Userinterface for executive decisions modeled as a sign and return book.
Find a file
tegwick 5c33d17330 Apply GH-DEC-2026-013 and GH-DEC-2026-014; close INFD-IN-0002
Two rulings landed and both corrected something.

GH-DEC-2026-013 accepted our binding-versus-awareness argument, wrote it into
the record as its §6, and did not change the outcome — it sharpened the defect.
Two different facts share one field named tenant: the act-scope, a property of
the act that our binding slice commits, and the principal's membership, a
property of the person that approval-engine exact-matches. Gate House's
correction stands: a binding slice that must commit the scope being entered
should commit that scope, not borrow a membership claim to stand in for it. Our
schema already does — binding.target IS the act-scope and is inside view_hash —
so no field was added, only a statement (PR-08) and a provenance record (PR-09),
since key-cape emits tenant as a bare string.

key-cape had already implemented registration-bound tenancy on 2026-09-09,
correct under both candidate rulings, so the fail-closed-at-first-use risk that
made us withhold the client strings was already retired. IN-0002 closed. The one
remaining input to T07 is the deployed origin.

GH-DEC-2026-014 granted commitment-only evidence and bounded it. It satisfies
non-alteration and NOT reconstructability, and must not be described otherwise
anywhere. It also corrected our wording of the gap: we wrote that it leaves us
able to erase the content, which understates it. Commitment-only moves integrity
out of our control and leaves availability entirely inside it — the party that
can withhold the content is the party the evidence is about. Limit 3's condition
reduced, not removed.

The grant carries a condition we did not propose and would not have thought of:
the path must assert that committed content exists and where custody sits, so
non-production is a finding attributable to the custodian rather than an
unremarkable blank. A commitment with no assertion that something is being
committed to is indistinguishable from a commitment to nothing. Booked as PR-53,
and marked not-a-reversal-candidate.

Recorded the meta-rule Gate House named, now in its third setting here: unknown
versus absent in the stance map, directory-asserted versus registration-supplied
in the tenant claim, erased versus never held in the evidence path. Wherever a
system reaches one appearance by two routes, the record must say which route.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01V3W1dQG7GFFM9d94jFx7iR

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 1565372@bnt-lap001
Assistant-Session: 16bb2f25-b34c-49ef-8e94-5fec3567a568
2026-09-10 07:57:57 +02:00
docs Apply GH-DEC-2026-013 and GH-DEC-2026-014; close INFD-IN-0002 2026-09-10 07:57:57 +02:00
history/20260909-initial-exploration Establish INTENT, Stage 1 GOAL, and founding workplan 2026-09-09 10:47:36 +02:00
informed_decision Declare the layer per GH-DEC-2026-012; close T02 2026-09-09 22:25:35 +02:00
intakes Apply GH-DEC-2026-013 and GH-DEC-2026-014; close INFD-IN-0002 2026-09-10 07:57:57 +02:00
schemas Promote schema and canonicalizer out of history; add EvidenceModel (T06) 2026-09-09 14:16:28 +02:00
tests Declare the layer per GH-DEC-2026-012; close T02 2026-09-09 22:25:35 +02:00
workplans Apply GH-DEC-2026-013 and GH-DEC-2026-014; close INFD-IN-0002 2026-09-10 07:57:57 +02:00
.custodian-brief.md chore(consistency): sync task status from DB [auto] 2026-09-09 22:29:41 +02:00
.repo-classification.yaml Use in-vocabulary capability tags 2026-09-09 12:40:50 +02:00
AGENTS.md Correct repo flavor to product; add SCOPE, AGENTS, classification 2026-09-09 12:38:41 +02:00
GOAL.md Declare the layer per GH-DEC-2026-012; close T02 2026-09-09 22:25:35 +02:00
INTENT.md Declare the layer per GH-DEC-2026-012; close T02 2026-09-09 22:25:35 +02:00
layer.yaml Declare the layer per GH-DEC-2026-012; close T02 2026-09-09 22:25:35 +02:00
Makefile Promote schema and canonicalizer out of history; add EvidenceModel (T06) 2026-09-09 14:16:28 +02:00
pep-stance.yaml Declare the layer per GH-DEC-2026-012; close T02 2026-09-09 22:25:35 +02:00
pyproject.toml Promote schema and canonicalizer out of history; add EvidenceModel (T06) 2026-09-09 14:16:28 +02:00
README.md Establish INTENT, Stage 1 GOAL, and founding workplan 2026-09-09 10:47:36 +02:00
SCOPE.md Apply GH-DEC-2026-013 and GH-DEC-2026-014; close INFD-IN-0002 2026-09-10 07:57:57 +02:00
WORK-RECORDS.md Sync intake ids and work records 2026-09-09 23:25:28 +02:00

informed-decision

User interface for executive decisions, modelled as a sign-and-return book — the German Umlaufmappe / Zeichnungsbuch, made cryptographic.

A Decision Memo carries a question, the context needed to answer it, the requested act, and a binding between identity, what was shown, and what was bound. The promise is not "the file was signed" but "this person, in this role, was shown this view, and bound this act."

One object model from a ten-second login (L0) to a multi-party instrument (L5).

Where to start

File What it is
INTENT.md Why this repository exists and what it must never become
GOAL.md The current stage, its invariants, and its definition of done
workplans/ Current work
history/20260909-initial-exploration/ Founding exploration — schema, state transitions, canonicalization, vectors

Stage 1

Own the browser-facing approver UI that approval-engine deliberately does not contain, and answer in writing who owns it. approval-engine is a bearer-token resource server with no browser client; key-cape (KEY-WP-0013-T02) is waiting on a client_id and callback URI that no component has claimed. This repository claims them.

See GOAL.md.

Boundaries

This repository renders questions and records answers. It does not decide (access-engine), does not own the approval object (approval-engine), does not author approval doctrine (gate-house), does not authenticate anyone (key-cape), and does not archive the trail (audit-core).