Apply GH-DEC-2026-015/016 and the audit-core registration; both blockers cleared

Origin and evidence path both landed today.

T07 origin: railiance-apps deployed decisions.coulomb.social and corrected the
hostname in this repo — not the decide.coulomb.social this workplan proposed.
Verified here rather than taken on report: both paths 200, TLS verify 0, Let's
Encrypt cert valid to 2026-12-09.

T08: audit-core registered the source with every field as proposed and landed
the detection half. INFD-IN-0003 closed. Their refinements booked — reconciliation
on the high-volume class too, since rate detects a stream stopping but never a
stream missing the particular renders that mattered, which is exactly our threat
model; and PR-12, the custody locator must be a stable non-secret identifier
because redact scans data and an existence declaration arriving without its
pointer looks complete while being useless.

INFD-IN-0004 ruled as GH-DEC-2026-015: gate-house reversed itself and nesting is
permitted for this pair. The decisive ground was not the cycle argument we led
with — our binding slice canonicalizes principal and target, two of the five
digest fields, so co-reference left us performing a partial recomputation of one
act in a second vocabulary, closer to the translation R3 forbade than nesting
is. Our ordering objection was withdrawn as mistaken.

The permission is conditioned and NOT ACTIVE until approval-engine states its
presentation exclusion as normative and tested. layer.yaml is deliberately
unchanged and carries nesting_permission_active false — we do not activate on
our own initiative.

GH-DEC-2026-016 ruled NC-03. Its §5 is live rather than hypothetical and is
booked as PR-11: principal_type: human is a property of the client registration,
structurally the same shape as the gap-route tenant, so a human-in-the-loop
control must not be discharged on it as verified humanity.

T07 stays progress: the submission to key-cape is written but unsent, blocked by
the local permission classifier rather than by any repository.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01V3W1dQG7GFFM9d94jFx7iR

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 1565372@bnt-lap001
Assistant-Session: 16bb2f25-b34c-49ef-8e94-5fec3567a568
This commit is contained in:
tegwick 2026-09-10 19:19:10 +02:00
parent 1614f257b6
commit 1fb17aec6b
6 changed files with 210 additions and 13 deletions

View file

@ -192,6 +192,35 @@ registration's authority, which `GH-DEC-2026-013` permits only as a bounded gap.
undifferentiated or absent provenance is a validation failure, not a default.
`trace: GH-DEC-2026-013 §5; key-cape 329e48f`
**PR-11 [rev-3] — A human-in-the-loop control is never discharged on an
unverified assertion of humanity.**
`GH-DEC-2026-016` requires that where an approval is *declared* as discharging a
human-in-the-loop control, the approver must be a human principal and
`approval-engine` must refuse at bind time. Its §5 lands here: what makes a
principal `human` belongs to the identity layer and **inherits A-16** — if
`human` is reachable by two routes, the control must not be discharged on a
registration-supplied claim. Refusing a service principal while accepting an
unverified assertion of humanity moves the defect rather than closing it.
**This is live for us, not hypothetical.** `principal_type: human` is a property
of the *client registration*, the same shape as our registration-supplied
`tenant`. Until its provenance is distinguishable, this surface treats it as
registration-supplied and does not present it as verified humanity.
*Pass:* `principal_type` is stored with its provenance like `tenant` (PR-09); no
copy, export field or evidence record describes a bind as human-verified on the
strength of the claim alone.
`trace: GH-DEC-2026-016 §5; A-16 with the marker-independence rider; PR-09`
**PR-12 [rev-3] — The custody locator is a stable non-secret identifier.**
`audit-core` applies `secret_policy: redact`, which scans `data`. A
credentialed URL or secret-shaped path in the custody field is redacted out and
the existence declaration (PR-53) arrives without its pointer. It fails visibly
`details.redaction.paths` records it — but the declaration is then useless.
*Pass:* the custody locator is an identifier the custodian resolves, never a
credentialed URL; a redaction finding on the custody field is a build-breaking
defect, not a warning.
`trace: audit-core docs/informed-decision-source-registration.md`
**PR-10 — A memo renders question, requested act, binding level, brief and
consequences before any action control is reachable.**
*Pass:* the disposition controls are not operable until the brief region has