2026-09-21 06:33:31 +02:00
|
|
|
# informed-decision — NetKingdom security layer declaration (DERIVED)
|
Declare the layer per GH-DEC-2026-012; close T02
Gate House ruled all three questions within a day, attributing the speed to the
request being filed before the architecture with candidate answers and their
costs.
R1 PEP-shaped, confirmed as proposed. The ruling settles the shape; the layer
stays ours to declare, so layer.yaml is written in this repository's voice
rather than transcribed from the reply.
R2 yes to a presentation claim, no second catalog row, under three limits now
declared in layer.yaml and tested. Limit 2 — the claim must never be an input to
the decision it presents for — is load-bearing: our self-dealing argument was
accepted because it holds, not despite it. Limit 3 drives architecture, since
here the actor being audited and the evidence source are the same component.
R3 (b) with the authority rule: binding digest authoritative for what the
request is, view_hash only for what was shown, neither substitutable, and a
disagreement between them is a finding against the presenting surface rather
than a fact about the request. Linkage is co-reference; nesting was refused
because it reproduces the GH-DEC-2026-008 hash cycle.
Built to v0.8 obligation 3 rather than migrating later: axis enumerated, unknown
resolves to fail_closed, absent distinguishable from unknown in the record, and
published-equals-shipped asserted by test rather than claimed. Every stance is
fail_closed, which is a conclusion not a shortcut — ops-warden can justify
fail_open on a continuity argument that does not exist here.
GH-DEC-2026-010 inherited as a declared gap in four documents: a decision cannot
today be proven to have come from access-engine. The decision path must not be
described as validated while FLEX-WP-0024 is open.
46 tests pass. T05 and T07 unblocked.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01V3W1dQG7GFFM9d94jFx7iR
Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 1565372@bnt-lap001
Assistant-Session: 16bb2f25-b34c-49ef-8e94-5fec3567a568
2026-09-09 22:25:35 +02:00
|
|
|
#
|
2026-09-21 06:33:31 +02:00
|
|
|
# THIS FILE DOES NOT GOVERN. GH-DEC-2026-017 §1 (A11) rules that the `layer:`
|
|
|
|
|
# key in INTENT.md frontmatter IS the declaration, and that an equivalent
|
|
|
|
|
# declaration file is a DERIVED ARTIFACT which must be marked as derived, must
|
|
|
|
|
# name INTENT.md as what it derives from, and must agree with it. §11 already
|
|
|
|
|
# said a repository declares its layer in its own INTENT.md; the file form was
|
|
|
|
|
# added to give the declaration a machine-readable shape, not a second
|
|
|
|
|
# authority.
|
|
|
|
|
#
|
|
|
|
|
# A disagreement between the two forms is a finding in its own right and must be
|
|
|
|
|
# reported rather than resolved away by precedence. There is none here: both
|
|
|
|
|
# files carried `surface` in the same casing before the ruling and both carry
|
|
|
|
|
# `Staff` after it, changed in one commit.
|
|
|
|
|
#
|
|
|
|
|
# Framework: net-kingdom/canon/standards/ — the body, UNVERSIONED on purpose.
|
|
|
|
|
# Companion: net-kingdom/SECURITY-COMPANION.md
|
Declare the layer per GH-DEC-2026-012; close T02
Gate House ruled all three questions within a day, attributing the speed to the
request being filed before the architecture with candidate answers and their
costs.
R1 PEP-shaped, confirmed as proposed. The ruling settles the shape; the layer
stays ours to declare, so layer.yaml is written in this repository's voice
rather than transcribed from the reply.
R2 yes to a presentation claim, no second catalog row, under three limits now
declared in layer.yaml and tested. Limit 2 — the claim must never be an input to
the decision it presents for — is load-bearing: our self-dealing argument was
accepted because it holds, not despite it. Limit 3 drives architecture, since
here the actor being audited and the evidence source are the same component.
R3 (b) with the authority rule: binding digest authoritative for what the
request is, view_hash only for what was shown, neither substitutable, and a
disagreement between them is a finding against the presenting surface rather
than a fact about the request. Linkage is co-reference; nesting was refused
because it reproduces the GH-DEC-2026-008 hash cycle.
Built to v0.8 obligation 3 rather than migrating later: axis enumerated, unknown
resolves to fail_closed, absent distinguishable from unknown in the record, and
published-equals-shipped asserted by test rather than claimed. Every stance is
fail_closed, which is a conclusion not a shortcut — ops-warden can justify
fail_open on a continuity argument that does not exist here.
GH-DEC-2026-010 inherited as a declared gap in four documents: a decision cannot
today be proven to have come from access-engine. The decision path must not be
described as validated while FLEX-WP-0024 is open.
46 tests pass. T05 and T07 unblocked.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01V3W1dQG7GFFM9d94jFx7iR
Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 1565372@bnt-lap001
Assistant-Session: 16bb2f25-b34c-49ef-8e94-5fec3567a568
2026-09-09 22:25:35 +02:00
|
|
|
# Voice: INTENT.md (this repository's own, per §11 "who must declare")
|
2026-09-21 06:33:31 +02:00
|
|
|
# Rulings: GH-DEC-2026-012 (INFD-IN-0001) — the shape
|
|
|
|
|
# GH-DEC-2026-017 (INFD-IN-0006) — the layer value, the form, the version
|
Declare the layer per GH-DEC-2026-012; close T02
Gate House ruled all three questions within a day, attributing the speed to the
request being filed before the architecture with candidate answers and their
costs.
R1 PEP-shaped, confirmed as proposed. The ruling settles the shape; the layer
stays ours to declare, so layer.yaml is written in this repository's voice
rather than transcribed from the reply.
R2 yes to a presentation claim, no second catalog row, under three limits now
declared in layer.yaml and tested. Limit 2 — the claim must never be an input to
the decision it presents for — is load-bearing: our self-dealing argument was
accepted because it holds, not despite it. Limit 3 drives architecture, since
here the actor being audited and the evidence source are the same component.
R3 (b) with the authority rule: binding digest authoritative for what the
request is, view_hash only for what was shown, neither substitutable, and a
disagreement between them is a finding against the presenting surface rather
than a fact about the request. Linkage is co-reference; nesting was refused
because it reproduces the GH-DEC-2026-008 hash cycle.
Built to v0.8 obligation 3 rather than migrating later: axis enumerated, unknown
resolves to fail_closed, absent distinguishable from unknown in the record, and
published-equals-shipped asserted by test rather than claimed. Every stance is
fail_closed, which is a conclusion not a shortcut — ops-warden can justify
fail_open on a continuity argument that does not exist here.
GH-DEC-2026-010 inherited as a declared gap in four documents: a decision cannot
today be proven to have come from access-engine. The decision path must not be
described as validated while FLEX-WP-0024 is open.
46 tests pass. T05 and T07 unblocked.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01V3W1dQG7GFFM9d94jFx7iR
Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 1565372@bnt-lap001
Assistant-Session: 16bb2f25-b34c-49ef-8e94-5fec3567a568
2026-09-09 22:25:35 +02:00
|
|
|
#
|
|
|
|
|
# Reference form: ops-warden's, adopted by audit-core and kings-guard, with
|
2026-09-21 06:33:31 +02:00
|
|
|
# kings-guard's adaptation for a repository with no Tooling contacts. ops-warden
|
|
|
|
|
# owns that form and is updating it for GH-DEC-2026-017 §1 and §5 in a parallel
|
|
|
|
|
# session; this file applies the two RULED properties (derived marking, absence
|
|
|
|
|
# of a standard version) and follows ops-warden's shape for everything else
|
|
|
|
|
# rather than inventing one.
|
Declare the layer per GH-DEC-2026-012; close T02
Gate House ruled all three questions within a day, attributing the speed to the
request being filed before the architecture with candidate answers and their
costs.
R1 PEP-shaped, confirmed as proposed. The ruling settles the shape; the layer
stays ours to declare, so layer.yaml is written in this repository's voice
rather than transcribed from the reply.
R2 yes to a presentation claim, no second catalog row, under three limits now
declared in layer.yaml and tested. Limit 2 — the claim must never be an input to
the decision it presents for — is load-bearing: our self-dealing argument was
accepted because it holds, not despite it. Limit 3 drives architecture, since
here the actor being audited and the evidence source are the same component.
R3 (b) with the authority rule: binding digest authoritative for what the
request is, view_hash only for what was shown, neither substitutable, and a
disagreement between them is a finding against the presenting surface rather
than a fact about the request. Linkage is co-reference; nesting was refused
because it reproduces the GH-DEC-2026-008 hash cycle.
Built to v0.8 obligation 3 rather than migrating later: axis enumerated, unknown
resolves to fail_closed, absent distinguishable from unknown in the record, and
published-equals-shipped asserted by test rather than claimed. Every stance is
fail_closed, which is a conclusion not a shortcut — ops-warden can justify
fail_open on a continuity argument that does not exist here.
GH-DEC-2026-010 inherited as a declared gap in four documents: a decision cannot
today be proven to have come from access-engine. The decision path must not be
described as validated while FLEX-WP-0024 is open.
46 tests pass. T05 and T07 unblocked.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01V3W1dQG7GFFM9d94jFx7iR
Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 1565372@bnt-lap001
Assistant-Session: 16bb2f25-b34c-49ef-8e94-5fec3567a568
2026-09-09 22:25:35 +02:00
|
|
|
|
|
|
|
|
schema_version: "0.1"
|
|
|
|
|
framework: netkingdom-security-layer-model
|
|
|
|
|
repository: informed-decision
|
Raise INFD-IN-0006: is §3's layer vocabulary closed, and what is `surface`?
The custodian's estate-wide sweep (2026-09-21), extending flex-auth's boundaries
review FLEX-WP-0030, found this repository declaring `layer: surface` against a
§3 vocabulary that does not enumerate it. flex-auth's validator admits only
{Staff, Engine, Tooling}, so this fails on the value rather than on casing or on
B1's precedence question. It was never raised here directly and it is not the
nine-repository defect: both our files say `surface`, in the same casing.
`surface` denotes the presentation-and-binding tier — the runtime a human
touches, where a decision rendered elsewhere is shown to a named person, that
person binds their identity to the act, and the evidence that the presentation
happened is produced. It was chosen by elimination on 2026-09-09 (f6376dd),
because GH-DEC-2026-012 R1 ruled us out of Engine and left the layer ours to
declare, and each remaining value is false of us: not Staff (deterministic by
construction, and holding state audit-core depends on at runtime, which §3.4
forbids Staff), not Tooling (we persist nothing another layer reads), not
Taxonomy (we are nothing but a runtime position). Faced with a false value that
satisfies a validator or the true word and a finding, the true word was written.
Position: `surface` names a real tier §3 does not enumerate. The sharpest form
is that a standing ruling plus a closed vocabulary leaves this repository no
conforming declaration available — the §9.1 defect applied to conformance that
§11 names against itself. But the ruling is gate-house's and we do not claim it
must go our way: if the vocabulary is ruled closed and a value named, both files
change the same day without argument. We ask only that such a ruling show how
§3's determinism cut reaches that value given GH-DEC-2026-012 R1, because the
next repository in this position will reason from it — and the tier a human
touches having no owner is exactly what produced approval-engine's unowned
inbox, key-cape's blocked client_id, and this repository.
Two observations offered: flex-auth's validator admits three values where §3
enumerates four, so railiance-master's `Taxonomy` fails the validator rather
than the standard and is separable without any ruling, leaving `surface` as the
only surveyed value outside §3 itself; and §3's row label is `Engines` while
declarations use `Engine`, which should be written out as declaration values if
the set is ruled closed.
The declared value is UNCHANGED on purpose. Changing it ahead of the ruling
would pre-empt gate-house and throw away the evidence of what was concluded.
layer.yaml, INTENT.md and AGENTS.md now say so in place, so the value is not
read as unexamined and no later agent silently "fixes" it. AGENTS.md's layer
section was also stale — it still said layer.yaml was unwritten.
28 layer conformance tests pass.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 63291@bnt-lap001
Assistant-Session: 8bd77868-ca68-4f49-bb1e-d539ecc0d703
2026-09-21 02:11:59 +02:00
|
|
|
|
2026-09-21 06:33:31 +02:00
|
|
|
# §11 derived-artifact rule + GH-DEC-2026-017 §1.
|
|
|
|
|
derived: true
|
|
|
|
|
derives_from: INTENT.md
|
|
|
|
|
derives_from_note: >-
|
|
|
|
|
INTENT.md frontmatter governs. This file is regenerated from it by hand and
|
|
|
|
|
changes in the same commit, so it is derived at the same commit by
|
|
|
|
|
construction; if the two ever disagree, INTENT.md is this repository's answer
|
|
|
|
|
and the disagreement is itself a finding.
|
|
|
|
|
|
|
|
|
|
# NO standard_version, and no companion_version — GH-DEC-2026-017 §5 (A12).
|
|
|
|
|
# A layer declaration asserts a STANDING property: which layer this repository
|
|
|
|
|
# is. That does not change when the standard is revised, and a version here
|
|
|
|
|
# makes every revision read as though it invalidated the declaration. The field
|
|
|
|
|
# was flagged by this repository on 2026-09-21 and by access-engine in its own
|
|
|
|
|
# file; the ruling removes it estate-wide from ops-warden's reference form.
|
|
|
|
|
# Version-scoped state belongs in the derived conformance record, which must
|
|
|
|
|
# carry the version it was derived at. `companion_version` is removed on the
|
|
|
|
|
# same reasoning; it is a version pin in a declaration and nothing in the
|
|
|
|
|
# ruling's argument distinguishes it. Raised with ops-warden as part of the
|
|
|
|
|
# reference-form update rather than decided here for the estate.
|
|
|
|
|
|
|
|
|
|
# §3 vocabulary — RULED CLOSED, value corrected 2026-09-21 (INFD-IN-0006).
|
Raise INFD-IN-0006: is §3's layer vocabulary closed, and what is `surface`?
The custodian's estate-wide sweep (2026-09-21), extending flex-auth's boundaries
review FLEX-WP-0030, found this repository declaring `layer: surface` against a
§3 vocabulary that does not enumerate it. flex-auth's validator admits only
{Staff, Engine, Tooling}, so this fails on the value rather than on casing or on
B1's precedence question. It was never raised here directly and it is not the
nine-repository defect: both our files say `surface`, in the same casing.
`surface` denotes the presentation-and-binding tier — the runtime a human
touches, where a decision rendered elsewhere is shown to a named person, that
person binds their identity to the act, and the evidence that the presentation
happened is produced. It was chosen by elimination on 2026-09-09 (f6376dd),
because GH-DEC-2026-012 R1 ruled us out of Engine and left the layer ours to
declare, and each remaining value is false of us: not Staff (deterministic by
construction, and holding state audit-core depends on at runtime, which §3.4
forbids Staff), not Tooling (we persist nothing another layer reads), not
Taxonomy (we are nothing but a runtime position). Faced with a false value that
satisfies a validator or the true word and a finding, the true word was written.
Position: `surface` names a real tier §3 does not enumerate. The sharpest form
is that a standing ruling plus a closed vocabulary leaves this repository no
conforming declaration available — the §9.1 defect applied to conformance that
§11 names against itself. But the ruling is gate-house's and we do not claim it
must go our way: if the vocabulary is ruled closed and a value named, both files
change the same day without argument. We ask only that such a ruling show how
§3's determinism cut reaches that value given GH-DEC-2026-012 R1, because the
next repository in this position will reason from it — and the tier a human
touches having no owner is exactly what produced approval-engine's unowned
inbox, key-cape's blocked client_id, and this repository.
Two observations offered: flex-auth's validator admits three values where §3
enumerates four, so railiance-master's `Taxonomy` fails the validator rather
than the standard and is separable without any ruling, leaving `surface` as the
only surveyed value outside §3 itself; and §3's row label is `Engines` while
declarations use `Engine`, which should be written out as declaration values if
the set is ruled closed.
The declared value is UNCHANGED on purpose. Changing it ahead of the ruling
would pre-empt gate-house and throw away the evidence of what was concluded.
layer.yaml, INTENT.md and AGENTS.md now say so in place, so the value is not
read as unexamined and no later agent silently "fixes" it. AGENTS.md's layer
section was also stale — it still said layer.yaml was unwritten.
28 layer conformance tests pass.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 63291@bnt-lap001
Assistant-Session: 8bd77868-ca68-4f49-bb1e-d539ecc0d703
2026-09-21 02:11:59 +02:00
|
|
|
#
|
2026-09-21 06:33:31 +02:00
|
|
|
# GH-DEC-2026-017 §3: the §3 vocabulary is CLOSED and has four tokens —
|
|
|
|
|
# Taxonomy, Tooling, Engine, Staff. Comparison is ASCII case-insensitive (§2 /
|
|
|
|
|
# A9), so no repository is asked to re-spell anything. `surface` is not among
|
|
|
|
|
# them: "surface is not a layer... Its correct declaration is layer: Staff, role:
|
|
|
|
|
# pep-shaped, which its own file already reasons from two ways." ops-mason and
|
|
|
|
|
# ops-warden are the precedent: Staff in the layer column, PEP-shaped in the
|
|
|
|
|
# role column.
|
|
|
|
|
#
|
|
|
|
|
# Changed the same day the ruling was received, in one commit, with no argument
|
|
|
|
|
# — exactly as this repository pre-committed in
|
|
|
|
|
# docs/gate-house-decision-request-layer-vocabulary.md §3. `role: pep-shaped` is
|
|
|
|
|
# untouched and was already right; a role is not a layer (GH-DEC-2026-012 R2,
|
|
|
|
|
# restated by GH-DEC-2026-017 §3 for the declaration field).
|
|
|
|
|
layer: Staff
|
Declare the layer per GH-DEC-2026-012; close T02
Gate House ruled all three questions within a day, attributing the speed to the
request being filed before the architecture with candidate answers and their
costs.
R1 PEP-shaped, confirmed as proposed. The ruling settles the shape; the layer
stays ours to declare, so layer.yaml is written in this repository's voice
rather than transcribed from the reply.
R2 yes to a presentation claim, no second catalog row, under three limits now
declared in layer.yaml and tested. Limit 2 — the claim must never be an input to
the decision it presents for — is load-bearing: our self-dealing argument was
accepted because it holds, not despite it. Limit 3 drives architecture, since
here the actor being audited and the evidence source are the same component.
R3 (b) with the authority rule: binding digest authoritative for what the
request is, view_hash only for what was shown, neither substitutable, and a
disagreement between them is a finding against the presenting surface rather
than a fact about the request. Linkage is co-reference; nesting was refused
because it reproduces the GH-DEC-2026-008 hash cycle.
Built to v0.8 obligation 3 rather than migrating later: axis enumerated, unknown
resolves to fail_closed, absent distinguishable from unknown in the record, and
published-equals-shipped asserted by test rather than claimed. Every stance is
fail_closed, which is a conclusion not a shortcut — ops-warden can justify
fail_open on a continuity argument that does not exist here.
GH-DEC-2026-010 inherited as a declared gap in four documents: a decision cannot
today be proven to have come from access-engine. The decision path must not be
described as validated while FLEX-WP-0024 is open.
46 tests pass. T05 and T07 unblocked.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01V3W1dQG7GFFM9d94jFx7iR
Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 1565372@bnt-lap001
Assistant-Session: 16bb2f25-b34c-49ef-8e94-5fec3567a568
2026-09-09 22:25:35 +02:00
|
|
|
role: pep-shaped
|
|
|
|
|
declared_by: INTENT.md
|
2026-09-21 06:33:31 +02:00
|
|
|
declared_at: "2026-09-09" # the declaration; the VALUE was corrected 2026-09-21
|
|
|
|
|
value_corrected_at: "2026-09-21"
|
|
|
|
|
ruling: GH-DEC-2026-017
|
|
|
|
|
shape_ruling: GH-DEC-2026-012
|
|
|
|
|
|
|
|
|
|
# ---------------------------------------------------------------------------
|
|
|
|
|
# HISTORY — why `surface` was written. KEPT ON PURPOSE, not erased.
|
|
|
|
|
#
|
|
|
|
|
# GH-DEC-2026-017 §3's reversal condition names this reasoning directly, so it
|
|
|
|
|
# has to remain readable: "§3's closure reverses on an argued amendment to §3,
|
|
|
|
|
# from a repository that bears a cost under the four-layer cut."
|
|
|
|
|
#
|
|
|
|
|
# From 2026-09-09 (commit f6376dd) to 2026-09-21 this file and INTENT.md both
|
|
|
|
|
# declared `layer: surface`, in the same casing, meaning the
|
|
|
|
|
# presentation-and-binding tier: the runtime a human touches, where a decision
|
|
|
|
|
# rendered elsewhere is shown to a named person, that person binds their
|
|
|
|
|
# identity to the act, and the evidence that the presentation happened is
|
|
|
|
|
# produced.
|
|
|
|
|
#
|
|
|
|
|
# It was chosen by ELIMINATION, not casually. GH-DEC-2026-012 R1 ruled this
|
|
|
|
|
# repository out of Engine and left the layer to it to declare, and each
|
|
|
|
|
# remaining §3 value was read as false of it:
|
|
|
|
|
# - not Staff — deterministic by construction (the same approval rendered to
|
|
|
|
|
# the same principal in the same role yields the same
|
|
|
|
|
# view_hash, asserted by test), and holding state audit-core
|
|
|
|
|
# depends on at runtime, which §3.4 forbids Staff;
|
|
|
|
|
# - not Tooling — persists nothing another layer reads;
|
|
|
|
|
# - not Taxonomy— nothing but a runtime position.
|
|
|
|
|
# Faced with picking a value it believed false or writing the true word and
|
|
|
|
|
# carrying the finding, this repository wrote the word and asked for a ruling.
|
|
|
|
|
# It did not ask for §3 to be amended in its favour, and it does not now.
|
|
|
|
|
#
|
|
|
|
|
# The ruling reaches Staff by the same elimination from the other end — not an
|
|
|
|
|
# Engine, and nothing else in the four is true, so Staff — and gives the value,
|
|
|
|
|
# which is what was asked for and what binds. The part of the elimination above
|
|
|
|
|
# that the ruling does not address is recorded as INFD-IN-0007 below. It is a
|
|
|
|
|
# question, not a reservation: the value is applied unconditionally.
|
|
|
|
|
#
|
|
|
|
|
# Request: docs/gate-house-decision-request-layer-vocabulary.md
|
|
|
|
|
# ---------------------------------------------------------------------------
|
|
|
|
|
|
|
|
|
|
# OPEN, non-blocking — INFD-IN-0007.
|
|
|
|
|
#
|
|
|
|
|
# §3.4 defines Staff as interactive and non-deterministic, working through
|
|
|
|
|
# agentic capability, and says Staff repositories MUST NOT hold state that
|
|
|
|
|
# another layer depends on at runtime. This repository is deterministic by test,
|
|
|
|
|
# forbids an agent from completing its protected act at all, and holds
|
|
|
|
|
# presentation evidence audit-core depends on. It is Staff by ruling and the
|
|
|
|
|
# declaration above says so. What is not yet written down is how §3's
|
|
|
|
|
# determinism cut reaches a deterministic, non-agentic, evidence-holding
|
|
|
|
|
# repository — the derivation this repository asked for as a non-condition, and
|
|
|
|
|
# which the ruling answers as far as the VALUE and not as far as the FIT.
|
|
|
|
|
# Asked once more of gate-house; no deadline, no dependency, nothing waits on it.
|
|
|
|
|
section_3_4_fit:
|
|
|
|
|
status: open
|
|
|
|
|
intake: INFD-IN-0007
|
|
|
|
|
blocks_nothing: true
|
|
|
|
|
|
|
|
|
|
# §4 catalog membership — ASKED by GH-DEC-2026-017 §4, ANSWERED here.
|
|
|
|
|
#
|
|
|
|
|
# gate-house deliberately did not enrol this repository: adding a row is a canon
|
|
|
|
|
# change, and §11's own rule — a layer stated ABOUT a repository BY another is
|
|
|
|
|
# not a declaration — applies to catalogue membership at least as strongly. The
|
|
|
|
|
# question was put, not decided. This repository's answer is YES, with the
|
|
|
|
|
# obligation that comes with it accepted rather than negotiated.
|
|
|
|
|
#
|
|
|
|
|
# Full argument: docs/section-4-catalog-row.md. Carried by gate-house as
|
|
|
|
|
# GH-WP-0004-T06.
|
|
|
|
|
catalog:
|
|
|
|
|
section_4_row_today: false
|
|
|
|
|
declared_voluntarily: true
|
|
|
|
|
scope_report: declared-voluntarily-outside-catalog-scope
|
|
|
|
|
requested: true
|
|
|
|
|
requested_at: "2026-09-21"
|
|
|
|
|
requested_row:
|
|
|
|
|
repository: informed-decision
|
|
|
|
|
layer: Staff
|
|
|
|
|
role: pep-shaped
|
|
|
|
|
evidence_source: "yes"
|
|
|
|
|
accepts_emission_guarantee: true
|
|
|
|
|
note: >-
|
|
|
|
|
Until the row exists, §11 does not bind this repository and a run that
|
|
|
|
|
grades it is over-scoped (GH-DEC-2026-017 §4). That is the reason to ask for
|
|
|
|
|
the row, not a reason to avoid it: this repository's presentation evidence
|
|
|
|
|
is the only record of what a human was shown before binding, and an evidence
|
|
|
|
|
obligation nobody is allowed to check is the weaker position.
|
Declare the layer per GH-DEC-2026-012; close T02
Gate House ruled all three questions within a day, attributing the speed to the
request being filed before the architecture with candidate answers and their
costs.
R1 PEP-shaped, confirmed as proposed. The ruling settles the shape; the layer
stays ours to declare, so layer.yaml is written in this repository's voice
rather than transcribed from the reply.
R2 yes to a presentation claim, no second catalog row, under three limits now
declared in layer.yaml and tested. Limit 2 — the claim must never be an input to
the decision it presents for — is load-bearing: our self-dealing argument was
accepted because it holds, not despite it. Limit 3 drives architecture, since
here the actor being audited and the evidence source are the same component.
R3 (b) with the authority rule: binding digest authoritative for what the
request is, view_hash only for what was shown, neither substitutable, and a
disagreement between them is a finding against the presenting surface rather
than a fact about the request. Linkage is co-reference; nesting was refused
because it reproduces the GH-DEC-2026-008 hash cycle.
Built to v0.8 obligation 3 rather than migrating later: axis enumerated, unknown
resolves to fail_closed, absent distinguishable from unknown in the record, and
published-equals-shipped asserted by test rather than claimed. Every stance is
fail_closed, which is a conclusion not a shortcut — ops-warden can justify
fail_open on a continuity argument that does not exist here.
GH-DEC-2026-010 inherited as a declared gap in four documents: a decision cannot
today be proven to have come from access-engine. The decision path must not be
described as validated while FLEX-WP-0024 is open.
46 tests pass. T05 and T07 unblocked.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01V3W1dQG7GFFM9d94jFx7iR
Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 1565372@bnt-lap001
Assistant-Session: 16bb2f25-b34c-49ef-8e94-5fec3567a568
2026-09-09 22:25:35 +02:00
|
|
|
|
|
|
|
|
# §6.4 — informed-decision is PEP-shaped: it causes a protected side effect on
|
|
|
|
|
# the far side of a decision (recording an approver entry against an approval
|
|
|
|
|
# object). Companion §5 is owed and §6.4 applies in full.
|
|
|
|
|
#
|
|
|
|
|
# Built to v0.8 obligation 3, not v0.7, per GH-DEC-2026-011 — see pep-stance.yaml.
|
|
|
|
|
pep_stance: pep-stance.yaml
|
|
|
|
|
|
|
|
|
|
protected_action: "Approver entry recorded against an approval object (POST /v1/approvals/{id}/entries)"
|
|
|
|
|
decision_engine: access-engine
|
|
|
|
|
|
|
|
|
|
# §6 — no repository other than access-engine exposes an authorization decision.
|
|
|
|
|
# This surface renders a question and records a human's answer. A disposition is
|
|
|
|
|
# evidence of an act, never a verdict.
|
|
|
|
|
decision_surfaces_exposed: none
|
|
|
|
|
|
|
|
|
|
# §3.3 / GH-DEC-2026-012 R2 — YES to a presentation claim, and NO second catalog
|
|
|
|
|
# row: PEP and PIP are shapes a repository has; §4 records the layers it
|
|
|
|
|
# occupies. The permission carries three limits, and they are the substance of
|
|
|
|
|
# it rather than caveats on it.
|
|
|
|
|
presentation_claim:
|
|
|
|
|
emitted: true
|
|
|
|
|
carries: presentation-only
|
|
|
|
|
limits:
|
|
|
|
|
- id: L1-presentation-only
|
|
|
|
|
rule: >-
|
|
|
|
|
The claim carries presentation and nothing else. It MUST NOT carry,
|
|
|
|
|
restate, summarise or imply the decision, the verdict, or whether the
|
|
|
|
|
act was permitted. A consumer learns from it only what was SHOWN, never
|
|
|
|
|
what was DECIDED.
|
|
|
|
|
- id: L2-not-an-input
|
|
|
|
|
rule: >-
|
|
|
|
|
The claim MUST NOT be an input to the decision it presents for. A policy
|
|
|
|
|
reading view_hash to decide whether an act is permitted would let the
|
|
|
|
|
presenting surface contribute to its own authorization.
|
|
|
|
|
note: >-
|
|
|
|
|
Load-bearing, not a formality. GH-DEC-2026-012 accepted this
|
|
|
|
|
repository's argument that a renderer attesting its own rendering is not
|
|
|
|
|
the self-dealing that kept the approval object out of access-engine —
|
|
|
|
|
but only because this limit holds. Without it the two collapse into the
|
|
|
|
|
same failure.
|
|
|
|
|
- id: L3-independent-evidence-path
|
|
|
|
|
rule: >-
|
|
|
|
|
The evidence copy reaches audit-core INDEPENDENTLY of this repository.
|
|
|
|
|
The claim endpoint and the evidence path are different things and
|
|
|
|
|
neither substitutes for the other. The copy that is evidence MUST NOT be
|
|
|
|
|
reachable only through the party it is evidence about.
|
|
|
|
|
note: >-
|
|
|
|
|
The limit that matters most here: audit evidence is protected from the
|
|
|
|
|
actor being audited, and in this component the actor and the source are
|
|
|
|
|
the same. Architecture consequence, tracked in
|
|
|
|
|
docs/specs/ArchitectureBlueprint.md.
|
|
|
|
|
|
|
|
|
|
# §17 — the shared request-claim schema is still unowned. This repository
|
|
|
|
|
# publishes at its own boundary and yields to that schema when it exists.
|
|
|
|
|
# Position accepted by GH-DEC-2026-012 and matching approval-engine's in
|
|
|
|
|
# APPROVAL-IN-0001.
|
|
|
|
|
request_claim_schema:
|
|
|
|
|
status: unowned-upstream
|
|
|
|
|
local_shape: published-at-own-boundary
|
|
|
|
|
yields_to: taxonomy-request-claim-schema
|
|
|
|
|
|
|
|
|
|
# GH-DEC-2026-012 R3 — (b), with the authority rule written down.
|
|
|
|
|
binding_digest_relationship:
|
|
|
|
|
ruling: GH-DEC-2026-012
|
|
|
|
|
view_hash_authoritative_for: what-was-shown
|
|
|
|
|
binding_digest_authoritative_for: what-the-request-is
|
|
|
|
|
binding_digest_owner: approval-engine
|
|
|
|
|
substitutable: false
|
|
|
|
|
disagreement_is: >-
|
|
|
|
|
A finding against the presenting surface, never a fact about the request.
|
Activate nesting per GH-DEC-2026-015: view_hash carries binding.digest
approval-engine met the condition. Verified here rather than taken on report:
their docs/approval-claim.md carries "Presentation exclusion — GH-DEC-2026-015
§4" in normative language, and I ran
tests/test_claim_contract.py::test_presentation_changes_cannot_change_the_approved_act
myself — 1 passed. That test pins the digest input set from BOTH sides, and the
narrowing half is what makes it real: without it a digest over four fields, or
over a constant, would pass the widening half perfectly.
view_hash now carries binding.digest and the act-scope is no longer
independently canonicalized here, so the act has exactly one canonicalization
computed by the layer that owns it. approval_binding_digest is validated for
shape and refused without its approval id — it is carried, never computed.
The three published vectors are unchanged: they do not carry the new key, so
pick omits it. Asserted, not assumed.
The cycle condition did not disappear, its protection moved — from refusing
nesting to approval-engine's normative exclusion. layer.yaml carries it as
cycle_condition with a test, so a future widening meets a rule rather than
silence.
One thing not assumed. Both gate-house and approval-engine said our binding
slice canonicalizes principal and target, two of their five fields. target
plainly is act material and is now dropped. But their principal is the party ON
WHOSE BEHALF the approval was issued, while ours is the person being BOUND — the
approver. Different roles, and dropping ours would remove who was shown this
from view_hash and gut the promise. Kept it, declared principal_role_overlap
open in layer.yaml, tested that changing the approver still moves view_hash, and
raised it rather than silently resolving it either way.
L0/L2 are unaffected: with no approval there is no digest to defer to, and
test_act_scope_still_binds_when_there_is_no_carried_digest pins that.
100 tests pass.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01V3W1dQG7GFFM9d94jFx7iR
Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 1565372@bnt-lap001
Assistant-Session: 16bb2f25-b34c-49ef-8e94-5fec3567a568
2026-09-10 20:58:22 +02:00
|
|
|
linkage: nesting
|
Declare the layer per GH-DEC-2026-012; close T02
Gate House ruled all three questions within a day, attributing the speed to the
request being filed before the architecture with candidate answers and their
costs.
R1 PEP-shaped, confirmed as proposed. The ruling settles the shape; the layer
stays ours to declare, so layer.yaml is written in this repository's voice
rather than transcribed from the reply.
R2 yes to a presentation claim, no second catalog row, under three limits now
declared in layer.yaml and tested. Limit 2 — the claim must never be an input to
the decision it presents for — is load-bearing: our self-dealing argument was
accepted because it holds, not despite it. Limit 3 drives architecture, since
here the actor being audited and the evidence source are the same component.
R3 (b) with the authority rule: binding digest authoritative for what the
request is, view_hash only for what was shown, neither substitutable, and a
disagreement between them is a finding against the presenting surface rather
than a fact about the request. Linkage is co-reference; nesting was refused
because it reproduces the GH-DEC-2026-008 hash cycle.
Built to v0.8 obligation 3 rather than migrating later: axis enumerated, unknown
resolves to fail_closed, absent distinguishable from unknown in the record, and
published-equals-shipped asserted by test rather than claimed. Every stance is
fail_closed, which is a conclusion not a shortcut — ops-warden can justify
fail_open on a continuity argument that does not exist here.
GH-DEC-2026-010 inherited as a declared gap in four documents: a decision cannot
today be proven to have come from access-engine. The decision path must not be
described as validated while FLEX-WP-0024 is open.
46 tests pass. T05 and T07 unblocked.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01V3W1dQG7GFFM9d94jFx7iR
Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 1565372@bnt-lap001
Assistant-Session: 16bb2f25-b34c-49ef-8e94-5fec3567a568
2026-09-09 22:25:35 +02:00
|
|
|
linkage_rule: >-
|
Activate nesting per GH-DEC-2026-015: view_hash carries binding.digest
approval-engine met the condition. Verified here rather than taken on report:
their docs/approval-claim.md carries "Presentation exclusion — GH-DEC-2026-015
§4" in normative language, and I ran
tests/test_claim_contract.py::test_presentation_changes_cannot_change_the_approved_act
myself — 1 passed. That test pins the digest input set from BOTH sides, and the
narrowing half is what makes it real: without it a digest over four fields, or
over a constant, would pass the widening half perfectly.
view_hash now carries binding.digest and the act-scope is no longer
independently canonicalized here, so the act has exactly one canonicalization
computed by the layer that owns it. approval_binding_digest is validated for
shape and refused without its approval id — it is carried, never computed.
The three published vectors are unchanged: they do not carry the new key, so
pick omits it. Asserted, not assumed.
The cycle condition did not disappear, its protection moved — from refusing
nesting to approval-engine's normative exclusion. layer.yaml carries it as
cycle_condition with a test, so a future widening meets a rule rather than
silence.
One thing not assumed. Both gate-house and approval-engine said our binding
slice canonicalizes principal and target, two of their five fields. target
plainly is act material and is now dropped. But their principal is the party ON
WHOSE BEHALF the approval was issued, while ours is the person being BOUND — the
approver. Different roles, and dropping ours would remove who was shown this
from view_hash and gut the promise. Kept it, declared principal_role_overlap
open in layer.yaml, tested that changing the approver still moves view_hash, and
raised it rather than silently resolving it either way.
L0/L2 are unaffected: with no approval there is no digest to defer to, and
test_act_scope_still_binds_when_there_is_no_carried_digest pins that.
100 tests pass.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01V3W1dQG7GFFM9d94jFx7iR
Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 1565372@bnt-lap001
Assistant-Session: 16bb2f25-b34c-49ef-8e94-5fec3567a568
2026-09-10 20:58:22 +02:00
|
|
|
view_hash CARRIES approval-engine's binding.digest as a field. That digest
|
|
|
|
|
is referenced, never recomputed or restated from this repository's own
|
|
|
|
|
vocabulary, and the act-scope is no longer independently canonicalized here
|
|
|
|
|
— so the act has exactly one canonicalization, computed by the layer that
|
|
|
|
|
owns it.
|
Apply GH-DEC-2026-015/016 and the audit-core registration; both blockers cleared
Origin and evidence path both landed today.
T07 origin: railiance-apps deployed decisions.coulomb.social and corrected the
hostname in this repo — not the decide.coulomb.social this workplan proposed.
Verified here rather than taken on report: both paths 200, TLS verify 0, Let's
Encrypt cert valid to 2026-12-09.
T08: audit-core registered the source with every field as proposed and landed
the detection half. INFD-IN-0003 closed. Their refinements booked — reconciliation
on the high-volume class too, since rate detects a stream stopping but never a
stream missing the particular renders that mattered, which is exactly our threat
model; and PR-12, the custody locator must be a stable non-secret identifier
because redact scans data and an existence declaration arriving without its
pointer looks complete while being useless.
INFD-IN-0004 ruled as GH-DEC-2026-015: gate-house reversed itself and nesting is
permitted for this pair. The decisive ground was not the cycle argument we led
with — our binding slice canonicalizes principal and target, two of the five
digest fields, so co-reference left us performing a partial recomputation of one
act in a second vocabulary, closer to the translation R3 forbade than nesting
is. Our ordering objection was withdrawn as mistaken.
The permission is conditioned and NOT ACTIVE until approval-engine states its
presentation exclusion as normative and tested. layer.yaml is deliberately
unchanged and carries nesting_permission_active false — we do not activate on
our own initiative.
GH-DEC-2026-016 ruled NC-03. Its §5 is live rather than hypothetical and is
booked as PR-11: principal_type: human is a property of the client registration,
structurally the same shape as the gap-route tenant, so a human-in-the-loop
control must not be discharged on it as verified humanity.
T07 stays progress: the submission to key-cape is written but unsent, blocked by
the local permission classifier rather than by any repository.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01V3W1dQG7GFFM9d94jFx7iR
Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 1565372@bnt-lap001
Assistant-Session: 16bb2f25-b34c-49ef-8e94-5fec3567a568
2026-09-10 19:19:10 +02:00
|
|
|
# GH-DEC-2026-015 (INFD-IN-0004) re-ruled: nesting is PERMITTED for this pair,
|
Activate nesting per GH-DEC-2026-015: view_hash carries binding.digest
approval-engine met the condition. Verified here rather than taken on report:
their docs/approval-claim.md carries "Presentation exclusion — GH-DEC-2026-015
§4" in normative language, and I ran
tests/test_claim_contract.py::test_presentation_changes_cannot_change_the_approved_act
myself — 1 passed. That test pins the digest input set from BOTH sides, and the
narrowing half is what makes it real: without it a digest over four fields, or
over a constant, would pass the widening half perfectly.
view_hash now carries binding.digest and the act-scope is no longer
independently canonicalized here, so the act has exactly one canonicalization
computed by the layer that owns it. approval_binding_digest is validated for
shape and refused without its approval id — it is carried, never computed.
The three published vectors are unchanged: they do not carry the new key, so
pick omits it. Asserted, not assumed.
The cycle condition did not disappear, its protection moved — from refusing
nesting to approval-engine's normative exclusion. layer.yaml carries it as
cycle_condition with a test, so a future widening meets a rule rather than
silence.
One thing not assumed. Both gate-house and approval-engine said our binding
slice canonicalizes principal and target, two of their five fields. target
plainly is act material and is now dropped. But their principal is the party ON
WHOSE BEHALF the approval was issued, while ours is the person being BOUND — the
approver. Different roles, and dropping ours would remove who was shown this
from view_hash and gut the promise. Kept it, declared principal_role_overlap
open in layer.yaml, tested that changing the approver still moves view_hash, and
raised it rather than silently resolving it either way.
L0/L2 are unaffected: with no approval there is no digest to defer to, and
test_act_scope_still_binds_when_there_is_no_carried_digest pins that.
100 tests pass.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01V3W1dQG7GFFM9d94jFx7iR
Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 1565372@bnt-lap001
Assistant-Session: 16bb2f25-b34c-49ef-8e94-5fec3567a568
2026-09-10 20:58:22 +02:00
|
|
|
# conditioned on approval-engine stating its presentation exclusion as
|
|
|
|
|
# NORMATIVE and TESTED rather than design intent.
|
Apply GH-DEC-2026-015/016 and the audit-core registration; both blockers cleared
Origin and evidence path both landed today.
T07 origin: railiance-apps deployed decisions.coulomb.social and corrected the
hostname in this repo — not the decide.coulomb.social this workplan proposed.
Verified here rather than taken on report: both paths 200, TLS verify 0, Let's
Encrypt cert valid to 2026-12-09.
T08: audit-core registered the source with every field as proposed and landed
the detection half. INFD-IN-0003 closed. Their refinements booked — reconciliation
on the high-volume class too, since rate detects a stream stopping but never a
stream missing the particular renders that mattered, which is exactly our threat
model; and PR-12, the custody locator must be a stable non-secret identifier
because redact scans data and an existence declaration arriving without its
pointer looks complete while being useless.
INFD-IN-0004 ruled as GH-DEC-2026-015: gate-house reversed itself and nesting is
permitted for this pair. The decisive ground was not the cycle argument we led
with — our binding slice canonicalizes principal and target, two of the five
digest fields, so co-reference left us performing a partial recomputation of one
act in a second vocabulary, closer to the translation R3 forbade than nesting
is. Our ordering objection was withdrawn as mistaken.
The permission is conditioned and NOT ACTIVE until approval-engine states its
presentation exclusion as normative and tested. layer.yaml is deliberately
unchanged and carries nesting_permission_active false — we do not activate on
our own initiative.
GH-DEC-2026-016 ruled NC-03. Its §5 is live rather than hypothetical and is
booked as PR-11: principal_type: human is a property of the client registration,
structurally the same shape as the gap-route tenant, so a human-in-the-loop
control must not be discharged on it as verified humanity.
T07 stays progress: the submission to key-cape is written but unsent, blocked by
the local permission classifier rather than by any repository.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01V3W1dQG7GFFM9d94jFx7iR
Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 1565372@bnt-lap001
Assistant-Session: 16bb2f25-b34c-49ef-8e94-5fec3567a568
2026-09-10 19:19:10 +02:00
|
|
|
#
|
Activate nesting per GH-DEC-2026-015: view_hash carries binding.digest
approval-engine met the condition. Verified here rather than taken on report:
their docs/approval-claim.md carries "Presentation exclusion — GH-DEC-2026-015
§4" in normative language, and I ran
tests/test_claim_contract.py::test_presentation_changes_cannot_change_the_approved_act
myself — 1 passed. That test pins the digest input set from BOTH sides, and the
narrowing half is what makes it real: without it a digest over four fields, or
over a constant, would pass the widening half perfectly.
view_hash now carries binding.digest and the act-scope is no longer
independently canonicalized here, so the act has exactly one canonicalization
computed by the layer that owns it. approval_binding_digest is validated for
shape and refused without its approval id — it is carried, never computed.
The three published vectors are unchanged: they do not carry the new key, so
pick omits it. Asserted, not assumed.
The cycle condition did not disappear, its protection moved — from refusing
nesting to approval-engine's normative exclusion. layer.yaml carries it as
cycle_condition with a test, so a future widening meets a rule rather than
silence.
One thing not assumed. Both gate-house and approval-engine said our binding
slice canonicalizes principal and target, two of their five fields. target
plainly is act material and is now dropped. But their principal is the party ON
WHOSE BEHALF the approval was issued, while ours is the person being BOUND — the
approver. Different roles, and dropping ours would remove who was shown this
from view_hash and gut the promise. Kept it, declared principal_role_overlap
open in layer.yaml, tested that changing the approver still moves view_hash, and
raised it rather than silently resolving it either way.
L0/L2 are unaffected: with no approval there is no digest to defer to, and
test_act_scope_still_binds_when_there_is_no_carried_digest pins that.
100 tests pass.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01V3W1dQG7GFFM9d94jFx7iR
Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 1565372@bnt-lap001
Assistant-Session: 16bb2f25-b34c-49ef-8e94-5fec3567a568
2026-09-10 20:58:22 +02:00
|
|
|
# ACTIVATED 2026-09-10, after verifying the condition here rather than taking
|
|
|
|
|
# it on report: approval-engine/docs/approval-claim.md carries "Presentation
|
|
|
|
|
# exclusion — GH-DEC-2026-015 §4" in normative language, and
|
|
|
|
|
# tests/test_claim_contract.py::test_presentation_changes_cannot_change_the_approved_act
|
|
|
|
|
# pins the input set from BOTH sides — widening (presentation material leaves
|
|
|
|
|
# the digest unchanged) and narrowing (each of the five act fields changes it).
|
|
|
|
|
# The narrowing half matters: without it a digest over four fields, or over a
|
|
|
|
|
# constant, would pass the widening half perfectly. Run and confirmed passing.
|
Apply GH-DEC-2026-015/016 and the audit-core registration; both blockers cleared
Origin and evidence path both landed today.
T07 origin: railiance-apps deployed decisions.coulomb.social and corrected the
hostname in this repo — not the decide.coulomb.social this workplan proposed.
Verified here rather than taken on report: both paths 200, TLS verify 0, Let's
Encrypt cert valid to 2026-12-09.
T08: audit-core registered the source with every field as proposed and landed
the detection half. INFD-IN-0003 closed. Their refinements booked — reconciliation
on the high-volume class too, since rate detects a stream stopping but never a
stream missing the particular renders that mattered, which is exactly our threat
model; and PR-12, the custody locator must be a stable non-secret identifier
because redact scans data and an existence declaration arriving without its
pointer looks complete while being useless.
INFD-IN-0004 ruled as GH-DEC-2026-015: gate-house reversed itself and nesting is
permitted for this pair. The decisive ground was not the cycle argument we led
with — our binding slice canonicalizes principal and target, two of the five
digest fields, so co-reference left us performing a partial recomputation of one
act in a second vocabulary, closer to the translation R3 forbade than nesting
is. Our ordering objection was withdrawn as mistaken.
The permission is conditioned and NOT ACTIVE until approval-engine states its
presentation exclusion as normative and tested. layer.yaml is deliberately
unchanged and carries nesting_permission_active false — we do not activate on
our own initiative.
GH-DEC-2026-016 ruled NC-03. Its §5 is live rather than hypothetical and is
booked as PR-11: principal_type: human is a property of the client registration,
structurally the same shape as the gap-route tenant, so a human-in-the-loop
control must not be discharged on it as verified humanity.
T07 stays progress: the submission to key-cape is written but unsent, blocked by
the local permission classifier rather than by any repository.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01V3W1dQG7GFFM9d94jFx7iR
Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 1565372@bnt-lap001
Assistant-Session: 16bb2f25-b34c-49ef-8e94-5fec3567a568
2026-09-10 19:19:10 +02:00
|
|
|
reruled_by: GH-DEC-2026-015
|
|
|
|
|
nesting_permitted_when: >-
|
|
|
|
|
approval-engine states the presentation exclusion from binding.digest as
|
Activate nesting per GH-DEC-2026-015: view_hash carries binding.digest
approval-engine met the condition. Verified here rather than taken on report:
their docs/approval-claim.md carries "Presentation exclusion — GH-DEC-2026-015
§4" in normative language, and I ran
tests/test_claim_contract.py::test_presentation_changes_cannot_change_the_approved_act
myself — 1 passed. That test pins the digest input set from BOTH sides, and the
narrowing half is what makes it real: without it a digest over four fields, or
over a constant, would pass the widening half perfectly.
view_hash now carries binding.digest and the act-scope is no longer
independently canonicalized here, so the act has exactly one canonicalization
computed by the layer that owns it. approval_binding_digest is validated for
shape and refused without its approval id — it is carried, never computed.
The three published vectors are unchanged: they do not carry the new key, so
pick omits it. Asserted, not assumed.
The cycle condition did not disappear, its protection moved — from refusing
nesting to approval-engine's normative exclusion. layer.yaml carries it as
cycle_condition with a test, so a future widening meets a rule rather than
silence.
One thing not assumed. Both gate-house and approval-engine said our binding
slice canonicalizes principal and target, two of their five fields. target
plainly is act material and is now dropped. But their principal is the party ON
WHOSE BEHALF the approval was issued, while ours is the person being BOUND — the
approver. Different roles, and dropping ours would remove who was shown this
from view_hash and gut the promise. Kept it, declared principal_role_overlap
open in layer.yaml, tested that changing the approver still moves view_hash, and
raised it rather than silently resolving it either way.
L0/L2 are unaffected: with no approval there is no digest to defer to, and
test_act_scope_still_binds_when_there_is_no_carried_digest pins that.
100 tests pass.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01V3W1dQG7GFFM9d94jFx7iR
Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 1565372@bnt-lap001
Assistant-Session: 16bb2f25-b34c-49ef-8e94-5fec3567a568
2026-09-10 20:58:22 +02:00
|
|
|
normative and tested.
|
|
|
|
|
nesting_permission_active: true
|
|
|
|
|
nesting_activated_at: "2026-09-10"
|
|
|
|
|
nesting_condition_evidence:
|
|
|
|
|
doc: approval-engine/docs/approval-claim.md#presentation-exclusion
|
|
|
|
|
test: tests/test_claim_contract.py::test_presentation_changes_cannot_change_the_approved_act
|
|
|
|
|
evidence_record: approval-engine/docs/evidence/2026-09-10-presentation-exclusion.json
|
|
|
|
|
# OPEN, raised with approval-engine rather than assumed. Their `principal` is
|
|
|
|
|
# the party ON WHOSE BEHALF the approval was issued; ours is the person being
|
|
|
|
|
# BOUND — the approver. Different roles, so this repository still commits its
|
|
|
|
|
# own principal in view_hash. Dropping it would remove *who was shown this*
|
|
|
|
|
# and gut the promise. If the two are the same field, ours drops too.
|
|
|
|
|
principal_role_overlap: open
|
|
|
|
|
# The cycle condition remains the thing to protect, and it is now protected by
|
|
|
|
|
# approval-engine's normative exclusion rather than by refusing nesting.
|
|
|
|
|
cycle_condition: >-
|
|
|
|
|
Mutual containment. view_hash carries binding.digest; binding.digest MUST
|
|
|
|
|
NOT cover presentation material, so containment stays one-directional and
|
|
|
|
|
the GH-DEC-2026-008 cycle cannot arise. If that exclusion is ever relaxed,
|
|
|
|
|
this linkage must be revisited before the widening ships — a fail-closed
|
|
|
|
|
consumer obeying a cyclic claim denies permanently.
|
Declare the layer per GH-DEC-2026-012; close T02
Gate House ruled all three questions within a day, attributing the speed to the
request being filed before the architecture with candidate answers and their
costs.
R1 PEP-shaped, confirmed as proposed. The ruling settles the shape; the layer
stays ours to declare, so layer.yaml is written in this repository's voice
rather than transcribed from the reply.
R2 yes to a presentation claim, no second catalog row, under three limits now
declared in layer.yaml and tested. Limit 2 — the claim must never be an input to
the decision it presents for — is load-bearing: our self-dealing argument was
accepted because it holds, not despite it. Limit 3 drives architecture, since
here the actor being audited and the evidence source are the same component.
R3 (b) with the authority rule: binding digest authoritative for what the
request is, view_hash only for what was shown, neither substitutable, and a
disagreement between them is a finding against the presenting surface rather
than a fact about the request. Linkage is co-reference; nesting was refused
because it reproduces the GH-DEC-2026-008 hash cycle.
Built to v0.8 obligation 3 rather than migrating later: axis enumerated, unknown
resolves to fail_closed, absent distinguishable from unknown in the record, and
published-equals-shipped asserted by test rather than claimed. Every stance is
fail_closed, which is a conclusion not a shortcut — ops-warden can justify
fail_open on a continuity argument that does not exist here.
GH-DEC-2026-010 inherited as a declared gap in four documents: a decision cannot
today be proven to have come from access-engine. The decision path must not be
described as validated while FLEX-WP-0024 is open.
46 tests pass. T05 and T07 unblocked.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01V3W1dQG7GFFM9d94jFx7iR
Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 1565372@bnt-lap001
Assistant-Session: 16bb2f25-b34c-49ef-8e94-5fec3567a568
2026-09-09 22:25:35 +02:00
|
|
|
|
2026-09-21 06:33:31 +02:00
|
|
|
# §5 applies to Staff, and this repository is now Staff by ruling — so the line
|
|
|
|
|
# below is the §11 mechanical check landing on it directly rather than by
|
|
|
|
|
# analogy. It is a browser-facing surface with no Tooling contact, so the check
|
|
|
|
|
# is total with an empty map and this repository is CONFORMING on §5, not
|
|
|
|
|
# blocked-clean and not a declared gap.
|
Declare the layer per GH-DEC-2026-012; close T02
Gate House ruled all three questions within a day, attributing the speed to the
request being filed before the architecture with candidate answers and their
costs.
R1 PEP-shaped, confirmed as proposed. The ruling settles the shape; the layer
stays ours to declare, so layer.yaml is written in this repository's voice
rather than transcribed from the reply.
R2 yes to a presentation claim, no second catalog row, under three limits now
declared in layer.yaml and tested. Limit 2 — the claim must never be an input to
the decision it presents for — is load-bearing: our self-dealing argument was
accepted because it holds, not despite it. Limit 3 drives architecture, since
here the actor being audited and the evidence source are the same component.
R3 (b) with the authority rule: binding digest authoritative for what the
request is, view_hash only for what was shown, neither substitutable, and a
disagreement between them is a finding against the presenting surface rather
than a fact about the request. Linkage is co-reference; nesting was refused
because it reproduces the GH-DEC-2026-008 hash cycle.
Built to v0.8 obligation 3 rather than migrating later: axis enumerated, unknown
resolves to fail_closed, absent distinguishable from unknown in the record, and
published-equals-shipped asserted by test rather than claimed. Every stance is
fail_closed, which is a conclusion not a shortcut — ops-warden can justify
fail_open on a continuity argument that does not exist here.
GH-DEC-2026-010 inherited as a declared gap in four documents: a decision cannot
today be proven to have come from access-engine. The decision path must not be
described as validated while FLEX-WP-0024 is open.
46 tests pass. T05 and T07 unblocked.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01V3W1dQG7GFFM9d94jFx7iR
Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 1565372@bnt-lap001
Assistant-Session: 16bb2f25-b34c-49ef-8e94-5fec3567a568
2026-09-09 22:25:35 +02:00
|
|
|
tooling_contacts: []
|
|
|
|
|
|
|
|
|
|
# §11 — record non-Tooling clients so the check is total.
|
|
|
|
|
non_tooling_clients: []
|
|
|
|
|
|
|
|
|
|
intended_non_tooling_clients:
|
|
|
|
|
- target: approval-engine
|
|
|
|
|
layer: engine
|
|
|
|
|
rationale: >-
|
|
|
|
|
GET /v1/approvals/{id} and /claim (approval:read) to render; POST
|
|
|
|
|
/v1/approvals/{id}/entries (approval:approve) to record a binding. Never
|
|
|
|
|
/consume. Requirements: approval-engine/docs/approver-surface-requirements.md.
|
|
|
|
|
- target: access-engine
|
|
|
|
|
layer: engine
|
|
|
|
|
rationale: >-
|
|
|
|
|
Decision consumed before rendering an approval to a person. A 200 from
|
|
|
|
|
approval-engine is not entitlement. This surface consumes a decision and
|
|
|
|
|
never renders one.
|
|
|
|
|
- target: key-cape
|
|
|
|
|
layer: engine
|
|
|
|
|
rationale: >-
|
|
|
|
|
Identity. Authorization-code + PKCE browser client. Identity is imported,
|
|
|
|
|
never invented here.
|
|
|
|
|
- target: audit-core
|
|
|
|
|
layer: engine
|
|
|
|
|
rationale: >-
|
|
|
|
|
Evidence destination for presentation records and dispositions. Must be an
|
|
|
|
|
independent path per limit L3-independent-evidence-path.
|
|
|
|
|
- target: state-hub
|
|
|
|
|
layer: not-catalogued
|
|
|
|
|
rationale: >-
|
|
|
|
|
Progress events. Outside §5 by the v0.5 scope rule. Recorded, not policed.
|
|
|
|
|
|
|
|
|
|
# §9.6 — presentation evidence is load-bearing: it is the only record of what a
|
|
|
|
|
# human was shown before binding. Atomicity and attestation cover accident and
|
|
|
|
|
# later tampering, never a compromised source.
|
|
|
|
|
evidence:
|
|
|
|
|
kind: load-bearing
|
|
|
|
|
residual: compromised-surface-presents-x-attests-y
|
|
|
|
|
residual_closed: false
|
|
|
|
|
custody: same-bound-as-every-other-source # §16 decided: no stronger archive
|
2026-09-21 06:33:31 +02:00
|
|
|
# A10 (GH-DEC-2026-018 §5) — emission is marked, never inferred. This
|
|
|
|
|
# repository EMITS into the estate's evidence stream; audit-core holds
|
|
|
|
|
# custody, which is disjoint from emission and discharges nothing of this
|
|
|
|
|
# emitter's guarantee.
|
|
|
|
|
emission_guarantee_owed: true
|
|
|
|
|
event_classes:
|
|
|
|
|
- id: presentation
|
|
|
|
|
kind: load-bearing
|
|
|
|
|
classification: volume
|
|
|
|
|
note: >-
|
|
|
|
|
One per render. Classified volume by this repository, which is the
|
|
|
|
|
classification a conformance run is SUPPLIED and MUST NOT infer.
|
|
|
|
|
- id: disposition
|
|
|
|
|
kind: load-bearing
|
|
|
|
|
classification: rare
|
|
|
|
|
note: >-
|
|
|
|
|
The binding act. Rare and security-relevant: heartbeat AND
|
|
|
|
|
reconciliation, never rate monitoring alone — a quiet month of
|
|
|
|
|
dispositions is indistinguishable from suppression by rate.
|
|
|
|
|
- id: stance-application
|
|
|
|
|
kind: load-bearing
|
|
|
|
|
classification: rare
|
|
|
|
|
note: Fail-closed stance applied at a binding attempt. Same form as disposition.
|
|
|
|
|
emission_guarantee_status: not-yet-declarable
|
|
|
|
|
emission_guarantee_blocked_on: >-
|
|
|
|
|
The local transactional outbox (§9.4) and the cadence declaration are
|
|
|
|
|
designed (docs/evidence-path-design.md §5) and depend on audit-core's
|
|
|
|
|
AUDIT-WP-0009 T04/T06 and on sender registration. Declared as owed rather
|
|
|
|
|
than described as operating.
|
Declare the layer per GH-DEC-2026-012; close T02
Gate House ruled all three questions within a day, attributing the speed to the
request being filed before the architecture with candidate answers and their
costs.
R1 PEP-shaped, confirmed as proposed. The ruling settles the shape; the layer
stays ours to declare, so layer.yaml is written in this repository's voice
rather than transcribed from the reply.
R2 yes to a presentation claim, no second catalog row, under three limits now
declared in layer.yaml and tested. Limit 2 — the claim must never be an input to
the decision it presents for — is load-bearing: our self-dealing argument was
accepted because it holds, not despite it. Limit 3 drives architecture, since
here the actor being audited and the evidence source are the same component.
R3 (b) with the authority rule: binding digest authoritative for what the
request is, view_hash only for what was shown, neither substitutable, and a
disagreement between them is a finding against the presenting surface rather
than a fact about the request. Linkage is co-reference; nesting was refused
because it reproduces the GH-DEC-2026-008 hash cycle.
Built to v0.8 obligation 3 rather than migrating later: axis enumerated, unknown
resolves to fail_closed, absent distinguishable from unknown in the record, and
published-equals-shipped asserted by test rather than claimed. Every stance is
fail_closed, which is a conclusion not a shortcut — ops-warden can justify
fail_open on a continuity argument that does not exist here.
GH-DEC-2026-010 inherited as a declared gap in four documents: a decision cannot
today be proven to have come from access-engine. The decision path must not be
described as validated while FLEX-WP-0024 is open.
46 tests pass. T05 and T07 unblocked.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01V3W1dQG7GFFM9d94jFx7iR
Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 1565372@bnt-lap001
Assistant-Session: 16bb2f25-b34c-49ef-8e94-5fec3567a568
2026-09-09 22:25:35 +02:00
|
|
|
note: >-
|
|
|
|
|
GH-DEC-2026-012 states the residual is not closed in those words, and this
|
|
|
|
|
repository is not credited with closing it. Same disposition as
|
|
|
|
|
approval-engine's equivalent residual for adversarial omission at a
|
|
|
|
|
compromised source.
|
|
|
|
|
|
|
|
|
|
# INHERITED DECLARED GAP — GH-DEC-2026-010.
|
|
|
|
|
#
|
|
|
|
|
# Obligation 1 now requires a decision be ATTRIBUTABLE to access-engine. No
|
|
|
|
|
# consumer can satisfy that today: flex-auth's decision envelope is unsigned.
|
|
|
|
|
# This is a declared §13 gap tracked as FLEX-WP-0024, not a clean path this
|
|
|
|
|
# repository can walk.
|
|
|
|
|
#
|
|
|
|
|
# Stated here, and in SCOPE.md and ArchitectureBlueprint.md, because
|
|
|
|
|
# GH-DEC-2026-012 requires it be said in this repository's own documents rather
|
|
|
|
|
# than describing validation as complete.
|
|
|
|
|
inherited_gaps:
|
|
|
|
|
- id: GH-DEC-2026-010-attributability
|
|
|
|
|
obligation: 1
|
|
|
|
|
gap: >-
|
|
|
|
|
A decision consumed from access-engine cannot today be proven to have come
|
|
|
|
|
from access-engine — the envelope is unsigned.
|
|
|
|
|
tracked_by: FLEX-WP-0024
|
|
|
|
|
consequence_here: >-
|
|
|
|
|
This surface's record can show that a decision was obtained and what it
|
|
|
|
|
said. It cannot yet show it was access-engine that said it. Validation of
|
|
|
|
|
the decision path MUST NOT be described as complete while this is open.
|
|
|
|
|
status: open
|
|
|
|
|
|
|
|
|
|
declared_shapes:
|
|
|
|
|
"5.1": []
|
|
|
|
|
"5.2": []
|
|
|
|
|
"5.3": []
|