Revise R3, rule the human-approver question, and correct A-16 and A-17
Four returns arrived overnight, two of them corrections to rules written yesterday. Both corrections are right. A-16 GAINS A RIDER. informed-decision pointed out the rule is silent on who writes the route marker, and the guarantee is only as good as that party's independence from what the marker asserts. Its own instance is the weak one: erased versus never-held is written by the party the evidence is about, so A-16 there reduces to a self-attestation and GH-DEC-2026-014 section 4 narrows it without removing it. Without the rider A-16 becomes the thing it exists to prevent — a sound check read as establishing a property it does not carry. The four instances are now graded by marker independence rather than listed as equals. A-17 GAINS A PRECONDITION. It asks which way a case fails, which is unanswerable where the case cannot be seen. Their commitment-only path had no failure direction at all as proposed: a reviewer got a blank, indistinguishable from erased, withheld, lost and never held. GH-DEC-2026-014 section 4 did not test the direction of failure, it manufactured one — the right outcome reached without noticing it was a different operation. So making the distinguishing case observable is a precondition of applying A-17, not an outcome of it, and A-17 therefore depends on A-16. Neither dependency was noticed when both were written a day apart. GH-DEC-2026-015 revises GH-DEC-2026-012 R3. approval-engine recommended exactly the option we refused, informed-decision could not comply with both, changed nothing, and raised it as a finding rather than choosing — having previously offered to let approval-engine settle R3 and declined to take that route twice. Nesting is permitted for this pair. The cycle objection needed mutual containment and approval-engine's digest structurally excludes presentation material for an independent reason. But the decisive ground is that the original ruling worked against its own rule: R3 forbade recomputing the other layer's digest from one's own vocabulary, and co-reference by identifier left informed-decision canonicalizing principal and target, two of the five fields in that digest. Nesting removes the duplication; co-reference manages it. We reached for the management option while stating the rule that recommends removal. Conditioned on approval-engine making the exclusion normative and tested rather than intentional, because the cycle cannot arise here is a belief and the cycle may not arise here is a rule with an owner — A-17's precondition applied to our own permission. The ordering objection is withdrawn as mistaken and the withdrawal is recorded: a cost accepted from the requester and never checked is how a wrong reason survives into a ruling. GH-DEC-2026-016 rules NC-03, which both repositories referred up and neither benefits from. Where an approval is declared as discharging a human-in-the-loop control, the approver must be a human principal and approval-engine must refuse at bind time rather than record it. Recording the principal type is the auditable half and stops nothing; an approval control satisfiable by the same class of actor it exists to check is theatre. Scoped to declared approvals, declared at issue and never inferred, on approval-engine's own pdp_path shape. One surface enforcing it is not the property being held — the guarantee would read as human-approved unless someone used a different client. Section 5 leaves what makes a principal human to the identity layer and notes it inherits A-16: refusing a service principal while accepting an unverified assertion of humanity moves the defect rather than closing it. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_012viPor8WJNCbV64ipwewrm Assistant: claude-code Assistant-Model: opus Assistant-Process: 1754332@bnt-lap001 Assistant-Session: 9c8ac536-ff5e-46a3-8ab1-a548bde25fc0
This commit is contained in:
parent
a5a1bcf537
commit
62c6399ddd
4 changed files with 402 additions and 6 deletions
18
INTENT.md
18
INTENT.md
|
|
@ -302,8 +302,8 @@ engines and Staff repositories implement them.
|
|||
13. **Audit evidence is protected from the actor being audited.**
|
||||
14. **Failure of critical policy or authorization dependencies fails closed.**
|
||||
15. **Production guarantees must survive incorrect agent behavior.**
|
||||
16. **Where one appearance is reachable by two routes, the record says which route.**
|
||||
17. **A transitional deviation is admissible only where it fails closed on the case that distinguishes it from the conformant state.**
|
||||
16. **Where one appearance is reachable by two routes, the record says which route** — and A-16 is only as strong as the marker-writer's independence from what the marker asserts.
|
||||
17. **A transitional deviation is admissible only where it fails closed on the case that distinguishes it from the conformant state** — and where that case is not observable, making it observable is a precondition rather than an outcome.
|
||||
|
||||
**On rules 16 and 17, which are newer than the rest.** Both were derived in
|
||||
September 2026 from rulings that kept arriving at the same shape, and they are
|
||||
|
|
@ -324,6 +324,12 @@ that the two routes must behave differently — usually they must behave identic
|
|||
and safely. It is that the **record** must distinguish them, or the safer reading of
|
||||
the appearance becomes unavailable to every later reader.
|
||||
|
||||
**The rider matters as much as the rule.** Where the route marker is written by the
|
||||
party whose conduct the route describes, rule 16 constrains a defect but not an
|
||||
adversary. `informed-decision` raised this against its own instance — the weakest
|
||||
of the four, an *erased*-versus-*never-held* marker written by the party the
|
||||
evidence is about — and it is the difference between a rule and a reassurance.
|
||||
|
||||
**Rule 17** governs what may enter a declared-gap register. It exists because two
|
||||
requests for transitional relief arrived in one week and had to be answered
|
||||
oppositely without the answers looking arbitrary: `ops-warden`'s dated transitional
|
||||
|
|
@ -334,6 +340,14 @@ which way it fails on the case that separates it from the conformant state. A
|
|||
promise that fails open is a permission; a promise that fails closed is a gap; only
|
||||
the second is a thing a register can hold.
|
||||
|
||||
**Rule 17 depends on rule 16**, which was not noticed when either was written. The
|
||||
question *"which way does it fail"* is unanswerable where the case cannot be seen,
|
||||
so an unobservable distinguishing case must be made observable before rule 17 is
|
||||
applied at all — otherwise the rule admits anything merely invisible, which reads
|
||||
as failing closed because nothing visibly fails. Raised by `informed-decision`
|
||||
from the instance it bears, which is also the instance where this repository
|
||||
manufactured a failure direction while believing it had tested one.
|
||||
|
||||
Neither rule has graduated to `net-kingdom/canon/standards/`. They are Gate House
|
||||
doctrine at repository level until they have been argued by a repository that bears
|
||||
a cost under them — which is how `security-layer-model` earned its acceptance and is
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue