Build the T08 domain core with the engine behind a seam

approval-engine APPROVAL-WP-0002-T01 is still progress and its namespace has no
pods, so the live end-to-end proof cannot run. Built everything that does not
depend on it, with the engine behind a Protocol plus a fake carrying its real
refusal semantics, so its arrival is a wiring change rather than a build.

- memo.py: the Decision Memo, versions, binding document. Principal, Scope,
  Awareness and Hat are dataclasses rather than dicts because the canonicalizer
  requires a shape and a missing key should fail at construction rather than
  deep inside hashing — which is exactly how it failed twice while building
  this. Field names follow the governed canonicalizer (item_id, severity,
  locator): the published vectors are the contract, so the object was aligned to
  them rather than the reverse.
- presentation.py: the sole writer of view_hash. One writer, one canonicalizer,
  one place to audit. Acknowledgment is an explicit method call and nothing
  infers it from scroll, dwell or focus.
- disposition.py: verbs and guards G_NOAGENT, G_STEP, G_PRES, G_ACK, G_REASONS,
  G_SEALED. accept is ABSENT from weak steps rather than present-and-disabled,
  because a greyed-out accept still teaches the wrong model. Only accept reaches
  the engine; a memo return is not represented there at all.
- provenance.py: claim routes per A-16. assert_human_control_dischargeable
  refuses a registration-supplied human, so PR-11's limitation fires at the
  point of use instead of sitting in a document.
- evidence.py: local outbox, commitment-only records carrying the
  GH-DEC-2026-014 §4 existence assertion, per-class reconciliation counts, and a
  custody-locator guard that rejects credentialed URLs (PR-12).
- approval_client.py: 409 duplicate_approver is success, 409 conflict terminal,
  503 fail-closed, approval:consume refused before a token is requested.

87 tests pass, including every negative case in the Use Case Catalog and that a
fail-closed outcome is recorded as a stance application with no verb field —
never as a decline, because the human did not make one.

T08 stays progress: the live proof is the remainder.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01V3W1dQG7GFFM9d94jFx7iR

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 1565372@bnt-lap001
Assistant-Session: 16bb2f25-b34c-49ef-8e94-5fec3567a568
This commit is contained in:
tegwick 2026-09-10 20:38:20 +02:00
parent 4379576abd
commit 9e1f77e32b
18 changed files with 1503 additions and 10 deletions

View file

@ -1,9 +1,27 @@
"""informed-decision — presentation and binding surface for decisions.
This package must never contain an authorization decision. See ``INTENT.md``
and ``AGENTS.md``: ``access-engine`` is the only policy decision point.
and ``AGENTS.md``: ``access-engine`` is the only policy decision point. What is
recorded here is evidence that a human performed an act, never a verdict on
whether the act was permitted.
"""
from .canonicalize import awareness_hash, view_hash
from .disposition import Actor, ActorKind, Disposition, DispositionRefused, Verb, legal_verbs, record
from .evidence import Commitment, EventClass, Outbox, heartbeat
from .memo import Awareness, BindingLevel, BindingSlice, Highlight, Memo, PacketItem, Principal, Scope, StepKind
from .presentation import Phase, Presentation, render
from .provenance import Claim, Route
from .stance import STANCE, resolve
__all__ = ["view_hash", "awareness_hash"]
__all__ = [
"view_hash", "awareness_hash",
"Memo", "BindingSlice", "Principal", "Scope", "PacketItem", "Highlight",
"Awareness", "BindingLevel", "StepKind",
"render", "Presentation", "Phase",
"record", "Disposition", "Verb", "Actor", "ActorKind", "DispositionRefused",
"legal_verbs",
"Outbox", "Commitment", "EventClass", "heartbeat",
"Claim", "Route",
"STANCE", "resolve",
]