diff --git a/decisions/decisions.md b/decisions/decisions.md index 650266b..dde72b4 100644 --- a/decisions/decisions.md +++ b/decisions/decisions.md @@ -2015,6 +2015,39 @@ It is `unknown` and `absent` again, in the identity layer. under §2 today. What must not happen is the path being described as validated while a consumer cannot see which fact it is relying on. +### 6. `informed-decision`'s argument for registration-bound, answered + +`INFD-IN-0002` arrived after this record was written, arguing for the registration-bound +resolution on a ground `key-cape` did not raise. `informed-decision`'s object model +separates a **pre-sign binding slice** — which commits which identity and which +scope/tenant is being entered — from awareness material shown but never signed. Under +registration-bound, it argues, the tenant is a property of the surface and its +registration, which is exactly what the binding slice commits; under directory-sourced it +describes the person, which sits closer to awareness than to binding. + +**The argument is accepted, and it does not change §1. It sharpens the defect.** + +What `informed-decision` describes is a real fact that deserves to be committed: *which +scope is this act being entered into*. That is a property of the **act**. It is not the +same fact as *which tenant is this person a member of*, which is a property of the +**principal** and is what `approval-engine` exact-matches to admit an approver. + +The trouble is that one claim named `tenant` is being asked to carry both. That is why +the registration-bound shape feels correct to `informed-decision` and wrong to the +identity layer: each is looking at a different fact through the same field. A binding +slice that must commit the scope being entered should **commit that scope**, not borrow +the principal's membership claim to stand in for it. + +So `informed-decision` is right that its binding needs the fact, right that the fact is +act-scoped rather than person-scoped, and wrong that this makes the principal's `tenant` +claim the place to put it. Its argument is the best available evidence that §5's +provenance requirement is necessary: two facts sharing one field is exactly the condition +under which a consumer cannot tell what it is relying on. + +This record does not design the second field. Whether the act-scope commitment is a +separate claim, part of the binding document, or something the request-claim schema +carries when §17 finds it an owner, is not doctrine and is not settled here. + ## What this does not rule Not ruled: whether `approval-engine`'s exact-match admission is the right gate, which is @@ -2044,3 +2077,184 @@ Relayed by `informed-decision` while asking about its own registration — a rep passing on a question that was not its to carry. `GH-DEC-2026-011`'s decline and this record's grant are the two halves of §3, which neither request asked for and which is the part of this record most likely to matter later. + +## GH-DEC-2026-014 — A commitment-only evidence record satisfies non-alteration, never reconstructability, and its erasure must be detectable + +```yaml +id: GH-DEC-2026-014 +kind: decision +title: A commitment-only evidence record satisfies non-alteration, never reconstructability, + and its erasure must be detectable +status: resolved +owner: Bernd Worsch +repo: gate-house +standard: net-kingdom/canon/standards/security-layer-model_v0.8.md +source_note: informed-decision INFD-IN-0003 +requested_dispositions: +- approved +- revised +- rejected +affects: +- gate-house +- informed-decision +- audit-core +- approval-engine +- net-kingdom +decided_by: Bernd Worsch +rationale: 'informed-decision asked what travels on the independent evidence path + that GH-DEC-2026-012 limit 3 requires, proposing commitment-only for stage 1 rather + than the full binding document, because the binding document carries commercial + and personal material that would enter the audit fabric under retention and export + entitlements designed for audit events. The payload schema and its retention are + audit-core custody and are not ruled here. Two things are doctrine. First, a commitment-only + record satisfies non-alteration and never reconstructability, and MUST NOT be described + as satisfying the second; this is the existing bound that an archive proves records + were not altered or truncated after arrival and never that one was never sent, applied + to a record that additionally does not carry what it commits to. Second, the gap + commitment-only leaves is availability rather than integrity, and it sits with the + actor being audited, so erasure or non-production of the committed content MUST + be detectable as a finding rather than present as an unremarkable absence. The independent + path therefore carries a declaration that content exists and where custody sits, + so that absence at retrieval is a conformance failure. Commitment-only is admissible + on the GH-DEC-2026-013 test because its distinguishing case fails closed: a reviewer + who cannot obtain the content gets no reconstruction rather than a wrong one. informed-decision + refusal of a separate evidence store is endorsed, on its own ground that it would + route around the section 16 archival-custody question by building a parallel archive + under another name.' +created: '2026-09-09T21:23:46.190170Z' +updated: '2026-09-09T21:23:46.190170Z' +``` + +## Context + +`GH-DEC-2026-012` limit 3 requires the evidence copy of a presentation record to reach +`audit-core` **independently of the emitter**, because in `informed-decision`'s case the +actor being audited and the evidence source are the same component. `INFD-IN-0003` asks +what travels on that path. + +The candidate it rejects is emitting the **full binding document**, which would put +commercial and personal material — at L4, contract text — into the audit fabric under +retention and export entitlements designed for audit events. That objection is sound and +is not merely operational: an evidence path that forces content into a custody regime +built for a different class of data is a defect in the evidence path, not a cost of using +it. + +It proposes **commitment-only** for Stage 1: hashes, principal, timestamps, +acknowledgements, co-referenced approval id, disposition verb, stance application. It +declares plainly that this leaves it able to **erase** the content, and asks not to be +credited with closing that. + +It also refused a third option on its own initiative — a separate evidence store — on +the ground that it has no owner and would route around §16's open question on stronger +archival custody by building a parallel archive under another name. + +## What is ruled here, and what is not + +**Not ruled: the payload.** Which fields travel, in what schema, under what retention, is +`audit-core`'s custody question and it has it. This record does not design the record. + +**Ruled: what may be claimed from a record of that shape, and what must remain visible +when it fails.** That is doctrine because it governs what a later reader is entitled to +conclude, and a reader's entitlement is not a custody decision. + +## Decision + +### 1. Commitment-only is admissible for Stage 1 + +Granted, on `GH-DEC-2026-013` §3's test: **its distinguishing case fails closed.** Where +the committed content is needed and cannot be obtained, a reviewer gets *no +reconstruction* rather than a *wrong* one. The record does not produce a confident +answer built on material nobody can check. Compare the shape refused there — a +transitional state that fails open on the case that distinguishes it is a permission +wearing a date. + +The data-protection reason is accepted as a reason of the right kind. Forcing L4 contract +text into an audit fabric to satisfy an evidence obligation would trade one control for a +breach of another, and doctrine that produces that trade is wrong rather than merely +expensive. + +### 2. It satisfies non-alteration. It does not satisfy reconstructability, and MUST NOT be described as doing so + +This repository already holds that **an archive proves records were not altered or +truncated after arrival, never that one was never sent.** A commitment-only record is +weaker again: it additionally does not carry what it commits to. So it establishes that +the *commitment* was made when it says and has not changed since. It establishes nothing +about what was committed to, except conditionally — *if* a document is later produced, +whether it is the one. + +**A commitment-only record MUST NOT be described as satisfying reconstructability**, in +`informed-decision`'s documents, in `audit-core`'s, or in any conformance claim. Every +privileged action being reconstructable from the evidence is a property of the estate's +audit obligation; a hash of an absent document does not have it and no amount of +integrity on the hash supplies it. + +This is the same discipline the §6.4 obligation-1 gap has: the check is sound, and the +property a reader infers from it is not present unless it is stated to be absent. + +### 3. The gap is availability, not integrity — and it sits with the audited party + +Say it in those words, because "we can erase the content" understates where the problem +is. Commitment-only moves **integrity** out of the emitter's control and leaves +**availability** entirely inside it. The party that can withhold the content is the party +the evidence is about. + +That is precisely the condition limit 3 exists to prevent, reduced but not removed. The +reduction is real — the emitter can no longer alter the record, which is the more common +failure — and it is not sufficient on its own. + +### 4. Non-production MUST be detectable as a finding, not present as an absence + +**This is the condition that makes §1's grant safe, and it is the part `INFD-IN-0003` did +not propose.** + +If the independent path holds only a commitment, a reviewer who asks for the content and +receives nothing cannot distinguish *erased*, *withheld*, *lost*, and *never held*. The +absence reads as an unremarkable blank rather than as evidence of anything. + +The independent path MUST therefore carry, alongside the commitment, **a declaration that +committed content exists and where custody sits**, such that failure to produce it at +retrieval is a **conformance failure** attributable to the custodian rather than a silent +gap in the record. A commitment with no accompanying assertion that something is being +committed to is indistinguishable from a commitment to nothing. + +This is `GH-DEC-2026-011` §3's rule in its third setting: two states, one observable +appearance, and the record must distinguish them. There it was `unknown` versus `absent` +in a stance map; in `GH-DEC-2026-013` §5 it was directory-asserted versus +registration-supplied in an identity claim; here it is *erased* versus *never held* in an +evidence path. The recurrence is the point — wherever a system can reach one appearance +by two routes, the record must say which route, or the safer reading of the appearance +becomes unavailable to everyone. + +### 5. The refusal of a separate evidence store is endorsed + +`informed-decision` refused it on the ground that it has no owner and would route around +§16's archival-custody question by building a parallel archive under another name. That +reasoning is correct and we would keep it as written. + +Add one thing to it: an evidence store owned by the party whose conduct it evidences is +not an evidence store, whatever its integrity properties. The ownership objection is +prior to the custody one. + +### 6. The residual is not closed and is not credited + +`informed-decision` asked, again, not to be credited with closing what it has not closed. +Honoured, again. The erasure gap stands alongside the compromised-surface residual from +`GH-DEC-2026-012`, and §4 narrows the first without closing it: a detectable +non-production tells a reviewer that something is missing and who owed it. It does not +produce the missing thing. + +## Reversal condition + +§1 reverses if commitment-only is found to be load-bearing for a reconstruction that +actually had to be performed and could not be — i.e. if the availability gap is realised +rather than theorised. Stage 1 is a stage; the burden is on the shape to keep earning it. + +§4 is not a reversal candidate. If it turns out to be expensive, the answer is a cheaper +mechanism for the same property, never the property's removal. + +## Provenance + +Raised by `informed-decision` (`INFD-IN-0003`), which proposed the shape, declared the +gap it leaves, refused a third option against its own convenience, and asked which half +of the question was doctrine. The half that was is ruled here; the payload is +`audit-core`'s and it has it. §4 was not requested by anyone.