Close INFD-IN-0001; design the independent evidence path; track both blockers

Housekeeping the ruling left behind, plus the one piece of blocked work that was
substantially ours to move.

INFD-IN-0001 closed with its resolution recorded, matching approval-engine's
IN-0002 form. It was still open after GH-DEC-2026-012 answered it.

INFD-IN-0003 and docs/evidence-path-design.md take up O-02, which was sitting in
the blueprint as "mechanism unchosen". Read independence and the local
transactional outbox are settled and not in question. The real question is what
travels, and it is sharper for us than for approval-engine because a
presentation record carries the brief and packet material actually shown to a
human. Three candidates with costs; proposal is commitment-only for Stage 1 —
hashes, principal, timestamps, acks, co-referenced approval id — which
discharges limit 3 and removes our ability to alter the record, while leaving us
able to erase the content. That residual is declared alongside the existing
compromised-surface one rather than papered over.

Deliberately not proposing the full binding document unilaterally: it would put
commercial and personal material into the audit fabric under retention and
export entitlements designed for audit events. That is a meaningful change in
what audit-core holds and is its owner's to accept, not ours to assume. The
third option, a separate evidence store, is refused here because that store has
no owner and inventing one routes around the §16 decision against stronger
archival custody.

Cadence declared and its form argued rather than copied: approval-engine's
heartbeat answer suits genuinely low-volume classes, but ours are mixed —
presentations are one per render, while dispositions and stance applications are
low-volume and are the security-relevant ones. Reconciliation per class as
primary, heartbeat for the low-volume classes. Depends on AUDIT-WP-0009 T04/T06;
declared, not claimed operating.

INFD-IN-0002 files the tenant blocker as a tracked record rather than leaving it
in message threads and a blueprint footnote. T07 and T08 now name their blocking
intakes.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01V3W1dQG7GFFM9d94jFx7iR

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 1565372@bnt-lap001
Assistant-Session: 16bb2f25-b34c-49ef-8e94-5fec3567a568
This commit is contained in:
tegwick 2026-09-09 23:19:27 +02:00
parent d50f480075
commit 024946e9da
5 changed files with 336 additions and 9 deletions

View file

@ -131,10 +131,19 @@ Consequences, binding on implementation:
4. **Atomicity covers accident, not compromise.** It does not close the residual
in `layer.yaml`, and must never be described as doing so.
Open for implementation: whether the independent path is `audit-core` pull,
a separately-credentialed push, or a third party drain. **T08 must not ship
without one chosen**, because "we will add the independent path later" is how
limit 3 quietly becomes limit 3-in-principle.
**Cadence is owed**, because `layer.yaml` declares presentation evidence
load-bearing (§9.6). The form differs from `approval-engine`'s: their classes are
genuinely low-volume, so a heartbeat is the answer. Ours are mixed —
presentations are high-volume (one per render), while dispositions and stance
applications are low-volume and are the security-relevant ones. Proposed:
reconciliation per class as the primary form, plus a heartbeat for the
low-volume classes, since a quiet month of dispositions is indistinguishable
from suppression by rate alone. Depends on `AUDIT-WP-0009` T04/T06; declared,
not claimed operating.
What travels is the open question — see `docs/evidence-path-design.md` and O-02.
**T08 must not ship without it chosen**, because "we will add the independent
path later" is how limit 3 quietly becomes limit 3-in-principle.
---
@ -236,8 +245,15 @@ condition that it holds *only* because registrations are static and
deployment-owned should be written into the contract, not left as reasoning in a
message.
**O-02 — The independent evidence path.** Its mechanism is unchosen. Must be
resolved before T08 ships.
**O-02 — The independent evidence path.** Design and decision request written:
`docs/evidence-path-design.md`, filed as `INFD-IN-0003`. Read independence and
the local transactional outbox are settled; the open question is **what
travels**, because a presentation record carries the brief and packet material
actually shown to a human. Proposal is commitment-only (hashes, principal,
timestamps, acks, co-referenced approval id) for Stage 1, with the erasure
residual declared rather than papered over. Awaiting `audit-core` on the payload
and the sender registration, and `gate-house` only if the content question is
doctrine. Must be resolved before T08 ships.
**O-03 — Requester identity for an engine-originated memo.** `approval-engine`
does not model a requester. Likely the approval's `principal`; needs confirming