Assistant: codex Assistant-Model: gpt-6-astra Assistant-Session: 01a0e76f-be98-7ae3-965d-e0b31290a4c4
27 lines
1.5 KiB
Markdown
27 lines
1.5 KiB
Markdown
# Synthetic generalisation contracts — 2026-09-28
|
|
|
|
These contracts are written before the corresponding lab implementations for
|
|
TD-WP-0003-T02. They are agent-authored research specifications, not externally
|
|
validated product requirements. Scenario claims use `agent-from-spec` and refer
|
|
here. Same-session authorship limits epistemic independence; passing these labs
|
|
must not be presented as independent validation of a real product.
|
|
|
|
## Delegated approval
|
|
|
|
A requester submits a request for review. Only the assigned reviewer can delegate
|
|
it to another reviewer. The requester cannot approve their own request; the
|
|
former reviewer loses approval authority after delegation. The delegate may
|
|
approve only after submission, and only the requester may then execute it.
|
|
Premature execution and unauthorized approval are refused without state change.
|
|
The persisted workflow and the independently probed execution gate must agree.
|
|
A complete run includes premature execution, submission, delegation, attempted
|
|
self-approval, former-reviewer approval, delegate approval and execution.
|
|
|
|
## Tenant lifecycle
|
|
|
|
Two tenant administrators independently use the same local resource name `R`.
|
|
Each can create, read and delete their own tenant's instance. Neither may read or
|
|
delete the other tenant's instance, including by supplying an explicit foreign
|
|
tenant id. Deleting tenant A's instance preserves tenant B's content. Recreating
|
|
A's instance must not resurrect its old content or affect B. At every step,
|
|
foreign reads remain denied and successful reads match the stored tenant record.
|