Two follow-ons from informed-decision, both asking whether the item was
doctrine or implementation. One was already ruled; the other splits.
GH-DEC-2026-013 gains a section 6. INFD-IN-0002 argued for
registration-bound on a ground key-cape did not raise: their pre-sign
binding slice commits which scope is being entered, so a tenant that is
a property of the surface matches what the binding commits, while a
person-property sits closer to awareness. The argument is accepted and
it does not change the ruling — it sharpens the defect. What they
describe is a real fact deserving commitment: which scope this act
enters. That is a property of the act, not of the principal, and it is
not the fact approval-engine exact-matches to admit an approver. One
claim named tenant is carrying two facts, which is why the shape feels
right to them and wrong to the identity layer. A binding slice that
must commit the scope entered should commit that scope rather than
borrow the principal's membership claim. Their argument is the best
evidence yet that section 5's provenance requirement is necessary.
GH-DEC-2026-014 rules the doctrine half of INFD-IN-0003 and hands the
rest to audit-core. Commitment-only is admissible for stage 1, on
GH-DEC-2026-013's own test: a reviewer who cannot obtain the content
gets no reconstruction rather than a wrong one. Their data-protection
reason is accepted as a reason of the right kind — doctrine that forces
L4 contract text into an audit fabric to satisfy an evidence obligation
is wrong rather than merely expensive.
Two limits. A commitment-only record satisfies non-alteration and never
reconstructability, and must not be described as satisfying it; this is
our existing bound applied to a record that additionally does not carry
what it commits to. And the gap it leaves is availability rather than
integrity, sitting with the audited party — so non-production must be
detectable as a finding rather than present as an absence. That last is
section 4 and nobody asked for it: a reviewer receiving nothing cannot
otherwise tell erased from withheld from never held.
That makes three settings now for one rule — unknown versus absent in a
stance map, directory-asserted versus registration-supplied in an
identity claim, erased versus never held in an evidence path. Wherever
a system reaches one appearance by two routes, the record must say
which route or the safer reading becomes unavailable to everyone.
Their refusal of a separate evidence store is endorsed, with one
addition: an evidence store owned by the party whose conduct it
evidences is not an evidence store, whatever its integrity properties.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012viPor8WJNCbV64ipwewrm
Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 1754332@bnt-lap001
Assistant-Session: 9c8ac536-ff5e-46a3-8ab1-a548bde25fc0
key-cape has no adapter populating the directory user tenant, so every
human token fell back to the default and approval-engine refused it by
exact match — presenting as a failed approval rather than as a
registration defect. It built a registration-bound resolution, then
declined to ratify its own design because the second option writes a
cross-tenant capability into the issuer. That reading was right and the
question is ours: what may be a source of a principal's identity is a
Core Rule, not a runbook.
Directory-sourced is the terminal state. A registration is a statement
about the actor; a tenant is a property of the principal; sourcing the
second from the first collapses two identities the estate keeps
distinct, in the direction that widens.
The registration-bound shape is admissible anyway, as a declared
bounded gap, and the reason is not that the design is careful. It is
that the case distinguishing it from the correct resolution fails
closed: where registration and directory disagree, issuance is refused
rather than resolved either way. And the same code turns from supplying
the zone into enforcing agreement with it the moment the directory
carries tenants, so it converges by subtraction.
That general property is section 3 and neither request asked for it.
A transitional shape is admissible where it fails closed on exactly the
case that distinguishes it from the correct resolution, and
inadmissible where it fails open there. It is section 8's asymmetry
applied to transitions, and it is what makes this grant and
GH-DEC-2026-011's decline one rule rather than two defensible calls: a
promise that fails open is a permission, a promise that fails closed is
a gap, and only the second is a thing a register can hold.
Two conditions strengthen what key-cape wrote about itself. Refusal on
disagreement is normative, including against a future change that
prefers the directory — picking any winner converts a refusal into a
silent cross-tenant assertion. And lifting the dynamic-registration
exclusion voids the rule rather than reopening it; key-cape wrote "must
be revisited", which implies the answer might survive review, and it
would not.
The finding they did not ask for is section 5. The tenant claim is a
bare string, so a consumer cannot tell a tenant the directory asserted
about the person from one a registration supplied about the client they
came through. approval-engine exact-matches that string and is relying
on the second while its contract reads as the first. That is
GH-DEC-2026-010 one layer down — a sound check whose reader infers a
property it does not carry. The claim must carry its provenance;
the mechanism is key-cape's.
Gap registered at net-kingdom@f9e1611.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012viPor8WJNCbV64ipwewrm
Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 1754332@bnt-lap001
Assistant-Session: 9c8ac536-ff5e-46a3-8ab1-a548bde25fc0
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012viPor8WJNCbV64ipwewrm
Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 1754332@bnt-lap001
Assistant-Session: 9c8ac536-ff5e-46a3-8ab1-a548bde25fc0
Updated by fix-consistency on 2026-09-09:
- update .custodian-brief.md for gate-house
Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 1754332@bnt-lap001
Assistant-Session: 9c8ac536-ff5e-46a3-8ab1-a548bde25fc0
informed-decision filed three rulings before writing any architecture,
with candidate answers, their costs, the self-dealing objection argued
against itself, and a list of what it was not asking for. That order is
what section 17 exists to produce, and KEY-WP-0013-T02 is blocked today,
so it is answered now rather than queued.
R1 — PEP-shaped, confirmed as proposed, not an Engine. It holds no
state another layer reads at runtime for a verdict, which is the test.
Its layer stays its own to declare; this settles its shape, which is
what was blocking. It should build to v0.8's obligation 3 rather than
v0.7's and inherit GH-DEC-2026-010's attribution gap knowingly rather
than describe its validation as complete.
R2 — yes, and no second catalog row. PEP and PIP are shapes a
repository has; the catalog records layers it occupies. Obligation 5
forbids a PIP republishing the PDP's decision, which is a prohibition
on republishing a decision, not on holding two shapes. Three limits
carry the permission: the claim carries presentation and nothing else,
it must never be an input to the decision it presents for, and its
evidence copy reaches audit-core independently of the emitter. The last
is the one that matters here, because the actor and the source are the
same component.
R3 — candidate (b). The binding digest is authoritative for what the
request is; view_hash only for what was shown; a disagreement between
them is a finding against the presenting surface, never a fact about
the request. (a) is refused doctrinally rather than on the cost given:
merging the two makes one repository the authority on what another
layer computes over a request, which is GH-DEC-2026-008's objection to
translation. (c) is refused because nesting the binding digest inside
view_hash reproduces the hash cycle that made GH-DEC-2026-008
unimplementable — we paid for that lesson once this quarter. The two
link by co-reference instead: the presentation record names the binding
identifier and never recomputes the other layer's digest.
The residual is not closed and the ruling says so, as they asked. A
compromised surface can present X and attest Y. Attestation covers
accident and later tampering, never a compromised source — the same
disposition approval-engine's equivalent takes.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012viPor8WJNCbV64ipwewrm
Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 1754332@bnt-lap001
Assistant-Session: 9c8ac536-ff5e-46a3-8ab1-a548bde25fc0
Updated by fix-consistency on 2026-09-09:
- update .custodian-brief.md for gate-house
Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 1754332@bnt-lap001
Assistant-Session: 9c8ac536-ff5e-46a3-8ab1-a548bde25fc0
Four repositories returned text reviews. Every substantive finding was
about a rule that read as satisfied by a check that did not satisfy it,
which is the failure mode this repo is structurally prone to: doctrine
is graded on whether it is right and consumed on whether it is
checkable, and only the implementers can tell those apart.
GH-DEC-2026-010 — attribution is not identity. Obligation 1 said a PEP
must hold a decision from access-engine; obligation 2 supplied a digest
test emphatic that it was mechanical rather than a matter of judgement.
That test establishes which request a decision is for and nothing about
who issued it, and it cannot: every input to it is either sent by the
caller or published, so a responder knowing a published package id and
version returns a well-formed allow. Fail-closed protects against a
decision point that is absent, not against one that lies. Section 9.4
required authenticated entries of the approval object and nothing
required it of the decision, so obligation 5 was written over a pair a
PEP could only half validate. The mechanism is access-engine's under
section 17 and it is not the standard's to choose, so the condition is
a declared section 13 gap rather than a rule invented here. Raised by
access-engine against its own artifact, which had already recorded it
as its own defect before reading our text.
GH-DEC-2026-011 — ops-warden assented to GH-DEC-2026-009 on the
falsifier's own terms, went looking for the section 5.1 escape hatch
the reversal clause predicted, and reported it does not have one. Then
it priced adoption: 0 of 3 signing targets and 3 of 21 routing lanes
resolve to a zone, so the cell adopted today fails closed on nearly
every certificate it issues whenever the engine is unreachable —
including the continuity path an operator needs to repair that
unreachability. Its ask for a dated transitional unknown: fail_open is
declined; it is indistinguishable at runtime from the stance the rule
forbids and would make the rule optional at the only moment it costs
anything. Its second preference is adopted instead: 13.1 records a
dated coverage figure beside each stance, so a strict consumer and an
unclassified one stop reading alike. Coverage is disclosure and does
not soften the stance — the record says so, and says what would make
the column come out again.
The round record is closed and carries the rest: totality by catch-all,
absent versus unknown (closing the section 16 question this version
opened), the drift test promoted to MUST, ops-mason marked, and
approval-engine's four editorial-but-load-bearing findings. Its own
finding ids are used rather than renumbered.
kings-guard and audit-core did not return a review. Section 14 records
that as not claimed rather than counting silence as assent, and names
the sections that therefore carry no assent from the repository best
placed to test them.
Standard amended at net-kingdom@64394e9; it stays proposed, and
publication and the acceptance flip are net-kingdom's.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012viPor8WJNCbV64ipwewrm
Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 1754332@bnt-lap001
Assistant-Session: 9c8ac536-ff5e-46a3-8ab1-a548bde25fc0
Four findings returned so far, all from access-engine and
approval-engine. F1 is the serious one: GH-DEC-2026-008 as written
mandated a comparison that could never pass, because a claim travelling
inside a hashed request cannot name the digest of the request containing
it. A fail-closed consumer obeying it would have denied destroy
permanently — the ruling and its own fail-closed requirement compounded
rather than cancelled.
Ruling and its four obligations stand; the comparison target is corrected
to the PDP's published exclusion-scoped digest, verified in flex-auth's
schema and canonical.go before amending. A consumer must not guess the
exclusion rule, and until a PDP publishes one the path is fail-closed
rather than complete.
F2 adds the general property access-engine flagged as a near miss it was
not asking to have written: an evidence-bearing input may be excluded
from a correspondence digest but never from the replay identity.
The round record notes what this says about the process. GH-DEC-2026-008
was correct in substance, argued from doctrine, and verified against
another repository's schema before issue — and none of that caught a
defect three repositories found within hours of building on it.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01WtJBr77gMFLrN93iEevqQJ
Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 425128@bnt-lap001
Assistant-Session: f5944d8b-dac4-4e1a-87eb-8b3d8f314a63
The cut is at net-kingdom@66eeaba as status: proposed. All eight
amendments applied, with a §15 change-log entry, a §1 "what changed", a
§16 reconciliation closing two questions and opening one, and a rewritten
§14. Section numbering unchanged.
§14 no longer claims acceptance on the owner's decision. Ten of eleven
changes were requested by another repository and seven by a repository
arguing against its own interest, but this version imposes costs on named
repositories — ops-warden's unknown cell, approval-engine's issue-time
digest — and a cost imposed without a review round is what §12 exists to
catch late. So it circulates first.
The amendment set stays as the per-amendment argument; the cut is the
text under review. v0.7 remains accepted and unpatched.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01WtJBr77gMFLrN93iEevqQJ
Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 425128@bnt-lap001
Assistant-Session: f5944d8b-dac4-4e1a-87eb-8b3d8f314a63
The summary-for-body pattern reached six instances in four repositories
in one week. approval-engine escalated it with a concrete split: the half
that is mechanically checkable and the half that is doctrine.
§11 gains an example-validates-against-schema check, with the clause that
matters most — where a field is optional but load-bearing, examples must
cover both its presence and its absence. That clause is instance six:
approval-engine's own claim examples omitted pdp_digest and contradicted
its schema, found while implementing GH-DEC-2026-008, by the repository
making the argument. An example set that silently omits an optional field
teaches every reader the field does not exist.
§12 gains the convention half, which no test can cover: derivatives
marked with source and derivation version, and dated review records
marked as status-as-of-date rather than current state.
The tally is recorded in full because it is the argument. Four of six
were self-reported and one was committed by the proposer, so the case is
that the publishing shape makes the error the default — not that four
repositories were careless. A control depending on repositories
volunteering corrections is not a control.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01WtJBr77gMFLrN93iEevqQJ
Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 425128@bnt-lap001
Assistant-Session: f5944d8b-dac4-4e1a-87eb-8b3d8f314a63
access-engine exercised the divergence capability it claimed in the v0.6
round, on the first occasion §13.1 held two rows. ops-warden resolves
unknown to fail_open, secrets-engine to fail_closed; both conformant,
both total, both test-pinned, disagreeing about the one case that by
construction nobody planned for. They also scope over different axes, so
the register cannot answer what an inventory exists to answer.
Ruling 1: unknown is not a zone and MUST fail closed. §9.3 permits
trading availability for openness per zone — and that trade requires
knowing the zone. Where the scope is unknown the trade cannot have been
made for it, so a permissive unknown does not extend a considered
decision, it invents the most permissive one. An unreachable engine is a
known request in a degraded system; an unclassified subject is not.
unknown is the cheapest state for an attacker to induce, so failing open
on it makes being unclassifiable a privilege escalation requiring no
credential, which §8's asymmetry forbids wherever it appears.
Ruling 2: each map declares its scoping axis and its relation to zone.
Forcing everyone onto zones would make secrets-engine assert a zone it
cannot know, and a fiction in a runtime-read test-pinned file is worse
than an honest incommensurability. The register records the axes and
states that cross-axis aggregation is unavailable.
ops-warden acquires one non-conformant cell at v0.8. It did everything
asked — published first, built the reference form, offered it estate-wide
— so this goes to the assent round rather than being imposed quietly.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01WtJBr77gMFLrN93iEevqQJ
Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 425128@bnt-lap001
Assistant-Session: f5944d8b-dac4-4e1a-87eb-8b3d8f314a63
access-engine raised, and declined to solve locally, a hole in the split
GH-DEC-2026-005 ruled on. approval-claim verification item 4 is a
disjunction and neither limb delivers "approved for THIS request" on the
PDP path: limb one requires translating between two engines' vocabularies
and no mapping is published, limb two (pdp_digest) is optional. Where the
digest is absent a consumer can hold valid_now true, receive an ALLOW,
consume and act with nothing establishing that approval and decision
concern the same action and target.
Ruled: the PDP digest is the correspondence and is required on that path;
a claim without one fails closed; the native limb survives only for
consumers already in approval-engine's vocabulary, including T-06. No
mapping is published — a translation can be wrong while still producing a
confident answer, it fails open, it would be owned by neither engine, and
recomputing another layer's binding is the re-derivation GH-DEC-2026-005
already forbids. The cost is stated: an approval issued without a bound
CheckRequest is unusable on this path, which is correct behaviour.
Also: adopted hub row b606e8ce as canonical for GH-DEC-2026-005 rather
than registering a duplicate; recorded approval-engine's narrowing of the
approver-threshold consequence (distinctness is a UNIQUE storage
invariant, so the PEP stopped checking that the engine applied its own
invariant, not whether dual control could be forged); and drafted A7/T08,
a §11 marking obligation and §12 consumer rule for derived summaries,
after four instances in one week across four repositories.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01WtJBr77gMFLrN93iEevqQJ
Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 425128@bnt-lap001
Assistant-Session: f5944d8b-dac4-4e1a-87eb-8b3d8f314a63
Exact normative text for all six amendments, section by section against
accepted v0.7, at docs/amendments/v0.8-amendment-set.md. Each carries its
defect statement, its replacement wording, and the decision or contract
that already governs its implementers — the statute move does not decide
any of them again.
A1 §9.7.3 corrects the consume ordering: v0.7's stated order leaves the
CAS able to prevent only the second record and never the second side
effect, which makes single consumption theatre. A2 adds the §11
emission-guarantee check so GH-IN-0001 cannot recur unnoticed. A3 keeps
the §13 tables and transcribes the four stance-map rows, ops-mason's gap
included, since the register migration is conditioned on an export. A4
lands the recomputability boundary with the criteria-grounding clause. A5
generalizes validation-by-owning-layer into §6.4 and adds the
validating-is-not-re-issuing demarcation to §8. A6 replaces §17's stale
"neither has assented" paragraph.
Deliberate omissions are recorded rather than left silent: §12's fourth
step is a status not an amendment, §16's reconciliation is assembly work,
and no §4 catalog row moves.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01WtJBr77gMFLrN93iEevqQJ
Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 425128@bnt-lap001
Assistant-Session: f5944d8b-dac4-4e1a-87eb-8b3d8f314a63
GH-WP-0003-T04. kings-guard's answer to KG-IN-0003 is adopted: the
posture/maturity line is recomputability, not volatility. Their argument
holds — volatility describes the two categories without partitioning
them, and every case it does not obviously cover becomes an argument at
exactly the boundary §6 exists to keep out of argument. The test is
§9.5's own determinism clause pointed where it had not been pointed.
Added one clause they did not propose, because their framing opens a
loophole: recomputability is assessed over the stated criteria, so a
criterion that dereferences a judgment is deterministic in form and
inferential in substance, and would put an opinion inside an engine
wearing a rule's clothes. A criterion MUST bottom out in evidence about
the subject, not in another party's conclusion about it. A recorded
judgment is evidence that the judgment was made, never that the thing
judged is so — the same distinction §9.6 draws about archives and
GH-DEC-2026-005 draws about valid_now.
All three kings-guard consequences carried, including the constraint they
volunteered against themselves (readiness is not an input to posture) and
their honest limit, which makes §17 load-bearing for the rule.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01WtJBr77gMFLrN93iEevqQJ
Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 425128@bnt-lap001
Assistant-Session: f5944d8b-dac4-4e1a-87eb-8b3d8f314a63
Two corrections from the repositories that implemented the decision, both
volunteered against their own interest.
approval-engine and flex-auth independently reported that the deferred
option's G3 revisit trigger was already spent when the decision was
written. Verified here against flex-auth/schemas/decision_envelope.schema.json:
FLEX-WP-0019 closed G3 on 2026-09-02 by adding the field, not by
composition. That resolves against ratification — carrying its own end was
the one structural thing the composed bundle did that the split does not,
so the strongest case for option D is answered, and the answer is no.
secrets-engine reported that the split reduces what the PEP verifies: the
distinct-approver threshold is now folded into valid_now and no longer
checked independently. Correct on layering and a real reduction; both are
true. Recorded with its compensating property — reconstructability at the
issuer under §9.6, which is detection rather than prevention.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01WtJBr77gMFLrN93iEevqQJ
Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 425128@bnt-lap001
Assistant-Session: f5944d8b-dac4-4e1a-87eb-8b3d8f314a63
GH-WP-0003-T03. maturity-engine holds the §13 gap register and the §13.1
stance-map inventory as queryable data and proposed the statute tables
become pointers. Two things are true at once: a statute should not carry
state, and a standard must be readable on its own.
The registers become pointers, and not before maturity-engine publishes a
committed, versioned export readable without a live query. Publication is
the migration's precondition, not its follow-up — pointing an auditor at
a live engine is not a register they can read, and would repeat in the
other direction the exact defect §13.1 was created to fix.
Until the export lands the tables stay and rows are transcribed, so
user-engine, tenant-engine, ops-warden and ops-mason are inventoried in
v0.8 either way rather than waiting on the condition.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01WtJBr77gMFLrN93iEevqQJ
Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 425128@bnt-lap001
Assistant-Session: f5944d8b-dac4-4e1a-87eb-8b3d8f314a63
Marking the 2026-08-29 review round read on the reasoning that v0.7's
acceptance closed it was an inference, not a check. This does the check:
fifteen findings and two answered questions from kings-guard, ops-warden,
access-engine and audit-core, each traced to v0.7 text or a decision
record rather than to the §15 change log.
All fifteen are dispositioned. None was silently dropped. The change log
deliberately is not the evidence — kings-guard's finding 1 was exactly
the case where the change log claimed a rule the body did not contain.
One item surfaced, and it is not a v0.6 finding: §17 still says
emission-cadence ownership is proposed and unassented, which
GH-DEC-2026-004 and the info-tech-canon and net-kingdom acceptances have
since made false. Tracked as GH-WP-0003-T07.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01WtJBr77gMFLrN93iEevqQJ
Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 425128@bnt-lap001
Assistant-Session: f5944d8b-dac4-4e1a-87eb-8b3d8f314a63
Five rulings made since security-layer-model v0.7 was accepted belong in
the statute and are currently held in gate-house contracts, decision
records, or a reply in another repository's inbox: the §9.7.3 consume
ordering clarification, the §11 emission-guarantee check, the §13/§13.1
register disposition, kings-guard's recomputability boundary for §9.5,
and GH-DEC-2026-005's split-validation doctrine.
Each was correctly kept out of v0.7. Together they are a version. v0.7
stays accepted and unedited; gate-house authors, net-kingdom publishes.
T03 also discharges the four outstanding §13.1 stance-map rows that
user-engine, tenant-engine, ops-warden and ops-mason are waiting on,
either as transcribed entries or as a confirmed pointer to
maturity-engine.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01WtJBr77gMFLrN93iEevqQJ
Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 425128@bnt-lap001
Assistant-Session: f5944d8b-dac4-4e1a-87eb-8b3d8f314a63
approval-engine raised APPROVAL-IN-0002: secrets-engine's PEP validator
expects a flex-auth ActionAuthorization but fetches the approval-claim
endpoint that GH-DEC-2026-003 names as step 1. Two objects on one path.
GH-IN-0002 records the intake; GH-DEC-2026-005 resolves it. The claim is
the step-1 artifact and always was — ActionAuthorization is unratified,
has no valid_now field, and cannot be served from a step-1 call. The
addition beyond confirmation is doctrine: a PEP validates each artifact
against the layer that owns its data, and no PIP republishes the PDP's
decision. The provenance.authority == "state-hub" requirement is struck;
State Hub is a read model and holds no runtime approval authority.
docs/contracts/approval-consumption.md carries the amendment at the
sequence itself so implementers find it there.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01WtJBr77gMFLrN93iEevqQJ
Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 425128@bnt-lap001
Assistant-Session: f5944d8b-dac4-4e1a-87eb-8b3d8f314a63