists to prevent: a sound check read
as establishing a property it does not carry. Raised by `informed-decision`
against its own instance, which is the weak one.
### A-17 — Fail-closed transitions
@ -573,13 +595,30 @@ length of the transition, but the direction of failure at the distinguishing
case. A promise that fails open is a permission; a promise that fails closed is a
gap.
**Precondition — the distinguishing case must be observable first.** A-17 asks
which way a case fails, and that question is unanswerable where the case cannot be
seen. **Where the distinguishing case is not observable, making it observable is a
precondition of applying A-17, not an outcome of it.** Otherwise A-17 admits
anything whose distinguishing case is merely invisible, which reads as failing
closed because nothing visibly fails.
**A-17 therefore depends on A-16.** One cannot ask which direction a case fails in
until the record can distinguish that case from its neighbours.
Instances: `GH-DEC-2026-011` (a dated transitional `unknown: fail_open` declined
— its distinguishing case is exactly where it fails open, so the transition
licenses the forbidden thing and dates it), `GH-DEC-2026-013` (a
registration-bound tenant granted — registration and directory disagreeing
refuses issuance rather than picking a winner), `GH-DEC-2026-014` (commitment-only
evidence granted — a reviewer who cannot obtain the content gets no
reconstruction rather than a wrong one).
evidence granted — but **only after** §4 made the case observable; as proposed it
had no failure direction at all, because a reviewer receiving a blank could not
tell *erased* from *withheld* from *lost* from *never held*).
The third instance is why the precondition is stated. `GH-DEC-2026-014` §4 did not
**test** the direction of failure; it **manufactured** one, by requiring an
existence assertion that turns non-production into a finding. That was the right
outcome reached without noticing it was a different operation from the one A-17
describes. Raised by `informed-decision`, from the instance it bears.
**A-16 and A-17 are newer than A-01…A-15 and are not yet estate doctrine.** They
are stated here because a property recorded only against the instance that