diff --git a/wiki/ApprovalConsumption.md b/wiki/ApprovalConsumption.md index fb1c695..e0b2e6a 100644 --- a/wiki/ApprovalConsumption.md +++ b/wiki/ApprovalConsumption.md @@ -23,6 +23,14 @@ v0.8 §6.4 obligation 5 hardened this: each artifact **must** be validated again the layer that owns its data, and a PIP **must not** republish the PDP's decision. Neither artifact may be taken from the other. +**One narrow exception now exists (`GH-DEC-2026-015`, 2026-09-10).** It revised +`GH-DEC-2026-012`'s R3 to permit nesting a binding digest inside a presentation +hash **for one specific pair, conditioned**. It does not reach this lane and +requires nothing here. It is recorded on this page for one reason: if a composed +artifact ever appears on the approval path, read it as a permission that may +exist rather than as a violation of the rule above — and then go and check which +pair the permission covers, because it is not general. + ## Three things that are easy to get wrong **1. Do not require `provenance.authority == 'state-hub'`.**