Finish KG-WP-0003: stream completeness and live qonto observation

Classify evidence as load-bearing or attributive, draft the emission-cadence
declaration for Taxonomy, treat silence as a stream finding, keep completeness
separate from record richness, forbid immune memory as a state plane, and make
containment proposals reconstructable to their origin. Observe real
qonto-assistant audit events; deny-class completeness stays unknown until the
source publishes a heartbeat.

Assistant: grok
Assistant-Session: 01a05ef1-9e5a-70f2-b0ff-0b05d6b38ae9
This commit is contained in:
tegwick 2026-09-02 00:11:57 +02:00
parent c85646dc3c
commit 9daea96c43
35 changed files with 2023 additions and 138 deletions

View file

@ -32,6 +32,28 @@ agent_principal_rules:
memory_is_not_a_state_plane: true
reconstructable_as_caller: true
# Honest split between what is mechanically checked and what remains an
# assertion. A claim in this file is not a test; the `form` column is.
agent_principal_rule_checks:
no_standing_credential:
form: test
checked_by: scripts/check_layer_conformance.py
tool_use_shapes:
form: assertion
note: >-
No third route is claimed. The Tooling-client scan covers the Tooling
half of "no third route". Distinguishing an Engine API call from an
ordinary Python call is not mechanical here; remaining assertion.
memory_is_not_a_state_plane:
form: test
checked_by: tests/test_immune_memory.py
reconstructable_as_caller:
form: mixed
tested: EffectorRequest origin fields (KG-WP-0003-T06)
remainder: >-
Full reconstructability of every agent action as the caller's is still
assertion; session and harness traces are glas-harness's.
catalog_entry:
owns:
- adaptive defence and judgment