| id |
type |
status |
date |
consumer |
consumer_domain |
canon_version |
artifacts |
related_demand |
related_workplan |
spawned_demand |
spawned_workplan |
| feedback/2026-09-21-net-kingdom-emission-cadence-declaration |
consumer-feedback |
reviewed |
2026-09-21 |
net-kingdom |
infotech |
0.7.0 |
| standard/emission-cadence |
|
| demand/EmissionActivityScope.md |
|
|
| demand/EmissionActivityScope.md |
|
|
Feedback: first source-owned Emission Cadence declaration (local-identity audit log)
Consumer: net-kingdom
Canon version used: 0.7.0; Emission Cadence document 0.2.0, wire schema 0.1
Artifacts exercised: infospace/schemas/emission-cadence.schema.yaml,
standards/emission-cadence/InfoTechCanonEmissionCadenceStandard.md
Related demand: demand/EmissionActivityScope.md
Source: net-kingdom's reply to INFO-WP-0029-T02 (State Hub message
3b2db043-b910-4552-930f-65d87b475f3b, thread 3432a831), and the files it
published at net-kingdom commit 116643f:
local-identity/emission-cadence.yaml and
local-identity/emission-cadence-findings.md. The consumer's own findings file
is the authoritative account. The sections below summarize it and do not
restate it.
Consumer purpose
Declare the intended cadence of the local-identity audit log (serve/token
issuance, revoke-token) as load-bearing security evidence, so that an
observer could read silence in that stream.
Hits
heartbeat-or-reconciliation with a reconciliation block. This expressed
a local-count versus observed-count comparison without inventing a heartbeat
the source does not emit.
extensions. These carried NetKingdom's evidence class, the
rate-monitoring prohibition, and completeness_claimed: false without
touching the generic contract.
- The schema was sufficient for a valid declaration. The consumer found it
contract_valid through its own profile tool.
Friction
emission-review could not be run by the consumer because
infospace-bench==0.1.0 is not installable from a package index. This is the
packaging limitation SCOPE.md already records. It now costs an adopter a
validation step.
reconciliation needs an observer that does not exist, so
compare_observed is a declared reference with no feed behind it.
Gaps
- Session-scoped silence. The source can emit only while an attended process
runs.
expected-rate has no meaningful floor (expected_min: 0 makes
silence meaningless), and a heartbeat outside a session does not exist.
Neither form can say "silent because not running". Filed as
demand/EmissionActivityScope.md.
Drop candidates
None.
Steward notes
- Validated canon-side on 2026-09-22.
info_tech_canon emission-review on
the declaration at 116643f returned ok: true, errors: [],
operational_truth_assessed: false.
- The pin was stale because of our brief, not because of the consumer. The
consumer pinned
972c0b6701d1693f and labelled it document 0.2.0, as
docs/emission-cadence-adoption.md instructed. That digest is the 0.1.0 draft
bundle. The candidate promotion (4d0851c) changed the standard's text after
the digest was taken, and the brief was not updated. The wire schema is
identical in both bundles, so the declaration's validity is unaffected. The
export manifest also hard-coded status: draft. It now reads status and
version from the standard. The brief names the corrected candidate digest,
b08b4d95fc4b0bd3.
- What this counts toward. This is one source-owned declaration from an owner
independent of this repository. It also records an incompatibility, which is
the third element of the stable gate (standard §10). It is not a second
declaration and not an observer result. The standard stays at candidate.
- Observer evaluation received, and it does not satisfy the gate.
audit-core replied 2026-09-22 (State Hub message
266abb18-0a85-4d85-9ff2-0745949c9587,
thread 368e54bf-6401-4184-a1d2-04f133945d40), against its own AUDIT-WP-0009
implementation (audit-core 01468ff, read at contract digest
b08b4d95fc4b0bd3): structurally, both entries in this declaration
validate. Operationally, audit-core registers no local-identity sender and
holds none of its events, so nothing sits behind compare_observed — by
audit-core's own account this is "not an observer result on the stream, and
it should not satisfy your section 10 stable gate." A second incompatibility
surfaced: the declaration's heartbeat block names an event_class, but
audit-core evaluates one heartbeat class (audit-core.heartbeat, carrying
the vouched-for class in data.class) driven by a separately registered
heartbeat_classes list — the two can drift apart, and neither side has
reconciled that yet. audit-core states a real observer result needs a
source with an expected-rate or reconciliation declaration registered there
and sending traffic — which is not this declaration. INFO-WP-0029-T05
(observer result) stays open on the strength of this reply alone.
- The NetKingdom security profile's rare-heartbeat MUST failure belongs to
NetKingdom's profile. It is not a defect of the generic contract.