From 71d1dc4e0f28b0cda7635f21a2c1dbd746971e6e Mon Sep 17 00:00:00 2001 From: Vantio Date: Tue, 29 Sep 2026 02:33:48 -0400 Subject: [PATCH] remedi(ghx): remove private program material from the public tip Take non-public program registers and program trees off the default branch without rewriting history. The public release checker now reads sealed pins that this tree already records. --- .github/workflows/w3-lab-teardown-verify.yml | 2 - docs/governance/LEGACY-STALE-NAMES.json | 47 +- docs/internal/c8-teardown/README.md | 138 -- .../internal/claim-scrub-report-2026-09-20.md | 118 -- .../00-INVENTORY.md | 55 - .../01-BOUNDARY.md | 30 - .../02-ARCHITECTURE.md | 30 - .../DISCLOSURE-RECORD.json | 250 --- .../GITHUB-SUPPORT-PURGE-PACKET.md | 58 - .../INDEPENDENT-COUNCIL.md | 26 - .../internal/enterprise-e1-e3/00-INVENTORY.md | 37 - docs/internal/enterprise-e1-e3/01-BOUNDARY.md | 36 - .../enterprise-e1-e3/02-ARCHITECTURE.md | 95 - .../03-IMPLEMENTATION-REPORT.md | 91 - .../enterprise-e1-e3/04-PENDING-COUNCIL.md | 46 - docs/internal/enterprise-e1-e3/STATUS.json | 71 - .../governance-assurance/00-BOUNDARY.md | 61 - .../08-VERSION-PROCEDURE.md | 24 - .../governance-assurance/09-DISCLOSURE.md | 21 - .../governance-assurance/overlays/README.md | 13 - .../reports/CONTROL_EVIDENCE_INDEX.json | 1131 ----------- .../CUSTOMER_RESPONSIBILITY_MATRIX.json | 728 ------- .../reports/FRAMEWORK_VERSION_REGISTER.json | 598 ------ .../reports/GOVERNANCE_POSTURE.json | 1725 ----------------- .../reports/GOVERNANCE_POSTURE.md | 677 ------- .../reports/PROCUREMENT_EVIDENCE_INDEX.json | 92 - .../reports/PUBLIC_DISCLOSURE.json | 10 - .../UNSUPPORTED_AND_EXTERNAL_CONTROLS.json | 182 -- .../reports/VERIFICATION_INSTRUCTIONS.md | 24 - .../stage-b/C6-REBIND.json | 185 -- .../governance-assurance/views/eu-ai-act.md | 21 - .../views/iso-iec-42001.md | 48 - .../views/nist-ai-agent-standards.md | 30 - .../views/nist-ai-rmf-playbook.md | 48 - .../governance-assurance/views/nist-ai-rmf.md | 48 - .../governance-assurance/views/us-federal.md | 53 - docs/internal/hiring/README.md | 16 - .../hiring/cto-evaluation/FRAMEWORK-STUB.md | 37 - .../hiring/head-of-product/COMPENSATION.md | 25 - .../hiring/head-of-product/INTERVIEW-LOOP.md | 30 - .../head-of-product/NINETY-DAY-OUTCOMES.md | 42 - .../hiring/head-of-product/OFFER-BOUNDARY.md | 50 - .../hiring/head-of-product/PACKAGE.json | 36 - .../internal/hiring/head-of-product/README.md | 48 - .../hiring/head-of-product/RED-FLAGS.md | 22 - .../ROLE-AND-RESPONSIBILITIES.md | 66 - .../hiring/head-of-product/SCORECARD.md | 43 - .../investor-demo-wave2/00-BOUNDARY.md | 44 - .../investor-demo-wave2/01-INVENTORY.md | 28 - .../investor-demo-wave2/02-ARCHITECTURE.md | 66 - .../03-IMPLEMENTATION-REPORT.md | 36 - .../investor-demo-wave2/04-COUNCIL-SLOT.md | 21 - .../investor-demo-wave2/WAVE2-MANIFEST.json | 107 - docs/internal/optics-best-in-class-roadmap.md | 1006 ---------- .../optics-cli-post-0324-cx-backlog.md | 16 - .../internal/optics-o7/00-BINDING-DECISION.md | 266 --- .../optics-o7/10-RUNTIME-INTEGRATION.md | 29 - docs/internal/optics-o7/BINDING-DECISION.json | 87 - .../optics-o7/RUNTIME-INTEGRATION.json | 45 - docs/internal/optics-pkg01/BOUNDARY.md | 120 -- docs/internal/optics-pkg01/COMPATIBILITY.md | 15 - docs/internal/optics-pkg01/CONFORMANCE.md | 24 - docs/internal/optics-pkg01/FAIL-OPEN.md | 13 - docs/internal/optics-pkg01/FIELD-CATALOG.md | 13 - .../optics-pkg01/IMPLEMENTATION-REPORT.md | 109 -- .../INDEPENDENT-COUNCIL-REPORT.md | 150 -- ...PENDENT-PINNED-UNICODE-RECOUNCIL-REPORT.md | 230 --- .../INDEPENDENT-RECOUNCIL-REPORT.md | 178 -- .../optics-pkg01/KNOWN-LIMITATIONS.md | 21 - docs/internal/optics-pkg01/PENDING-COUNCIL.md | 39 - .../optics-pkg01/PRIVACY-DISPOSITIONS.md | 55 - .../ARCHITECTURE-COUNCIL-NOTES.md | 65 - .../BOUNDARY.md | 36 - .../DESIGN.md | 27 - .../GATE-CATALOG.md | 23 - .../IMPLEMENTATION-REPORT.md | 42 - .../INVENTORY.md | 38 - .../KNOWN-LIMITATIONS.md | 14 - .../NO-WRITER.md | 17 - docs/internal/optics-pkg02-unit-a/ALIASES.md | 47 - docs/internal/optics-pkg02-unit-a/BOUNDARY.md | 38 - .../COMPATIBILITY-FIXTURES.md | 57 - .../IMPLEMENTATION-REPORT.md | 67 - .../optics-pkg02-unit-a/KNOWN-LIMITATIONS.md | 20 - .../NO-OPTIMISTIC-DEFAULTS.md | 37 - .../optics-pkg02-unit-a/VOCABULARY.md | 61 - docs/internal/optics-pkg02-unit-b/BOUNDARY.md | 37 - .../COMPATIBILITY-FIXTURES.md | 15 - docs/internal/optics-pkg02-unit-b/DESIGN.md | 42 - .../IMPLEMENTATION-REPORT.md | 46 - .../optics-pkg02-unit-b/KNOWN-LIMITATIONS.md | 17 - .../NO-OPTIMISTIC-DEFAULTS.md | 32 - docs/internal/optics-pkg02-unit-b/PRIVACY.md | 15 - docs/internal/optics-pkg02-unit-c/ADAPTER.md | 19 - docs/internal/optics-pkg02-unit-c/BOUNDARY.md | 35 - docs/internal/optics-pkg02-unit-c/DESIGN.md | 38 - .../optics-pkg02-unit-c/FIXTURE-SCORE.md | 26 - .../IMPLEMENTATION-REPORT.md | 42 - .../internal/optics-pkg02-unit-c/INVENTORY.md | 31 - .../optics-pkg02-unit-c/KNOWN-LIMITATIONS.md | 15 - .../internal/optics-pkg02-unit-c/NO-WRITER.md | 15 - docs/internal/optics-pkg02-unit-d/BOUNDARY.md | 37 - docs/internal/optics-pkg02-unit-d/DELTA.md | 22 - docs/internal/optics-pkg02-unit-d/DESIGN.md | 19 - .../IMPLEMENTATION-REPORT.md | 44 - .../INTERNAL-RELEASE-NOTE.md | 15 - .../optics-pkg02-unit-d/KNOWN-LIMITATIONS.md | 17 - .../NO-OPTIMISTIC-DEFAULTS.md | 22 - .../ORDINARY-CLIENT-PROOF.md | 21 - docs/internal/optics-pkg02-unit-d/PRIVACY.md | 15 - docs/internal/optics-pkg02-unit-d/ROLLBACK.md | 17 - docs/internal/optics-pkg02-unit-e/BOUNDARY.md | 28 - docs/internal/optics-pkg02-unit-e/DESIGN.md | 32 - .../IMPLEMENTATION-REPORT.md | 30 - .../optics-pkg02-unit-e/KNOWN-LIMITATIONS.md | 13 - .../optics-pkg02-unit-e/MATRIX-MARKERS.json | 97 - .../NO-OPTIMISTIC-DEFAULTS.md | 15 - .../ORDINARY-CLIENT-PROOF.md | 23 - .../optics-pkg02-unit-e/RECORD-DELTA.md | 26 - docs/internal/optics-pkg02-unit-e/ROLLBACK.md | 11 - docs/internal/optics-pkg02-unit-f/BOUNDARY.md | 36 - .../optics-pkg02-unit-f/COMPATIBILITY.md | 21 - docs/internal/optics-pkg02-unit-f/DESIGN.md | 30 - .../IMPLEMENTATION-REPORT.md | 40 - .../optics-pkg02-unit-f/KNOWN-LIMITATIONS.md | 14 - .../NO-OPTIMISTIC-DEFAULTS.md | 29 - .../ORDINARY-CLIENT-PROOF.md | 18 - docs/internal/optics-pkg02-unit-f/PRIVACY.md | 15 - docs/internal/pe-egress/00-INVENTORY.md | 48 - docs/internal/pe-egress/01-BOUNDARY.md | 32 - docs/internal/pe-egress/02-ARCHITECTURE.md | 58 - docs/internal/pe-egress/03-PENDING-COUNCIL.md | 24 - docs/internal/pe-egress/EGRESS-MANIFEST.json | 38 - .../pe-egress/IMPLEMENTATION-REPORT.md | 39 - .../internal/pe-host-authority/00-BOUNDARY.md | 71 - .../01-MECHANISM-COVERAGE.md | 89 - .../pe-host-authority/02-LOCAL-PROOF.md | 45 - .../HOST-AUTHORITY-MANIFEST.json | 39 - .../pe-host-authority/INDEPENDENT-COUNCIL.md | 57 - docs/internal/pe-ingress/00-BOUNDARY.md | 53 - docs/internal/pe-ingress/01-INVENTORY.md | 52 - docs/internal/pe-ingress/02-ARCHITECTURE.md | 43 - .../pe-ingress/03-AUTHORITY-CONTRACT.md | 84 - .../internal/pe-ingress/04-REVOKE-RECOVERY.md | 39 - .../pe-ingress/05-UNSUPPORTED-AND-HEALTH.md | 49 - .../pe-ingress/06-IMPLEMENTATION-REPORT.md | 35 - .../internal/pe-ingress/07-PENDING-COUNCIL.md | 56 - .../internal/pe-ingress/INGRESS-MANIFEST.json | 50 - .../pe-progressive-enforcement/00-BOUNDARY.md | 54 - .../01-LIFECYCLE.md | 56 - .../pe-progressive-enforcement/02-GATES.md | 27 - .../03-KNOWN-LIMITATIONS.md | 15 - .../04-IMPLEMENTATION-REPORT.md | 29 - .../05-COUNCIL-SLOT.md | 21 - .../pe-progressive-enforcement/MANIFEST.json | 45 - .../pe-sequential-authority/BOUNDARY.md | 59 - .../pe-sequential-authority/DESIGN.md | 67 - .../IMPLEMENTATION-REPORT.md | 58 - .../pe-sequential-authority/INVARIANTS.md | 29 - .../KNOWN-LIMITATIONS.md | 25 - .../NO-OPTIMISTIC-DEFAULTS.md | 20 - .../PENDING-COUNCIL.md | 21 - docs/internal/python-3.1.0-stage2-backlog.md | 55 - .../shared-health-runtime/ARCHITECTURE.md | 104 - .../shared-health-runtime/BOUNDARY.md | 44 - .../INDEPENDENT-COUNCIL.md | 33 - .../wave3/claim-inventory/00-BOUNDARY.md | 27 - .../wave3/claim-inventory/01-METHOD.md | 26 - .../wave3/claim-inventory/02-DISPOSITIONS.md | 18 - .../wave3/claim-inventory/03-DRIFT.md | 26 - .../wave3/claim-inventory/04-FREEZE.md | 27 - docs/internal/wave3/claim-inventory/README.md | 19 - .../internal/wave3/clean-host/00-POD-PROBE.md | 81 - .../wave3/clean-host/01-CANDIDATE-PLANES.md | 61 - .../wave3/enterprise-runtime/00-BOUNDARY.md | 50 - .../enterprise-runtime/01-ARCHITECTURE.md | 21 - .../enterprise-runtime/02-STATE-SEPARATION.md | 20 - .../03-IMPLEMENTATION-REPORT.md | 47 - .../enterprise-runtime/04-PENDING-COUNCIL.md | 17 - .../INTEGRATION-REGISTER.json | 165 -- .../enterprise-runtime/RUNTIME-REGISTER.json | 74 - .../wave3/enterprise-runtime/STATUS.json | 59 - .../otlp-enable-test-disable/00-BOUNDARY.md | 44 - .../otlp-enable-test-disable/01-HARNESS.md | 36 - .../02-WS7-HONESTY.md | 19 - .../03-IMPLEMENTATION-REPORT.md | 46 - .../04-PENDING-COUNCIL.md | 16 - .../REST-REGISTER.json | 64 - .../wave3/pe-integration/00-BOUNDARY.md | 50 - .../wave3/pe-integration/01-ARCHITECTURE.md | 25 - .../pe-integration/02-STATE-SEPARATION.md | 27 - .../03-IMPLEMENTATION-REPORT.md | 39 - .../pe-integration/04-PENDING-COUNCIL.md | 16 - .../pe-integration/INTEGRATION-REGISTER.json | 246 --- .../pe-integration/RUNTIME-REGISTER.json | 73 - .../internal/wave3/performance/00-BOUNDARY.md | 56 - docs/internal/wave3/performance/01-METHOD.md | 80 - .../wave3/performance/02-ENVIRONMENT.md | 53 - .../wave3/performance/03-PENDING-COUNCIL.md | 14 - .../performance/PERFORMANCE-REGISTER.json | 729 ------- .../wave3/performance/scripts/qualify.mjs | 843 -------- .../wave3/product-health/00-BOUNDARY.md | 51 - .../wave3/product-health/01-READING.md | 39 - .../wave3/product-health/02-FAILURE-TRUTH.md | 28 - .../03-IMPLEMENTATION-REPORT.md | 47 - .../product-health/04-PENDING-COUNCIL.md | 23 - .../product-health/INTEGRATION-REGISTER.json | 133 -- .../product-health/RUNTIME-REGISTER.json | 70 - .../internal/wave3/product-health/STATUS.json | 52 - .../wave3/public-inventory/00-BOUNDARY.md | 24 - .../wave3/public-inventory/01-METHOD.md | 27 - .../wave3/public-inventory/02-WEBSITE.md | 72 - .../wave3/public-inventory/03-GITHUB.md | 55 - .../internal/wave3/public-inventory/04-NPM.md | 24 - .../wave3/public-inventory/05-PYPI.md | 30 - .../public-inventory/06-OTHER-SURFACES.md | 42 - .../wave3/public-inventory/07-DRIFT.md | 28 - .../internal/wave3/public-inventory/README.md | 20 - docs/internal/ws7-otel-i3/00-INVENTORY.md | 44 - docs/internal/ws7-otel-i3/01-BOUNDARY.md | 42 - .../02-ARCHITECTURE-COUNCIL-NOTES.md | 104 - docs/internal/ws7-otel-i3/03-ADAPTER.md | 53 - .../ws7-otel-i3/ADAPTER-MANIFEST.json | 26 - .../ws7-otel-i3/IMPLEMENTATION-REPORT.md | 45 - docs/internal/ws7-otel-mapping/00-BOUNDARY.md | 58 - .../ws7-otel-mapping/01-SEMANTIC-MAPPING.md | 123 -- .../02-ADAPTER-STUB-BOUNDARIES.md | 61 - .../ws7-otel-mapping/03-PENDING-COUNCIL.md | 13 - .../ws7-otel-mapping/IMPLEMENTATION-REPORT.md | 55 - .../ws7-otel-mapping/MAPPING-MANIFEST.json | 17 - .../production-readiness/CLAIM-LEDGER.json | 301 --- .../production-readiness/COMPANY-GATES.json | 90 - .../DECISION-REGISTER.json | 150 -- .../production-readiness/DEMO-READINESS.json | 45 - .../DEPENDENCY-GRAPH.json | 366 ---- .../production-readiness/EXECUTIVE-REPORT.md | 62 - .../EXTERNAL-DEPENDENCIES.json | 92 - .../INVESTOR-READINESS.json | 72 - .../production-readiness/MASTER-MANIFEST.json | 238 --- .../production-readiness/PILOT-READINESS.json | 56 - .../RELEASE-REGISTER.json | 138 -- .../production-readiness/RISK-REGISTER.json | 110 -- .../WORKSTREAM-REGISTRY.json | 604 ------ .../authority/00-INVENTORY.md | 34 - .../authority/01-BOUNDARY.md | 72 - .../02-ARCHITECTURE-COUNCIL-NOTES.md | 49 - .../authority/WAVE2-AUTHORITY.json | 315 --- .../production-readiness/demo/00-BOUNDARY.md | 72 - .../demo/01-SIMULATION-LABEL-RULE.md | 62 - .../demo/02-STORY-BEATS.md | 62 - .../demo/03-DEMO-SCRIPT.md | 117 -- .../demo/04-OPERATOR-RUNBOOK.md | 48 - .../demo/05-RESET-OUTLINE.md | 40 - .../demo/06-EXPECTED-OUTPUTS.md | 149 -- .../demo/07-FAILURE-INJECTION-OUTLINE.md | 65 - .../demo/08-CLAIM-LEDGER.json | 189 -- .../demo/09-LIMITATION-LEDGER.json | 98 - .../demo/10-WAVE2-SCAFFOLD.md | 36 - .../demo/11-COUNCIL-SLOT.md | 29 - .../demo/DEMO-MANIFEST.json | 106 - .../demo/scaffolding/README.md | 11 - .../scaffolding/labeled-event-envelope.json | 15 - .../diligence/00-ROOM-BOUNDARY.md | 97 - .../diligence/01-TIERS.md | 46 - .../diligence/02-CATEGORY-THESIS.md | 48 - .../diligence/03-PRODUCT-LADDER.md | 48 - .../diligence/04-ARCHITECTURE.md | 50 - .../diligence/05-THREAT-MODEL.md | 52 - .../diligence/06-PRIVACY-MODEL.md | 62 - .../diligence/07-CLAIM-LEDGER.md | 52 - .../diligence/08-PROOF-TAXONOMY.md | 49 - .../diligence/09-CAPABILITIES.md | 56 - .../diligence/10-TARGET-ARCHITECTURE.md | 54 - .../diligence/11-BUILD-STATUS.md | 51 - .../diligence/12-DEMO-GUIDE.md | 59 - .../diligence/13-TECHNICAL-APPENDIX.md | 50 - .../diligence/14-RELEASE-DISCIPLINE.md | 46 - .../diligence/15-DEPLOYMENT.md | 50 - .../diligence/16-PILOT.md | 47 - .../diligence/17-DESIGN-PARTNER.md | 43 - .../diligence/18-STRANGER-HOST-GATE.md | 55 - .../diligence/19-ROADMAP.md | 43 - .../diligence/20-DIFFERENTIATION.md | 42 - .../diligence/21-USE-OF-FUNDS.md | 53 - .../diligence/22-HIRING-PLAN.md | 50 - .../diligence/23-EVIDENCE-INDEX.md | 43 - .../diligence/24-LIMITATIONS.md | 63 - .../diligence/25-RISKS.md | 46 - .../diligence/DILIGENCE-MANIFEST.json | 287 --- .../production-readiness/diligence/README.md | 69 - .../production-readiness/wave3/00-BOUNDARY.md | 32 - .../wave3/02-INDEPENDENT-COUNCIL.md | 27 - .../production-readiness/wave3/03-BOUNDARY.md | 37 - .../production-readiness/wave3/04-BOUNDARY.md | 64 - .../wave3/05-PRODUCT-HEALTH-FAILURE-TRUTH.md | 34 - .../production-readiness/wave3/10-COUNCIL.md | 59 - .../wave3/BLOCKED-INFRA.json | 64 - .../wave3/CLAIM-AND-VERSION-NOTES.md | 30 - .../wave3/CLEAN-HOST-REGISTER.md | 114 -- .../wave3/ELIGIBILITY-PACKET.md | 67 - .../ENTERPRISE-INTEGRATION-REGISTER.json | 165 -- .../wave3/ENTERPRISE-RUNTIME-REGISTER.json | 74 - .../wave3/ENTERPRISE-RUNTIME-STATUS.json | 59 - .../wave3/ENTERPRISE-RUNTIME.md | 21 - .../wave3/INTEGRATION-REGISTER.json | 246 --- .../wave3/O7-NODE-BINDING-DECISION.json | 60 - .../wave3/OTLP-ENABLE-TEST-DISABLE.md | 17 - .../wave3/OTLP-REST-REGISTER.json | 64 - .../wave3/PE-INTEGRATED-RUNTIME.md | 24 - .../wave3/PERFORMANCE-COUNCIL.md | 26 - .../wave3/PERFORMANCE-QUALIFICATION.md | 37 - .../wave3/PERFORMANCE-REGISTER.json | 729 ------- .../production-readiness/wave3/README.md | 9 - .../wave3/RUNTIME-REGISTER.json | 73 - .../production-readiness/wave3/STATUS.json | 38 - .../wave3/WAVE3-TRACK4-MANIFEST.json | 52 - .../product-health/INTEGRATION-REGISTER.json | 133 -- .../product-health/RUNTIME-REGISTER.json | 70 - .../wave3/product-health/STATUS.json | 52 - .../release-engineering/00-INVENTORY.md | 8 +- .../release-engineering/01-BOUNDARY.md | 2 +- .../SEALED-RELEASE-PINS.json | 18 + .../generated/manifest-license-scan.json | 35 - .../generated/open-core-sbom.cdx.json | 35 - docs/scripts/disclosure-review.mjs | 58 + internal/enterprise-governance/README.md | 17 - internal/enterprise-governance/package.json | 17 - .../enterprise-governance/src/boundary.cjs | 136 -- internal/enterprise-governance/src/engine.cjs | 1415 -------------- .../enterprise-governance/src/envelope.cjs | 297 --- internal/enterprise-governance/src/index.cjs | 60 - internal/enterprise-governance/src/scan.cjs | 96 - .../enterprise-runtime-integration/README.md | 9 - .../package.json | 17 - .../src/boundary.cjs | 225 --- .../src/compose.cjs | 633 ------ .../src/index.cjs | 29 - .../src/project.cjs | 191 -- .../src/registers.cjs | 103 - internal/pe-integrated-runtime/README.md | 11 - internal/pe-integrated-runtime/package.json | 17 - .../pe-integrated-runtime/src/boundary.cjs | 224 --- internal/pe-integrated-runtime/src/index.cjs | 29 - .../src/product-health.cjs | 568 ------ .../pe-integrated-runtime/src/project.cjs | 217 --- .../pe-integrated-runtime/src/registers.cjs | 70 - .../pe-integrated-runtime/src/runtime.cjs | 807 -------- .../w3-otlp-enable-test-disable/README.md | 15 - .../w3-otlp-enable-test-disable/package.json | 17 - .../src/attempts.cjs | 325 ---- .../src/boundary.cjs | 81 - .../w3-otlp-enable-test-disable/src/cycle.cjs | 157 -- .../w3-otlp-enable-test-disable/src/index.cjs | 19 - .../src/records.cjs | 96 - .../src/registers.cjs | 95 - .../w3-otlp-enable-test-disable/src/rest.cjs | 93 - internal/wave3-claim-inventory/freeze.cjs | 135 -- packages/investor-demo-wave2/README.md | 21 - .../investor-demo-wave2/bin/investor-demo.cjs | 63 - packages/investor-demo-wave2/package.json | 20 - .../investor-demo-wave2/src/canonical.cjs | 32 - .../investor-demo-wave2/src/cli-probe.cjs | 230 --- .../investor-demo-wave2/src/constants.cjs | 121 -- packages/investor-demo-wave2/src/index.cjs | 27 - packages/investor-demo-wave2/src/model.cjs | 162 -- packages/investor-demo-wave2/src/report.cjs | 27 - packages/investor-demo-wave2/src/safety.cjs | 203 -- packages/investor-demo-wave2/src/session.cjs | 685 ------- packages/investor-demo-wave2/src/verify.cjs | 130 -- scripts/aws/test_w3_lab_teardown_workflow.py | 34 +- scripts/release/ws11/inventory.mjs | 12 +- .../adversarial.test.mjs | 11 +- .../direct.test.mjs | 14 +- tests/enterprise-e1-e3/adversarial.test.cjs | 1278 ------------ tests/enterprise-e1-e3/direct.test.cjs | 267 --- tests/enterprise-e1-e3/fixture.cjs | 93 - tests/enterprise-e1-e3/isolation.test.cjs | 97 - .../adversarial.test.cjs | 248 --- .../direct.test.cjs | 296 --- .../isolation.test.cjs | 88 - .../investor-demo-wave2/adversarial.test.cjs | 202 -- tests/investor-demo-wave2/direct.test.cjs | 158 -- .../adversarial.test.cjs | 197 -- tests/pe-integrated-runtime/direct.test.cjs | 435 ----- .../pe-integrated-runtime/isolation.test.cjs | 85 - .../product-health.test.cjs | 380 ---- .../direct.test.cjs | 124 -- .../honesty.test.cjs | 96 - .../isolation.test.cjs | 149 -- tests/wave2-authority/adversarial.test.cjs | 199 -- tests/wave2-authority/assess.cjs | 267 --- tests/wave2-authority/direct.test.cjs | 152 -- .../authorization.test.cjs | 98 - tests/wave3-claim-inventory/direct.test.cjs | 88 - .../wave3-performance/qualification.test.mjs | 169 -- 395 files changed, 112 insertions(+), 39390 deletions(-) delete mode 100644 docs/internal/c8-teardown/README.md delete mode 100644 docs/internal/claim-scrub-report-2026-09-20.md delete mode 100644 docs/internal/disclosure-governance-cleanup/00-INVENTORY.md delete mode 100644 docs/internal/disclosure-governance-cleanup/01-BOUNDARY.md delete mode 100644 docs/internal/disclosure-governance-cleanup/02-ARCHITECTURE.md delete mode 100644 docs/internal/disclosure-governance-cleanup/DISCLOSURE-RECORD.json delete mode 100644 docs/internal/disclosure-governance-cleanup/GITHUB-SUPPORT-PURGE-PACKET.md delete mode 100644 docs/internal/disclosure-governance-cleanup/INDEPENDENT-COUNCIL.md delete mode 100644 docs/internal/enterprise-e1-e3/00-INVENTORY.md delete mode 100644 docs/internal/enterprise-e1-e3/01-BOUNDARY.md delete mode 100644 docs/internal/enterprise-e1-e3/02-ARCHITECTURE.md delete mode 100644 docs/internal/enterprise-e1-e3/03-IMPLEMENTATION-REPORT.md delete mode 100644 docs/internal/enterprise-e1-e3/04-PENDING-COUNCIL.md delete mode 100644 docs/internal/enterprise-e1-e3/STATUS.json delete mode 100644 docs/internal/governance-assurance/00-BOUNDARY.md delete mode 100644 docs/internal/governance-assurance/08-VERSION-PROCEDURE.md delete mode 100644 docs/internal/governance-assurance/09-DISCLOSURE.md delete mode 100644 docs/internal/governance-assurance/overlays/README.md delete mode 100644 docs/internal/governance-assurance/reports/CONTROL_EVIDENCE_INDEX.json delete mode 100644 docs/internal/governance-assurance/reports/CUSTOMER_RESPONSIBILITY_MATRIX.json delete mode 100644 docs/internal/governance-assurance/reports/FRAMEWORK_VERSION_REGISTER.json delete mode 100644 docs/internal/governance-assurance/reports/GOVERNANCE_POSTURE.json delete mode 100644 docs/internal/governance-assurance/reports/GOVERNANCE_POSTURE.md delete mode 100644 docs/internal/governance-assurance/reports/PROCUREMENT_EVIDENCE_INDEX.json delete mode 100644 docs/internal/governance-assurance/reports/PUBLIC_DISCLOSURE.json delete mode 100644 docs/internal/governance-assurance/reports/UNSUPPORTED_AND_EXTERNAL_CONTROLS.json delete mode 100644 docs/internal/governance-assurance/reports/VERIFICATION_INSTRUCTIONS.md delete mode 100644 docs/internal/governance-assurance/stage-b/C6-REBIND.json delete mode 100644 docs/internal/governance-assurance/views/eu-ai-act.md delete mode 100644 docs/internal/governance-assurance/views/iso-iec-42001.md delete mode 100644 docs/internal/governance-assurance/views/nist-ai-agent-standards.md delete mode 100644 docs/internal/governance-assurance/views/nist-ai-rmf-playbook.md delete mode 100644 docs/internal/governance-assurance/views/nist-ai-rmf.md delete mode 100644 docs/internal/governance-assurance/views/us-federal.md delete mode 100644 docs/internal/hiring/README.md delete mode 100644 docs/internal/hiring/cto-evaluation/FRAMEWORK-STUB.md delete mode 100644 docs/internal/hiring/head-of-product/COMPENSATION.md delete mode 100644 docs/internal/hiring/head-of-product/INTERVIEW-LOOP.md delete mode 100644 docs/internal/hiring/head-of-product/NINETY-DAY-OUTCOMES.md delete mode 100644 docs/internal/hiring/head-of-product/OFFER-BOUNDARY.md delete mode 100644 docs/internal/hiring/head-of-product/PACKAGE.json delete mode 100644 docs/internal/hiring/head-of-product/README.md delete mode 100644 docs/internal/hiring/head-of-product/RED-FLAGS.md delete mode 100644 docs/internal/hiring/head-of-product/ROLE-AND-RESPONSIBILITIES.md delete mode 100644 docs/internal/hiring/head-of-product/SCORECARD.md delete mode 100644 docs/internal/investor-demo-wave2/00-BOUNDARY.md delete mode 100644 docs/internal/investor-demo-wave2/01-INVENTORY.md delete mode 100644 docs/internal/investor-demo-wave2/02-ARCHITECTURE.md delete mode 100644 docs/internal/investor-demo-wave2/03-IMPLEMENTATION-REPORT.md delete mode 100644 docs/internal/investor-demo-wave2/04-COUNCIL-SLOT.md delete mode 100644 docs/internal/investor-demo-wave2/WAVE2-MANIFEST.json delete mode 100644 docs/internal/optics-best-in-class-roadmap.md delete mode 100644 docs/internal/optics-cli-post-0324-cx-backlog.md delete mode 100644 docs/internal/optics-o7/00-BINDING-DECISION.md delete mode 100644 docs/internal/optics-o7/10-RUNTIME-INTEGRATION.md delete mode 100644 docs/internal/optics-o7/BINDING-DECISION.json delete mode 100644 docs/internal/optics-o7/RUNTIME-INTEGRATION.json delete mode 100644 docs/internal/optics-pkg01/BOUNDARY.md delete mode 100644 docs/internal/optics-pkg01/COMPATIBILITY.md delete mode 100644 docs/internal/optics-pkg01/CONFORMANCE.md delete mode 100644 docs/internal/optics-pkg01/FAIL-OPEN.md delete mode 100644 docs/internal/optics-pkg01/FIELD-CATALOG.md delete mode 100644 docs/internal/optics-pkg01/IMPLEMENTATION-REPORT.md delete mode 100644 docs/internal/optics-pkg01/INDEPENDENT-COUNCIL-REPORT.md delete mode 100644 docs/internal/optics-pkg01/INDEPENDENT-PINNED-UNICODE-RECOUNCIL-REPORT.md delete mode 100644 docs/internal/optics-pkg01/INDEPENDENT-RECOUNCIL-REPORT.md delete mode 100644 docs/internal/optics-pkg01/KNOWN-LIMITATIONS.md delete mode 100644 docs/internal/optics-pkg01/PENDING-COUNCIL.md delete mode 100644 docs/internal/optics-pkg01/PRIVACY-DISPOSITIONS.md delete mode 100644 docs/internal/optics-pkg02-reader-compat-gates/ARCHITECTURE-COUNCIL-NOTES.md delete mode 100644 docs/internal/optics-pkg02-reader-compat-gates/BOUNDARY.md delete mode 100644 docs/internal/optics-pkg02-reader-compat-gates/DESIGN.md delete mode 100644 docs/internal/optics-pkg02-reader-compat-gates/GATE-CATALOG.md delete mode 100644 docs/internal/optics-pkg02-reader-compat-gates/IMPLEMENTATION-REPORT.md delete mode 100644 docs/internal/optics-pkg02-reader-compat-gates/INVENTORY.md delete mode 100644 docs/internal/optics-pkg02-reader-compat-gates/KNOWN-LIMITATIONS.md delete mode 100644 docs/internal/optics-pkg02-reader-compat-gates/NO-WRITER.md delete mode 100644 docs/internal/optics-pkg02-unit-a/ALIASES.md delete mode 100644 docs/internal/optics-pkg02-unit-a/BOUNDARY.md delete mode 100644 docs/internal/optics-pkg02-unit-a/COMPATIBILITY-FIXTURES.md delete mode 100644 docs/internal/optics-pkg02-unit-a/IMPLEMENTATION-REPORT.md delete mode 100644 docs/internal/optics-pkg02-unit-a/KNOWN-LIMITATIONS.md delete mode 100644 docs/internal/optics-pkg02-unit-a/NO-OPTIMISTIC-DEFAULTS.md delete mode 100644 docs/internal/optics-pkg02-unit-a/VOCABULARY.md delete mode 100644 docs/internal/optics-pkg02-unit-b/BOUNDARY.md delete mode 100644 docs/internal/optics-pkg02-unit-b/COMPATIBILITY-FIXTURES.md delete mode 100644 docs/internal/optics-pkg02-unit-b/DESIGN.md delete mode 100644 docs/internal/optics-pkg02-unit-b/IMPLEMENTATION-REPORT.md delete mode 100644 docs/internal/optics-pkg02-unit-b/KNOWN-LIMITATIONS.md delete mode 100644 docs/internal/optics-pkg02-unit-b/NO-OPTIMISTIC-DEFAULTS.md delete mode 100644 docs/internal/optics-pkg02-unit-b/PRIVACY.md delete mode 100644 docs/internal/optics-pkg02-unit-c/ADAPTER.md delete mode 100644 docs/internal/optics-pkg02-unit-c/BOUNDARY.md delete mode 100644 docs/internal/optics-pkg02-unit-c/DESIGN.md delete mode 100644 docs/internal/optics-pkg02-unit-c/FIXTURE-SCORE.md delete mode 100644 docs/internal/optics-pkg02-unit-c/IMPLEMENTATION-REPORT.md delete mode 100644 docs/internal/optics-pkg02-unit-c/INVENTORY.md delete mode 100644 docs/internal/optics-pkg02-unit-c/KNOWN-LIMITATIONS.md delete mode 100644 docs/internal/optics-pkg02-unit-c/NO-WRITER.md delete mode 100644 docs/internal/optics-pkg02-unit-d/BOUNDARY.md delete mode 100644 docs/internal/optics-pkg02-unit-d/DELTA.md delete mode 100644 docs/internal/optics-pkg02-unit-d/DESIGN.md delete mode 100644 docs/internal/optics-pkg02-unit-d/IMPLEMENTATION-REPORT.md delete mode 100644 docs/internal/optics-pkg02-unit-d/INTERNAL-RELEASE-NOTE.md delete mode 100644 docs/internal/optics-pkg02-unit-d/KNOWN-LIMITATIONS.md delete mode 100644 docs/internal/optics-pkg02-unit-d/NO-OPTIMISTIC-DEFAULTS.md delete mode 100644 docs/internal/optics-pkg02-unit-d/ORDINARY-CLIENT-PROOF.md delete mode 100644 docs/internal/optics-pkg02-unit-d/PRIVACY.md delete mode 100644 docs/internal/optics-pkg02-unit-d/ROLLBACK.md delete mode 100644 docs/internal/optics-pkg02-unit-e/BOUNDARY.md delete mode 100644 docs/internal/optics-pkg02-unit-e/DESIGN.md delete mode 100644 docs/internal/optics-pkg02-unit-e/IMPLEMENTATION-REPORT.md delete mode 100644 docs/internal/optics-pkg02-unit-e/KNOWN-LIMITATIONS.md delete mode 100644 docs/internal/optics-pkg02-unit-e/MATRIX-MARKERS.json delete mode 100644 docs/internal/optics-pkg02-unit-e/NO-OPTIMISTIC-DEFAULTS.md delete mode 100644 docs/internal/optics-pkg02-unit-e/ORDINARY-CLIENT-PROOF.md delete mode 100644 docs/internal/optics-pkg02-unit-e/RECORD-DELTA.md delete mode 100644 docs/internal/optics-pkg02-unit-e/ROLLBACK.md delete mode 100644 docs/internal/optics-pkg02-unit-f/BOUNDARY.md delete mode 100644 docs/internal/optics-pkg02-unit-f/COMPATIBILITY.md delete mode 100644 docs/internal/optics-pkg02-unit-f/DESIGN.md delete mode 100644 docs/internal/optics-pkg02-unit-f/IMPLEMENTATION-REPORT.md delete mode 100644 docs/internal/optics-pkg02-unit-f/KNOWN-LIMITATIONS.md delete mode 100644 docs/internal/optics-pkg02-unit-f/NO-OPTIMISTIC-DEFAULTS.md delete mode 100644 docs/internal/optics-pkg02-unit-f/ORDINARY-CLIENT-PROOF.md delete mode 100644 docs/internal/optics-pkg02-unit-f/PRIVACY.md delete mode 100644 docs/internal/pe-egress/00-INVENTORY.md delete mode 100644 docs/internal/pe-egress/01-BOUNDARY.md delete mode 100644 docs/internal/pe-egress/02-ARCHITECTURE.md delete mode 100644 docs/internal/pe-egress/03-PENDING-COUNCIL.md delete mode 100644 docs/internal/pe-egress/EGRESS-MANIFEST.json delete mode 100644 docs/internal/pe-egress/IMPLEMENTATION-REPORT.md delete mode 100644 docs/internal/pe-host-authority/00-BOUNDARY.md delete mode 100644 docs/internal/pe-host-authority/01-MECHANISM-COVERAGE.md delete mode 100644 docs/internal/pe-host-authority/02-LOCAL-PROOF.md delete mode 100644 docs/internal/pe-host-authority/HOST-AUTHORITY-MANIFEST.json delete mode 100644 docs/internal/pe-host-authority/INDEPENDENT-COUNCIL.md delete mode 100644 docs/internal/pe-ingress/00-BOUNDARY.md delete mode 100644 docs/internal/pe-ingress/01-INVENTORY.md delete mode 100644 docs/internal/pe-ingress/02-ARCHITECTURE.md delete mode 100644 docs/internal/pe-ingress/03-AUTHORITY-CONTRACT.md delete mode 100644 docs/internal/pe-ingress/04-REVOKE-RECOVERY.md delete mode 100644 docs/internal/pe-ingress/05-UNSUPPORTED-AND-HEALTH.md delete mode 100644 docs/internal/pe-ingress/06-IMPLEMENTATION-REPORT.md delete mode 100644 docs/internal/pe-ingress/07-PENDING-COUNCIL.md delete mode 100644 docs/internal/pe-ingress/INGRESS-MANIFEST.json delete mode 100644 docs/internal/pe-progressive-enforcement/00-BOUNDARY.md delete mode 100644 docs/internal/pe-progressive-enforcement/01-LIFECYCLE.md delete mode 100644 docs/internal/pe-progressive-enforcement/02-GATES.md delete mode 100644 docs/internal/pe-progressive-enforcement/03-KNOWN-LIMITATIONS.md delete mode 100644 docs/internal/pe-progressive-enforcement/04-IMPLEMENTATION-REPORT.md delete mode 100644 docs/internal/pe-progressive-enforcement/05-COUNCIL-SLOT.md delete mode 100644 docs/internal/pe-progressive-enforcement/MANIFEST.json delete mode 100644 docs/internal/pe-sequential-authority/BOUNDARY.md delete mode 100644 docs/internal/pe-sequential-authority/DESIGN.md delete mode 100644 docs/internal/pe-sequential-authority/IMPLEMENTATION-REPORT.md delete mode 100644 docs/internal/pe-sequential-authority/INVARIANTS.md delete mode 100644 docs/internal/pe-sequential-authority/KNOWN-LIMITATIONS.md delete mode 100644 docs/internal/pe-sequential-authority/NO-OPTIMISTIC-DEFAULTS.md delete mode 100644 docs/internal/pe-sequential-authority/PENDING-COUNCIL.md delete mode 100644 docs/internal/python-3.1.0-stage2-backlog.md delete mode 100644 docs/internal/shared-health-runtime/ARCHITECTURE.md delete mode 100644 docs/internal/shared-health-runtime/BOUNDARY.md delete mode 100644 docs/internal/shared-health-runtime/INDEPENDENT-COUNCIL.md delete mode 100644 docs/internal/wave3/claim-inventory/00-BOUNDARY.md delete mode 100644 docs/internal/wave3/claim-inventory/01-METHOD.md delete mode 100644 docs/internal/wave3/claim-inventory/02-DISPOSITIONS.md delete mode 100644 docs/internal/wave3/claim-inventory/03-DRIFT.md delete mode 100644 docs/internal/wave3/claim-inventory/04-FREEZE.md delete mode 100644 docs/internal/wave3/claim-inventory/README.md delete mode 100644 docs/internal/wave3/clean-host/00-POD-PROBE.md delete mode 100644 docs/internal/wave3/clean-host/01-CANDIDATE-PLANES.md delete mode 100644 docs/internal/wave3/enterprise-runtime/00-BOUNDARY.md delete mode 100644 docs/internal/wave3/enterprise-runtime/01-ARCHITECTURE.md delete mode 100644 docs/internal/wave3/enterprise-runtime/02-STATE-SEPARATION.md delete mode 100644 docs/internal/wave3/enterprise-runtime/03-IMPLEMENTATION-REPORT.md delete mode 100644 docs/internal/wave3/enterprise-runtime/04-PENDING-COUNCIL.md delete mode 100644 docs/internal/wave3/enterprise-runtime/INTEGRATION-REGISTER.json delete mode 100644 docs/internal/wave3/enterprise-runtime/RUNTIME-REGISTER.json delete mode 100644 docs/internal/wave3/enterprise-runtime/STATUS.json delete mode 100644 docs/internal/wave3/otlp-enable-test-disable/00-BOUNDARY.md delete mode 100644 docs/internal/wave3/otlp-enable-test-disable/01-HARNESS.md delete mode 100644 docs/internal/wave3/otlp-enable-test-disable/02-WS7-HONESTY.md delete mode 100644 docs/internal/wave3/otlp-enable-test-disable/03-IMPLEMENTATION-REPORT.md delete mode 100644 docs/internal/wave3/otlp-enable-test-disable/04-PENDING-COUNCIL.md delete mode 100644 docs/internal/wave3/otlp-enable-test-disable/REST-REGISTER.json delete mode 100644 docs/internal/wave3/pe-integration/00-BOUNDARY.md delete mode 100644 docs/internal/wave3/pe-integration/01-ARCHITECTURE.md delete mode 100644 docs/internal/wave3/pe-integration/02-STATE-SEPARATION.md delete mode 100644 docs/internal/wave3/pe-integration/03-IMPLEMENTATION-REPORT.md delete mode 100644 docs/internal/wave3/pe-integration/04-PENDING-COUNCIL.md delete mode 100644 docs/internal/wave3/pe-integration/INTEGRATION-REGISTER.json delete mode 100644 docs/internal/wave3/pe-integration/RUNTIME-REGISTER.json delete mode 100644 docs/internal/wave3/performance/00-BOUNDARY.md delete mode 100644 docs/internal/wave3/performance/01-METHOD.md delete mode 100644 docs/internal/wave3/performance/02-ENVIRONMENT.md delete mode 100644 docs/internal/wave3/performance/03-PENDING-COUNCIL.md delete mode 100644 docs/internal/wave3/performance/PERFORMANCE-REGISTER.json delete mode 100644 docs/internal/wave3/performance/scripts/qualify.mjs delete mode 100644 docs/internal/wave3/product-health/00-BOUNDARY.md delete mode 100644 docs/internal/wave3/product-health/01-READING.md delete mode 100644 docs/internal/wave3/product-health/02-FAILURE-TRUTH.md delete mode 100644 docs/internal/wave3/product-health/03-IMPLEMENTATION-REPORT.md delete mode 100644 docs/internal/wave3/product-health/04-PENDING-COUNCIL.md delete mode 100644 docs/internal/wave3/product-health/INTEGRATION-REGISTER.json delete mode 100644 docs/internal/wave3/product-health/RUNTIME-REGISTER.json delete mode 100644 docs/internal/wave3/product-health/STATUS.json delete mode 100644 docs/internal/wave3/public-inventory/00-BOUNDARY.md delete mode 100644 docs/internal/wave3/public-inventory/01-METHOD.md delete mode 100644 docs/internal/wave3/public-inventory/02-WEBSITE.md delete mode 100644 docs/internal/wave3/public-inventory/03-GITHUB.md delete mode 100644 docs/internal/wave3/public-inventory/04-NPM.md delete mode 100644 docs/internal/wave3/public-inventory/05-PYPI.md delete mode 100644 docs/internal/wave3/public-inventory/06-OTHER-SURFACES.md delete mode 100644 docs/internal/wave3/public-inventory/07-DRIFT.md delete mode 100644 docs/internal/wave3/public-inventory/README.md delete mode 100644 docs/internal/ws7-otel-i3/00-INVENTORY.md delete mode 100644 docs/internal/ws7-otel-i3/01-BOUNDARY.md delete mode 100644 docs/internal/ws7-otel-i3/02-ARCHITECTURE-COUNCIL-NOTES.md delete mode 100644 docs/internal/ws7-otel-i3/03-ADAPTER.md delete mode 100644 docs/internal/ws7-otel-i3/ADAPTER-MANIFEST.json delete mode 100644 docs/internal/ws7-otel-i3/IMPLEMENTATION-REPORT.md delete mode 100644 docs/internal/ws7-otel-mapping/00-BOUNDARY.md delete mode 100644 docs/internal/ws7-otel-mapping/01-SEMANTIC-MAPPING.md delete mode 100644 docs/internal/ws7-otel-mapping/02-ADAPTER-STUB-BOUNDARIES.md delete mode 100644 docs/internal/ws7-otel-mapping/03-PENDING-COUNCIL.md delete mode 100644 docs/internal/ws7-otel-mapping/IMPLEMENTATION-REPORT.md delete mode 100644 docs/internal/ws7-otel-mapping/MAPPING-MANIFEST.json delete mode 100644 docs/programs/production-readiness/CLAIM-LEDGER.json delete mode 100644 docs/programs/production-readiness/COMPANY-GATES.json delete mode 100644 docs/programs/production-readiness/DECISION-REGISTER.json delete mode 100644 docs/programs/production-readiness/DEMO-READINESS.json delete mode 100644 docs/programs/production-readiness/DEPENDENCY-GRAPH.json delete mode 100644 docs/programs/production-readiness/EXECUTIVE-REPORT.md delete mode 100644 docs/programs/production-readiness/EXTERNAL-DEPENDENCIES.json delete mode 100644 docs/programs/production-readiness/INVESTOR-READINESS.json delete mode 100644 docs/programs/production-readiness/MASTER-MANIFEST.json delete mode 100644 docs/programs/production-readiness/PILOT-READINESS.json delete mode 100644 docs/programs/production-readiness/RELEASE-REGISTER.json delete mode 100644 docs/programs/production-readiness/RISK-REGISTER.json delete mode 100644 docs/programs/production-readiness/WORKSTREAM-REGISTRY.json delete mode 100644 docs/programs/production-readiness/authority/00-INVENTORY.md delete mode 100644 docs/programs/production-readiness/authority/01-BOUNDARY.md delete mode 100644 docs/programs/production-readiness/authority/02-ARCHITECTURE-COUNCIL-NOTES.md delete mode 100644 docs/programs/production-readiness/authority/WAVE2-AUTHORITY.json delete mode 100644 docs/programs/production-readiness/demo/00-BOUNDARY.md delete mode 100644 docs/programs/production-readiness/demo/01-SIMULATION-LABEL-RULE.md delete mode 100644 docs/programs/production-readiness/demo/02-STORY-BEATS.md delete mode 100644 docs/programs/production-readiness/demo/03-DEMO-SCRIPT.md delete mode 100644 docs/programs/production-readiness/demo/04-OPERATOR-RUNBOOK.md delete mode 100644 docs/programs/production-readiness/demo/05-RESET-OUTLINE.md delete mode 100644 docs/programs/production-readiness/demo/06-EXPECTED-OUTPUTS.md delete mode 100644 docs/programs/production-readiness/demo/07-FAILURE-INJECTION-OUTLINE.md delete mode 100644 docs/programs/production-readiness/demo/08-CLAIM-LEDGER.json delete mode 100644 docs/programs/production-readiness/demo/09-LIMITATION-LEDGER.json delete mode 100644 docs/programs/production-readiness/demo/10-WAVE2-SCAFFOLD.md delete mode 100644 docs/programs/production-readiness/demo/11-COUNCIL-SLOT.md delete mode 100644 docs/programs/production-readiness/demo/DEMO-MANIFEST.json delete mode 100644 docs/programs/production-readiness/demo/scaffolding/README.md delete mode 100644 docs/programs/production-readiness/demo/scaffolding/labeled-event-envelope.json delete mode 100644 docs/programs/production-readiness/diligence/00-ROOM-BOUNDARY.md delete mode 100644 docs/programs/production-readiness/diligence/01-TIERS.md delete mode 100644 docs/programs/production-readiness/diligence/02-CATEGORY-THESIS.md delete mode 100644 docs/programs/production-readiness/diligence/03-PRODUCT-LADDER.md delete mode 100644 docs/programs/production-readiness/diligence/04-ARCHITECTURE.md delete mode 100644 docs/programs/production-readiness/diligence/05-THREAT-MODEL.md delete mode 100644 docs/programs/production-readiness/diligence/06-PRIVACY-MODEL.md delete mode 100644 docs/programs/production-readiness/diligence/07-CLAIM-LEDGER.md delete mode 100644 docs/programs/production-readiness/diligence/08-PROOF-TAXONOMY.md delete mode 100644 docs/programs/production-readiness/diligence/09-CAPABILITIES.md delete mode 100644 docs/programs/production-readiness/diligence/10-TARGET-ARCHITECTURE.md delete mode 100644 docs/programs/production-readiness/diligence/11-BUILD-STATUS.md delete mode 100644 docs/programs/production-readiness/diligence/12-DEMO-GUIDE.md delete mode 100644 docs/programs/production-readiness/diligence/13-TECHNICAL-APPENDIX.md delete mode 100644 docs/programs/production-readiness/diligence/14-RELEASE-DISCIPLINE.md delete mode 100644 docs/programs/production-readiness/diligence/15-DEPLOYMENT.md delete mode 100644 docs/programs/production-readiness/diligence/16-PILOT.md delete mode 100644 docs/programs/production-readiness/diligence/17-DESIGN-PARTNER.md delete mode 100644 docs/programs/production-readiness/diligence/18-STRANGER-HOST-GATE.md delete mode 100644 docs/programs/production-readiness/diligence/19-ROADMAP.md delete mode 100644 docs/programs/production-readiness/diligence/20-DIFFERENTIATION.md delete mode 100644 docs/programs/production-readiness/diligence/21-USE-OF-FUNDS.md delete mode 100644 docs/programs/production-readiness/diligence/22-HIRING-PLAN.md delete mode 100644 docs/programs/production-readiness/diligence/23-EVIDENCE-INDEX.md delete mode 100644 docs/programs/production-readiness/diligence/24-LIMITATIONS.md delete mode 100644 docs/programs/production-readiness/diligence/25-RISKS.md delete mode 100644 docs/programs/production-readiness/diligence/DILIGENCE-MANIFEST.json delete mode 100644 docs/programs/production-readiness/diligence/README.md delete mode 100644 docs/programs/production-readiness/wave3/00-BOUNDARY.md delete mode 100644 docs/programs/production-readiness/wave3/02-INDEPENDENT-COUNCIL.md delete mode 100644 docs/programs/production-readiness/wave3/03-BOUNDARY.md delete mode 100644 docs/programs/production-readiness/wave3/04-BOUNDARY.md delete mode 100644 docs/programs/production-readiness/wave3/05-PRODUCT-HEALTH-FAILURE-TRUTH.md delete mode 100644 docs/programs/production-readiness/wave3/10-COUNCIL.md delete mode 100644 docs/programs/production-readiness/wave3/BLOCKED-INFRA.json delete mode 100644 docs/programs/production-readiness/wave3/CLAIM-AND-VERSION-NOTES.md delete mode 100644 docs/programs/production-readiness/wave3/CLEAN-HOST-REGISTER.md delete mode 100644 docs/programs/production-readiness/wave3/ELIGIBILITY-PACKET.md delete mode 100644 docs/programs/production-readiness/wave3/ENTERPRISE-INTEGRATION-REGISTER.json delete mode 100644 docs/programs/production-readiness/wave3/ENTERPRISE-RUNTIME-REGISTER.json delete mode 100644 docs/programs/production-readiness/wave3/ENTERPRISE-RUNTIME-STATUS.json delete mode 100644 docs/programs/production-readiness/wave3/ENTERPRISE-RUNTIME.md delete mode 100644 docs/programs/production-readiness/wave3/INTEGRATION-REGISTER.json delete mode 100644 docs/programs/production-readiness/wave3/O7-NODE-BINDING-DECISION.json delete mode 100644 docs/programs/production-readiness/wave3/OTLP-ENABLE-TEST-DISABLE.md delete mode 100644 docs/programs/production-readiness/wave3/OTLP-REST-REGISTER.json delete mode 100644 docs/programs/production-readiness/wave3/PE-INTEGRATED-RUNTIME.md delete mode 100644 docs/programs/production-readiness/wave3/PERFORMANCE-COUNCIL.md delete mode 100644 docs/programs/production-readiness/wave3/PERFORMANCE-QUALIFICATION.md delete mode 100644 docs/programs/production-readiness/wave3/PERFORMANCE-REGISTER.json delete mode 100644 docs/programs/production-readiness/wave3/README.md delete mode 100644 docs/programs/production-readiness/wave3/RUNTIME-REGISTER.json delete mode 100644 docs/programs/production-readiness/wave3/STATUS.json delete mode 100644 docs/programs/production-readiness/wave3/WAVE3-TRACK4-MANIFEST.json delete mode 100644 docs/programs/production-readiness/wave3/product-health/INTEGRATION-REGISTER.json delete mode 100644 docs/programs/production-readiness/wave3/product-health/RUNTIME-REGISTER.json delete mode 100644 docs/programs/production-readiness/wave3/product-health/STATUS.json create mode 100644 docs/programs/release-engineering/SEALED-RELEASE-PINS.json delete mode 100644 internal/enterprise-governance/README.md delete mode 100644 internal/enterprise-governance/package.json delete mode 100644 internal/enterprise-governance/src/boundary.cjs delete mode 100644 internal/enterprise-governance/src/engine.cjs delete mode 100644 internal/enterprise-governance/src/envelope.cjs delete mode 100644 internal/enterprise-governance/src/index.cjs delete mode 100644 internal/enterprise-governance/src/scan.cjs delete mode 100644 internal/enterprise-runtime-integration/README.md delete mode 100644 internal/enterprise-runtime-integration/package.json delete mode 100644 internal/enterprise-runtime-integration/src/boundary.cjs delete mode 100644 internal/enterprise-runtime-integration/src/compose.cjs delete mode 100644 internal/enterprise-runtime-integration/src/index.cjs delete mode 100644 internal/enterprise-runtime-integration/src/project.cjs delete mode 100644 internal/enterprise-runtime-integration/src/registers.cjs delete mode 100644 internal/pe-integrated-runtime/README.md delete mode 100644 internal/pe-integrated-runtime/package.json delete mode 100644 internal/pe-integrated-runtime/src/boundary.cjs delete mode 100644 internal/pe-integrated-runtime/src/index.cjs delete mode 100644 internal/pe-integrated-runtime/src/product-health.cjs delete mode 100644 internal/pe-integrated-runtime/src/project.cjs delete mode 100644 internal/pe-integrated-runtime/src/registers.cjs delete mode 100644 internal/pe-integrated-runtime/src/runtime.cjs delete mode 100644 internal/w3-otlp-enable-test-disable/README.md delete mode 100644 internal/w3-otlp-enable-test-disable/package.json delete mode 100644 internal/w3-otlp-enable-test-disable/src/attempts.cjs delete mode 100644 internal/w3-otlp-enable-test-disable/src/boundary.cjs delete mode 100644 internal/w3-otlp-enable-test-disable/src/cycle.cjs delete mode 100644 internal/w3-otlp-enable-test-disable/src/index.cjs delete mode 100644 internal/w3-otlp-enable-test-disable/src/records.cjs delete mode 100644 internal/w3-otlp-enable-test-disable/src/registers.cjs delete mode 100644 internal/w3-otlp-enable-test-disable/src/rest.cjs delete mode 100644 internal/wave3-claim-inventory/freeze.cjs delete mode 100644 packages/investor-demo-wave2/README.md delete mode 100644 packages/investor-demo-wave2/bin/investor-demo.cjs delete mode 100644 packages/investor-demo-wave2/package.json delete mode 100644 packages/investor-demo-wave2/src/canonical.cjs delete mode 100644 packages/investor-demo-wave2/src/cli-probe.cjs delete mode 100644 packages/investor-demo-wave2/src/constants.cjs delete mode 100644 packages/investor-demo-wave2/src/index.cjs delete mode 100644 packages/investor-demo-wave2/src/model.cjs delete mode 100644 packages/investor-demo-wave2/src/report.cjs delete mode 100644 packages/investor-demo-wave2/src/safety.cjs delete mode 100644 packages/investor-demo-wave2/src/session.cjs delete mode 100644 packages/investor-demo-wave2/src/verify.cjs delete mode 100644 tests/enterprise-e1-e3/adversarial.test.cjs delete mode 100644 tests/enterprise-e1-e3/direct.test.cjs delete mode 100644 tests/enterprise-e1-e3/fixture.cjs delete mode 100644 tests/enterprise-e1-e3/isolation.test.cjs delete mode 100644 tests/enterprise-runtime-integration/adversarial.test.cjs delete mode 100644 tests/enterprise-runtime-integration/direct.test.cjs delete mode 100644 tests/enterprise-runtime-integration/isolation.test.cjs delete mode 100644 tests/investor-demo-wave2/adversarial.test.cjs delete mode 100644 tests/investor-demo-wave2/direct.test.cjs delete mode 100644 tests/pe-integrated-runtime/adversarial.test.cjs delete mode 100644 tests/pe-integrated-runtime/direct.test.cjs delete mode 100644 tests/pe-integrated-runtime/isolation.test.cjs delete mode 100644 tests/pe-integrated-runtime/product-health.test.cjs delete mode 100644 tests/w3-otlp-enable-test-disable/direct.test.cjs delete mode 100644 tests/w3-otlp-enable-test-disable/honesty.test.cjs delete mode 100644 tests/w3-otlp-enable-test-disable/isolation.test.cjs delete mode 100644 tests/wave2-authority/adversarial.test.cjs delete mode 100644 tests/wave2-authority/assess.cjs delete mode 100644 tests/wave2-authority/direct.test.cjs delete mode 100644 tests/wave3-claim-inventory/authorization.test.cjs delete mode 100644 tests/wave3-claim-inventory/direct.test.cjs delete mode 100644 tests/wave3-performance/qualification.test.mjs diff --git a/.github/workflows/w3-lab-teardown-verify.yml b/.github/workflows/w3-lab-teardown-verify.yml index a27f7773..aa38e1d1 100644 --- a/.github/workflows/w3-lab-teardown-verify.yml +++ b/.github/workflows/w3-lab-teardown-verify.yml @@ -29,8 +29,6 @@ name: Verify W3 lab teardown role # Class B stays unauthorized until STAGE_B_BILLING_CLOSE_PASS and # NONINTERACTIVE_TEARDOWN_READY are both recorded. A green run does not # record either token. -# -# See docs/internal/c8-teardown/README.md. on: workflow_dispatch: diff --git a/docs/governance/LEGACY-STALE-NAMES.json b/docs/governance/LEGACY-STALE-NAMES.json index a7e027c3..f5d6d6b6 100644 --- a/docs/governance/LEGACY-STALE-NAMES.json +++ b/docs/governance/LEGACY-STALE-NAMES.json @@ -1,6 +1,6 @@ { "schema": "vantio.docs-release.legacy-stale-names/v1", - "note": "Frozen debt outside the canonical set. A new path or a changed count fails the documentation release check. Canonical docs must not appear here. Optics manual leftovers are listed under intentional_leftovers, not in hits. packages/optics-record-vocabulary/vocabulary/record-vocabulary.json is frozen at count 2 for sight_loop. That Unit A file is on main and may be absent on this branch; the freeze applies when the file is present. tests/shared-health-vocabulary/collision.test.cjs is a reviewed 2026-09-27 addition at count 2. Those matches are prohibition needles in the test. The path stays in this hits list and in the legacy scan. It is not an intentional leftover and it is not hidden by legacy_scan.exclude_prefixes. tests/optics-pkg02-reader-compat-gates/isolation.test.cjs is a reviewed 2026-09-27 addition at count 2. Those matches are prohibition needles in the isolation test. The path stays in this hits list and in the legacy scan. It is not an intentional leftover and it is not hidden by legacy_scan.exclude_prefixes. docs/internal/optics-pkg02-unit-e/DESIGN.md, packages/vantio-agent-sdk-py-future/src/vantio_future/writer.py, and tests/optics-pkg02-unit-e/test_04_rollback.py are reviewed 2026-09-27 additions at count 1. Those matches name the sealed 3.1.0 workflow field as a rollback compatibility value. Each path stays in this hits list and in the legacy scan. None is an intentional leftover and none is hidden by legacy_scan.exclude_prefixes. docs/internal/wave3/public-inventory/03-GITHUB.md is a reviewed 2026-09-27 addition at count 2. docs/internal/wave3/public-inventory/05-PYPI.md is a reviewed 2026-09-27 addition at count 1. Those matches quote public GitHub and registry text inside the Wave 3 public-estate inventory. Each path stays in this hits list and in the legacy scan. None is an intentional leftover and none is hidden by legacy_scan.exclude_prefixes. The inventory dispositions stay UNREVIEWED. The Wave 3 public-surface inventory JSON and claim-ledger JSON were removed from the public tree. They are not hidden by legacy_scan.exclude_prefixes. A reintroduction is new debt.", + "note": "Frozen debt outside the canonical set. A new path or a changed count fails the documentation release check. Canonical docs must not appear here. Optics manual leftovers are listed under intentional_leftovers, not in hits. packages/optics-record-vocabulary/vocabulary/record-vocabulary.json is frozen at count 2 for sight_loop. That Unit A file is on main and may be absent on this branch; the freeze applies when the file is present. tests/shared-health-vocabulary/collision.test.cjs is a reviewed 2026-09-27 addition at count 2. Those matches are prohibition needles in the test. The path stays in this hits list and in the legacy scan. It is not an intentional leftover and it is not hidden by legacy_scan.exclude_prefixes. tests/optics-pkg02-reader-compat-gates/isolation.test.cjs is a reviewed 2026-09-27 addition at count 2. Those matches are prohibition needles in the isolation test. The path stays in this hits list and in the legacy scan. It is not an intentional leftover and it is not hidden by legacy_scan.exclude_prefixes. packages/vantio-agent-sdk-py-future/src/vantio_future/writer.py and tests/optics-pkg02-unit-e/test_04_rollback.py are reviewed 2026-09-27 additions at count 1. Those matches name the sealed 3.1.0 workflow field as a rollback compatibility value. Each path stays in this hits list and in the legacy scan. None is an intentional leftover and none is hidden by legacy_scan.exclude_prefixes. docs/internal stale-name hits, including the Wave 3 public-estate inventory pages, left the public tip with the non-public program trees. They are not frozen hits. The Wave 3 public-surface inventory JSON and claim-ledger JSON were removed from the public tree. They are not hidden by legacy_scan.exclude_prefixes. A reintroduction is new debt.", "reviewed_updates": [ { "path": "tests/shared-health-vocabulary/collision.test.cjs", @@ -16,13 +16,6 @@ "reviewed_on": "2026-09-27", "reason": "The isolation test names retired public strings only to assert that the reader-compat gate docs do not contain them. The path stays in the legacy scan and in hits. It is not an intentional leftover and it is not added to legacy_scan.exclude_prefixes." }, - { - "path": "docs/internal/optics-pkg02-unit-e/DESIGN.md", - "count": 1, - "disposition": "FROZEN_DEBT", - "reviewed_on": "2026-09-27", - "reason": "Unit E rollback design names the sealed 3.1.0 workflow field as a compatibility mention of the previous writer shape. The path stays in the legacy scan and in hits. It is not an intentional leftover and it is not added to legacy_scan.exclude_prefixes." - }, { "path": "packages/vantio-agent-sdk-py-future/src/vantio_future/writer.py", "count": 1, @@ -36,20 +29,6 @@ "disposition": "FROZEN_DEBT", "reviewed_on": "2026-09-27", "reason": "The rollback test asserts the sealed 3.1.0 workflow field on the legacy file. The match is a compatibility needle. The path stays in the legacy scan and in hits. It is not an intentional leftover and it is not added to legacy_scan.exclude_prefixes." - }, - { - "path": "docs/internal/wave3/public-inventory/03-GITHUB.md", - "count": 2, - "disposition": "FROZEN_DEBT", - "reviewed_on": "2026-09-27", - "reason": "The public-estate inventory quotes live GitHub topic and release text. The matches are quotations, not a product-name adoption. Public-surface dispositions stay UNREVIEWED. The path stays in the legacy scan and in hits. It is not an intentional leftover and it is not added to legacy_scan.exclude_prefixes." - }, - { - "path": "docs/internal/wave3/public-inventory/05-PYPI.md", - "count": 1, - "disposition": "FROZEN_DEBT", - "reviewed_on": "2026-09-27", - "reason": "The public-estate inventory quotes the live PyPI summary. The match is a quotation, not a product-name adoption. Public-surface dispositions stay UNREVIEWED. The path stays in the legacy scan and in hits. It is not an intentional leftover and it is not added to legacy_scan.exclude_prefixes." } ], "intentional_leftovers": { @@ -142,30 +121,6 @@ "path": "docs/getting-started-tier01.md", "count": 4 }, - { - "path": "docs/internal/claim-scrub-report-2026-09-20.md", - "count": 1 - }, - { - "path": "docs/internal/optics-pkg01/BOUNDARY.md", - "count": 1 - }, - { - "path": "docs/internal/optics-pkg01/COMPATIBILITY.md", - "count": 1 - }, - { - "path": "docs/internal/optics-pkg02-unit-e/DESIGN.md", - "count": 1 - }, - { - "path": "docs/internal/wave3/public-inventory/03-GITHUB.md", - "count": 2 - }, - { - "path": "docs/internal/wave3/public-inventory/05-PYPI.md", - "count": 1 - }, { "path": "docs/observe-only.md", "count": 3 diff --git a/docs/internal/c8-teardown/README.md b/docs/internal/c8-teardown/README.md deleted file mode 100644 index 51821b2b..00000000 --- a/docs/internal/c8-teardown/README.md +++ /dev/null @@ -1,138 +0,0 @@ -# INTERNAL_RESTRICTED — C8 teardown role verification - -Audience: INTERNAL_RESTRICTED - -This note is the dispatch and protection record for the GitHub Actions OIDC check of `vantio-w3-lab-teardown`. It does not authorize Class B, a Paid plan change, or a new host. - -A passing run is the verification that the role can be assumed and that the probes below behaved as expected. This note does not itself prove the role is present in AWS. - -## Role - -| Item | Value | -| --- | --- | -| Role ARN | `arn:aws:iam::960577828987:role/vantio-w3-lab-teardown` | -| Account | `960577828987` | -| OIDC provider | `token.actions.githubusercontent.com` | -| Trust action | `sts:AssumeRoleWithWebIdentity` | -| Trust subject | `repo:vantioai/vantio-open-core:environment:w3-lab-teardown` | -| Audience | `sts.amazonaws.com` | -| Region | `us-east-2` | -| Max session | 3600 seconds | -| Prepared policy SHA-256 | `2fd3909fe84cbe93b15c5525ece0d247d0f4f4a91e333346001d512e1efc5215` | -| Key pair name in that policy | `vantio-w3-class-b-lab-01` | - -The SHA-256 above is a prepared digest of the policy document after the key pair name was substituted to `vantio-w3-class-b-lab-01`. It is not a live-measured hash from IAM. This repository does not store that policy JSON. The workflow does not call `iam:GetRole`. Check 2 records MaxSessionDuration as 3600 from this handoff and fails unless the assume step returns an STS Expiration at most one hour ahead. - -The workflow does not create a long-lived access key, an IAM user, or a root key. The job refuses to start the assume step if `AWS_ACCESS_KEY_ID`, `AWS_SECRET_ACCESS_KEY`, or `AWS_SESSION_TOKEN` is already set. `use-existing-credentials` is false, so ambient credentials cannot skip the OIDC exchange. - -`configure-aws-credentials` v6 emits the STS Expiration only when credential outputs are enabled. The assume step turns that on so check 2 can record Expiration. The verify step reads `aws-expiration`, `aws-account-id`, and `authenticated-arn`. It does not read the secret credential outputs. - -## GitHub environment - -Name: `w3-lab-teardown`. - -The Founder must create this protected environment BEFORE any dispatch. GitHub auto-creates an unprotected environment when a job that sets `environment:` is scheduled and that name does not already exist. An unprotected environment has no required reviewers and no branch rule, and a job that reaches it can assume the role. The trust policy checks the environment subject. It does not check GitHub's protection rules. - -Creation was attempted on 2026-09-28 with the repository integration token: - -```text -PUT /repos/vantioai/vantio-open-core/environments/w3-lab-teardown -``` - -GitHub returned `403 Resource not accessible by integration`. That call did not create the environment. Do not dispatch this workflow to "see if the environment appears." - -If an unprotected `w3-lab-teardown` environment was created by a dispatch, delete it before creating the protected one: - -```bash -gh api --method DELETE repos/vantioai/vantio-open-core/environments/w3-lab-teardown -``` - -Delete only the accidental unprotected environment. After it is gone, create the protected environment. The protected publish environments `npm-publish`, `pypi`, and `mcp-registry-publish` already use this pattern: - -- required reviewer GitHub login `zacharybalicki` (user id `269605088`) -- `prevent_self_review: false` (a single reviewer can approve a run they started; the sibling environments use this) -- custom deployment branch policy allowing only `main` - -`zacharybalicki` must remain a required reviewer. Other reviewers may be added beside that user. `prevent_self_review` stays false so the publish-environment pattern does not deadlock a single reviewer. - -```bash -gh api --method PUT repos/vantioai/vantio-open-core/environments/w3-lab-teardown --input - <<'JSON' -{ - "wait_timer": 0, - "prevent_self_review": false, - "can_admins_bypass": true, - "reviewers": [ - {"type": "User", "id": 269605088} - ], - "deployment_branch_policy": { - "protected_branches": false, - "custom_branch_policies": true - } -} -JSON - -gh api --method POST \ - repos/vantioai/vantio-open-core/environments/w3-lab-teardown/deployment-branch-policies \ - --input - <<'JSON' -{"name": "main", "type": "branch"} -JSON -``` - -The `preflight` job does not set `environment:`. It GETs the environment and fails unless the environment exists, `zacharybalicki` (id `269605088`) is a required reviewer, and the deployment branch policy allows only `main`. The `verify` job is the only job that sets `environment: w3-lab-teardown`, and it has `needs: preflight`. A failed preflight skips `verify`, so that skipped job does not schedule the environment. Both jobs also require `GITHUB_WORKFLOW_REF` to be `vantioai/vantio-open-core/.github/workflows/w3-lab-teardown-verify.yml@refs/heads/main`. - -## Dispatch - -After this workflow file is on `main` and the protected environment already exists, open Actions, choose **Verify W3 lab teardown role**, and run it on `main`. Leave fixture close off unless the ids of an already-provisioned disposable lab are in hand. - -`verify` waits for the environment reviewer before the OIDC assume. - -```bash -gh workflow run w3-lab-teardown-verify.yml --ref main \ - -f run_destructive_fixtures=false -``` - -Destructive close is limited to the ids passed at dispatch. The verifier describes each id in `us-east-2` and refuses the call when the tags do not match the authorized fixture. The key pair input is accepted only when it is exactly `vantio-w3-class-b-lab-01`. Close order is settle-first (GAP-C8-VER-002): terminate the instance, wait until that instance is terminated and the data volume is `available` with no attachments, `DeleteVolume` without `DetachVolume` when the volume is already free, wait until the EIP `AssociationId` is gone, `ReleaseAddress` without `DisassociateAddress` when the address is already free, retry `DeleteSecurityGroup` on `DependencyViolation`, then delete the key pair. Reported check numbers stay 9 instance, 10 volume, 11 security group, 12 key pair, 13 EIP. Run `36506523073` denied `DetachVolume` on an instance ARN and `DisassociateAddress` on a network-interface ARN under the prepared policy above. Those actions remain allowed only on `volume/*` and `elastic-ip/*`. This verifier does not widen that policy to `Resource:*`. `DependencyViolation` on the security group is a residual dependency, not a missing `DeleteSecurityGroup` grant. - -```bash -gh workflow run w3-lab-teardown-verify.yml --ref main \ - -f run_destructive_fixtures=true \ - -f fixture_instance_id=i-0123456789abcdef0 \ - -f fixture_volume_id=vol-0123456789abcdef0 \ - -f fixture_security_group_id=sg-0123456789abcdef0 \ - -f fixture_keypair_name=vantio-w3-class-b-lab-01 \ - -f fixture_eip_allocation_id=eipalloc-0123456789abcdef0 -``` - -Those example ids are placeholders. Pass only real disposable fixture ids. - -Checks 9–13 stay `NOT_RUN_AWAITING_FIXTURES` when the flag is false, or when the flag is true and that id was not passed. That status does not fail the job. - -## What the job checks - -The log prints `CHECK NN STATUS name: detail`. The same rows are in the job summary and in the artifact `w3-lab-teardown-verify-` (`w3-lab-teardown-verify.json`). The artifact field `policy_sha256` is labeled `prepared_digest`. It is not a live-measured hash. The job fails when any check is `FAIL`. - -1. `sts get-caller-identity` shows account `960577828987` and role `vantio-w3-lab-teardown`. -2. Requested session duration is 3600 seconds or less, and the assume step returned an STS Expiration. A missing Expiration is a fail. Remaining lifetime must be at most one hour plus two minutes of clock skew. -3. `DescribeInstances` in `us-east-2` with the lab tag filters (`vantio:program=w3-clean-host-lab`, `vantio:lifecycle=lab`, `vantio:destroyable=true`, `vantio:environment=lab`). Zero instances is a pass. `AccessDenied` is a fail. -4. `CreateSecurityGroup --dry-run` in `us-east-2` for `vantio-w3-teardown-verify-tagged-deny-probe`, with the lab tags (`vantio:program=w3-clean-host-lab`, `vantio:lifecycle=lab`, `vantio:destroyable=true`, `vantio:environment=lab`). The `--tag-specifications` value is one JSON object that starts with `{`, which is the form AWS CLI v2 parses as JSON and sends to EC2. `AccessDenied` or `UnauthorizedOperation` is a pass. `DryRunOperation`, or a call that returns a group id, is a fail, because the create would have been allowed. The default path does not call `TerminateInstances` and does not delete a group. `NotFound`, any code ending in `NotFound`, `NotFoundException`, and `ResourceNotFoundException` fail this check, including when the message contains `explicit deny` or `not authorized`. Those codes mean the named resource does not exist. Run `36474749760` (GAP-C8-VER-001) returned `InvalidInstanceID.NotFound` for `TerminateInstances --dry-run` on sentinel `i-0deadbeef0deadbee` in `us-east-2`. This role is allowed to call `ec2:TerminateInstances` when the lab tags match, and EC2 answers a missing instance id with `NotFound` instead of `DryRunOperation` or `UnauthorizedOperation`. The verifier uses this tagged create dry-run for that reason. A pass means the create was denied. It does not measure the tag condition on `ec2:TerminateInstances`. `iam:SimulatePrincipalPolicy` is not called. This role is not granted that action, and this workflow does not add it. -5. `CreateSecurityGroup --dry-run` in `us-east-2` for `vantio-w3-teardown-verify-deny-probe`, without those tags. The expected result is `AccessDenied` or `UnauthorizedOperation`. `DryRunOperation` is a fail. `RunInstances` is not called. A group id is not deleted by this check. `NotFound` fails this check. -6. `iam:GetUser` for the nonexistent name `vantio-w3-teardown-verify-deny-probe`. The expected result is `AccessDenied`. `CreateUser` is not called. -7. `ce:GetCostAndUsage` (Cost Explorer lives in `us-east-1`). The expected result is `AccessDenied`. The probe does not change a support plan or payment method. -8. `DescribeInstances` in `us-east-1`, and `CreateSecurityGroup --dry-run` there for `vantio-w3-teardown-verify-region-deny-probe`. Both must be denied with `AccessDenied` or `UnauthorizedOperation`. `DryRunOperation`, or a call that returns a group id, is a fail. `NotFound`, any code ending in `NotFound`, `NotFoundException`, and `ResourceNotFoundException` fail this check on either call, including when the message contains `explicit deny` or `not authorized`. The default path does not call `TerminateInstances`. On run `36474749760`, describe in `us-east-1` was denied and the sentinel `TerminateInstances --dry-run` returned `InvalidInstanceID.NotFound`, so that terminate result did not prove the region boundary. -9. Terminate the passed instance, only when destructive close is on and the id's tags match. After `TerminateInstances` is accepted, the verifier waits until the instance reports `terminated` before the volume, EIP, and security group closes. That wait does not by itself pass this check. `NotFound` during the wait is not a pass. -10. Delete the passed volume when its tags match, including `vantio:owned-by=transaction`. `available` with no attachments calls `DeleteVolume` and does not call `DetachVolume`. A volume that is still `in-use` is polled until it is free. `DetachVolume` runs only after that wait is exhausted. The locked policy allows `DetachVolume` on `volume/*` only, so a detach that still names the instance ARN can be `UnauthorizedOperation`. -11. Delete the passed security group when its tags match. `DependencyViolation` is retried with bounded backoff. That error is a residual dependency, not a missing `DeleteSecurityGroup` grant. `NotFound` does not pass. -12. Delete the key pair only when the name is `vantio-w3-class-b-lab-01`. -13. Release the passed EIP when its tags match. No `AssociationId` calls `ReleaseAddress` and does not call `DisassociateAddress`. An address that is still associated is polled until the association id is gone. `DisassociateAddress` is not called while the address is attached: the locked policy allows that action on `elastic-ip/*` only, and EC2 also authorizes the network-interface ARN. `NotFound` does not pass. -14. `cloudtrail:LookupEvents` in `us-east-2` for this session. A successful call with zero events is a pass; ingestion can lag. -15. `DOCUMENTED`. The STS Expiration is recorded. The job cannot prove the credentials are dead before that timestamp. The credentials action clears the environment variables when the job ends. - -## What this does not do - -- It does not provision a Class B lab or any other host. -- It does not create IAM users, access keys, or root keys. Check 6 is `iam:GetUser` on a probe name. It does not call `CreateUser`. -- It does not change billing, payments, or the Paid plan. -- It does not grant `NONINTERACTIVE_TEARDOWN_READY`. -- It does not record `STAGE_B_BILLING_CLOSE_PASS`. - -Class B remains unauthorized until both `STAGE_B_BILLING_CLOSE_PASS` and `NONINTERACTIVE_TEARDOWN_READY` are actually recorded. The governance record in this repository still has billing at `STAGE_B_BILLING_CLOSE_PENDING`, and C8 is not `NONINTERACTIVE_TEARDOWN_READY`. A green run of this workflow does not flip those tokens. diff --git a/docs/internal/claim-scrub-report-2026-09-20.md b/docs/internal/claim-scrub-report-2026-09-20.md deleted file mode 100644 index a3a37cb5..00000000 --- a/docs/internal/claim-scrub-report-2026-09-20.md +++ /dev/null @@ -1,118 +0,0 @@ -# Claim Scrub Report — vantio-open-core -**Date:** 2026-09-20 -**Authority:** CEO decision 2026-09-20 — Align public GitHub open-core to locked commercial model. -**Branch:** `cursor/claim-scrub-open-core-1ed9` - ---- - -## Canonical Model (locked) - -1. **Optics** — free observe-only entry (this repo) -2. **Phantom Engine** — primary paid product; Observe/Enforce/Control are functions inside PE; $799/node/mo -3. **Vantio Enterprise** — optional governance add-on; "talk to sales" - -Gate is NOT a current standalone public SKU. Gate may remain as internal/legacy/compat identifier, clearly labeled. - ---- - -## Phase 1 — File Classification - -| File | Classification | Decision | -|------|---------------|----------| -| `docs/PRODUCT_LINEUP.md` | PUBLIC | CONFLICT — scrubbed | -| `docs/observe-only.md` | PUBLIC | CONFLICT — scrubbed | -| `docs/getting-started-tier01.md` | PUBLIC | CONFLICT — scrubbed | -| `docs/optics-mcp.md` | PUBLIC | CONFLICT — scrubbed | -| `docs/sight-loop.md` | PUBLIC | CONFLICT — scrubbed | -| `docs/gate-mcp.md` | PUBLIC | CONFLICT — scrubbed (relabeled legacy/compat) | -| `docs/dogfood-optics.md` | PUBLIC | CONFLICT — scrubbed | -| `docs/surfaces.md` | PUBLIC | CONFLICT — scrubbed | -| `docs/prove.md` | PUBLIC | CONFLICT — scrubbed (Pro/Enterprise → PE/Enterprise) | -| `docs/framework-integrations.md` | PUBLIC | CONFLICT — scrubbed (Pro/Enterprise → PE/Enterprise) | -| `packages/vantio-agent-sdk-py/CHANGELOG.md` | CUSTOMER_SHIPPED | CONFLICT — scrubbed | -| `packages/vantio-agent-sdk-py/README.md` | CUSTOMER_SHIPPED | CONFLICT — scrubbed | -| `packages/vantio-agent-sdk/README.md` | CUSTOMER_SHIPPED | CONFLICT — scrubbed | -| `packages/vantio-agent-sdk/package.json` | CUSTOMER_SHIPPED | CONFLICT — scrubbed | -| `packages/vantio-optics-mcp/README.md` | CUSTOMER_SHIPPED | CONFLICT — scrubbed | -| `packages/vantio-optics-mcp/package.json` | CUSTOMER_SHIPPED | CONFLICT — scrubbed | -| `packages/vantio-gate-mcp/README.md` | CUSTOMER_SHIPPED | CONFLICT — scrubbed (legacy/compat label) | -| `packages/vantio-gate-mcp/server.json` | CUSTOMER_SHIPPED | CONFLICT — scrubbed ("Pro API key" → "Phantom Engine API key") | -| `README.md` | PUBLIC | CONFLICT — scrubbed | -| `CONTRIBUTING.md` | PUBLIC | CONFLICT — scrubbed (added legacy/compat note) | -| `integrations/hooks/openclaw-plugin.example.md` | PUBLIC | CONFLICT — scrubbed | -| `integrations/hooks/README.md` | PUBLIC | CONFLICT — scrubbed | -| `examples/adapters/llamaindex-py/README.md` | CUSTOMER_SHIPPED | CONFLICT — scrubbed | -| `docs/specs/*` | INTERNAL_ONLY | Gate symbols used as internal code identifiers — no rename per task rules | -| `docs/webhooks.md` | INTERNAL | Gate event names are API identifiers — no rename per task rules | -| `architecture_state.md` | INTERNAL | `vantio-pro` reference labeled archival — no change | - ---- - -## Phase 2 — Before/After Summary - -### Removed entirely as a purchasable public SKU -- `Gate ($499)` / `Gate ($499/month)` as a line in pricing tables -- `### Enforce · Vantio Gate ($499)` as a feature-layer section -- Four-product commercial ladder: Optics → Gate → Phantom Engine → Enterprise - -### Replaced with canonical 3-product model -**Before:** Optics (Free) · Gate ($499) · Phantom Engine ($799/node) · Enterprise (talk to sales) -**After:** Optics (Free) · Phantom Engine ($799/node/mo) · Enterprise (talk to sales) - -### Upgrade path — before -> Residual risk closes with **Vantio Gate**, then **Vantio Phantom Engine** - -### Upgrade path — after -> Residual risk closes with **Vantio Phantom Engine** ($799/node/mo) — see vantio.ai/pricing - -### Gate — retained as internal/legacy/compat -- `@vantio/gate-mcp` package retained; labeled "legacy/compat; Gate is not a current standalone public SKU" in: README, package description, CONTRIBUTING.md, docs/gate-mcp.md, docs/surfaces.md -- Internal code symbols (`gate_evaluate`, `VANTIO_GATE_BLOCKED`, `GateBlockedError`, `gate.blocked` webhook event names) — NOT renamed per task rules - ---- - -## Phase 3 — Verification Sweep Results - -### Search: `$499` / `499/month` / `Gate.*$` -- Only remaining hit: `packages/vantio-agent-sdk-py/CHANGELOG.md` line 7 — **intentional historical note**, clearly labeled - -### Search: four-product commercial model / old ladder -- No remaining hits in public/customer-shipped files - -### Search: `Gate.*standalone.*SKU` / `Gate.*pro` / `Pro.*Gate` -- Only remaining hits are our own "Gate is not a current standalone public SKU" corrections - -### Search: `$50,000` / `$50k` / `$100k` ARR language -- None found in any file - -### Search: `vantio-pro` -- Only in `architecture_state.md` (INTERNAL, labeled "archival only") - ---- - -## Remaining CONFLICT Items - -**None** — all public/customer-facing stale claims have been resolved. - -### Items intentionally NOT changed (per task rules) - -| Pattern | Reason | -|---------|--------| -| `gate_evaluate`, `gate_get_policy`, `gate_residual_risk`, `gate_normalize_policy`, `gate_explain`, `gate_upgrade_path` | Internal MCP tool names — no dependency analysis done; rename prohibited | -| `GateBlockedError`, `VANTIO_GATE_BLOCKED` | Internal error class and constant names in code | -| `gate.dry_run_blocked`, `gate.enforcement_gap`, `gate.blocked` | Webhook event type identifiers (API surface) | -| `docs/specs/WRAP_*.md` references to "Gate host-block / size / spend path" | INTERNAL_ONLY spec docs; Gate used as internal function name | -| `vantio.ai/gate` URL in `@vantio/gate-mcp` package.json / server.json | Package-level URLs for a real (legacy/compat) package | - ---- - -## Confirmations - -- **AE (Autonomous Enterprise) imports:** None introduced — no AE code imported -- **Package publish:** No `npm publish`, `pnpm publish`, or PyPI publish performed -- **Merge:** PR is draft — not merged -- **Enforcement semantics:** No changes to interceptor logic, fail-open behavior, or package code - ---- - -CLAIM_SCRUB_OPEN_CORE: COMPLETE diff --git a/docs/internal/disclosure-governance-cleanup/00-INVENTORY.md b/docs/internal/disclosure-governance-cleanup/00-INVENTORY.md deleted file mode 100644 index d2ee525c..00000000 --- a/docs/internal/disclosure-governance-cleanup/00-INVENTORY.md +++ /dev/null @@ -1,55 +0,0 @@ -# Disclosure and governance cleanup — inventory - -Audience: INTERNAL_RESTRICTED - -Base: `89f95099d0dce463307eb75d78e7fcf2ef99feb2` (`Merge pull request #83`). - -This inventory records what was true before the fix. It does not copy a customer manual into this tree. - -## Documentation governance - -`node docs/scripts/check-docs-release.mjs` on the base failed one check: - -`legacy-stale-name-inventory-frozen`: `new stale-name files: tests/shared-health-vocabulary/collision.test.cjs` - -The legacy scan extensions include `.cjs`. `docs/governance/MANIFEST.json` does not exclude `tests/shared-health-vocabulary/`. The frozen `hits` list in `docs/governance/LEGACY-STALE-NAMES.json` did not name that test. The live match count on the base was 2. No other path was new, missing, or changed. - -The collision test still asserts that the shared-health catalog directory does not contain the retired public strings, and that it does not contain a live probe command. Those strings are why the file is in the scan. Removing the strings, or excluding the path, would hide the debt instead of reviewing it. - -## Public Phantom Engine draft - -| Fact | Observation | -| --- | --- | -| Pull request | https://github.com/vantioai/vantio-open-core/pull/66 | -| State | `closed`, draft, `merged` false, `merged_at` null | -| Closed at | `2026-09-27T07:33:14Z` | -| Head ref name | `docs/phantom-engine-customer-manual-v1` | -| Head SHA | `60726bef7a7d7da35525a4d832ec63b5f8ca5bad` | -| Branch on origin | absent (`git ls-remote` of that head returned no ref) | -| Remaining advertised ref | `refs/pull/66/head` at the same SHA | -| Other advertised refs at the eight draft commits | none | -| Forks | 0 | -| Compare with this main | `diverged`, 8 commits ahead, merge base `14249ba84ff1f3d5aa8ad7a7366172f29235c76e` | -| Customer manual on this worktree | absent | - -The eight public commits are `8baead08d12192799ad51bae6f411cd394c444e4` through `60726bef7a7d7da35525a4d832ec63b5f8ca5bad`. They are not ancestors of this main. Closing the pull request did not delete the pull ref or the commit objects. - -## Private channel - -| Fact | Observation | -| --- | --- | -| Repository | `vantioai/vantio-pe-customer-docs` | -| Visibility | private | -| Anonymous HTML and API | 404 | -| Forking | disabled | -| Main tip | `d876ced0531607b7468efa3d0da981821be2cbbc` | -| Tip change | `INTERNAL-RELOCATION.md` only (blob `d94b631f91b402e3c17f455cd0280cb0b0aaafea`) | -| Wording-fix commit | `ec633d192544c22cde2853226b3f8e77d753a49f` | -| Manual path | `docs/customer/phantom-engine/` | -| Placement status | `PHANTOM_CUSTOMER_DOCS_PRIVATE_CHANNEL_PLACED` | - -Contents-listing blob SHAs on the private default branch match the reviewed public-tip blobs for 16 manual files. `CUSTOMER-OVERVIEW.md` and `EVIDENCE-AND-ASSURANCE.md` match the reviewed post-edit blobs `3d4de013f6da9db6418a02cedf6c5009d1b95356` and `3c68008c6702f8daf082c1315aaa2f0072ca9109`. Public-tip SHA-256 values were recomputed from the still-cached public blobs and match the private relocation record. Manual bytes were not written into this worktree. Post-edit SHA-256 was not recomputed here; the private git blob is the checked identity for those two files. - -## Support purge - -No GitHub Support ticket exists from this force. The cached pull request diff, the pull ref, and the eight commits are still the public residue. diff --git a/docs/internal/disclosure-governance-cleanup/01-BOUNDARY.md b/docs/internal/disclosure-governance-cleanup/01-BOUNDARY.md deleted file mode 100644 index 493afffc..00000000 --- a/docs/internal/disclosure-governance-cleanup/01-BOUNDARY.md +++ /dev/null @@ -1,30 +0,0 @@ -# Disclosure and governance cleanup — boundary - -Audience: INTERNAL_RESTRICTED - -Producer: Cursor cloud agent `bc-07ad7beb-878c-5c79-bc02-25cfbc56e015`, model Grok 4.7. - -Producer classification: `DISCLOSURE_GOVERNANCE_CLEANUP_READY_FOR_COUNCIL` - -That classification means this branch is ready for a separate council. It is not a council verdict, not a merge, and not a statement that GitHub has purged anything. - -## What this force does - -- Adds `tests/shared-health-vocabulary/collision.test.cjs` to the frozen stale-name inventory at the live count, with a reviewed reason. -- Keeps that path inside the legacy scan. -- Records the public draft tip, the eight commit SHAs, and the reviewed manual hashes. -- Records the private-channel copy check. -- Writes a GitHub Support purge packet and marks it unsent. - -## What this force keeps closed - -- Merge of this pull request. Council is a separate reader. -- Merge of pull request #66, reopening it, or copying `docs/customer/phantom-engine/` onto public `main`. -- Contacting GitHub Support, filing the packet, or any other external send. -- `git filter-repo`, a force push, or a rewrite of `main`. -- Customer deploy, announcements, credential changes, and registry publish. -- CLI `0.3.24` and Python `3.1.0` bytes. -- Editing the collision test to delete the prohibition needles. -- Treating an intentional leftover, or an exclude prefix, as the fix for this file. - -`docs/customer/phantom-engine/` stays absent from this worktree. diff --git a/docs/internal/disclosure-governance-cleanup/02-ARCHITECTURE.md b/docs/internal/disclosure-governance-cleanup/02-ARCHITECTURE.md deleted file mode 100644 index ceba213b..00000000 --- a/docs/internal/disclosure-governance-cleanup/02-ARCHITECTURE.md +++ /dev/null @@ -1,30 +0,0 @@ -# Disclosure and governance cleanup — architecture - -Audience: INTERNAL_RESTRICTED - -Two residues are separate. The documentation gate can see a test file. GitHub can still serve a closed pull request. This force accounts for both without moving customer-manual bytes onto public `main`. - -## Collision-test inventory - -`docs/governance/STALE-NAMES.json` lists retired public names. `docs/scripts/docs-release-lib.mjs` counts them outside `docs/governance/` and `docs/scripts/`. `docs/governance/LEGACY-STALE-NAMES.json` `hits` is the frozen debt. A new path fails `legacy-stale-name-inventory-frozen`. - -The collision test is new debt because it contains the prohibition needles. The reviewed disposition is `FROZEN_DEBT`: - -- `reviewed_updates` names the path, the count, and the reason. -- `hits` carries the same path and count. -- `intentional_leftovers` does not name the path. That list is for the Optics manual's declared leftover storage, not for a test that is supposed to forbid the strings. -- `legacy_scan.exclude_prefixes` does not hide the path. An exclude would make the scan report the file missing after it had been added, or would omit it before review. Either result hides the path. - -`collisionTestInventoryProblems` is check `collision-test-inventory-reviewed`. It fails when the review entry is missing, the disposition is not `FROZEN_DEBT`, the counts disagree, the path is an intentional leftover, an exclude prefix hides it, or the live scan does not see it. A different new file that contains a retired name still fails the frozen-inventory check. This review does not except that other file. - -## Public draft residue - -Pull request #66 is closed and unmerged. The branch ref is gone. `refs/pull/66/head` still points at `60726bef7a7d7da35525a4d832ec63b5f8ca5bad`. GitHub documents that pull refs are read-only from a client push, and that cached pull-request views are removed by contacting GitHub Support after other refs are gone. - -This force does not rewrite `main`. The eight commits diverge from `main` at merge base `14249ba84ff1f3d5aa8ad7a7366172f29235c76e`. A mirror history rewrite would touch refs that do not contain the manual. The purge packet asks a later authorized person to request removal of this pull request's cache and the eight objects only. It also records GitHub's limit: Support does not remove data it judges non-sensitive, and it prefers credential rotation when that mitigates the risk. This residue is document text, not a credential. Support may decline. The packet does not claim a purge. - -The private repository already holds the manual. Sixteen private blobs match the public tip. Two private blobs match the reviewed wording-fix hashes. The hash table in `DISCLOSURE-RECORD.json` is the public preservation of those identities. The manual text stays in the private repository. - -## Council - -`INDEPENDENT-COUNCIL.md` is the slot. This producer does not fill a pass. diff --git a/docs/internal/disclosure-governance-cleanup/DISCLOSURE-RECORD.json b/docs/internal/disclosure-governance-cleanup/DISCLOSURE-RECORD.json deleted file mode 100644 index 29d9537c..00000000 --- a/docs/internal/disclosure-governance-cleanup/DISCLOSURE-RECORD.json +++ /dev/null @@ -1,250 +0,0 @@ -{ - "schema": "vantio.disclosure.pe-public-draft/v1", - "audience": "INTERNAL_RESTRICTED", - "classification": "DISCLOSURE_GOVERNANCE_CLEANUP_READY_FOR_COUNCIL", - "council_status": "PENDING_INDEPENDENT_COUNCIL", - "producer": { - "agent": "bc-07ad7beb-878c-5c79-bc02-25cfbc56e015", - "url": "https://cursor.com/agents/bc-07ad7beb-878c-5c79-bc02-25cfbc56e015", - "model": "Grok 4.7", - "base": "89f95099d0dce463307eb75d78e7fcf2ef99feb2" - }, - "verified_at_utc": "2026-09-27T11:19:38Z", - "verification_method": "Public tip blobs were fetched from the GitHub git blobs API and hashed in memory. SHA-256 and git blob SHA were compared with the private relocation record. Private default-branch contents listings supplied the current private blob SHAs and sizes. Manual bytes were not written into this worktree. Post-edit SHA-256 for the two wording-fix files was not recomputed; those private git blobs were compared with the reviewed post-edit hashes.", - "public_pull_request": { - "repo": "vantioai/vantio-open-core", - "number": 66, - "url": "https://github.com/vantioai/vantio-open-core/pull/66", - "state": "closed", - "draft": true, - "merged": false, - "merged_at": null, - "closed_at": "2026-09-27T07:33:14Z", - "head_ref": "docs/phantom-engine-customer-manual-v1", - "head_sha": "60726bef7a7d7da35525a4d832ec63b5f8ca5bad", - "base_ref": "main", - "base_sha_at_open": "d7299a35be0d9a70ec306ca672aa1359e09f1515", - "branch_ref_on_origin": "ABSENT", - "pull_ref": "refs/pull/66/head", - "pull_ref_sha": "60726bef7a7d7da35525a4d832ec63b5f8ca5bad" - }, - "public_commits": [ - "8baead08d12192799ad51bae6f411cd394c444e4", - "dada18b428ec4caadc0f799a7a4c38e2e599032b", - "9bd056f66ed4ea2fe6aff93f62aacbd3b0e06821", - "aca55ef3fc2b01b6e1643ecb752185f492e4be77", - "2f0cb57ebd2a7558d99f5cf73f352d0b497c6f3e", - "bb70c56f5755d0d9cdbd3c165e01f7076704faec", - "949063873365e804a6d2ebddc39d97ea584b3f22", - "60726bef7a7d7da35525a4d832ec63b5f8ca5bad" - ], - "reachable_from_main": false, - "compare_with_base": { - "base": "89f95099d0dce463307eb75d78e7fcf2ef99feb2", - "status": "diverged", - "ahead_by": 8, - "merge_base": "14249ba84ff1f3d5aa8ad7a7366172f29235c76e" - }, - "forks_observed": 0, - "only_advertised_ref": "refs/pull/66/head", - "private_channel": { - "repo": "vantioai/vantio-pe-customer-docs", - "visibility": "private", - "forking": false, - "anonymous_http_status": 404, - "main_tip": "d876ced0531607b7468efa3d0da981821be2cbbc", - "wording_fix_commit": "ec633d192544c22cde2853226b3f8e77d753a49f", - "relocation_record_blob": "d94b631f91b402e3c17f455cd0280cb0b0aaafea", - "manual_path": "docs/customer/phantom-engine/", - "placement_status": "PHANTOM_CUSTOMER_DOCS_PRIVATE_CHANNEL_PLACED", - "manual_bytes_copied_into_open_core": false - }, - "non_manual_tip_objects": [ - { - "path": ".gitattributes", - "public_tip_git_blob": "5e0e3814231035ffa52e7779c9e042bee8851bc6", - "main_git_blob": "4de3e66861ac5f6a603c677b3c7fd1147ca4bdab", - "copied_onto_main": false, - "note": "The tip adds an export-ignore rule for the customer manual tree. This main does not have that rule. This force does not copy it." - } - ], - "reviewed_hashes": { - "source_tip": "60726bef7a7d7da35525a4d832ec63b5f8ca5bad", - "files": [ - { - "path": "ARCHITECTURE-BOUNDARIES.md", - "public_tip_git_blob": "d79fe88e373442b0164ac02866c068db15c1c5a1", - "public_tip_sha256": "075642b3b8797d505b59130b7c0374d0ffaad89fa7bafebc2ebee8ac83fa66e5", - "public_tip_bytes": 7162, - "private_bytes": "MATCHES_PUBLIC_TIP", - "private_git_blob": "d79fe88e373442b0164ac02866c068db15c1c5a1", - "private_bytes_size": 7162 - }, - { - "path": "BACKUP-AND-RECOVERY.md", - "public_tip_git_blob": "6432fa61cb5112b605df9b2e85a37292f5187bc6", - "public_tip_sha256": "34e4f6b1f8917f2969374f090c99b5ab19977ccbd0ad0818de2c9e503c49e55b", - "public_tip_bytes": 4932, - "private_bytes": "MATCHES_PUBLIC_TIP", - "private_git_blob": "6432fa61cb5112b605df9b2e85a37292f5187bc6", - "private_bytes_size": 4932 - }, - { - "path": "CUSTOMER-AI-GUIDE.md", - "public_tip_git_blob": "84d17c495ebb86642462d1be64773e7d05339688", - "public_tip_sha256": "c389ed3eab8d5dbb73de52fa9f8a9393aff79820eb9abb6cd5f93698bc632ed6", - "public_tip_bytes": 4843, - "private_bytes": "MATCHES_PUBLIC_TIP", - "private_git_blob": "84d17c495ebb86642462d1be64773e7d05339688", - "private_bytes_size": 4843 - }, - { - "path": "CUSTOMER-OVERVIEW.md", - "public_tip_git_blob": "e039a083b800cb35f92de80a67658f931224c74d", - "public_tip_sha256": "8499a295d393496bc901d441df7f56d8482c4c60c82b13f2db650201b857974e", - "public_tip_bytes": 8250, - "private_bytes": "WORDING_FIX", - "private_git_blob": "3d4de013f6da9db6418a02cedf6c5009d1b95356", - "private_bytes_size": 8262 - }, - { - "path": "CUSTOMER-RELEASE-NOTES.md", - "public_tip_git_blob": "b3d4f48a8ca41fa84db89f46fd09cbdaf21e4d2d", - "public_tip_sha256": "fb3c606e44063cf70fa8bf27dbbacda9ce31fb6c137a4cd436df1d6b090ff5df", - "public_tip_bytes": 3144, - "private_bytes": "MATCHES_PUBLIC_TIP", - "private_git_blob": "b3d4f48a8ca41fa84db89f46fd09cbdaf21e4d2d", - "private_bytes_size": 3144 - }, - { - "path": "DEPLOYMENT-GUIDE.md", - "public_tip_git_blob": "9564fcd84ef96303dc655355719e7c186feeac48", - "public_tip_sha256": "22df6e9762724c2904675722e58c8b2c2e88256c39469092508340e9769647f3", - "public_tip_bytes": 7925, - "private_bytes": "MATCHES_PUBLIC_TIP", - "private_git_blob": "9564fcd84ef96303dc655355719e7c186feeac48", - "private_bytes_size": 7925 - }, - { - "path": "ENROLLMENT-GUIDE.md", - "public_tip_git_blob": "a226b761c21d53c542db09320a1ef24af0bae4c9", - "public_tip_sha256": "e6784ab19d25e78666059c68b1cb6a8b63d6c1e8ab599d80e575a8aaea313e34", - "public_tip_bytes": 5411, - "private_bytes": "MATCHES_PUBLIC_TIP", - "private_git_blob": "a226b761c21d53c542db09320a1ef24af0bae4c9", - "private_bytes_size": 5411 - }, - { - "path": "EVIDENCE-AND-ASSURANCE.md", - "public_tip_git_blob": "680fba001bfec6b8915511ff58d679b5084e0858", - "public_tip_sha256": "144b3bb92e1eaa4bd3dcc0a5b815ed1012e044fb2ffeca202b3edbf9ff53ed62", - "public_tip_bytes": 6506, - "private_bytes": "WORDING_FIX", - "private_git_blob": "3c68008c6702f8daf082c1315aaa2f0072ca9109", - "private_bytes_size": 6502 - }, - { - "path": "INCIDENT-RESPONSE.md", - "public_tip_git_blob": "c7a662dadc9d7b3215882b5b8470ba6404c78c9f", - "public_tip_sha256": "f2f776fb340b4ace024460583a84bb12ec45343a49ad2bf7482537fc6d6a1b89", - "public_tip_bytes": 4990, - "private_bytes": "MATCHES_PUBLIC_TIP", - "private_git_blob": "c7a662dadc9d7b3215882b5b8470ba6404c78c9f", - "private_bytes_size": 4990 - }, - { - "path": "KNOWN-LIMITATIONS.md", - "public_tip_git_blob": "e653036404bc7c27ba926c9eb6463514f3e9dcb5", - "public_tip_sha256": "316e6df5078716f9c48dcb55fcb6ced076704bef92cd148b4b758edb2d77a1af", - "public_tip_bytes": 5776, - "private_bytes": "MATCHES_PUBLIC_TIP", - "private_git_blob": "e653036404bc7c27ba926c9eb6463514f3e9dcb5", - "private_bytes_size": 5776 - }, - { - "path": "OPERATIONS-RUNBOOK.md", - "public_tip_git_blob": "af03a89e6122190b813336d54b98faa90f9c42fb", - "public_tip_sha256": "b278730c0a689ec73e965e9a43c085977ff3da093420f43e4de6f3f0d0a21699", - "public_tip_bytes": 6014, - "private_bytes": "MATCHES_PUBLIC_TIP", - "private_git_blob": "af03a89e6122190b813336d54b98faa90f9c42fb", - "private_bytes_size": 6014 - }, - { - "path": "POLICY-GUIDE.md", - "public_tip_git_blob": "bea4581739ba1bd7843534a055f302627a06ed9a", - "public_tip_sha256": "11cb4ea7ed42a56b71329cbee1404eb9ba2abce530195a2cb2faf029441acee6", - "public_tip_bytes": 6893, - "private_bytes": "MATCHES_PUBLIC_TIP", - "private_git_blob": "bea4581739ba1bd7843534a055f302627a06ed9a", - "private_bytes_size": 6893 - }, - { - "path": "REMOVAL-AND-UNINSTALL.md", - "public_tip_git_blob": "fb7c5c6c5d031b6bd7fdb9ca7884f342e54750d8", - "public_tip_sha256": "22a4fb0a9d5884ab344ca114e7c48e810b209b204e8f6200c6bbbf116a86de57", - "public_tip_bytes": 4124, - "private_bytes": "MATCHES_PUBLIC_TIP", - "private_git_blob": "fb7c5c6c5d031b6bd7fdb9ca7884f342e54750d8", - "private_bytes_size": 4124 - }, - { - "path": "SECURITY-GUIDE.md", - "public_tip_git_blob": "15cea6bc857a953bd20a6b2aab008a5266f36f55", - "public_tip_sha256": "4ad6ce02f19f78c198bea75ed645f2a6e72ca010d679ab82cb4974e085a40a14", - "public_tip_bytes": 5456, - "private_bytes": "MATCHES_PUBLIC_TIP", - "private_git_blob": "15cea6bc857a953bd20a6b2aab008a5266f36f55", - "private_bytes_size": 5456 - }, - { - "path": "SUPPORTED-ENVIRONMENTS.md", - "public_tip_git_blob": "8fbeef34ee69916759e0f5314154980f563b166b", - "public_tip_sha256": "0591becc1be26633ab925bcfa21f6a3a96ff09a9b7d589de50b14138640c38fe", - "public_tip_bytes": 6181, - "private_bytes": "MATCHES_PUBLIC_TIP", - "private_git_blob": "8fbeef34ee69916759e0f5314154980f563b166b", - "private_bytes_size": 6181 - }, - { - "path": "TROUBLESHOOTING.md", - "public_tip_git_blob": "493e5fa1a570c37cc23a587f47c5282e1213c5d9", - "public_tip_sha256": "34b0e4b0caa582bd7024fed73663e9636b6e79452b3a2b2c54ce938122e0fe04", - "public_tip_bytes": 7051, - "private_bytes": "MATCHES_PUBLIC_TIP", - "private_git_blob": "493e5fa1a570c37cc23a587f47c5282e1213c5d9", - "private_bytes_size": 7051 - }, - { - "path": "UPGRADE-AND-ROLLBACK.md", - "public_tip_git_blob": "3cd040b9e4dc8795a0e4cfe0a6e4965aeb3c4d01", - "public_tip_sha256": "aa44cd444c738bde27769c0e1f88b092d77efae9e45390229531a329dda94dfa", - "public_tip_bytes": 4697, - "private_bytes": "MATCHES_PUBLIC_TIP", - "private_git_blob": "3cd040b9e4dc8795a0e4cfe0a6e4965aeb3c4d01", - "private_bytes_size": 4697 - }, - { - "path": "VERSION-METADATA.json", - "public_tip_git_blob": "75cb1522951573346b84869cb76c94213e9f34bd", - "public_tip_sha256": "bb7b873f546b894dfe00bd9f0594a558199817b72925608bff325f99e95ed400", - "public_tip_bytes": 2130, - "private_bytes": "MATCHES_PUBLIC_TIP", - "private_git_blob": "75cb1522951573346b84869cb76c94213e9f34bd", - "private_bytes_size": 2130 - } - ] - }, - "history_rewrite": { - "git_filter_repo_run": false, - "force_push": false, - "main_rewritten": false - }, - "support_purge": { - "packet": "docs/internal/disclosure-governance-cleanup/GITHUB-SUPPORT-PURGE-PACKET.md", - "status": "PREPARED_NOT_SENT", - "contacted_github_support": false, - "reason": "External communication is not authorized. The packet is prepared for a later Founder send." - }, - "merge_to_public_main": "NOT_AUTHORIZED" -} diff --git a/docs/internal/disclosure-governance-cleanup/GITHUB-SUPPORT-PURGE-PACKET.md b/docs/internal/disclosure-governance-cleanup/GITHUB-SUPPORT-PURGE-PACKET.md deleted file mode 100644 index 1a016377..00000000 --- a/docs/internal/disclosure-governance-cleanup/GITHUB-SUPPORT-PURGE-PACKET.md +++ /dev/null @@ -1,58 +0,0 @@ -# GitHub Support purge packet - -Audience: INTERNAL_RESTRICTED - -PACKET_STATUS: PREPARED_NOT_SENT - -GITHUB_SUPPORT_CONTACTED: false - -PUBLIC_PR_66_STATE: CLOSED_UNMERGED - -TIP: 60726bef7a7d7da35525a4d832ec63b5f8ca5bad - -PULL_REF: refs/pull/66/head - -HISTORY_REWRITE_OF_MAIN: NOT_PERFORMED - -FILTER_REPO_RUN: false - -MERGE_TO_PUBLIC_MAIN: NOT_AUTHORIZED - -This force did not submit this packet. - -## Why this is a packet and not a ticket - -External communication is not authorized. Nobody in this force opened https://support.github.com/ or wrote to GitHub Support. A later Founder action would submit the request below. Until that action, the status stays `PREPARED_NOT_SENT`. - -## Request a later sender may file - -Repository: `vantioai/vantio-open-core` - -Sensitive residue: customer-confidential manual files that were committed on a public draft and were not merged. The file names and content hashes are in `DISCLOSURE-RECORD.json`. Do not attach or paste the file bodies into the ticket. - -Scope the sender should ask for: - -- Cached views of pull request 66, including the files diff and earlier description revisions. -- The read-only ref `refs/pull/66/head`. -- These eight commits, only if they are not reachable from `main`: `8baead08d12192799ad51bae6f411cd394c444e4`, `dada18b428ec4caadc0f799a7a4c38e2e599032b`, `9bd056f66ed4ea2fe6aff93f62aacbd3b0e06821`, `aca55ef3fc2b01b6e1643ecb752185f492e4be77`, `2f0cb57ebd2a7558d99f5cf73f352d0b497c6f3e`, `bb70c56f5755d0d9cdbd3c165e01f7076704faec`, `949063873365e804a6d2ebddc39d97ea584b3f22`, `60726bef7a7d7da35525a4d832ec63b5f8ca5bad`. -- Server garbage collection of those objects after the pull ref is gone. - -Facts the sender can cite, observed `2026-09-27T11:19:38Z`: - -- Pull request 66 is closed, draft, and `merged_at` is null. Closed at `2026-09-27T07:33:14Z`. -- Branch `docs/phantom-engine-customer-manual-v1` is not on origin. -- The only advertised ref at the tip is `refs/pull/66/head`. -- Fork count was 0. -- Compare against `89f95099d0dce463307eb75d78e7fcf2ef99feb2` was `diverged`. Merge base `14249ba84ff1f3d5aa8ad7a7366172f29235c76e`. The tip is not an ancestor of `main`. -- A private copy already exists in `vantioai/vantio-pe-customer-docs`. Anonymous access to that repository returned 404. Do not ask GitHub to copy the manual, and do not ask GitHub to make that repository public. - -## What the sender must not do - -- Do not rewrite `main`. `HISTORY_REWRITE_OF_MAIN` stays `NOT_PERFORMED` unless a separate decision says otherwise. -- Do not run `git filter-repo` against this repository as part of filing the ticket. `FILTER_REPO_RUN` stays false. GitHub's published removal guide assumes a history rewrite and then a Support request for pull refs, because clients cannot push `refs/pull/`. That rewrite is the wrong tool here: the manual is not on `main`, and a mirror push would risk every other ref. -- Do not reopen or merge pull request 66. `MERGE_TO_PUBLIC_MAIN` stays `NOT_AUTHORIZED`. -- Do not include manual text in the ticket. - -## Limit, stated before any send - -GitHub's published guide says Support will not remove non-sensitive data, and will assist only when Support decides the risk cannot be mitigated by rotating credentials. This residue is document text, not a credential. Rotation does not remove the cached draft. Support may decline. This packet does not record a purge, a ticket number, or a success. diff --git a/docs/internal/disclosure-governance-cleanup/INDEPENDENT-COUNCIL.md b/docs/internal/disclosure-governance-cleanup/INDEPENDENT-COUNCIL.md deleted file mode 100644 index 0eda7420..00000000 --- a/docs/internal/disclosure-governance-cleanup/INDEPENDENT-COUNCIL.md +++ /dev/null @@ -1,26 +0,0 @@ -# Independent council slot - -Audience: INTERNAL_RESTRICTED - -| Item | Value | -| --- | --- | -| Producer classification | `DISCLOSURE_GOVERNANCE_CLEANUP_READY_FOR_COUNCIL` | -| Council status | `PENDING_INDEPENDENT_COUNCIL` | -| Producer | `bc-07ad7beb-878c-5c79-bc02-25cfbc56e015` | -| Base | `89f95099d0dce463307eb75d78e7fcf2ef99feb2` | - -The producer classification means the notes, the inventory update, the disclosure record, and the unsent purge packet are ready for a separate reader. It is not a council verdict. - -A pass from this producer would be void. Merge of this branch, merge of pull request #66, and contact with GitHub Support stay outside this force. - -Read: - -- `00-INVENTORY.md` -- `01-BOUNDARY.md` -- `02-ARCHITECTURE.md` -- `DISCLOSURE-RECORD.json` -- `GITHUB-SUPPORT-PURGE-PACKET.md` -- `docs/governance/LEGACY-STALE-NAMES.json` `reviewed_updates` -- `node --test docs/scripts/check-docs-release.test.mjs tests/disclosure-governance-cleanup/direct.test.mjs tests/disclosure-governance-cleanup/adversarial.test.mjs` - -Confirm the worktree still has no `docs/customer/phantom-engine/` tree, pull request #66 is still closed without `merged_at`, and the packet status is still `PREPARED_NOT_SENT`. diff --git a/docs/internal/enterprise-e1-e3/00-INVENTORY.md b/docs/internal/enterprise-e1-e3/00-INVENTORY.md deleted file mode 100644 index 3c2b967d..00000000 --- a/docs/internal/enterprise-e1-e3/00-INVENTORY.md +++ /dev/null @@ -1,37 +0,0 @@ -# Enterprise E1–E3 internal inventory - -Audience: INTERNAL_RESTRICTED - -Producer: Cursor cloud agent `bc-c9b05a34-636c-589b-987b-4ea94e4f8c4c`. This producer does not sit the council. - -Starting commit: `89f95099d0dce463307eb75d78e7fcf2ef99feb2` - -## What was already on that commit - -| Item | State verified in this tree | -| --- | --- | -| Plan packet | `docs/planning/enterprise-governance/` merged by pull request #71 at `8eb353a94c08c1adaaa36d36e2536ee5619e9eb6` | -| Plan classification inside the packet | `ENTERPRISE_GOVERNANCE_E1_E3_PLAN_READY_FOR_COUNCIL` | -| Plan council file | `06-INDEPENDENT-COUNCIL.md` is `PENDING_INDEPENDENT_COUNCIL`. No council verdict is stored | -| Situation this force treats as input | `ENTERPRISE_GOVERNANCE_E1_E3_PLAN_MERGED_NO_IMPLEMENTATION` | -| Requirements | 33. 24 were `PLANNED`. 9 were `UNSATISFIED`. Evidence tier and customer validation were `UNSET` | -| Founder decisions EG-D1 through EG-D10 | Unresolved, each with a safe default | -| Future-force template | `07-FUTURE-FORCE.md` remains `NOT AUTHORIZED` | -| Phantom Engine commit cited by the plan | `631e435315cd780d83d3259e111893c1d0569bc3`. This repository does not contain that tree | -| Package versions | `@vantio/cli` `0.3.24`, `vantio-agent-sdk` `3.1.0`, Node SDK `0.2.4`. Unchanged | - -The template in `07-FUTURE-FORCE.md` says an implementation force should stop without `ENTERPRISE_GOVERNANCE_E1_E3_PLAN_COUNCIL_PASSED`. That token is not in this tree. The Founder standing authorization dated 2026-09-27 names Enterprise E1–E3 internal work and stops before merge. This force follows that authorization. It does not record the plan council as passed, and it does not edit the plan packet. - -A later revision on draft pull request #100 closed `not_before`, sticky `ENDED`, and a later `NARROW`. A composition revision after `ENTERPRISE_E1_E3_INTERNAL_NEEDS_REVISION` on `db70e93bca42d7d5be56b2afaed4d1c95a24cf24` closed deferred-widen holds A–E. Council `bc-9e4306a5-2874-5ae1-ba2e-c6aadfd1ba5b` reopened holds A and B on `73f291b009f4b0d223c5003385f38973a3a5e8b1`. The sibling revision closed those two holds. Council `bc-3cc20d59-8923-5424-b1ba-ac17db02854a` returned `ENTERPRISE_E1_E3_INTERNAL_NEEDS_REVISION` on `34a1d2ad1007e573cc1fac137f334b2acb5c3a33` because a clock climbed a live cap that already sat above a recorded open-widen ceiling back to the stored widen target. This revision keeps that live cap. The handoff token is `ENTERPRISE_E1_E3_INTERNAL_REVISION_READY_FOR_COUNCIL`. The plan council stays pending. - -## What this force adds - -| Path | Role | -| --- | --- | -| `internal/enterprise-governance/` | In-process record evaluator. Private. Not a workspace package | -| `tests/enterprise-e1-e3/` | Direct, adversarial, and isolation tests | -| `docs/internal/enterprise-e1-e3/` | Inventory, boundary, architecture notes, implementation report, pending council | - -## What this force does not find - -No Enterprise ownership, delegation, or approval runtime existed under `packages/` or `extensions/`. Optics observation stays account-free. Phantom Engine enrollment, kernel programs, and the quarantine executor are not in this repository. No identity provider, credential store, or hosted activation channel is selected here. diff --git a/docs/internal/enterprise-e1-e3/01-BOUNDARY.md b/docs/internal/enterprise-e1-e3/01-BOUNDARY.md deleted file mode 100644 index e94a32b2..00000000 --- a/docs/internal/enterprise-e1-e3/01-BOUNDARY.md +++ /dev/null @@ -1,36 +0,0 @@ -# Enterprise E1–E3 internal boundary - -Audience: INTERNAL_RESTRICTED - -Producer classification: `ENTERPRISE_E1_E3_INTERNAL_READY_FOR_COUNCIL` - -That classification means this branch is ready for a separate council. It is not a council verdict, not a merge, and not host proof. - -## In scope - -An in-memory evaluator that applies the merged plan's record rules: - -- E1 title stays with the customer root. Vantio is not a member of the root set. Host enroll and retire are intent records. Policy approval is not host attachment. -- E2 grants are subsets, carry `not_before` and `not_after`, and do not transfer title. Exercise stays closed before `not_before`. `ENDED` does not reopen. A later narrow bounds existing grants. A deferred policy widen composes onto the policy in force when its window opens. A later narrow that sets a cap between the approval baseline and the stored target, or that removes a destination the widen would add, stays in force through entry, clock-back, and re-entry. Sibling widens with different end times stay composed when one expires or a clock moves before the other's start. A live cap above a recorded open-widen ceiling stays at that live cap when a clock composes the older widen. A freeze, a store outage, and a window that has already ended leave an unapplied widen unapplied, and an outage does not roll back a widen already applied. Redelegation stays forbidden. Spawn does not mint a grant. A child envelope wider than the permitted subset of the current customer policy is refused. -- E3 classes are `INSPECT`, `NARROW`, `WIDEN`, `ROOT`, and `RECOVERY`. The rejected acts in the plan stay rejected. Same-person `WIDEN`, workload self-approval, and a grant recipient approving their own grant are refused as approval. -- Role labels and agent consensus do not satisfy a class. Opaque handles are not identity proof. No external identity and no credential is created. -- EG-D1 through EG-D10 stay unresolved. EG-D5 and EG-D6 stay on their defaults: this module does not activate a host, and it does not select a store product. - -## Out of scope - -- Live customer authority, a customer host, or a Phantom Engine process. -- Enrollment, kernel loading, egress drops, quarantine, and `phantom_deny_breakglass_off`. -- A second enforcement engine, a CLI command, or a change under `packages/`, `extensions/`, `.github/`, or `docs/governance/`. -- Edits to `docs/planning/enterprise-governance/`. The plan hashes stay those in `GOVERNANCE-MANIFEST.json`. -- CLI `0.3.24` and Python `3.1.0`. -- Certifications, a stable schema, Spanner, a WORM product, or a proof system. -- EG-SP-1 through EG-SP-5. Those tests need a host Vantio does not operate. They are not run. -- EG-E3-8 and EG-SUB-6. The record can state the rule. The host action and the on-host channel are not present. - -## Schema - -`schema_status` is `unstable-pre-1.0`. `schema_version` is `0`. Module version is `0.0.0-unstable-pre-1.0`. The package is private and is not listed in `pnpm-workspace.yaml`. - -## Result flags that stay false - -Every result forces `host_contacted`, `verified_on_host`, `live_customer_authority`, `external_identity_created`, `credential_created`, `identity_authenticated`, `vantio_sufficient`, `active_set_by_enterprise_writer`, and `satisfies_host_proof` to false. `APPROVED` means the record rule was satisfied. It does not mean a host attached, a freeze ran, or a council passed. diff --git a/docs/internal/enterprise-e1-e3/02-ARCHITECTURE.md b/docs/internal/enterprise-e1-e3/02-ARCHITECTURE.md deleted file mode 100644 index 1d948bbc..00000000 --- a/docs/internal/enterprise-e1-e3/02-ARCHITECTURE.md +++ /dev/null @@ -1,95 +0,0 @@ -# Enterprise E1–E3 architecture notes for council - -Audience: INTERNAL_RESTRICTED - -These notes are the architecture record for the internal evaluator. They are not a council verdict. Seats are in `04-PENDING-COUNCIL.md`. - -## 1. Placement - -The evaluator lives in `internal/enterprise-governance/`. Callers pass plain objects and receive a result. Nothing in the module opens a socket, reads a host, or imports a package under `packages/`. - -Phantom Engine remains the enforcement plane. An enroll intent stores `enrolled: false`, `protected: false`, and `enforced: false`, and names the mechanism `PHANTOM_ENGINE_ON_CUSTOMER_HOST` without performing it. A retire intent keeps the "record says retired, process may still be active" contradiction visible. This module does not clear it. - -## 2. Parties - -An identity is an opaque string the caller already holds, plus a caller-asserted kind: `customer`, `workload`, or `vantio`. Accepting that pair records a handle. It does not create an external identity, a credential, or a proof. - -| Rule | Evaluator behavior | -| --- | --- | -| Vantio is not in the root set | Kind `vantio` cannot found the root, join the owner set, or be the recovery party. Relabeling the same id as `customer` is refused | -| Workload is not title | Kind `workload` cannot found the root or receive `security` or `recovery` | -| Roles are not proof | `role`, `roles`, `role_labels`, and `claimed_role` do not fill a seat | -| Consensus is not approval | `agent_consensus`, `consensus`, `votes`, and `agent_votes` do not fill a seat | -| Distinct ids are not a human proof | The same id twice is rejected for `WIDEN`. Two different strings are not checked as the same person. `identity_authenticated` stays false | - -`recordRecognizedCustomer` lets the root record that an already accepted customer handle may sit a `WIDEN` seat. Recognition is not membership in the root set and does not mint a grant. - -## 3. Title and exercise - -Founding stores `title_holder: customer_root` and the reserved powers `freeze`, `revoke_grant`, `recover`, `export`, `hash`, `rollback`, `uninstall`, and `remove_witness`. Grants do not delete that list. A grant field that hands any of those powers exclusively to Vantio is refused. - -The founding call also stores an authority ceiling and an initial policy. The policy must be a subset of the ceiling. Later `WIDEN` may move policy up to the ceiling and not past it. The plan does not define a ceremony for raising the ceiling, so this evaluator refuses that change instead of inventing one. - -## 4. Envelope subset - -A child envelope is inside a parent when: - -- hosts, destinations, actions, and domains are subsets -- every parent path constraint is still present -- a numeric cap is not raised, and a cap is not removed - -Adding a path constraint or lowering a cap is a narrow. Adding a destination, raising a cap, dropping a path constraint, or adding a domain is a widen. A grant that does any of those against the current policy is refused as `NOT_A_DELEGATION_WIDENS`. `WIDEN` of policy must be a pure widen inside the ceiling, with `not_after` set. The duration number is `NOT_SET`. The caller supplies the timestamps. The module does not invent a product limit. - -## 5. Grants, spawn, and expiry - -A new grant requires class `WIDEN`, two distinct customer identities inside the recognized set, and a delegate who is not one of those two. The delegator must be in the root set. Any other delegator is `REDELEGATION_FORBIDDEN` while EG-D1 stays unresolved. A `redelegation: allowed` flag is refused. - -`noteSpawn` does not insert a grant. A child envelope must be a subset of the grant scope while the window is open, and a subset of `rollback_target` after the clock passes `not_after` or after revocation. It must also be a subset of the current customer policy, so a later root `NARROW` bounds grants that were approved under a wider envelope. A child outside that intersection is refused with `within_subset: false`. A missing parent does not mint a grant. - -Approval compares `not_before` and `not_after` to the process clock. Before `not_before`, exercise is `NOT_YET` and `can_exercise` is false, including a security grant, so that grant does not narrow policy yet. `noteClock` into the window opens it. After `not_after`, or when `not_after` is already past at approval, exercise is `ENDED`. `noteSpawn` applies the same window when `now` is present: a `now` before `not_before` does not return `PARENT_EGRESS_SCOPE_ONLY` or `within_subset: true`. Omitting `now` on an ended grant returns `ROLLBACK_SCOPE_ONLY`. - -`ENDED` stays ended. A later `noteClock` before `not_before` does not write `NOT_YET`, and a later `noteClock` inside the old window does not write `OPEN` or set `can_exercise` true. The grant state is not set to `EXPIRED`, and `host_expanded_authority_cleared` stays `UNSATISFIED`. That is the record half of EG-E2-8. The host half stays `RECORD_LAYER_ONLY_HOST_UNSATISFIED` because host maps are not read. - -A policy `WIDEN` whose `not_before` is still in the future is stored on `open_widens` with that start time, the policy at approval (`baseline`), and the approved envelope. It stays off `root.policy` until a clock reaches the window. At that clock the evaluator composes the authority the approval added, measured against `baseline`, onto the policy then in force. A later narrow that cut an action, lowered a cap below the baseline, or added a path constraint stays in force. A cap a later narrow set between the approval baseline and the stored widen target stays too; the deferred widen does not raise it. A later approval that sets the live cap above that recorded ceiling stays at the live cap. The older widen's stored target is not restored on a later clock, including a clock that drops an expired sibling. A destination, host, action, or domain the approval added is applied when a later narrow left it in place. A later narrow that removed one, including a cut made while the window was already open, keeps it out on entry, after a clock back before `not_before`, and on re-entry. Two deferred widens approved from the same baseline both contribute while their own windows contain the clock, so a spend approval and a destination approval survive together. - -A recorded freeze leaves every still-unapplied entry unapplied, including after a later narrow and when two widens are pending. `noteClock` while `available` is false leaves policy version, spend, and destinations where they are, and does not roll back a widen that was already applied. A widen whose `not_after` is already past at approval is `POLICY_WIDEN_ENDED` with `policy_applied: false`. It is omitted from `open_widens`, so a later clock inside that past window does not expand policy. - -When a clock moves before `not_before`, or past `not_after`, that entry's authority is removed and every sibling whose window still contains the clock is composed again. The leaving entry's rollback is not substituted for the whole policy, so a sibling spend cap or destination is not dropped with it. After `not_after` the entry is dropped, and a later clock does not restore it. A clock back before the start leaves the entry deferred. Removing that entry does not add a destination, host, action, or domain, does not drop a path constraint, and does not raise a cap, including when the live cap already sits above a ceiling recorded on a sibling that remains open. Host clearance stays `UNSATISFIED`. - -## 6. Approval classes - -| Class | Seats | Notes | -| --- | --- | --- | -| `INSPECT` | One customer root, or one customer inside an open read grant | A policy body on the call is refused | -| `NARROW` | The root, or one customer holding an open security grant | The change must be a strict subset. A delegate cannot change domains or edit outside the grant | -| `WIDEN` | Exactly two distinct customer identities. EG-D2 default | A witness does not count. Three seats are refused. The same id twice is rejected | -| `ROOT` | A member of the root set. EG-D9 default is one | Owner set, recovery party, witness removal, enroll intent, retire intent, security and recovery revocation | -| `RECOVERY` | The recovery party or the root | Completes with no Vantio seat. Modes are `last-known`, `observe-only`, and `stay-quarantined` | -| Missing class | None | `REFUSED` / `MISSING_CLASS` | -| Rejected acts | None | `REJECTED`. No approval record is stored | - -A recorded freeze uses `RECOVERY` and then blocks later grants and policy widens in this store, including apply of a deferred widen whose window a later clock enters. Narrowing still works. `host_freeze_performed` stays false. EG-E3-8 stays `HOST_UNSATISFIED`. - -`stay-quarantined` does not thaw. A proposed envelope outside the pre-containment snapshot is `WIDER_THAN_CEILING`. A fourth mode is rejected. That comparison is the record rule for EG-E3-7. It does not clear the Phantom Engine residual, so the requirement stays `RECORD_LAYER_ONLY_HOST_UNSATISFIED`. - -## 7. ACTIVE is a quote - -The enterprise grant state is never assigned `ACTIVE`. `quoteHostReport` accepts `source: "host_report"` only. `enterprise_writer`, `approver_click`, `console`, `dry_run`, `billing`, and `support` are rejected. The quote is stored beside the grant. `displayGrant` reports `display_active` only from that quote, with `verified_on_host: false` and `host_contacted: false`. A version mismatch does not store the quote. - -This is a caller-supplied quote inside a unit test or a later adapter. It is not evidence that a host was reached. - -## 8. Store outage - -`setRecordStoreAvailable(false)` blocks widening writes, including new grants and new `ACTIVE` quotes. A clock into an already approved deferred-widen window does not change policy version, spend, or destinations while the flag is false. A customer root can still record a freeze on the customer-held object; after the flag is turned back on, the freeze still blocks widening. `recover` and `leaveFromCustomerHeldMaterial` read the material argument and do not require the hosted flag. A `vantio_only` holder is rejected. No bytes of prompts, completions, or credentials are stored. Those keys are refused. - -## 9. What a passing test does not prove - -| Id | This branch | Still unsatisfied | -| --- | --- | --- | -| EG-E2-8 | Record layer stops expanded exercise after the clock or revocation, and does not reopen it | Host maps were not read | -| EG-E3-7 | Wider-than-snapshot recovery is rejected in the record | Phantom Engine ceiling check was not run | -| EG-E3-8 | Freeze is a customer record | No one-shot freeze on a host Vantio does not operate | -| EG-SUB-6 | Not implemented | No customer-owned on-host channel | -| EG-SP-1 through EG-SP-5 | Not run | Need a host this process does not operate, with Vantio absent | - -Company-host dogfood is not the customer model (EG-D8). This workspace did not run those host tests, and a unit suite must not be described as if it had. diff --git a/docs/internal/enterprise-e1-e3/03-IMPLEMENTATION-REPORT.md b/docs/internal/enterprise-e1-e3/03-IMPLEMENTATION-REPORT.md deleted file mode 100644 index d04e7bc4..00000000 --- a/docs/internal/enterprise-e1-e3/03-IMPLEMENTATION-REPORT.md +++ /dev/null @@ -1,91 +0,0 @@ -# Enterprise E1–E3 implementation report - -Audience: INTERNAL_RESTRICTED - -Producer classification: `ENTERPRISE_E1_E3_INTERNAL_READY_FOR_COUNCIL` - -Producer: `bc-c9b05a34-636c-589b-987b-4ea94e4f8c4c` at https://cursor.com/agents/bc-c9b05a34-636c-589b-987b-4ea94e4f8c4c - -Model: Grok 4.7. This producer did not sit the council and did not mark the pull request ready. - -## What landed - -Private module `@vantio/enterprise-governance-internal` at `0.0.0-unstable-pre-1.0` under `internal/enterprise-governance/`. It is not in `pnpm-workspace.yaml`. It does not change `@vantio/cli` `0.3.24`, `vantio-agent-sdk` `3.1.0`, or the other published manifests. - -The plan packet under `docs/planning/enterprise-governance/` is byte-identical to the hashes in `GOVERNANCE-MANIFEST.json`. Its council file is still pending. EG-D1 through EG-D10 remain unresolved. EG-D5 and EG-D6 were left on the defaults named in the plan: no host activation in this repository, and no store product selected. - -## Checks - -From the repository root: - -```sh -node --test tests/enterprise-e1-e3/*.test.cjs -node docs/scripts/check-docs-release.mjs -``` - -The first producer run of the test command reported 32 tests and 0 failures. Direct tests cover founding, host intent, policy widen, grant window, narrow, recovery and freeze records, revocation, customer-held evidence, spawn, and inspect. Adversarial tests cover the rejected acts, self-approval, consensus, role labels, workload domains, redelegation, subset violations, child inheritance, writer sources, root-only acts, recovery ceiling, freeze, store outage, and prohibited fields. Isolation tests cover package paths, plan hashes, and the absence of network or host imports. - -## Revision - -Council `bc-6a9b9454-6006-513e-830b-47879601b121` returned `ENTERPRISE_E1_E3_INTERNAL_NEEDS_REVISION` on tip `2598d89c14085dcda280a574a372b5d81f28ae1f`. Revision producer: `bc-f6c05a63-83a5-5bd9-bcf6-ae26f1826380` at https://cursor.com/agents/bc-f6c05a63-83a5-5bd9-bcf6-ae26f1826380. This revision stays on draft pull request #100. Handoff token: `ENTERPRISE_E1_E3_INTERNAL_REVISION_READY_FOR_COUNCIL`. That token is not a council verdict and not host proof. - -Record-layer changes: - -- `not_before` closes exercise. An approved grant is `NOT_YET` with `can_exercise` false until the window, so a security grant does not narrow policy early. `noteSpawn` with `now` before `not_before` does not report parent egress or `within_subset: true`. A policy `WIDEN` with a future `not_before` is stored on `open_widens` and is written onto `root.policy` only when a clock enters the window. -- `ENDED` is sticky. A later clock before `not_before` does not become `NOT_YET`, and a clock back inside the window does not become `OPEN`. A grant whose `not_after` is already past is not left `OPEN`. Spawn without `now` on an ended grant returns `ROLLBACK_SCOPE_ONLY`. `host_expanded_authority_cleared` stays `UNSATISFIED`. EG-E2-8 remains `RECORD_LAYER_ONLY_HOST_UNSATISFIED`. -- A later root `NARROW` bounds existing grants. Spawn of a child outside the current customer envelope is refused with `within_subset: false`. - -The revision run of `node --test tests/enterprise-e1-e3/*.test.cjs` reported 35 tests and 0 failures. The three new adversarial tests cover those holds. EG-D1 through EG-D10 stay unresolved. EG-E3-7, EG-E3-8, EG-SUB-6, and EG-SP-1 through EG-SP-5 stay host-unsatisfied. `verified_on_host` stays false. No live customer authority was created. - -## Composition revision - -Council `bc-fb458789-7599-5abb-a10f-ccc17f25ead3` returned `ENTERPRISE_E1_E3_INTERNAL_NEEDS_REVISION` on tip `db70e93bca42d7d5be56b2afaed4d1c95a24cf24`. Revision producer: `bc-03d7917b-2c1d-55c3-bbe9-33637a05f4f7` at https://cursor.com/agents/bc-03d7917b-2c1d-55c3-bbe9-33637a05f4f7. This revision stays on draft pull request #100. Handoff token: `ENTERPRISE_E1_E3_INTERNAL_REVISION_READY_FOR_COUNCIL`. That token is not a council verdict and not host proof. - -Record-layer changes: - -- A deferred widen applies by composing the authority it added, relative to the policy at approval, onto the policy in force. A later root narrow to `read`, spend 15, and path constraints `p1` and `p2` stays in force when the window opens. The child `connect` / spend 50 stays `within_subset: false`. After the widen window, that narrow is still the policy. -- Two deferred widens from the same baseline, one adding destination `d2` and one raising spend to 80, both apply at window entry. The same second widen issued after an immediate first widen stays `NOT_A_PURE_WIDEN`. -- A recorded freeze still returns `FREEZE_RECORDED` for a later grant, and `noteClock` into the deferred window leaves spend and destinations unexpanded. -- While the store is unavailable, `proposeGrant` returns `STORE_UNAVAILABLE_NO_WIDEN`, and `noteClock` into the deferred window leaves policy version, spend, and destinations unchanged. -- A policy widen whose `not_after` is already past is `POLICY_WIDEN_ENDED` with `policy_applied: false`. Spend and destinations stay at the current policy, including when a later clock is placed inside that past window. - -The isolated `not_before`, sticky `ENDED`, and later-`NARROW` holds stay closed. The composition run of `node --test tests/enterprise-e1-e3/*.test.cjs` reported 40 tests and 0 failures. EG-D1 through EG-D10 stay unresolved. EG-E2-8 stays `RECORD_LAYER_ONLY_HOST_UNSATISFIED`. `verified_on_host` stays false. No live customer authority was created. CLI `0.3.24` and Python `3.1.0` are unchanged. - -## Sibling revision - -Council `bc-9e4306a5-2874-5ae1-ba2e-c6aadfd1ba5b` returned `ENTERPRISE_E1_E3_INTERNAL_NEEDS_REVISION` on tip `73f291b009f4b0d223c5003385f38973a3a5e8b1`. Revision producer: `bc-80600242-87e1-5cba-b975-527b8c52e798` at https://cursor.com/agents/bc-80600242-87e1-5cba-b975-527b8c52e798. This revision stays on draft pull request #100. Handoff token: `ENTERPRISE_E1_E3_INTERNAL_REVISION_READY_FOR_COUNCIL`. That token is not a council verdict and not host proof. - -Record-layer changes: - -- A later narrow that sets spend or size between the approval baseline and the stored widen target stays. `noteClock` inside the deferred window does not raise that cap to the stored target. -- A destination a later narrow removes is not treated as an addition still owed by an earlier deferred widen. The cut holds when the narrow lands before the window, and when it lands while the window is open, including clock-back before `not_before` and re-entry. The scripted narrow (`read`, spend 15, paths `p1` and `p2`) still holds through entry, clock-back, and expiry. `d2` still returns on re-entry when that narrow did not remove it. -- When one deferred widen expires, or a clock moves before its start, siblings whose windows still contain the clock are composed again. The leaving entry's rollback is not applied as the whole policy. A spend approval that runs longer than a destination approval stays at 80 after the destination window ends, and the symmetric case keeps `d2`. A clock from April back to February drops a spend widen that has not started and leaves `d2` in place. - -Holds C–E stay closed. A freeze still leaves pending widens unapplied after a later narrow. A store outage still leaves policy version, spend, and destinations unchanged, including an already-applied widen. A widen whose window has already ended stays `POLICY_WIDEN_ENDED` with `policy_applied: false`. - -The sibling run of `node --test tests/enterprise-e1-e3/*.test.cjs` reported 48 tests and 0 failures. EG-D1 through EG-D10 stay unresolved. EG-E2-8 stays `RECORD_LAYER_ONLY_HOST_UNSATISFIED`. `verified_on_host` stays false. No live customer authority was created. CLI `0.3.24` and Python `3.1.0` are unchanged. - -## Ceiling revision - -Council `bc-3cc20d59-8923-5424-b1ba-ac17db02854a` returned `ENTERPRISE_E1_E3_INTERNAL_NEEDS_REVISION` on tip `34a1d2ad1007e573cc1fac137f334b2acb5c3a33`. Revision producer: `bc-d63660c7-e8e6-55e6-96dd-3d7f69c3241b` at https://cursor.com/agents/bc-d63660c7-e8e6-55e6-96dd-3d7f69c3241b. This revision stays on draft pull request #100. Handoff token: `ENTERPRISE_E1_E3_INTERNAL_REVISION_READY_FOR_COUNCIL`. That token is not a council verdict and not host proof. - -Record-layer change: - -- `composeCap` keeps a live cap that is already above the ceiling recorded on an older open widen. It does not restore that widen's stored target. An immediate widen to spend 90, a root narrow to 70, and a later immediate widen to 85 stay at 85 on `noteClock`. The same shape for size stays at 75. With a deferred spend-80 window still open, a later approval of 75 survives the January clock. A March clock that drops an expired `d2` leaves spend at 75. The recorded ceiling on the older widen stays 70. - -Holds A–E stay closed. The isolated `not_before`, sticky `ENDED`, and later-`NARROW` holds stay closed. A cap equal to the recorded ceiling still stays there, including the scripted narrow to spend 70 and the sibling expiry that keeps spend 80 after `d2` drops. - -The ceiling run of `node --test tests/enterprise-e1-e3/*.test.cjs` reported 52 tests and 0 failures. EG-D1 through EG-D10 stay unresolved. EG-E2-8 stays `RECORD_LAYER_ONLY_HOST_UNSATISFIED`. `verified_on_host` stays false. No live customer authority was created. CLI `0.3.24` and Python `3.1.0` are unchanged. - -`node docs/scripts/check-docs-release.mjs` fails `legacy-stale-name-inventory-frozen` on this branch and on starting commit `89f95099d0dce463307eb75d78e7fcf2ef99feb2`. The only named file is `tests/shared-health-vocabulary/collision.test.cjs`, which this force does not edit. The other release checks passed. This branch adds no stale-name file. - -## Hard-stop attestations - -- No live customer authority, credential, or external identity. -- No host contact. `verified_on_host` is false on every result. -- No second enforcement engine, enroll command, or kernel loader. -- No CLI, Python, workflow, or `docs/governance/` change. -- No plan-packet edit. Plan council was not marked passed. -- EG-SP-1 through EG-SP-5 were not run. EG-E3-8 and EG-SUB-6 stay host-unsatisfied. -- Schema stays `unstable-pre-1.0`. -- Draft pull request only. Not merged. diff --git a/docs/internal/enterprise-e1-e3/04-PENDING-COUNCIL.md b/docs/internal/enterprise-e1-e3/04-PENDING-COUNCIL.md deleted file mode 100644 index 49364e34..00000000 --- a/docs/internal/enterprise-e1-e3/04-PENDING-COUNCIL.md +++ /dev/null @@ -1,46 +0,0 @@ -# Pending council — Enterprise E1–E3 internal - -Audience: INTERNAL_RESTRICTED - -Status: `PENDING_INDEPENDENT_COUNCIL` - -Producer classification under review: `ENTERPRISE_E1_E3_INTERNAL_READY_FOR_COUNCIL` - -Revision handoff: `ENTERPRISE_E1_E3_INTERNAL_REVISION_READY_FOR_COUNCIL` - -That classification is the handoff. It is not a verdict. The producer `bc-c9b05a34-636c-589b-987b-4ea94e4f8c4c` does not fill the verdict column. A later revision on the same draft pull request closed three record-layer holds (`not_before`, sticky `ENDED`, and a later `NARROW` bounding existing grants). A further revision, after council `bc-fb458789-7599-5abb-a10f-ccc17f25ead3` returned `ENTERPRISE_E1_E3_INTERNAL_NEEDS_REVISION` on `db70e93bca42d7d5be56b2afaed4d1c95a24cf24`, closed deferred-widen composition holds A–E. Council `bc-9e4306a5-2874-5ae1-ba2e-c6aadfd1ba5b` then returned `ENTERPRISE_E1_E3_INTERNAL_NEEDS_REVISION` on `73f291b009f4b0d223c5003385f38973a3a5e8b1` and reopened holds A and B. A further revision on the same draft closed those two holds without reopening C–E or the isolated holds. Council `bc-3cc20d59-8923-5424-b1ba-ac17db02854a` then returned `ENTERPRISE_E1_E3_INTERNAL_NEEDS_REVISION` on `34a1d2ad1007e573cc1fac137f334b2acb5c3a33`: a clock restored a stored widen target when the live cap was already above the ceiling recorded for that widen. A further revision on the same draft keeps that live cap (spend 85, size 75, and spend 75 through a March clock that drops expired `d2`). None of these revisions fills the verdict column. Host proofs stay open. - -The plan council in `docs/planning/enterprise-governance/06-INDEPENDENT-COUNCIL.md` is a different review and is still pending. This file does not close it. - -## Identity to be filled by the council - -| Item | Value | -| --- | --- | -| Council agent | unset | -| Council URL | unset | -| Model | unset | -| Reviewed tip | unset | -| Reviewed at (UTC) | unset | -| Verdict | unset | - -## Seats - -| Seat | Scope | Verdict | -| --- | --- | --- | -| 1 | Record layer versus host proof, including EG-E2-8, EG-E3-7, EG-E3-8, EG-SUB-6, and EG-SP-1 through EG-SP-5 | `PENDING_INDEPENDENT_COUNCIL` | -| 2 | E1 title, root set, and host intent versus enrollment | `PENDING_INDEPENDENT_COUNCIL` | -| 3 | E2 subset, expiry, redelegation, and spawn | `PENDING_INDEPENDENT_COUNCIL` | -| 4 | E3 classes and rejected acts | `PENDING_INDEPENDENT_COUNCIL` | -| 5 | Self-approval, agent consensus, and role-as-proof | `PENDING_INDEPENDENT_COUNCIL` | -| 6 | Customer-held freeze, revoke, and recover versus a Vantio-only path | `PENDING_INDEPENDENT_COUNCIL` | -| 7 | Store outage does not widen | `PENDING_INDEPENDENT_COUNCIL` | -| 8 | Prohibited fields and the absence of credentials | `PENDING_INDEPENDENT_COUNCIL` | -| 9 | No package change, no second enforcement plane, no identity provider | `PENDING_INDEPENDENT_COUNCIL` | -| 10 | EG-D1 through EG-D10 left unresolved, including EG-D5 and EG-D6 | `PENDING_INDEPENDENT_COUNCIL` | - -## What the council reviews - -- `internal/enterprise-governance/` and `tests/enterprise-e1-e3/` against the plan packet at merge `8eb353a94c08c1adaaa36d36e2536ee5619e9eb6`, which is an ancestor of starting commit `89f95099d0dce463307eb75d78e7fcf2ef99feb2`. -- The architecture notes in `02-ARCHITECTURE.md`. -- Absence of diffs under `packages/`, `extensions/`, `.github/`, `docs/governance/`, and `docs/planning/enterprise-governance/`. -- The producer did not write a pass in the verdict column. diff --git a/docs/internal/enterprise-e1-e3/STATUS.json b/docs/internal/enterprise-e1-e3/STATUS.json deleted file mode 100644 index 77d615cb..00000000 --- a/docs/internal/enterprise-e1-e3/STATUS.json +++ /dev/null @@ -1,71 +0,0 @@ -{ - "document": "ENTERPRISE-E1-E3-INTERNAL-STATUS", - "audience": "INTERNAL_RESTRICTED", - "schema_status": "unstable-pre-1.0", - "schema_version": 0, - "producer_classification": "ENTERPRISE_E1_E3_INTERNAL_READY_FOR_COUNCIL", - "council_status": "PENDING_INDEPENDENT_COUNCIL", - "council_verdict": null, - "producer": "bc-c9b05a34-636c-589b-987b-4ea94e4f8c4c", - "revision_classification": "ENTERPRISE_E1_E3_INTERNAL_REVISION_READY_FOR_COUNCIL", - "revision_of": "2598d89c14085dcda280a574a372b5d81f28ae1f", - "prior_council": "bc-6a9b9454-6006-513e-830b-47879601b121", - "composition_revision_classification": "ENTERPRISE_E1_E3_INTERNAL_REVISION_READY_FOR_COUNCIL", - "composition_revision_of": "db70e93bca42d7d5be56b2afaed4d1c95a24cf24", - "composition_council": "bc-fb458789-7599-5abb-a10f-ccc17f25ead3", - "composition_producer": "bc-03d7917b-2c1d-55c3-bbe9-33637a05f4f7", - "council_2": "bc-9e4306a5-2874-5ae1-ba2e-c6aadfd1ba5b", - "council_2_verdict": "ENTERPRISE_E1_E3_INTERNAL_NEEDS_REVISION", - "sibling_revision_classification": "ENTERPRISE_E1_E3_INTERNAL_REVISION_READY_FOR_COUNCIL", - "sibling_revision_of": "73f291b009f4b0d223c5003385f38973a3a5e8b1", - "sibling_producer": "bc-80600242-87e1-5cba-b975-527b8c52e798", - "council_3": "bc-3cc20d59-8923-5424-b1ba-ac17db02854a", - "council_3_verdict": "ENTERPRISE_E1_E3_INTERNAL_NEEDS_REVISION", - "ceiling_revision_classification": "ENTERPRISE_E1_E3_INTERNAL_REVISION_READY_FOR_COUNCIL", - "ceiling_revision_of": "34a1d2ad1007e573cc1fac137f334b2acb5c3a33", - "ceiling_producer": "bc-d63660c7-e8e6-55e6-96dd-3d7f69c3241b", - "starting_commit": "89f95099d0dce463307eb75d78e7fcf2ef99feb2", - "plan_merge": "8eb353a94c08c1adaaa36d36e2536ee5619e9eb6", - "plan_situation": "ENTERPRISE_GOVERNANCE_E1_E3_PLAN_MERGED_NO_IMPLEMENTATION", - "plan_council": "PENDING_INDEPENDENT_COUNCIL", - "decisions_resolved": false, - "live_customer_authority": false, - "external_identity_created": false, - "credential_created": false, - "host_contacted": false, - "requirements": { - "EG-E1-1": "INTERNAL_RULE_ENFORCED", - "EG-E1-2": "INTERNAL_RULE_ENFORCED_HOST_MECHANISM_ABSENT", - "EG-E1-3": "INTERNAL_RULE_ENFORCED", - "EG-E1-4": "INTERNAL_RULE_ENFORCED_HOST_MECHANISM_ABSENT", - "EG-E1-5": "INTERNAL_RULE_ENFORCED", - "EG-E1-6": "INTERNAL_RULE_ENFORCED", - "EG-E2-1": "INTERNAL_RULE_ENFORCED", - "EG-E2-2": "INTERNAL_RULE_ENFORCED", - "EG-E2-3": "INTERNAL_RULE_ENFORCED", - "EG-E2-4": "INTERNAL_RULE_ENFORCED", - "EG-E2-5": "INTERNAL_RULE_ENFORCED", - "EG-E2-6": "INTERNAL_RULE_ENFORCED", - "EG-E2-7": "INTERNAL_RULE_ENFORCED", - "EG-E2-8": "RECORD_LAYER_ONLY_HOST_UNSATISFIED", - "EG-E3-1": "INTERNAL_RULE_ENFORCED", - "EG-E3-2": "INTERNAL_RULE_ENFORCED", - "EG-E3-3": "INTERNAL_RULE_ENFORCED", - "EG-E3-4": "INTERNAL_RULE_ENFORCED", - "EG-E3-5": "INTERNAL_RULE_ENFORCED", - "EG-E3-6": "INTERNAL_RULE_ENFORCED", - "EG-E3-7": "RECORD_LAYER_ONLY_HOST_UNSATISFIED", - "EG-E3-8": "HOST_UNSATISFIED", - "EG-SUB-1": "INTERNAL_RULE_ENFORCED", - "EG-SUB-2": "INTERNAL_RULE_ENFORCED", - "EG-SUB-3": "INTERNAL_RULE_ENFORCED_HOST_MECHANISM_ABSENT", - "EG-SUB-4": "INTERNAL_RULE_ENFORCED", - "EG-SUB-5": "INTERNAL_RULE_ENFORCED", - "EG-SUB-6": "HOST_UNSATISFIED", - "EG-SP-1": "NOT_RUN_HOST_UNSATISFIED", - "EG-SP-2": "NOT_RUN_HOST_UNSATISFIED", - "EG-SP-3": "NOT_RUN_HOST_UNSATISFIED", - "EG-SP-4": "NOT_RUN_HOST_UNSATISFIED", - "EG-SP-5": "NOT_RUN_HOST_UNSATISFIED" - } -} diff --git a/docs/internal/governance-assurance/00-BOUNDARY.md b/docs/internal/governance-assurance/00-BOUNDARY.md deleted file mode 100644 index e6e40594..00000000 --- a/docs/internal/governance-assurance/00-BOUNDARY.md +++ /dev/null @@ -1,61 +0,0 @@ -# WS17 Governance Assurance — boundary - -Audience: INTERNAL_RESTRICTED - -Package: `@vantio/governance-assurance` `0.2.0-internal` - -Producer classification: `WS17_GOVERNANCE_ASSURANCE_0_2_0_INTERNAL_REBIND_READY_FOR_COUNCIL` - -That classification is a producer handoff. It is not a council verdict. `council_status` stays `PENDING_INDEPENDENT_COUNCIL`. Reviewers of the independent council are not this producer. - -This packet supersedes producer classification `WS17_GOVERNANCE_ASSURANCE_READY_FOR_COUNCIL` from `0.1.0-internal`. The earlier handoff is not a verdict on this rebind. - -Release class: `NON-NORMATIVE`. `NOT_LEGAL_ADVICE`. `NO_COMPLIANCE_GUARANTEE`. - -Program claim ceiling: `INTERNAL_CLEAN_HOST_PROOF`. Installer token: `VANTIO_INSTALLER_REPEATABLE_PATH_PROVED_WITH_LIMITATIONS`. - -## Locked input - -| Item | Value | -| --- | --- | -| Repository | `vantioai/vantio-open-core` | -| First-packet start | `98ecaf6e9dd6fb831e7d2728379e2f785f41804f` | -| 0.1.0-internal currency | `a80fd4288df4983bf294aa219511ef60d86fa87c` | -| 0.2.0-internal currency | `b0bcbdeb01ccb84a58a3aa6aacd0c05f94b22450` | -| Branch | `cursor/ws17-governance-assurance-0.2.0-internal-4ba7` | - -The revision reads that tip so the Stage B close, the C5 integration record, and the merged Wave 2 tracks can be cited. Those citations do not count toward satisfaction. Ingress, egress, and Unit E stay uncounted. Enforcement efficacy stays `NOT_PROVED`. This revision does not self-council. - -## What this force contains - -- `packages/governance-assurance/` — private package, outside the pnpm workspace -- `tests/governance-assurance/` — producer tests -- `docs/internal/governance-assurance/` — these notes, the Stage B citation, and generated reports - -## What this force keeps closed - -- Publication, tags, npm, PyPI, and public release assets -- CLI `0.3.24`, npm SDK `0.2.4`, and Python `3.1.0` bytes -- Phantom Engine loader and enforcement runtime -- A fourth public product -- Legal advice, certification, conformity assessment, and regulator filings -- External procurement submission -- Customer deploy and stranger-host execution -- A self-assigned council pass -- `0.3.0`, `0.4.0`, and `1.0.0-customer-candidate` - -## Role - -Vantio is the runtime authority, enforcement, revocation, recovery, and independently verifiable evidence layer for AI governance on customer-controlled Linux infrastructure. Vantio supports governance programs; Vantio does **not** independently make an AI system lawful, compliant, certified, regulator-approved, unbiased, appropriate for a regulated use, safe for every environment, or conformant with every framework. - -## Report sections - -The force names the report files and the conclusions they must refuse. No separate founder addendum file was in the starting tree. The generated reports use the sections named by the force: provenance, role, claim ceiling, separated states, control rows, program bindings, open gates, Wave 2 bindings, responsibilities, framework versions, unsupported and external controls, procurement index, and verification instructions. They do not contain a compliance score. - -## Revision holds - -`EB-T1` binds GA-20 only. It is custody, version, and artifact identity. It does not satisfy GA-12 or GA-19. - -GA-24 does not take satisfaction from `packages/vantio-cli/package.json`. The public manual states that a secret placed in the URL path is stored, because the path is kept. That exception is on the control record. The row is not a pass. - -Stage B stays `PARTIAL_INTERNAL_CLEAN_HOST_PROOF`. RBK-004 stays `SOURCE_CLOSED_MERGED` without a live residual-only re-proof. Billing stays `STAGE_B_BILLING_CLOSE_PENDING`. Recordings A-H stay `NOT_CAPTURED`. C8 stays `DESIGN_COMPLETE_AWAITING_FOUNDER`. Class B stays `BLOCKED`. `PUBLIC_REWRITE` stays `HOLD`. `STAGE_B_DESTROY_PASS` stays on its own axis and does not close Council F. diff --git a/docs/internal/governance-assurance/08-VERSION-PROCEDURE.md b/docs/internal/governance-assurance/08-VERSION-PROCEDURE.md deleted file mode 100644 index 42c5aeeb..00000000 --- a/docs/internal/governance-assurance/08-VERSION-PROCEDURE.md +++ /dev/null @@ -1,24 +0,0 @@ -# Version procedure - -Audience: INTERNAL_RESTRICTED - -Current package version: `0.2.0-internal` - -It supersedes `0.1.0-internal`. Catalog rows whose capability version was the package version now use `0.2.0-internal` and set `supersedes` to `0.1.0-internal`. `review_date` is `2026-09-28` on every row. Product pins stay on their own capability versions with `supersedes` null: CLI `0.3.24`, npm SDK `0.2.4`, Python `3.1.0`. - -Soft-dependency currency for this rebind is `b0bcbdeb01ccb84a58a3aa6aacd0c05f94b22450`. The prior currency `a80fd4288df4983bf294aa219511ef60d86fa87c` remains the 0.1.0-internal citation point. Refreshing currency does not raise a proof class. - -The 0.2.0-internal packet cites the Stage B accepted close and the C5 integration record. It rereads the merged ingress, egress, and Unit E tracks. Those tracks still do not count toward satisfaction. Enforcement efficacy stays `NOT_PROVED`. O7 is cited as `INTERNAL_CLEAN_HOST_INITIALIZATION_PROOF` for an observe record with enforcement not enabled. That citation does not authorize the O7 store. Enterprise stays `NO_LIVE_CUSTOMER_AUTHORITY`. - -Council acceptance of this packet is a separate force. `council_status` stays `PENDING_INDEPENDENT_COUNCIL`. This package does not sit that council. - -| Version | When it is allowed | -| --- | --- | -| `0.2.0-internal` | This rebind. Wave 2 merges are cited, and the Stage B close is cited. Citing those facts does not grant satisfaction and does not authorize the next rung. | -| `0.3.0` | After a clean-host qualification that this partial Stage B proof does not supply. `BLOCKED_INFRA` and an unset evidence tier do not qualify. `PARTIAL_INTERNAL_CLEAN_HOST_PROOF` does not qualify. | -| `0.4.0` | After stranger-host execution is authorized and completed. Readiness does not qualify. | -| `1.0.0-customer-candidate` | Only after an external assessment, a disclosure review, and a separate release council. | - -A version bump does not raise a proof class. A prior pass does not survive a stale row. Mapping commit stays `NOT_SELF_HASHED` until a release process records the tip outside the hashed body. - -Open gates from the C5 record stay visible: Council F billing and C8, Council I recordings, the live RBK-004 re-proof, and Class B. diff --git a/docs/internal/governance-assurance/09-DISCLOSURE.md b/docs/internal/governance-assurance/09-DISCLOSURE.md deleted file mode 100644 index b0a0766c..00000000 --- a/docs/internal/governance-assurance/09-DISCLOSURE.md +++ /dev/null @@ -1,21 +0,0 @@ -# Disclosure — public and private paths - -Audience: INTERNAL_RESTRICTED - -## Where this packet lives - -The source is in the public `vantio-open-core` repository because that is where the other private internal packages live. The package is `private`, it is outside `pnpm-workspace.yaml`, and the npm promote list does not name it. The public README is unchanged. There is no public SKU. - -Distribution of the reports is `INTERNAL_RESTRICTED`. The public disclosure object withholds control rows, evidence hashes, Wave 2 states, and procurement detail. - -## What was kept generic - -Framework rows use identifiers, dates, and source URLs. ISO/IEC 42001 clause text is `SOURCE_ACCESS_REQUIRED`. No clause number is invented. Every control row is present with that reference, so the current-document unmapped list is empty. An empty list is not a clause map. EU rows are a technical crosswalk and do not classify a system. Federal rows point at OMB memoranda and do not copy a procurement strategy. Superseded OMB rows set `source_url` to the successor PDF. This register did not retrieve a separate copy of the rescinded memorandum. - -Host-authority evidence cites the contract-only manifest already in this tree. It does not add loader behavior or enforcement parameters. - -## Overlays - -Customer-confidential material, government bid strategy, and proprietary enforcement detail are not in this packet. Those overlays are `OVERLAY_REQUIRED` and are not stored here. See `overlays/README.md`. - -Proof class does not rise when an audience changes from internal to investor, customer, or assessor. Nothing in this packet is cleared for `PUBLIC` except the short disclosure object. diff --git a/docs/internal/governance-assurance/overlays/README.md b/docs/internal/governance-assurance/overlays/README.md deleted file mode 100644 index 8ccaf15e..00000000 --- a/docs/internal/governance-assurance/overlays/README.md +++ /dev/null @@ -1,13 +0,0 @@ -# Overlays - -Audience: INTERNAL_RESTRICTED - -No customer-confidential overlay is stored in this directory. - -No government procurement strategy overlay is stored in this directory. - -No proprietary Phantom Engine enforcement overlay is stored in this directory. - -Status: `OVERLAY_REQUIRED` for any future overlay. `SOURCE_ACCESS_REQUIRED` for ISO/IEC 42001 clause text. - -Do not commit those overlays onto this public tree. diff --git a/docs/internal/governance-assurance/reports/CONTROL_EVIDENCE_INDEX.json b/docs/internal/governance-assurance/reports/CONTROL_EVIDENCE_INDEX.json deleted file mode 100644 index 11998b72..00000000 --- a/docs/internal/governance-assurance/reports/CONTROL_EVIDENCE_INDEX.json +++ /dev/null @@ -1,1131 +0,0 @@ -{ - "bindings": [ - { - "artifact_records": [ - { - "path": "docs/programs/production-readiness/RELEASE-REGISTER.json", - "present": true, - "sha256": "f14f164592ddc8552e4dfbb7f92704419eeed1668d4a1a1e0dc7dde777568218" - } - ], - "artifact_status": "PRESENT", - "binding_id": "EB-T1", - "collection_source": "RELEASE-REGISTER.json REL-PY-3.1.0 close block", - "control_ids": [ - "GA-20" - ], - "count_control_ids": [ - "GA-20" - ], - "counts_toward_satisfaction": true, - "environment": "source tree vantio-open-core at b0bcbdeb01ccb84a58a3aa6aacd0c05f94b22450. Not a clean host and not a stranger host.", - "freshness": "CURRENT_FOR_CATALOG_REVIEW", - "independent_verifier": "UNSET", - "informs_posture": true, - "limitations": [ - "Custody, version, and artifact identity only. This record does not establish runtime observation or observation evidence capture.", - "Wheel sha256 dcf84cb3c4f144ece21032001657bfd9c91067faeffbefd0fb2ae19d6109dbeb and sdist sha256 9f991291d5e44a23e17a9b0d7db24f6e7048d4c76cf0a9c37e35ccbcfe999c4f are the pins the close says matched.", - "client_proof is CITED_PRIOR_VALID. Python 3.10 and 3.11 were NOT_REEXECUTED.", - "signature_reverified is false. formal_slsa_claim is false.", - "This force did not download the registry and did not mutate Python 3.1.0." - ], - "producer": "production-readiness release register", - "product_version": "3.1.0", - "prohibited_interpretations": [ - "Do not read the close as stranger-host proof, customer validation, or enforcement.", - "Do not count this record toward GA-12 or GA-19." - ], - "proof_class": "RELEASE_CLOSE_PACKET", - "source_commit": "b0bcbdeb01ccb84a58a3aa6aacd0c05f94b22450", - "timestamp": "2026-09-27T11:18:04Z", - "title": "Python 3.1.0 release-close packet", - "track_id": "T1", - "verification_result": "REGISTRY_HASHES_MATCH_AUTHORIZED_PINS_CLIENT_NOT_REEXECUTED", - "wave2_state": "RELEASE_CLOSED_REGISTRY_VERIFIED" - }, - { - "artifact_records": [ - { - "path": "docs/planning/optics-option-c-revalidation/00-REVALIDATION.md", - "present": true, - "sha256": "ed2c8be7a0d601116d145a0ffb311389b2c066f72bb13c67694c99aa9cd76f6a" - } - ], - "artifact_status": "PRESENT", - "binding_id": "EB-T3", - "collection_source": "00-REVALIDATION.md section 6", - "control_ids": [ - "GA-19" - ], - "count_control_ids": [], - "counts_toward_satisfaction": false, - "environment": "source tree vantio-open-core at b0bcbdeb01ccb84a58a3aa6aacd0c05f94b22450. Not a clean host and not a stranger host.", - "freshness": "UNSET", - "independent_verifier": "UNSET", - "informs_posture": false, - "limitations": [ - "O7 status on this tree is NOT_AUTHORIZED.", - "Founder decision 9 is unresolved. The Node binding is BLOCKED_NODE until that decision and an O6 selection exist.", - "No council pass is claimed. This catalog does not open a store.", - "Stage B cites O7 INTERNAL_CLEAN_HOST_INITIALIZATION_PROOF for an observe record with enforcement NOT_ENABLED. That citation does not authorize this store and does not count toward satisfaction." - ], - "producer": "option-c revalidation packet", - "product_version": "not-opened", - "prohibited_interpretations": [ - "Do not treat a predecessor check as a database.", - "Do not treat BLOCKED_NODE as a chosen library." - ], - "proof_class": "DESIGN_RECORD", - "source_commit": "b0bcbdeb01ccb84a58a3aa6aacd0c05f94b22450", - "timestamp": "UNKNOWN", - "title": "O7 store remains unauthorized", - "track_id": "T3", - "verification_result": "O7_NOT_AUTHORIZED_DECISION_9_UNRESOLVED_BLOCKED_NODE", - "wave2_state": "NOT_IMPLEMENTED_UNVERIFIED_BLOCKED_NODE" - }, - { - "artifact_records": [ - { - "path": "docs/internal/shared-health-runtime/BOUNDARY.md", - "present": true, - "sha256": "8716ccad2a1871bea8ae9a188e8d940e3bdae36897500141dc346eee47b27f42" - }, - { - "path": "packages/shared-health-runtime/package.json", - "present": true, - "sha256": "8814eeb38912ca69709ef90919ad7f9c3f89f9cf393c850d120fb1baf696c98b" - } - ], - "artifact_status": "PRESENT", - "binding_id": "EB-T4", - "collection_source": "docs/internal/shared-health-runtime/BOUNDARY.md", - "control_ids": [ - "GA-21", - "GA-28" - ], - "count_control_ids": [ - "GA-28" - ], - "counts_toward_satisfaction": true, - "environment": "source tree vantio-open-core at b0bcbdeb01ccb84a58a3aa6aacd0c05f94b22450. Not a clean host and not a stranger host.", - "freshness": "CURRENT_FOR_CATALOG_REVIEW", - "independent_verifier": "UNSET", - "informs_posture": true, - "limitations": [ - "No Phantom Engine runtime integration is claimed.", - "Emitted freshness is UNKNOWN.", - "audit.green stays false. A healthy token is not a measured latch." - ], - "producer": "shared-health runtime package", - "product_version": "0.0.0-unstable-pre-1.0", - "prohibited_interpretations": [ - "Do not read the health package as live enforcement or as independent verification." - ], - "proof_class": "PRODUCER_TEST", - "source_commit": "b0bcbdeb01ccb84a58a3aa6aacd0c05f94b22450", - "timestamp": "UNKNOWN", - "title": "Shared health runtime", - "track_id": "T4", - "verification_result": "IMPLEMENTED_INTERNAL_GREEN_FALSE_NO_PE_INTEGRATION", - "wave2_state": "IMPLEMENTED_INTERNAL" - }, - { - "artifact_records": [ - { - "path": "docs/internal/pe-ingress/INGRESS-MANIFEST.json", - "present": true, - "sha256": "d19c7af47b84420e6b571daf48e33687cece57302082a94ac9e89dec2ee4c277" - }, - { - "path": "packages/pe-ingress-authority/src/constants.cjs", - "present": true, - "sha256": "9140b55b6513cb5bfa8bf90bc65e0fe0e78f7cc76d272ae165b43589a985f53a" - } - ], - "artifact_status": "PRESENT", - "binding_id": "EB-T5", - "collection_source": "merge eb34662c120199c6e58b9cb01011c54363ea3f91 PE_INGRESS_PROGRAM_MERGED_OBSERVE_ONLY_LOADER_UNTOUCHED", - "control_ids": [ - "GA-14" - ], - "count_control_ids": [], - "counts_toward_satisfaction": false, - "environment": "source tree vantio-open-core at b0bcbdeb01ccb84a58a3aa6aacd0c05f94b22450. Not a clean host and not a stranger host.", - "freshness": "CURRENT_FOR_CATALOG_REVIEW", - "independent_verifier": "UNSET", - "informs_posture": true, - "limitations": [ - "packet_plane is OBSERVE_ONLY. packet_effect stays NOT_APPLIED. live_loader_mutated is false.", - "The ingress program council is a different force. This catalog does not sit it and does not re-execute the tests.", - "The 0.2.0 rebind read this merge and still does not count it toward satisfaction. Stage B enforcement efficacy is NOT_PROVED." - ], - "producer": "pe-ingress-authority package", - "product_version": "0.0.0-internal", - "prohibited_interpretations": [ - "Do not mark ingress satisfied because it merged observe-only.", - "Do not describe OBSERVE_ONLY as enforcement or as a loader edit." - ], - "proof_class": "DESIGN_RECORD", - "source_commit": "eb34662c120199c6e58b9cb01011c54363ea3f91", - "timestamp": "UNKNOWN", - "title": "Ingress program merged observe-only", - "track_id": "T5", - "verification_result": "MERGED_OBSERVE_ONLY_NOT_COUNTED", - "wave2_state": "MERGED_OBSERVE_ONLY_LOADER_UNTOUCHED" - }, - { - "artifact_records": [ - { - "path": "docs/internal/pe-egress/EGRESS-MANIFEST.json", - "present": true, - "sha256": "d8102bb740b9df10a4376e7d90a71053f0ce48f866fd578eb44d7fdc8816ac8b" - }, - { - "path": "packages/pe-egress-authority/src/decision.cjs", - "present": true, - "sha256": "82d60106a082fa6d16019e2c52a3d83f49db15042998c600ea989995ed376e42" - } - ], - "artifact_status": "PRESENT", - "binding_id": "EB-T6", - "collection_source": "merge 6e6c7d1d79fb9af8de7cffe321022e2521b184bd PE_EGRESS_PROGRAM_MERGED_CONTRACT_ONLY_HOST_NETWORK_NOT_EXECUTED", - "control_ids": [ - "GA-15" - ], - "count_control_ids": [], - "counts_toward_satisfaction": false, - "environment": "source tree vantio-open-core at b0bcbdeb01ccb84a58a3aa6aacd0c05f94b22450. Not a clean host and not a stranger host.", - "freshness": "CURRENT_FOR_CATALOG_REVIEW", - "independent_verifier": "UNSET", - "informs_posture": true, - "limitations": [ - "this_force_executed_host is false. this_force_executed_network is false. optimistic_allow is false.", - "The egress program council is a different force. This catalog does not sit it and does not re-execute the tests.", - "The 0.2.0 rebind read this merge and still does not count it toward satisfaction. Stage B enforcement efficacy is NOT_PROVED." - ], - "producer": "pe-egress-authority package", - "product_version": "0.0.0-internal", - "prohibited_interpretations": [ - "Do not mark egress enforcement satisfied from a contract case or from the merge.", - "Do not treat observation as an egress block." - ], - "proof_class": "DESIGN_RECORD", - "source_commit": "6e6c7d1d79fb9af8de7cffe321022e2521b184bd", - "timestamp": "UNKNOWN", - "title": "Egress program merged contract-only", - "track_id": "T6", - "verification_result": "MERGED_CONTRACT_ONLY_NOT_COUNTED", - "wave2_state": "MERGED_CONTRACT_ONLY_HOST_NETWORK_NOT_EXECUTED" - }, - { - "artifact_records": [ - { - "path": "docs/internal/pe-host-authority/HOST-AUTHORITY-MANIFEST.json", - "present": true, - "sha256": "db77a98acf8db8c1b3dd8e0c528cdf344b391534a5b53a6d485d5b9bc133fae5" - } - ], - "artifact_status": "PRESENT", - "binding_id": "EB-T7", - "collection_source": "HOST-AUTHORITY-MANIFEST.json", - "control_ids": [ - "GA-10", - "GA-11", - "GA-13", - "GA-32" - ], - "count_control_ids": [], - "counts_toward_satisfaction": false, - "environment": "source tree vantio-open-core at b0bcbdeb01ccb84a58a3aa6aacd0c05f94b22450. Not a clean host and not a stranger host.", - "freshness": "CURRENT_FOR_CATALOG_REVIEW", - "independent_verifier": "UNSET", - "informs_posture": false, - "limitations": [ - "kernel_loaded_this_force is false. loader_mutated_this_force is false.", - "clean_host_infrastructure is false. stranger_host is NOT_RUN.", - "Contract rows are not runtime enforcement." - ], - "producer": "pe-host-authority package", - "product_version": "0.0.0-internal-proof", - "prohibited_interpretations": [ - "Do not promote CONTRACT_ONLY to host enforcement or to clean-host proof." - ], - "proof_class": "CONTRACT_EVALUATION", - "source_commit": "b0bcbdeb01ccb84a58a3aa6aacd0c05f94b22450", - "timestamp": "UNKNOWN", - "title": "Host-authority contract", - "track_id": "T7", - "verification_result": "CONTRACT_ONLY_KERNEL_NOT_EXECUTED", - "wave2_state": "CONTRACT_ONLY" - }, - { - "artifact_records": [ - { - "path": "packages/pe-sequential-authority/src/result.cjs", - "present": true, - "sha256": "1fada36c770c3cd0ba39186adc22123c6eb9b5142cbd9e68da8ac09693990020" - } - ], - "artifact_status": "PRESENT", - "binding_id": "EB-T8", - "collection_source": "result.cjs host_attachment false, merge 842a4ce1e2578eff3baa8ccd41113fb03071769a", - "control_ids": [ - "GA-13", - "GA-17", - "GA-30", - "GA-32" - ], - "count_control_ids": [ - "GA-17", - "GA-30" - ], - "counts_toward_satisfaction": true, - "environment": "source tree vantio-open-core at b0bcbdeb01ccb84a58a3aa6aacd0c05f94b22450. Not a clean host and not a stranger host.", - "freshness": "CURRENT_FOR_CATALOG_REVIEW", - "independent_verifier": "UNSET", - "informs_posture": true, - "limitations": [ - "The merge subject records evaluate-only and host_attachment false.", - "This catalog does not re-adjudicate that council and does not call the result external proof.", - "Counts only toward in-process evaluation rows. Satisfaction still refuses a compliance pass." - ], - "producer": "pe-sequential-authority package", - "product_version": "0.0.0-unstable-pre-1.0", - "prohibited_interpretations": [ - "Do not describe the merge as host attachment or as kernel enroll." - ], - "proof_class": "PRODUCER_TEST", - "source_commit": "842a4ce1e2578eff3baa8ccd41113fb03071769a", - "timestamp": "UNKNOWN", - "title": "Sequential and aggregate authority", - "track_id": "T8", - "verification_result": "EVALUATE_ONLY_HOST_ATTACHMENT_FALSE", - "wave2_state": "MERGED_EVALUATE_ONLY_HOST_ATTACHMENT_FALSE" - }, - { - "artifact_records": [ - { - "path": "packages/pe-progressive-enforcement/src/boundary.cjs", - "present": true, - "sha256": "db84e9d981726fea920af11dc7541645d4b74cf25afa91ea2690d9b323fbbe07" - } - ], - "artifact_status": "PRESENT", - "binding_id": "EB-T9", - "collection_source": "boundary.cjs", - "control_ids": [ - "GA-13", - "GA-31", - "GA-32" - ], - "count_control_ids": [ - "GA-31" - ], - "counts_toward_satisfaction": true, - "environment": "source tree vantio-open-core at b0bcbdeb01ccb84a58a3aa6aacd0c05f94b22450. Not a clean host and not a stranger host.", - "freshness": "CURRENT_FOR_CATALOG_REVIEW", - "independent_verifier": "UNSET", - "informs_posture": true, - "limitations": [ - "host_attachment is NOT_PERFORMED. live_enforcement is false. auto_enforce_from_observation is false.", - "Separate this from host enforcement." - ], - "producer": "pe-progressive-enforcement package", - "product_version": "0.0.0-unstable-pre-1.0", - "prohibited_interpretations": [ - "Do not treat an in-process stage as a host enforce action." - ], - "proof_class": "PRODUCER_TEST", - "source_commit": "b0bcbdeb01ccb84a58a3aa6aacd0c05f94b22450", - "timestamp": "UNKNOWN", - "title": "Progressive enforcement lifecycle", - "track_id": "T9", - "verification_result": "IN_PROCESS_HOST_ATTACHMENT_NOT_PERFORMED", - "wave2_state": "MERGED_IN_PROCESS_HOST_ATTACHMENT_NOT_PERFORMED" - }, - { - "artifact_records": [ - { - "path": "docs/planning/clean-host-lifecycle/execution/EXECUTION-MANIFEST.json", - "present": true, - "sha256": "0c9a1c5b675a9914799fe573070339082db082a8798f300bde224871b9ef17a9" - } - ], - "artifact_status": "PRESENT", - "binding_id": "EB-T10", - "collection_source": "EXECUTION-MANIFEST.json", - "control_ids": [ - "GA-27", - "GA-33", - "GA-40" - ], - "count_control_ids": [], - "counts_toward_satisfaction": false, - "environment": "source tree vantio-open-core at b0bcbdeb01ccb84a58a3aa6aacd0c05f94b22450. Not a clean host and not a stranger host.", - "freshness": "UNSET", - "independent_verifier": "UNSET", - "informs_posture": false, - "limitations": [ - "sequence_result is BLOCKED_INFRA. evidence_tier is UNSET.", - "The guard-script exit is not a sequence pass.", - "Does not count toward control satisfaction.", - "Stage B PARTIAL_INTERNAL_CLEAN_HOST_PROOF is a different program. It does not clear BLOCKED_INFRA and it does not qualify 0.3.0." - ], - "producer": "clean-host execution packet", - "product_version": "blocked", - "prohibited_interpretations": [ - "Do not treat exit 0 of check-guards.sh as clean-host proof." - ], - "proof_class": "BLOCKED_UNSET", - "source_commit": "b0bcbdeb01ccb84a58a3aa6aacd0c05f94b22450", - "timestamp": "2026-09-27T11:18:58Z", - "title": "Clean-host execution", - "track_id": "T10", - "verification_result": "BLOCKED_INFRA_EVIDENCE_UNSET", - "wave2_state": "BLOCKED_INFRA" - }, - { - "artifact_records": [ - { - "path": "docs/internal/investor-demo-wave2/WAVE2-MANIFEST.json", - "present": true, - "sha256": "16030199a2ebbc39f8564f44d782db893b53fb60673e2fe6bcceb20203788b09" - } - ], - "artifact_status": "PRESENT", - "binding_id": "EB-T11", - "collection_source": "WAVE2-MANIFEST.json", - "control_ids": [ - "GA-39" - ], - "count_control_ids": [], - "counts_toward_satisfaction": false, - "environment": "source tree vantio-open-core at b0bcbdeb01ccb84a58a3aa6aacd0c05f94b22450. Not a clean host and not a stranger host.", - "freshness": "NOT_APPLICABLE", - "independent_verifier": "UNSET", - "informs_posture": false, - "limitations": [ - "external_proof is NOT_PROVED_EXTERNAL. A demo is never compliance proof." - ], - "producer": "investor-demo package", - "product_version": "0.0.0-unstable-pre-1.0", - "prohibited_interpretations": [ - "Do not use the investor demo as evidence that a control is met." - ], - "proof_class": "NOT_COMPLIANCE_ELIGIBLE", - "source_commit": "b0bcbdeb01ccb84a58a3aa6aacd0c05f94b22450", - "timestamp": "UNKNOWN", - "title": "Investor demo", - "track_id": "T11", - "verification_result": "NOT_COMPLIANCE_PROOF", - "wave2_state": "DEMO_NOT_COMPLIANCE_PROOF" - }, - { - "artifact_records": [ - { - "path": "packages/optics-otel-i3/src/boundary.cjs", - "present": true, - "sha256": "6d121dcbcb51db7fb860c26ee16a17321007558e60ea9372dbe2da268f40dd8e" - } - ], - "artifact_status": "PRESENT", - "binding_id": "EB-T12", - "collection_source": "boundary.cjs", - "control_ids": [ - "GA-29" - ], - "count_control_ids": [], - "counts_toward_satisfaction": false, - "environment": "source tree vantio-open-core at b0bcbdeb01ccb84a58a3aa6aacd0c05f94b22450. Not a clean host and not a stranger host.", - "freshness": "CURRENT_FOR_CATALOG_REVIEW", - "independent_verifier": "UNSET", - "informs_posture": true, - "limitations": [ - "default_enabled is false. product_otlp_export_authorized is false.", - "otlp_metrics and otlp_logs are NOT_AUTHORIZED.", - "Interoperability is not operational until configured and independently verified. That verification is absent." - ], - "producer": "optics-otel-i3 package", - "product_version": "0.0.0-unstable-pre-1.0", - "prohibited_interpretations": [ - "Do not treat the adapter file as a live export." - ], - "proof_class": "PRODUCER_TEST", - "source_commit": "b0bcbdeb01ccb84a58a3aa6aacd0c05f94b22450", - "timestamp": "UNKNOWN", - "title": "OTLP I3 adapter", - "track_id": "T12", - "verification_result": "DEFAULT_DISABLED_NOT_OPERATIONAL", - "wave2_state": "IMPLEMENTED_INTERNAL_DEFAULT_DISABLED" - }, - { - "artifact_records": [ - { - "path": "docs/planning/enterprise-governance/00-PROGRAM-BOUNDARY.md", - "present": true, - "sha256": "73feb095fa90b6b9310e13d059dd595e177cf18b7946ad015ddc2dab1a30f87e" - } - ], - "artifact_status": "PRESENT", - "binding_id": "EB-T13", - "collection_source": "00-PROGRAM-BOUNDARY.md", - "control_ids": [ - "GA-05", - "GA-06", - "GA-07", - "GA-08", - "GA-09", - "GA-18", - "GA-23", - "GA-36" - ], - "count_control_ids": [], - "counts_toward_satisfaction": false, - "environment": "source tree vantio-open-core at b0bcbdeb01ccb84a58a3aa6aacd0c05f94b22450. Not a clean host and not a stranger host.", - "freshness": "CURRENT_FOR_CATALOG_REVIEW", - "independent_verifier": "UNSET", - "informs_posture": false, - "limitations": [ - "The packet says it does not authorize an implementation.", - "Internal plan and customer deploy are different. Neither is live here.", - "The 0.2.0 rebind leaves Enterprise at NO_LIVE_CUSTOMER_AUTHORITY. A Stage B observe record is not a live customer authority object." - ], - "producer": "enterprise planning packet", - "product_version": "plan-only", - "prohibited_interpretations": [ - "Do not describe the plan as customer authority or as a council pass." - ], - "proof_class": "DESIGN_RECORD", - "source_commit": "b0bcbdeb01ccb84a58a3aa6aacd0c05f94b22450", - "timestamp": "UNKNOWN", - "title": "Enterprise E1-E3 plan", - "track_id": "T13", - "verification_result": "NO_LIVE_CUSTOMER_AUTHORITY", - "wave2_state": "PLAN_ONLY_NO_LIVE_CUSTOMER_AUTHORITY" - }, - { - "artifact_records": [ - { - "path": "docs/programs/release-engineering/WS11-MANIFEST.json", - "present": true, - "sha256": "152feef78ec05b0b0ab97b404435cc6964fdc6c6e93d4041b67f7dc5c002af3e" - } - ], - "artifact_status": "PRESENT", - "binding_id": "EB-T14", - "collection_source": "WS11-MANIFEST.json", - "control_ids": [ - "GA-02", - "GA-26" - ], - "count_control_ids": [ - "GA-02", - "GA-26" - ], - "counts_toward_satisfaction": true, - "environment": "source tree vantio-open-core at b0bcbdeb01ccb84a58a3aa6aacd0c05f94b22450. Not a clean host and not a stranger host.", - "freshness": "CURRENT_FOR_CATALOG_REVIEW", - "independent_verifier": "UNSET", - "informs_posture": true, - "limitations": [ - "formal_slsa_level, formal_certification, formal_reproducibility, and hardware_backed_provenance are NOT_CLAIMED.", - "council_pass is false. release_success is false.", - "A later git merge of the packet is not a certification." - ], - "producer": "WS11 release engineering", - "product_version": "characterized", - "prohibited_interpretations": [ - "Do not read characterization as SLSA, a certificate, or a publish authorization." - ], - "proof_class": "CHARACTERIZATION", - "source_commit": "45b9d998e3ac92e944c4ab5bfbc40e0706ea4fd7", - "timestamp": "UNKNOWN", - "title": "WS11 release characterization", - "track_id": "T14", - "verification_result": "CHARACTERIZED_FORMAL_CLAIMS_NOT_CLAIMED", - "wave2_state": "CHARACTERIZED_NO_FORMAL_CERTIFICATION" - }, - { - "artifact_records": [ - { - "path": "docs/planning/stranger-host-gate/PACKET-MANIFEST.json", - "present": true, - "sha256": "e3177a98ca0fc9cfddb44aef9dcc0e3996fe17616f38df23f7dc8749a8addacd" - } - ], - "artifact_status": "PRESENT", - "binding_id": "EB-T16", - "collection_source": "PACKET-MANIFEST.json", - "control_ids": [ - "GA-34" - ], - "count_control_ids": [], - "counts_toward_satisfaction": false, - "environment": "source tree vantio-open-core at b0bcbdeb01ccb84a58a3aa6aacd0c05f94b22450. Not a clean host and not a stranger host.", - "freshness": "CURRENT_FOR_CATALOG_REVIEW", - "independent_verifier": "UNSET", - "informs_posture": false, - "limitations": [ - "execution_status is NOT_AUTHORIZED. placeholder_execution is NOT_EXECUTED.", - "No evidence tier is assigned. This force did not execute a stranger host.", - "NEXT_LAB is NOT_YET_AUTHORIZED. Class B provision is BLOCKED. PUBLIC_REWRITE stays HOLD." - ], - "producer": "stranger-host prep packet", - "product_version": "readiness-only", - "prohibited_interpretations": [ - "Do not treat readiness as external proof.", - "Do not treat Phantom-Box as a stranger host." - ], - "proof_class": "DESIGN_RECORD", - "source_commit": "b0bcbdeb01ccb84a58a3aa6aacd0c05f94b22450", - "timestamp": "UNKNOWN", - "title": "Stranger-host readiness", - "track_id": "T16", - "verification_result": "EXECUTION_NOT_AUTHORIZED", - "wave2_state": "READINESS_ONLY_EXECUTION_NOT_AUTHORIZED" - }, - { - "artifact_records": [], - "artifact_status": "NO_ARTIFACT", - "binding_id": "EB-BENCH", - "collection_source": "no evidence artifact", - "control_ids": [ - "GA-39" - ], - "count_control_ids": [], - "counts_toward_satisfaction": false, - "environment": "source tree vantio-open-core at b0bcbdeb01ccb84a58a3aa6aacd0c05f94b22450. Not a clean host and not a stranger host.", - "freshness": "UNSET", - "independent_verifier": "UNSET", - "informs_posture": false, - "limitations": [ - "No benchmark artifact is bound. A design target is not evidence." - ], - "producer": "none on this tree", - "product_version": "absent", - "prohibited_interpretations": [ - "Do not state a performance ranking." - ], - "proof_class": "NONE", - "source_commit": "b0bcbdeb01ccb84a58a3aa6aacd0c05f94b22450", - "timestamp": "UNKNOWN", - "title": "Best-in-class and benchmark claims", - "track_id": "BENCHMARK", - "verification_result": "NO_EVIDENCE_BACKED_CLAIM", - "wave2_state": "DESIGN_TARGET" - }, - { - "artifact_records": [ - { - "path": "packages/vantio-cli-pkg02/package.json", - "present": true, - "sha256": "6a2d4467faeb5abe0720fa4d9c78eb80ddc9da163e4591c97dc734e40107121d" - }, - { - "path": "docs/planning/optics-pkg02/04-COMPATIBILITY-MATRIX.md", - "present": true, - "sha256": "c567a39fed505b7ab09b8a9cf97a5d7f9fdd78cc347422ae630a41764480f395" - } - ], - "artifact_status": "PRESENT", - "binding_id": "EB-UNIT-D", - "collection_source": "private CLI line and compatibility note", - "control_ids": [ - "GA-19", - "GA-27" - ], - "count_control_ids": [], - "counts_toward_satisfaction": false, - "environment": "source tree vantio-open-core at b0bcbdeb01ccb84a58a3aa6aacd0c05f94b22450. Not a clean host and not a stranger host.", - "freshness": "CURRENT_FOR_CATALOG_REVIEW", - "independent_verifier": "UNSET", - "informs_posture": true, - "limitations": [ - "UNIT_D_PROVED_NOT_SHIPPED. activates_unit_e is false.", - "Frozen CLI 0.3.24 is a different package and was not reopened.", - "The future line does not count as a shipped control." - ], - "producer": "PKG-02 Unit D", - "product_version": "0.4.0-pkg02-unit-d", - "prohibited_interpretations": [ - "Do not describe 0.4.0-pkg02-unit-d as the shipping CLI." - ], - "proof_class": "PRODUCER_TEST", - "source_commit": "98ecaf6e9dd6fb831e7d2728379e2f785f41804f", - "timestamp": "UNKNOWN", - "title": "PKG-02 Unit D future CLI", - "track_id": "UNIT-D", - "verification_result": "UNIT_D_PROVED_NOT_SHIPPED", - "wave2_state": "MERGED_FUTURE_CLI_NOT_SHIPPED" - }, - { - "artifact_records": [ - { - "path": "docs/internal/optics-pkg02-unit-e/BOUNDARY.md", - "present": true, - "sha256": "90a78c39a5fcb51b4e3f3311eeb4fd4b0fe5b2166e4245194a2f823073c25e00" - }, - { - "path": "docs/internal/optics-pkg02-unit-e/MATRIX-MARKERS.json", - "present": true, - "sha256": "df4297edae3afdedb9f583b28e637ccf25f7c9d9da4dfa0c25ee28012509de70" - } - ], - "artifact_status": "PRESENT", - "binding_id": "EB-UNIT-E", - "collection_source": "merge a80fd4288df4983bf294aa219511ef60d86fa87c OPTICS_PKG02_UNIT_E_MERGED_NO_LIVE_INTEGRATION", - "control_ids": [ - "GA-19" - ], - "count_control_ids": [], - "counts_toward_satisfaction": false, - "environment": "source tree vantio-open-core at b0bcbdeb01ccb84a58a3aa6aacd0c05f94b22450. Not a clean host and not a stranger host.", - "freshness": "CURRENT_FOR_CATALOG_REVIEW", - "independent_verifier": "UNSET", - "informs_posture": true, - "limitations": [ - "The main merge subject records OPTICS_PKG02_UNIT_E_MERGED_NO_LIVE_INTEGRATION.", - "MATRIX-MARKERS.json still records merged false and marker_achievement READY_FOR_COUNCIL. activates_unit_e is true on that Unit E marker.", - "activates_unit_e stays false on the planning matrix and on Unit D. registry_publish is false. sealed is false.", - "Sealed Python 3.1.0 and CLI 0.3.24 were not mutated. This catalog did not re-execute Unit E tests.", - "The 0.2.0 rebind read this merge and still does not count it toward satisfaction." - ], - "producer": "PKG-02 Unit E", - "product_version": "PKG02-FUTURE-PYTHON-UNASSIGNED", - "prohibited_interpretations": [ - "Do not describe the future Python writer as sealed 3.1.0, as a live integration, or as a shipped control." - ], - "proof_class": "DESIGN_RECORD", - "source_commit": "a80fd4288df4983bf294aa219511ef60d86fa87c", - "timestamp": "UNKNOWN", - "title": "PKG-02 Unit E future Python writer", - "track_id": "UNIT-E", - "verification_result": "MERGED_NO_LIVE_INTEGRATION_NOT_A_SHIPPED_WRITER", - "wave2_state": "MERGED_NO_LIVE_INTEGRATION" - }, - { - "artifact_records": [ - { - "path": "packages/vantio-cli/package.json", - "present": true, - "sha256": "5f772f6ad1a071f34905a6b30eb29be32eea4175ab58bee1e235f9ee3c7ef6e0" - } - ], - "artifact_status": "PRESENT", - "binding_id": "EB-CLI-0324", - "collection_source": "packages/vantio-cli/package.json", - "control_ids": [ - "GA-01", - "GA-03", - "GA-12", - "GA-16", - "GA-19", - "GA-25" - ], - "count_control_ids": [ - "GA-01", - "GA-03", - "GA-12", - "GA-16", - "GA-19", - "GA-25" - ], - "counts_toward_satisfaction": true, - "environment": "source tree vantio-open-core at b0bcbdeb01ccb84a58a3aa6aacd0c05f94b22450. Not a clean host and not a stranger host.", - "freshness": "CURRENT_FOR_CATALOG_REVIEW", - "independent_verifier": "UNSET", - "informs_posture": true, - "limitations": [ - "This force does not reopen CLI 0.3.24.", - "Repository tests are producer tests. They are not a customer deployment.", - "The version file is not a live observation of a host.", - "The version file does not establish GA-24 credential non-collection." - ], - "producer": "published @vantio/cli", - "product_version": "0.3.24", - "prohibited_interpretations": [ - "Do not treat the package manifest as host enforcement or as external proof.", - "Do not treat the package manifest as proof that credentials are not collected." - ], - "proof_class": "PRODUCER_TEST", - "source_commit": "b0bcbdeb01ccb84a58a3aa6aacd0c05f94b22450", - "timestamp": "UNKNOWN", - "title": "Frozen Optics CLI", - "track_id": "CLI", - "verification_result": "FROZEN_CLI_0_3_24_UNCHANGED", - "wave2_state": "FROZEN_PUBLISHED" - }, - { - "artifact_records": [ - { - "path": "docs/products/optics/USER-MANUAL.md", - "present": true, - "sha256": "28533aefb660f08d33393a5e67455a473176f92d487f2ee3f153b18e0fecc385" - }, - { - "path": "docs/products/optics/PRIVACY-AND-SECURITY.md", - "present": true, - "sha256": "b7738dd3348a351e034e4896b3fc335c51fb928170622acb3dfd01e5b400673b" - } - ], - "artifact_status": "PRESENT", - "binding_id": "EB-OPTICS-PRIVACY", - "collection_source": "USER-MANUAL.md privacy section and PRIVACY-AND-SECURITY.md path segments", - "control_ids": [ - "GA-24" - ], - "count_control_ids": [], - "counts_toward_satisfaction": false, - "environment": "source tree vantio-open-core at b0bcbdeb01ccb84a58a3aa6aacd0c05f94b22450. Not a clean host and not a stranger host.", - "freshness": "CURRENT_FOR_CATALOG_REVIEW", - "independent_verifier": "UNSET", - "informs_posture": true, - "limitations": [ - "A secret placed in the URL path is stored, because the path is kept.", - "The manual says query strings are dropped and that prompts, completions, and request bodies are not kept on the free path.", - "This catalog did not re-execute a secret-in-path fixture.", - "Does not count toward satisfaction. A version file is not this evidence." - ], - "producer": "Optics public manual", - "product_version": "0.3.24", - "prohibited_interpretations": [ - "Do not treat the manual as a re-executed non-collection proof.", - "Do not treat path retention as credential non-collection." - ], - "proof_class": "DESIGN_RECORD", - "source_commit": "b0bcbdeb01ccb84a58a3aa6aacd0c05f94b22450", - "timestamp": "UNKNOWN", - "title": "Optics public privacy statement", - "track_id": "OPTICS-PRIVACY", - "verification_result": "URL_PATH_SECRET_RETAINED_NOT_REEXECUTED", - "wave2_state": "DOCUMENTED_EXCEPTION_NOT_REEXECUTED" - }, - { - "artifact_records": [ - { - "path": "packages/governance-assurance/src/constants.cjs", - "present": true, - "sha256": "719657293022ef2cd82a3f4babc809fd4390e5020de2763794efd051937258b5" - } - ], - "artifact_status": "PRESENT", - "binding_id": "EB-ROLE", - "collection_source": "ROLE_STATEMENT", - "control_ids": [ - "GA-04", - "GA-22", - "GA-35", - "GA-37", - "GA-39" - ], - "count_control_ids": [ - "GA-39" - ], - "counts_toward_satisfaction": true, - "environment": "source tree vantio-open-core at b0bcbdeb01ccb84a58a3aa6aacd0c05f94b22450. Not a clean host and not a stranger host.", - "freshness": "CURRENT_FOR_CATALOG_REVIEW", - "independent_verifier": "UNSET", - "informs_posture": true, - "limitations": [ - "The statement limits claims. It does not prove a customer system." - ], - "producer": "governance-assurance package", - "product_version": "0.2.0-internal", - "prohibited_interpretations": [ - "Do not quote the role statement as a certification." - ], - "proof_class": "PRODUCER_TEST", - "source_commit": "b0bcbdeb01ccb84a58a3aa6aacd0c05f94b22450", - "timestamp": "2026-09-28T17:26:43Z", - "title": "Role statement and claim ceiling", - "track_id": "WS17", - "verification_result": "DISCLOSURE_ONLY", - "wave2_state": "PRIVATE_MAPPING_LAYER" - }, - { - "artifact_records": [ - { - "path": "packages/governance-assurance/src/staleness.cjs", - "present": true, - "sha256": "45770ea3132c724a3fa3e0b9294570fba297b1f62071868fcea79a4346bdf3e6" - } - ], - "artifact_status": "PRESENT", - "binding_id": "EB-STALENESS", - "collection_source": "staleness.cjs", - "control_ids": [ - "GA-21" - ], - "count_control_ids": [ - "GA-21" - ], - "counts_toward_satisfaction": true, - "environment": "source tree vantio-open-core at b0bcbdeb01ccb84a58a3aa6aacd0c05f94b22450. Not a clean host and not a stranger host.", - "freshness": "CURRENT_FOR_CATALOG_REVIEW", - "independent_verifier": "UNSET", - "informs_posture": true, - "limitations": [ - "The function can mark a row stale. It does not measure a customer evidence window." - ], - "producer": "governance-assurance package", - "product_version": "0.2.0-internal", - "prohibited_interpretations": [ - "Do not treat a generated staleness section as the underlying evidence." - ], - "proof_class": "PRODUCER_TEST", - "source_commit": "b0bcbdeb01ccb84a58a3aa6aacd0c05f94b22450", - "timestamp": "2026-09-28T17:26:43Z", - "title": "Staleness function", - "track_id": "WS17", - "verification_result": "STALENESS_FUNCTION_PRESENT", - "wave2_state": "IMPLEMENTED_INTERNAL" - }, - { - "artifact_records": [ - { - "path": "packages/governance-assurance/src/reports.cjs", - "present": true, - "sha256": "656f3d9e8a577715e08e04ebc83e6cc511a68618bd986fae77b430ec5bde9d8c" - } - ], - "artifact_status": "PRESENT", - "binding_id": "EB-PROCUREMENT", - "collection_source": "reports.cjs", - "control_ids": [ - "GA-38" - ], - "count_control_ids": [ - "GA-38" - ], - "counts_toward_satisfaction": true, - "environment": "source tree vantio-open-core at b0bcbdeb01ccb84a58a3aa6aacd0c05f94b22450. Not a clean host and not a stranger host.", - "freshness": "CURRENT_FOR_CATALOG_REVIEW", - "independent_verifier": "UNSET", - "informs_posture": true, - "limitations": [ - "Distribution stays INTERNAL_RESTRICTED unless a later review says otherwise. Proof class does not rise with audience." - ], - "producer": "governance-assurance package", - "product_version": "0.2.0-internal", - "prohibited_interpretations": [ - "Do not submit this index externally from this force." - ], - "proof_class": "PRODUCER_TEST", - "source_commit": "b0bcbdeb01ccb84a58a3aa6aacd0c05f94b22450", - "timestamp": "2026-09-28T17:26:43Z", - "title": "Procurement index generator", - "track_id": "WS17", - "verification_result": "INDEX_GENERATED_NOT_SUBMITTED", - "wave2_state": "PRIVATE_NOT_SUBMITTED" - }, - { - "artifact_records": [ - { - "path": "docs/internal/governance-assurance/stage-b/C6-REBIND.json", - "present": true, - "sha256": "0ab713761007e6ef98ede125755c91bc2696b9515700100d0b933019ba1a7b99" - }, - { - "path": "packages/vantio-install/vantio_install/constants.py", - "present": true, - "sha256": "685591ce71bc0c1d87ae91a84e370375d2bf123f88f0174a93ce81519a2f3618" - }, - { - "path": "packages/vantio-cli/package.json", - "present": true, - "sha256": "5f772f6ad1a071f34905a6b30eb29be32eea4175ab58bee1e235f9ee3c7ef6e0" - }, - { - "path": "packages/vantio-agent-sdk/package.json", - "present": true, - "sha256": "9b049c29544e62cfe533f6c30ed51b2d9854f98e89d912647ab46016c11d8984" - }, - { - "path": "packages/vantio-agent-sdk-py/pyproject.toml", - "present": true, - "sha256": "7a031c6b36bff33529c434b489231dbd2d041e596424833255cd05cfd77e935f" - } - ], - "artifact_status": "PRESENT", - "binding_id": "EB-STAGE-B", - "collection_source": "C6-REBIND.json program_bindings, with installer ceiling and frozen pins hashed beside it", - "control_ids": [ - "GA-12", - "GA-13", - "GA-19", - "GA-27", - "GA-33", - "GA-39", - "GA-40" - ], - "count_control_ids": [], - "counts_toward_satisfaction": false, - "environment": "documentary citation of the 2026-09-28 closure program. Not a re-execution. Not a clean host and not a stranger host.", - "freshness": "CURRENT_FOR_CATALOG_REVIEW", - "independent_verifier": "UNSET", - "informs_posture": true, - "limitations": [ - "Documentary citation. reexecuted is false. This catalog did not rerun the lab.", - "Stage B is PARTIAL_INTERNAL_CLEAN_HOST_PROOF. proof_state is PARTIAL_NOT_FULL_EFFICACY. The claim ceiling is INTERNAL_CLEAN_HOST_PROOF.", - "Installer token is VANTIO_INSTALLER_REPEATABLE_PATH_PROVED_WITH_LIMITATIONS. It is not VANTIO_INSTALLER_INTERNAL_CUSTOMER_CANDIDATE.", - "Optics is INTERNAL_CLEAN_HOST_INSTALLATION_PROOF for frozen CLI 0.3.24. npm SDK stays 0.2.4. Python SDK stays 3.1.0.", - "O7 is INTERNAL_CLEAN_HOST_INITIALIZATION_PROOF with enforcement NOT_ENABLED. Phantom Engine is INTERNAL_CLEAN_HOST_OBSERVE_ONLY_PROOF.", - "Uninstall is LIVE_REMOVAL_AND_BPF_UNPIN_PROOF. That is not a residual-only path.", - "Destruction is STAGE_B_DESTROY_PASS for the lab resources. It is not product decommission and it does not close Council F.", - "Enforcement efficacy is NOT_PROVED. Repeatability is NOT_YET_PROVED. This citation does not qualify 0.3.0.", - "constants.py still emits PROOF_STATE NOT_PROVED and still forbids a claim that the governance rebind is a completed product proof." - ], - "producer": "closure program citation, not this catalog", - "product_version": "0.2.0-internal", - "prohibited_interpretations": [ - "Do not treat this citation as a re-executed clean-host pass.", - "Do not raise the proof class from this file." - ], - "proof_class": "CHARACTERIZATION", - "source_commit": "b0bcbdeb01ccb84a58a3aa6aacd0c05f94b22450", - "timestamp": "2026-09-28T17:26:43Z", - "title": "Stage B accepted close citation", - "track_id": "STAGE-B", - "verification_result": "PARTIAL_INTERNAL_CLEAN_HOST_PROOF", - "wave2_state": "STAGE_B_PARTIAL_CITED_NOT_REEXECUTED" - }, - { - "artifact_records": [ - { - "path": "docs/internal/governance-assurance/stage-b/C6-REBIND.json", - "present": true, - "sha256": "0ab713761007e6ef98ede125755c91bc2696b9515700100d0b933019ba1a7b99" - } - ], - "artifact_status": "PRESENT", - "binding_id": "EB-C5", - "collection_source": "C6-REBIND.json open_gates and tally", - "control_ids": [ - "GA-22", - "GA-34", - "GA-39", - "GA-40" - ], - "count_control_ids": [], - "counts_toward_satisfaction": false, - "environment": "documentary citation of the 2026-09-28 closure program. Not a re-execution. Not a clean host and not a stranger host.", - "freshness": "CURRENT_FOR_CATALOG_REVIEW", - "independent_verifier": "UNSET", - "informs_posture": true, - "limitations": [ - "C5 classification is INTEGRATION_PASS_WITH_NONBLOCKING_AND_OPEN_GATES. Clean-pass tally is zero.", - "Council F is NEEDS_REVISION. Billing close is STAGE_B_BILLING_CLOSE_PENDING.", - "Council I is NEEDS_REVISION. Recordings A-H are NOT_CAPTURED.", - "C8 is DESIGN_COMPLETE_AWAITING_FOUNDER_CREDENTIAL_OR_ROLE. noninteractive_teardown_ready is false.", - "Class B is BLOCKED. NEXT_LAB is NOT_YET_AUTHORIZED. PUBLIC_REWRITE is HOLD.", - "Council J was prep only. This packet does not convert that prep into a WS17 council acceptance." - ], - "producer": "closure program citation, not this catalog", - "product_version": "0.2.0-internal", - "prohibited_interpretations": [ - "Do not hide Council F or Council I.", - "Do not treat C5 as this package's independent council." - ], - "proof_class": "CHARACTERIZATION", - "source_commit": "b0bcbdeb01ccb84a58a3aa6aacd0c05f94b22450", - "timestamp": "2026-09-28T17:26:43Z", - "title": "C5 integration close with open gates", - "track_id": "C5", - "verification_result": "OPEN_GATES_VISIBLE", - "wave2_state": "C5_INTEGRATION_PASS_WITH_NONBLOCKING_AND_OPEN_GATES" - }, - { - "artifact_records": [ - { - "path": "docs/internal/governance-assurance/stage-b/C6-REBIND.json", - "present": true, - "sha256": "0ab713761007e6ef98ede125755c91bc2696b9515700100d0b933019ba1a7b99" - }, - { - "path": "docs/internal/pe-ingress/INGRESS-MANIFEST.json", - "present": true, - "sha256": "d19c7af47b84420e6b571daf48e33687cece57302082a94ac9e89dec2ee4c277" - }, - { - "path": "packages/pe-ingress-authority/src/constants.cjs", - "present": true, - "sha256": "9140b55b6513cb5bfa8bf90bc65e0fe0e78f7cc76d272ae165b43589a985f53a" - }, - { - "path": "docs/internal/pe-egress/EGRESS-MANIFEST.json", - "present": true, - "sha256": "d8102bb740b9df10a4376e7d90a71053f0ce48f866fd578eb44d7fdc8816ac8b" - }, - { - "path": "packages/pe-egress-authority/src/decision.cjs", - "present": true, - "sha256": "82d60106a082fa6d16019e2c52a3d83f49db15042998c600ea989995ed376e42" - }, - { - "path": "docs/internal/optics-pkg02-unit-e/MATRIX-MARKERS.json", - "present": true, - "sha256": "df4297edae3afdedb9f583b28e637ccf25f7c9d9da4dfa0c25ee28012509de70" - } - ], - "artifact_status": "PRESENT", - "binding_id": "EB-WAVE2-RESIDUAL", - "collection_source": "ingress, egress, and Unit E files reread at the 0.2.0 tip, with C6-REBIND.json", - "control_ids": [ - "GA-13", - "GA-14", - "GA-15", - "GA-27", - "GA-40" - ], - "count_control_ids": [], - "counts_toward_satisfaction": false, - "environment": "documentary citation of the 2026-09-28 closure program. Not a re-execution. Not a clean host and not a stranger host.", - "freshness": "CURRENT_FOR_CATALOG_REVIEW", - "independent_verifier": "UNSET", - "informs_posture": true, - "limitations": [ - "Ingress remains MERGED_OBSERVE_ONLY_LOADER_UNTOUCHED and does not count.", - "Egress remains MERGED_CONTRACT_ONLY_HOST_NETWORK_NOT_EXECUTED and does not count.", - "Unit E remains MERGED_NO_LIVE_INTEGRATION and does not count.", - "RBK-004 is SOURCE_CLOSED_MERGED at b0bcbdeb01ccb84a58a3aa6aacd0c05f94b22450. live_reproof_claimed is false. The live Class A residual-only re-proof is NOT_YET_AUTHORIZED.", - "C3 listed GAP-SB-RBK-004 as open before that merge. The later C1 and C5 records are the ones this rebind binds.", - "Enforcement efficacy is NOT_PROVED." - ], - "producer": "closure program citation plus the merged track files", - "product_version": "0.2.0-internal", - "prohibited_interpretations": [ - "Do not count the observe-only or contract-only merges because the catalog version changed.", - "Do not describe a source merge as a live residual-only re-proof." - ], - "proof_class": "CHARACTERIZATION", - "source_commit": "b0bcbdeb01ccb84a58a3aa6aacd0c05f94b22450", - "timestamp": "2026-09-28T17:26:43Z", - "title": "Wave 2 residual honesty after the 0.2.0 reading", - "track_id": "WAVE2-RESIDUAL", - "verification_result": "ENFORCEMENT_NOT_PROVED_RBK004_SOURCE_CLOSED_LIVE_REPROOF_NOT_CLAIMED", - "wave2_state": "WAVE2_RESIDUAL_HONESTY_UNSATISFIED" - } - ], - "document": "CONTROL_EVIDENCE_INDEX", - "provenance": { - "audience": "INTERNAL_RESTRICTED", - "catalog_version": "0.2.0-internal", - "council_status": "PENDING_INDEPENDENT_COUNCIL", - "distribution": "INTERNAL_RESTRICTED", - "generated_at": "2026-09-28T17:26:43Z", - "generator": "@vantio/governance-assurance", - "mapping_commit": "NOT_SELF_HASHED", - "mapping_version": "0.2.0-internal", - "package_name": "@vantio/governance-assurance", - "package_version": "0.2.0-internal", - "producer_classification": "WS17_GOVERNANCE_ASSURANCE_0_2_0_INTERNAL_REBIND_READY_FOR_COUNCIL", - "program_claim_ceiling": "INTERNAL_CLEAN_HOST_PROOF", - "retrieved_at": "2026-09-28T17:26:43Z", - "reviewer": "PENDING_INDEPENDENT_COUNCIL", - "self_certified_council_pass": false, - "source_base_commit": "b0bcbdeb01ccb84a58a3aa6aacd0c05f94b22450", - "source_repository": "vantioai/vantio-open-core", - "supersedes_package": "0.1.0-internal" - }, - "schema": "vantio.governance-assurance.evidence-index/v1" -} diff --git a/docs/internal/governance-assurance/reports/CUSTOMER_RESPONSIBILITY_MATRIX.json b/docs/internal/governance-assurance/reports/CUSTOMER_RESPONSIBILITY_MATRIX.json deleted file mode 100644 index d1e33d05..00000000 --- a/docs/internal/governance-assurance/reports/CUSTOMER_RESPONSIBILITY_MATRIX.json +++ /dev/null @@ -1,728 +0,0 @@ -{ - "audience": "INTERNAL_RESTRICTED", - "customer_org_structure": "NOT_ASSERTED", - "document": "CUSTOMER_RESPONSIBILITY_MATRIX", - "provenance": { - "audience": "INTERNAL_RESTRICTED", - "catalog_version": "0.2.0-internal", - "council_status": "PENDING_INDEPENDENT_COUNCIL", - "distribution": "INTERNAL_RESTRICTED", - "generated_at": "2026-09-28T17:26:43Z", - "generator": "@vantio/governance-assurance", - "mapping_commit": "NOT_SELF_HASHED", - "mapping_version": "0.2.0-internal", - "package_name": "@vantio/governance-assurance", - "package_version": "0.2.0-internal", - "producer_classification": "WS17_GOVERNANCE_ASSURANCE_0_2_0_INTERNAL_REBIND_READY_FOR_COUNCIL", - "program_claim_ceiling": "INTERNAL_CLEAN_HOST_PROOF", - "retrieved_at": "2026-09-28T17:26:43Z", - "reviewer": "PENDING_INDEPENDENT_COUNCIL", - "self_certified_council_pass": false, - "source_base_commit": "b0bcbdeb01ccb84a58a3aa6aacd0c05f94b22450", - "source_repository": "vantioai/vantio-open-core", - "supersedes_package": "0.1.0-internal" - }, - "raci_values": [ - "RESPONSIBLE", - "ACCOUNTABLE", - "CONSULTED", - "INFORMED", - "NOT_APPLICABLE" - ], - "roles": [ - "VANTIO", - "CUSTOMER_AI_OWNER", - "CUSTOMER_SECURITY", - "CUSTOMER_COMPLIANCE", - "CUSTOMER_LEGAL", - "CUSTOMER_PRIVACY", - "CUSTOMER_INFRASTRUCTURE_OPERATOR", - "MODEL_PROVIDER", - "THIRD_PARTY_INTEGRATOR", - "INDEPENDENT_ASSESSOR" - ], - "rows": [ - { - "control_id": "GA-01", - "domain": "OPERATIONAL", - "primary_support": "VANTIO_PARTIALLY_SUPPORTS", - "raci": { - "CUSTOMER_AI_OWNER": "ACCOUNTABLE", - "CUSTOMER_COMPLIANCE": "CONSULTED", - "CUSTOMER_INFRASTRUCTURE_OPERATOR": "CONSULTED", - "CUSTOMER_LEGAL": "INFORMED", - "CUSTOMER_PRIVACY": "INFORMED", - "CUSTOMER_SECURITY": "CONSULTED", - "INDEPENDENT_ASSESSOR": "CONSULTED", - "MODEL_PROVIDER": "INFORMED", - "THIRD_PARTY_INTEGRATOR": "INFORMED", - "VANTIO": "RESPONSIBLE" - } - }, - { - "control_id": "GA-02", - "domain": "EVIDENCE", - "primary_support": "VANTIO_PARTIALLY_SUPPORTS", - "raci": { - "CUSTOMER_AI_OWNER": "ACCOUNTABLE", - "CUSTOMER_COMPLIANCE": "CONSULTED", - "CUSTOMER_INFRASTRUCTURE_OPERATOR": "CONSULTED", - "CUSTOMER_LEGAL": "INFORMED", - "CUSTOMER_PRIVACY": "INFORMED", - "CUSTOMER_SECURITY": "CONSULTED", - "INDEPENDENT_ASSESSOR": "CONSULTED", - "MODEL_PROVIDER": "INFORMED", - "THIRD_PARTY_INTEGRATOR": "INFORMED", - "VANTIO": "RESPONSIBLE" - } - }, - { - "control_id": "GA-03", - "domain": "DISCLOSURE", - "primary_support": "VANTIO_PARTIALLY_SUPPORTS", - "raci": { - "CUSTOMER_AI_OWNER": "INFORMED", - "CUSTOMER_COMPLIANCE": "CONSULTED", - "CUSTOMER_INFRASTRUCTURE_OPERATOR": "CONSULTED", - "CUSTOMER_LEGAL": "INFORMED", - "CUSTOMER_PRIVACY": "INFORMED", - "CUSTOMER_SECURITY": "CONSULTED", - "INDEPENDENT_ASSESSOR": "CONSULTED", - "MODEL_PROVIDER": "INFORMED", - "THIRD_PARTY_INTEGRATOR": "INFORMED", - "VANTIO": "RESPONSIBLE" - } - }, - { - "control_id": "GA-04", - "domain": "LEGAL", - "primary_support": "CUSTOMER_PROVIDES", - "raci": { - "CUSTOMER_AI_OWNER": "RESPONSIBLE", - "CUSTOMER_COMPLIANCE": "CONSULTED", - "CUSTOMER_INFRASTRUCTURE_OPERATOR": "CONSULTED", - "CUSTOMER_LEGAL": "ACCOUNTABLE", - "CUSTOMER_PRIVACY": "INFORMED", - "CUSTOMER_SECURITY": "CONSULTED", - "INDEPENDENT_ASSESSOR": "CONSULTED", - "MODEL_PROVIDER": "CONSULTED", - "THIRD_PARTY_INTEGRATOR": "INFORMED", - "VANTIO": "NOT_APPLICABLE" - } - }, - { - "control_id": "GA-05", - "domain": "OPERATIONAL", - "primary_support": "CUSTOMER_CONFIGURES", - "raci": { - "CUSTOMER_AI_OWNER": "ACCOUNTABLE", - "CUSTOMER_COMPLIANCE": "CONSULTED", - "CUSTOMER_INFRASTRUCTURE_OPERATOR": "RESPONSIBLE", - "CUSTOMER_LEGAL": "INFORMED", - "CUSTOMER_PRIVACY": "INFORMED", - "CUSTOMER_SECURITY": "CONSULTED", - "INDEPENDENT_ASSESSOR": "CONSULTED", - "MODEL_PROVIDER": "INFORMED", - "THIRD_PARTY_INTEGRATOR": "INFORMED", - "VANTIO": "CONSULTED" - } - }, - { - "control_id": "GA-06", - "domain": "OPERATIONAL", - "primary_support": "CUSTOMER_CONFIGURES", - "raci": { - "CUSTOMER_AI_OWNER": "ACCOUNTABLE", - "CUSTOMER_COMPLIANCE": "CONSULTED", - "CUSTOMER_INFRASTRUCTURE_OPERATOR": "RESPONSIBLE", - "CUSTOMER_LEGAL": "INFORMED", - "CUSTOMER_PRIVACY": "INFORMED", - "CUSTOMER_SECURITY": "CONSULTED", - "INDEPENDENT_ASSESSOR": "CONSULTED", - "MODEL_PROVIDER": "INFORMED", - "THIRD_PARTY_INTEGRATOR": "INFORMED", - "VANTIO": "CONSULTED" - } - }, - { - "control_id": "GA-07", - "domain": "OPERATIONAL", - "primary_support": "CUSTOMER_CONFIGURES", - "raci": { - "CUSTOMER_AI_OWNER": "ACCOUNTABLE", - "CUSTOMER_COMPLIANCE": "CONSULTED", - "CUSTOMER_INFRASTRUCTURE_OPERATOR": "RESPONSIBLE", - "CUSTOMER_LEGAL": "INFORMED", - "CUSTOMER_PRIVACY": "INFORMED", - "CUSTOMER_SECURITY": "CONSULTED", - "INDEPENDENT_ASSESSOR": "CONSULTED", - "MODEL_PROVIDER": "INFORMED", - "THIRD_PARTY_INTEGRATOR": "INFORMED", - "VANTIO": "CONSULTED" - } - }, - { - "control_id": "GA-08", - "domain": "OPERATIONAL", - "primary_support": "NOT_IMPLEMENTED", - "raci": { - "CUSTOMER_AI_OWNER": "ACCOUNTABLE", - "CUSTOMER_COMPLIANCE": "CONSULTED", - "CUSTOMER_INFRASTRUCTURE_OPERATOR": "CONSULTED", - "CUSTOMER_LEGAL": "INFORMED", - "CUSTOMER_PRIVACY": "INFORMED", - "CUSTOMER_SECURITY": "RESPONSIBLE", - "INDEPENDENT_ASSESSOR": "CONSULTED", - "MODEL_PROVIDER": "INFORMED", - "THIRD_PARTY_INTEGRATOR": "INFORMED", - "VANTIO": "INFORMED" - } - }, - { - "control_id": "GA-09", - "domain": "OPERATIONAL", - "primary_support": "NOT_IMPLEMENTED", - "raci": { - "CUSTOMER_AI_OWNER": "ACCOUNTABLE", - "CUSTOMER_COMPLIANCE": "CONSULTED", - "CUSTOMER_INFRASTRUCTURE_OPERATOR": "CONSULTED", - "CUSTOMER_LEGAL": "INFORMED", - "CUSTOMER_PRIVACY": "INFORMED", - "CUSTOMER_SECURITY": "RESPONSIBLE", - "INDEPENDENT_ASSESSOR": "CONSULTED", - "MODEL_PROVIDER": "INFORMED", - "THIRD_PARTY_INTEGRATOR": "INFORMED", - "VANTIO": "INFORMED" - } - }, - { - "control_id": "GA-10", - "domain": "OPERATIONAL", - "primary_support": "UNVERIFIED", - "raci": { - "CUSTOMER_AI_OWNER": "ACCOUNTABLE", - "CUSTOMER_COMPLIANCE": "CONSULTED", - "CUSTOMER_INFRASTRUCTURE_OPERATOR": "CONSULTED", - "CUSTOMER_LEGAL": "INFORMED", - "CUSTOMER_PRIVACY": "INFORMED", - "CUSTOMER_SECURITY": "RESPONSIBLE", - "INDEPENDENT_ASSESSOR": "CONSULTED", - "MODEL_PROVIDER": "INFORMED", - "THIRD_PARTY_INTEGRATOR": "INFORMED", - "VANTIO": "INFORMED" - } - }, - { - "control_id": "GA-11", - "domain": "OPERATIONAL", - "primary_support": "UNVERIFIED", - "raci": { - "CUSTOMER_AI_OWNER": "ACCOUNTABLE", - "CUSTOMER_COMPLIANCE": "CONSULTED", - "CUSTOMER_INFRASTRUCTURE_OPERATOR": "CONSULTED", - "CUSTOMER_LEGAL": "INFORMED", - "CUSTOMER_PRIVACY": "INFORMED", - "CUSTOMER_SECURITY": "RESPONSIBLE", - "INDEPENDENT_ASSESSOR": "CONSULTED", - "MODEL_PROVIDER": "INFORMED", - "THIRD_PARTY_INTEGRATOR": "INFORMED", - "VANTIO": "INFORMED" - } - }, - { - "control_id": "GA-12", - "domain": "OPERATIONAL", - "primary_support": "VANTIO_PARTIALLY_SUPPORTS", - "raci": { - "CUSTOMER_AI_OWNER": "ACCOUNTABLE", - "CUSTOMER_COMPLIANCE": "CONSULTED", - "CUSTOMER_INFRASTRUCTURE_OPERATOR": "CONSULTED", - "CUSTOMER_LEGAL": "INFORMED", - "CUSTOMER_PRIVACY": "INFORMED", - "CUSTOMER_SECURITY": "CONSULTED", - "INDEPENDENT_ASSESSOR": "CONSULTED", - "MODEL_PROVIDER": "INFORMED", - "THIRD_PARTY_INTEGRATOR": "INFORMED", - "VANTIO": "RESPONSIBLE" - } - }, - { - "control_id": "GA-13", - "domain": "OPERATIONAL", - "primary_support": "UNVERIFIED", - "raci": { - "CUSTOMER_AI_OWNER": "ACCOUNTABLE", - "CUSTOMER_COMPLIANCE": "CONSULTED", - "CUSTOMER_INFRASTRUCTURE_OPERATOR": "CONSULTED", - "CUSTOMER_LEGAL": "INFORMED", - "CUSTOMER_PRIVACY": "INFORMED", - "CUSTOMER_SECURITY": "RESPONSIBLE", - "INDEPENDENT_ASSESSOR": "CONSULTED", - "MODEL_PROVIDER": "INFORMED", - "THIRD_PARTY_INTEGRATOR": "INFORMED", - "VANTIO": "INFORMED" - } - }, - { - "control_id": "GA-14", - "domain": "OPERATIONAL", - "primary_support": "UNVERIFIED", - "raci": { - "CUSTOMER_AI_OWNER": "ACCOUNTABLE", - "CUSTOMER_COMPLIANCE": "CONSULTED", - "CUSTOMER_INFRASTRUCTURE_OPERATOR": "CONSULTED", - "CUSTOMER_LEGAL": "INFORMED", - "CUSTOMER_PRIVACY": "INFORMED", - "CUSTOMER_SECURITY": "RESPONSIBLE", - "INDEPENDENT_ASSESSOR": "CONSULTED", - "MODEL_PROVIDER": "INFORMED", - "THIRD_PARTY_INTEGRATOR": "INFORMED", - "VANTIO": "INFORMED" - } - }, - { - "control_id": "GA-15", - "domain": "OPERATIONAL", - "primary_support": "UNVERIFIED", - "raci": { - "CUSTOMER_AI_OWNER": "ACCOUNTABLE", - "CUSTOMER_COMPLIANCE": "CONSULTED", - "CUSTOMER_INFRASTRUCTURE_OPERATOR": "CONSULTED", - "CUSTOMER_LEGAL": "INFORMED", - "CUSTOMER_PRIVACY": "INFORMED", - "CUSTOMER_SECURITY": "RESPONSIBLE", - "INDEPENDENT_ASSESSOR": "CONSULTED", - "MODEL_PROVIDER": "INFORMED", - "THIRD_PARTY_INTEGRATOR": "INFORMED", - "VANTIO": "INFORMED" - } - }, - { - "control_id": "GA-16", - "domain": "OPERATIONAL", - "primary_support": "VANTIO_PARTIALLY_SUPPORTS", - "raci": { - "CUSTOMER_AI_OWNER": "ACCOUNTABLE", - "CUSTOMER_COMPLIANCE": "CONSULTED", - "CUSTOMER_INFRASTRUCTURE_OPERATOR": "CONSULTED", - "CUSTOMER_LEGAL": "INFORMED", - "CUSTOMER_PRIVACY": "INFORMED", - "CUSTOMER_SECURITY": "CONSULTED", - "INDEPENDENT_ASSESSOR": "CONSULTED", - "MODEL_PROVIDER": "INFORMED", - "THIRD_PARTY_INTEGRATOR": "INFORMED", - "VANTIO": "RESPONSIBLE" - } - }, - { - "control_id": "GA-17", - "domain": "OPERATIONAL", - "primary_support": "VANTIO_PARTIALLY_SUPPORTS", - "raci": { - "CUSTOMER_AI_OWNER": "ACCOUNTABLE", - "CUSTOMER_COMPLIANCE": "CONSULTED", - "CUSTOMER_INFRASTRUCTURE_OPERATOR": "CONSULTED", - "CUSTOMER_LEGAL": "INFORMED", - "CUSTOMER_PRIVACY": "INFORMED", - "CUSTOMER_SECURITY": "CONSULTED", - "INDEPENDENT_ASSESSOR": "CONSULTED", - "MODEL_PROVIDER": "INFORMED", - "THIRD_PARTY_INTEGRATOR": "INFORMED", - "VANTIO": "RESPONSIBLE" - } - }, - { - "control_id": "GA-18", - "domain": "OPERATIONAL", - "primary_support": "NOT_IMPLEMENTED", - "raci": { - "CUSTOMER_AI_OWNER": "ACCOUNTABLE", - "CUSTOMER_COMPLIANCE": "CONSULTED", - "CUSTOMER_INFRASTRUCTURE_OPERATOR": "CONSULTED", - "CUSTOMER_LEGAL": "INFORMED", - "CUSTOMER_PRIVACY": "INFORMED", - "CUSTOMER_SECURITY": "RESPONSIBLE", - "INDEPENDENT_ASSESSOR": "CONSULTED", - "MODEL_PROVIDER": "INFORMED", - "THIRD_PARTY_INTEGRATOR": "INFORMED", - "VANTIO": "INFORMED" - } - }, - { - "control_id": "GA-19", - "domain": "EVIDENCE", - "primary_support": "VANTIO_PARTIALLY_SUPPORTS", - "raci": { - "CUSTOMER_AI_OWNER": "ACCOUNTABLE", - "CUSTOMER_COMPLIANCE": "CONSULTED", - "CUSTOMER_INFRASTRUCTURE_OPERATOR": "CONSULTED", - "CUSTOMER_LEGAL": "INFORMED", - "CUSTOMER_PRIVACY": "INFORMED", - "CUSTOMER_SECURITY": "CONSULTED", - "INDEPENDENT_ASSESSOR": "CONSULTED", - "MODEL_PROVIDER": "INFORMED", - "THIRD_PARTY_INTEGRATOR": "INFORMED", - "VANTIO": "RESPONSIBLE" - } - }, - { - "control_id": "GA-20", - "domain": "EVIDENCE", - "primary_support": "VANTIO_PARTIALLY_SUPPORTS", - "raci": { - "CUSTOMER_AI_OWNER": "ACCOUNTABLE", - "CUSTOMER_COMPLIANCE": "CONSULTED", - "CUSTOMER_INFRASTRUCTURE_OPERATOR": "CONSULTED", - "CUSTOMER_LEGAL": "INFORMED", - "CUSTOMER_PRIVACY": "INFORMED", - "CUSTOMER_SECURITY": "CONSULTED", - "INDEPENDENT_ASSESSOR": "CONSULTED", - "MODEL_PROVIDER": "INFORMED", - "THIRD_PARTY_INTEGRATOR": "INFORMED", - "VANTIO": "RESPONSIBLE" - } - }, - { - "control_id": "GA-21", - "domain": "EVIDENCE", - "primary_support": "VANTIO_PARTIALLY_SUPPORTS", - "raci": { - "CUSTOMER_AI_OWNER": "ACCOUNTABLE", - "CUSTOMER_COMPLIANCE": "CONSULTED", - "CUSTOMER_INFRASTRUCTURE_OPERATOR": "CONSULTED", - "CUSTOMER_LEGAL": "INFORMED", - "CUSTOMER_PRIVACY": "INFORMED", - "CUSTOMER_SECURITY": "CONSULTED", - "INDEPENDENT_ASSESSOR": "CONSULTED", - "MODEL_PROVIDER": "INFORMED", - "THIRD_PARTY_INTEGRATOR": "INFORMED", - "VANTIO": "RESPONSIBLE" - } - }, - { - "control_id": "GA-22", - "domain": "EVIDENCE", - "primary_support": "NOT_IMPLEMENTED", - "raci": { - "CUSTOMER_AI_OWNER": "ACCOUNTABLE", - "CUSTOMER_COMPLIANCE": "CONSULTED", - "CUSTOMER_INFRASTRUCTURE_OPERATOR": "CONSULTED", - "CUSTOMER_LEGAL": "INFORMED", - "CUSTOMER_PRIVACY": "INFORMED", - "CUSTOMER_SECURITY": "RESPONSIBLE", - "INDEPENDENT_ASSESSOR": "CONSULTED", - "MODEL_PROVIDER": "INFORMED", - "THIRD_PARTY_INTEGRATOR": "INFORMED", - "VANTIO": "INFORMED" - } - }, - { - "control_id": "GA-23", - "domain": "OPERATIONAL", - "primary_support": "CUSTOMER_PROVIDES", - "raci": { - "CUSTOMER_AI_OWNER": "ACCOUNTABLE", - "CUSTOMER_COMPLIANCE": "CONSULTED", - "CUSTOMER_INFRASTRUCTURE_OPERATOR": "RESPONSIBLE", - "CUSTOMER_LEGAL": "INFORMED", - "CUSTOMER_PRIVACY": "INFORMED", - "CUSTOMER_SECURITY": "CONSULTED", - "INDEPENDENT_ASSESSOR": "CONSULTED", - "MODEL_PROVIDER": "INFORMED", - "THIRD_PARTY_INTEGRATOR": "INFORMED", - "VANTIO": "CONSULTED" - } - }, - { - "control_id": "GA-24", - "domain": "PRIVACY", - "primary_support": "VANTIO_PARTIALLY_SUPPORTS", - "raci": { - "CUSTOMER_AI_OWNER": "CONSULTED", - "CUSTOMER_COMPLIANCE": "CONSULTED", - "CUSTOMER_INFRASTRUCTURE_OPERATOR": "CONSULTED", - "CUSTOMER_LEGAL": "INFORMED", - "CUSTOMER_PRIVACY": "ACCOUNTABLE", - "CUSTOMER_SECURITY": "CONSULTED", - "INDEPENDENT_ASSESSOR": "CONSULTED", - "MODEL_PROVIDER": "INFORMED", - "THIRD_PARTY_INTEGRATOR": "INFORMED", - "VANTIO": "RESPONSIBLE" - } - }, - { - "control_id": "GA-25", - "domain": "PRIVACY", - "primary_support": "VANTIO_PARTIALLY_SUPPORTS", - "raci": { - "CUSTOMER_AI_OWNER": "CONSULTED", - "CUSTOMER_COMPLIANCE": "CONSULTED", - "CUSTOMER_INFRASTRUCTURE_OPERATOR": "CONSULTED", - "CUSTOMER_LEGAL": "INFORMED", - "CUSTOMER_PRIVACY": "ACCOUNTABLE", - "CUSTOMER_SECURITY": "CONSULTED", - "INDEPENDENT_ASSESSOR": "CONSULTED", - "MODEL_PROVIDER": "INFORMED", - "THIRD_PARTY_INTEGRATOR": "INFORMED", - "VANTIO": "RESPONSIBLE" - } - }, - { - "control_id": "GA-26", - "domain": "EVIDENCE", - "primary_support": "VANTIO_PARTIALLY_SUPPORTS", - "raci": { - "CUSTOMER_AI_OWNER": "ACCOUNTABLE", - "CUSTOMER_COMPLIANCE": "CONSULTED", - "CUSTOMER_INFRASTRUCTURE_OPERATOR": "CONSULTED", - "CUSTOMER_LEGAL": "INFORMED", - "CUSTOMER_PRIVACY": "INFORMED", - "CUSTOMER_SECURITY": "CONSULTED", - "INDEPENDENT_ASSESSOR": "CONSULTED", - "MODEL_PROVIDER": "INFORMED", - "THIRD_PARTY_INTEGRATOR": "INFORMED", - "VANTIO": "RESPONSIBLE" - } - }, - { - "control_id": "GA-27", - "domain": "OPERATIONAL", - "primary_support": "UNVERIFIED", - "raci": { - "CUSTOMER_AI_OWNER": "ACCOUNTABLE", - "CUSTOMER_COMPLIANCE": "CONSULTED", - "CUSTOMER_INFRASTRUCTURE_OPERATOR": "CONSULTED", - "CUSTOMER_LEGAL": "INFORMED", - "CUSTOMER_PRIVACY": "INFORMED", - "CUSTOMER_SECURITY": "RESPONSIBLE", - "INDEPENDENT_ASSESSOR": "CONSULTED", - "MODEL_PROVIDER": "INFORMED", - "THIRD_PARTY_INTEGRATOR": "INFORMED", - "VANTIO": "INFORMED" - } - }, - { - "control_id": "GA-28", - "domain": "OPERATIONAL", - "primary_support": "VANTIO_PARTIALLY_SUPPORTS", - "raci": { - "CUSTOMER_AI_OWNER": "ACCOUNTABLE", - "CUSTOMER_COMPLIANCE": "CONSULTED", - "CUSTOMER_INFRASTRUCTURE_OPERATOR": "CONSULTED", - "CUSTOMER_LEGAL": "INFORMED", - "CUSTOMER_PRIVACY": "INFORMED", - "CUSTOMER_SECURITY": "CONSULTED", - "INDEPENDENT_ASSESSOR": "CONSULTED", - "MODEL_PROVIDER": "INFORMED", - "THIRD_PARTY_INTEGRATOR": "INFORMED", - "VANTIO": "RESPONSIBLE" - } - }, - { - "control_id": "GA-29", - "domain": "OPERATIONAL", - "primary_support": "CUSTOMER_CONFIGURES", - "raci": { - "CUSTOMER_AI_OWNER": "ACCOUNTABLE", - "CUSTOMER_COMPLIANCE": "CONSULTED", - "CUSTOMER_INFRASTRUCTURE_OPERATOR": "RESPONSIBLE", - "CUSTOMER_LEGAL": "INFORMED", - "CUSTOMER_PRIVACY": "INFORMED", - "CUSTOMER_SECURITY": "CONSULTED", - "INDEPENDENT_ASSESSOR": "CONSULTED", - "MODEL_PROVIDER": "INFORMED", - "THIRD_PARTY_INTEGRATOR": "INFORMED", - "VANTIO": "CONSULTED" - } - }, - { - "control_id": "GA-30", - "domain": "OPERATIONAL", - "primary_support": "VANTIO_PARTIALLY_SUPPORTS", - "raci": { - "CUSTOMER_AI_OWNER": "ACCOUNTABLE", - "CUSTOMER_COMPLIANCE": "CONSULTED", - "CUSTOMER_INFRASTRUCTURE_OPERATOR": "CONSULTED", - "CUSTOMER_LEGAL": "INFORMED", - "CUSTOMER_PRIVACY": "INFORMED", - "CUSTOMER_SECURITY": "CONSULTED", - "INDEPENDENT_ASSESSOR": "CONSULTED", - "MODEL_PROVIDER": "INFORMED", - "THIRD_PARTY_INTEGRATOR": "INFORMED", - "VANTIO": "RESPONSIBLE" - } - }, - { - "control_id": "GA-31", - "domain": "OPERATIONAL", - "primary_support": "VANTIO_PARTIALLY_SUPPORTS", - "raci": { - "CUSTOMER_AI_OWNER": "ACCOUNTABLE", - "CUSTOMER_COMPLIANCE": "CONSULTED", - "CUSTOMER_INFRASTRUCTURE_OPERATOR": "CONSULTED", - "CUSTOMER_LEGAL": "INFORMED", - "CUSTOMER_PRIVACY": "INFORMED", - "CUSTOMER_SECURITY": "CONSULTED", - "INDEPENDENT_ASSESSOR": "CONSULTED", - "MODEL_PROVIDER": "INFORMED", - "THIRD_PARTY_INTEGRATOR": "INFORMED", - "VANTIO": "RESPONSIBLE" - } - }, - { - "control_id": "GA-32", - "domain": "EVIDENCE", - "primary_support": "UNVERIFIED", - "raci": { - "CUSTOMER_AI_OWNER": "ACCOUNTABLE", - "CUSTOMER_COMPLIANCE": "CONSULTED", - "CUSTOMER_INFRASTRUCTURE_OPERATOR": "CONSULTED", - "CUSTOMER_LEGAL": "INFORMED", - "CUSTOMER_PRIVACY": "INFORMED", - "CUSTOMER_SECURITY": "RESPONSIBLE", - "INDEPENDENT_ASSESSOR": "CONSULTED", - "MODEL_PROVIDER": "INFORMED", - "THIRD_PARTY_INTEGRATOR": "INFORMED", - "VANTIO": "INFORMED" - } - }, - { - "control_id": "GA-33", - "domain": "EVIDENCE", - "primary_support": "UNVERIFIED", - "raci": { - "CUSTOMER_AI_OWNER": "ACCOUNTABLE", - "CUSTOMER_COMPLIANCE": "CONSULTED", - "CUSTOMER_INFRASTRUCTURE_OPERATOR": "CONSULTED", - "CUSTOMER_LEGAL": "INFORMED", - "CUSTOMER_PRIVACY": "INFORMED", - "CUSTOMER_SECURITY": "RESPONSIBLE", - "INDEPENDENT_ASSESSOR": "CONSULTED", - "MODEL_PROVIDER": "INFORMED", - "THIRD_PARTY_INTEGRATOR": "INFORMED", - "VANTIO": "INFORMED" - } - }, - { - "control_id": "GA-34", - "domain": "EVIDENCE", - "primary_support": "UNVERIFIED", - "raci": { - "CUSTOMER_AI_OWNER": "ACCOUNTABLE", - "CUSTOMER_COMPLIANCE": "CONSULTED", - "CUSTOMER_INFRASTRUCTURE_OPERATOR": "CONSULTED", - "CUSTOMER_LEGAL": "INFORMED", - "CUSTOMER_PRIVACY": "INFORMED", - "CUSTOMER_SECURITY": "RESPONSIBLE", - "INDEPENDENT_ASSESSOR": "CONSULTED", - "MODEL_PROVIDER": "INFORMED", - "THIRD_PARTY_INTEGRATOR": "INFORMED", - "VANTIO": "INFORMED" - } - }, - { - "control_id": "GA-35", - "domain": "LEGAL", - "primary_support": "THIRD_PARTY_REQUIRED", - "raci": { - "CUSTOMER_AI_OWNER": "RESPONSIBLE", - "CUSTOMER_COMPLIANCE": "CONSULTED", - "CUSTOMER_INFRASTRUCTURE_OPERATOR": "CONSULTED", - "CUSTOMER_LEGAL": "ACCOUNTABLE", - "CUSTOMER_PRIVACY": "INFORMED", - "CUSTOMER_SECURITY": "CONSULTED", - "INDEPENDENT_ASSESSOR": "CONSULTED", - "MODEL_PROVIDER": "RESPONSIBLE", - "THIRD_PARTY_INTEGRATOR": "INFORMED", - "VANTIO": "NOT_APPLICABLE" - } - }, - { - "control_id": "GA-36", - "domain": "OPERATIONAL", - "primary_support": "CUSTOMER_PROVIDES", - "raci": { - "CUSTOMER_AI_OWNER": "ACCOUNTABLE", - "CUSTOMER_COMPLIANCE": "CONSULTED", - "CUSTOMER_INFRASTRUCTURE_OPERATOR": "RESPONSIBLE", - "CUSTOMER_LEGAL": "INFORMED", - "CUSTOMER_PRIVACY": "INFORMED", - "CUSTOMER_SECURITY": "CONSULTED", - "INDEPENDENT_ASSESSOR": "CONSULTED", - "MODEL_PROVIDER": "INFORMED", - "THIRD_PARTY_INTEGRATOR": "INFORMED", - "VANTIO": "CONSULTED" - } - }, - { - "control_id": "GA-37", - "domain": "LEGAL", - "primary_support": "CUSTOMER_PROVIDES", - "raci": { - "CUSTOMER_AI_OWNER": "RESPONSIBLE", - "CUSTOMER_COMPLIANCE": "CONSULTED", - "CUSTOMER_INFRASTRUCTURE_OPERATOR": "CONSULTED", - "CUSTOMER_LEGAL": "ACCOUNTABLE", - "CUSTOMER_PRIVACY": "INFORMED", - "CUSTOMER_SECURITY": "CONSULTED", - "INDEPENDENT_ASSESSOR": "CONSULTED", - "MODEL_PROVIDER": "CONSULTED", - "THIRD_PARTY_INTEGRATOR": "INFORMED", - "VANTIO": "NOT_APPLICABLE" - } - }, - { - "control_id": "GA-38", - "domain": "PROCUREMENT", - "primary_support": "VANTIO_PARTIALLY_SUPPORTS", - "raci": { - "CUSTOMER_AI_OWNER": "ACCOUNTABLE", - "CUSTOMER_COMPLIANCE": "ACCOUNTABLE", - "CUSTOMER_INFRASTRUCTURE_OPERATOR": "CONSULTED", - "CUSTOMER_LEGAL": "CONSULTED", - "CUSTOMER_PRIVACY": "INFORMED", - "CUSTOMER_SECURITY": "CONSULTED", - "INDEPENDENT_ASSESSOR": "CONSULTED", - "MODEL_PROVIDER": "INFORMED", - "THIRD_PARTY_INTEGRATOR": "INFORMED", - "VANTIO": "RESPONSIBLE" - } - }, - { - "control_id": "GA-39", - "domain": "DISCLOSURE", - "primary_support": "VANTIO_PROVIDES", - "raci": { - "CUSTOMER_AI_OWNER": "INFORMED", - "CUSTOMER_COMPLIANCE": "CONSULTED", - "CUSTOMER_INFRASTRUCTURE_OPERATOR": "CONSULTED", - "CUSTOMER_LEGAL": "INFORMED", - "CUSTOMER_PRIVACY": "INFORMED", - "CUSTOMER_SECURITY": "CONSULTED", - "INDEPENDENT_ASSESSOR": "CONSULTED", - "MODEL_PROVIDER": "INFORMED", - "THIRD_PARTY_INTEGRATOR": "INFORMED", - "VANTIO": "RESPONSIBLE" - } - }, - { - "control_id": "GA-40", - "domain": "OPERATIONAL", - "primary_support": "UNVERIFIED", - "raci": { - "CUSTOMER_AI_OWNER": "ACCOUNTABLE", - "CUSTOMER_COMPLIANCE": "CONSULTED", - "CUSTOMER_INFRASTRUCTURE_OPERATOR": "CONSULTED", - "CUSTOMER_LEGAL": "INFORMED", - "CUSTOMER_PRIVACY": "INFORMED", - "CUSTOMER_SECURITY": "RESPONSIBLE", - "INDEPENDENT_ASSESSOR": "CONSULTED", - "MODEL_PROVIDER": "INFORMED", - "THIRD_PARTY_INTEGRATOR": "INFORMED", - "VANTIO": "INFORMED" - } - } - ], - "schema": "vantio.governance-assurance.responsibility/v1", - "template": true -} diff --git a/docs/internal/governance-assurance/reports/FRAMEWORK_VERSION_REGISTER.json b/docs/internal/governance-assurance/reports/FRAMEWORK_VERSION_REGISTER.json deleted file mode 100644 index 0096c41b..00000000 --- a/docs/internal/governance-assurance/reports/FRAMEWORK_VERSION_REGISTER.json +++ /dev/null @@ -1,598 +0,0 @@ -{ - "document": "FRAMEWORK_VERSION_REGISTER", - "frameworks": [ - { - "documents": [ - { - "active": true, - "authority": "NIST", - "body_copied": false, - "document_id": "NIST-AI-100-1", - "effective_date": "UNKNOWN", - "jurisdiction": "US", - "next_review_trigger": "Reviewed at package 0.2.0-internal on 2026-09-28. Next rebind at 0.3.0 only after a clean-host qualification that PARTIAL_INTERNAL_CLEAN_HOST_PROOF does not supply, or sooner when the cited authority republishes.", - "notes": "NIST states the framework was released on January 26, 2023 and is intended for voluntary use. No legal effective date is recorded here. Function identifiers are used. Subcategory narrative is not copied. The same NIST page states that AI RMF 1.0 is being revised.", - "publication_date": "2023-01-26", - "retrieved_at": "2026-09-28T17:26:43Z", - "source_access": "PUBLIC_IDENTIFIER", - "source_url": "https://www.nist.gov/itl/ai-risk-management-framework", - "superseded_by": null, - "superseded_status": "CURRENT", - "title": "Artificial Intelligence Risk Management Framework (AI RMF 1.0)", - "version": "1.0" - } - ], - "framework_id": "NIST-AI-RMF", - "title": "NIST AI Risk Management Framework", - "unmapped_control_ids": [ - { - "control_ids": [], - "version": "1.0" - } - ] - }, - { - "documents": [ - { - "active": true, - "authority": "NIST", - "body_copied": false, - "document_id": "NIST-AI-RMF-PLAYBOOK-FIRST", - "effective_date": "UNKNOWN", - "jurisdiction": "US", - "next_review_trigger": "Reviewed at package 0.2.0-internal on 2026-09-28. Next rebind at 0.3.0 only after a clean-host qualification that PARTIAL_INTERNAL_CLEAN_HOST_PROOF does not supply, or sooner when the cited authority republishes.", - "notes": "The NIST playbook page states that the first complete version was announced on March 30, 2023, that it is based on AI RMF 1.0, and that it is for voluntary use. Suggested actions are not copied. The page says the playbook will be updated after AI RMF 1.0 is revised.", - "publication_date": "2023-03-30", - "retrieved_at": "2026-09-28T17:26:43Z", - "source_access": "PUBLIC_IDENTIFIER", - "source_url": "https://www.nist.gov/itl/ai-risk-management-framework/nist-ai-rmf-playbook", - "superseded_by": null, - "superseded_status": "CURRENT", - "title": "NIST AI RMF Playbook", - "version": "first-complete-version" - } - ], - "framework_id": "NIST-AI-RMF-PLAYBOOK", - "title": "NIST AI RMF Playbook", - "unmapped_control_ids": [ - { - "control_ids": [], - "version": "first-complete-version" - } - ] - }, - { - "documents": [ - { - "active": true, - "authority": "NIST", - "body_copied": false, - "document_id": "NIST-AGENT-INITIATIVE-PAGE", - "effective_date": "UNKNOWN", - "jurisdiction": "US", - "next_review_trigger": "Reviewed at package 0.2.0-internal on 2026-09-28. Next rebind at 0.3.0 only after a clean-host qualification that PARTIAL_INTERNAL_CLEAN_HOST_PROOF does not supply, or sooner when the cited authority republishes.", - "notes": "The NIST initiative page describes voluntary guidelines, protocols, and research. It does not, on the page retrieved for this register, state a single publication date or an effective date. No output text is copied.", - "publication_date": "UNKNOWN", - "retrieved_at": "2026-09-28T17:26:43Z", - "source_access": "PUBLIC_IDENTIFIER", - "source_url": "https://www.nist.gov/artificial-intelligence/ai-agent-standards-initiative", - "superseded_by": null, - "superseded_status": "CURRENT", - "title": "AI Agent Standards Initiative", - "version": "page-undated" - }, - { - "active": true, - "authority": "NIST", - "body_copied": false, - "document_id": "NIST-AI-800-5", - "effective_date": "UNKNOWN", - "jurisdiction": "US", - "next_review_trigger": "Reviewed at package 0.2.0-internal on 2026-09-28. Next rebind at 0.3.0 only after a clean-host qualification that PARTIAL_INTERNAL_CLEAN_HOST_PROOF does not supply, or sooner when the cited authority republishes.", - "notes": "NIST lists this report as published May 18, 2026, report number 800-5. It summarizes RFI responses. It is not a control baseline this catalog adopts, and its text is not copied.", - "publication_date": "2026-05-18", - "retrieved_at": "2026-09-28T17:26:43Z", - "source_access": "PUBLIC_IDENTIFIER", - "source_url": "https://www.nist.gov/publications/summary-analysis-responses-request-information-regarding-security-considerations-ai", - "superseded_by": null, - "superseded_status": "CURRENT", - "title": "Summary Analysis of Responses to the Request for Information Regarding Security Considerations for AI Agents", - "version": "800-5" - }, - { - "active": true, - "authority": "NIST NCCoE", - "body_copied": false, - "document_id": "NCCOE-AGENT-IDENTITY-CONCEPT", - "effective_date": "UNKNOWN", - "jurisdiction": "US", - "next_review_trigger": "Reviewed at package 0.2.0-internal on 2026-09-28. Next rebind at 0.3.0 only after a clean-host qualification that PARTIAL_INTERNAL_CLEAN_HOST_PROOF does not supply, or sooner when the cited authority republishes.", - "notes": "CSRC lists the concept paper as published February 5, 2026, with a public comment period that closed April 2, 2026. It is a concept paper for a potential project, not a finished practice guide. Text is not copied.", - "publication_date": "2026-02-05", - "retrieved_at": "2026-09-28T17:26:43Z", - "source_access": "PUBLIC_IDENTIFIER", - "source_url": "https://csrc.nist.gov/pubs/other/2026/02/05/accelerating-the-adoption-of-software-and-ai-agent/ipd", - "superseded_by": null, - "superseded_status": "CURRENT", - "title": "Accelerating the Adoption of Software and Artificial Intelligence Agent Identity and Authorization", - "version": "2026-02-05" - } - ], - "framework_id": "NIST-AI-AGENT-STANDARDS", - "title": "NIST AI Agent Standards Initiative outputs", - "unmapped_control_ids": [ - { - "control_ids": [ - "GA-01", - "GA-02", - "GA-03", - "GA-04", - "GA-05", - "GA-06", - "GA-07", - "GA-08", - "GA-09", - "GA-10", - "GA-11", - "GA-12", - "GA-13", - "GA-14", - "GA-15", - "GA-16", - "GA-17", - "GA-18", - "GA-19", - "GA-20", - "GA-21", - "GA-22", - "GA-23", - "GA-24", - "GA-25", - "GA-26", - "GA-27", - "GA-28", - "GA-29", - "GA-31", - "GA-32", - "GA-33", - "GA-34", - "GA-35", - "GA-36", - "GA-37", - "GA-38", - "GA-39", - "GA-40" - ], - "version": "page-undated" - }, - { - "control_ids": [ - "GA-01", - "GA-02", - "GA-03", - "GA-04", - "GA-05", - "GA-06", - "GA-07", - "GA-08", - "GA-09", - "GA-10", - "GA-11", - "GA-12", - "GA-14", - "GA-15", - "GA-16", - "GA-17", - "GA-18", - "GA-19", - "GA-20", - "GA-21", - "GA-22", - "GA-23", - "GA-24", - "GA-25", - "GA-26", - "GA-27", - "GA-28", - "GA-29", - "GA-30", - "GA-31", - "GA-32", - "GA-33", - "GA-34", - "GA-35", - "GA-36", - "GA-37", - "GA-38", - "GA-39", - "GA-40" - ], - "version": "800-5" - }, - { - "control_ids": [ - "GA-01", - "GA-02", - "GA-03", - "GA-04", - "GA-05", - "GA-07", - "GA-08", - "GA-09", - "GA-10", - "GA-11", - "GA-12", - "GA-13", - "GA-14", - "GA-15", - "GA-17", - "GA-18", - "GA-19", - "GA-20", - "GA-21", - "GA-22", - "GA-23", - "GA-24", - "GA-25", - "GA-26", - "GA-27", - "GA-28", - "GA-29", - "GA-30", - "GA-31", - "GA-32", - "GA-33", - "GA-34", - "GA-35", - "GA-36", - "GA-37", - "GA-38", - "GA-39", - "GA-40" - ], - "version": "2026-02-05" - } - ] - }, - { - "documents": [ - { - "active": true, - "authority": "European Parliament and Council", - "body_copied": false, - "document_id": "REG-EU-2024-1689", - "effective_date": "UNKNOWN", - "jurisdiction": "EU", - "next_review_trigger": "Reviewed at package 0.2.0-internal on 2026-09-28. Next rebind at 0.3.0 only after a clean-host qualification that PARTIAL_INTERNAL_CLEAN_HOST_PROOF does not supply, or sooner when the cited authority republishes.", - "notes": "ELI identifies Regulation (EU) 2024/1689, published in the Official Journal on 12 July 2024. The regulation states more than one application date. This register does not collapse those dates into one effective date and does not copy the articles. The crosswalk is technical and is not a legal classification.", - "publication_date": "2024-07-12", - "retrieved_at": "2026-09-28T17:26:43Z", - "source_access": "PUBLIC_IDENTIFIER", - "source_url": "http://data.europa.eu/eli/reg/2024/1689/oj", - "superseded_by": null, - "superseded_status": "CURRENT", - "title": "Regulation (EU) 2024/1689", - "version": "2024/1689" - } - ], - "framework_id": "EU-AI-ACT", - "title": "EU AI Act technical crosswalk", - "unmapped_control_ids": [ - { - "control_ids": [ - "GA-02", - "GA-03", - "GA-05", - "GA-06", - "GA-07", - "GA-08", - "GA-09", - "GA-10", - "GA-11", - "GA-14", - "GA-15", - "GA-16", - "GA-17", - "GA-18", - "GA-20", - "GA-21", - "GA-22", - "GA-23", - "GA-24", - "GA-26", - "GA-27", - "GA-28", - "GA-29", - "GA-30", - "GA-31", - "GA-32", - "GA-33", - "GA-34", - "GA-38", - "GA-40" - ], - "version": "2024/1689" - } - ] - }, - { - "documents": [ - { - "active": true, - "authority": "ISO/IEC", - "body_copied": false, - "document_id": "ISO-IEC-42001-2023", - "effective_date": "UNKNOWN", - "jurisdiction": "INTERNATIONAL", - "next_review_trigger": "Reviewed at package 0.2.0-internal on 2026-09-28. Next rebind at 0.3.0 only after a clean-host qualification that PARTIAL_INTERNAL_CLEAN_HOST_PROOF does not supply, or sooner when the cited authority republishes.", - "notes": "The public catalog identifier is ISO/IEC 42001:2023. Clause text was not retrieved. No clause number and no clause sentence is asserted. A management-system certificate is not claimed. Every control row is present with reference SOURCE_ACCESS_REQUIRED, so the current-document unmapped list is empty. An empty list is not a clause map.", - "publication_date": "UNKNOWN", - "retrieved_at": "2026-09-28T17:26:43Z", - "source_access": "SOURCE_ACCESS_REQUIRED", - "source_url": "https://www.iso.org/standard/81230.html", - "superseded_by": null, - "superseded_status": "CURRENT", - "title": "ISO/IEC 42001:2023", - "version": "2023" - } - ], - "framework_id": "ISO-IEC-42001", - "title": "ISO/IEC 42001", - "unmapped_control_ids": [ - { - "control_ids": [], - "version": "2023" - } - ] - }, - { - "documents": [ - { - "active": true, - "authority": "OMB", - "body_copied": false, - "document_id": "OMB-M-25-21", - "effective_date": "UNKNOWN", - "jurisdiction": "US", - "next_review_trigger": "Reviewed at package 0.2.0-internal on 2026-09-28. Next rebind at 0.3.0 only after a clean-host qualification that PARTIAL_INTERNAL_CLEAN_HOST_PROOF does not supply, or sooner when the cited authority republishes.", - "notes": "The memorandum is dated April 3, 2025. It states that it rescinds and replaces OMB Memorandum M-24-10. A single effective date is not recorded in this register. Agency duties are not copied and are not claimed as met.", - "publication_date": "2025-04-03", - "retrieved_at": "2026-09-28T17:26:43Z", - "source_access": "PUBLIC_IDENTIFIER", - "source_url": "https://www.whitehouse.gov/wp-content/uploads/2025/02/M-25-21-Accelerating-Federal-Use-of-AI-through-Innovation-Governance-and-Public-Trust.pdf", - "superseded_by": null, - "superseded_status": "CURRENT", - "title": "Accelerating Federal Use of AI through Innovation, Governance, and Public Trust", - "version": "M-25-21" - }, - { - "active": true, - "authority": "OMB", - "body_copied": false, - "document_id": "OMB-M-25-22", - "effective_date": "UNKNOWN", - "jurisdiction": "US", - "next_review_trigger": "Reviewed at package 0.2.0-internal on 2026-09-28. Next rebind at 0.3.0 only after a clean-host qualification that PARTIAL_INTERNAL_CLEAN_HOST_PROOF does not supply, or sooner when the cited authority republishes.", - "notes": "The memorandum is dated April 3, 2025. It states that it rescinds and replaces OMB Memorandum M-24-18. It also states that it applies to contracts awarded from solicitations issued on or after 180 days after issuance. This register does not convert that rule into a calendar effective date.", - "publication_date": "2025-04-03", - "retrieved_at": "2026-09-28T17:26:43Z", - "source_access": "PUBLIC_IDENTIFIER", - "source_url": "https://www.whitehouse.gov/wp-content/uploads/2025/02/M-25-22-Driving-Efficient-Acquisition-of-Artificial-Intelligence-in-Government.pdf", - "superseded_by": null, - "superseded_status": "CURRENT", - "title": "Driving Efficient Acquisition of Artificial Intelligence in Government", - "version": "M-25-22" - }, - { - "active": true, - "authority": "OMB", - "body_copied": false, - "document_id": "OMB-M-26-04", - "effective_date": "UNKNOWN", - "jurisdiction": "US", - "next_review_trigger": "Reviewed at package 0.2.0-internal on 2026-09-28. Next rebind at 0.3.0 only after a clean-host qualification that PARTIAL_INTERNAL_CLEAN_HOST_PROOF does not supply, or sooner when the cited authority republishes.", - "notes": "The OMB memoranda index lists M-26-04 on December 11, 2025. The memorandum body is not copied. No claim is made that a model meets it. Effective date is UNKNOWN in this register.", - "publication_date": "2025-12-11", - "retrieved_at": "2026-09-28T17:26:43Z", - "source_access": "PUBLIC_IDENTIFIER", - "source_url": "https://www.whitehouse.gov/wp-content/uploads/2025/12/M-26-04-Increasing-Public-Trust-in-Artificial-Intelligence-Through-Unbiased-AI-Principles-1.pdf", - "superseded_by": null, - "superseded_status": "CURRENT", - "title": "Increasing Public Trust in Artificial Intelligence Through Unbiased AI Principles", - "version": "M-26-04" - }, - { - "active": false, - "authority": "OMB", - "body_copied": false, - "document_id": "OMB-M-24-10", - "effective_date": "UNKNOWN", - "jurisdiction": "US", - "next_review_trigger": "Reviewed at package 0.2.0-internal on 2026-09-28. Next rebind at 0.3.0 only after a clean-host qualification that PARTIAL_INTERNAL_CLEAN_HOST_PROOF does not supply, or sooner when the cited authority republishes.", - "notes": "Current only as a superseded pointer. M-25-21 states that it rescinds and replaces M-24-10. source_url is the successor PDF, not a retrieved copy of the superseded memorandum. The superseded memorandum is not an active mapping.", - "publication_date": "UNKNOWN", - "retrieved_at": "2026-09-28T17:26:43Z", - "source_access": "PUBLIC_IDENTIFIER", - "source_url": "https://www.whitehouse.gov/wp-content/uploads/2025/02/M-25-21-Accelerating-Federal-Use-of-AI-through-Innovation-Governance-and-Public-Trust.pdf", - "superseded_by": "M-25-21", - "superseded_status": "SUPERSEDED", - "title": "Advancing Governance, Innovation, and Risk Management for Agency Use of Artificial Intelligence", - "version": "M-24-10" - }, - { - "active": false, - "authority": "OMB", - "body_copied": false, - "document_id": "OMB-M-24-18", - "effective_date": "UNKNOWN", - "jurisdiction": "US", - "next_review_trigger": "Reviewed at package 0.2.0-internal on 2026-09-28. Next rebind at 0.3.0 only after a clean-host qualification that PARTIAL_INTERNAL_CLEAN_HOST_PROOF does not supply, or sooner when the cited authority republishes.", - "notes": "Current only as a superseded pointer. M-25-22 states that it rescinds and replaces M-24-18. source_url is the successor PDF, not a retrieved copy of the superseded memorandum. The superseded memorandum is not an active mapping.", - "publication_date": "UNKNOWN", - "retrieved_at": "2026-09-28T17:26:43Z", - "source_access": "PUBLIC_IDENTIFIER", - "source_url": "https://www.whitehouse.gov/wp-content/uploads/2025/02/M-25-22-Driving-Efficient-Acquisition-of-Artificial-Intelligence-in-Government.pdf", - "superseded_by": "M-25-22", - "superseded_status": "SUPERSEDED", - "title": "Advancing the Responsible Acquisition of Artificial Intelligence in Government", - "version": "M-24-18" - } - ], - "framework_id": "US-FEDERAL-AI-ACQUISITION", - "title": "U.S. federal AI acquisition and governance guidance", - "unmapped_control_ids": [ - { - "control_ids": [ - "GA-01", - "GA-02", - "GA-03", - "GA-05", - "GA-06", - "GA-07", - "GA-08", - "GA-09", - "GA-10", - "GA-11", - "GA-12", - "GA-13", - "GA-14", - "GA-15", - "GA-16", - "GA-17", - "GA-18", - "GA-19", - "GA-20", - "GA-21", - "GA-22", - "GA-23", - "GA-24", - "GA-25", - "GA-26", - "GA-27", - "GA-28", - "GA-29", - "GA-30", - "GA-31", - "GA-32", - "GA-33", - "GA-34", - "GA-35", - "GA-36", - "GA-37", - "GA-38", - "GA-40" - ], - "version": "M-25-21" - }, - { - "control_ids": [ - "GA-01", - "GA-02", - "GA-03", - "GA-04", - "GA-05", - "GA-06", - "GA-07", - "GA-08", - "GA-09", - "GA-10", - "GA-11", - "GA-12", - "GA-13", - "GA-14", - "GA-15", - "GA-16", - "GA-17", - "GA-18", - "GA-19", - "GA-20", - "GA-21", - "GA-22", - "GA-23", - "GA-24", - "GA-25", - "GA-27", - "GA-28", - "GA-29", - "GA-30", - "GA-31", - "GA-32", - "GA-33", - "GA-34", - "GA-35", - "GA-36", - "GA-37", - "GA-39", - "GA-40" - ], - "version": "M-25-22" - }, - { - "control_ids": [ - "GA-01", - "GA-02", - "GA-03", - "GA-04", - "GA-05", - "GA-06", - "GA-07", - "GA-08", - "GA-09", - "GA-10", - "GA-11", - "GA-12", - "GA-13", - "GA-14", - "GA-15", - "GA-16", - "GA-17", - "GA-18", - "GA-19", - "GA-20", - "GA-21", - "GA-22", - "GA-23", - "GA-24", - "GA-25", - "GA-26", - "GA-27", - "GA-28", - "GA-29", - "GA-30", - "GA-31", - "GA-32", - "GA-33", - "GA-34", - "GA-36", - "GA-37", - "GA-38", - "GA-39", - "GA-40" - ], - "version": "M-26-04" - } - ] - } - ], - "provenance": { - "audience": "INTERNAL_RESTRICTED", - "catalog_version": "0.2.0-internal", - "council_status": "PENDING_INDEPENDENT_COUNCIL", - "distribution": "INTERNAL_RESTRICTED", - "generated_at": "2026-09-28T17:26:43Z", - "generator": "@vantio/governance-assurance", - "mapping_commit": "NOT_SELF_HASHED", - "mapping_version": "0.2.0-internal", - "package_name": "@vantio/governance-assurance", - "package_version": "0.2.0-internal", - "producer_classification": "WS17_GOVERNANCE_ASSURANCE_0_2_0_INTERNAL_REBIND_READY_FOR_COUNCIL", - "program_claim_ceiling": "INTERNAL_CLEAN_HOST_PROOF", - "retrieved_at": "2026-09-28T17:26:43Z", - "reviewer": "PENDING_INDEPENDENT_COUNCIL", - "self_certified_council_pass": false, - "source_base_commit": "b0bcbdeb01ccb84a58a3aa6aacd0c05f94b22450", - "source_repository": "vantioai/vantio-open-core", - "supersedes_package": "0.1.0-internal" - }, - "schema": "vantio.governance-assurance.framework-register/v1" -} diff --git a/docs/internal/governance-assurance/reports/GOVERNANCE_POSTURE.json b/docs/internal/governance-assurance/reports/GOVERNANCE_POSTURE.json deleted file mode 100644 index f2b18867..00000000 --- a/docs/internal/governance-assurance/reports/GOVERNANCE_POSTURE.json +++ /dev/null @@ -1,1725 +0,0 @@ -{ - "claim_ceiling": "Governance Assurance 0.2.0-internal is a private mapping layer. NON-NORMATIVE. NOT_LEGAL_ADVICE. NO_COMPLIANCE_GUARANTEE. It does not certify a system, approve a procurement, classify legal risk, or convert a missing capability into a pass. It does not raise a proof class and it is not a customer candidate.", - "controls": [ - { - "capability_version": "0.3.24", - "claim_ceiling": "This row binds a bounded fact already in the tree. It is not certification, legal conformity, or external proof.", - "configuration_state": "NOT_CONFIGURED", - "control_id": "GA-01", - "evidence_freshness": "CURRENT_FOR_CATALOG_REVIEW", - "implementation_state": "AVAILABLE", - "lifecycle_order": 1, - "primary_support": "VANTIO_PARTIALLY_SUPPORTS", - "product": "OPTICS", - "proof_class": "PRODUCER_TEST", - "review_date": "2026-09-28", - "runtime_state": "NOT_APPLICABLE", - "satisfaction": { - "binding_ids": [ - "EB-CLI-0324" - ], - "pass": false, - "prior_pass": "NOT_PROMOTED", - "reason": "EVIDENCE_BOUND_NOT_A_COMPLIANCE_PASS", - "staleness": { - "clears_prior_pass": false, - "reasons": [], - "stale": false - }, - "status": "BOUND_WITH_LIMITS" - }, - "supersedes": null, - "title": "AI system inventory for supported observation paths", - "verification_state": "PRODUCER_TESTED" - }, - { - "capability_version": "characterized", - "claim_ceiling": "This row binds a bounded fact already in the tree. It is not certification, legal conformity, or external proof.", - "configuration_state": "NOT_APPLICABLE", - "control_id": "GA-02", - "evidence_freshness": "CURRENT_FOR_CATALOG_REVIEW", - "implementation_state": "IMPLEMENTED_INTERNAL", - "lifecycle_order": 2, - "primary_support": "VANTIO_PARTIALLY_SUPPORTS", - "product": "GOVERNANCE_ASSURANCE", - "proof_class": "CHARACTERIZATION", - "review_date": "2026-09-28", - "runtime_state": "NOT_APPLICABLE", - "satisfaction": { - "binding_ids": [ - "EB-T14" - ], - "pass": false, - "prior_pass": "NOT_PROMOTED", - "reason": "EVIDENCE_BOUND_NOT_A_COMPLIANCE_PASS", - "staleness": { - "clears_prior_pass": false, - "reasons": [], - "stale": false - }, - "status": "BOUND_WITH_LIMITS" - }, - "supersedes": null, - "title": "Component and release-surface inventory", - "verification_state": "PRODUCER_TESTED" - }, - { - "capability_version": "0.3.24", - "claim_ceiling": "This row binds a bounded fact already in the tree. It is not certification, legal conformity, or external proof.", - "configuration_state": "NOT_APPLICABLE", - "control_id": "GA-03", - "evidence_freshness": "CURRENT_FOR_CATALOG_REVIEW", - "implementation_state": "AVAILABLE", - "lifecycle_order": 3, - "primary_support": "VANTIO_PARTIALLY_SUPPORTS", - "product": "OPTICS", - "proof_class": "PRODUCER_TEST", - "review_date": "2026-09-28", - "runtime_state": "NOT_APPLICABLE", - "satisfaction": { - "binding_ids": [ - "EB-CLI-0324" - ], - "pass": false, - "prior_pass": "NOT_PROMOTED", - "reason": "EVIDENCE_BOUND_NOT_A_COMPLIANCE_PASS", - "staleness": { - "clears_prior_pass": false, - "reasons": [], - "stale": false - }, - "status": "BOUND_WITH_LIMITS" - }, - "supersedes": null, - "title": "Coverage gap disclosure", - "verification_state": "PRODUCER_TESTED" - }, - { - "capability_version": "0.2.0-internal", - "claim_ceiling": "The named customer or third-party role holds this duty. Vantio does not discharge it.", - "configuration_state": "NOT_APPLICABLE", - "control_id": "GA-04", - "evidence_freshness": "CURRENT_FOR_CATALOG_REVIEW", - "implementation_state": "NOT_IMPLEMENTED", - "lifecycle_order": 4, - "primary_support": "CUSTOMER_PROVIDES", - "product": "GOVERNANCE_ASSURANCE", - "proof_class": "NONE", - "review_date": "2026-09-28", - "runtime_state": "NOT_APPLICABLE", - "satisfaction": { - "pass": false, - "prior_pass": "NOT_PROMOTED", - "reason": "NOT_A_PASS", - "staleness": { - "clears_prior_pass": false, - "reasons": [], - "stale": false - }, - "status": "NOT_SATISFIED" - }, - "supersedes": "0.1.0-internal", - "title": "Legal classification and conformity roles", - "verification_state": "NOT_TESTED" - }, - { - "capability_version": "plan-only", - "claim_ceiling": "The named customer or third-party role holds this duty. Vantio does not discharge it.", - "configuration_state": "NOT_CONFIGURED", - "control_id": "GA-05", - "evidence_freshness": "CURRENT_FOR_CATALOG_REVIEW", - "implementation_state": "DESIGNED", - "lifecycle_order": 5, - "primary_support": "CUSTOMER_CONFIGURES", - "product": "ENTERPRISE", - "proof_class": "DESIGN_RECORD", - "review_date": "2026-09-28", - "runtime_state": "NOT_APPLICABLE", - "satisfaction": { - "pass": false, - "prior_pass": "NOT_PROMOTED", - "reason": "NOT_A_PASS", - "staleness": { - "clears_prior_pass": false, - "reasons": [], - "stale": false - }, - "status": "NOT_SATISFIED" - }, - "supersedes": null, - "title": "Ownership assignment", - "verification_state": "NOT_TESTED" - }, - { - "capability_version": "plan-only", - "claim_ceiling": "The named customer or third-party role holds this duty. Vantio does not discharge it.", - "configuration_state": "NOT_CONFIGURED", - "control_id": "GA-06", - "evidence_freshness": "CURRENT_FOR_CATALOG_REVIEW", - "implementation_state": "DESIGNED", - "lifecycle_order": 6, - "primary_support": "CUSTOMER_CONFIGURES", - "product": "ENTERPRISE", - "proof_class": "DESIGN_RECORD", - "review_date": "2026-09-28", - "runtime_state": "NOT_APPLICABLE", - "satisfaction": { - "pass": false, - "prior_pass": "NOT_PROMOTED", - "reason": "NOT_A_PASS", - "staleness": { - "clears_prior_pass": false, - "reasons": [], - "stale": false - }, - "status": "NOT_SATISFIED" - }, - "supersedes": null, - "title": "Delegated authority", - "verification_state": "NOT_TESTED" - }, - { - "capability_version": "plan-only", - "claim_ceiling": "The named customer or third-party role holds this duty. Vantio does not discharge it.", - "configuration_state": "NOT_CONFIGURED", - "control_id": "GA-07", - "evidence_freshness": "CURRENT_FOR_CATALOG_REVIEW", - "implementation_state": "DESIGNED", - "lifecycle_order": 7, - "primary_support": "CUSTOMER_CONFIGURES", - "product": "ENTERPRISE", - "proof_class": "DESIGN_RECORD", - "review_date": "2026-09-28", - "runtime_state": "NOT_APPLICABLE", - "satisfaction": { - "pass": false, - "prior_pass": "NOT_PROMOTED", - "reason": "NOT_A_PASS", - "staleness": { - "clears_prior_pass": false, - "reasons": [], - "stale": false - }, - "status": "NOT_SATISFIED" - }, - "supersedes": null, - "title": "Approvals and dual control", - "verification_state": "NOT_TESTED" - }, - { - "capability_version": "absent", - "claim_ceiling": "This row is not satisfied. Absence, a plan, or an in-revision track is not a pass.", - "configuration_state": "NOT_CONFIGURED", - "control_id": "GA-08", - "evidence_freshness": "UNSET", - "implementation_state": "NOT_IMPLEMENTED", - "lifecycle_order": 8, - "primary_support": "NOT_IMPLEMENTED", - "product": "ENTERPRISE", - "proof_class": "NONE", - "review_date": "2026-09-28", - "runtime_state": "NOT_APPLICABLE", - "satisfaction": { - "pass": false, - "prior_pass": "CLEARED", - "reason": "STALE", - "staleness": { - "clears_prior_pass": true, - "reasons": [ - "EVIDENCE_UNSET" - ], - "stale": true - }, - "status": "NOT_SATISFIED" - }, - "supersedes": null, - "title": "Exception handling", - "verification_state": "NOT_TESTED" - }, - { - "capability_version": "absent", - "claim_ceiling": "This row is not satisfied. Absence, a plan, or an in-revision track is not a pass.", - "configuration_state": "NOT_CONFIGURED", - "control_id": "GA-09", - "evidence_freshness": "UNSET", - "implementation_state": "NOT_IMPLEMENTED", - "lifecycle_order": 9, - "primary_support": "NOT_IMPLEMENTED", - "product": "ENTERPRISE", - "proof_class": "NONE", - "review_date": "2026-09-28", - "runtime_state": "NOT_APPLICABLE", - "satisfaction": { - "pass": false, - "prior_pass": "CLEARED", - "reason": "STALE", - "staleness": { - "clears_prior_pass": true, - "reasons": [ - "EVIDENCE_UNSET" - ], - "stale": true - }, - "status": "NOT_SATISFIED" - }, - "supersedes": null, - "title": "Customer policy authoring", - "verification_state": "NOT_TESTED" - }, - { - "capability_version": "not-in-this-tree", - "claim_ceiling": "This row is not satisfied. Absence, a plan, or an in-revision track is not a pass.", - "configuration_state": "NOT_CONFIGURED", - "control_id": "GA-10", - "evidence_freshness": "UNSET", - "implementation_state": "NOT_IMPLEMENTED", - "lifecycle_order": 10, - "primary_support": "UNVERIFIED", - "product": "PHANTOM_ENGINE", - "proof_class": "NONE", - "review_date": "2026-09-28", - "runtime_state": "NOT_RUNNING", - "satisfaction": { - "pass": false, - "prior_pass": "CLEARED", - "reason": "STALE", - "staleness": { - "clears_prior_pass": true, - "reasons": [ - "EVIDENCE_UNSET" - ], - "stale": true - }, - "status": "NOT_SATISFIED" - }, - "supersedes": null, - "title": "Host policy configuration", - "verification_state": "NOT_TESTED" - }, - { - "capability_version": "not-in-this-tree", - "claim_ceiling": "This row is not satisfied. Absence, a plan, or an in-revision track is not a pass.", - "configuration_state": "NOT_CONFIGURED", - "control_id": "GA-11", - "evidence_freshness": "UNSET", - "implementation_state": "NOT_IMPLEMENTED", - "lifecycle_order": 11, - "primary_support": "UNVERIFIED", - "product": "PHANTOM_ENGINE", - "proof_class": "NONE", - "review_date": "2026-09-28", - "runtime_state": "NOT_RUNNING", - "satisfaction": { - "pass": false, - "prior_pass": "CLEARED", - "reason": "STALE", - "staleness": { - "clears_prior_pass": true, - "reasons": [ - "EVIDENCE_UNSET" - ], - "stale": true - }, - "status": "NOT_SATISFIED" - }, - "supersedes": null, - "title": "Host enrollment", - "verification_state": "NOT_TESTED" - }, - { - "capability_version": "0.3.24", - "claim_ceiling": "This row binds a bounded fact already in the tree. It is not certification, legal conformity, or external proof.", - "configuration_state": "NOT_CONFIGURED", - "control_id": "GA-12", - "evidence_freshness": "CURRENT_FOR_CATALOG_REVIEW", - "implementation_state": "AVAILABLE", - "lifecycle_order": 12, - "primary_support": "VANTIO_PARTIALLY_SUPPORTS", - "product": "OPTICS", - "proof_class": "PRODUCER_TEST", - "review_date": "2026-09-28", - "runtime_state": "NOT_APPLICABLE", - "satisfaction": { - "binding_ids": [ - "EB-CLI-0324" - ], - "pass": false, - "prior_pass": "NOT_PROMOTED", - "reason": "EVIDENCE_BOUND_NOT_A_COMPLIANCE_PASS", - "staleness": { - "clears_prior_pass": false, - "reasons": [], - "stale": false - }, - "status": "BOUND_WITH_LIMITS" - }, - "supersedes": null, - "title": "Runtime observation of supported agent egress", - "verification_state": "PRODUCER_TESTED" - }, - { - "capability_version": "not-attached", - "claim_ceiling": "This row is not satisfied. Absence, a plan, or an in-revision track is not a pass.", - "configuration_state": "NOT_CONFIGURED", - "control_id": "GA-13", - "evidence_freshness": "UNSET", - "implementation_state": "NOT_IMPLEMENTED", - "lifecycle_order": 13, - "primary_support": "UNVERIFIED", - "product": "PHANTOM_ENGINE", - "proof_class": "NONE", - "review_date": "2026-09-28", - "runtime_state": "NOT_RUNNING", - "satisfaction": { - "pass": false, - "prior_pass": "CLEARED", - "reason": "STALE", - "staleness": { - "clears_prior_pass": true, - "reasons": [ - "EVIDENCE_UNSET" - ], - "stale": true - }, - "status": "NOT_SATISFIED" - }, - "supersedes": null, - "title": "Runtime enforcement", - "verification_state": "NOT_TESTED" - }, - { - "capability_version": "merged-observe-only", - "claim_ceiling": "This row is not satisfied. The observe-only merge is not a pass.", - "configuration_state": "UNKNOWN", - "control_id": "GA-14", - "evidence_freshness": "CURRENT_FOR_CATALOG_REVIEW", - "implementation_state": "NOT_IMPLEMENTED", - "lifecycle_order": 14, - "primary_support": "UNVERIFIED", - "product": "PHANTOM_ENGINE", - "proof_class": "NONE", - "review_date": "2026-09-28", - "runtime_state": "UNKNOWN", - "satisfaction": { - "pass": false, - "prior_pass": "NOT_PROMOTED", - "reason": "NOT_A_PASS", - "staleness": { - "clears_prior_pass": false, - "reasons": [], - "stale": false - }, - "status": "NOT_SATISFIED" - }, - "supersedes": null, - "title": "Ingress control", - "verification_state": "NOT_TESTED" - }, - { - "capability_version": "merged-contract-only", - "claim_ceiling": "This row is not satisfied. The contract-only merge is not a pass.", - "configuration_state": "UNKNOWN", - "control_id": "GA-15", - "evidence_freshness": "CURRENT_FOR_CATALOG_REVIEW", - "implementation_state": "NOT_IMPLEMENTED", - "lifecycle_order": 15, - "primary_support": "UNVERIFIED", - "product": "PHANTOM_ENGINE", - "proof_class": "NONE", - "review_date": "2026-09-28", - "runtime_state": "UNKNOWN", - "satisfaction": { - "pass": false, - "prior_pass": "NOT_PROMOTED", - "reason": "NOT_A_PASS", - "staleness": { - "clears_prior_pass": false, - "reasons": [], - "stale": false - }, - "status": "NOT_SATISFIED" - }, - "supersedes": null, - "title": "Egress enforcement", - "verification_state": "NOT_TESTED" - }, - { - "capability_version": "0.3.24", - "claim_ceiling": "This row binds a bounded fact already in the tree. It is not certification, legal conformity, or external proof.", - "configuration_state": "NOT_CONFIGURED", - "control_id": "GA-16", - "evidence_freshness": "CURRENT_FOR_CATALOG_REVIEW", - "implementation_state": "AVAILABLE", - "lifecycle_order": 16, - "primary_support": "VANTIO_PARTIALLY_SUPPORTS", - "product": "OPTICS", - "proof_class": "PRODUCER_TEST", - "review_date": "2026-09-28", - "runtime_state": "NOT_APPLICABLE", - "satisfaction": { - "binding_ids": [ - "EB-CLI-0324" - ], - "pass": false, - "prior_pass": "NOT_PROMOTED", - "reason": "EVIDENCE_BOUND_NOT_A_COMPLIANCE_PASS", - "staleness": { - "clears_prior_pass": false, - "reasons": [], - "stale": false - }, - "status": "BOUND_WITH_LIMITS" - }, - "supersedes": null, - "title": "Process attribution on supported paths", - "verification_state": "PRODUCER_TESTED" - }, - { - "capability_version": "0.0.0-unstable-pre-1.0", - "claim_ceiling": "This row binds a bounded fact already in the tree. It is not certification, legal conformity, or external proof.", - "configuration_state": "NOT_APPLICABLE", - "control_id": "GA-17", - "evidence_freshness": "CURRENT_FOR_CATALOG_REVIEW", - "implementation_state": "IMPLEMENTED_INTERNAL", - "lifecycle_order": 17, - "primary_support": "VANTIO_PARTIALLY_SUPPORTS", - "product": "PHANTOM_ENGINE", - "proof_class": "PRODUCER_TEST", - "review_date": "2026-09-28", - "runtime_state": "NOT_APPLICABLE", - "satisfaction": { - "binding_ids": [ - "EB-T8" - ], - "pass": false, - "prior_pass": "NOT_PROMOTED", - "reason": "EVIDENCE_BOUND_NOT_A_COMPLIANCE_PASS", - "staleness": { - "clears_prior_pass": false, - "reasons": [], - "stale": false - }, - "status": "BOUND_WITH_LIMITS" - }, - "supersedes": null, - "title": "In-process revocation step", - "verification_state": "PRODUCER_TESTED" - }, - { - "capability_version": "absent", - "claim_ceiling": "This row is not satisfied. Absence, a plan, or an in-revision track is not a pass.", - "configuration_state": "NOT_CONFIGURED", - "control_id": "GA-18", - "evidence_freshness": "UNSET", - "implementation_state": "NOT_IMPLEMENTED", - "lifecycle_order": 18, - "primary_support": "NOT_IMPLEMENTED", - "product": "PHANTOM_ENGINE", - "proof_class": "NONE", - "review_date": "2026-09-28", - "runtime_state": "NOT_RUNNING", - "satisfaction": { - "pass": false, - "prior_pass": "CLEARED", - "reason": "STALE", - "staleness": { - "clears_prior_pass": true, - "reasons": [ - "EVIDENCE_UNSET" - ], - "stale": true - }, - "status": "NOT_SATISFIED" - }, - "supersedes": null, - "title": "Recovery after revocation or failure", - "verification_state": "NOT_TESTED" - }, - { - "capability_version": "cli 0.3.24 / unit D private / unit E not live", - "claim_ceiling": "This row binds a bounded fact already in the tree. It is not certification, legal conformity, or external proof.", - "configuration_state": "NOT_CONFIGURED", - "control_id": "GA-19", - "evidence_freshness": "CURRENT_FOR_CATALOG_REVIEW", - "implementation_state": "AVAILABLE", - "lifecycle_order": 19, - "primary_support": "VANTIO_PARTIALLY_SUPPORTS", - "product": "OPTICS", - "proof_class": "PRODUCER_TEST", - "review_date": "2026-09-28", - "runtime_state": "NOT_APPLICABLE", - "satisfaction": { - "binding_ids": [ - "EB-CLI-0324" - ], - "pass": false, - "prior_pass": "NOT_PROMOTED", - "reason": "EVIDENCE_BOUND_NOT_A_COMPLIANCE_PASS", - "staleness": { - "clears_prior_pass": false, - "reasons": [], - "stale": false - }, - "status": "BOUND_WITH_LIMITS" - }, - "supersedes": null, - "title": "Evidence capture for supported observation", - "verification_state": "PRODUCER_TESTED" - }, - { - "capability_version": "3.1.0", - "claim_ceiling": "This row binds a bounded fact already in the tree. It is not certification, legal conformity, or external proof.", - "configuration_state": "NOT_APPLICABLE", - "control_id": "GA-20", - "evidence_freshness": "CURRENT_FOR_CATALOG_REVIEW", - "implementation_state": "IMPLEMENTED_INTERNAL", - "lifecycle_order": 20, - "primary_support": "VANTIO_PARTIALLY_SUPPORTS", - "product": "OPTICS", - "proof_class": "RELEASE_CLOSE_PACKET", - "review_date": "2026-09-28", - "runtime_state": "NOT_APPLICABLE", - "satisfaction": { - "binding_ids": [ - "EB-T1" - ], - "pass": false, - "prior_pass": "NOT_PROMOTED", - "reason": "EVIDENCE_BOUND_NOT_A_COMPLIANCE_PASS", - "staleness": { - "clears_prior_pass": false, - "reasons": [], - "stale": false - }, - "status": "BOUND_WITH_LIMITS" - }, - "supersedes": null, - "title": "Evidence custody for the closed Python release", - "verification_state": "PRODUCER_TESTED" - }, - { - "capability_version": "0.2.0-internal", - "claim_ceiling": "This row binds a bounded fact already in the tree. It is not certification, legal conformity, or external proof.", - "configuration_state": "NOT_APPLICABLE", - "control_id": "GA-21", - "evidence_freshness": "CURRENT_FOR_CATALOG_REVIEW", - "implementation_state": "IMPLEMENTED_INTERNAL", - "lifecycle_order": 21, - "primary_support": "VANTIO_PARTIALLY_SUPPORTS", - "product": "GOVERNANCE_ASSURANCE", - "proof_class": "PRODUCER_TEST", - "review_date": "2026-09-28", - "runtime_state": "NOT_APPLICABLE", - "satisfaction": { - "binding_ids": [ - "EB-STALENESS" - ], - "pass": false, - "prior_pass": "NOT_PROMOTED", - "reason": "EVIDENCE_BOUND_NOT_A_COMPLIANCE_PASS", - "staleness": { - "clears_prior_pass": false, - "reasons": [], - "stale": false - }, - "status": "BOUND_WITH_LIMITS" - }, - "supersedes": "0.1.0-internal", - "title": "Evidence freshness and staleness", - "verification_state": "PRODUCER_TESTED" - }, - { - "capability_version": "0.2.0-internal", - "claim_ceiling": "This row is not satisfied. Absence, a plan, or an in-revision track is not a pass.", - "configuration_state": "NOT_APPLICABLE", - "control_id": "GA-22", - "evidence_freshness": "UNSET", - "implementation_state": "NOT_IMPLEMENTED", - "lifecycle_order": 22, - "primary_support": "NOT_IMPLEMENTED", - "product": "GOVERNANCE_ASSURANCE", - "proof_class": "NONE", - "review_date": "2026-09-28", - "runtime_state": "NOT_APPLICABLE", - "satisfaction": { - "pass": false, - "prior_pass": "CLEARED", - "reason": "STALE", - "staleness": { - "clears_prior_pass": true, - "reasons": [ - "EVIDENCE_UNSET" - ], - "stale": true - }, - "status": "NOT_SATISFIED" - }, - "supersedes": "0.1.0-internal", - "title": "Independent verification", - "verification_state": "NOT_TESTED" - }, - { - "capability_version": "statement-only", - "claim_ceiling": "The named customer or third-party role holds this duty. Vantio does not discharge it.", - "configuration_state": "NOT_APPLICABLE", - "control_id": "GA-23", - "evidence_freshness": "CURRENT_FOR_CATALOG_REVIEW", - "implementation_state": "NOT_IMPLEMENTED", - "lifecycle_order": 23, - "primary_support": "CUSTOMER_PROVIDES", - "product": "PHANTOM_ENGINE", - "proof_class": "DESIGN_RECORD", - "review_date": "2026-09-28", - "runtime_state": "NOT_APPLICABLE", - "satisfaction": { - "pass": false, - "prior_pass": "NOT_PROMOTED", - "reason": "NOT_A_PASS", - "staleness": { - "clears_prior_pass": false, - "reasons": [], - "stale": false - }, - "status": "NOT_SATISFIED" - }, - "supersedes": null, - "title": "Customer-controlled infrastructure boundary", - "verification_state": "NOT_TESTED" - }, - { - "capability_version": "0.3.24", - "claim_ceiling": "Partial. A secret placed in the URL path is stored because the path is kept. The CLI version file does not prove non-collection. This row is not certification, legal conformity, or external proof.", - "configuration_state": "NOT_APPLICABLE", - "control_id": "GA-24", - "evidence_freshness": "CURRENT_FOR_CATALOG_REVIEW", - "implementation_state": "AVAILABLE", - "lifecycle_order": 24, - "primary_support": "VANTIO_PARTIALLY_SUPPORTS", - "product": "OPTICS", - "proof_class": "DESIGN_RECORD", - "review_date": "2026-09-28", - "runtime_state": "NOT_APPLICABLE", - "satisfaction": { - "pass": false, - "prior_pass": "NOT_PROMOTED", - "reason": "NO_COUNTING_EVIDENCE", - "staleness": { - "clears_prior_pass": false, - "reasons": [], - "stale": false - }, - "status": "NOT_SATISFIED" - }, - "supersedes": null, - "title": "Credential and secret non-collection on supported paths", - "verification_state": "NOT_TESTED" - }, - { - "capability_version": "0.3.24", - "claim_ceiling": "This row binds a bounded fact already in the tree. It is not certification, legal conformity, or external proof.", - "configuration_state": "NOT_APPLICABLE", - "control_id": "GA-25", - "evidence_freshness": "CURRENT_FOR_CATALOG_REVIEW", - "implementation_state": "AVAILABLE", - "lifecycle_order": 25, - "primary_support": "VANTIO_PARTIALLY_SUPPORTS", - "product": "OPTICS", - "proof_class": "PRODUCER_TEST", - "review_date": "2026-09-28", - "runtime_state": "NOT_APPLICABLE", - "satisfaction": { - "binding_ids": [ - "EB-CLI-0324" - ], - "pass": false, - "prior_pass": "NOT_PROMOTED", - "reason": "EVIDENCE_BOUND_NOT_A_COMPLIANCE_PASS", - "staleness": { - "clears_prior_pass": false, - "reasons": [], - "stale": false - }, - "status": "BOUND_WITH_LIMITS" - }, - "supersedes": null, - "title": "Content non-retention on supported paths", - "verification_state": "PRODUCER_TESTED" - }, - { - "capability_version": "characterized", - "claim_ceiling": "This row binds a bounded fact already in the tree. It is not certification, legal conformity, or external proof.", - "configuration_state": "NOT_APPLICABLE", - "control_id": "GA-26", - "evidence_freshness": "CURRENT_FOR_CATALOG_REVIEW", - "implementation_state": "IMPLEMENTED_INTERNAL", - "lifecycle_order": 26, - "primary_support": "VANTIO_PARTIALLY_SUPPORTS", - "product": "GOVERNANCE_ASSURANCE", - "proof_class": "CHARACTERIZATION", - "review_date": "2026-09-28", - "runtime_state": "NOT_APPLICABLE", - "satisfaction": { - "binding_ids": [ - "EB-T14" - ], - "pass": false, - "prior_pass": "NOT_PROMOTED", - "reason": "EVIDENCE_BOUND_NOT_A_COMPLIANCE_PASS", - "staleness": { - "clears_prior_pass": false, - "reasons": [], - "stale": false - }, - "status": "BOUND_WITH_LIMITS" - }, - "supersedes": null, - "title": "Change and release characterization", - "verification_state": "PRODUCER_TESTED" - }, - { - "capability_version": "blocked", - "claim_ceiling": "This row is not satisfied. Absence, a plan, or an in-revision track is not a pass.", - "configuration_state": "NOT_CONFIGURED", - "control_id": "GA-27", - "evidence_freshness": "UNSET", - "implementation_state": "NOT_IMPLEMENTED", - "lifecycle_order": 27, - "primary_support": "UNVERIFIED", - "product": "PHANTOM_ENGINE", - "proof_class": "BLOCKED_UNSET", - "review_date": "2026-09-28", - "runtime_state": "NOT_RUNNING", - "satisfaction": { - "pass": false, - "prior_pass": "CLEARED", - "reason": "STALE", - "staleness": { - "clears_prior_pass": true, - "reasons": [ - "EVIDENCE_UNSET" - ], - "stale": true - }, - "status": "NOT_SATISFIED" - }, - "supersedes": null, - "title": "Rollback and uninstall proof", - "verification_state": "NOT_TESTED" - }, - { - "capability_version": "0.0.0-unstable-pre-1.0", - "claim_ceiling": "This row binds a bounded fact already in the tree. It is not certification, legal conformity, or external proof.", - "configuration_state": "NOT_APPLICABLE", - "control_id": "GA-28", - "evidence_freshness": "CURRENT_FOR_CATALOG_REVIEW", - "implementation_state": "IMPLEMENTED_INTERNAL", - "lifecycle_order": 28, - "primary_support": "VANTIO_PARTIALLY_SUPPORTS", - "product": "OPTICS", - "proof_class": "PRODUCER_TEST", - "review_date": "2026-09-28", - "runtime_state": "NOT_APPLICABLE", - "satisfaction": { - "binding_ids": [ - "EB-T4" - ], - "pass": false, - "prior_pass": "NOT_PROMOTED", - "reason": "EVIDENCE_BOUND_NOT_A_COMPLIANCE_PASS", - "staleness": { - "clears_prior_pass": false, - "reasons": [], - "stale": false - }, - "status": "BOUND_WITH_LIMITS" - }, - "supersedes": null, - "title": "Health and degradation signaling", - "verification_state": "PRODUCER_TESTED" - }, - { - "capability_version": "0.0.0-unstable-pre-1.0", - "claim_ceiling": "The adapter exists and defaults off. A configured, independently checked export is not in this tree.", - "configuration_state": "NOT_CONFIGURED", - "control_id": "GA-29", - "evidence_freshness": "CURRENT_FOR_CATALOG_REVIEW", - "implementation_state": "IMPLEMENTED_INTERNAL", - "lifecycle_order": 29, - "primary_support": "CUSTOMER_CONFIGURES", - "product": "OPTICS", - "proof_class": "PRODUCER_TEST", - "review_date": "2026-09-28", - "runtime_state": "NOT_RUNNING", - "satisfaction": { - "pass": false, - "prior_pass": "NOT_PROMOTED", - "reason": "NO_COUNTING_EVIDENCE", - "staleness": { - "clears_prior_pass": false, - "reasons": [], - "stale": false - }, - "status": "NOT_SATISFIED" - }, - "supersedes": null, - "title": "Telemetry interoperability", - "verification_state": "PRODUCER_TESTED" - }, - { - "capability_version": "0.0.0-unstable-pre-1.0", - "claim_ceiling": "This row binds a bounded fact already in the tree. It is not certification, legal conformity, or external proof.", - "configuration_state": "NOT_APPLICABLE", - "control_id": "GA-30", - "evidence_freshness": "CURRENT_FOR_CATALOG_REVIEW", - "implementation_state": "IMPLEMENTED_INTERNAL", - "lifecycle_order": 30, - "primary_support": "VANTIO_PARTIALLY_SUPPORTS", - "product": "PHANTOM_ENGINE", - "proof_class": "PRODUCER_TEST", - "review_date": "2026-09-28", - "runtime_state": "NOT_APPLICABLE", - "satisfaction": { - "binding_ids": [ - "EB-T8" - ], - "pass": false, - "prior_pass": "NOT_PROMOTED", - "reason": "EVIDENCE_BOUND_NOT_A_COMPLIANCE_PASS", - "staleness": { - "clears_prior_pass": false, - "reasons": [], - "stale": false - }, - "status": "BOUND_WITH_LIMITS" - }, - "supersedes": null, - "title": "Sequential and aggregate evaluation", - "verification_state": "PRODUCER_TESTED" - }, - { - "capability_version": "0.0.0-unstable-pre-1.0", - "claim_ceiling": "This row binds a bounded fact already in the tree. It is not certification, legal conformity, or external proof.", - "configuration_state": "NOT_APPLICABLE", - "control_id": "GA-31", - "evidence_freshness": "CURRENT_FOR_CATALOG_REVIEW", - "implementation_state": "IMPLEMENTED_INTERNAL", - "lifecycle_order": 31, - "primary_support": "VANTIO_PARTIALLY_SUPPORTS", - "product": "PHANTOM_ENGINE", - "proof_class": "PRODUCER_TEST", - "review_date": "2026-09-28", - "runtime_state": "NOT_APPLICABLE", - "satisfaction": { - "binding_ids": [ - "EB-T9" - ], - "pass": false, - "prior_pass": "NOT_PROMOTED", - "reason": "EVIDENCE_BOUND_NOT_A_COMPLIANCE_PASS", - "staleness": { - "clears_prior_pass": false, - "reasons": [], - "stale": false - }, - "status": "BOUND_WITH_LIMITS" - }, - "supersedes": null, - "title": "Progressive enforcement staging in process", - "verification_state": "PRODUCER_TESTED" - }, - { - "capability_version": "not-performed", - "claim_ceiling": "This row is not satisfied. Absence, a plan, or an in-revision track is not a pass.", - "configuration_state": "NOT_CONFIGURED", - "control_id": "GA-32", - "evidence_freshness": "UNSET", - "implementation_state": "NOT_IMPLEMENTED", - "lifecycle_order": 32, - "primary_support": "UNVERIFIED", - "product": "PHANTOM_ENGINE", - "proof_class": "NONE", - "review_date": "2026-09-28", - "runtime_state": "NOT_RUNNING", - "satisfaction": { - "pass": false, - "prior_pass": "CLEARED", - "reason": "STALE", - "staleness": { - "clears_prior_pass": true, - "reasons": [ - "EVIDENCE_UNSET" - ], - "stale": true - }, - "status": "NOT_SATISFIED" - }, - "supersedes": null, - "title": "Host-attachment proof", - "verification_state": "NOT_TESTED" - }, - { - "capability_version": "blocked", - "claim_ceiling": "This row is not satisfied. Absence, a plan, or an in-revision track is not a pass.", - "configuration_state": "NOT_CONFIGURED", - "control_id": "GA-33", - "evidence_freshness": "UNSET", - "implementation_state": "DESIGNED", - "lifecycle_order": 33, - "primary_support": "UNVERIFIED", - "product": "PHANTOM_ENGINE", - "proof_class": "BLOCKED_UNSET", - "review_date": "2026-09-28", - "runtime_state": "NOT_RUNNING", - "satisfaction": { - "pass": false, - "prior_pass": "CLEARED", - "reason": "STALE", - "staleness": { - "clears_prior_pass": true, - "reasons": [ - "EVIDENCE_UNSET" - ], - "stale": true - }, - "status": "NOT_SATISFIED" - }, - "supersedes": null, - "title": "Clean-host proof", - "verification_state": "NOT_TESTED" - }, - { - "capability_version": "readiness-only", - "claim_ceiling": "This row is not satisfied. Absence, a plan, or an in-revision track is not a pass.", - "configuration_state": "NOT_CONFIGURED", - "control_id": "GA-34", - "evidence_freshness": "CURRENT_FOR_CATALOG_REVIEW", - "implementation_state": "DESIGNED", - "lifecycle_order": 34, - "primary_support": "UNVERIFIED", - "product": "PHANTOM_ENGINE", - "proof_class": "DESIGN_RECORD", - "review_date": "2026-09-28", - "runtime_state": "NOT_RUNNING", - "satisfaction": { - "pass": false, - "prior_pass": "NOT_PROMOTED", - "reason": "NOT_A_PASS", - "staleness": { - "clears_prior_pass": false, - "reasons": [], - "stale": false - }, - "status": "NOT_SATISFIED" - }, - "supersedes": null, - "title": "Stranger-host proof", - "verification_state": "NOT_TESTED" - }, - { - "capability_version": "0.2.0-internal", - "claim_ceiling": "The named customer or third-party role holds this duty. Vantio does not discharge it.", - "configuration_state": "NOT_APPLICABLE", - "control_id": "GA-35", - "evidence_freshness": "NOT_APPLICABLE", - "implementation_state": "NOT_IMPLEMENTED", - "lifecycle_order": 35, - "primary_support": "THIRD_PARTY_REQUIRED", - "product": "GOVERNANCE_ASSURANCE", - "proof_class": "NONE", - "review_date": "2026-09-28", - "runtime_state": "NOT_APPLICABLE", - "satisfaction": { - "pass": false, - "prior_pass": "NOT_PROMOTED", - "reason": "NOT_A_PASS", - "staleness": { - "clears_prior_pass": false, - "reasons": [], - "stale": false - }, - "status": "NOT_SATISFIED" - }, - "supersedes": "0.1.0-internal", - "title": "Model-provider obligations", - "verification_state": "NOT_TESTED" - }, - { - "capability_version": "plan-only", - "claim_ceiling": "The named customer or third-party role holds this duty. Vantio does not discharge it.", - "configuration_state": "NOT_CONFIGURED", - "control_id": "GA-36", - "evidence_freshness": "CURRENT_FOR_CATALOG_REVIEW", - "implementation_state": "DESIGNED", - "lifecycle_order": 36, - "primary_support": "CUSTOMER_PROVIDES", - "product": "ENTERPRISE", - "proof_class": "DESIGN_RECORD", - "review_date": "2026-09-28", - "runtime_state": "NOT_APPLICABLE", - "satisfaction": { - "pass": false, - "prior_pass": "NOT_PROMOTED", - "reason": "NOT_A_PASS", - "staleness": { - "clears_prior_pass": false, - "reasons": [], - "stale": false - }, - "status": "NOT_SATISFIED" - }, - "supersedes": null, - "title": "Human oversight", - "verification_state": "NOT_TESTED" - }, - { - "capability_version": "0.2.0-internal", - "claim_ceiling": "The named customer or third-party role holds this duty. Vantio does not discharge it.", - "configuration_state": "NOT_APPLICABLE", - "control_id": "GA-37", - "evidence_freshness": "UNSET", - "implementation_state": "NOT_IMPLEMENTED", - "lifecycle_order": 37, - "primary_support": "CUSTOMER_PROVIDES", - "product": "GOVERNANCE_ASSURANCE", - "proof_class": "NONE", - "review_date": "2026-09-28", - "runtime_state": "NOT_APPLICABLE", - "satisfaction": { - "pass": false, - "prior_pass": "CLEARED", - "reason": "STALE", - "staleness": { - "clears_prior_pass": true, - "reasons": [ - "EVIDENCE_UNSET" - ], - "stale": true - }, - "status": "NOT_SATISFIED" - }, - "supersedes": "0.1.0-internal", - "title": "Incident evidence and legal submission", - "verification_state": "NOT_TESTED" - }, - { - "capability_version": "0.2.0-internal", - "claim_ceiling": "A private index for review. Not a submission and not an authorization to sell.", - "configuration_state": "NOT_APPLICABLE", - "control_id": "GA-38", - "evidence_freshness": "CURRENT_FOR_CATALOG_REVIEW", - "implementation_state": "IMPLEMENTED_INTERNAL", - "lifecycle_order": 38, - "primary_support": "VANTIO_PARTIALLY_SUPPORTS", - "product": "GOVERNANCE_ASSURANCE", - "proof_class": "PRODUCER_TEST", - "review_date": "2026-09-28", - "runtime_state": "NOT_APPLICABLE", - "satisfaction": { - "binding_ids": [ - "EB-PROCUREMENT" - ], - "pass": false, - "prior_pass": "NOT_PROMOTED", - "reason": "EVIDENCE_BOUND_NOT_A_COMPLIANCE_PASS", - "staleness": { - "clears_prior_pass": false, - "reasons": [], - "stale": false - }, - "status": "BOUND_WITH_LIMITS" - }, - "supersedes": "0.1.0-internal", - "title": "Procurement evidence packaging", - "verification_state": "PRODUCER_TESTED" - }, - { - "capability_version": "0.2.0-internal", - "claim_ceiling": "Vantio provides this disclosure. The disclosure does not make any system conformant.", - "configuration_state": "NOT_APPLICABLE", - "control_id": "GA-39", - "evidence_freshness": "CURRENT_FOR_CATALOG_REVIEW", - "implementation_state": "IMPLEMENTED_INTERNAL", - "lifecycle_order": 39, - "primary_support": "VANTIO_PROVIDES", - "product": "GOVERNANCE_ASSURANCE", - "proof_class": "PRODUCER_TEST", - "review_date": "2026-09-28", - "runtime_state": "NOT_APPLICABLE", - "satisfaction": { - "binding_ids": [ - "EB-ROLE" - ], - "pass": false, - "prior_pass": "NOT_PROMOTED", - "reason": "EVIDENCE_BOUND_NOT_A_COMPLIANCE_PASS", - "staleness": { - "clears_prior_pass": false, - "reasons": [], - "stale": false - }, - "status": "BOUND_WITH_LIMITS" - }, - "supersedes": "0.1.0-internal", - "title": "Claim ceiling and disclosure", - "verification_state": "PRODUCER_TESTED" - }, - { - "capability_version": "blocked", - "claim_ceiling": "This row is not satisfied. Absence, a plan, or an in-revision track is not a pass.", - "configuration_state": "NOT_CONFIGURED", - "control_id": "GA-40", - "evidence_freshness": "UNSET", - "implementation_state": "NOT_IMPLEMENTED", - "lifecycle_order": 40, - "primary_support": "UNVERIFIED", - "product": "PHANTOM_ENGINE", - "proof_class": "BLOCKED_UNSET", - "review_date": "2026-09-28", - "runtime_state": "NOT_RUNNING", - "satisfaction": { - "pass": false, - "prior_pass": "CLEARED", - "reason": "STALE", - "staleness": { - "clears_prior_pass": true, - "reasons": [ - "EVIDENCE_UNSET" - ], - "stale": true - }, - "status": "NOT_SATISFIED" - }, - "supersedes": null, - "title": "Decommissioning", - "verification_state": "NOT_TESTED" - } - ], - "counts": { - "controls": 40, - "customer_responsibility_assignments": 62, - "evidence_bindings": 25, - "external_controls": 9, - "frameworks": 6, - "mappings": 144, - "unsupported_controls": 14 - }, - "document": "GOVERNANCE_POSTURE", - "open_gates": [ - { - "from_council": "F", - "id": "GATE-F-BILLING", - "state": "OPEN", - "summary": "C2 STAGE_B_BILLING_CLOSE_PENDING. September 2026 period open. Delayed charges UNKNOWN. A billing close is required before Class B." - }, - { - "from_council": "F", - "id": "GATE-F-C8", - "state": "OPEN", - "summary": "C8 DESIGN_COMPLETE_AWAITING_FOUNDER_CREDENTIAL_OR_ROLE. Interactive destroy does not satisfy NONINTERACTIVE_TEARDOWN_READY." - }, - { - "from_council": "I", - "id": "GATE-I-RECORDINGS", - "state": "OPEN", - "summary": "Recordings A-H NOT_CAPTURED. C15 plan only. Visual and demo completeness stays open." - }, - { - "from_councils": [ - "A", - "E", - "C1" - ], - "id": "GATE-RBK004-LIVE", - "state": "OPEN_NONBLOCKING_FOR_INTEGRATION_CEILING", - "summary": "GAP-SB-RBK-004 SOURCE_CLOSED_MERGED. Live Class A residual-only re-proof is not claimed and is NOT_YET_AUTHORIZED." - }, - { - "id": "GATE-CLASS-B", - "state": "BLOCKED", - "summary": "Class B provision BLOCKED until billing close and C8 NONINTERACTIVE_TEARDOWN_READY, plus the remaining hard stops. No Paid plan. No new host until those gates clear." - } - ], - "program_bindings": { - "aws_destruction_note": "Founder close records removal of the lab instance, root volume, security group, and key pair. C5 keeps that axis visible as STAGE_B_DESTROY_PASS. Council F stays NEEDS_REVISION.", - "billing_close": "STAGE_B_BILLING_CLOSE_PENDING", - "billing_lineage": "Founder close recorded NOT_YET_FULLY_RECONCILED. C3 recorded REQUIRES_FINAL_RECONCILIATION. C5 records STAGE_B_BILLING_CLOSE_PENDING. This rebind binds the C5 token.", - "c15": "PLAN_READY_AWAITING_AUTHORIZED_LAB", - "c1_merge_sha": "b0bcbdeb01ccb84a58a3aa6aacd0c05f94b22450", - "c1_pr": 125, - "c1_state": "MERGED_SOURCE_CLOSED", - "c3_classification": "STAGE_B_EVIDENCE_CONSOLIDATION_PASS", - "c5_classification": "INTEGRATION_PASS_WITH_NONBLOCKING_AND_OPEN_GATES", - "c5_state": "CLOSED", - "c8": "DESIGN_COMPLETE_AWAITING_FOUNDER_CREDENTIAL_OR_ROLE", - "c8_ready": false, - "c8_short": "DESIGN_COMPLETE_AWAITING_FOUNDER", - "claim_ceiling": "INTERNAL_CLEAN_HOST_PROOF", - "class_b": "BLOCKED", - "clean_host_evidence_tier": "UNSET", - "clean_host_sequence": "BLOCKED_INFRA", - "council_f": "NEEDS_REVISION", - "council_i": "NEEDS_REVISION", - "council_j": "PASS_WITH_NONBLOCKING_NOTES_PREP_ONLY", - "customer_deployment": "NOT_AUTHORIZED", - "destruction": "STAGE_B_DESTROY_PASS", - "enforcement_efficacy": "NOT_PROVED", - "enterprise": "NO_LIVE_CUSTOMER_AUTHORITY", - "frozen_pins": { - "@vantio/agent-sdk": "0.2.4", - "@vantio/cli": "0.3.24", - "vantio-agent-sdk": "3.1.0" - }, - "full_ws17_at_council_j": "DEFERRED_TO_C6", - "health": "PASS_WITH_LIMITATIONS", - "health_detail": "DEGRADED", - "installer": "VANTIO_INSTALLER_REPEATABLE_PATH_PROVED_WITH_LIMITATIONS", - "installer_not_yet": "VANTIO_INSTALLER_INTERNAL_CUSTOMER_CANDIDATE", - "installer_proof": "TRANSACTIONAL_OBSERVE_ONLY_PATH_PROVED_WITH_LIMITATIONS", - "live_reproof_claimed": false, - "marketing_announcement": "HOLD", - "next_lab": "NOT_YET_AUTHORIZED", - "noninteractive_teardown_ready": false, - "o7": "INTERNAL_CLEAN_HOST_INITIALIZATION_PROOF", - "o7_enforcement": "NOT_ENABLED", - "optics": "INTERNAL_CLEAN_HOST_INSTALLATION_PROOF", - "pe_customer_portability_tip": "fab81efc08110506ff90847495197e7051a253b5", - "pe_sealed_archive_sha256": "72719cf4c590805378188da38a0d43c540e6722328268bde3955f07d2c3a9128", - "phantom_engine": "INTERNAL_CLEAN_HOST_OBSERVE_ONLY_PROOF", - "proof_state": "PARTIAL_NOT_FULL_EFFICACY", - "public_publication": "HOLD", - "public_rewrite": "HOLD", - "qualifies_for_0_3_0": false, - "qualifies_for_0_4_0": false, - "qualifies_for_customer_candidate": false, - "rbk_001_002": "CLOSED_LIVE_PASS", - "rbk_004": "SOURCE_CLOSED_MERGED", - "rbk_004_live_class_a_reproof": "NOT_YET_AUTHORIZED", - "recordings_a_h": "NOT_CAPTURED", - "repeatability": "NOT_YET_PROVED", - "residual_only_path": "SOURCE_CLOSED_AWAITING_LIVE_REPROOF", - "stage_b": "PARTIAL_INTERNAL_CLEAN_HOST_PROOF", - "stranger_host": "NOT_AUTHORIZED_WITHOUT_NAMED_ENVIRONMENT_AND_OPERATOR", - "uninstall": "LIVE_REMOVAL_AND_BPF_UNPIN_PROOF", - "wave2_egress": "MERGED_CONTRACT_ONLY_HOST_NETWORK_NOT_EXECUTED", - "wave2_ingress": "MERGED_OBSERVE_ONLY_LOADER_UNTOUCHED", - "wave2_unit_e": "MERGED_NO_LIVE_INTEGRATION" - }, - "prohibited_interpretations": [ - "Do not treat this packet as a compliance percentage or an overall score.", - "Do not treat a missing, planned, or in-revision capability as a pass.", - "Do not promote producer tests, internal packages, or a demo into external proof.", - "Do not treat a dashboard, an HTTP 200, process existence, exit 0, or a generated report as sole proof.", - "Do not treat the producer as the independent verifier.", - "Do not assign legal classification, conformity, registration, or incident submission to Vantio by default.", - "Do not read a framework crosswalk as certification, regulator approval, or a statement that Vantio fulfills the framework.", - "Do not treat the Python 3.1.0 release-close as runtime observation or as observation evidence capture.", - "Do not treat a package version file as proof that credentials are not collected.", - "Do not treat PARTIAL_INTERNAL_CLEAN_HOST_PROOF as full efficacy, as 0.3.0, or as a customer candidate.", - "Do not treat SOURCE_CLOSED_MERGED on RBK-004 as a live Class A residual-only re-proof.", - "Do not treat STAGE_B_DESTROY_PASS as a billing close, as C8 readiness, or as Council F acceptance.", - "Do not treat NOT_CAPTURED recordings as captured demonstrations.", - "Do not treat an integration record that names open gates as a clean result with those gates removed." - ], - "provenance": { - "audience": "INTERNAL_RESTRICTED", - "catalog_version": "0.2.0-internal", - "council_status": "PENDING_INDEPENDENT_COUNCIL", - "distribution": "INTERNAL_RESTRICTED", - "generated_at": "2026-09-28T17:26:43Z", - "generator": "@vantio/governance-assurance", - "mapping_commit": "NOT_SELF_HASHED", - "mapping_version": "0.2.0-internal", - "package_name": "@vantio/governance-assurance", - "package_version": "0.2.0-internal", - "producer_classification": "WS17_GOVERNANCE_ASSURANCE_0_2_0_INTERNAL_REBIND_READY_FOR_COUNCIL", - "program_claim_ceiling": "INTERNAL_CLEAN_HOST_PROOF", - "retrieved_at": "2026-09-28T17:26:43Z", - "reviewer": "PENDING_INDEPENDENT_COUNCIL", - "self_certified_council_pass": false, - "source_base_commit": "b0bcbdeb01ccb84a58a3aa6aacd0c05f94b22450", - "source_repository": "vantioai/vantio-open-core", - "supersedes_package": "0.1.0-internal" - }, - "rebind_not_claimed": [ - "0.3.0", - "0.4.0", - "1.0.0-customer-candidate", - "VANTIO_INSTALLER_INTERNAL_CUSTOMER_CANDIDATE", - "enforcement efficacy proved", - "recordings captured", - "billing close pass", - "C8 NONINTERACTIVE_TEARDOWN_READY", - "live Class A residual-only RBK-004 re-proof", - "Class B or stranger-host or customer deploy authorized", - "PUBLIC_REWRITE or announcement or publish", - "claim ceiling above INTERNAL_CLEAN_HOST_PROOF", - "a clean integration result that hides Council F or Council I", - "WS17 council acceptance by this producer", - "claim ledger freeze (that is C7)" - ], - "refuses": [ - "overall compliance score", - "compliance percentage", - "legal conclusion", - "certification conclusion", - "regulator approval" - ], - "residuals": [ - "GAP-SB-RES-001 remains an open documentation gap on Council A. It is not one of the five C5 open gates.", - "Repeatability is NOT_YET_PROVED. One transactional observe-only install does not make a repeatable claim.", - "Uninstall plus BPF unpin on the re-apply path is not a residual-only RBK-004 live re-proof.", - "O7 initialization is an observe record with enforcement NOT_ENABLED. It is not a store authorization and not host enforcement.", - "Enterprise E1-E3 stays NO_LIVE_CUSTOMER_AUTHORITY.", - "The prior clean-host sequence stays BLOCKED_INFRA with evidence tier UNSET. Stage B partial proof does not clear it and does not qualify 0.3.0." - ], - "role_statement": "Vantio is the runtime authority, enforcement, revocation, recovery, and independently verifiable evidence layer for AI governance on customer-controlled Linux infrastructure. Vantio supports governance programs; Vantio does not independently make an AI system lawful, compliant, certified, regulator-approved, unbiased, appropriate for a regulated use, safe for every environment, or conformant with every framework.", - "schema": "vantio.governance-assurance.posture/v1", - "state_separation": { - "capability": [ - "NOT_IMPLEMENTED", - "DESIGNED", - "IMPLEMENTED_INERT", - "IMPLEMENTED_INTERNAL", - "INTEGRATED", - "AVAILABLE" - ], - "configuration": [ - "NOT_CONFIGURED", - "CONFIGURED", - "MISCONFIGURED", - "UNKNOWN", - "NOT_APPLICABLE" - ], - "runtime": [ - "NOT_RUNNING", - "OBSERVING", - "ENFORCING", - "DEGRADED", - "STALE", - "DISCONNECTED", - "UNKNOWN", - "NOT_APPLICABLE" - ], - "verification": [ - "NOT_TESTED", - "PRODUCER_TESTED", - "INDEPENDENTLY_TESTED", - "CLEAN_HOST_INTERNAL_PROOF", - "PROVED_EXTERNAL", - "CUSTOMER_VALIDATED", - "EXTERNALLY_ASSESSED" - ] - }, - "support_classes": [ - "VANTIO_PROVIDES", - "VANTIO_PARTIALLY_SUPPORTS", - "CUSTOMER_CONFIGURES", - "CUSTOMER_PROVIDES", - "THIRD_PARTY_REQUIRED", - "NOT_APPLICABLE", - "NOT_IMPLEMENTED", - "UNVERIFIED" - ], - "wave2": [ - { - "binding_id": "EB-T1", - "count_control_ids": [ - "GA-20" - ], - "counts_toward_satisfaction": true, - "freshness": "CURRENT_FOR_CATALOG_REVIEW", - "independent_verifier": "UNSET", - "proof_class": "RELEASE_CLOSE_PACKET", - "track_id": "T1", - "verification_result": "REGISTRY_HASHES_MATCH_AUTHORIZED_PINS_CLIENT_NOT_REEXECUTED", - "wave2_state": "RELEASE_CLOSED_REGISTRY_VERIFIED" - }, - { - "binding_id": "EB-T3", - "count_control_ids": [], - "counts_toward_satisfaction": false, - "freshness": "UNSET", - "independent_verifier": "UNSET", - "proof_class": "DESIGN_RECORD", - "track_id": "T3", - "verification_result": "O7_NOT_AUTHORIZED_DECISION_9_UNRESOLVED_BLOCKED_NODE", - "wave2_state": "NOT_IMPLEMENTED_UNVERIFIED_BLOCKED_NODE" - }, - { - "binding_id": "EB-T4", - "count_control_ids": [ - "GA-28" - ], - "counts_toward_satisfaction": true, - "freshness": "CURRENT_FOR_CATALOG_REVIEW", - "independent_verifier": "UNSET", - "proof_class": "PRODUCER_TEST", - "track_id": "T4", - "verification_result": "IMPLEMENTED_INTERNAL_GREEN_FALSE_NO_PE_INTEGRATION", - "wave2_state": "IMPLEMENTED_INTERNAL" - }, - { - "binding_id": "EB-T5", - "count_control_ids": [], - "counts_toward_satisfaction": false, - "freshness": "CURRENT_FOR_CATALOG_REVIEW", - "independent_verifier": "UNSET", - "proof_class": "DESIGN_RECORD", - "track_id": "T5", - "verification_result": "MERGED_OBSERVE_ONLY_NOT_COUNTED", - "wave2_state": "MERGED_OBSERVE_ONLY_LOADER_UNTOUCHED" - }, - { - "binding_id": "EB-T6", - "count_control_ids": [], - "counts_toward_satisfaction": false, - "freshness": "CURRENT_FOR_CATALOG_REVIEW", - "independent_verifier": "UNSET", - "proof_class": "DESIGN_RECORD", - "track_id": "T6", - "verification_result": "MERGED_CONTRACT_ONLY_NOT_COUNTED", - "wave2_state": "MERGED_CONTRACT_ONLY_HOST_NETWORK_NOT_EXECUTED" - }, - { - "binding_id": "EB-T7", - "count_control_ids": [], - "counts_toward_satisfaction": false, - "freshness": "CURRENT_FOR_CATALOG_REVIEW", - "independent_verifier": "UNSET", - "proof_class": "CONTRACT_EVALUATION", - "track_id": "T7", - "verification_result": "CONTRACT_ONLY_KERNEL_NOT_EXECUTED", - "wave2_state": "CONTRACT_ONLY" - }, - { - "binding_id": "EB-T8", - "count_control_ids": [ - "GA-17", - "GA-30" - ], - "counts_toward_satisfaction": true, - "freshness": "CURRENT_FOR_CATALOG_REVIEW", - "independent_verifier": "UNSET", - "proof_class": "PRODUCER_TEST", - "track_id": "T8", - "verification_result": "EVALUATE_ONLY_HOST_ATTACHMENT_FALSE", - "wave2_state": "MERGED_EVALUATE_ONLY_HOST_ATTACHMENT_FALSE" - }, - { - "binding_id": "EB-T9", - "count_control_ids": [ - "GA-31" - ], - "counts_toward_satisfaction": true, - "freshness": "CURRENT_FOR_CATALOG_REVIEW", - "independent_verifier": "UNSET", - "proof_class": "PRODUCER_TEST", - "track_id": "T9", - "verification_result": "IN_PROCESS_HOST_ATTACHMENT_NOT_PERFORMED", - "wave2_state": "MERGED_IN_PROCESS_HOST_ATTACHMENT_NOT_PERFORMED" - }, - { - "binding_id": "EB-T10", - "count_control_ids": [], - "counts_toward_satisfaction": false, - "freshness": "UNSET", - "independent_verifier": "UNSET", - "proof_class": "BLOCKED_UNSET", - "track_id": "T10", - "verification_result": "BLOCKED_INFRA_EVIDENCE_UNSET", - "wave2_state": "BLOCKED_INFRA" - }, - { - "binding_id": "EB-T11", - "count_control_ids": [], - "counts_toward_satisfaction": false, - "freshness": "NOT_APPLICABLE", - "independent_verifier": "UNSET", - "proof_class": "NOT_COMPLIANCE_ELIGIBLE", - "track_id": "T11", - "verification_result": "NOT_COMPLIANCE_PROOF", - "wave2_state": "DEMO_NOT_COMPLIANCE_PROOF" - }, - { - "binding_id": "EB-T12", - "count_control_ids": [], - "counts_toward_satisfaction": false, - "freshness": "CURRENT_FOR_CATALOG_REVIEW", - "independent_verifier": "UNSET", - "proof_class": "PRODUCER_TEST", - "track_id": "T12", - "verification_result": "DEFAULT_DISABLED_NOT_OPERATIONAL", - "wave2_state": "IMPLEMENTED_INTERNAL_DEFAULT_DISABLED" - }, - { - "binding_id": "EB-T13", - "count_control_ids": [], - "counts_toward_satisfaction": false, - "freshness": "CURRENT_FOR_CATALOG_REVIEW", - "independent_verifier": "UNSET", - "proof_class": "DESIGN_RECORD", - "track_id": "T13", - "verification_result": "NO_LIVE_CUSTOMER_AUTHORITY", - "wave2_state": "PLAN_ONLY_NO_LIVE_CUSTOMER_AUTHORITY" - }, - { - "binding_id": "EB-T14", - "count_control_ids": [ - "GA-02", - "GA-26" - ], - "counts_toward_satisfaction": true, - "freshness": "CURRENT_FOR_CATALOG_REVIEW", - "independent_verifier": "UNSET", - "proof_class": "CHARACTERIZATION", - "track_id": "T14", - "verification_result": "CHARACTERIZED_FORMAL_CLAIMS_NOT_CLAIMED", - "wave2_state": "CHARACTERIZED_NO_FORMAL_CERTIFICATION" - }, - { - "binding_id": "EB-T16", - "count_control_ids": [], - "counts_toward_satisfaction": false, - "freshness": "CURRENT_FOR_CATALOG_REVIEW", - "independent_verifier": "UNSET", - "proof_class": "DESIGN_RECORD", - "track_id": "T16", - "verification_result": "EXECUTION_NOT_AUTHORIZED", - "wave2_state": "READINESS_ONLY_EXECUTION_NOT_AUTHORIZED" - }, - { - "binding_id": "EB-BENCH", - "count_control_ids": [], - "counts_toward_satisfaction": false, - "freshness": "UNSET", - "independent_verifier": "UNSET", - "proof_class": "NONE", - "track_id": "BENCHMARK", - "verification_result": "NO_EVIDENCE_BACKED_CLAIM", - "wave2_state": "DESIGN_TARGET" - }, - { - "binding_id": "EB-UNIT-D", - "count_control_ids": [], - "counts_toward_satisfaction": false, - "freshness": "CURRENT_FOR_CATALOG_REVIEW", - "independent_verifier": "UNSET", - "proof_class": "PRODUCER_TEST", - "track_id": "UNIT-D", - "verification_result": "UNIT_D_PROVED_NOT_SHIPPED", - "wave2_state": "MERGED_FUTURE_CLI_NOT_SHIPPED" - }, - { - "binding_id": "EB-UNIT-E", - "count_control_ids": [], - "counts_toward_satisfaction": false, - "freshness": "CURRENT_FOR_CATALOG_REVIEW", - "independent_verifier": "UNSET", - "proof_class": "DESIGN_RECORD", - "track_id": "UNIT-E", - "verification_result": "MERGED_NO_LIVE_INTEGRATION_NOT_A_SHIPPED_WRITER", - "wave2_state": "MERGED_NO_LIVE_INTEGRATION" - }, - { - "binding_id": "EB-CLI-0324", - "count_control_ids": [ - "GA-01", - "GA-03", - "GA-12", - "GA-16", - "GA-19", - "GA-25" - ], - "counts_toward_satisfaction": true, - "freshness": "CURRENT_FOR_CATALOG_REVIEW", - "independent_verifier": "UNSET", - "proof_class": "PRODUCER_TEST", - "track_id": "CLI", - "verification_result": "FROZEN_CLI_0_3_24_UNCHANGED", - "wave2_state": "FROZEN_PUBLISHED" - }, - { - "binding_id": "EB-OPTICS-PRIVACY", - "count_control_ids": [], - "counts_toward_satisfaction": false, - "freshness": "CURRENT_FOR_CATALOG_REVIEW", - "independent_verifier": "UNSET", - "proof_class": "DESIGN_RECORD", - "track_id": "OPTICS-PRIVACY", - "verification_result": "URL_PATH_SECRET_RETAINED_NOT_REEXECUTED", - "wave2_state": "DOCUMENTED_EXCEPTION_NOT_REEXECUTED" - }, - { - "binding_id": "EB-ROLE", - "count_control_ids": [ - "GA-39" - ], - "counts_toward_satisfaction": true, - "freshness": "CURRENT_FOR_CATALOG_REVIEW", - "independent_verifier": "UNSET", - "proof_class": "PRODUCER_TEST", - "track_id": "WS17", - "verification_result": "DISCLOSURE_ONLY", - "wave2_state": "PRIVATE_MAPPING_LAYER" - }, - { - "binding_id": "EB-STALENESS", - "count_control_ids": [ - "GA-21" - ], - "counts_toward_satisfaction": true, - "freshness": "CURRENT_FOR_CATALOG_REVIEW", - "independent_verifier": "UNSET", - "proof_class": "PRODUCER_TEST", - "track_id": "WS17", - "verification_result": "STALENESS_FUNCTION_PRESENT", - "wave2_state": "IMPLEMENTED_INTERNAL" - }, - { - "binding_id": "EB-PROCUREMENT", - "count_control_ids": [ - "GA-38" - ], - "counts_toward_satisfaction": true, - "freshness": "CURRENT_FOR_CATALOG_REVIEW", - "independent_verifier": "UNSET", - "proof_class": "PRODUCER_TEST", - "track_id": "WS17", - "verification_result": "INDEX_GENERATED_NOT_SUBMITTED", - "wave2_state": "PRIVATE_NOT_SUBMITTED" - }, - { - "binding_id": "EB-STAGE-B", - "count_control_ids": [], - "counts_toward_satisfaction": false, - "freshness": "CURRENT_FOR_CATALOG_REVIEW", - "independent_verifier": "UNSET", - "proof_class": "CHARACTERIZATION", - "track_id": "STAGE-B", - "verification_result": "PARTIAL_INTERNAL_CLEAN_HOST_PROOF", - "wave2_state": "STAGE_B_PARTIAL_CITED_NOT_REEXECUTED" - }, - { - "binding_id": "EB-C5", - "count_control_ids": [], - "counts_toward_satisfaction": false, - "freshness": "CURRENT_FOR_CATALOG_REVIEW", - "independent_verifier": "UNSET", - "proof_class": "CHARACTERIZATION", - "track_id": "C5", - "verification_result": "OPEN_GATES_VISIBLE", - "wave2_state": "C5_INTEGRATION_PASS_WITH_NONBLOCKING_AND_OPEN_GATES" - }, - { - "binding_id": "EB-WAVE2-RESIDUAL", - "count_control_ids": [], - "counts_toward_satisfaction": false, - "freshness": "CURRENT_FOR_CATALOG_REVIEW", - "independent_verifier": "UNSET", - "proof_class": "CHARACTERIZATION", - "track_id": "WAVE2-RESIDUAL", - "verification_result": "ENFORCEMENT_NOT_PROVED_RBK004_SOURCE_CLOSED_LIVE_REPROOF_NOT_CLAIMED", - "wave2_state": "WAVE2_RESIDUAL_HONESTY_UNSATISFIED" - } - ] -} diff --git a/docs/internal/governance-assurance/reports/GOVERNANCE_POSTURE.md b/docs/internal/governance-assurance/reports/GOVERNANCE_POSTURE.md deleted file mode 100644 index 694e8723..00000000 --- a/docs/internal/governance-assurance/reports/GOVERNANCE_POSTURE.md +++ /dev/null @@ -1,677 +0,0 @@ -# Governance posture - -Audience: INTERNAL_RESTRICTED - -## Provenance - -- Package: @vantio/governance-assurance 0.2.0-internal -- Catalog: 0.2.0-internal -- Mapping: 0.2.0-internal -- Mapping commit: NOT_SELF_HASHED -- Source: vantioai/vantio-open-core @ b0bcbdeb01ccb84a58a3aa6aacd0c05f94b22450 -- Reviewer: PENDING_INDEPENDENT_COUNCIL -- Council: PENDING_INDEPENDENT_COUNCIL - -## Role - -Vantio is the runtime authority, enforcement, revocation, recovery, and independently verifiable evidence layer for AI governance on customer-controlled Linux infrastructure. Vantio supports governance programs; Vantio does not independently make an AI system lawful, compliant, certified, regulator-approved, unbiased, appropriate for a regulated use, safe for every environment, or conformant with every framework. - -## Claim ceiling - -Governance Assurance 0.2.0-internal is a private mapping layer. NON-NORMATIVE. NOT_LEGAL_ADVICE. NO_COMPLIANCE_GUARANTEE. It does not certify a system, approve a procurement, classify legal risk, or convert a missing capability into a pass. It does not raise a proof class and it is not a customer candidate. - -## State separation - -Capability, configuration, runtime, and verification stay separate fields on every row. - -## Counts - -- Controls: 40 -- Frameworks: 6 -- Mappings: 144 -- Evidence bindings: 25 -- Customer responsibility assignments: 62 -- Unsupported controls: 14 -- External controls: 9 - -## Control rows - -### GA-01 AI system inventory for supported observation paths - -- Capability version: 0.3.24 -- Supersedes: none -- Review date: 2026-09-28 -- Capability: AVAILABLE -- Configuration: NOT_CONFIGURED -- Runtime: NOT_APPLICABLE -- Verification: PRODUCER_TESTED -- Support: VANTIO_PARTIALLY_SUPPORTS -- Satisfaction: BOUND_WITH_LIMITS (EVIDENCE_BOUND_NOT_A_COMPLIANCE_PASS) -- Stale: false -- Ceiling: This row binds a bounded fact already in the tree. It is not certification, legal conformity, or external proof. - -### GA-02 Component and release-surface inventory - -- Capability version: characterized -- Supersedes: none -- Review date: 2026-09-28 -- Capability: IMPLEMENTED_INTERNAL -- Configuration: NOT_APPLICABLE -- Runtime: NOT_APPLICABLE -- Verification: PRODUCER_TESTED -- Support: VANTIO_PARTIALLY_SUPPORTS -- Satisfaction: BOUND_WITH_LIMITS (EVIDENCE_BOUND_NOT_A_COMPLIANCE_PASS) -- Stale: false -- Ceiling: This row binds a bounded fact already in the tree. It is not certification, legal conformity, or external proof. - -### GA-03 Coverage gap disclosure - -- Capability version: 0.3.24 -- Supersedes: none -- Review date: 2026-09-28 -- Capability: AVAILABLE -- Configuration: NOT_APPLICABLE -- Runtime: NOT_APPLICABLE -- Verification: PRODUCER_TESTED -- Support: VANTIO_PARTIALLY_SUPPORTS -- Satisfaction: BOUND_WITH_LIMITS (EVIDENCE_BOUND_NOT_A_COMPLIANCE_PASS) -- Stale: false -- Ceiling: This row binds a bounded fact already in the tree. It is not certification, legal conformity, or external proof. - -### GA-04 Legal classification and conformity roles - -- Capability version: 0.2.0-internal -- Supersedes: 0.1.0-internal -- Review date: 2026-09-28 -- Capability: NOT_IMPLEMENTED -- Configuration: NOT_APPLICABLE -- Runtime: NOT_APPLICABLE -- Verification: NOT_TESTED -- Support: CUSTOMER_PROVIDES -- Satisfaction: NOT_SATISFIED (NOT_A_PASS) -- Stale: false -- Ceiling: The named customer or third-party role holds this duty. Vantio does not discharge it. - -### GA-05 Ownership assignment - -- Capability version: plan-only -- Supersedes: none -- Review date: 2026-09-28 -- Capability: DESIGNED -- Configuration: NOT_CONFIGURED -- Runtime: NOT_APPLICABLE -- Verification: NOT_TESTED -- Support: CUSTOMER_CONFIGURES -- Satisfaction: NOT_SATISFIED (NOT_A_PASS) -- Stale: false -- Ceiling: The named customer or third-party role holds this duty. Vantio does not discharge it. - -### GA-06 Delegated authority - -- Capability version: plan-only -- Supersedes: none -- Review date: 2026-09-28 -- Capability: DESIGNED -- Configuration: NOT_CONFIGURED -- Runtime: NOT_APPLICABLE -- Verification: NOT_TESTED -- Support: CUSTOMER_CONFIGURES -- Satisfaction: NOT_SATISFIED (NOT_A_PASS) -- Stale: false -- Ceiling: The named customer or third-party role holds this duty. Vantio does not discharge it. - -### GA-07 Approvals and dual control - -- Capability version: plan-only -- Supersedes: none -- Review date: 2026-09-28 -- Capability: DESIGNED -- Configuration: NOT_CONFIGURED -- Runtime: NOT_APPLICABLE -- Verification: NOT_TESTED -- Support: CUSTOMER_CONFIGURES -- Satisfaction: NOT_SATISFIED (NOT_A_PASS) -- Stale: false -- Ceiling: The named customer or third-party role holds this duty. Vantio does not discharge it. - -### GA-08 Exception handling - -- Capability version: absent -- Supersedes: none -- Review date: 2026-09-28 -- Capability: NOT_IMPLEMENTED -- Configuration: NOT_CONFIGURED -- Runtime: NOT_APPLICABLE -- Verification: NOT_TESTED -- Support: NOT_IMPLEMENTED -- Satisfaction: NOT_SATISFIED (STALE) -- Stale: true -- Ceiling: This row is not satisfied. Absence, a plan, or an in-revision track is not a pass. - -### GA-09 Customer policy authoring - -- Capability version: absent -- Supersedes: none -- Review date: 2026-09-28 -- Capability: NOT_IMPLEMENTED -- Configuration: NOT_CONFIGURED -- Runtime: NOT_APPLICABLE -- Verification: NOT_TESTED -- Support: NOT_IMPLEMENTED -- Satisfaction: NOT_SATISFIED (STALE) -- Stale: true -- Ceiling: This row is not satisfied. Absence, a plan, or an in-revision track is not a pass. - -### GA-10 Host policy configuration - -- Capability version: not-in-this-tree -- Supersedes: none -- Review date: 2026-09-28 -- Capability: NOT_IMPLEMENTED -- Configuration: NOT_CONFIGURED -- Runtime: NOT_RUNNING -- Verification: NOT_TESTED -- Support: UNVERIFIED -- Satisfaction: NOT_SATISFIED (STALE) -- Stale: true -- Ceiling: This row is not satisfied. Absence, a plan, or an in-revision track is not a pass. - -### GA-11 Host enrollment - -- Capability version: not-in-this-tree -- Supersedes: none -- Review date: 2026-09-28 -- Capability: NOT_IMPLEMENTED -- Configuration: NOT_CONFIGURED -- Runtime: NOT_RUNNING -- Verification: NOT_TESTED -- Support: UNVERIFIED -- Satisfaction: NOT_SATISFIED (STALE) -- Stale: true -- Ceiling: This row is not satisfied. Absence, a plan, or an in-revision track is not a pass. - -### GA-12 Runtime observation of supported agent egress - -- Capability version: 0.3.24 -- Supersedes: none -- Review date: 2026-09-28 -- Capability: AVAILABLE -- Configuration: NOT_CONFIGURED -- Runtime: NOT_APPLICABLE -- Verification: PRODUCER_TESTED -- Support: VANTIO_PARTIALLY_SUPPORTS -- Satisfaction: BOUND_WITH_LIMITS (EVIDENCE_BOUND_NOT_A_COMPLIANCE_PASS) -- Stale: false -- Ceiling: This row binds a bounded fact already in the tree. It is not certification, legal conformity, or external proof. - -### GA-13 Runtime enforcement - -- Capability version: not-attached -- Supersedes: none -- Review date: 2026-09-28 -- Capability: NOT_IMPLEMENTED -- Configuration: NOT_CONFIGURED -- Runtime: NOT_RUNNING -- Verification: NOT_TESTED -- Support: UNVERIFIED -- Satisfaction: NOT_SATISFIED (STALE) -- Stale: true -- Ceiling: This row is not satisfied. Absence, a plan, or an in-revision track is not a pass. - -### GA-14 Ingress control - -- Capability version: merged-observe-only -- Supersedes: none -- Review date: 2026-09-28 -- Capability: NOT_IMPLEMENTED -- Configuration: UNKNOWN -- Runtime: UNKNOWN -- Verification: NOT_TESTED -- Support: UNVERIFIED -- Satisfaction: NOT_SATISFIED (NOT_A_PASS) -- Stale: false -- Ceiling: This row is not satisfied. The observe-only merge is not a pass. - -### GA-15 Egress enforcement - -- Capability version: merged-contract-only -- Supersedes: none -- Review date: 2026-09-28 -- Capability: NOT_IMPLEMENTED -- Configuration: UNKNOWN -- Runtime: UNKNOWN -- Verification: NOT_TESTED -- Support: UNVERIFIED -- Satisfaction: NOT_SATISFIED (NOT_A_PASS) -- Stale: false -- Ceiling: This row is not satisfied. The contract-only merge is not a pass. - -### GA-16 Process attribution on supported paths - -- Capability version: 0.3.24 -- Supersedes: none -- Review date: 2026-09-28 -- Capability: AVAILABLE -- Configuration: NOT_CONFIGURED -- Runtime: NOT_APPLICABLE -- Verification: PRODUCER_TESTED -- Support: VANTIO_PARTIALLY_SUPPORTS -- Satisfaction: BOUND_WITH_LIMITS (EVIDENCE_BOUND_NOT_A_COMPLIANCE_PASS) -- Stale: false -- Ceiling: This row binds a bounded fact already in the tree. It is not certification, legal conformity, or external proof. - -### GA-17 In-process revocation step - -- Capability version: 0.0.0-unstable-pre-1.0 -- Supersedes: none -- Review date: 2026-09-28 -- Capability: IMPLEMENTED_INTERNAL -- Configuration: NOT_APPLICABLE -- Runtime: NOT_APPLICABLE -- Verification: PRODUCER_TESTED -- Support: VANTIO_PARTIALLY_SUPPORTS -- Satisfaction: BOUND_WITH_LIMITS (EVIDENCE_BOUND_NOT_A_COMPLIANCE_PASS) -- Stale: false -- Ceiling: This row binds a bounded fact already in the tree. It is not certification, legal conformity, or external proof. - -### GA-18 Recovery after revocation or failure - -- Capability version: absent -- Supersedes: none -- Review date: 2026-09-28 -- Capability: NOT_IMPLEMENTED -- Configuration: NOT_CONFIGURED -- Runtime: NOT_RUNNING -- Verification: NOT_TESTED -- Support: NOT_IMPLEMENTED -- Satisfaction: NOT_SATISFIED (STALE) -- Stale: true -- Ceiling: This row is not satisfied. Absence, a plan, or an in-revision track is not a pass. - -### GA-19 Evidence capture for supported observation - -- Capability version: cli 0.3.24 / unit D private / unit E not live -- Supersedes: none -- Review date: 2026-09-28 -- Capability: AVAILABLE -- Configuration: NOT_CONFIGURED -- Runtime: NOT_APPLICABLE -- Verification: PRODUCER_TESTED -- Support: VANTIO_PARTIALLY_SUPPORTS -- Satisfaction: BOUND_WITH_LIMITS (EVIDENCE_BOUND_NOT_A_COMPLIANCE_PASS) -- Stale: false -- Ceiling: This row binds a bounded fact already in the tree. It is not certification, legal conformity, or external proof. - -### GA-20 Evidence custody for the closed Python release - -- Capability version: 3.1.0 -- Supersedes: none -- Review date: 2026-09-28 -- Capability: IMPLEMENTED_INTERNAL -- Configuration: NOT_APPLICABLE -- Runtime: NOT_APPLICABLE -- Verification: PRODUCER_TESTED -- Support: VANTIO_PARTIALLY_SUPPORTS -- Satisfaction: BOUND_WITH_LIMITS (EVIDENCE_BOUND_NOT_A_COMPLIANCE_PASS) -- Stale: false -- Ceiling: This row binds a bounded fact already in the tree. It is not certification, legal conformity, or external proof. - -### GA-21 Evidence freshness and staleness - -- Capability version: 0.2.0-internal -- Supersedes: 0.1.0-internal -- Review date: 2026-09-28 -- Capability: IMPLEMENTED_INTERNAL -- Configuration: NOT_APPLICABLE -- Runtime: NOT_APPLICABLE -- Verification: PRODUCER_TESTED -- Support: VANTIO_PARTIALLY_SUPPORTS -- Satisfaction: BOUND_WITH_LIMITS (EVIDENCE_BOUND_NOT_A_COMPLIANCE_PASS) -- Stale: false -- Ceiling: This row binds a bounded fact already in the tree. It is not certification, legal conformity, or external proof. - -### GA-22 Independent verification - -- Capability version: 0.2.0-internal -- Supersedes: 0.1.0-internal -- Review date: 2026-09-28 -- Capability: NOT_IMPLEMENTED -- Configuration: NOT_APPLICABLE -- Runtime: NOT_APPLICABLE -- Verification: NOT_TESTED -- Support: NOT_IMPLEMENTED -- Satisfaction: NOT_SATISFIED (STALE) -- Stale: true -- Ceiling: This row is not satisfied. Absence, a plan, or an in-revision track is not a pass. - -### GA-23 Customer-controlled infrastructure boundary - -- Capability version: statement-only -- Supersedes: none -- Review date: 2026-09-28 -- Capability: NOT_IMPLEMENTED -- Configuration: NOT_APPLICABLE -- Runtime: NOT_APPLICABLE -- Verification: NOT_TESTED -- Support: CUSTOMER_PROVIDES -- Satisfaction: NOT_SATISFIED (NOT_A_PASS) -- Stale: false -- Ceiling: The named customer or third-party role holds this duty. Vantio does not discharge it. - -### GA-24 Credential and secret non-collection on supported paths - -- Capability version: 0.3.24 -- Supersedes: none -- Review date: 2026-09-28 -- Capability: AVAILABLE -- Configuration: NOT_APPLICABLE -- Runtime: NOT_APPLICABLE -- Verification: NOT_TESTED -- Support: VANTIO_PARTIALLY_SUPPORTS -- Satisfaction: NOT_SATISFIED (NO_COUNTING_EVIDENCE) -- Stale: false -- Ceiling: Partial. A secret placed in the URL path is stored because the path is kept. The CLI version file does not prove non-collection. This row is not certification, legal conformity, or external proof. - -### GA-25 Content non-retention on supported paths - -- Capability version: 0.3.24 -- Supersedes: none -- Review date: 2026-09-28 -- Capability: AVAILABLE -- Configuration: NOT_APPLICABLE -- Runtime: NOT_APPLICABLE -- Verification: PRODUCER_TESTED -- Support: VANTIO_PARTIALLY_SUPPORTS -- Satisfaction: BOUND_WITH_LIMITS (EVIDENCE_BOUND_NOT_A_COMPLIANCE_PASS) -- Stale: false -- Ceiling: This row binds a bounded fact already in the tree. It is not certification, legal conformity, or external proof. - -### GA-26 Change and release characterization - -- Capability version: characterized -- Supersedes: none -- Review date: 2026-09-28 -- Capability: IMPLEMENTED_INTERNAL -- Configuration: NOT_APPLICABLE -- Runtime: NOT_APPLICABLE -- Verification: PRODUCER_TESTED -- Support: VANTIO_PARTIALLY_SUPPORTS -- Satisfaction: BOUND_WITH_LIMITS (EVIDENCE_BOUND_NOT_A_COMPLIANCE_PASS) -- Stale: false -- Ceiling: This row binds a bounded fact already in the tree. It is not certification, legal conformity, or external proof. - -### GA-27 Rollback and uninstall proof - -- Capability version: blocked -- Supersedes: none -- Review date: 2026-09-28 -- Capability: NOT_IMPLEMENTED -- Configuration: NOT_CONFIGURED -- Runtime: NOT_RUNNING -- Verification: NOT_TESTED -- Support: UNVERIFIED -- Satisfaction: NOT_SATISFIED (STALE) -- Stale: true -- Ceiling: This row is not satisfied. Absence, a plan, or an in-revision track is not a pass. - -### GA-28 Health and degradation signaling - -- Capability version: 0.0.0-unstable-pre-1.0 -- Supersedes: none -- Review date: 2026-09-28 -- Capability: IMPLEMENTED_INTERNAL -- Configuration: NOT_APPLICABLE -- Runtime: NOT_APPLICABLE -- Verification: PRODUCER_TESTED -- Support: VANTIO_PARTIALLY_SUPPORTS -- Satisfaction: BOUND_WITH_LIMITS (EVIDENCE_BOUND_NOT_A_COMPLIANCE_PASS) -- Stale: false -- Ceiling: This row binds a bounded fact already in the tree. It is not certification, legal conformity, or external proof. - -### GA-29 Telemetry interoperability - -- Capability version: 0.0.0-unstable-pre-1.0 -- Supersedes: none -- Review date: 2026-09-28 -- Capability: IMPLEMENTED_INTERNAL -- Configuration: NOT_CONFIGURED -- Runtime: NOT_RUNNING -- Verification: PRODUCER_TESTED -- Support: CUSTOMER_CONFIGURES -- Satisfaction: NOT_SATISFIED (NO_COUNTING_EVIDENCE) -- Stale: false -- Ceiling: The adapter exists and defaults off. A configured, independently checked export is not in this tree. - -### GA-30 Sequential and aggregate evaluation - -- Capability version: 0.0.0-unstable-pre-1.0 -- Supersedes: none -- Review date: 2026-09-28 -- Capability: IMPLEMENTED_INTERNAL -- Configuration: NOT_APPLICABLE -- Runtime: NOT_APPLICABLE -- Verification: PRODUCER_TESTED -- Support: VANTIO_PARTIALLY_SUPPORTS -- Satisfaction: BOUND_WITH_LIMITS (EVIDENCE_BOUND_NOT_A_COMPLIANCE_PASS) -- Stale: false -- Ceiling: This row binds a bounded fact already in the tree. It is not certification, legal conformity, or external proof. - -### GA-31 Progressive enforcement staging in process - -- Capability version: 0.0.0-unstable-pre-1.0 -- Supersedes: none -- Review date: 2026-09-28 -- Capability: IMPLEMENTED_INTERNAL -- Configuration: NOT_APPLICABLE -- Runtime: NOT_APPLICABLE -- Verification: PRODUCER_TESTED -- Support: VANTIO_PARTIALLY_SUPPORTS -- Satisfaction: BOUND_WITH_LIMITS (EVIDENCE_BOUND_NOT_A_COMPLIANCE_PASS) -- Stale: false -- Ceiling: This row binds a bounded fact already in the tree. It is not certification, legal conformity, or external proof. - -### GA-32 Host-attachment proof - -- Capability version: not-performed -- Supersedes: none -- Review date: 2026-09-28 -- Capability: NOT_IMPLEMENTED -- Configuration: NOT_CONFIGURED -- Runtime: NOT_RUNNING -- Verification: NOT_TESTED -- Support: UNVERIFIED -- Satisfaction: NOT_SATISFIED (STALE) -- Stale: true -- Ceiling: This row is not satisfied. Absence, a plan, or an in-revision track is not a pass. - -### GA-33 Clean-host proof - -- Capability version: blocked -- Supersedes: none -- Review date: 2026-09-28 -- Capability: DESIGNED -- Configuration: NOT_CONFIGURED -- Runtime: NOT_RUNNING -- Verification: NOT_TESTED -- Support: UNVERIFIED -- Satisfaction: NOT_SATISFIED (STALE) -- Stale: true -- Ceiling: This row is not satisfied. Absence, a plan, or an in-revision track is not a pass. - -### GA-34 Stranger-host proof - -- Capability version: readiness-only -- Supersedes: none -- Review date: 2026-09-28 -- Capability: DESIGNED -- Configuration: NOT_CONFIGURED -- Runtime: NOT_RUNNING -- Verification: NOT_TESTED -- Support: UNVERIFIED -- Satisfaction: NOT_SATISFIED (NOT_A_PASS) -- Stale: false -- Ceiling: This row is not satisfied. Absence, a plan, or an in-revision track is not a pass. - -### GA-35 Model-provider obligations - -- Capability version: 0.2.0-internal -- Supersedes: 0.1.0-internal -- Review date: 2026-09-28 -- Capability: NOT_IMPLEMENTED -- Configuration: NOT_APPLICABLE -- Runtime: NOT_APPLICABLE -- Verification: NOT_TESTED -- Support: THIRD_PARTY_REQUIRED -- Satisfaction: NOT_SATISFIED (NOT_A_PASS) -- Stale: false -- Ceiling: The named customer or third-party role holds this duty. Vantio does not discharge it. - -### GA-36 Human oversight - -- Capability version: plan-only -- Supersedes: none -- Review date: 2026-09-28 -- Capability: DESIGNED -- Configuration: NOT_CONFIGURED -- Runtime: NOT_APPLICABLE -- Verification: NOT_TESTED -- Support: CUSTOMER_PROVIDES -- Satisfaction: NOT_SATISFIED (NOT_A_PASS) -- Stale: false -- Ceiling: The named customer or third-party role holds this duty. Vantio does not discharge it. - -### GA-37 Incident evidence and legal submission - -- Capability version: 0.2.0-internal -- Supersedes: 0.1.0-internal -- Review date: 2026-09-28 -- Capability: NOT_IMPLEMENTED -- Configuration: NOT_APPLICABLE -- Runtime: NOT_APPLICABLE -- Verification: NOT_TESTED -- Support: CUSTOMER_PROVIDES -- Satisfaction: NOT_SATISFIED (STALE) -- Stale: true -- Ceiling: The named customer or third-party role holds this duty. Vantio does not discharge it. - -### GA-38 Procurement evidence packaging - -- Capability version: 0.2.0-internal -- Supersedes: 0.1.0-internal -- Review date: 2026-09-28 -- Capability: IMPLEMENTED_INTERNAL -- Configuration: NOT_APPLICABLE -- Runtime: NOT_APPLICABLE -- Verification: PRODUCER_TESTED -- Support: VANTIO_PARTIALLY_SUPPORTS -- Satisfaction: BOUND_WITH_LIMITS (EVIDENCE_BOUND_NOT_A_COMPLIANCE_PASS) -- Stale: false -- Ceiling: A private index for review. Not a submission and not an authorization to sell. - -### GA-39 Claim ceiling and disclosure - -- Capability version: 0.2.0-internal -- Supersedes: 0.1.0-internal -- Review date: 2026-09-28 -- Capability: IMPLEMENTED_INTERNAL -- Configuration: NOT_APPLICABLE -- Runtime: NOT_APPLICABLE -- Verification: PRODUCER_TESTED -- Support: VANTIO_PROVIDES -- Satisfaction: BOUND_WITH_LIMITS (EVIDENCE_BOUND_NOT_A_COMPLIANCE_PASS) -- Stale: false -- Ceiling: Vantio provides this disclosure. The disclosure does not make any system conformant. - -### GA-40 Decommissioning - -- Capability version: blocked -- Supersedes: none -- Review date: 2026-09-28 -- Capability: NOT_IMPLEMENTED -- Configuration: NOT_CONFIGURED -- Runtime: NOT_RUNNING -- Verification: NOT_TESTED -- Support: UNVERIFIED -- Satisfaction: NOT_SATISFIED (STALE) -- Stale: true -- Ceiling: This row is not satisfied. Absence, a plan, or an in-revision track is not a pass. - -## Program bindings - -- Stage B: PARTIAL_INTERNAL_CLEAN_HOST_PROOF -- Installer: VANTIO_INSTALLER_REPEATABLE_PATH_PROVED_WITH_LIMITATIONS -- Claim ceiling: INTERNAL_CLEAN_HOST_PROOF -- RBK-004: SOURCE_CLOSED_MERGED -- Live Class A re-proof: NOT_YET_AUTHORIZED -- Billing: STAGE_B_BILLING_CLOSE_PENDING (NEEDS_REVISION) -- Recordings A-H: NOT_CAPTURED (NEEDS_REVISION) -- Enforcement efficacy: NOT_PROVED -- C8: DESIGN_COMPLETE_AWAITING_FOUNDER_CREDENTIAL_OR_ROLE -- Class B: BLOCKED -- Next lab: NOT_YET_AUTHORIZED -- Public rewrite: HOLD -- Destruction: STAGE_B_DESTROY_PASS - -## Open gates - -- GATE-F-BILLING OPEN: C2 STAGE_B_BILLING_CLOSE_PENDING. September 2026 period open. Delayed charges UNKNOWN. A billing close is required before Class B. -- GATE-F-C8 OPEN: C8 DESIGN_COMPLETE_AWAITING_FOUNDER_CREDENTIAL_OR_ROLE. Interactive destroy does not satisfy NONINTERACTIVE_TEARDOWN_READY. -- GATE-I-RECORDINGS OPEN: Recordings A-H NOT_CAPTURED. C15 plan only. Visual and demo completeness stays open. -- GATE-RBK004-LIVE OPEN_NONBLOCKING_FOR_INTEGRATION_CEILING: GAP-SB-RBK-004 SOURCE_CLOSED_MERGED. Live Class A residual-only re-proof is not claimed and is NOT_YET_AUTHORIZED. -- GATE-CLASS-B BLOCKED: Class B provision BLOCKED until billing close and C8 NONINTERACTIVE_TEARDOWN_READY, plus the remaining hard stops. No Paid plan. No new host until those gates clear. - -## Residuals - -- GAP-SB-RES-001 remains an open documentation gap on Council A. It is not one of the five C5 open gates. -- Repeatability is NOT_YET_PROVED. One transactional observe-only install does not make a repeatable claim. -- Uninstall plus BPF unpin on the re-apply path is not a residual-only RBK-004 live re-proof. -- O7 initialization is an observe record with enforcement NOT_ENABLED. It is not a store authorization and not host enforcement. -- Enterprise E1-E3 stays NO_LIVE_CUSTOMER_AUTHORITY. -- The prior clean-host sequence stays BLOCKED_INFRA with evidence tier UNSET. Stage B partial proof does not clear it and does not qualify 0.3.0. - -## Wave 2 bindings - -- T1 EB-T1: RELEASE_CLOSED_REGISTRY_VERIFIED / REGISTRY_HASHES_MATCH_AUTHORIZED_PINS_CLIENT_NOT_REEXECUTED -- T3 EB-T3: NOT_IMPLEMENTED_UNVERIFIED_BLOCKED_NODE / O7_NOT_AUTHORIZED_DECISION_9_UNRESOLVED_BLOCKED_NODE -- T4 EB-T4: IMPLEMENTED_INTERNAL / IMPLEMENTED_INTERNAL_GREEN_FALSE_NO_PE_INTEGRATION -- T5 EB-T5: MERGED_OBSERVE_ONLY_LOADER_UNTOUCHED / MERGED_OBSERVE_ONLY_NOT_COUNTED -- T6 EB-T6: MERGED_CONTRACT_ONLY_HOST_NETWORK_NOT_EXECUTED / MERGED_CONTRACT_ONLY_NOT_COUNTED -- T7 EB-T7: CONTRACT_ONLY / CONTRACT_ONLY_KERNEL_NOT_EXECUTED -- T8 EB-T8: MERGED_EVALUATE_ONLY_HOST_ATTACHMENT_FALSE / EVALUATE_ONLY_HOST_ATTACHMENT_FALSE -- T9 EB-T9: MERGED_IN_PROCESS_HOST_ATTACHMENT_NOT_PERFORMED / IN_PROCESS_HOST_ATTACHMENT_NOT_PERFORMED -- T10 EB-T10: BLOCKED_INFRA / BLOCKED_INFRA_EVIDENCE_UNSET -- T11 EB-T11: DEMO_NOT_COMPLIANCE_PROOF / NOT_COMPLIANCE_PROOF -- T12 EB-T12: IMPLEMENTED_INTERNAL_DEFAULT_DISABLED / DEFAULT_DISABLED_NOT_OPERATIONAL -- T13 EB-T13: PLAN_ONLY_NO_LIVE_CUSTOMER_AUTHORITY / NO_LIVE_CUSTOMER_AUTHORITY -- T14 EB-T14: CHARACTERIZED_NO_FORMAL_CERTIFICATION / CHARACTERIZED_FORMAL_CLAIMS_NOT_CLAIMED -- T16 EB-T16: READINESS_ONLY_EXECUTION_NOT_AUTHORIZED / EXECUTION_NOT_AUTHORIZED -- BENCHMARK EB-BENCH: DESIGN_TARGET / NO_EVIDENCE_BACKED_CLAIM -- UNIT-D EB-UNIT-D: MERGED_FUTURE_CLI_NOT_SHIPPED / UNIT_D_PROVED_NOT_SHIPPED -- UNIT-E EB-UNIT-E: MERGED_NO_LIVE_INTEGRATION / MERGED_NO_LIVE_INTEGRATION_NOT_A_SHIPPED_WRITER -- CLI EB-CLI-0324: FROZEN_PUBLISHED / FROZEN_CLI_0_3_24_UNCHANGED -- OPTICS-PRIVACY EB-OPTICS-PRIVACY: DOCUMENTED_EXCEPTION_NOT_REEXECUTED / URL_PATH_SECRET_RETAINED_NOT_REEXECUTED -- WS17 EB-ROLE: PRIVATE_MAPPING_LAYER / DISCLOSURE_ONLY -- WS17 EB-STALENESS: IMPLEMENTED_INTERNAL / STALENESS_FUNCTION_PRESENT -- WS17 EB-PROCUREMENT: PRIVATE_NOT_SUBMITTED / INDEX_GENERATED_NOT_SUBMITTED -- STAGE-B EB-STAGE-B: STAGE_B_PARTIAL_CITED_NOT_REEXECUTED / PARTIAL_INTERNAL_CLEAN_HOST_PROOF -- C5 EB-C5: C5_INTEGRATION_PASS_WITH_NONBLOCKING_AND_OPEN_GATES / OPEN_GATES_VISIBLE -- WAVE2-RESIDUAL EB-WAVE2-RESIDUAL: WAVE2_RESIDUAL_HONESTY_UNSATISFIED / ENFORCEMENT_NOT_PROVED_RBK004_SOURCE_CLOSED_LIVE_REPROOF_NOT_CLAIMED - -## Prohibited interpretations - -- Do not treat this packet as a compliance percentage or an overall score. -- Do not treat a missing, planned, or in-revision capability as a pass. -- Do not promote producer tests, internal packages, or a demo into external proof. -- Do not treat a dashboard, an HTTP 200, process existence, exit 0, or a generated report as sole proof. -- Do not treat the producer as the independent verifier. -- Do not assign legal classification, conformity, registration, or incident submission to Vantio by default. -- Do not read a framework crosswalk as certification, regulator approval, or a statement that Vantio fulfills the framework. -- Do not treat the Python 3.1.0 release-close as runtime observation or as observation evidence capture. -- Do not treat a package version file as proof that credentials are not collected. -- Do not treat PARTIAL_INTERNAL_CLEAN_HOST_PROOF as full efficacy, as 0.3.0, or as a customer candidate. -- Do not treat SOURCE_CLOSED_MERGED on RBK-004 as a live Class A residual-only re-proof. -- Do not treat STAGE_B_DESTROY_PASS as a billing close, as C8 readiness, or as Council F acceptance. -- Do not treat NOT_CAPTURED recordings as captured demonstrations. -- Do not treat an integration record that names open gates as a clean result with those gates removed. - -This report has no compliance score and no legal conclusion. diff --git a/docs/internal/governance-assurance/reports/PROCUREMENT_EVIDENCE_INDEX.json b/docs/internal/governance-assurance/reports/PROCUREMENT_EVIDENCE_INDEX.json deleted file mode 100644 index edb44e7f..00000000 --- a/docs/internal/governance-assurance/reports/PROCUREMENT_EVIDENCE_INDEX.json +++ /dev/null @@ -1,92 +0,0 @@ -{ - "artifacts": [ - { - "distribution": "INTERNAL_RESTRICTED", - "name": "GOVERNANCE_POSTURE.json", - "proof_class": "PRODUCER_TEST", - "proof_class_elevated": false - }, - { - "distribution": "INTERNAL_RESTRICTED", - "name": "GOVERNANCE_POSTURE.md", - "proof_class": "PRODUCER_TEST", - "proof_class_elevated": false - }, - { - "distribution": "INTERNAL_RESTRICTED", - "name": "CUSTOMER_RESPONSIBILITY_MATRIX.json", - "proof_class": "PRODUCER_TEST", - "proof_class_elevated": false - }, - { - "distribution": "INTERNAL_RESTRICTED", - "name": "CONTROL_EVIDENCE_INDEX.json", - "proof_class": "PRODUCER_TEST", - "proof_class_elevated": false - }, - { - "distribution": "INTERNAL_RESTRICTED", - "name": "FRAMEWORK_VERSION_REGISTER.json", - "proof_class": "PRODUCER_TEST", - "proof_class_elevated": false - }, - { - "distribution": "INTERNAL_RESTRICTED", - "name": "UNSUPPORTED_AND_EXTERNAL_CONTROLS.json", - "proof_class": "PRODUCER_TEST", - "proof_class_elevated": false - }, - { - "distribution": "INTERNAL_RESTRICTED", - "name": "PROCUREMENT_EVIDENCE_INDEX.json", - "proof_class": "PRODUCER_TEST", - "proof_class_elevated": false - }, - { - "distribution": "INTERNAL_RESTRICTED", - "name": "VERIFICATION_INSTRUCTIONS.md", - "proof_class": "PRODUCER_TEST", - "proof_class_elevated": false - } - ], - "claim_ceiling": "Governance Assurance 0.2.0-internal is a private mapping layer. NON-NORMATIVE. NOT_LEGAL_ADVICE. NO_COMPLIANCE_GUARANTEE. It does not certify a system, approve a procurement, classify legal risk, or convert a missing capability into a pass. It does not raise a proof class and it is not a customer candidate.", - "customer_confidential_on_public": false, - "distribution": "INTERNAL_RESTRICTED", - "distribution_classes": [ - "PUBLIC", - "INVESTOR_UNDER_NDA", - "CUSTOMER_CONFIDENTIAL", - "INTERNAL_RESTRICTED", - "ASSESSOR_CONFIDENTIAL" - ], - "document": "PROCUREMENT_EVIDENCE_INDEX", - "proof_class_elevated": false, - "provenance": { - "audience": "INTERNAL_RESTRICTED", - "catalog_version": "0.2.0-internal", - "council_status": "PENDING_INDEPENDENT_COUNCIL", - "distribution": "INTERNAL_RESTRICTED", - "generated_at": "2026-09-28T17:26:43Z", - "generator": "@vantio/governance-assurance", - "mapping_commit": "NOT_SELF_HASHED", - "mapping_version": "0.2.0-internal", - "package_name": "@vantio/governance-assurance", - "package_version": "0.2.0-internal", - "producer_classification": "WS17_GOVERNANCE_ASSURANCE_0_2_0_INTERNAL_REBIND_READY_FOR_COUNCIL", - "program_claim_ceiling": "INTERNAL_CLEAN_HOST_PROOF", - "retrieved_at": "2026-09-28T17:26:43Z", - "reviewer": "PENDING_INDEPENDENT_COUNCIL", - "self_certified_council_pass": false, - "source_base_commit": "b0bcbdeb01ccb84a58a3aa6aacd0c05f94b22450", - "source_repository": "vantioai/vantio-open-core", - "supersedes_package": "0.1.0-internal" - }, - "refuses": [ - "ATO", - "FedRAMP authorization", - "agency acceptance", - "procurement approval" - ], - "schema": "vantio.governance-assurance.procurement/v1", - "submission_status": "NOT_SUBMITTED" -} diff --git a/docs/internal/governance-assurance/reports/PUBLIC_DISCLOSURE.json b/docs/internal/governance-assurance/reports/PUBLIC_DISCLOSURE.json deleted file mode 100644 index dab2b8f4..00000000 --- a/docs/internal/governance-assurance/reports/PUBLIC_DISCLOSURE.json +++ /dev/null @@ -1,10 +0,0 @@ -{ - "claim_ceiling": "Governance Assurance 0.2.0-internal is a private mapping layer. NON-NORMATIVE. NOT_LEGAL_ADVICE. NO_COMPLIANCE_GUARANTEE. It does not certify a system, approve a procurement, classify legal risk, or convert a missing capability into a pass. It does not raise a proof class and it is not a customer candidate.", - "customer_confidential": false, - "detail": "CONTROL_DETAIL_WITHHELD", - "distribution": "PUBLIC", - "document": "GOVERNANCE_PUBLIC_DISCLOSURE", - "procurement_submitted": false, - "proof_class_elevated": false, - "role_statement": "Vantio is the runtime authority, enforcement, revocation, recovery, and independently verifiable evidence layer for AI governance on customer-controlled Linux infrastructure. Vantio supports governance programs; Vantio does not independently make an AI system lawful, compliant, certified, regulator-approved, unbiased, appropriate for a regulated use, safe for every environment, or conformant with every framework." -} diff --git a/docs/internal/governance-assurance/reports/UNSUPPORTED_AND_EXTERNAL_CONTROLS.json b/docs/internal/governance-assurance/reports/UNSUPPORTED_AND_EXTERNAL_CONTROLS.json deleted file mode 100644 index d93b3465..00000000 --- a/docs/internal/governance-assurance/reports/UNSUPPORTED_AND_EXTERNAL_CONTROLS.json +++ /dev/null @@ -1,182 +0,0 @@ -{ - "document": "UNSUPPORTED_AND_EXTERNAL_CONTROLS", - "external": [ - { - "control_id": "GA-04", - "primary_support": "CUSTOMER_PROVIDES", - "reason": "A customer or third party holds the duty. Vantio does not discharge it.", - "title": "Legal classification and conformity roles" - }, - { - "control_id": "GA-05", - "primary_support": "CUSTOMER_CONFIGURES", - "reason": "A customer or third party holds the duty. Vantio does not discharge it.", - "title": "Ownership assignment" - }, - { - "control_id": "GA-06", - "primary_support": "CUSTOMER_CONFIGURES", - "reason": "A customer or third party holds the duty. Vantio does not discharge it.", - "title": "Delegated authority" - }, - { - "control_id": "GA-07", - "primary_support": "CUSTOMER_CONFIGURES", - "reason": "A customer or third party holds the duty. Vantio does not discharge it.", - "title": "Approvals and dual control" - }, - { - "control_id": "GA-23", - "primary_support": "CUSTOMER_PROVIDES", - "reason": "A customer or third party holds the duty. Vantio does not discharge it.", - "title": "Customer-controlled infrastructure boundary" - }, - { - "control_id": "GA-29", - "primary_support": "CUSTOMER_CONFIGURES", - "reason": "A customer or third party holds the duty. Vantio does not discharge it.", - "title": "Telemetry interoperability" - }, - { - "control_id": "GA-35", - "primary_support": "THIRD_PARTY_REQUIRED", - "reason": "A customer or third party holds the duty. Vantio does not discharge it.", - "title": "Model-provider obligations" - }, - { - "control_id": "GA-36", - "primary_support": "CUSTOMER_PROVIDES", - "reason": "A customer or third party holds the duty. Vantio does not discharge it.", - "title": "Human oversight" - }, - { - "control_id": "GA-37", - "primary_support": "CUSTOMER_PROVIDES", - "reason": "A customer or third party holds the duty. Vantio does not discharge it.", - "title": "Incident evidence and legal submission" - } - ], - "external_control_count": 9, - "provenance": { - "audience": "INTERNAL_RESTRICTED", - "catalog_version": "0.2.0-internal", - "council_status": "PENDING_INDEPENDENT_COUNCIL", - "distribution": "INTERNAL_RESTRICTED", - "generated_at": "2026-09-28T17:26:43Z", - "generator": "@vantio/governance-assurance", - "mapping_commit": "NOT_SELF_HASHED", - "mapping_version": "0.2.0-internal", - "package_name": "@vantio/governance-assurance", - "package_version": "0.2.0-internal", - "producer_classification": "WS17_GOVERNANCE_ASSURANCE_0_2_0_INTERNAL_REBIND_READY_FOR_COUNCIL", - "program_claim_ceiling": "INTERNAL_CLEAN_HOST_PROOF", - "retrieved_at": "2026-09-28T17:26:43Z", - "reviewer": "PENDING_INDEPENDENT_COUNCIL", - "self_certified_council_pass": false, - "source_base_commit": "b0bcbdeb01ccb84a58a3aa6aacd0c05f94b22450", - "source_repository": "vantioai/vantio-open-core", - "supersedes_package": "0.1.0-internal" - }, - "schema": "vantio.governance-assurance.unsupported/v1", - "unsupported": [ - { - "control_id": "GA-08", - "implementation_state": "NOT_IMPLEMENTED", - "primary_support": "NOT_IMPLEMENTED", - "reason": "Unverified or not implemented. This entry is not a pass.", - "title": "Exception handling" - }, - { - "control_id": "GA-09", - "implementation_state": "NOT_IMPLEMENTED", - "primary_support": "NOT_IMPLEMENTED", - "reason": "Unverified or not implemented. This entry is not a pass.", - "title": "Customer policy authoring" - }, - { - "control_id": "GA-10", - "implementation_state": "NOT_IMPLEMENTED", - "primary_support": "UNVERIFIED", - "reason": "Unverified or not implemented. This entry is not a pass.", - "title": "Host policy configuration" - }, - { - "control_id": "GA-11", - "implementation_state": "NOT_IMPLEMENTED", - "primary_support": "UNVERIFIED", - "reason": "Unverified or not implemented. This entry is not a pass.", - "title": "Host enrollment" - }, - { - "control_id": "GA-13", - "implementation_state": "NOT_IMPLEMENTED", - "primary_support": "UNVERIFIED", - "reason": "Unverified or not implemented. This entry is not a pass.", - "title": "Runtime enforcement" - }, - { - "control_id": "GA-14", - "implementation_state": "NOT_IMPLEMENTED", - "primary_support": "UNVERIFIED", - "reason": "Unverified or not implemented. This entry is not a pass.", - "title": "Ingress control" - }, - { - "control_id": "GA-15", - "implementation_state": "NOT_IMPLEMENTED", - "primary_support": "UNVERIFIED", - "reason": "Unverified or not implemented. This entry is not a pass.", - "title": "Egress enforcement" - }, - { - "control_id": "GA-18", - "implementation_state": "NOT_IMPLEMENTED", - "primary_support": "NOT_IMPLEMENTED", - "reason": "Unverified or not implemented. This entry is not a pass.", - "title": "Recovery after revocation or failure" - }, - { - "control_id": "GA-22", - "implementation_state": "NOT_IMPLEMENTED", - "primary_support": "NOT_IMPLEMENTED", - "reason": "Unverified or not implemented. This entry is not a pass.", - "title": "Independent verification" - }, - { - "control_id": "GA-27", - "implementation_state": "NOT_IMPLEMENTED", - "primary_support": "UNVERIFIED", - "reason": "Unverified or not implemented. This entry is not a pass.", - "title": "Rollback and uninstall proof" - }, - { - "control_id": "GA-32", - "implementation_state": "NOT_IMPLEMENTED", - "primary_support": "UNVERIFIED", - "reason": "Unverified or not implemented. This entry is not a pass.", - "title": "Host-attachment proof" - }, - { - "control_id": "GA-33", - "implementation_state": "DESIGNED", - "primary_support": "UNVERIFIED", - "reason": "Unverified or not implemented. This entry is not a pass.", - "title": "Clean-host proof" - }, - { - "control_id": "GA-34", - "implementation_state": "DESIGNED", - "primary_support": "UNVERIFIED", - "reason": "Unverified or not implemented. This entry is not a pass.", - "title": "Stranger-host proof" - }, - { - "control_id": "GA-40", - "implementation_state": "NOT_IMPLEMENTED", - "primary_support": "UNVERIFIED", - "reason": "Unverified or not implemented. This entry is not a pass.", - "title": "Decommissioning" - } - ], - "unsupported_control_count": 14 -} diff --git a/docs/internal/governance-assurance/reports/VERIFICATION_INSTRUCTIONS.md b/docs/internal/governance-assurance/reports/VERIFICATION_INSTRUCTIONS.md deleted file mode 100644 index 4db2d687..00000000 --- a/docs/internal/governance-assurance/reports/VERIFICATION_INSTRUCTIONS.md +++ /dev/null @@ -1,24 +0,0 @@ -# Verification instructions - -Audience: INTERNAL_RESTRICTED - -From the repository root: - -``` -node --test tests/governance-assurance/*.test.cjs -``` - -The package is private and is not a pnpm workspace member. Do not publish it. - -A passing test run is a producer check of this catalog. It is not independent verification, not a clean-host proof, and not a stranger-host proof. - -Reviewer for the mappings is PENDING_INDEPENDENT_COUNCIL. This force does not sit that council. - -Regenerate the reports with the package `buildReports` function. The default clock is the catalog review instant, not a live wall clock. - -Version rebind: - -- 0.2.0-internal is this catalog. It rebinds citations to the Stage B accepted close and the C5 integration record. It does not grant satisfaction to ingress, egress, Unit E, enforcement, billing, recordings, Class B, or a live RBK-004 re-proof. -- 0.3.0 only after a clean-host qualification that this partial Stage B proof does not supply. BLOCKED_INFRA and an unset evidence tier do not qualify. -- 0.4.0 after stranger-host execution is authorized and completed. -- 1.0.0-customer-candidate only after external assessment, disclosure review, and a separate release council. diff --git a/docs/internal/governance-assurance/stage-b/C6-REBIND.json b/docs/internal/governance-assurance/stage-b/C6-REBIND.json deleted file mode 100644 index 6a0ce920..00000000 --- a/docs/internal/governance-assurance/stage-b/C6-REBIND.json +++ /dev/null @@ -1,185 +0,0 @@ -{ - "document": "C6-REBIND", - "audience": "INTERNAL_RESTRICTED", - "package": "@vantio/governance-assurance", - "version": "0.2.0-internal", - "supersedes_package": "0.1.0-internal", - "review_date": "2026-09-28", - "source_repository": "vantioai/vantio-open-core", - "source_base_commit": "b0bcbdeb01ccb84a58a3aa6aacd0c05f94b22450", - "reexecuted": false, - "kind": "DOCUMENTARY_CITATION", - "council_status": "PENDING_INDEPENDENT_COUNCIL", - "self_certified_council_pass": false, - "npm_publish": false, - "claim_ceiling": "INTERNAL_CLEAN_HOST_PROOF", - "not_a_customer_candidate": true, - "sources": [ - { - "document": "FOUNDER-ACCEPTED-STAGE-B-CLOSE", - "as_of_et": "2026-09-28T12:47:18-04:00", - "role": "Founder-accepted Stage B close" - }, - { - "document": "C1-STATUS", - "as_of_et": "2026-09-28T13:22:58-04:00", - "role": "GAP-SB-RBK-004 source close, PR 125" - }, - { - "document": "C3-STATUS", - "as_of_et": "2026-09-28T12:56:30-04:00", - "role": "Evidence consolidation before the C1 merge" - }, - { - "document": "C5-STATUS", - "as_of_et": "2026-09-28T13:26:43-04:00", - "role": "Integration close" - }, - { - "document": "C5-INTEGRATION-COUNCIL", - "as_of_et": "2026-09-28T13:26:43-04:00", - "role": "Integration council record" - }, - { - "document": "C5-COMPONENT-VERDICTS", - "as_of_et": "2026-09-28T13:26:43-04:00", - "role": "Component verdicts" - }, - { - "document": "COUNCIL-J-GOVERNANCE-ASSURANCE-PREP", - "as_of_et": "2026-09-28T12:59:15-04:00", - "role": "Prep only. Full WS17 deferred to C6" - } - ], - "program_bindings": { - "stage_b": "PARTIAL_INTERNAL_CLEAN_HOST_PROOF", - "installer": "VANTIO_INSTALLER_REPEATABLE_PATH_PROVED_WITH_LIMITATIONS", - "installer_not_yet": "VANTIO_INSTALLER_INTERNAL_CUSTOMER_CANDIDATE", - "claim_ceiling": "INTERNAL_CLEAN_HOST_PROOF", - "proof_state": "PARTIAL_NOT_FULL_EFFICACY", - "optics": "INTERNAL_CLEAN_HOST_INSTALLATION_PROOF", - "o7": "INTERNAL_CLEAN_HOST_INITIALIZATION_PROOF", - "o7_enforcement": "NOT_ENABLED", - "phantom_engine": "INTERNAL_CLEAN_HOST_OBSERVE_ONLY_PROOF", - "installer_proof": "TRANSACTIONAL_OBSERVE_ONLY_PATH_PROVED_WITH_LIMITATIONS", - "uninstall": "LIVE_REMOVAL_AND_BPF_UNPIN_PROOF", - "rbk_001_002": "CLOSED_LIVE_PASS", - "rbk_004": "SOURCE_CLOSED_MERGED", - "rbk_004_live_class_a_reproof": "NOT_YET_AUTHORIZED", - "live_reproof_claimed": false, - "residual_only_path": "SOURCE_CLOSED_AWAITING_LIVE_REPROOF", - "billing_close": "STAGE_B_BILLING_CLOSE_PENDING", - "council_f": "NEEDS_REVISION", - "billing_lineage": "Founder close recorded NOT_YET_FULLY_RECONCILED. C3 recorded REQUIRES_FINAL_RECONCILIATION. C5 records STAGE_B_BILLING_CLOSE_PENDING. This rebind binds the C5 token.", - "recordings_a_h": "NOT_CAPTURED", - "council_i": "NEEDS_REVISION", - "c15": "PLAN_READY_AWAITING_AUTHORIZED_LAB", - "enforcement_efficacy": "NOT_PROVED", - "repeatability": "NOT_YET_PROVED", - "c8": "DESIGN_COMPLETE_AWAITING_FOUNDER_CREDENTIAL_OR_ROLE", - "c8_short": "DESIGN_COMPLETE_AWAITING_FOUNDER", - "c8_ready": false, - "noninteractive_teardown_ready": false, - "class_b": "BLOCKED", - "next_lab": "NOT_YET_AUTHORIZED", - "stranger_host": "NOT_AUTHORIZED_WITHOUT_NAMED_ENVIRONMENT_AND_OPERATOR", - "customer_deployment": "NOT_AUTHORIZED", - "public_rewrite": "HOLD", - "public_publication": "HOLD", - "marketing_announcement": "HOLD", - "destruction": "STAGE_B_DESTROY_PASS", - "aws_destruction_note": "Founder close records removal of the lab instance, root volume, security group, and key pair. C5 keeps that axis visible as STAGE_B_DESTROY_PASS. Council F stays NEEDS_REVISION.", - "c5_classification": "INTEGRATION_PASS_WITH_NONBLOCKING_AND_OPEN_GATES", - "c5_state": "CLOSED", - "c3_classification": "STAGE_B_EVIDENCE_CONSOLIDATION_PASS", - "c1_state": "MERGED_SOURCE_CLOSED", - "c1_pr": 125, - "c1_merge_sha": "b0bcbdeb01ccb84a58a3aa6aacd0c05f94b22450", - "council_j": "PASS_WITH_NONBLOCKING_NOTES_PREP_ONLY", - "full_ws17_at_council_j": "DEFERRED_TO_C6", - "frozen_pins": { - "@vantio/cli": "0.3.24", - "@vantio/agent-sdk": "0.2.4", - "vantio-agent-sdk": "3.1.0" - }, - "pe_customer_portability_tip": "fab81efc08110506ff90847495197e7051a253b5", - "pe_sealed_archive_sha256": "72719cf4c590805378188da38a0d43c540e6722328268bde3955f07d2c3a9128", - "health": "PASS_WITH_LIMITATIONS", - "health_detail": "DEGRADED", - "wave2_ingress": "MERGED_OBSERVE_ONLY_LOADER_UNTOUCHED", - "wave2_egress": "MERGED_CONTRACT_ONLY_HOST_NETWORK_NOT_EXECUTED", - "wave2_unit_e": "MERGED_NO_LIVE_INTEGRATION", - "enterprise": "NO_LIVE_CUSTOMER_AUTHORITY", - "clean_host_sequence": "BLOCKED_INFRA", - "clean_host_evidence_tier": "UNSET", - "qualifies_for_0_3_0": false, - "qualifies_for_0_4_0": false, - "qualifies_for_customer_candidate": false - }, - "tally": { - "clean_pass": 0, - "pass_with_nonblocking_notes": 8, - "needs_revision": 2, - "blocked": 0, - "letters_pass_with_notes": ["A", "B", "C", "D", "E", "G", "H", "J"], - "letters_needs_revision": ["F", "I"], - "open_gate_letters": ["F", "I"], - "note": "J is prep-only within PASS_WITH_NONBLOCKING_NOTES. Full WS17 stays deferred until a separate council reads this 0.2.0-internal packet. This producer does not sit that council." - }, - "open_gates": [ - { - "id": "GATE-F-BILLING", - "from_council": "F", - "state": "OPEN", - "summary": "C2 STAGE_B_BILLING_CLOSE_PENDING. September 2026 period open. Delayed charges UNKNOWN. A billing close is required before Class B." - }, - { - "id": "GATE-F-C8", - "from_council": "F", - "state": "OPEN", - "summary": "C8 DESIGN_COMPLETE_AWAITING_FOUNDER_CREDENTIAL_OR_ROLE. Interactive destroy does not satisfy NONINTERACTIVE_TEARDOWN_READY." - }, - { - "id": "GATE-I-RECORDINGS", - "from_council": "I", - "state": "OPEN", - "summary": "Recordings A-H NOT_CAPTURED. C15 plan only. Visual and demo completeness stays open." - }, - { - "id": "GATE-RBK004-LIVE", - "from_councils": ["A", "E", "C1"], - "state": "OPEN_NONBLOCKING_FOR_INTEGRATION_CEILING", - "summary": "GAP-SB-RBK-004 SOURCE_CLOSED_MERGED. Live Class A residual-only re-proof is not claimed and is NOT_YET_AUTHORIZED." - }, - { - "id": "GATE-CLASS-B", - "state": "BLOCKED", - "summary": "Class B provision BLOCKED until billing close and C8 NONINTERACTIVE_TEARDOWN_READY, plus the remaining hard stops. No Paid plan. No new host until those gates clear." - } - ], - "recorded_nonblocking_residuals": [ - "GAP-SB-RES-001 remains an open documentation gap on Council A. It is not one of the five C5 open gates.", - "Repeatability is NOT_YET_PROVED. One transactional observe-only install does not make a repeatable claim.", - "Uninstall plus BPF unpin on the re-apply path is not a residual-only RBK-004 live re-proof.", - "O7 initialization is an observe record with enforcement NOT_ENABLED. It is not a store authorization and not host enforcement.", - "Enterprise E1-E3 stays NO_LIVE_CUSTOMER_AUTHORITY.", - "The prior clean-host sequence stays BLOCKED_INFRA with evidence tier UNSET. Stage B partial proof does not clear it and does not qualify 0.3.0." - ], - "not_claimed": [ - "0.3.0", - "0.4.0", - "1.0.0-customer-candidate", - "VANTIO_INSTALLER_INTERNAL_CUSTOMER_CANDIDATE", - "enforcement efficacy proved", - "recordings captured", - "billing close pass", - "C8 NONINTERACTIVE_TEARDOWN_READY", - "live Class A residual-only RBK-004 re-proof", - "Class B or stranger-host or customer deploy authorized", - "PUBLIC_REWRITE or announcement or publish", - "claim ceiling above INTERNAL_CLEAN_HOST_PROOF", - "a clean integration result that hides Council F or Council I", - "WS17 council acceptance by this producer", - "claim ledger freeze (that is C7)" - ] -} diff --git a/docs/internal/governance-assurance/views/eu-ai-act.md b/docs/internal/governance-assurance/views/eu-ai-act.md deleted file mode 100644 index a7f38cde..00000000 --- a/docs/internal/governance-assurance/views/eu-ai-act.md +++ /dev/null @@ -1,21 +0,0 @@ -# EU-AI-ACT 2024/1689 - -Audience: INTERNAL_RESTRICTED - -Vantio does not fulfill this framework. Rows are crosswalks. - -Status: CURRENT. Active: true. - -- MAP-EU-GA-01-Art11 GA-01 Art. 11: Technical documentation support is limited to metadata the product actually records. This is not the legal technical file. -- MAP-EU-GA-04-Art6 GA-04 Art. 6: Risk classification stays with the customer and counsel. This row does not classify any system. -- MAP-EU-GA-04-Art27 GA-04 Art. 27: Fundamental-rights assessment stays with the customer and counsel. -- MAP-EU-GA-04-Art43 GA-04 Art. 43: Conformity assessment is excluded from Vantio. No notified-body role is claimed. -- MAP-EU-GA-04-Art49 GA-04 Art. 49: Registration is a customer and counsel duty. Vantio does not register a system. -- MAP-EU-GA-12-Art12 GA-12 Art. 12: Supported observation can contribute logs of destination, process, size, and timing. It is not a complete record-keeping system. -- MAP-EU-GA-13-Art15 GA-13 Art. 15: Cybersecurity and robustness duties are not discharged. Runtime enforcement is unverified in this tree. -- MAP-EU-GA-19-Art12 GA-19 Art. 12: Evidence capture is partial and path-limited. It is not automatic logging for every system. -- MAP-EU-GA-25-Art10 GA-25 Art. 10: Data-governance and training-data duties stay with the customer and the model provider. -- MAP-EU-GA-35-Art53 GA-35 Art. 53: General-purpose model provider duties are not Vantio duties. The article identifier is a boundary, not a claim of conformity. -- MAP-EU-GA-36-Art14 GA-36 Art. 14: Human oversight stays with the customer. Planned approval classes are not live oversight. -- MAP-EU-GA-37-Art73 GA-37 Art. 73: Legal incident submission stays with the customer. This package does not notify an authority. -- MAP-EU-GA-39-Art13 GA-39 Art. 13: Transparency to users of a customer system is not established by this disclosure row. diff --git a/docs/internal/governance-assurance/views/iso-iec-42001.md b/docs/internal/governance-assurance/views/iso-iec-42001.md deleted file mode 100644 index 1cfd6adb..00000000 --- a/docs/internal/governance-assurance/views/iso-iec-42001.md +++ /dev/null @@ -1,48 +0,0 @@ -# ISO-IEC-42001 2023 - -Audience: INTERNAL_RESTRICTED - -Vantio does not fulfill this framework. Rows are crosswalks. - -Status: CURRENT. Active: true. - -- MAP-ISO-GA-01 GA-01 SOURCE_ACCESS_REQUIRED: No clause number is assigned. Vantio does not establish the customer's management system and does not claim certification readiness. -- MAP-ISO-GA-02 GA-02 SOURCE_ACCESS_REQUIRED: No clause number is assigned. Vantio does not establish the customer's management system and does not claim certification readiness. -- MAP-ISO-GA-03 GA-03 SOURCE_ACCESS_REQUIRED: No clause number is assigned. Vantio does not establish the customer's management system and does not claim certification readiness. -- MAP-ISO-GA-04 GA-04 SOURCE_ACCESS_REQUIRED: No clause number is assigned. Vantio does not establish the customer's management system and does not claim certification readiness. -- MAP-ISO-GA-05 GA-05 SOURCE_ACCESS_REQUIRED: No clause number is assigned. Vantio does not establish the customer's management system and does not claim certification readiness. -- MAP-ISO-GA-06 GA-06 SOURCE_ACCESS_REQUIRED: No clause number is assigned. Vantio does not establish the customer's management system and does not claim certification readiness. -- MAP-ISO-GA-07 GA-07 SOURCE_ACCESS_REQUIRED: No clause number is assigned. Vantio does not establish the customer's management system and does not claim certification readiness. -- MAP-ISO-GA-08 GA-08 SOURCE_ACCESS_REQUIRED: No clause number is assigned. Vantio does not establish the customer's management system and does not claim certification readiness. -- MAP-ISO-GA-09 GA-09 SOURCE_ACCESS_REQUIRED: No clause number is assigned. Vantio does not establish the customer's management system and does not claim certification readiness. -- MAP-ISO-GA-10 GA-10 SOURCE_ACCESS_REQUIRED: No clause number is assigned. Vantio does not establish the customer's management system and does not claim certification readiness. -- MAP-ISO-GA-11 GA-11 SOURCE_ACCESS_REQUIRED: No clause number is assigned. Vantio does not establish the customer's management system and does not claim certification readiness. -- MAP-ISO-GA-12 GA-12 SOURCE_ACCESS_REQUIRED: No clause number is assigned. Vantio does not establish the customer's management system and does not claim certification readiness. -- MAP-ISO-GA-13 GA-13 SOURCE_ACCESS_REQUIRED: No clause number is assigned. Vantio does not establish the customer's management system and does not claim certification readiness. -- MAP-ISO-GA-14 GA-14 SOURCE_ACCESS_REQUIRED: No clause number is assigned. Vantio does not establish the customer's management system and does not claim certification readiness. -- MAP-ISO-GA-15 GA-15 SOURCE_ACCESS_REQUIRED: No clause number is assigned. Vantio does not establish the customer's management system and does not claim certification readiness. -- MAP-ISO-GA-16 GA-16 SOURCE_ACCESS_REQUIRED: No clause number is assigned. Vantio does not establish the customer's management system and does not claim certification readiness. -- MAP-ISO-GA-17 GA-17 SOURCE_ACCESS_REQUIRED: No clause number is assigned. Vantio does not establish the customer's management system and does not claim certification readiness. -- MAP-ISO-GA-18 GA-18 SOURCE_ACCESS_REQUIRED: No clause number is assigned. Vantio does not establish the customer's management system and does not claim certification readiness. -- MAP-ISO-GA-19 GA-19 SOURCE_ACCESS_REQUIRED: No clause number is assigned. Vantio does not establish the customer's management system and does not claim certification readiness. -- MAP-ISO-GA-20 GA-20 SOURCE_ACCESS_REQUIRED: No clause number is assigned. Vantio does not establish the customer's management system and does not claim certification readiness. -- MAP-ISO-GA-21 GA-21 SOURCE_ACCESS_REQUIRED: No clause number is assigned. Vantio does not establish the customer's management system and does not claim certification readiness. -- MAP-ISO-GA-22 GA-22 SOURCE_ACCESS_REQUIRED: No clause number is assigned. Vantio does not establish the customer's management system and does not claim certification readiness. -- MAP-ISO-GA-23 GA-23 SOURCE_ACCESS_REQUIRED: No clause number is assigned. Vantio does not establish the customer's management system and does not claim certification readiness. -- MAP-ISO-GA-24 GA-24 SOURCE_ACCESS_REQUIRED: No clause number is assigned. Vantio does not establish the customer's management system and does not claim certification readiness. -- MAP-ISO-GA-25 GA-25 SOURCE_ACCESS_REQUIRED: No clause number is assigned. Vantio does not establish the customer's management system and does not claim certification readiness. -- MAP-ISO-GA-26 GA-26 SOURCE_ACCESS_REQUIRED: No clause number is assigned. Vantio does not establish the customer's management system and does not claim certification readiness. -- MAP-ISO-GA-27 GA-27 SOURCE_ACCESS_REQUIRED: No clause number is assigned. Vantio does not establish the customer's management system and does not claim certification readiness. -- MAP-ISO-GA-28 GA-28 SOURCE_ACCESS_REQUIRED: No clause number is assigned. Vantio does not establish the customer's management system and does not claim certification readiness. -- MAP-ISO-GA-29 GA-29 SOURCE_ACCESS_REQUIRED: No clause number is assigned. Vantio does not establish the customer's management system and does not claim certification readiness. -- MAP-ISO-GA-30 GA-30 SOURCE_ACCESS_REQUIRED: No clause number is assigned. Vantio does not establish the customer's management system and does not claim certification readiness. -- MAP-ISO-GA-31 GA-31 SOURCE_ACCESS_REQUIRED: No clause number is assigned. Vantio does not establish the customer's management system and does not claim certification readiness. -- MAP-ISO-GA-32 GA-32 SOURCE_ACCESS_REQUIRED: No clause number is assigned. Vantio does not establish the customer's management system and does not claim certification readiness. -- MAP-ISO-GA-33 GA-33 SOURCE_ACCESS_REQUIRED: No clause number is assigned. Vantio does not establish the customer's management system and does not claim certification readiness. -- MAP-ISO-GA-34 GA-34 SOURCE_ACCESS_REQUIRED: No clause number is assigned. Vantio does not establish the customer's management system and does not claim certification readiness. -- MAP-ISO-GA-35 GA-35 SOURCE_ACCESS_REQUIRED: No clause number is assigned. Vantio does not establish the customer's management system and does not claim certification readiness. -- MAP-ISO-GA-36 GA-36 SOURCE_ACCESS_REQUIRED: No clause number is assigned. Vantio does not establish the customer's management system and does not claim certification readiness. -- MAP-ISO-GA-37 GA-37 SOURCE_ACCESS_REQUIRED: No clause number is assigned. Vantio does not establish the customer's management system and does not claim certification readiness. -- MAP-ISO-GA-38 GA-38 SOURCE_ACCESS_REQUIRED: No clause number is assigned. Vantio does not establish the customer's management system and does not claim certification readiness. -- MAP-ISO-GA-39 GA-39 SOURCE_ACCESS_REQUIRED: No clause number is assigned. Vantio does not establish the customer's management system and does not claim certification readiness. -- MAP-ISO-GA-40 GA-40 SOURCE_ACCESS_REQUIRED: No clause number is assigned. Vantio does not establish the customer's management system and does not claim certification readiness. diff --git a/docs/internal/governance-assurance/views/nist-ai-agent-standards.md b/docs/internal/governance-assurance/views/nist-ai-agent-standards.md deleted file mode 100644 index cdf1a459..00000000 --- a/docs/internal/governance-assurance/views/nist-ai-agent-standards.md +++ /dev/null @@ -1,30 +0,0 @@ -# NIST-AI-AGENT-STANDARDS page-undated - -Audience: INTERNAL_RESTRICTED - -Vantio does not fulfill this framework. Rows are crosswalks. - -Status: CURRENT. Active: true. - -- MAP-AGENT-GA-30-NIST-AGENT-INITIATIVE-PAGE GA-30 NIST-AGENT-INITIATIVE-PAGE: Sequential evaluation is an internal candidate. It is not an industry standard adopted by the initiative. - -# NIST-AI-AGENT-STANDARDS 800-5 - -Audience: INTERNAL_RESTRICTED - -Vantio does not fulfill this framework. Rows are crosswalks. - -Status: CURRENT. Active: true. - -- MAP-AGENT-GA-13-NIST-AI-800-5 GA-13 NIST-AI-800-5: The report summarizes comments on agent security. It is not a requirement this catalog treats as met. - -# NIST-AI-AGENT-STANDARDS 2026-02-05 - -Audience: INTERNAL_RESTRICTED - -Vantio does not fulfill this framework. Rows are crosswalks. - -Status: CURRENT. Active: true. - -- MAP-AGENT-GA-06-NCCOE-AGENT-IDENTITY-CONCEPT GA-06 NCCOE-AGENT-IDENTITY-CONCEPT: The concept paper discusses agent identity and authorization. This tree has no live delegation object. -- MAP-AGENT-GA-16-NCCOE-AGENT-IDENTITY-CONCEPT GA-16 NCCOE-AGENT-IDENTITY-CONCEPT: Process metadata on a wrapped path is not agent identity infrastructure. diff --git a/docs/internal/governance-assurance/views/nist-ai-rmf-playbook.md b/docs/internal/governance-assurance/views/nist-ai-rmf-playbook.md deleted file mode 100644 index f67596f8..00000000 --- a/docs/internal/governance-assurance/views/nist-ai-rmf-playbook.md +++ /dev/null @@ -1,48 +0,0 @@ -# NIST-AI-RMF-PLAYBOOK first-complete-version - -Audience: INTERNAL_RESTRICTED - -Vantio does not fulfill this framework. Rows are crosswalks. - -Status: CURRENT. Active: true. - -- MAP-PLAY-GA-01 GA-01 MAP: Playbook suggestions for MAP are not copied and are not adopted as completed actions. -- MAP-PLAY-GA-02 GA-02 MAP: Playbook suggestions for MAP are not copied and are not adopted as completed actions. -- MAP-PLAY-GA-03 GA-03 MAP: Playbook suggestions for MAP are not copied and are not adopted as completed actions. -- MAP-PLAY-GA-04 GA-04 GOVERN: Playbook suggestions for GOVERN are not copied and are not adopted as completed actions. -- MAP-PLAY-GA-05 GA-05 GOVERN: Playbook suggestions for GOVERN are not copied and are not adopted as completed actions. -- MAP-PLAY-GA-06 GA-06 GOVERN: Playbook suggestions for GOVERN are not copied and are not adopted as completed actions. -- MAP-PLAY-GA-07 GA-07 GOVERN: Playbook suggestions for GOVERN are not copied and are not adopted as completed actions. -- MAP-PLAY-GA-08 GA-08 GOVERN: Playbook suggestions for GOVERN are not copied and are not adopted as completed actions. -- MAP-PLAY-GA-09 GA-09 GOVERN: Playbook suggestions for GOVERN are not copied and are not adopted as completed actions. -- MAP-PLAY-GA-10 GA-10 MANAGE: Playbook suggestions for MANAGE are not copied and are not adopted as completed actions. -- MAP-PLAY-GA-11 GA-11 MANAGE: Playbook suggestions for MANAGE are not copied and are not adopted as completed actions. -- MAP-PLAY-GA-12 GA-12 MEASURE: Playbook suggestions for MEASURE are not copied and are not adopted as completed actions. -- MAP-PLAY-GA-13 GA-13 MANAGE: Playbook suggestions for MANAGE are not copied and are not adopted as completed actions. -- MAP-PLAY-GA-14 GA-14 MANAGE: Playbook suggestions for MANAGE are not copied and are not adopted as completed actions. -- MAP-PLAY-GA-15 GA-15 MANAGE: Playbook suggestions for MANAGE are not copied and are not adopted as completed actions. -- MAP-PLAY-GA-16 GA-16 MAP: Playbook suggestions for MAP are not copied and are not adopted as completed actions. -- MAP-PLAY-GA-17 GA-17 MANAGE: Playbook suggestions for MANAGE are not copied and are not adopted as completed actions. -- MAP-PLAY-GA-18 GA-18 MANAGE: Playbook suggestions for MANAGE are not copied and are not adopted as completed actions. -- MAP-PLAY-GA-19 GA-19 MEASURE: Playbook suggestions for MEASURE are not copied and are not adopted as completed actions. -- MAP-PLAY-GA-20 GA-20 MEASURE: Playbook suggestions for MEASURE are not copied and are not adopted as completed actions. -- MAP-PLAY-GA-21 GA-21 MEASURE: Playbook suggestions for MEASURE are not copied and are not adopted as completed actions. -- MAP-PLAY-GA-22 GA-22 MEASURE: Playbook suggestions for MEASURE are not copied and are not adopted as completed actions. -- MAP-PLAY-GA-23 GA-23 GOVERN: Playbook suggestions for GOVERN are not copied and are not adopted as completed actions. -- MAP-PLAY-GA-24 GA-24 GOVERN: Playbook suggestions for GOVERN are not copied and are not adopted as completed actions. -- MAP-PLAY-GA-25 GA-25 GOVERN: Playbook suggestions for GOVERN are not copied and are not adopted as completed actions. -- MAP-PLAY-GA-26 GA-26 GOVERN: Playbook suggestions for GOVERN are not copied and are not adopted as completed actions. -- MAP-PLAY-GA-27 GA-27 MANAGE: Playbook suggestions for MANAGE are not copied and are not adopted as completed actions. -- MAP-PLAY-GA-28 GA-28 MEASURE: Playbook suggestions for MEASURE are not copied and are not adopted as completed actions. -- MAP-PLAY-GA-29 GA-29 MANAGE: Playbook suggestions for MANAGE are not copied and are not adopted as completed actions. -- MAP-PLAY-GA-30 GA-30 MANAGE: Playbook suggestions for MANAGE are not copied and are not adopted as completed actions. -- MAP-PLAY-GA-31 GA-31 MANAGE: Playbook suggestions for MANAGE are not copied and are not adopted as completed actions. -- MAP-PLAY-GA-32 GA-32 MEASURE: Playbook suggestions for MEASURE are not copied and are not adopted as completed actions. -- MAP-PLAY-GA-33 GA-33 MEASURE: Playbook suggestions for MEASURE are not copied and are not adopted as completed actions. -- MAP-PLAY-GA-34 GA-34 MEASURE: Playbook suggestions for MEASURE are not copied and are not adopted as completed actions. -- MAP-PLAY-GA-35 GA-35 MAP: Playbook suggestions for MAP are not copied and are not adopted as completed actions. -- MAP-PLAY-GA-36 GA-36 GOVERN: Playbook suggestions for GOVERN are not copied and are not adopted as completed actions. -- MAP-PLAY-GA-37 GA-37 MANAGE: Playbook suggestions for MANAGE are not copied and are not adopted as completed actions. -- MAP-PLAY-GA-38 GA-38 GOVERN: Playbook suggestions for GOVERN are not copied and are not adopted as completed actions. -- MAP-PLAY-GA-39 GA-39 GOVERN: Playbook suggestions for GOVERN are not copied and are not adopted as completed actions. -- MAP-PLAY-GA-40 GA-40 MANAGE: Playbook suggestions for MANAGE are not copied and are not adopted as completed actions. diff --git a/docs/internal/governance-assurance/views/nist-ai-rmf.md b/docs/internal/governance-assurance/views/nist-ai-rmf.md deleted file mode 100644 index 57c7f2d5..00000000 --- a/docs/internal/governance-assurance/views/nist-ai-rmf.md +++ /dev/null @@ -1,48 +0,0 @@ -# NIST-AI-RMF 1.0 - -Audience: INTERNAL_RESTRICTED - -Vantio does not fulfill this framework. Rows are crosswalks. - -Status: CURRENT. Active: true. - -- MAP-NIST-GA-01 GA-01 MAP: MAP is the function identifier only. Vantio does not fulfill MAP. Subcategory text is not copied. Support on this row follows VANTIO_PARTIALLY_SUPPORTS. -- MAP-NIST-GA-02 GA-02 MAP: MAP is the function identifier only. Vantio does not fulfill MAP. Subcategory text is not copied. Support on this row follows VANTIO_PARTIALLY_SUPPORTS. -- MAP-NIST-GA-03 GA-03 MAP: MAP is the function identifier only. Vantio does not fulfill MAP. Subcategory text is not copied. Support on this row follows VANTIO_PARTIALLY_SUPPORTS. -- MAP-NIST-GA-04 GA-04 GOVERN: GOVERN is the function identifier only. Vantio does not fulfill GOVERN. Subcategory text is not copied. Support on this row follows CUSTOMER_PROVIDES. -- MAP-NIST-GA-05 GA-05 GOVERN: GOVERN is the function identifier only. Vantio does not fulfill GOVERN. Subcategory text is not copied. Support on this row follows CUSTOMER_CONFIGURES. -- MAP-NIST-GA-06 GA-06 GOVERN: GOVERN is the function identifier only. Vantio does not fulfill GOVERN. Subcategory text is not copied. Support on this row follows CUSTOMER_CONFIGURES. -- MAP-NIST-GA-07 GA-07 GOVERN: GOVERN is the function identifier only. Vantio does not fulfill GOVERN. Subcategory text is not copied. Support on this row follows CUSTOMER_CONFIGURES. -- MAP-NIST-GA-08 GA-08 GOVERN: GOVERN is the function identifier only. Vantio does not fulfill GOVERN. Subcategory text is not copied. Support on this row follows NOT_IMPLEMENTED. -- MAP-NIST-GA-09 GA-09 GOVERN: GOVERN is the function identifier only. Vantio does not fulfill GOVERN. Subcategory text is not copied. Support on this row follows NOT_IMPLEMENTED. -- MAP-NIST-GA-10 GA-10 MANAGE: MANAGE is the function identifier only. Vantio does not fulfill MANAGE. Subcategory text is not copied. Support on this row follows UNVERIFIED. -- MAP-NIST-GA-11 GA-11 MANAGE: MANAGE is the function identifier only. Vantio does not fulfill MANAGE. Subcategory text is not copied. Support on this row follows UNVERIFIED. -- MAP-NIST-GA-12 GA-12 MEASURE: MEASURE is the function identifier only. Vantio does not fulfill MEASURE. Subcategory text is not copied. Support on this row follows VANTIO_PARTIALLY_SUPPORTS. -- MAP-NIST-GA-13 GA-13 MANAGE: MANAGE is the function identifier only. Vantio does not fulfill MANAGE. Subcategory text is not copied. Support on this row follows UNVERIFIED. -- MAP-NIST-GA-14 GA-14 MANAGE: MANAGE is the function identifier only. Vantio does not fulfill MANAGE. Subcategory text is not copied. Support on this row follows UNVERIFIED. -- MAP-NIST-GA-15 GA-15 MANAGE: MANAGE is the function identifier only. Vantio does not fulfill MANAGE. Subcategory text is not copied. Support on this row follows UNVERIFIED. -- MAP-NIST-GA-16 GA-16 MAP: MAP is the function identifier only. Vantio does not fulfill MAP. Subcategory text is not copied. Support on this row follows VANTIO_PARTIALLY_SUPPORTS. -- MAP-NIST-GA-17 GA-17 MANAGE: MANAGE is the function identifier only. Vantio does not fulfill MANAGE. Subcategory text is not copied. Support on this row follows VANTIO_PARTIALLY_SUPPORTS. -- MAP-NIST-GA-18 GA-18 MANAGE: MANAGE is the function identifier only. Vantio does not fulfill MANAGE. Subcategory text is not copied. Support on this row follows NOT_IMPLEMENTED. -- MAP-NIST-GA-19 GA-19 MEASURE: MEASURE is the function identifier only. Vantio does not fulfill MEASURE. Subcategory text is not copied. Support on this row follows VANTIO_PARTIALLY_SUPPORTS. -- MAP-NIST-GA-20 GA-20 MEASURE: MEASURE is the function identifier only. Vantio does not fulfill MEASURE. Subcategory text is not copied. Support on this row follows VANTIO_PARTIALLY_SUPPORTS. -- MAP-NIST-GA-21 GA-21 MEASURE: MEASURE is the function identifier only. Vantio does not fulfill MEASURE. Subcategory text is not copied. Support on this row follows VANTIO_PARTIALLY_SUPPORTS. -- MAP-NIST-GA-22 GA-22 MEASURE: MEASURE is the function identifier only. Vantio does not fulfill MEASURE. Subcategory text is not copied. Support on this row follows NOT_IMPLEMENTED. -- MAP-NIST-GA-23 GA-23 GOVERN: GOVERN is the function identifier only. Vantio does not fulfill GOVERN. Subcategory text is not copied. Support on this row follows CUSTOMER_PROVIDES. -- MAP-NIST-GA-24 GA-24 GOVERN: GOVERN is the function identifier only. Vantio does not fulfill GOVERN. Subcategory text is not copied. Support on this row follows VANTIO_PARTIALLY_SUPPORTS. -- MAP-NIST-GA-25 GA-25 GOVERN: GOVERN is the function identifier only. Vantio does not fulfill GOVERN. Subcategory text is not copied. Support on this row follows VANTIO_PARTIALLY_SUPPORTS. -- MAP-NIST-GA-26 GA-26 GOVERN: GOVERN is the function identifier only. Vantio does not fulfill GOVERN. Subcategory text is not copied. Support on this row follows VANTIO_PARTIALLY_SUPPORTS. -- MAP-NIST-GA-27 GA-27 MANAGE: MANAGE is the function identifier only. Vantio does not fulfill MANAGE. Subcategory text is not copied. Support on this row follows UNVERIFIED. -- MAP-NIST-GA-28 GA-28 MEASURE: MEASURE is the function identifier only. Vantio does not fulfill MEASURE. Subcategory text is not copied. Support on this row follows VANTIO_PARTIALLY_SUPPORTS. -- MAP-NIST-GA-29 GA-29 MANAGE: MANAGE is the function identifier only. Vantio does not fulfill MANAGE. Subcategory text is not copied. Support on this row follows CUSTOMER_CONFIGURES. -- MAP-NIST-GA-30 GA-30 MANAGE: MANAGE is the function identifier only. Vantio does not fulfill MANAGE. Subcategory text is not copied. Support on this row follows VANTIO_PARTIALLY_SUPPORTS. -- MAP-NIST-GA-31 GA-31 MANAGE: MANAGE is the function identifier only. Vantio does not fulfill MANAGE. Subcategory text is not copied. Support on this row follows VANTIO_PARTIALLY_SUPPORTS. -- MAP-NIST-GA-32 GA-32 MEASURE: MEASURE is the function identifier only. Vantio does not fulfill MEASURE. Subcategory text is not copied. Support on this row follows UNVERIFIED. -- MAP-NIST-GA-33 GA-33 MEASURE: MEASURE is the function identifier only. Vantio does not fulfill MEASURE. Subcategory text is not copied. Support on this row follows UNVERIFIED. -- MAP-NIST-GA-34 GA-34 MEASURE: MEASURE is the function identifier only. Vantio does not fulfill MEASURE. Subcategory text is not copied. Support on this row follows UNVERIFIED. -- MAP-NIST-GA-35 GA-35 MAP: MAP is the function identifier only. Vantio does not fulfill MAP. Subcategory text is not copied. Support on this row follows THIRD_PARTY_REQUIRED. -- MAP-NIST-GA-36 GA-36 GOVERN: GOVERN is the function identifier only. Vantio does not fulfill GOVERN. Subcategory text is not copied. Support on this row follows CUSTOMER_PROVIDES. -- MAP-NIST-GA-37 GA-37 MANAGE: MANAGE is the function identifier only. Vantio does not fulfill MANAGE. Subcategory text is not copied. Support on this row follows CUSTOMER_PROVIDES. -- MAP-NIST-GA-38 GA-38 GOVERN: GOVERN is the function identifier only. Vantio does not fulfill GOVERN. Subcategory text is not copied. Support on this row follows VANTIO_PARTIALLY_SUPPORTS. -- MAP-NIST-GA-39 GA-39 GOVERN: GOVERN is the function identifier only. Vantio does not fulfill GOVERN. Subcategory text is not copied. Support on this row follows VANTIO_PROVIDES. -- MAP-NIST-GA-40 GA-40 MANAGE: MANAGE is the function identifier only. Vantio does not fulfill MANAGE. Subcategory text is not copied. Support on this row follows UNVERIFIED. diff --git a/docs/internal/governance-assurance/views/us-federal.md b/docs/internal/governance-assurance/views/us-federal.md deleted file mode 100644 index 48bdaae5..00000000 --- a/docs/internal/governance-assurance/views/us-federal.md +++ /dev/null @@ -1,53 +0,0 @@ -# US-FEDERAL-AI-ACQUISITION M-25-21 - -Audience: INTERNAL_RESTRICTED - -Vantio does not fulfill this framework. Rows are crosswalks. - -Status: CURRENT. Active: true. - -- MAP-FED-GA-04-M-25-21 GA-04 M-25-21: High-impact and agency governance determinations belong to the agency. This row does not make them. -- MAP-FED-GA-39-M-25-21 GA-39 M-25-21: The claim ceiling is a vendor disclosure. It is not an agency compliance plan. - -# US-FEDERAL-AI-ACQUISITION M-25-22 - -Audience: INTERNAL_RESTRICTED - -Vantio does not fulfill this framework. Rows are crosswalks. - -Status: CURRENT. Active: true. - -- MAP-FED-GA-26-M-25-22 GA-26 M-25-22: Release characterization is not post-award performance monitoring and not a contract deliverable. -- MAP-FED-GA-38-M-25-22 GA-38 M-25-22: The private index can be read while preparing a vendor response. It is not a submission and not an award. - -# US-FEDERAL-AI-ACQUISITION M-26-04 - -Audience: INTERNAL_RESTRICTED - -Vantio does not fulfill this framework. Rows are crosswalks. - -Status: CURRENT. Active: true. - -- MAP-FED-GA-35-M-26-04 GA-35 M-26-04: LLM procurement principles are agency and provider matters. No model is asserted to meet them. - -# US-FEDERAL-AI-ACQUISITION M-24-10 - -Audience: INTERNAL_RESTRICTED - -Vantio does not fulfill this framework. Rows are crosswalks. - -Status: SUPERSEDED. Active: false. -Superseded by: M-25-21. - -- MAP-SUPER-M-24-10 register M-24-10: Superseded by M-25-21. Visible so a reader does not apply the replaced memorandum as current. - -# US-FEDERAL-AI-ACQUISITION M-24-18 - -Audience: INTERNAL_RESTRICTED - -Vantio does not fulfill this framework. Rows are crosswalks. - -Status: SUPERSEDED. Active: false. -Superseded by: M-25-22. - -- MAP-SUPER-M-24-18 register M-24-18: Superseded by M-25-22. Visible so a reader does not apply the replaced memorandum as current. diff --git a/docs/internal/hiring/README.md b/docs/internal/hiring/README.md deleted file mode 100644 index 83a94516..00000000 --- a/docs/internal/hiring/README.md +++ /dev/null @@ -1,16 +0,0 @@ -# Internal hiring - -Audience: INTERNAL_RESTRICTED - -This directory is hiring material. It is not product documentation, not a customer artifact, and not an external announcement. - -`docs/internal/` is already on the documentation packaging deny list (`docs/governance/PACKAGING-EXCLUSION.json`). These files stay on that path so a public package build does not pick them up. The repository itself is public; the audience label is a handling rule for people and agents, not an access control. - -## Packages - -| Package | Path | Offer status | -| --- | --- | --- | -| Head of Product / Head of Product Engineering | `head-of-product/` | The only hiring package in this change | -| CTO evaluation framework stub | `cto-evaluation/FRAMEWORK-STUB.md` | Separate future document. Not an offer exhibit | - -WS13 force: Head of Product or Head of Product Engineering. Founder, co-founder, technical co-founder, guaranteed CTO, and automatic CTO succession are outside this package. diff --git a/docs/internal/hiring/cto-evaluation/FRAMEWORK-STUB.md b/docs/internal/hiring/cto-evaluation/FRAMEWORK-STUB.md deleted file mode 100644 index c2a7247a..00000000 --- a/docs/internal/hiring/cto-evaluation/FRAMEWORK-STUB.md +++ /dev/null @@ -1,37 +0,0 @@ -# CTO evaluation framework — stub - -Audience: INTERNAL_RESTRICTED - -Status: `STUB` - -Attachment: **Not an offer exhibit.** Do not append this file to a Head of Product or Head of Product Engineering offer, link it as a term, or put it in the candidate packet. - -The Head of Product hiring package records a consideration line and stops. This file is the separate future framework that line points at. Opening, approving, or applying the framework is out of scope for WS13. - -## Consideration line - -Until a later Founder document replaces this stub, the only status it carries is: - -`POSSIBLE / UNDECIDED / NOT PROMISED / NOT APPROVED / NOT AUTOMATIC` - -## Slots a future framework would have to set - -All slots are unset. An unset slot is not a default, not a vote, and not an approval. - -| Slot | State | -| --- | --- | -| Who may open an evaluation | NOT SET | -| Who may approve an appointment | NOT SET | -| Criteria | NOT SET | -| Evidence required | NOT SET | -| Timing | NOT SET | -| Relationship to the Head of Product offer | NONE | -| Automatic succession | Outside this framework. Not a slot to fill with a yes. | - -## Stop - -- This stub does not evaluate a person. -- This stub does not name a candidate. -- This stub does not create a path from Head of Product or Head of Product Engineering to CTO. -- This stub does not change compensation, equity, or title. -- Filling any slot above requires a separate Founder document. Editing this stub inside the Head of Product offer packet is not that document. diff --git a/docs/internal/hiring/head-of-product/COMPENSATION.md b/docs/internal/hiring/head-of-product/COMPENSATION.md deleted file mode 100644 index 5788b073..00000000 --- a/docs/internal/hiring/head-of-product/COMPENSATION.md +++ /dev/null @@ -1,25 +0,0 @@ -# Compensation - -Audience: INTERNAL_RESTRICTED - -Offer exhibit: yes - -Every cell below is a placeholder. A placeholder is not a quote, not a band that has been approved, and not a number a candidate or an agent may invent. - -| Component | Placeholder | -| --- | --- | -| Band name | TBD | -| Cash base | TBD | -| Equity | TBD | -| Variable / bonus | TBD | -| Sign-on | TBD | -| Benefits | TBD | -| Currency | TBD | -| Location differential | TBD | -| Start date | TBD | - -Equity in this offer is compensation for the single allowed title. It is not a founder grant. This file does not set a percentage, a share count, a strike price, or a vesting schedule. - -The CTO consideration line is not a compensation term and does not add equity, title, or severance. - -Numbers enter this file only by a later Founder edit that replaces `TBD` with a stated figure and a source for that figure. Until that edit, interviewers say "TBD" and stop. diff --git a/docs/internal/hiring/head-of-product/INTERVIEW-LOOP.md b/docs/internal/hiring/head-of-product/INTERVIEW-LOOP.md deleted file mode 100644 index e717a156..00000000 --- a/docs/internal/hiring/head-of-product/INTERVIEW-LOOP.md +++ /dev/null @@ -1,30 +0,0 @@ -# Interview loop - -Audience: INTERNAL_RESTRICTED - -Offer exhibit: yes - -The loop is run by the Founder. This package does not name a second interviewer as required. An engineer may sit stage 4. The candidate does not run the loop and does not score themselves. - -No stage grants founder status or opens the CTO framework. - -| Stage | Name | Who | Input | Output | Stop rule | -| --- | --- | --- | --- | --- | --- | -| 0 | Read-ahead | Candidate, before any live conversation | `docs/governance/canonical/product-boundary.md` and this package's `OFFER-BOUNDARY.md` | Candidate arrives having read both | Missing read-ahead reschedules. It does not become a coaching session that supplies the answers. | -| 1 | Title screen | Founder | Allowed titles and the CTO consideration line | Scorecard S1, S2, S7 | `NO` on S1 or S2 ends the loop. | -| 2 | Boundary restatement | Founder | The canonical product-boundary file only. No extra slides. | Scorecard S3 and S6 | An added mechanism, price, or proof claim is `NO` on S3. | -| 3 | Written decision | Candidate, asynchronous, two days | A prompt chosen by the Founder from an open question already in the repo. The prompt cites the file that holds the question. | Memo of at most two pages. Scorecard S4 | A memo that sets a new price, a release date, or a customer commitment is `NO` on S4. | -| 4 | Frozen artifact | Founder, optionally with an engineer | `@vantio/cli` `0.3.24` as a frozen artifact. The engineer may describe the freeze. The engineer does not expand the role. | Scorecard S5 | A plan to reopen the CLI inside this hiring process is `NO` on S5. | -| 5 | Offer read-back | Founder | `OFFER-BOUNDARY.md` and `COMPENSATION.md` | Candidate reads the title, the exclusion line, the CTO consideration line, and the compensation `TBD` row aloud | Refusal to read the CTO line as written ends the loop. | -| 6 | References | Founder | Names supplied by the candidate | Notes. References are optional and do not replace S1–S6. | A reference is not used to add a title. | - -## Stage 3 prompt rules - -- The prompt is a question that already exists in a repository file. -- The prompt asks for a recommendation and a source list. -- The prompt does not ask for a new architecture, a kernel design, or a publish. -- The Founder records the prompt path on the score sheet. - -## Records - -Keep the score sheet in `SCORECARD.md`'s table, or in a private copy of that table stored with the candidate file. Do not put candidate names into this repository. diff --git a/docs/internal/hiring/head-of-product/NINETY-DAY-OUTCOMES.md b/docs/internal/hiring/head-of-product/NINETY-DAY-OUTCOMES.md deleted file mode 100644 index b9d5224d..00000000 --- a/docs/internal/hiring/head-of-product/NINETY-DAY-OUTCOMES.md +++ /dev/null @@ -1,42 +0,0 @@ -# 90-day outcomes - -Audience: INTERNAL_RESTRICTED - -Offer exhibit: yes - -These outcomes measure whether the hire stayed inside the offer boundary and the interim scope. They are not the missing Founder Master Program responsibilities list. They do not set revenue, headcount, ship dates, or proof claims. - -The Founder marks each outcome `MET` or `NOT_MET` from the artifact named in the row. A narrative without the artifact is `NOT_MET`. - -## Day 30 - -| ID | Outcome | Artifact | Met when | -| --- | --- | --- | --- | -| D30-1 | Product-boundary restatement matches the canonical file | A short memo that quotes or closely tracks `docs/governance/canonical/product-boundary.md` and lists every sentence the hire wanted to add | The add-list is empty, or every added sentence was withheld and marked withheld | -| D30-2 | Public identity matches the offer title | Signature, directory entry, and any bio the hire controls | The string is the single offered title. Founder, co-founder, technical co-founder, and CTO do not appear | -| D30-3 | Source log exists | A log of proposed external product sentences | Each row has a repository path, or the row is marked withheld | - -## Day 60 - -| ID | Outcome | Artifact | Met when | -| --- | --- | --- | --- | -| D60-1 | One product decision memo | Memo with decision, source paths, unproved items, and the Founder checkpoint | The Founder has accepted or rejected it in writing. The memo does not change a price, a release, or a customer commitment by itself | -| D60-2 | Open questions for the missing program list | A list of responsibility questions the hire cannot answer because the Founder Master Program list is empty | The list does not fill in the answers | - -## Day 90 - -| ID | Outcome | Artifact | Met when | -| --- | --- | --- | --- | -| D90-1 | No unsourced external product sentence shipped | Source log from D30-3, updated through day 90 | Every shipped external sentence has a path. Withheld rows stayed withheld | -| D90-2 | Offer boundary held for 90 days | Founder note | The note states that the title, the CTO consideration line, and the exhibit list were unchanged | -| D90-3 | CTO framework stayed closed | Absence of an opened evaluation, recorded by the Founder | `docs/internal/hiring/cto-evaluation/FRAMEWORK-STUB.md` is still a stub. No evaluation of this hire was started | - -## What these outcomes do not require - -- A product release -- A publish -- A customer contract -- A compensation number -- Opening the CTO framework - -Day-90 success is the seven artifacts above marked `MET`. It is not a promotion. diff --git a/docs/internal/hiring/head-of-product/OFFER-BOUNDARY.md b/docs/internal/hiring/head-of-product/OFFER-BOUNDARY.md deleted file mode 100644 index ada1b0b2..00000000 --- a/docs/internal/hiring/head-of-product/OFFER-BOUNDARY.md +++ /dev/null @@ -1,50 +0,0 @@ -# Offer boundary - -Audience: INTERNAL_RESTRICTED - -Offer exhibit: yes - -This file is the boundary a candidate reads back at stage 5 of the interview loop. It is also the checklist for anyone assembling the offer packet. - -## The offer includes - -- One title: Head of Product, or Head of Product Engineering -- The exhibits listed in `README.md` -- Compensation cells, all `TBD`, until a Founder replaces them -- The 90-day outcomes in `NINETY-DAY-OUTCOMES.md` - -## The offer records this CTO line and no other CTO language - -`POSSIBLE / UNDECIDED / NOT PROMISED / NOT APPROVED / NOT AUTOMATIC` - -Meaning of that line, for the read-back: - -| Word | How it is read | -| --- | --- | -| POSSIBLE | A future evaluation may exist later | -| UNDECIDED | No decision has been made | -| NOT PROMISED | The offer does not promise an outcome | -| NOT APPROVED | No approval has been given | -| NOT AUTOMATIC | The Head of Product title does not become CTO by time, performance, or succession | - -## The offer excludes - -- Founder -- Co-founder -- Technical co-founder -- Guaranteed CTO -- Automatic CTO succession -- `docs/internal/hiring/cto-evaluation/FRAMEWORK-STUB.md` as an exhibit, a link in the offer, or a term -- Any responsibilities text attributed to the Founder Master Program, because that list was absent at authoring time -- Any compensation number - -## Packet check before send - -| Check | Required state | -| --- | --- | -| Title appears once, and it is an allowed title | Pass | -| Founder, co-founder, technical co-founder, and CTO are absent as titles | Pass | -| CTO line matches the string in this file exactly | Pass | -| CTO framework file is absent from the packet | Pass | -| Compensation table still says TBD, unless a later Founder edit replaced it | Pass | -| Candidate name is not added to this repository | Pass | diff --git a/docs/internal/hiring/head-of-product/PACKAGE.json b/docs/internal/hiring/head-of-product/PACKAGE.json deleted file mode 100644 index 3b6a8490..00000000 --- a/docs/internal/hiring/head-of-product/PACKAGE.json +++ /dev/null @@ -1,36 +0,0 @@ -{ - "schema": "vantio.internal.hiring.head-of-product/v1", - "audience": "INTERNAL_RESTRICTED", - "workstream": "WS13", - "base_commit": "5064f32f1cdfcb840dfd100e2ce5c712d046550d", - "titles_allowed": ["Head of Product", "Head of Product Engineering"], - "titles_outside_offer": [ - "founder", - "co-founder", - "technical co-founder", - "CTO" - ], - "cto_consideration": "POSSIBLE / UNDECIDED / NOT PROMISED / NOT APPROVED / NOT AUTOMATIC", - "cto_automatic_succession": false, - "cto_framework_path": "docs/internal/hiring/cto-evaluation/FRAMEWORK-STUB.md", - "cto_framework_attached_to_offer": false, - "founder_master_program_responsibilities": "ABSENT", - "compensation": { - "base": "TBD", - "equity": "TBD", - "variable": "TBD", - "sign_on": "TBD", - "benefits": "TBD", - "currency": "TBD", - "band": "TBD" - }, - "offer_exhibits": [ - "docs/internal/hiring/head-of-product/ROLE-AND-RESPONSIBILITIES.md", - "docs/internal/hiring/head-of-product/SCORECARD.md", - "docs/internal/hiring/head-of-product/INTERVIEW-LOOP.md", - "docs/internal/hiring/head-of-product/NINETY-DAY-OUTCOMES.md", - "docs/internal/hiring/head-of-product/RED-FLAGS.md", - "docs/internal/hiring/head-of-product/COMPENSATION.md", - "docs/internal/hiring/head-of-product/OFFER-BOUNDARY.md" - ] -} diff --git a/docs/internal/hiring/head-of-product/README.md b/docs/internal/hiring/head-of-product/README.md deleted file mode 100644 index 92097393..00000000 --- a/docs/internal/hiring/head-of-product/README.md +++ /dev/null @@ -1,48 +0,0 @@ -# Head of Product / Head of Product Engineering — hiring package - -Audience: INTERNAL_RESTRICTED - -Workstream: WS13 - -Base commit this package was written against: `5064f32f1cdfcb840dfd100e2ce5c712d046550d` (`origin/main`). - -## Role - -The offer uses one title, chosen before the offer is sent: - -- Head of Product -- Head of Product Engineering - -The offer does not use founder, co-founder, technical co-founder, or CTO. - -CTO consideration, recorded on the offer as a status line and nowhere else, is exactly: - -`POSSIBLE / UNDECIDED / NOT PROMISED / NOT APPROVED / NOT AUTOMATIC` - -That line is not a grant, a timeline, or an approval. A future CTO evaluation, if one is ever opened, uses `docs/internal/hiring/cto-evaluation/FRAMEWORK-STUB.md`. That file is not part of this package and is not attached to the offer. - -## Offer exhibits - -These files may be attached to an internal offer packet: - -| Exhibit | File | -| --- | --- | -| Role and responsibilities | `ROLE-AND-RESPONSIBILITIES.md` | -| Scorecard | `SCORECARD.md` | -| Interview loop | `INTERVIEW-LOOP.md` | -| 90-day outcomes | `NINETY-DAY-OUTCOMES.md` | -| Red flags | `RED-FLAGS.md` | -| Compensation placeholders | `COMPENSATION.md` | -| Offer boundary | `OFFER-BOUNDARY.md` | - -`PACKAGE.json` is the machine-readable index of the same facts. It is an internal record, not a candidate exhibit. - -## Not an offer exhibit - -`docs/internal/hiring/cto-evaluation/FRAMEWORK-STUB.md` - -Do not append it, link it as a term, or place it in the candidate packet. - -## Source limit - -The WS13 force asks for the responsibilities list from the Founder Master Program. That program text is not in this repository. The responsibilities file records the search and leaves the program list empty. It does not invent a replacement list and attribute it to that program. diff --git a/docs/internal/hiring/head-of-product/RED-FLAGS.md b/docs/internal/hiring/head-of-product/RED-FLAGS.md deleted file mode 100644 index 6b770e82..00000000 --- a/docs/internal/hiring/head-of-product/RED-FLAGS.md +++ /dev/null @@ -1,22 +0,0 @@ -# Red flags - -Audience: INTERNAL_RESTRICTED - -Offer exhibit: yes - -A red flag in this table is a `STOP` on the current loop. The Founder may record why the loop ended. The Founder does not convert a red flag into a different title in order to continue. - -| ID | Signal | Why it stops the loop | -| --- | --- | --- | -| RF-1 | The candidate requires founder, co-founder, or technical co-founder in the title, the equity legend, or the public bio | Those titles are outside the offer | -| RF-2 | The candidate requires the CTO title, a date on which CTO will be granted, or automatic succession | CTO is not granted by this offer | -| RF-3 | The candidate treats `POSSIBLE` in the consideration line as a promise, an approval, or a default future | The full line is `POSSIBLE / UNDECIDED / NOT PROMISED / NOT APPROVED / NOT AUTOMATIC` | -| RF-4 | The candidate asks for the CTO framework stub to be attached, linked as a term, or described as part of the offer | The stub is a separate document and is not an exhibit | -| RF-5 | The candidate adds a mechanism, a price, a certification, or a proof claim that `docs/governance/canonical/product-boundary.md` does not state, and presents it as current | Claim discipline is a required scorecard criterion | -| RF-6 | The candidate supplies a statistic, a time-to-value, a cost reduction, or a performance figure that has no measurement path in the documents they were given | This package contains no such figure and does not authorize one | -| RF-7 | The candidate fills in the empty Founder Master Program responsibilities table and presents the fill as the program | That table is empty because the source text was absent | -| RF-8 | The candidate treats a compensation `TBD` cell as a quoted number, or invents a band | Every compensation cell is `TBD` | -| RF-9 | The candidate proposes publishing Phantom Engine customer material, credentials, or customer data from this hiring process | This package does not include that material and does not authorize publication | -| RF-10 | The candidate describes the role as authority to merge, publish, price, or bind a customer without a Founder checkpoint | Interim scope INT-3 requires that checkpoint | - -Red flags are about this offer. They are not a general character verdict, and they are not recorded in the public repository next to a person's name. diff --git a/docs/internal/hiring/head-of-product/ROLE-AND-RESPONSIBILITIES.md b/docs/internal/hiring/head-of-product/ROLE-AND-RESPONSIBILITIES.md deleted file mode 100644 index 23196a2e..00000000 --- a/docs/internal/hiring/head-of-product/ROLE-AND-RESPONSIBILITIES.md +++ /dev/null @@ -1,66 +0,0 @@ -# Role and responsibilities - -Audience: INTERNAL_RESTRICTED - -Offer exhibit: yes - -## Title - -| Field | Value | -| --- | --- | -| Allowed titles | Head of Product, or Head of Product Engineering | -| Titles selected per offer | One of the two. Chosen before the offer is sent. | -| Titles outside this offer | Founder. Co-founder. Technical co-founder. CTO. | -| CTO consideration line | `POSSIBLE / UNDECIDED / NOT PROMISED / NOT APPROVED / NOT AUTOMATIC` | -| Automatic CTO succession | Outside this offer | -| CTO framework | Separate document. Not attached. See `OFFER-BOUNDARY.md`. | - -The two allowed titles are alternative names for this one hire. They are not two seats, and they are not a path from one title into founder or CTO. - -## Founder Master Program responsibilities list - -WS13 requires this package to include the responsibilities list from the Founder Master Program. Retrieval on 2026-09-27: - -| Location | Result | -| --- | --- | -| `vantioai/vantio-open-core` at `5064f32f1cdfcb840dfd100e2ce5c712d046550d` | No Founder Master Program file | -| GitHub code search, `org:vantioai`, phrases "Founder Master Program", "Head of Product", "Head of Product Engineering" | No code matches | -| Linear documents | No document | -| Sibling Founder Force briefs available in this run (master control plane, WS1 Units B and C, WS2, WS3, WS3 P34, WS5, WS6, WS7, WS8, WS9, WS10, WS12) | Each brief is its own force. None contains a Head of Product responsibilities list. The master control plane names the Founder Master Program only as the source of category boundaries. | - -Status: `RESPONSIBILITIES_SOURCE_ABSENT` - -Copied list: - -| ID | Responsibility text from the Founder Master Program | -| --- | --- | -| — | None. The cell stays empty until the Founder supplies that program text and a later change pastes it here. | - -Do not interview a candidate against a list that is not in the table above. Do not fill the table from memory, from a model draft, or from a generic Head of Product description and then label the result as the Founder Master Program. - -## Duties the WS13 force does state - -These rows are copied from the WS13 force. They are role boundaries for the offer. They are not a substitute Founder Master Program list. - -| ID | Duty | Source | -| --- | --- | --- | -| WS13-1 | Hold exactly one of the allowed titles: Head of Product, or Head of Product Engineering. | WS13 force | -| WS13-2 | Keep founder, co-founder, and technical co-founder out of the title, the offer letter, and any equity legend in that offer. | WS13 force | -| WS13-3 | Keep CTO out of the offer. The consideration line is exactly `POSSIBLE / UNDECIDED / NOT PROMISED / NOT APPROVED / NOT AUTOMATIC`. | WS13 force | -| WS13-4 | Leave automatic CTO succession out of the offer. | WS13 force | -| WS13-5 | Leave the CTO evaluation framework off the offer. It is a separate future document. | WS13 force | - -## Interim operating scope - -Status: `INTERIM`. `NOT_FROM_FOUNDER_MASTER_PROGRAM`. - -This scope is how the company can use the hire before the missing program list is pasted. It is bounded by documents that already exist. It is not an invented product plan. - -| ID | Scope | Bound | -| --- | --- | --- | -| INT-1 | Keep external product sentences aligned with `docs/governance/canonical/product-boundary.md` on the base commit above. | A sentence that adds a mechanism, a price, or a proof the canonical file does not state is withheld. | -| INT-2 | Treat Optics, Phantom Engine, and Enterprise as the three commercial categories in that canonical file. Optics is free local-first observe. Phantom Engine is Enforce + Control on enrolled Linux hosts at the price stated there. Enterprise is governance on top of that protection and is talk-to-sales. | This package does not add a fourth commercial product. | -| INT-3 | Bring a Founder checkpoint before a change to a public claim, a published price, a release, or a customer commitment. | The hire does not hold that checkpoint alone. | -| INT-4 | Leave frozen release artifacts unchanged unless a later Founder force reopens them. At this base commit, `@vantio/cli` is `0.3.24` and `vantio-agent-sdk` is `3.1.0` in tree. | This hiring package does not reopen either artifact. | - -Canonical product facts used above were read from `docs/governance/canonical/product-boundary.md` and the package manifests on `5064f32f1cdfcb840dfd100e2ce5c712d046550d`. Phantom Engine customer manuals are out of scope for this package. diff --git a/docs/internal/hiring/head-of-product/SCORECARD.md b/docs/internal/hiring/head-of-product/SCORECARD.md deleted file mode 100644 index 1617acea..00000000 --- a/docs/internal/hiring/head-of-product/SCORECARD.md +++ /dev/null @@ -1,43 +0,0 @@ -# Scorecard - -Audience: INTERNAL_RESTRICTED - -Offer exhibit: yes - -Use this scorecard only with `ROLE-AND-RESPONSIBILITIES.md`. There is no Founder Master Program responsibilities list to score. Do not add criteria in the interview in order to fill that gap. - -Ratings: `STRONG` / `MIXED` / `NO` / `NOT_OBSERVED` - -A hire requires `STRONG` on S1, S2, and S3. Any `NO` on S1, S2, or S3 stops the loop. `MIXED` on S4 or S5 can continue only with a written Founder note. `NOT_OBSERVED` on a required criterion is not a pass. - -| ID | Criterion | What strong looks like | Required | -| --- | --- | --- | --- | -| S1 | Title fit | The candidate accepts one allowed title and can restate, unprompted, that founder, co-founder, technical co-founder, and CTO are outside the offer. They can read the CTO consideration line without turning it into a promise. | Yes | -| S2 | Offer boundary | The candidate can point to which documents are offer exhibits and can state that the CTO framework stub is not one of them. | Yes | -| S3 | Claim discipline | Given `docs/governance/canonical/product-boundary.md`, the candidate restates Optics, Phantom Engine, and Enterprise using that file. Added mechanisms, prices, and proof claims are absent from the restatement. | Yes | -| S4 | Written decision | The take-home memo names a decision, cites file paths, states what is unproved, and names a Founder checkpoint. It does not set a new price. | Yes | -| S5 | Frozen-artifact judgment | The candidate can say what they would leave unchanged on `@vantio/cli` `0.3.24` and why a hiring conversation does not reopen it. | Yes | -| S6 | Interim scope | The candidate treats INT-1 through INT-4 as interim and can say the Founder Master Program list is empty. | Yes | -| S7 | Compensation posture | The candidate treats every compensation cell as `TBD` and does not quote a number from this package. | Screen | - -## Score sheet - -| ID | Rating | Evidence (quote or file) | Interviewer | Date | -| --- | --- | --- | --- | --- | -| S1 | | | | | -| S2 | | | | | -| S3 | | | | | -| S4 | | | | | -| S5 | | | | | -| S6 | | | | | -| S7 | | | | | - -Loop result: `ADVANCE` / `STOP` / `FOUNDER_NOTE_REQUIRED` - -Founder note, if required: - -| Field | Value | -| --- | --- | -| Criterion | | -| Why the loop continues | | -| What must be true before an offer | | diff --git a/docs/internal/investor-demo-wave2/00-BOUNDARY.md b/docs/internal/investor-demo-wave2/00-BOUNDARY.md deleted file mode 100644 index 4ea27cfe..00000000 --- a/docs/internal/investor-demo-wave2/00-BOUNDARY.md +++ /dev/null @@ -1,44 +0,0 @@ -# Investor demo Wave 2 boundary - -Audience: INTERNAL_RESTRICTED - -Producer classification: `INVESTOR_DEMO_WAVE2_READY_FOR_COUNCIL` - -This classification means the branch is ready for a separate council. It is not a council verdict, not a customer demonstration, and not `PROVED_EXTERNAL`. - -## Locked input - -| Item | Value | -| --- | --- | -| Repository | `vantioai/vantio-open-core` | -| Starting commit | `89f95099d0dce463307eb75d78e7fcf2ef99feb2` | -| Design tip | `43cc35371e109e6a377cc31e4fd2438bfceea797` | -| Design merge | pull request #75, commit `62379ca40ee18d04dd24af815b13a32b84be4001` | -| CLI | `@vantio/cli@0.3.24`, not reopened | -| Founder beat text | `ABSENT`. B01–B18 stay the room sequence | -| Announcements | `HOLD` | - -## What this force writes - -- `packages/investor-demo-wave2/` — private runner, not a workspace member, not a published CLI -- `tests/investor-demo-wave2/` — direct and adversarial tests -- `docs/internal/investor-demo-wave2/` — this packet - -## What this force does not do - -- It does not edit `packages/vantio-cli` or any other published package. -- It does not bump, tag, publish, or announce. -- It does not run Phantom Engine, enroll a host, load a kernel program, or call a live provider. -- It does not write `LOCAL_OBSERVATION` or count a simulated row as customer activity. -- It does not write enforcement action tokens into a run file. -- It does not copy the design envelope into `~/.vantio/runs/`. -- It does not change the design directory under `docs/programs/production-readiness/demo/`. -- It does not merge. - -## Proof - -Every card carries a proof class from this set: `INTERNAL_FUNCTIONAL`, `SIMULATED_LABELED`, `NARRATED_BOUNDARY`, `OFFLINE_FALLBACK`, `HELD_NOT_EXECUTED`. - -Every card carries `external_proof` `NOT_PROVED_EXTERNAL`. Evidence tier and customer validation stay `UNSET`. - -`INVESTOR_DEMO_WAVE2_READY_FOR_COUNCIL` is assigned only after uninstall of the recorded demo home succeeds and the local verifier accepts the export. Visual completion does not assign it. `INVESTOR_DEMO_WAVE2_AWAITING_UNINSTALL` is the pre-uninstall classification when the other checks passed. A failed check is `INVESTOR_DEMO_WAVE2_BLOCKED`. diff --git a/docs/internal/investor-demo-wave2/01-INVENTORY.md b/docs/internal/investor-demo-wave2/01-INVENTORY.md deleted file mode 100644 index e1c38941..00000000 --- a/docs/internal/investor-demo-wave2/01-INVENTORY.md +++ /dev/null @@ -1,28 +0,0 @@ -# Inventory - -Audience: INTERNAL_RESTRICTED - -Read before implementation. Versions below were taken from this tree at `89f95099d0dce463307eb75d78e7fcf2ef99feb2`. - -## Design - -`43cc35371e109e6a377cc31e4fd2438bfceea797` is commit `43cc353` ("Revise the investor demo design after council needs-revision"). Pull request #75 merged it. The files under `docs/programs/production-readiness/demo/` still say the design producer classification `INVESTOR_DEMO_DESIGN_REVISION_READY_FOR_COUNCIL` and `wave2: NOT_AUTHORIZED`. This force treats that merged tip as the design to implement. It does not rewrite those files and does not convert their classification into a council pass. - -`founder_text` is `ABSENT` on B01–B18. This force keeps that sequence. The show list in the Wave 2 brief is the card set, not a replacement for the beats. - -`10-WAVE2-SCAFFOLD.md` requires a labeled demo writer, simulation labels on prove and discover totals, a fixed-id flag, a sentinel-scoped reset, and an F1 stop. It also says the labeled writer is a future CLI version, not a silent edit of 0.3.24. The standing order for this force says not to reopen CLI 0.3.24. The runner is that writer, outside the frozen package. - -## CLI - -`packages/vantio-cli/package.json` version is `0.3.24`. `demoCommand` writes hostname `optics-demo.invalid`, action `OBSERVED`, bytes 0, and no `evidence_origin`. `discover` prints an observed-locally count that includes that host. `prove --format=md` does not print `SIMULATED_DEMO`. Readers use `os.homedir()`, so `HOME` isolates them. Default `status` does not contact a registry. - -## Other sources used by cards - -| Card | Source in this tree | What the tree actually contains | -| --- | --- | --- | -| Coverage | `docs/products/optics/SUPPORTED-PATHS.md` | Unobserved paths are not blocked. This room does not start an agent. | -| Descendant authority | `docs/planning/enterprise-governance/02-E2-DELEGATED-AUTHORITY.md` | Planned records. No live grant store. `ACTIVE` requires a host report. | -| Health | `docs/planning/shared-health-vocabulary/HEALTH-VOCABULARY.json` | Catalog values include `degraded`, `observing`, and `not_enrolled`. | -| Optics observation | CLI `demo` | In-process stub. No network. | - -Phantom Engine is not in this repository. Enforcement, host enrollment, and cluster behavior are not executed. diff --git a/docs/internal/investor-demo-wave2/02-ARCHITECTURE.md b/docs/internal/investor-demo-wave2/02-ARCHITECTURE.md deleted file mode 100644 index 1b1983f7..00000000 --- a/docs/internal/investor-demo-wave2/02-ARCHITECTURE.md +++ /dev/null @@ -1,66 +0,0 @@ -# Architecture notes for council - -Audience: INTERNAL_RESTRICTED - -These are the producer's decisions. They are not a council verdict. - -## 1. CLI 0.3.24 stays frozen - -The labeled writer lives in `@vantio/investor-demo-wave2`. The frozen `demo` command is invoked as a subprocess when it is present and prints `0.3.24`. The runner does not patch its files. The CLI run file still has no `evidence_origin`. The wave2 envelope, stored at `.vantio/demo-session/labeled-envelope.json`, carries `evidence_origin` `SIMULATED_DEMO` and `producer` `demo_command`. That file has no `vantio_run_log` marker, so the frozen CLI does not treat it as a run. - -`producer_version` is `wave2-0.0.0`. It matches the architecture charset `[A-Za-z0-9._+-]` and the 32-character limit. The demo producer does not accept `LOCAL_OBSERVATION`. - -A fixed envelope trace id is `--trace-id` with the form `0x` plus 16 hex characters. A fixed timestamp is `--started-at` in UTC millisecond form. Those flags do not change the CLI file's trace id. - -## 2. Proof class on every card - -| Class | Meaning in this runner | -| --- | --- | -| `INTERNAL_FUNCTIONAL` | The check ran in this session and the result is in the export. | -| `SIMULATED_LABELED` | The row is a labeled simulation and was not applied as a product event. | -| `NARRATED_BOUNDARY` | The room states a document boundary. No event file was created for it. | -| `OFFLINE_FALLBACK` | The frozen CLI was not used. The committed fallback is labeled. | -| `HELD_NOT_EXECUTED` | The step has not run. Uninstall uses this until the demo home is removed. | - -`PROVED_EXTERNAL` and `CUSTOMER_VALIDATED` are not members of the class list. Every card sets `external_proof` to `NOT_PROVED_EXTERNAL`. - -## 3. Simulations - -A card with `is_simulation` true must use `SIMULATED_DEMO`, `NARRATED_BOUNDARY`, or `INJECTED_UNLABELED_SYNTHETIC`. `LIVE_LOCAL_OBSERVATION` is refused. Customer activity total is fixed at 0. The CLI sentence `observed locally` is stored as not a customer total. - -The banner is `SIMULATION — SIMULATED_DEMO — vantio demo — no network — not a customer call`. - -## 4. Cards - -| Card | What the session does | Proof class when the CLI ran | -| --- | --- | --- | -| Workload discovery | Scans the demo home. Simulated and unlabeled rows are excluded from the customer total. | `INTERNAL_FUNCTIONAL` | -| Optics observation | Runs `demo` once, or records the offline fallback. | `INTERNAL_FUNCTIONAL` | -| Coverage | Checks the supported-path rule that unobserved is not blocked. No agent is started. | `NARRATED_BOUNDARY` | -| Ingress and egress | Records one labeled egress stub. Opens no listener. Ingress is `NOT_OBSERVED`. | `SIMULATED_LABELED` | -| Policy proposal | Records a proposal and does not apply it. | `SIMULATED_LABELED` | -| Simulation | Writes the banner and the labeled envelope. | `INTERNAL_FUNCTIONAL` | -| Canary enforcement | Drops a privacy canary before storage. Writes no enforcement action. | `INTERNAL_FUNCTIONAL` | -| Allowed and blocked | Stores permit and deny shapes with `applied` false. Run files must not contain enforcement tokens. | `SIMULATED_LABELED` | -| Descendant authority | A fixture subset stays `PROPOSED`. A widening or redelegating child is `REFUSED`. `ACTIVE` is not set. | `INTERNAL_FUNCTIONAL` | -| Health degradation | Accepts `degraded` only when the WS4 catalog lists it. No host is enrolled. | `SIMULATED_LABELED` | -| Recovery | Session record returns to `observing`. Host state stays `not_enrolled`. | `INTERNAL_FUNCTIONAL` | -| Evidence export | Writes the labeled JSON export. It is not an HTML customer report. | `INTERNAL_FUNCTIONAL` | -| Revocation | Revokes the demo sentinel. Does not rotate a credential or a customer grant. | `INTERNAL_FUNCTIONAL` | -| Rollback | Returns policy to `ROLLED_BACK` and health to `not_enrolled`. Does not delete run files. | `INTERNAL_FUNCTIONAL` | -| Uninstall | Removes the recorded demo home. Refuses the operator home, the checkout, and a symlink. | `INTERNAL_FUNCTIONAL` after removal | -| Independent verification | Recomputes the export hash and the invariants in a second function. Council stays pending. | `INTERNAL_FUNCTIONAL` | - -When the CLI is missing, the version is not `0.3.24`, or `--offline` is set, discovery and observation use `OFFLINE_FALLBACK`. A CLI that runs and then fails the stub checks is `LIVE_DEVIATION`, and the export is `INVESTOR_DEMO_WAVE2_BLOCKED`. The fallback is not used to hide that deviation. - -## 5. F1 - -On request, the runner plants `0xinjectunlabeled01` after `discover`. The file has no `evidence_origin` and its host is not `optics-demo.invalid`. Disposition is `DISCARDED`. The runner does not prove it, does not add it to the customer total, and does not set a success narration. B16–B18 remain in the beat list, including `L-FOUNDER-BEATS-ABSENT`. Uninstall deletes the file with the demo home. - -## 6. Reset - -The sentinel records the demo home, the operator home, and the repository root. The demo home must be the `demo-home` child of a session directory under the OS temp directory. Uninstall deletes that directory and any new `vantio-proof-*.html` recorded for the session, except paths under the operator home. A second uninstall reports `already_removed` and does not delete the operator home. - -## 7. Readiness - -`visual_completion_counts` is false. The ready classification requires the invariant list to be empty and the uninstall card to be executed. The local verifier checks the canonical SHA-256. A mismatch or a classification that does not match the invariants fails the verifier. diff --git a/docs/internal/investor-demo-wave2/03-IMPLEMENTATION-REPORT.md b/docs/internal/investor-demo-wave2/03-IMPLEMENTATION-REPORT.md deleted file mode 100644 index ed81a5ed..00000000 --- a/docs/internal/investor-demo-wave2/03-IMPLEMENTATION-REPORT.md +++ /dev/null @@ -1,36 +0,0 @@ -# Implementation report - -Audience: INTERNAL_RESTRICTED - -Producer classification before council: `INVESTOR_DEMO_WAVE2_READY_FOR_COUNCIL` - -This classification means the branch is ready for a separate council. It is not a council verdict, not a merge, and not `PROVED_EXTERNAL`. - -## What landed - -Private package `@vantio/investor-demo-wave2` at `0.0.0-unstable-pre-1.0`. It is not in `pnpm-workspace.yaml`. Live CLI sources do not import it. - -The runner executes the sixteen cards in `02-ARCHITECTURE.md`, keeps B01–B18 with `founder_text` `ABSENT`, and writes a labeled export. CLI `@vantio/cli@0.3.24` is invoked and not modified. - -## Checks - -From the repository root: - -```sh -node --test tests/investor-demo-wave2/*.test.cjs -``` - -The producer run of that command reported 14 tests and 0 failures. The live test ran `status`, `demo` once, `prove --list`, `prove --run --format=md`, and `discover` against a temporary `HOME`. The offline test did not spawn the CLI. Adversarial tests covered the unlabeled discard, operator-home refusal, checkout refusal, symlink refusal, forged sentinel, origin and trace refusal, widening authority, unknown health state, revocation, enforcement-token scan, and a rewritten external-proof field. - -`node docs/scripts/check-docs-release.mjs` returned `ok: false` with one failure: `legacy-stale-name-inventory-frozen` reports `tests/shared-health-vocabulary/collision.test.cjs` as a new stale-name file. That file is already on the starting commit. This branch does not add it and does not edit the frozen inventory. The other release checks passed. This report does not claim a registry check. - -## Hard-stop attestations - -- No CLI, Python SDK, or Node SDK source change, and no version bump. -- No publish, tag, npm release, PyPI release, or announcement. Announcement field is `HOLD`. -- No live provider call, Phantom Engine enrollment, kernel program, or cluster drill. -- No customer total for simulated or unlabeled rows. -- No `PROVED_EXTERNAL` and no `CUSTOMER_VALIDATED`. -- Design files under `docs/programs/production-readiness/demo/` are unchanged. -- Draft pull request only. Not marked ready. Not merged. -- Council is a separate agent. This producer did not run it. diff --git a/docs/internal/investor-demo-wave2/04-COUNCIL-SLOT.md b/docs/internal/investor-demo-wave2/04-COUNCIL-SLOT.md deleted file mode 100644 index d610caed..00000000 --- a/docs/internal/investor-demo-wave2/04-COUNCIL-SLOT.md +++ /dev/null @@ -1,21 +0,0 @@ -# Council slot - -Audience: INTERNAL_RESTRICTED - -Status: `PENDING_INDEPENDENT_COUNCIL` - -Producer classification: `INVESTOR_DEMO_WAVE2_READY_FOR_COUNCIL` - -This file does not fill a verdict, a seat table, or a pass token. A later council replaces it or appends its own report. - -## Questions - -1. Is keeping B01–B18 with `founder_text` `ABSENT` acceptable for this implementation, given that the Founder Master Program text is still not in the tree? -2. Is a private runner outside `@vantio/cli@0.3.24` the right place for the labeled writer the scaffold described? -3. Do the five proof classes state the room honestly, including `OFFLINE_FALLBACK` and `SIMULATED_LABELED` for steps this repository cannot execute as product events? -4. Does the local recompute stay clearly short of `PROVED_EXTERNAL`? -5. Does uninstall's refusal of the operator home, the checkout, and a symlink match the reset outline? - -## Producer attestation - -The producer did not sit this council. Announcements stay `HOLD`. CLI 0.3.24 stays frozen. diff --git a/docs/internal/investor-demo-wave2/WAVE2-MANIFEST.json b/docs/internal/investor-demo-wave2/WAVE2-MANIFEST.json deleted file mode 100644 index 83808b07..00000000 --- a/docs/internal/investor-demo-wave2/WAVE2-MANIFEST.json +++ /dev/null @@ -1,107 +0,0 @@ -{ - "schema": "vantio.investor-demo.wave2-manifest/v1", - "audience": "INTERNAL_RESTRICTED", - "producer_classification": "INVESTOR_DEMO_WAVE2_READY_FOR_COUNCIL", - "council_status": "PENDING_INDEPENDENT_COUNCIL", - "external_proof": "NOT_PROVED_EXTERNAL", - "announcement": "HOLD", - "design_tip": "43cc35371e109e6a377cc31e4fd2438bfceea797", - "base_commit": "89f95099d0dce463307eb75d78e7fcf2ef99feb2", - "files": [ - { - "path": "docs/internal/investor-demo-wave2/00-BOUNDARY.md", - "sha256": "50b473894b771d85ec6d3df58af0e1fc2e47e4b29049b0b80b34366d18a21e0f", - "bytes": 2175 - }, - { - "path": "docs/internal/investor-demo-wave2/01-INVENTORY.md", - "sha256": "9a5361a3ce7e918a837fc261bbc02e68b8ac065f282f4f10719c2441a05c53ba", - "bytes": 2327 - }, - { - "path": "docs/internal/investor-demo-wave2/02-ARCHITECTURE.md", - "sha256": "67d354aea358d230aac0a80dd6baaea1ed95f2be3ea1ff6dfe5e3b9f023ace75", - "bytes": 5553 - }, - { - "path": "docs/internal/investor-demo-wave2/03-IMPLEMENTATION-REPORT.md", - "sha256": "6195e3a9b6b6654a7d8cfa7ff0b75642cfaa34d6ad8461953eaa9a75e7051f4e", - "bytes": 2207 - }, - { - "path": "docs/internal/investor-demo-wave2/04-COUNCIL-SLOT.md", - "sha256": "7029603cd0a40fdc6c37de8ae1de9b2e0ceb5a0e1f243d4a28985de2fb3dc258", - "bytes": 1017 - }, - { - "path": "packages/investor-demo-wave2/README.md", - "sha256": "d39f77aa1add5b0aa3a44cb6c18cc0557672a2a948d0c09b3c8a995ffaa80a76", - "bytes": 699 - }, - { - "path": "packages/investor-demo-wave2/bin/investor-demo.cjs", - "sha256": "9a72349355c200a07e6b187c0fdd0eabc158e4ea9ca57c1bb2ff1f10ed429868", - "bytes": 2200 - }, - { - "path": "packages/investor-demo-wave2/package.json", - "sha256": "493df290abe3711bd08352e9f5c9fd30f5be776e6773af611f44c1e630242644", - "bytes": 569 - }, - { - "path": "packages/investor-demo-wave2/src/canonical.cjs", - "sha256": "639779d8cda6993038d49e15fb443245526c344b3658be98ee4c4fce195532a4", - "bytes": 848 - }, - { - "path": "packages/investor-demo-wave2/src/cli-probe.cjs", - "sha256": "b7ff846b606745500b6e8bbec82675cd48c6d6401d42c752abab129762138609", - "bytes": 7152 - }, - { - "path": "packages/investor-demo-wave2/src/constants.cjs", - "sha256": "3ba50fa0cd4af33bb9579e5bbb365d8834c07e0be1fcc49554e7c2c34dff33c2", - "bytes": 3406 - }, - { - "path": "packages/investor-demo-wave2/src/index.cjs", - "sha256": "88b16eff7e740cbdd0150efeaf2908ca06b330a6b9e4c41f8747b53a34bec4aa", - "bytes": 609 - }, - { - "path": "packages/investor-demo-wave2/src/model.cjs", - "sha256": "516e2ce03e3c3eccef91074ecbd84ba4137fa8c79620162bf023c995962a09e9", - "bytes": 5207 - }, - { - "path": "packages/investor-demo-wave2/src/report.cjs", - "sha256": "2cecc30193120bdc2d550aa3b7228ab1c8af0d2fefb8a1391a722ea18f3b21c0", - "bytes": 845 - }, - { - "path": "packages/investor-demo-wave2/src/safety.cjs", - "sha256": "b7b6b1fb4ccd14491040d4c1dad786a77a07e94b074664ef559240713d5e5989", - "bytes": 7033 - }, - { - "path": "packages/investor-demo-wave2/src/session.cjs", - "sha256": "48dec26c87560b83deb68fdf4542e6f4bc4c54bb781eda3c57316a34b28e993d", - "bytes": 25422 - }, - { - "path": "packages/investor-demo-wave2/src/verify.cjs", - "sha256": "f5195ab019554c23b768a2512121c95479098954aabd5538e0995a6b2cb83df7", - "bytes": 6382 - }, - { - "path": "tests/investor-demo-wave2/adversarial.test.cjs", - "sha256": "fcfe2248a477bb6b119462cabdf8de694fae6e478ab4f94b9a6ae6265274add9", - "bytes": 9714 - }, - { - "path": "tests/investor-demo-wave2/direct.test.cjs", - "sha256": "074470212ee5594ee36dcadd06bfa6668c2aff65b58ecc032b0cdc16e62183c3", - "bytes": 7631 - } - ] -} diff --git a/docs/internal/optics-best-in-class-roadmap.md b/docs/internal/optics-best-in-class-roadmap.md deleted file mode 100644 index f7916e36..00000000 --- a/docs/internal/optics-best-in-class-roadmap.md +++ /dev/null @@ -1,1006 +0,0 @@ -# Optics best-in-class roadmap - -Internal planning capture only. This document does not authorize implementation, a release, a tag, a seal, or a publish. It makes no public claim. It assigns no dates and no timelines. - -Out of scope for this capture: `packages/vantio-cli` (frozen at 0.3.24, LIVE_AND_CLIENT_PROVED) and the in-progress Python 3.1.0 diagnostic model work (PR #53). - -**Planning sequence (no dates):** Foundational → Operational maturity → Product experience → Later strategic decisions. This order is planning language only. It does not promise delivery. - -**Planning note (no dates):** After this addendum, stop expanding feature categories and turn the roadmap into a traceable architecture. Best-in-class sequence: Evidence and privacy → Storage integrity and migration → Correlation and query → Diagnostics and self-observability → Performance and overload proof → Local UI → Trends, alerts, interoperability → Independent customer validation. This order is planning language only. It does not promise delivery. - -## Section 1 — Data architecture - -**FOUNDATIONAL.** Highest priority. Sequence this section before other roadmap items. - -1. Local storage backend migration from per-run JSON files to an embedded local store (e.g., SQLite), keeping JSON as the export/proof format only. Rationale: current design does not scale to real customer call volume; search/tail/diff currently require file scanning. -2. Retention and pruning policy: - - `vantio config set retention.max-age ` - - `vantio config set retention.max-size ` - - `vantio prune --dry-run` / `vantio prune` - - Must default to unbounded retention unless the customer configures a limit (never silently delete evidence). - -## Section 2 — Correlation and analysis - -**FUTURE.** - -3. Session/workflow grouping: allow multiple related calls to be correlated under one parent session/run identifier distinct from a single call's trace ID. Design the schema change required; do not implement. -4. Cross-run trend/comparison command (e.g., `vantio trends --since=`) showing error-rate and duration drift over time using only already-stored structural metadata (never inspecting content). -5. Usage/cost metadata: investigate whether token/usage fields are exposed by supported providers in structural response metadata (not body content inspection). Requires an explicit separate product decision before any implementation — design memo on feasibility and privacy boundary only. - -## Section 3 — Local visual surface - -**FUTURE, STRATEGIC.** - -6. A fully local, localhost-only, read-only web UI (`vantio ui`) rendering the same on-disk evidence: timeline, session grouping, filters. No account, no cloud, no external network. Highest-leverage "feels mature" item; own dedicated future release — not folded into CLI or Python patch releases. - -## Section 4 — CLI ergonomics - -**FUTURE, LOW RISK, SMALL SCOPE EACH.** - -7. Confirm and document `NO_COLOR` / `--no-color` support across all commands. -8. Shell completion: `vantio completion bash|zsh|fish`. -9. `vantio legend` explaining every status glyph/color/label. -10. Pager-awareness for long tail/search (`$PAGER`, `--no-pager`). -11. `--quiet` mode distinct from `--json` (exit code only). - -## Section 5 — Coverage transparency - -**FUTURE.** - -12. `vantio status --coverage`: list every currently supported HTTP client/provider on this runtime, and explicitly state what is not covered. - -## Section 6 — Security hard gates - -Schedule with real priority. Not implemented in this capture. - -13. Metadata redaction test suite: fixtures with tokens in headers/query strings; assert persisted record NEVER contains them. Same severity class as prompt/completion non-storage; release-blocking when implemented. -14. Fail-open reliability gate: prove if Optics write/observation path throws or is killed mid-run, wrapped app output/behavior is byte-identical to running without Optics. Document target max per-call overhead (e.g. "<5ms p99") to validate once implemented. - -## Section 7 — Compatibility and documentation - -**FUTURE.** - -15. Versioned config file (e.g. `vantio.config.json`) as alternative to flags/env for redaction, retention, telemetry defaults. -16. Documented flag/schema deprecation policy once JSON schema exits unstable-pre-1.0. -17. Generated single reference (e.g. `vantio help --all`) so `--help` and public docs cannot drift. -18. Runnable multi-agent example repository for prospective customers. - -Sections 8–22 are roadmap and design only. None of these items is claimed to exist. - -## Section 8 — Cardinality and resource governance - -- Indexed-field allowlist -- Cardinality budgets -- Maximum local write rate and queue size -- Database-size limits -- Explicit overflow and dropped-record evidence -- Query-cost limits -- No silent evidence loss - -## Section 9 — Database integrity and migrations - -- Versioned transactional schema migrations -- Pre-migration backup -- Migration dry run -- Integrity checks -- Interrupted-migration recovery -- Newer-schema refusal or bounded read-only fallback -- No silent empty-database recreation -- Rollback compatibility tests - -## Section 10 — Proof and operational-store separation - -- SQLite is the searchable operational index -- JSON proof remains portable, hashable, scoped, and independently verifiable -- No claim of tamper-proofing or notarization without external proof -- Retention and compaction must not alter previously exported proof artifacts - -## Section 11 — Trace, session, and process correlation - -Design fields for: - -- run_id -- trace_id -- span_id -- parent_span_id -- session_id -- process_id -- parent_process_id - -Require concurrency, async, thread, child-process, retry, and context-conflict tests before implementation is considered complete. - -## Section 12 — Sampling and overload - -- Define unsampled default behavior -- Define queue-full and burst behavior -- If sampling is ever introduced, record policy and coverage explicitly -- Preserve error, slow-call, and proof-critical evidence under a future policy -- Never display sampled evidence as complete - -## Section 13 — Clock and event ordering - -- UTC canonical timestamps -- Monotonic duration measurement -- Customer-selected display timezone later -- Clock-rollback and DST tests -- No negative durations -- Stable tied-timestamp ordering -- No causal claims based only on timestamp proximity - -## Section 14 — Optics self-observability - -Diagnostic metrics: - -- hooks installed -- events received -- events persisted -- events rejected/dropped -- write/query latency -- database size -- last successful write -- integrity state -- formatter failures -- migration state -- redaction failures -- schema version - -Hard rule: Optics internal diagnostics must not recursively appear as customer AI activity. - -## Section 15 — Bounded query contract - -- One query model shared by CLI, local UI, and structured output -- Filters for provider, destination, status, fault domain, coverage, time, duration, process, session, trace, freshness, and HTTP status -- No arbitrary SQL exposure -- Saved views store queries, not duplicate evidence - -## Section 16 — Alerting architecture decision - -- Do not silently add a daemon -- Evaluate run-time, post-run, external-scheduler, and explicit-service options -- Define trigger evidence, window, freshness, deduplication, recovery, severity, and safe remediation -- Privacy invariant and evidence-write failures are highest-severity candidates - -## Section 17 — Local indicators, not invented SLOs - -Potential indicators: - -- observed-call success -- latency percentiles -- provider-error rate -- evidence-write success -- evidence freshness -- partial/unknown/unavailable rate - -Do not label any objective as an SLO until the customer configures one. - -## Section 18 — Local UI truth contract - -Require explicit UI states for: - -- first run -- healthy -- honest idle -- not attached -- partial coverage -- stale evidence -- sampled evidence -- migration required -- database corruption -- privacy failure -- unsupported client -- mixed outcomes -- no results -- historical-only data - -Every material view must show status, scope, time range, freshness, evidence source, version, limitation, and completeness. - -Require keyboard navigation, contrast, reduced motion, color-independent status, responsive layouts, copyable local deep links, UTC-preserving timezone display, localhost-only binding, and read-only first release. - -## Section 19 — Portability and provenance - -Design future export/import/backup/restore behavior: - -- imported evidence cannot masquerade as locally observed -- duplicate handling -- schema compatibility -- source-machine provenance -- no secrets -- no silent overwrite -- config inclusion separately controlled - -## Section 20 — Evidence origin - -Add design values: - -- LOCAL_OBSERVATION -- SIMULATED_DEMO -- IMPORTED -- TEST_FIXTURE - -Demo and fixture evidence must be excluded from operational trends by default. - -## Section 21 — Release and upgrade posture - -- No background auto-update -- Explicit version and integrity inspection -- Release-channel visibility -- Schema compatibility -- rollback compatibility -- security-update visibility -- registry check only when explicitly requested - -## Section 22 — Customer annotations - -- Customer may name or annotate runs -- Annotation is stored separately -- Annotation never mutates original observation evidence -- UI must visibly distinguish observed evidence from customer-entered context - -## Section 23 — Complete observability requirement matrix - -Roadmap and design only. None of these requirements is claimed to exist. None is marked implemented. Status for every item in this section is TARGET_DESIGN. - -1. Signal contract: traces, metrics, logs/events, context/baggage, external profiles, and what Optics intentionally does not collect. -2. Semantic-convention conformance: upstream version, implemented fields, intentional omissions, Optics-specific extension namespace, schema identity, compatibility handling, and tests. -3. Context-propagation security: sensitive baggage prohibition, allowlists, size limits, imported-context provenance, malformed context, replay, collision, and trust classification. -4. Resource identity: service/application, environment, deployment version, runtime, process, host and container identity with privacy-safe provenance and conflict handling. -5. Observed dependency topology: current/historical edges, first/last seen, partial coverage, simulated-data exclusion, and no ownership inference from names alone. -6. Baselines: transparent deterministic baselines for call volume, destinations, latency, errors, retries, unknown outcomes, and coverage changes. -7. Deduplication and idempotency: stable event identity, duplicate markers, repeat-safe import, multi-hook detection, and no duplicate inflation of metrics. -8. Instrumentation conflicts: coexistence with OpenTelemetry/APM/provider SDK instrumentation, duplicate hooks, wrapper order, and multiple Optics copies. -9. Data-quality dimensions: coverage, freshness, completeness, integrity, correlation, and privacy checks; no misleading aggregate percentage. -10. Golden signals: call rate, error rate, duration, in-progress work, retries, queue depth, dropped records, write latency, unknown outcomes, and coverage gaps. -11. Cardinality-safe metric model: no trace/run/session IDs or arbitrary URLs in metric labels; high-cardinality identifiers remain in events/traces. -12. Exemplars: trend/chart drill-down to representative local runs and traces. -13. Sampling correction: exact versus estimated counts, sampling probability, mixed-policy periods, proof disclosure, and policy-change markers. -14. Performance budgets: startup, initialization, per-call overhead, memory, write latency, queue, query, UI, export, and shutdown flush, measured by percentiles. -15. Graceful degradation: application continues under queue saturation or storage failure; incomplete evidence is disclosed; no recursive drop-notice storms. -16. Crash consistency: normal exit, signals, power loss, sleep/resume, interpreter shutdown, interrupted streams, and queued writes; COMPLETE/PARTIAL/INTERRUPTED/ABANDONED/RECOVERED states. -17. Local security: filesystem permissions, Windows ACLs, Unix modes, multi-user workstation boundaries, symlink defense, imported-evidence quarantine, and optional at-rest-encryption feasibility. -18. Local UI security: loopback-only binding, no third-party assets/analytics, CSP, origin restrictions, CSRF defense, output escaping, no query-string secrets, no mutation endpoints in v1, explicit shutdown, and no persistent daemon. -19. Accessibility: screen readers, keyboard flow, focus, non-color status, contrast, reduced motion, text scaling, narrow viewports, ASCII fallback, and terminal width. -20. Destination normalization: case, ports, IPv4/IPv6, redirects, proxies, regional hosts, and query-string exclusion by default. -21. Provider identity confidence: provenance of provider/model identity and no unsupported inference. -22. Privacy corpus: allowlisting before persistence, encoded/nested secrets, URLs, credentials, PII, financial/health indicators, Unicode bypass testing, and release-blocking invariant failures. -23. Local data operations: selective deletion, backup implications, import provenance, retention proof, and no unsupported compliance claims. -24. Automation contract: read-only local API/CLI schema, pagination, sorting, time bounds, error objects, cancellation, query limits, schema negotiation, and localhost-only default. -25. Export formats: JSON/JSONL, simple tabular export, future OTLP/SIEM feasibility, integrity manifest, filters/time range, schema version, completeness, sampling, and redaction metadata. -26. Incident workflow: detect, scope, investigate, explain, export, remediate, and verify recovery. -27. Alert lifecycle: active, acknowledged, silenced, resolved, deduplication, maintenance windows, evidence retention, recovery notices, and honest idle handling. -28. SLI/SLO separation: Optics-product-health SLIs separate from observed-workload provider SLIs; no SLO claim until customer target and window are configured. -29. Cross-platform matrix: Windows/WSL, Linux, macOS if supported, containers, CI, proxies, TLS interception, IPv6, offline, locale, and restrictive filesystem cases. -30. Upgrade and rollback: old/new record compatibility, interrupted migration, safe rollback, mixed CLI/Python versions, future schema refusal, and export/import testing. -31. Product telemetry separation: customer evidence versus optional Vantio telemetry, explicit destinations, fields, triggers, frequency, last result, and disable precedence. -32. Documentation operability: executable quickstarts, fixture-generated output, versioned docs, flag parity, known issues, migration notes, and remediation anchors. -33. Support/security operations: vulnerability disclosure, supported-version policy, safe issue templates, support bundle, severity model, release advisories, integrity checks, and rollback guidance. -34. Independent customer acceptance: persona matrix and adversity scenarios covering errors, coverage gaps, concurrency, migration, privacy, rollback, uninstall, and portability. - -## Requirement traceability template - -Applies to every roadmap item in Sections 1–23. No item in this document is marked implemented. Every item remains TARGET_DESIGN. - -- Requirement ID -- Customer problem -- Scope -- Evidence required -- Test required -- Privacy classification -- Failure behavior -- UI state -- CLI state -- Structured state -- Documentation -- Release gate -- Current evidence tier -- Required closing tier -- Independent verifier -- Stranger-host -- Customer-validation -- Status: TARGET_DESIGN / INTERNAL_PROOF / PROVED_EXTERNAL / CUSTOMER_VALIDATED - -Counted from numbered items in this document: Sections 1–7 contain 18 numbered requirements, and Section 23 contains 34 numbered requirements. Each of those 52 numbered requirements has status TARGET_DESIGN. Sections 8–22 are unnumbered design bullets and remain TARGET_DESIGN; this document does not give them a separate numeric total. - -Current evidence tier, required closing tier, independent verifier, stranger-host, and customer-validation are unset for every item. No item is assigned UNIT_PROVED, INTEGRATION_PROVED, STRANGER_HOST_PROVED, PROVED_EXTERNAL, or CUSTOMER_VALIDATED. Requirement status and evidence tier are different fields. INTERNAL_PROOF is a requirement-status value, not an evidence tier, and it must not be displayed as CUSTOMER_VALIDATED. - -## Governance — separation of layers - -These governance sections are design controls. They do not delete Sections 1–23. They do not mark any item implemented or complete. They do not reopen CLI 0.3.24. They do not add Python 3.1.0 implementation scope. - -- Requirement: Sections 1–23. Status of every requirement remains TARGET_DESIGN. -- Architecture: the dependency graph, budget categories, and threat-model linkage below. Numeric budget targets are NOT_SET. -- Implementation: not authorized by this document. -- Proof: the acceptance evidence hierarchy below. No evidence tier is assigned. -- Release: release-gate fields are unset. This document does not authorize a release. -- Customer validation: a defined evidence tier that no item has reached. - -## Governance — requirement dependency graph - -Dependency relationships only. No dates. No delivery promise. Every workstream remains TARGET_DESIGN. - -Local UI (Section 3 and Section 18) depends on all of the following before it can be treated as a coherent workstream: operational storage, schema migration, bounded query contract, evidence-origin model, privacy policy, local UI security model, and freshness/completeness semantics. - -### Operational storage - -Section 1, item 1. - -- Prerequisites: none inside this roadmap. This workstream is foundational. -- Downstream dependents: retention and pruning, schema migration, proof separation, bounded query, correlation, local UI, trends, export, and self-observability. -- Incompatible parallel work: keeping per-run JSON file scanning as the long-term search, tail, and diff store. JSON remains the export and proof format only. -- Migration dependency: the store change is the migration this graph sequences before UI and query. -- Privacy dependency: retention defaults stay unbounded unless the customer sets a limit. -- Schema dependency: versioned schema before readers depend on the store. -- UI dependency: Local UI reads this store and does not replace it. -- Validation dependency: integrity checks and crash-consistency states. - -### Retention and pruning - -Section 1, item 2. - -- Prerequisites: operational storage; unbounded retention unless the customer configures a limit. -- Downstream dependents: database-size budget, local data operations, proof separation. -- Incompatible parallel work: silent deletion of evidence; compaction that changes a previously exported proof artifact. -- Migration dependency: prune behavior has to follow the active schema. -- Privacy dependency: never silently delete evidence. -- Schema dependency: retention limits are configuration, not a rewrite of exported proof. -- UI dependency: a prune result has to be visible as an explicit evidence state. -- Validation dependency: `vantio prune --dry-run` before a destructive prune. - -### Schema migration and database integrity - -Section 9 and Section 23, item 30. - -- Prerequisites: operational storage. -- Downstream dependents: bounded query, local UI, upgrade and rollback, export and import. -- Incompatible parallel work: silent empty-database recreation; a UI built on an unversioned store; rollback onto a privacy-weaker schema. -- Migration dependency: versioned transactional migrations, pre-migration backup, dry run, interrupted-migration recovery, and newer-schema refusal or bounded read-only fallback. -- Privacy dependency: rollback compatibility includes the privacy invariants, not only row shape. -- Schema dependency: mixed CLI and Python readers refuse or stay read-only when the schema is newer. -- UI dependency: explicit “migration required” and “database corruption” states. -- Validation dependency: rollback compatibility tests and interrupted-migration tests. - -### Proof and operational-store separation - -Section 10. - -- Prerequisites: operational storage. -- Downstream dependents: export, retention, portability. -- Incompatible parallel work: treating the operational index as notarized or tamper-proof without external proof; retention or compaction that alters previously exported proof. -- Migration dependency: proof artifacts stay stable across store migrations. -- Privacy dependency: proof export carries redaction metadata and does not add secrets. -- Schema dependency: proof schema identity is independent of the operational index. -- UI dependency: the UI shows evidence source and does not present the index as the proof artifact. -- Validation dependency: exported proof remains hashable and independently verifiable after retention. - -### Privacy policy - -Section 6, items 13 and 14, and Section 23, items 22 and 31. - -- Prerequisites: none. The redaction invariant is release-blocking when the work is implemented. This document does not implement it. -- Downstream dependents: storage, query, local UI, export, import, product-telemetry separation, and annotations. -- Incompatible parallel work: persisting tokens from headers or query strings; inspecting body content for usage or cost; mixing optional Vantio telemetry with customer evidence. -- Migration dependency: rollback and a newer schema cannot weaken an existing privacy invariant. -- Privacy dependency: allowlisting before persistence. -- Schema dependency: persisted records exclude non-allowlisted secrets. -- UI dependency: Local UI depends on this policy; privacy failure is an explicit UI state. -- Validation dependency: metadata redaction fixtures and the privacy corpus, including encoded and nested secrets. Usage and cost metadata still requires a separate product decision before any implementation. - -### Evidence-origin model - -Section 20. - -- Prerequisites: a schema field for origin. -- Downstream dependents: trends, UI truth contract, import, baselines, and customer-validation evidence. -- Incompatible parallel work: counting SIMULATED_DEMO or TEST_FIXTURE in operational trends by default; letting IMPORTED masquerade as LOCAL_OBSERVATION. -- Migration dependency: origin survives schema migration and import. -- Privacy dependency: import carries no secrets. -- Schema dependency: design values are LOCAL_OBSERVATION, SIMULATED_DEMO, IMPORTED, and TEST_FIXTURE. -- UI dependency: Local UI depends on this model and shows evidence source. -- Validation dependency: trend queries exclude demo and fixture evidence. This document sets no exception. - -### Correlation schema - -Section 2, item 3, and Section 11. - -- Prerequisites: operational storage schema. -- Downstream dependents: session grouping in the local UI, trends, and exemplars. -- Incompatible parallel work: using one call’s trace ID as the parent session or run identifier. -- Migration dependency: adding session and process fields is a schema change and stays design-only here. -- Privacy dependency: correlation IDs are not metric labels. -- Schema dependency: run_id, trace_id, span_id, parent_span_id, session_id, process_id, and parent_process_id. -- UI dependency: session grouping waits on this schema. -- Validation dependency: concurrency, async, thread, child-process, retry, and context-conflict tests are required before implementation is considered complete. Those tests are not recorded here. - -### Bounded query contract - -Section 15 and Section 23, item 24. - -- Prerequisites: operational storage, evidence-origin model, and freshness/completeness semantics. -- Downstream dependents: CLI, local UI, structured output, saved views, and the automation contract. -- Incompatible parallel work: arbitrary SQL exposure; saved views that duplicate evidence. -- Migration dependency: queries target the versioned store. -- Privacy dependency: filters do not require content inspection. -- Schema dependency: one query model for CLI, local UI, and structured output. -- UI dependency: Local UI depends on this contract. -- Validation dependency: pagination, sorting, time bounds, cancellation, and query limits. - -### Freshness and completeness semantics - -Sections 12, 13, 17, and 18, and Section 23, items 9 and 13. - -- Prerequisites: clock and ordering rules, sampling-policy recording, and evidence origin. -- Downstream dependents: UI states, trends, alerts, and baselines. -- Incompatible parallel work: displaying sampled evidence as complete; causal claims from timestamp proximity alone; labeling an objective as an SLO before the customer configures a target and window. -- Migration dependency: ordering rules apply to records read after a migration. -- Privacy dependency: completeness checks do not read body content. -- Schema dependency: sampling policy, coverage, and clock fields are explicit. -- UI dependency: Local UI depends on these semantics. Stale, sampled, partial, unknown, and unavailable stay explicit states. -- Validation dependency: clock-rollback, DST, negative-duration, and tied-timestamp tests. - -### Local UI security model - -Section 23, item 18. - -- Prerequisites: privacy policy. -- Downstream dependents: Local UI. -- Incompatible parallel work: non-loopback binding, third-party assets or analytics, mutation endpoints in the first release, a persistent daemon, or secrets in query strings. -- Migration dependency: the UI refuses or discloses a store that requires migration. -- Privacy dependency: output escaping and no query-string secrets. -- Schema dependency: the UI reads the bounded query contract and does not invent a second schema. -- UI dependency: Local UI depends on this model. -- Validation dependency: binding, origin, CSRF, escaping, and shutdown checks. Those checks are not recorded here. - -### Local UI - -Section 3, Section 18, and Section 23, item 19. - -- Prerequisites: operational storage, schema migration, bounded query contract, evidence-origin model, privacy policy, local UI security model, and freshness/completeness semantics. -- Downstream dependents: exemplar drill-down, incident-workflow views, and display of customer annotations. -- Incompatible parallel work: folding this UI into a CLI patch release or a Python patch release; shipping the UI before the prerequisites above; a read-write first release. -- Migration dependency: schema migration, listed above. -- Privacy dependency: privacy policy, listed above. -- Schema dependency: bounded query contract and evidence origin, listed above. -- UI dependency: truth-contract states, accessibility, localhost-only binding, and read-only first release. -- Validation dependency: every material view shows status, scope, time range, freshness, evidence source, version, limitation, and completeness. A healthy screen is not proof. - -### Cardinality, queue, and overload - -Sections 8 and 12, and Section 23, items 11 and 15. - -- Prerequisites: operational storage. -- Downstream dependents: the metric model, self-observability, graceful degradation, and the budget ledger. -- Incompatible parallel work: metric labels that contain trace, run, or session IDs, or arbitrary URLs; silent evidence loss. -- Migration dependency: cardinality limits apply to the versioned store. -- Privacy dependency: high-cardinality identifiers stay in events and traces, not in metric labels. -- Schema dependency: indexed-field allowlist and overflow records. -- UI dependency: sampled or partial evidence stays labeled. -- Validation dependency: queue-full, burst, and dropped-record evidence. - -### Self-observability - -Section 14. - -- Prerequisites: operational storage and privacy policy. -- Downstream dependents: diagnostics for write latency, database size, integrity, migration, redaction, and schema version. -- Incompatible parallel work: Optics internal diagnostics appearing as customer AI activity. -- Migration dependency: migration state is a diagnostic, not a customer trace. -- Privacy dependency: redaction failures are diagnostics. -- Schema dependency: schema version is reported separately from customer spans. -- UI dependency: diagnostics must not be rendered as customer activity. -- Validation dependency: a recursion check that internal diagnostics are excluded from customer activity. - -### Alerting architecture - -Section 16 and Section 23, item 27. - -- Prerequisites: bounded query, freshness and completeness, evidence origin, and privacy policy. -- Downstream dependents: incident workflow. -- Incompatible parallel work: silently adding a daemon. -- Migration dependency: alerts read the versioned store and honor freshness. -- Privacy dependency: privacy-invariant failure is a highest-severity candidate. -- Schema dependency: alert state is not a second copy of evidence. -- UI dependency: any future surface uses the local UI truth contract. No surface is selected here. -- Validation dependency: the architecture decision among run-time, post-run, external-scheduler, and explicit-service options. The decision is not made in this document. - -### Trends and baselines - -Section 2, item 4, Section 17, and Section 23, items 6 and 12. - -- Prerequisites: operational storage, structural metadata only, evidence origin, and sampling disclosure. -- Downstream dependents: exemplars. -- Incompatible parallel work: inspecting body content; including demo or fixture evidence in operational trends by default. -- Migration dependency: baselines read records that survived migration without treating import as local observation. -- Privacy dependency: structural metadata only. -- Schema dependency: origin, sampling, and coverage fields. -- UI dependency: charts drill down to representative local runs and traces. -- Validation dependency: exact versus estimated counts stay distinct. - -### Usage and cost metadata - -Section 2, item 5. - -- Prerequisites: an explicit separate product decision, and structural response metadata only. -- Downstream dependents: none until that decision exists. -- Incompatible parallel work: implementing this item from this roadmap; inspecting body content. -- Migration dependency: none until a decision exists. -- Privacy dependency: the privacy boundary is part of the design memo, which is not written here. -- Schema dependency: unset until a decision exists. -- UI dependency: none until a decision exists. -- Validation dependency: feasibility and privacy memo only. - -### Portability, export, and import - -Sections 10 and 19, and Section 23, item 25. - -- Prerequisites: proof separation, evidence origin, privacy policy, and schema version. -- Downstream dependents: portability scenarios in independent customer acceptance. -- Incompatible parallel work: imported evidence masquerading as locally observed; silent overwrite; secrets in an export. -- Migration dependency: schema compatibility on import. -- Privacy dependency: no secrets; config inclusion is separately controlled. -- Schema dependency: integrity manifest, schema version, completeness, sampling, and redaction metadata. -- UI dependency: imported evidence shows its origin. -- Validation dependency: duplicate handling and quarantine of imported evidence. - -### Customer annotations - -Section 22. - -- Prerequisites: evidence origin, operational storage, and the local UI truth contract. -- Downstream dependents: a visible distinction between observed evidence and customer-entered context. -- Incompatible parallel work: an annotation that mutates the original observation. -- Migration dependency: annotations live in separate storage and survive store migration without rewriting proof. -- Privacy dependency: annotation text is customer-entered context, not an observation. -- Schema dependency: annotation records are separate from observation records. -- UI dependency: the distinction is visible. -- Validation dependency: a test that annotation edits leave the original observation unchanged. - -### CLI ergonomics and coverage transparency - -Sections 4 and 5. - -- Prerequisites: none that authorize new product behavior in this document. -- Downstream dependents: the generated help reference in Section 7, item 17. -- Incompatible parallel work: defining `--quiet` as a synonym of `--json`; treating CLI ergonomics as a substitute for the Local UI workstream. -- Migration dependency: none. -- Privacy dependency: coverage output states what is not covered and does not dump secrets. -- Schema dependency: none beyond the existing evidence the commands would read. -- UI dependency: terminal behavior only. This is not the local web UI. -- Validation dependency: NO_COLOR, completion, legend, pager, quiet mode, and coverage listing remain design items. - -### Release, upgrade, and customer validation - -Sections 7 and 21, and Section 23, items 32, 33, and 34. - -- Prerequisites: migration, privacy, schema compatibility, and the evidence hierarchy. -- Downstream dependents: none inside the product. Acceptance closes only at the tier the hierarchy requires. -- Incompatible parallel work: background auto-update; treating this document as customer validation or as a release. -- Migration dependency: old and new record compatibility, interrupted migration, and safe rollback. -- Privacy dependency: security-update visibility does not weaken redaction. -- Schema dependency: future schema refusal and export/import testing. -- UI dependency: none that bypasses the Local UI prerequisites. -- Validation dependency: persona and adversity scenarios. They are requirements, not recorded results. - -## Governance — nonfunctional budget ledger - -Reusable fields for every budget: Budget ID, Category, User impact, Current target, Target status (NOT_SET | TARGET_DESIGN | TESTED_INTERNAL | PROVED_EXTERNAL | CUSTOMER_VALIDATED), Measurement method, Workload profile, Percentile/aggregation, Privacy impact, Failure behavior, Release gate, Evidence reference. - -Requirement status and budget-target status are different fields. Every requirement remains TARGET_DESIGN. Every numeric current target below is NOT_SET. Every budget target status below is NOT_SET. An example figure named elsewhere in this document is not adopted as a current target. - -No measurement method, workload profile, percentile, release gate, or evidence reference is set. Privacy impact and failure behavior below point at existing design rules and do not add a numeric limit. - -### NFR-STARTUP - -- Budget ID: NFR-STARTUP -- Category: startup -- User impact: time added before the wrapped application is usable -- Current target: NOT_SET -- Target status: NOT_SET -- Measurement method: NOT_SET -- Workload profile: NOT_SET -- Percentile/aggregation: NOT_SET -- Privacy impact: startup must not persist secrets while initializing -- Failure behavior: application startup continues if Optics observation cannot start; the gap is disclosed -- Release gate: NOT_SET -- Evidence reference: none - -### NFR-INTERCEPTOR-INIT - -- Budget ID: NFR-INTERCEPTOR-INIT -- Category: interceptor init -- User impact: time to install observation hooks -- Current target: NOT_SET -- Target status: NOT_SET -- Measurement method: NOT_SET -- Workload profile: NOT_SET -- Percentile/aggregation: NOT_SET -- Privacy impact: hook installation must not record customer content -- Failure behavior: a failed hook install is disclosed and does not change application output -- Release gate: NOT_SET -- Evidence reference: none - -### NFR-PER-CALL-OVERHEAD - -- Budget ID: NFR-PER-CALL-OVERHEAD -- Category: per-call overhead -- User impact: time added on each observed call -- Current target: NOT_SET -- Target status: NOT_SET -- Measurement method: NOT_SET -- Workload profile: NOT_SET -- Percentile/aggregation: NOT_SET -- Privacy impact: overhead measurement must not read body content -- Failure behavior: if the observation path throws or is killed, wrapped application output stays byte-identical to a run without Optics -- Release gate: NOT_SET -- Evidence reference: none - -### NFR-MEMORY - -- Budget ID: NFR-MEMORY -- Category: memory -- User impact: resident memory added by observation and the local store -- Current target: NOT_SET -- Target status: NOT_SET -- Measurement method: NOT_SET -- Workload profile: NOT_SET -- Percentile/aggregation: NOT_SET -- Privacy impact: memory holding secrets is not flushed into evidence -- Failure behavior: memory pressure follows the queue and degradation rules; evidence loss is explicit -- Release gate: NOT_SET -- Evidence reference: none - -### NFR-WRITE-LATENCY - -- Budget ID: NFR-WRITE-LATENCY -- Category: write latency -- User impact: delay to persist one observation -- Current target: NOT_SET -- Target status: NOT_SET -- Measurement method: NOT_SET -- Workload profile: NOT_SET -- Percentile/aggregation: NOT_SET -- Privacy impact: the write path allowlists before persistence -- Failure behavior: a failed write is disclosed; the application continues -- Release gate: NOT_SET -- Evidence reference: none - -### NFR-QUEUE-CAPACITY - -- Budget ID: NFR-QUEUE-CAPACITY -- Category: queue capacity -- User impact: how many observations can wait during a burst -- Current target: NOT_SET -- Target status: NOT_SET -- Measurement method: NOT_SET -- Workload profile: NOT_SET -- Percentile/aggregation: NOT_SET -- Privacy impact: queued records obey the same allowlist as persisted records -- Failure behavior: queue-full and burst behavior must be defined; drops are explicit -- Release gate: NOT_SET -- Evidence reference: none - -### NFR-DATABASE-SIZE - -- Budget ID: NFR-DATABASE-SIZE -- Category: database size -- User impact: disk used by the operational store -- Current target: NOT_SET -- Target status: NOT_SET -- Measurement method: NOT_SET -- Workload profile: NOT_SET -- Percentile/aggregation: NOT_SET -- Privacy impact: size limits must not silently delete evidence; retention stays unbounded unless the customer sets a limit -- Failure behavior: reaching a future configured limit produces explicit evidence, not a silent wipe -- Release gate: NOT_SET -- Evidence reference: none - -### NFR-QUERY-LATENCY - -- Budget ID: NFR-QUERY-LATENCY -- Category: query latency -- User impact: time to answer a bounded query -- Current target: NOT_SET -- Target status: NOT_SET -- Measurement method: NOT_SET -- Workload profile: NOT_SET -- Percentile/aggregation: NOT_SET -- Privacy impact: queries use structural fields and do not inspect body content -- Failure behavior: query-cost limits stop a runaway query; the failure is explicit -- Release gate: NOT_SET -- Evidence reference: none - -### NFR-UI-QUERY-RENDER-LATENCY - -- Budget ID: NFR-UI-QUERY-RENDER-LATENCY -- Category: UI query/render latency -- User impact: time for the local UI to show a bounded result -- Current target: NOT_SET -- Target status: NOT_SET -- Measurement method: NOT_SET -- Workload profile: NOT_SET -- Percentile/aggregation: NOT_SET -- Privacy impact: render uses the privacy policy and the evidence-origin model -- Failure behavior: a slow or failed query stays an explicit UI state and is not shown as a healthy current view -- Release gate: NOT_SET -- Evidence reference: none - -### NFR-EXPORT-TIME - -- Budget ID: NFR-EXPORT-TIME -- Category: export time -- User impact: time to write a proof or tabular export -- Current target: NOT_SET -- Target status: NOT_SET -- Measurement method: NOT_SET -- Workload profile: NOT_SET -- Percentile/aggregation: NOT_SET -- Privacy impact: export includes redaction metadata and omits secrets -- Failure behavior: a partial export is labeled incomplete and does not overwrite an existing proof silently -- Release gate: NOT_SET -- Evidence reference: none - -### NFR-SHUTDOWN-FLUSH - -- Budget ID: NFR-SHUTDOWN-FLUSH -- Category: shutdown flush -- User impact: whether queued writes reach disk before exit -- Current target: NOT_SET -- Target status: NOT_SET -- Measurement method: NOT_SET -- Workload profile: NOT_SET -- Percentile/aggregation: NOT_SET -- Privacy impact: flush persists only allowlisted fields -- Failure behavior: crash-consistency states COMPLETE, PARTIAL, INTERRUPTED, ABANDONED, and RECOVERED stay explicit -- Release gate: NOT_SET -- Evidence reference: none - -### NFR-DROPPED-RECORD - -- Budget ID: NFR-DROPPED-RECORD -- Category: dropped-record behavior -- User impact: whether a lost observation is visible -- Current target: NOT_SET -- Target status: NOT_SET -- Measurement method: NOT_SET -- Workload profile: NOT_SET -- Percentile/aggregation: NOT_SET -- Privacy impact: a drop notice must not contain the dropped secret or body -- Failure behavior: overflow and dropped records are explicit; no silent evidence loss; no recursive drop-notice storm -- Release gate: NOT_SET -- Evidence reference: none - -## Governance — threat-model linkage - -Design linkage only. Each case names the required control objective. None of these controls is claimed to exist. No case is closed. Status of every case is TARGET_DESIGN. Residual risk is unset. - -### Compromised observed app - -- Threat actor: code running inside the observed application, including a dependency -- Asset: local evidence store and proof export -- Trust boundary: observed application process versus Optics persistence -- Abuse path: the application submits customer content, credentials, or forged records for persistence -- Prevention: allowlisting before persistence; observation evidence is structural metadata; annotations and imports cannot rewrite a local observation -- Detection: redaction-failure and rejected-event diagnostics, kept out of customer AI activity -- Failure behavior: the application continues; rejected or incomplete evidence is disclosed -- Recovery: refuse the bad record; do not recreate an empty database silently -- Residual risk: unset -- Required test: fixtures with disallowed content assert the persisted record excludes it -- Status: TARGET_DESIGN - -### Malicious local user - -- Threat actor: another user on the same workstation -- Asset: evidence files, database, exports, and configuration -- Trust boundary: user account versus other local accounts -- Abuse path: a local user reads or replaces another user’s evidence or config -- Prevention: filesystem permissions, Windows ACLs, Unix modes, and multi-user workstation boundaries -- Detection: integrity checks and permission failures surfaced as integrity state -- Failure behavior: access outside the owner boundary fails closed for the store and does not widen the file mode -- Recovery: restore from a pre-migration backup or an export the owner still trusts; do not silently create a replacement database -- Residual risk: unset -- Required test: two-user permission fixtures on the documented filesystem cases -- Status: TARGET_DESIGN - -### Poisoned imported evidence - -- Threat actor: the author of an imported bundle -- Asset: operational trends, UI views, and proof exports -- Trust boundary: imported bytes versus LOCAL_OBSERVATION -- Abuse path: imported records are presented as locally observed customer activity -- Prevention: IMPORTED origin, quarantine, duplicate handling, and no silent overwrite -- Detection: evidence source and origin shown on every material view -- Failure behavior: import that fails provenance or schema checks is refused or quarantined -- Recovery: leave prior local observations unchanged -- Residual risk: unset -- Required test: import fixtures that must not count as local observation or as operational trends -- Status: TARGET_DESIGN - -### Malformed trace context - -- Threat actor: a caller or upstream process supplying trace context -- Asset: correlation fields and any propagated baggage -- Trust boundary: incoming context versus trusted local correlation -- Abuse path: malformed, replayed, colliding, or sensitive baggage is stored or propagated -- Prevention: sensitive-baggage prohibition, allowlists, size limits, and trust classification -- Detection: context-conflict and rejected-context diagnostics -- Failure behavior: malformed context is not treated as a trusted parent span -- Recovery: record the conflict without adopting the bad context -- Residual risk: unset -- Required test: malformed, replay, collision, and oversize-context fixtures -- Status: TARGET_DESIGN - -### Oversized telemetry - -- Threat actor: a noisy or hostile observed workload -- Asset: queue, store, and application latency -- Trust boundary: observation path versus application progress -- Abuse path: volume exhausts queue, disk, or query budget -- Prevention: cardinality budgets, queue bounds, database-size policy, and query-cost limits, with numeric targets still NOT_SET -- Detection: dropped-record, queue, and database-size diagnostics -- Failure behavior: explicit overflow; application continues; no silent evidence loss; no drop-notice storm -- Recovery: customer retention policy only when the customer has configured a limit -- Residual risk: unset -- Required test: burst and queue-full fixtures that assert explicit drop evidence -- Status: TARGET_DESIGN - -### Path traversal and symlink - -- Threat actor: a local user or a crafted import path -- Asset: files outside the intended evidence directory -- Trust boundary: configured evidence path versus the rest of the filesystem -- Abuse path: a path or symlink redirects reads or writes outside the evidence directory -- Prevention: symlink defense and path confinement to the configured evidence location -- Detection: refused path attempts in integrity state -- Failure behavior: the operation stops and does not follow the link out of the evidence root -- Recovery: no partial write outside the evidence root -- Residual risk: unset -- Required test: symlink and parent-directory fixtures that must fail closed -- Status: TARGET_DESIGN - -### Local UI injection - -- Threat actor: evidence or annotation text rendered by the local UI -- Asset: the local browser session -- Trust boundary: stored text versus the UI document -- Abuse path: stored text is interpreted as active UI content -- Prevention: output escaping, CSP, and no third-party assets -- Detection: the first UI release has no mutation endpoint that could persist an injected action -- Failure behavior: untrusted text renders as text -- Recovery: restart the local UI process; the store is unchanged because the first release is read-only -- Residual risk: unset -- Required test: render fixtures for evidence and annotation text -- Status: TARGET_DESIGN - -### Unauthorized local UI access - -- Threat actor: a different local user or a non-loopback client -- Asset: the read-only evidence view -- Trust boundary: loopback interface versus other interfaces and users -- Abuse path: a client off-machine, or another local user, opens the UI -- Prevention: loopback-only binding, origin restrictions, and explicit shutdown -- Detection: bind and origin failures are visible; no analytics channel exists to hide them -- Failure behavior: non-loopback and cross-origin requests are refused -- Recovery: shut the UI down; it is not a persistent daemon -- Residual risk: unset -- Required test: bind-address and origin fixtures -- Status: TARGET_DESIGN - -### Query denial of service - -- Threat actor: a local query client -- Asset: UI and CLI responsiveness and store availability -- Trust boundary: bounded query contract versus arbitrary query power -- Abuse path: an expensive query or unrestricted scan stalls the local store -- Prevention: no arbitrary SQL; query-cost limits; pagination and time bounds -- Detection: query latency and rejected-query diagnostics -- Failure behavior: the query is cancelled or refused; the application under observation keeps running -- Recovery: another bounded query still works; saved views store queries, not copied evidence -- Residual risk: unset -- Required test: over-broad query fixtures that must hit the cost limit -- Status: TARGET_DESIGN - -### Database corruption - -- Threat actor: crash, disk fault, or a partial write -- Asset: operational store integrity -- Trust boundary: durable store versus in-flight queue -- Abuse path: a torn write or interrupted migration is opened as a healthy database -- Prevention: transactional migrations, integrity checks, and crash-consistency states -- Detection: integrity state and the “database corruption” UI state -- Failure behavior: refuse silent empty-database recreation; newer or corrupt schemas stay refused or bounded read-only -- Recovery: pre-migration backup and interrupted-migration recovery -- Residual risk: unset -- Required test: interrupted migration and torn-write fixtures -- Status: TARGET_DESIGN - -### Instrumentation recursion - -- Threat actor: Optics observing its own diagnostic writes -- Asset: customer activity views and metric totals -- Trust boundary: customer AI calls versus Optics-internal diagnostics -- Abuse path: hooks, writes, or formatter failures are stored as customer calls and inflate metrics -- Prevention: internal diagnostics are excluded from customer activity and from metric labels -- Detection: a recursion counter that must stay out of the customer event stream -- Failure behavior: diagnostic failure does not create another customer event -- Recovery: drop the recursive diagnostic, record one explicit internal failure, and stop -- Residual risk: unset -- Required test: a self-observation fixture that asserts zero customer events from internal diagnostics -- Status: TARGET_DESIGN - -### Metadata secret placement - -- Threat actor: an application or provider that puts tokens in headers, query strings, or nested fields -- Asset: persisted records, exports, and UI -- Trust boundary: allowlisted structural metadata versus secrets and content -- Abuse path: a secret in a header, query string, URL, or encoded field is stored -- Prevention: allowlisting before persistence; query strings excluded from destination normalization by default -- Detection: redaction-failure diagnostic; release-blocking invariant when this control is implemented -- Failure behavior: the persisted record does not contain the secret; the application still returns its own output -- Recovery: the bad field is omitted, not masked in place with a reversible copy -- Residual risk: unset -- Required test: the metadata redaction suite and the privacy corpus, including Unicode and nested encodings -- Status: TARGET_DESIGN - -### Duplicate instrumentation - -- Threat actor: stacked Optics copies or co-installed OpenTelemetry, APM, or provider SDK hooks -- Asset: event identity and metric totals -- Trust boundary: one observation pipeline versus other hooks in the same process -- Abuse path: one call is stored more than once and inflates counts -- Prevention: stable event identity, duplicate markers, and no duplicate inflation of metrics -- Detection: multi-hook detection -- Failure behavior: duplicates are marked and excluded from inflated totals -- Recovery: repeat-safe import does not create a second logical event -- Residual risk: unset -- Required test: wrapper-order and multiple-copy fixtures -- Status: TARGET_DESIGN - -### Tampered annotation - -- Threat actor: the local customer, or another local user editing annotation storage -- Asset: original observation evidence -- Trust boundary: annotation store versus observation store -- Abuse path: an annotation edit changes the original observation or is shown as an observation -- Prevention: annotations are stored separately and never mutate observation evidence -- Detection: the UI distinguishes customer-entered context from observed evidence -- Failure behavior: a corrupt annotation is dropped from view and the observation remains -- Recovery: restore or delete the annotation without rewriting proof -- Residual risk: unset -- Required test: an annotation edit that must leave the observation bytes unchanged -- Status: TARGET_DESIGN - -### Rollback to a privacy-weaker schema - -- Threat actor: an operator rolling back software or schema -- Asset: privacy invariants already enforced on stored records -- Trust boundary: newer privacy schema versus an older reader -- Abuse path: rollback reinterprets stored records under weaker redaction or re-emits stripped secrets -- Prevention: rollback compatibility tests include privacy invariants; a privacy-weaker schema is refused -- Detection: schema version and migration state -- Failure behavior: refuse the weaker schema rather than rewrite records -- Recovery: stay on the privacy-preserving schema or use a bounded read-only fallback that does not export newly weakened fields -- Residual risk: unset -- Required test: rollback fixtures that attempt to read current records with a weaker schema and must fail closed -- Status: TARGET_DESIGN - -## Governance — acceptance evidence hierarchy - -Evidence tiers, from narrowest to broadest. Assigning a tier is a proof record. This document assigns none. - -- UNIT_PROVED: one component met one requirement under its stated fixture. This does not establish integration, a stranger host, external proof, or customer validation. -- INTEGRATION_PROVED: linked components met the requirement together on one controlled host. This does not establish a stranger host, external proof, or customer validation. -- STRANGER_HOST_PROVED: the same check passed on a host that is not the producer’s development environment. This does not establish customer validation. -- PROVED_EXTERNAL: an independent verifier outside the producing change recorded the required evidence. This does not establish customer validation. -- CUSTOMER_VALIDATED: the customer confirmed the requirement on that customer’s own workload and window. - -Rules: - -- Producer success is not proof. -- Exit code zero is not proof. -- A healthy UI is not proof. -- Imported evidence is not local observation. -- Simulated demo evidence is not customer evidence. -- INTERNAL_PROOF cannot be displayed as CUSTOMER_VALIDATED. -- Stale evidence cannot retain a current pass. -- Unsupported and unavailable stay explicit. - -Traceability for every roadmap item uses the template above, including current evidence tier, required closing tier, independent verifier, stranger-host, customer-validation, and status. Those evidence fields are unset. Status remains TARGET_DESIGN. No item is complete. - diff --git a/docs/internal/optics-cli-post-0324-cx-backlog.md b/docs/internal/optics-cli-post-0324-cx-backlog.md deleted file mode 100644 index b43578b1..00000000 --- a/docs/internal/optics-cli-post-0324-cx-backlog.md +++ /dev/null @@ -1,16 +0,0 @@ -# OPTICS CLI POST-0.3.24 CX BACKLOG - -Backlog only. Do not reopen, patch, republish, or retag @vantio/cli@0.3.24. - -The Python SDK 3.1.0 customer lines (Optics status, observed outcome, provider response) are in `packages/vantio-agent-sdk-py`. This note is the deferred CLI refinement. It does not change the CLI package. - -1. Replace primary human label "Application error" with precise observed outcomes - (Provider authentication failed, Provider denied the request, Provider rate-limited - the request, Provider service error, Connection to provider failed, Provider outcome unavailable, etc.). -2. Keep machine token APPLICATION_ERROR until a deliberate schema decision. -3. Rename displayed concept from "Application outcome" to "Observed outcome". -4. Show raw status separately: Provider response: HTTP 401 Unauthorized. -5. Make next actions outcome-aware: remediation first, inspection second, proof third. -6. Standardize next-action hierarchy across intercepted call output, run summary, tail, prove. -7. Do not patch 0.3.24 solely for this. -8. Schedule for the next intentional CLI customer-experience release. diff --git a/docs/internal/optics-o7/00-BINDING-DECISION.md b/docs/internal/optics-o7/00-BINDING-DECISION.md deleted file mode 100644 index 51d96115..00000000 --- a/docs/internal/optics-o7/00-BINDING-DECISION.md +++ /dev/null @@ -1,266 +0,0 @@ -# O7 Node binding decision packet - -Audience: INTERNAL_RESTRICTED - -Council: `bc-00af4334-6f4f-59be-9ebf-c084d3c9baa6`, model Grok 4.7. - -Council URL: https://cursor.com/agents/bc-00af4334-6f4f-59be-9ebf-c084d3c9baa6 - -Starting commit: `0620f10ee52d3abcea18c1c988df02f687f51b36` - -Observed: 2026-09-27 - -Verdict: `O7_NODE_BINDING_COUNCIL_PASSED` - -Machine-readable copy: `BINDING-DECISION.json` - -## 1. Selection - -| Field | Value | -| --- | --- | -| Binding | `node:sqlite` | -| Version | `24.15.0` | -| Token | `node:sqlite@24.15.0` | -| What the version is | The minimum Node.js version. The module is the one compiled into that Node.js binary. | -| npm dependency | None | -| npm integrity | None. There is no package tarball. | -| Runtime pin | `node>=24.15.0` on the 24.x line, plus Node.js 26.x | -| Fallback token | `better-sqlite3@13.0.3` | -| Fallback installed | No | -| Load fallback when `node:sqlite` is missing | No. Fail open. | - -`24.15.0` is the revision named in the Node.js 24.19.0 documentation history table: "v24.15.0 | SQLite is now a release candidate." Source: `https://nodejs.org/docs/latest-v24.x/api/sqlite.html`, fetched 2026-09-27. The current-line documentation, Node.js v26.8.1, says Stability 1.2, release candidate, and dates that designation to v25.7.0. Source: `https://nodejs.org/api/sqlite.html`, fetched 2026-09-27. - -Node.js 22.23.3 documentation still says the module is experimental after v22.13.0 removed the `--experimental-sqlite` flag. Source: `https://nodejs.org/docs/latest-v22.x/api/sqlite.html`, fetched 2026-09-27. Node.js 22 is unsupported for this selection. - -## 2. Engine - -The engine stays the ratified one. `docs/architecture/optics-foundation/08-ARCHITECTURE-DECISION-PACK.md` section 12 and `docs/architecture/optics-foundation/03-OPERATIONAL-STORE-AND-PORTABLE-PROOF.md` section 4: embedded SQLite, WAL, application-owned schema, path `~/.vantio/optics/store.sqlite` under the evidence root. - -Python's mechanism stays the standard-library `sqlite3` module. This packet does not replace it. - -The Python writer that a Node binding has to meet is `packages/optics-operational-store/src/optics_operational_store/store.py`: - -- `timeout=0` and `isolation_level=None` in `_connect` -- `PRAGMA journal_mode=WAL`, and the call fails open with `WAL_UNAVAILABLE` when the result is not `wal` -- `PRAGMA integrity_check` -- `PRAGMA user_version` -- `BEGIN IMMEDIATE`, `COMMIT`, and `ROLLBACK` -- Bound parameters, including the `ON CONFLICT` upsert into `store_meta` -- Tables `store_meta`, `records`, and `drops` with ordinary columns and indexes -- No `STRICT` tables and no `FOREIGN KEY` clauses -- Read-only open through a `file:` URI with `mode=ro`, which must not create a missing file -- Backup is a filesystem copy, not the SQLite online backup API - -Busy-timeout and page size stay `NOT_SET`. A binding whose default is to wait on a lock has to be opened with an explicit zero wait before it matches this store. - -## 3. What this packet leaves alone - -- `@vantio/cli` `0.3.24`, `@vantio/agent-sdk` `0.2.4`, and `vantio-agent-sdk` `3.1.0` -- `docs/governance/VERSION-METADATA.json` -- Gate 8 in `docs/architecture/optics-foundation/09-IMPLEMENTATION-GATES.md` -- The sentence "9. Node SQLite binding. Not selected." in the architecture decision pack -- `docs/planning/optics-o7-store/STORE-MANIFEST.json`, which still says `founder_decision_9` is `UNRESOLVED` -- `docs/planning/optics-production/PACKAGES.json`, which still says `O6` needs a Founder decision -- Node `openStore`, which still returns `NODE_BINDING_UNSELECTED` and creates no file -- Every `package.json` dependency list. None gains `sqlite3`, `better-sqlite3`, or `node:sqlite` - -Those older files describe the tree Track 2 has not changed yet. This packet is the selection. Track 2 implements this packet. It does not treat the older "not selected" sentence as a reason to choose a different library, and it does not treat this packet as a reason to pretend the current process already opens a database. - -Evidence tier stays `UNSET`. Gate 8 stays closed. `external_proof` is `NOT_CLAIMED`. - -## 4. Repository constraints that bound the choice - -| Constraint | Where it is written | Effect on the choice | -| --- | --- | --- | -| Store and CLI engines | `packages/optics-operational-store/package.json` and `packages/vantio-cli/package.json`: `node>=18.3.0` | The frozen CLI is not edited. A binding that needs a newer Node applies to a future store load, not to CLI `0.3.24`. | -| Node SDK engines | `packages/vantio-agent-sdk/package.json`: `node>=18.0.0` | Same. The SDK is not edited. | -| Import ban | `tests/optics-option-c-revalidation/adversarial.test.cjs` rejects a Node binding import and a package dependency on `sqlite3`, `better-sqlite3`, `better-sqlite`, or `node:sqlite` | This packet adds no import and no dependency. Track 2 is the change that lifts the ban for the selected module only. | -| Running facade | `packages/optics-operational-store/src/open.cjs` | Stays `NODE_BINDING_UNSELECTED`. | -| Node release calendar | `https://github.com/nodejs/release`, fetched 2026-09-27 | Node.js 18 EOL 2025-04-30. Node.js 20 EOL 2026-04-30. Node.js 22 Maintenance LTS through 2027-04-30. Node.js 24 Active LTS through 2028-04-30. Node.js 25 EOL 2026-06-01. Node.js 26 Current, EOL 2029-04-30. | - -Node.js 18 and 20 are end of life on the observation date. Keeping them in `engines` is the frozen manifest. It is not a reason to pick a binding that only exists as a source build on those lines. - -## 5. Candidates - -| Candidate | Class | Disposition | -| --- | --- | --- | -| `node:sqlite` | Node.js built-in, synchronous `DatabaseSync` | Selected, floor `24.15.0` | -| `better-sqlite3@13.0.3` | Native addon, synchronous, MIT | Fallback. Not installed. | -| `sqlite3@6.0.1` | Native addon, asynchronous, BSD-3-Clause | Disqualified | -| `sql.js` | SQLite compiled to WebAssembly, MIT | Disqualified | -| `libSQL` and Turso | Fork, and a separate Rust engine | Disqualified | -| `bun:sqlite` | Bun built-in | Disqualified | - -Wrappers that sit on top of one of these are not a second candidate. DuckDB stays rejected by the ratified option C record. SQLCipher stays out because at-rest encryption is Founder decision 5 and is not selected. - -## 6. Evidence - -### 6.1 `node:sqlite` documentation - -Fetched 2026-09-27: - -- Node.js v26.8.1 `https://nodejs.org/api/sqlite.html`. Stability 1.2, release candidate. History: experimental and unflagged at v22.13.0 and v23.4.0; release candidate at v25.7.0. `DatabaseSync` is synchronous. `timeout` default is 0 and arrived at v24.0.0 and v22.16.0. `readOnly: true` fails when the file is missing. `enableForeignKeyConstraints` default is true. `allowExtension` default is false. `exec` runs SQL and returns no rows. `prepare` returns `StatementSync` with `run`, `get`, and `all`. `defensive` defaults to true from v24.14.0 and v25.5.0. -- Node.js v24.19.0 `https://nodejs.org/docs/latest-v24.x/api/sqlite.html`. History row v24.15.0: "SQLite is now a release candidate." -- Node.js v22.23.3 `https://nodejs.org/docs/latest-v22.x/api/sqlite.html`. History row v22.13.0: no longer behind the flag, still experimental. `timeout` added at v22.16.0. Further constructor options added at v22.18.0. -- `https://github.com/nodejs/node/blob/main/configure.py` exposes `--without-sqlite` with the help text "build without SQLite (disables SQLite and Web Storage API)". A build that passes that flag has no module. -- The v26.8.1 page also distinguishes builds linked with `--shared-sqlite`. Those builds are a different SQLite than the one Node vendors. They are unsupported by this selection. -- `https://github.com/nodejs/node/issues/54135`. The bundled SQLite version is readable with `sqlite_version()` and `process.versions.sqlite`. A maintainer comment on that issue says a security fix could move the bundled version backward. This packet does not pin a SQLite version number for `node:sqlite`. - -### 6.2 `better-sqlite3@13.0.3` - -Fetched 2026-09-27 from the npm registry and from tag `v13.0.3`: - -- Registry `https://registry.npmjs.org/better-sqlite3/13.0.3`. Version `13.0.3`. License MIT. Integrity `sha512-RbOBxmLBG8uvFUc15X9+9SFemKcQ0WBuISBVkpuiaUB2qblC8UWlHEjdWVoZ8AdhSwmoEgsiXKfopX0CQxaACQ==`. Published 2026-08-05. -- `package.json` at that tag. `engines.node` is `>=22`. Runtime dependency is `node-addon-api`. `files` includes `prebuilds/**`. `exports` names `linux-x64`, `linux-arm64`, `linuxmusl-x64`, `linuxmusl-arm64`, `darwin-x64`, `darwin-arm64`, `win32-x64`, and `win32-arm64`. The fetched manifest has no `install` script. This council did not unpack the published tarball, so the presence of those prebuilds inside the tarball is the manifest's claim. -- `lib/database.js` at that tag. Default `timeout` is 5000. The constructor rejects a negative timeout. Zero is allowed by the comparison `timeout < 0`. `readonly` is a separate option. The spelling `readOnly` throws. -- `deps/sqlite3/sqlite3.h` at that tag. `#define SQLITE_VERSION "3.53.4"`. - -This council did not `npm install` the package. - -### 6.3 Disqualified projects - -- `sqlite3` on npm, version `6.0.1`, license BSD-3-Clause. The project README is titled as deprecated and says the repository is unmaintained. The GitHub repository `TryGhost/node-sqlite3` is archived. The API is asynchronous. Sources fetched via the npm page and the repository README on 2026-09-27. -- `sql.js` README at `https://github.com/sql-js/sql.js/blob/master/README.md`. The library stores the database in a memory file and states that it does not persist changes. Persistence is an export of a typed array and a later import of those bytes. The same README points Node users at a native binding when they need to work on database files directly. -- `libSQL` README at `https://github.com/tursodatabase/libsql/blob/main/README.md`. libSQL is a fork of SQLite with its own extensions, including a virtual write-ahead log interface and embedded replicas. The same README says the Turso database is a separate Rust engine and is not that fork. Either one is a different engine from the ratified SQLite file. - -### 6.4 Workstation probe - -This probe is not a supported-floor run, not a crash test, and not a stranger-host or external proof. The machine was Linux, Node.js `v22.14.0`, Python `3.12.3` linked to SQLite `3.45.1`. Node reported `process.versions.sqlite` `3.47.2`. Loading `node:sqlite` printed `ExperimentalWarning: SQLite is an experimental feature and might change at any time`. The files lived under a temporary directory and were deleted before this packet was written. No `*.sqlite` file was added to the repository. - -Observed on that Node `v22.14.0` build: - -- `PRAGMA journal_mode=WAL` through `prepare().get()` returned `wal`. Before `close`, the directory contained `store.sqlite-wal` and `store.sqlite-shm`. -- `exec("BEGIN IMMEDIATE")` returned `undefined`. An insert followed by `ROLLBACK` left `COUNT(*)` at 0. A later `COMMIT` kept the row. `PRAGMA user_version = 1` through `prepare().run()` survived. `PRAGMA integrity_check` returned `ok`. -- `readOnly: true` on a missing path threw `ERR_SQLITE_ERROR` (`unable to open database file`) and left the path absent. A later read-only open of the real file rejected an insert with `attempt to write a readonly database`. -- `enableForeignKeyConstraints: true` made `PRAGMA foreign_keys` return 1. `false` made it return 0. The Python schema has no foreign keys. The Python connection does not enable them. Track 2 sets this option to `false`. -- `timeout: 2500` left `PRAGMA busy_timeout` at 0. An unknown constructor option was also accepted and ignored. On this build, a constructor that does not throw is not evidence that the option took effect. The v22 documentation places the `timeout` option at v22.16.0, which is above v22.14.0. -- `isTransaction` is absent on this build. The v22.23.3 documentation lists it. Track 2 does not need the property. `BEGIN IMMEDIATE` and `ROLLBACK` are the contract. -- After Node closed the file, Python `sqlite3` opened the same path, read journal mode `wal`, `user_version` 1, and the committed row. A Python `ROLLBACK` dropped an uncommitted insert. A Python `COMMIT` of a second row was then read back by Node. - -That is evidence that this build's SQLite 3.47.2 and this Python's SQLite 3.45.1 can share one ordinary WAL file for sequential writers, for a schema with no `STRICT` tables. It is not evidence about Node.js 24.15.0, about simultaneous writers, or about a killed process. - -## 7. Criterion notes - -The brief asks for these properties. Popularity was not a score. Download counts appear in the npm registry and were not used. - -| Criterion | `node:sqlite@24.15.0` | `better-sqlite3@13.0.3` | -| --- | --- | --- | -| Node runtime | Gap. Floor is 24.15.0. Node 22 loads an experimental module and is unsupported. CLI `0.3.24` engines stay `>=18.3.0` because the CLI is not modified. | Meets its own manifest: `node>=22`, which includes Maintenance LTS 22. Misses the frozen `>=18.3.0` field the same way, on lines that are already end of life. Not installed here. | -| Native dependency | None beyond the Node binary. | Native addon. | -| Prebuilt binaries | The official Node binary is the build. | Manifest names eight platform entry points and a `prebuilds` directory. Tarball not unpacked here. | -| Linux architectures | Official Node Linux binaries on the supported lines. This council exercised one Linux x64 workstation on an unsupported Node. | Manifest names `linux-x64`, `linux-arm64`, `linuxmusl-x64`, `linuxmusl-arm64`. | -| Transactions | `exec` of `BEGIN IMMEDIATE`, `COMMIT`, and `ROLLBACK` worked on the probed build. | Documented `transaction()` helper and `exec`. Not executed here. | -| WAL | Host `-wal` and `-shm` files appeared on the probed build. Python reread the file. | Documented `pragma('journal_mode = WAL')`. Not executed here. | -| Prepared statements | `StatementSync` `run`, `get`, and `all` worked on the probed build. | Documented `prepare`. Not executed here. | -| Crash consistency | SQLite WAL recovery is the mechanism. This council did not kill a writer. | Same mechanism. Not crash-tested. | -| Installation reliability | `require('node:sqlite')` either resolves or throws. A throw fail-opens. | A missing platform binary fails the addon load. The package has to be optional or the future CLI install fails closed. | -| Release packaging | No dependency entry. Track 2 changes the private store `engines` field. | An npm dependency, optional if it is ever adopted. | -| Supply chain | The Node.js release the operator already runs. | The npm package, `node-addon-api`, and a native binary. | -| Maintenance | The Node.js project. The module is Stability 1.2 on the current docs, not Stability 2. | Release `13.0.3` on 2026-08-05. MIT. The project is one maintainer line, Joshua Wise, and it has kept shipping. | -| Memory | Synchronous calls block the Node event loop for the duration of the SQLite call. The same is true of the Python store. The query limit of 500 is an application rule. | Same synchronous shape, plus a worker helper this store does not need. | -| Concurrency | One `DatabaseSync` is a single connection. WAL is what lets another process read. Simultaneous Node and Python writers were not tested. `timeout` default 0 means a lock does not wait. | WAL is available. Default timeout 5000 waits. Track 2 would have to pass 0. | -| Rollback | SQL `ROLLBACK` worked on the probe. Software rollback stops loading the module and leaves the file and its sidecars. | SQL rollback is SQLite's. Software rollback removes a dependency and leaves the file. | -| License | No third license beyond the Node.js binary already required to run the CLI. SQLite itself is public domain. | MIT. Compatible with the MIT CLI. | -| Ordinary-client installation | A client on an official Node binary at the floor installs no extra module. A client on Node 22 fail-opens. CLI `0.3.24` does not load the store, so today's CLI install is unchanged. | Extra native install for a future package. | -| Testability | Gap. This environment cannot run Node.js 24.15.0. The probe covered Node.js 22.14.0 only. | Could be installed on this Node 22.14.0. This council did not install it, because the packet must not add the dependency. | -| Long-term support | Node.js 24 through 2028-04-30 and Node.js 26 through 2029-04-30, on the release schedule fetched above, for as long as those lines keep the module. The API is a release candidate. | Semver on the library. Bundled SQLite is 3.53.4 at this version. A new Node major has already moved `engines` to `>=22`. | - -## 8. Disqualifiers - -`sqlite3@6.0.1`. The maintainers have deprecated and archived it. The API is asynchronous, so a `BEGIN IMMEDIATE` transaction depends on a serialized queue the application would have to build. The store facade and the Python writer are synchronous. Maintenance status removes it before popularity is considered. The BSD-3-Clause license would have been compatible. - -`sql.js`. The database lives in a WebAssembly memory image. The README's persistence path is export and import of the whole byte array. A crash after a write and before that export loses the write. The host files `store.sqlite-wal` and `store.sqlite-shm` are the ratified WAL pair. This library does not produce them. - -`libSQL` and Turso. libSQL is a fork with extra WAL and replica machinery. Turso's README describes a separate Rust engine. Option C ratified SQLite. Selecting either one reopens the engine. File-format promises on the libSQL README do not make the fork the ratified engine. - -`bun:sqlite`. The store package, the CLI, and the Node SDK declare Node. A Bun-only module is outside that runtime. - -`better-sqlite3@13.0.3` is not disqualified. It loses the primary seat for three recorded reasons: - -1. It is a native addon and a third SQLite build. Python already links one SQLite. `node:sqlite` uses the SQLite inside the Node binary. Adding 3.53.4 makes a third. -2. The default busy timeout is 5000 ms. The store's contract is no wait. Every open would have to remember `timeout: 0`. `node:sqlite` documents the default as 0. -3. A required dependency fails installation on machines outside the eight exported platform tuples. The ordinary-client failure mode for this product is a native install failure. Fail-open only works if the dependency is optional, which is a later packaging choice, not the primary seat. - -It remains the fallback because its API is semver-stable on Node.js `>=22`, including the Maintenance LTS line this selection leaves unsupported. - -## 9. Why the floor is 24.15.0 - -Three dates stack, and the floor is the latest of them: - -- v22.13.0 unflags the module and leaves it experimental. -- v22.16.0 and v24.0.0 add the `timeout` option. The probed v22.14.0 build ignores `timeout`. -- v24.15.0 is the 24.x revision that marks the module a release candidate. v22.23.3 documentation has not received that mark. The probed v22.14.0 build prints the experimental warning. - -Node.js 22 remains Maintenance LTS until 2027-04-30. Leaving it unsupported is a support gap. Covering it with the experimental module would bind the store to an API Node's own warning says might change at any time. Covering it with `better-sqlite3` would take the native addon as the primary. This council accepts the Node.js 22 gap and writes the addon down as the fallback. - -Node.js 25 reached end of life on 2026-06-01. It is unsupported even where a 25.x build marked the module as a release candidate. - -## 10. Track 2 limits - -Track 2 may load `node:sqlite` only when `process.versions.node` is on Node.js 24 at or above `24.15.0`, or on Node.js 26. Below that, including a Node.js 22 that can already `require` the module, the call fail-opens and creates no file. - -Constructor options Track 2 sets, then checks, because the probed build ignores unknown options: - -- filesystem path, not a `file:` URI -- `readOnly: true` for the read-only open, and a missing path must stay missing -- `timeout: 0`, then `PRAGMA busy_timeout` must read back 0 -- `enableForeignKeyConstraints: false`, then `PRAGMA foreign_keys` must read back 0 -- `allowExtension` left false - -SQL Track 2 may use: - -- `prepare('PRAGMA journal_mode=WAL').get()` and a fail-open when the mode is not `wal`. `exec` returns no row, so it cannot confirm the mode. -- `exec` for `BEGIN IMMEDIATE`, `COMMIT`, and `ROLLBACK` -- `prepare` with bound parameters for every value the application supplies -- `PRAGMA user_version` and `PRAGMA integrity_check` -- the same non-`STRICT` tables the Python writer already creates - -SQL and APIs Track 2 leaves unused: - -- `STRICT` -- `loadExtension` and `allowExtension: true` -- `createSession`, `applyChangeset`, `createTagStore`, `setAuthorizer` -- user-defined functions and aggregates -- `sqlite.backup` as a replacement for the filesystem copy the Python store already does -- `ATTACH` of a second database - -`defensive` defaults to true on Node.js versions at and above v24.14.0. The selected floor is above that. Defensive mode does not change the file format. Track 2 does not treat it as the integrity check. `PRAGMA integrity_check` remains the check. - -A future `engines` field on the private store package becomes `>=24.15.0` in the Track 2 change. CLI `0.3.24` does not gain that field. - -## 11. Fallback and rollback - -Operational fallback when the module is missing, the Node version is below the floor, or open throws: the call returns, the application continues, and no store file is created. The current reason code is `NODE_BINDING_UNSELECTED`. Track 2 may use a distinct reason for "selected binding cannot load." It does not download or compile another library inside that failure. - -Named fallback for a later council: `better-sqlite3@13.0.3`, integrity `sha512-RbOBxmLBG8uvFUc15X9+9SFemKcQ0WBuISBVkpuiaUB2qblC8UWlHEjdWVoZ8AdhSwmoEgsiXKfopX0CQxaACQ==`. If that later council adopts it, the package is an `optionalDependency`, every open passes `timeout: 0`, and a missing addon fail-opens. It is not a required dependency of `@vantio/cli`. This council does not adopt it. - -Software rollback: stop loading `node:sqlite`. Leave `store.sqlite`, `store.sqlite-wal`, and `store.sqlite-shm` on disk. Do not down-migrate `user_version`. Do not delete the sidecars. Legacy JSON files stay where they are. - -SQL rollback: a failed `BEGIN IMMEDIATE` body ends in `ROLLBACK`. The corrupt-file rule in the architecture pack still applies. A failed write does not replace the file with an empty database. - -## 12. Platforms - -Authorized target: official Node.js release binaries for Node.js 24 at or above 24.15.0, and for Node.js 26, built with the default SQLite configuration. - -Unsupported: - -- Node.js below 24.15.0, including 18, 20, 22, and 25 -- binaries configured with `--without-sqlite` -- binaries configured with `--shared-sqlite` -- Bun and Deno -- a WASM memory image or an export-byte-array store - -Exercised here: one Linux workstation, Node.js v22.14.0, which is on the unsupported list. Windows, macOS, arm64, musl, Node.js 24.15.0, and Node.js 26 were not run. Windows ACL detail stays Founder decision 8. This packet does not invent an ACL. - -## 13. Release impact - -This change is documents plus a test that locks the documents. No package manifest changes. No changelog heading changes. No tag. No publish. - -CLI `0.3.24` continues to declare `node>=18.3.0` and continues to ignore the store. A later CLI that loads the store cannot keep that engines field. That CLI is a later release. This packet does not open it. - -The private store package stays `0.0.0-unstable-pre-1.0` and `private: true`. `schema_status` stays `unstable-pre-1.0`. The store stays off the default write path. `O12` stays unmet. `O6` in `PACKAGES.json` stays the historical cell. The implementation status of the binding is this packet, not that cell. - -## 14. Reading rule - -This record selects the Node binding. The architecture decision pack still says the binding is not selected. The running store still returns `NODE_BINDING_UNSELECTED`. Those sentences remain true of those files and of the current process. Track 2 implements `node:sqlite@24.15.0` from this record and does not pick a different library because an older sentence still says "not selected." diff --git a/docs/internal/optics-o7/10-RUNTIME-INTEGRATION.md b/docs/internal/optics-o7/10-RUNTIME-INTEGRATION.md deleted file mode 100644 index 72e6f21a..00000000 --- a/docs/internal/optics-o7/10-RUNTIME-INTEGRATION.md +++ /dev/null @@ -1,29 +0,0 @@ -# O7 runtime integration - -Audience: INTERNAL_RESTRICTED - -Classification: `O7_RUNTIME_INTEGRATION_READY_FOR_COUNCIL` - -Starting commit: `ebc060f2af98362bc7e317f4a01e635138a657b1` - -Binding: `node:sqlite@24.15.0`, from `docs/internal/optics-o7/00-BINDING-DECISION.md`. - -This record is an implementation handoff. It is not a council pass, not an evidence tier, and not a host proof. - -## What the runtime does - -`packages/optics-operational-store` loads `node:sqlite` only when `process.versions.node` is Node.js 24 at or above 24.15.0, or Node.js 26. On every other version, including Node.js 22 that can already resolve the builtin, `openStore` returns `NODE_BINDING_CANNOT_LOAD`, the application continues, and no store file is created. - -On a supported runtime the constructor receives a filesystem path. Read-only opens pass `readOnly: true` and do not create a missing path. Every open passes `timeout: 0` and `enableForeignKeyConstraints: false`, then reads back `PRAGMA busy_timeout` and `PRAGMA foreign_keys`. `allowExtension` stays false. WAL is confirmed with `prepare('PRAGMA journal_mode=WAL').get()`. `BEGIN IMMEDIATE`, `COMMIT`, and `ROLLBACK` go through `exec`. Application values use bound parameters. Tables match the Python writer and are not `STRICT`. Backup is a filesystem copy. - -`better-sqlite3` is not installed and is not loaded when the selected module cannot load. - -The private store `engines` field is `>=24.15.0`. `@vantio/cli` `0.3.24` stays `>=18.3.0`. `@vantio/agent-sdk` `0.2.4` and `vantio-agent-sdk` `3.1.0` are unchanged. - -## What stays closed - -Evidence tier `UNSET`. Gate 8 closed. `external_proof` is `NOT_CLAIMED`. The store is not a default write path. `schema_status` stays `unstable-pre-1.0`. The package stays private at `0.0.0-unstable-pre-1.0`. No publish and no customer migration. - -This force executed the store tests on the official Node.js `v24.15.0` and `v26.10.0` linux-x64 binaries inside this workspace. That execution is not a stranger host, not a clean-host certification, and not external proof. Node.js 22.14.0 in this workspace fail-opens with `NODE_BINDING_CANNOT_LOAD` and creates no file. - -`docs/architecture/optics-foundation/08-ARCHITECTURE-DECISION-PACK.md` still says the binding is not selected. `docs/planning/optics-o7-store/STORE-MANIFEST.json` still says `founder_decision_9` is `UNRESOLVED`. Those sentences describe those older files. This runtime implements the binding packet. diff --git a/docs/internal/optics-o7/BINDING-DECISION.json b/docs/internal/optics-o7/BINDING-DECISION.json deleted file mode 100644 index 88bf2e4b..00000000 --- a/docs/internal/optics-o7/BINDING-DECISION.json +++ /dev/null @@ -1,87 +0,0 @@ -{ - "document": "OPTICS_O7_NODE_BINDING_DECISION", - "audience": "INTERNAL_RESTRICTED", - "schema_status": "unstable-pre-1.0", - "verdict": "O7_NODE_BINDING_COUNCIL_PASSED", - "council": { - "agent": "bc-00af4334-6f4f-59be-9ebf-c084d3c9baa6", - "model": "Grok 4.7", - "url": "https://cursor.com/agents/bc-00af4334-6f4f-59be-9ebf-c084d3c9baa6", - "self_certified_store_implementation": false - }, - "repository": "vantioai/vantio-open-core", - "starting_commit": "0620f10ee52d3abcea18c1c988df02f687f51b36", - "observed_on": "2026-09-27", - "engine": { - "remains": "embedded SQLite with WAL", - "source": "CITED_FROM_RATIFIED_TEXT", - "sentence": "Embedded SQLite, WAL, application-owned schema, path `~/.vantio/optics/store.sqlite` under the evidence root.", - "python_mechanism": "stdlib_sqlite3" - }, - "selected_binding": "node:sqlite", - "selected_version": "24.15.0", - "selected_binding_at_version": "node:sqlite@24.15.0", - "version_meaning": "Minimum Node.js version whose 24.x documentation marks node:sqlite as a release candidate. The module is the copy built into that Node.js binary. There is no npm package and no npm integrity hash.", - "dependency_pin": { - "npm": null, - "runtime": "node>=24.15.0", - "supported_lines": ["24.x>=24.15.0", "26.x"], - "package_json_edited": false - }, - "fallback": { - "binding": "better-sqlite3", - "version": "13.0.3", - "binding_at_version": "better-sqlite3@13.0.3", - "integrity": "sha512-RbOBxmLBG8uvFUc15X9+9SFemKcQ0WBuISBVkpuiaUB2qblC8UWlHEjdWVoZ8AdhSwmoEgsiXKfopX0CQxaACQ==", - "engines": "node>=22", - "license": "MIT", - "bundled_sqlite_version": "3.53.4", - "installed": false, - "load_on_primary_failure": false, - "adoption_rule": "A later council only. If adopted, optionalDependency, timeout 0, fail-open when the addon is absent. Not a required dependency of @vantio/cli." - }, - "operational_fallback": "FAIL_OPEN_NO_FILE", - "rollback": { - "software": "Stop loading node:sqlite. Leave store.sqlite, store.sqlite-wal, and store.sqlite-shm in place. Do not down-migrate user_version.", - "sql": "BEGIN IMMEDIATE failure uses ROLLBACK. Do not replace the file with an empty database.", - "automatic_switch_to_fallback_binding": false - }, - "platforms": { - "authorized_target": "Official Node.js release binaries >=24.15.0 on 24.x and 26.x, built with the default SQLite configuration.", - "exercised_by_this_council": "One Linux workstation, Node.js v22.14.0, which is below the floor and printed the experimental warning. Temp files deleted.", - "unsupported": [ - "Node.js <24.15.0", - "Node.js 18, 20, 22, and 25", - "Node.js configured with --without-sqlite", - "Node.js configured with --shared-sqlite", - "Bun and Deno", - "WASM or in-memory exports as the store file" - ] - }, - "release_impact": { - "cli_modified": false, - "cli_version": "0.3.24", - "node_sdk_modified": false, - "node_sdk_version": "0.2.4", - "python_sdk_modified": false, - "python_sdk_version": "3.1.0", - "version_metadata_edited": false, - "future_store_engines": "Track 2 raises the private store package engines to >=24.15.0. This packet does not.", - "publication": false - }, - "honesty": { - "evidence_tier": "UNSET", - "gate_8": "CLOSED", - "architecture_pack_amended": false, - "running_open_store_reason": "NODE_BINDING_UNSELECTED", - "running_founder_decision_9": "UNRESOLVED", - "decision_9_selection": "CLOSED_BY_THIS_RECORD", - "runtime_proof": false, - "stranger_host": false, - "external_proof": "NOT_CLAIMED", - "customer_migration": false, - "default_write_path": false, - "historical_packets_rewritten": false - }, - "reading_rule": "This record selects the Node binding. docs/architecture/optics-foundation/08-ARCHITECTURE-DECISION-PACK.md still says the binding is not selected, and the running store still returns NODE_BINDING_UNSELECTED. Those older sentences stay in place. Track 2 implements this record and does not pick a different library." -} diff --git a/docs/internal/optics-o7/RUNTIME-INTEGRATION.json b/docs/internal/optics-o7/RUNTIME-INTEGRATION.json deleted file mode 100644 index 8f6523c1..00000000 --- a/docs/internal/optics-o7/RUNTIME-INTEGRATION.json +++ /dev/null @@ -1,45 +0,0 @@ -{ - "document": "OPTICS_O7_RUNTIME_INTEGRATION", - "audience": "INTERNAL_RESTRICTED", - "schema_status": "unstable-pre-1.0", - "classification": "O7_RUNTIME_INTEGRATION_READY_FOR_COUNCIL", - "council_status": "PENDING_INDEPENDENT_COUNCIL", - "self_certified_council_pass": false, - "repository": "vantioai/vantio-open-core", - "starting_commit": "ebc060f2af98362bc7e317f4a01e635138a657b1", - "selected_binding": "node:sqlite", - "selected_version": "24.15.0", - "selected_binding_at_version": "node:sqlite@24.15.0", - "npm_dependency": null, - "fallback_binding_at_version": "better-sqlite3@13.0.3", - "fallback_installed": false, - "load_fallback_on_failure": false, - "store_engines": ">=24.15.0", - "cli_engines": ">=18.3.0", - "cli_version": "0.3.24", - "node_sdk_version": "0.2.4", - "python_sdk_version": "3.1.0", - "below_floor_reason": "NODE_BINDING_CANNOT_LOAD", - "below_floor_creates_file": false, - "supported_lines": ["24.x>=24.15.0", "26.x"], - "constructor": { - "path": "filesystem path", - "readOnly": true, - "timeout": 0, - "enableForeignKeyConstraints": false, - "allowExtension": false - }, - "honesty": { - "evidence_tier": "UNSET", - "gate_8": "CLOSED", - "runtime_proof": false, - "stranger_host": false, - "external_proof": "NOT_CLAIMED", - "customer_migration": false, - "default_write_path": false, - "publication": false, - "floor_executed_by_this_force": true, - "floor_binaries": ["node-v24.15.0-linux-x64", "node-v26.10.0-linux-x64"], - "floor_host": "this workspace only" - } -} diff --git a/docs/internal/optics-pkg01/BOUNDARY.md b/docs/internal/optics-pkg01/BOUNDARY.md deleted file mode 100644 index 7d722298..00000000 --- a/docs/internal/optics-pkg01/BOUNDARY.md +++ /dev/null @@ -1,120 +0,0 @@ -# PKG-01 boundary - -Audience: INTERNAL_RESTRICTED - -Phase 1 inventory for Slice 1. This note is the implementation boundary. It does not change live writers, and it does not declare a stable schema. - -`schema_status`: `unstable-pre-1.0` - -Option: **B**. A private contract package. CLI `@vantio/cli@0.3.24` and Python `vantio-agent-sdk` 3.1.0 do not load it. - -Starting commit: `311f260a5f1bee1d3dc9b3734fd6910fb1116094` - -## What this package is - -`packages/optics-evidence-contract/` holds a machine-readable allowlist, denylist, enums, and normalization rules, plus hand-written Node and Python validators. Tests live under `tests/optics-evidence-contract/`. Nothing in this package is on a customer install path. - -The validators return a detached plain-data result. They do not write `~/.vantio/runs`, do not create a database, and do not retain a caller-supplied application result. - -## Live Node writer (frozen) - -File: `packages/vantio-cli/bin/interceptor.cjs` (read, not modified). - -Version in `packages/vantio-cli/package.json`: `0.3.24`. Engines: Node `>=18.3.0`. - -On process exit the interceptor writes one JSON object. Envelope keys written in source: - -`vantio_run_log` `"1"`, `schema_version` `2`, `plane` `"optics"`, `data_note`, `trace_id` (`RUN_TRACE_ID`, from `VANTIO_TRACE_ID` or `randomUUID()`), `pid`, `ppid`, `node_version`, `platform`, `arch`, `started_at`, `generated_at`, `duration_ms`, `cli_version`, `free_mode`, `calls`, `summary`, `residual`. - -Call keys written in that mapper: `hostname`, `provider` (including `guessProvider`), `method`, `path`, `scheme`, `request_bytes`, `bytes` (expression `call.bytes || 0`), `status`, `ok`, `content_type`, `duration_ms`, `action`, `ts`, `redactions`, `error`, `error_class`. - -Summary includes `est_spend_usd`. Residual is prose. The Node run file does not set `schema_status` and does not set `evidence_origin`. - -PII categories already named in the interceptor policy default are `ssn`, `email`, `credit_card`, and `phone`. That redactor runs on request bodies inside the live process. It is not this package, and this package does not change it. Slice 1 does not treat hashing or masking as a way to keep a secret. - -Display tokens live in `packages/vantio-cli/bin/optics-cx.cjs`: `OBSERVED`, `NOT_OBSERVED`, `UNSUPPORTED`, `UNAVAILABLE`, `APPLICATION_ERROR`, `OPTICS_ERROR`, `PARTIAL`, `SUCCESS`. `applicationStatusFromHttp` maps 200–399 to `SUCCESS`, 400–599 to `APPLICATION_ERROR`, and any other or missing status to `UNAVAILABLE`. The stored `ok` boolean is not the application outcome. `PARTIAL` there is a mixed-run display rollup. It is a different field from run `lifecycle` `PARTIAL` and from query completeness. - -Reader gate in `packages/vantio-cli/bin/vantio.js`: `loadRunLog` / `tryLoadRunLog` accept a file when `vantio_run_log === "1"`. They do not check `schema_version`. Those functions are not exported. Compatibility tests re-check the marker on fixture copies and call `applicationStatusFromHttp` from `optics-cx.cjs`. They do not start the CLI against `~/.vantio/runs`. - -`vantio demo` writes `hostname` `optics-demo.invalid`, `provider` `openai`, `POST /v1/chat/completions`, status 200, `bytes` 0, `action` `OBSERVED`. The file has no origin field. The trace id it mints is `0x` plus hex. In today’s file that string is the run boundary. - -## Live Python writer (frozen) - -File: `packages/vantio-agent-sdk-py/vantio/_http_observe.py` (read, not modified). - -Version in `pyproject.toml`: `vantio-agent-sdk` `3.1.0`. Requires Python `>=3.10`. Python 3.0.15 is not the target. - -`_write_run_log` writes only when `_calls` is non-empty and `_trace_id` is set. Envelope keys: `vantio_run_log` `"1"`, `schema_version` `2`, `schema_status`, `plane` `"optics"`, `workflow` `"sight_loop"`, `data_note`, `status_labels`, `trace_id`, `runtime` `"python"`, `mediation` (comma-joined), `started_at`, `generated_at`, `calls`, `summary`, `residual`. It does not write `pid`, `ppid`, `free_mode`, `duration_ms`, or `est_spend_usd`. - -Call objects are the in-memory records from `_record`: `hostname`, `provider`, `action`, `mediation`, `ts`, plus extras such as `status`, `ok`, `duration_ms`, `error_class`, `failure_kind`, `error`, and human outcome lines (`opticsStatus`, `applicationStatus`, `opticsLabel`, and customer outcome fields). `provider` defaults to `"other"` when the caller did not set one. - -`SCHEMA_STATUS` in `vantio/_outcome.py` is `unstable-pre-1.0`. `__version__` is `3.1.0`. - -## Fields the contract will not persist - -From the live objects, these are outside the A1 allowlist and are omitted from contract output: - -- `plane`, `data_note`, `residual`, `workflow`, `status_labels`, `free_mode` -- `summary`, including `est_spend_usd` and other cost or usage keys (Founder decision 2 stays unresolved; the safe default is exclusion) -- `ok` as an application outcome -- human prose: `opticsLabel`, `applicationOutcomeLabel`, `providerResponse`, `failure_response`, `nextAction` -- `provider` when it is a substring guess (`guessProvider`). Contract `provider_id` is `unknown` with `provider_confidence` `NONE` unless the caller already supplied an allowlisted id and a confidence the rules accept. This package does not copy the host catalog and does not guess a vendor from a hostname -- `error` message text, stack, args, header maps, cookies, prompts, completions, bodies -- machine hostname, username, working directory, environment, command line -- `redactions` counts, enforcement `action` values other than `OBSERVED` - -Legacy `trace_id` on a `vantio_run_log` file is mapped to `run_id`. It is not copied into contract `trace_id`. A4 identifies that current field as the wrapped-process boundary. Contract `trace_id` is set only from a trace-context input that passes the hex rules, with an explicit basis. `VANTIO_TRACE_ID` shape on a contract record is `ASSERTED_CONTEXT`. It is not observation proof and it does not mint `run_id`. - -Legacy `bytes` value `0` maps to `response_bytes` null. The frozen writer still stores `0`. This package does not change that writer. - -## Privacy-sensitive sources seen on the write path - -The live writers can be handed, or can copy, material the contract must refuse: - -- URL query, fragment, and userinfo on destinations the hooks already parse into `hostname` / `path` / `scheme` (the stored split is structural; a future caller can still put a raw URL or a secret into `path` or `error`) -- `error` and exception text (`_record_http_exception` can set `error` to `network_error` and always stores `error_class`) -- header and cookie maps if a caller nests them on a record -- policy and telemetry identifiers (`anonymousId` is a telemetry-file concern, not an observation field) -- PII categories named in the interceptor: email, SSN, credit card, phone -- demo host `optics-demo.invalid` - -Field-name denial is not enough. Values inside allowlisted strings are scanned. - -## Reader compatibility - -Current readers keep parsing today’s files. Contract normalization returns a new object. It does not write that object back over the fixture or into `~/.vantio/runs`. - -A missing origin stays a reader label `LEGACY_UNMARKED`. It is not stored as `LOCAL_OBSERVATION`. Destination `optics-demo.invalid` yields `SIMULATED_DEMO`. Claimed `LOCAL_OBSERVATION` without recognized producer (`node_interceptor`, `python_observe`, `demo_command`), a version string of at most 32 characters in `[A-Za-z0-9._+-]`, and an allowlisted origin is `LEGACY_UNMARKED`. The demo producer does not preserve `LOCAL_OBSERVATION`. - -## Fail-open - -`interceptor.cjs` already swallows run-log write failures. `_write_run_log` returns on exception. The private validator matches that posture for its own API: internal failures become a result object, the supplied application result is returned as a detached plain copy, and no secret from the thrown value is copied into the result. This does not claim that the live CLI or Python runtime fail open. - -This does not prove the live CLI or Python process is fail-open. Those paths are not wired to this package. - -## Out of scope for this package - -SQLite, WAL, migrations, database files, retention, pruning, trends, alerting, UI, daemon, OTLP, SIEM, stable schema, public API, package publish, tag, seal, cost and token fields, machine hostname, customer promotion of `LEGACY_UNMARKED`, a seventh annotation origin, freshness `CURRENT`, numeric performance targets, and any edit under: - -- `packages/vantio-cli/` -- `packages/vantio-agent-sdk-py/` -- `packages/vantio-agent-sdk/` -- `docs/architecture/optics-foundation/` -- `docs/planning/optics-foundation-a8/` - -Gate 8 in `docs/architecture/optics-foundation/09-IMPLEMENTATION-GATES.md` still says closed. This force opens Gate 8 only for the private PKG-01 source. That architecture file is not edited. - -## Risks recorded before coding - -| Risk | Bound | -| --- | --- | -| Cross-language drift | One corpus. Canonical JSON compared byte for byte. Both scanners load `contract/detector-classes.json`. String bounds are UTF-8 bytes | -| Hostile getters and cycles | Bounded walk. Getter throws and cycles become `REJECT_RECORD` with no exception text in the result | -| Recursion and size | Depth, key, array, node, and string caps. Over-long strings are dropped without storing a prefix | -| Secret in a diagnostic | Reason codes and remediation codes are a closed token set. Values are never interpolated | -| Unicode bypass | Session ids and field-name comparison use pinned NFC from profile `PKG01-UCD-16.0.0`. NFKC and a confusable map are detection-only. The folded form is not stored. Host ICU and CPython `unicodedata` are not the privacy decision | -| Percent-encoding and base64 | One detection decode. Decoded text is not stored. Invalid UTF-8 fails closed for that field | -| JSON number drift | Integers only, inside the safe integer range | -| Application mutation | Input objects are not written. Frozen-input tests cover that | -| False privacy pass | Removal is the disposition. No hash and no mask of a canary is stored | -| Scope leak | Scope tests fail if the CLI or Python package references this package, if versions move, or if a SQLite dependency appears | diff --git a/docs/internal/optics-pkg01/COMPATIBILITY.md b/docs/internal/optics-pkg01/COMPATIBILITY.md deleted file mode 100644 index de8a2824..00000000 --- a/docs/internal/optics-pkg01/COMPATIBILITY.md +++ /dev/null @@ -1,15 +0,0 @@ -# PKG-01 compatibility - -Audience: INTERNAL_RESTRICTED - -Compatibility fixtures are copies. The contract output is not written back over them, and the live writers are not modified. - -A Node-shaped envelope (`vantio_run_log` `"1"`, `schema_version` 2, `calls`) maps the legacy `trace_id` string onto contract `run_id`. It does not become the contract `trace_id`. Missing origin yields reader label `LEGACY_UNMARKED` and disposition `REPLACE_WITH_SAFE_CATEGORY`. `schema_version` on the contract record is `0`. The legacy integer is kept only on `compatibility.legacy_schema_version`. `plane`, `data_note`, `free_mode`, `summary`, and `residual` are omitted. `est_spend_usd` is not in the output. - -A call's `bytes` value `0` becomes `response_bytes` null. An explicit contract `response_bytes` of `0` is kept. `provider` is not inferred from the legacy string; `provider_id` is `unknown` and `provider_confidence` is `NONE` unless the caller supplied an allowlisted token. Content-type parameters are dropped. - -A Python-shaped envelope is recognized when `runtime` is `python` or `workflow` is `sight_loop`. `workflow` and `status_labels` are omitted. `schema_status` `unstable-pre-1.0` is preserved. Mediation must be one of the closed tokens or it becomes `unknown`. - -`applicationStatusFromHttp` in this package matches `packages/vantio-cli/bin/optics-cx.cjs` for integer statuses: 200–399 `SUCCESS`, 400–599 `APPLICATION_ERROR`, otherwise `UNAVAILABLE`. The compatibility test calls that frozen helper directly. It does not import `vantio.js` and it does not start a CLI against `~/.vantio/runs`. - -Python `SCHEMA_STATUS` in `vantio/_outcome.py` remains `unstable-pre-1.0`. The test reads that source. It does not call `shield` or `install`. diff --git a/docs/internal/optics-pkg01/CONFORMANCE.md b/docs/internal/optics-pkg01/CONFORMANCE.md deleted file mode 100644 index 6eaae345..00000000 --- a/docs/internal/optics-pkg01/CONFORMANCE.md +++ /dev/null @@ -1,24 +0,0 @@ -# PKG-01 conformance - -Audience: INTERNAL_RESTRICTED - -Node and Python validators are hand-written. Both read the same files in `packages/optics-evidence-contract/contract/`. Neither imports `@vantio/cli` or `vantio-agent-sdk`. - -The shared corpus is `tests/optics-evidence-contract/corpus.json` (220 cases). Each case has an input (or a base plus patch, or a language harness), one disposition, one reason, completeness impact, Optics-health impact, a remediation code, and the canary strings that must be absent from canonical output. Measured fields also record a UTF-8 byte length. Both languages assert that length with their own UTF-8 encoder. Harness cases for accessors, proxies, class instances, functions, a function-valued field, binary containers, and the isolated non-returning getter are not plain JSON. Their disposition and reason still match across languages. The non-returning getter is constructed only inside `hostile_worker.cjs` and `hostile_worker.py`. - -Privacy normalization and category membership use the committed profile `PKG01-UCD-16.0.0`. Tests recompute the profile file hashes, rerun the offline generator, and compare Node and Python verification vectors. They do not call host ICU or CPython `unicodedata` for the decision. - -Canonical JSON is sorted keys, no insignificant whitespace, integers only, and the same short control escapes in both languages. The conformance test compares those strings byte for byte. - -Run from the repository root, offline, with no package install: - -```bash -node --test tests/optics-evidence-contract/node.test.cjs -python3 tests/optics-evidence-contract/python_test.py -``` - -Node engine for this package is `>=18.3.0`, matching the frozen CLI. Python uses the stdlib only. The private package has no dependencies. - -`schema_status` on every result is `unstable-pre-1.0`. `schema_version` is `0`. `diagnostics.scope_complete` is false. `completeness_inputs.integrity_state` is `UNKNOWN`. `completeness_inputs.sampling` is `UNSAMPLED`. `compatibility.live_writer_modified` is false. - -This corpus is an internal conformance fixture. It is not a portable customer proof and it is not shipped. diff --git a/docs/internal/optics-pkg01/FAIL-OPEN.md b/docs/internal/optics-pkg01/FAIL-OPEN.md deleted file mode 100644 index aa36af2e..00000000 --- a/docs/internal/optics-pkg01/FAIL-OPEN.md +++ /dev/null @@ -1,13 +0,0 @@ -# PKG-01 fail-open - -Audience: INTERNAL_RESTRICTED - -`validateEvidence` and `validateBytes` catch their own failures and return a result. They do not throw into the caller. The caller-supplied `applicationResult` is returned as a detached plain copy when validation omits a secret, drops an event, hits the injected fault seam, receives malformed UTF-8, or receives a string longer than the input bound. The copy is not the caller's object. Mutating the input after validation does not change the result, and mutating the result does not change the input. - -The injected fault is `options.injectFault === true`. It exists so tests can force the internal path. The result reason is `VALIDATOR_FAULT`, the issue location is `OPTICS`, and the exception text is not copied into the result. - -Malformed UTF-8 bytes return `MALFORMED_UTF8` without a decoded secret. A string above `max_input_chars` returns `INPUT_BOUND` without scanning or copying the string into the result. - -Cycles and nesting at the depth bound return `CYCLE_REJECTED` and `EXCESSIVE_NESTING`. An accessor property or proxy is rejected as `ACCESSOR_PROPERTY_FORBIDDEN` before the getter runs. A plain class instance is `REJECT_RECORD` / `UNSUPPORTED_COMPLEX_VALUE`. A function or other callable is `REJECT_FIELD` / `UNSUPPORTED_COMPLEX_VALUE`. A getter that never returns is not given an in-process timeout. That case is executed only in a killable subprocess. The getter message is not stored. - -These tests cover the private validator only. They do not claim that the frozen CLI or Python runtime fail open, and they do not execute those writers. diff --git a/docs/internal/optics-pkg01/FIELD-CATALOG.md b/docs/internal/optics-pkg01/FIELD-CATALOG.md deleted file mode 100644 index 631a8160..00000000 --- a/docs/internal/optics-pkg01/FIELD-CATALOG.md +++ /dev/null @@ -1,13 +0,0 @@ -# PKG-01 field catalog - -Audience: INTERNAL_RESTRICTED - -The catalog is `packages/optics-evidence-contract/contract/field-catalog.json`. It is not a JSON Schema, and it is not a stable public schema. `schema_status` is `unstable-pre-1.0`. `schema_version` `0` means unassigned. - -120 field rows. Record classes: `run_envelope`, `observation_event`, `derived_diagnostic`, `annotation`, `product_health`, `import_quarantine`, `validation_result`. `proof_manifest` is listed as not written by this slice. - -Each row carries the canonical name, type, required flag, producer, origin, purpose, sensitivity, cardinality, index / export / proof / metric eligibility, normalization, max size, invalid disposition, compatibility note, and fixture coverage. Unknown keys are denied. Usage, token counts, cost, machine hostname, and an annotation evidence-origin are not allowlisted fields. - -Enums, ranks, and remediation codes are in `contract/enums.json`. Bounds and normalization rules are in `contract/normalization.json`. Prohibited names and detectors are in `contract/prohibited-fields.json`. Package identity and the unresolved Founder decisions are in `contract/contract-metadata.json`. - -Writer origins are `LOCAL_OBSERVATION`, `SIMULATED_DEMO`, `IMPORTED`, `TEST_FIXTURE`, `PRODUCT_HEALTH`, and `DERIVED_DIAGNOSTIC`. `LEGACY_UNMARKED` is a reader label. It is not stored as a writer origin and it is not promoted to `LOCAL_OBSERVATION`. diff --git a/docs/internal/optics-pkg01/IMPLEMENTATION-REPORT.md b/docs/internal/optics-pkg01/IMPLEMENTATION-REPORT.md deleted file mode 100644 index 068d6012..00000000 --- a/docs/internal/optics-pkg01/IMPLEMENTATION-REPORT.md +++ /dev/null @@ -1,109 +0,0 @@ -# PKG-01 implementation report - -Audience: INTERNAL_RESTRICTED - -Producer only. This report does not pass council. - -## Classification - -`OPTICS_PKG01_REVISION_READY_FOR_COUNCIL` - -Producer classification for the pinned-Unicode revision. This is not a council pass. Status for the next agent is `PENDING_INDEPENDENT_RECOUNCIL` (pinned-Unicode). The revision starts from tip `4a34ce40645ba5aa4495437d4fdfb4f7e91ac156`. Earlier council records stay historical: `INDEPENDENT-COUNCIL-REPORT.md` and `INDEPENDENT-RECOUNCIL-REPORT.md`, both `OPTICS_PKG01_NEEDS_REVISION`. - -## What landed - -Private package `packages/optics-evidence-contract/` (Option B): - -- `contract/field-catalog.json` (120 fields) -- `contract/prohibited-fields.json` -- `contract/enums.json` -- `contract/normalization.json` -- `contract/contract-metadata.json` -- `contract/detector-classes.json` -- Hand-written `src/validate.cjs`, `src/canonical.cjs`, `src/walk.cjs`, `src/privacy.cjs`, `src/unicode_profile.cjs` -- Hand-written `src/validate.py`, `src/canonical.py`, `src/walk.py`, `src/privacy.py`, `src/unicode_profile.py` -- Pinned Unicode profile `PKG01-UCD-16.0.0` under `contract/unicode-profile.json`, `contract/unicode-nfkc-map.json`, `contract/unicode-category-ranges.json`, and `contract/unicode-profile-metadata.json` -- Offline generator `tools/generate_unicode_profile.py` and committed UCD sources under `contract/unicode-source/` - -Tests: `tests/optics-evidence-contract/corpus.json` (220 fixtures), `node.test.cjs`, `python_test.py`, `hostile_worker.cjs`, `hostile_worker.py`. - -Internal notes: `docs/internal/optics-pkg01/`. - -No live CLI or Python runtime file was modified. No workflow file was modified. No architecture or planning file was modified. No SQLite module, database file, migration, UI, daemon, OTLP, SIEM, or alerting path was added. - -## Revision matrix - -Started from council head `ed2a45ee9f09a9056050f8082f0302ce24d4ad42`. - -| Blocker | Before | After | -| --- | --- | --- | -| B1 allowlisted detector values | Charset match stored the value. Privacy result null. | `REJECT_FIELD` / `DETECTOR_MATCH`. Value absent. Privacy category `DETECTOR_MATCH`. | -| B2 secret-shaped field name | `STRIP` / `UNKNOWN_FIELD_OMITTED`. Raw name copied into stripped fields. | `REJECT_FIELD` / `DETECTOR_MATCH`. Locator `UNKNOWN_FIELD_REDACTED_1`. Raw name absent from output. | -| B3 Unicode email path | Node stored the path. Python rejected it. | Both `REJECT_FIELD` / `REDACTION_DROP`. Path absent. NFC and NFD agree. | -| B4 `prompt` plus newline | Node dropped the record but echoed the raw name. Python stripped the field and echoed the raw name. | Both `REJECT_RECORD` / `PROHIBITED_FIELD_NAME`. Locator `PROHIBITED_FIELD_CATEGORY`. | -| B5 inherited trace labeled `OPTICS_GENERATED` | Caller basis stored. Traceparent meaning null. Inherited context kept `LOCAL_OBSERVATION`. | Basis replaced with `ASSERTED_CONTEXT`, or `IMPORTED_UNVERIFIED` on import quarantine. Meaning set. Conflict diagnostic set. `LOCAL_OBSERVATION` kept only with destination or HTTP evidence. | -| B6 missing status | Missing optics became `SUCCESS`. Missing action became `OBSERVED`. | Missing optics is `UNAVAILABLE` / `MISSING_REQUIRED_STATUS`. Missing action stays absent. HTTP 500 stays HTTP 500. Legacy `bytes` 0 stays null. Explicit `response_bytes` 0 stays 0. | -| B7 detached output | `application_result` was the caller reference. | Plain copy. Post-validation mutation does not cross the boundary. | -| B8 hostile accessor | Throwing getter ran and returned `HOSTILE_INPUT`. | `ACCESSOR_PROPERTY_FORBIDDEN` before the getter runs. Non-returning getter is isolated in a subprocess. No in-process timeout is claimed. | - -## Detector-parity revision - -Started from PR head `075b82508fa93b84ce7416512a8d422ed4ca4e49`. Closed B1–B8 behavior stays in the corpus. - -| Probe | Before (re-council) | After | -| --- | --- | --- | -| PAN `/pay/4111111111111111α` and the before-digit form | Node redacted. Python stored the path. | Both `REJECT_FIELD` / `REDACTION_DROP`. Path absent. Privacy category `DESTINATION_COMPONENT_REDACTED`. | -| Mixed-script `sk-`, Bearer, JWT, Basic, `ghp_`, `AKIA`, `AIza` | One language stored the value. | Both reject. Detector fields use `DETECTOR_MATCH`. A secret path uses `REDACTION_DROP` plus `DESTINATION_COMPONENT_REDACTED`. | -| `/` plus 300 U+03B1 | Node stored it. Python treated the letters as a privacy drop. | Both `REJECT_FIELD` / `MAX_SIZE_EXCEEDED`. Privacy event null. 601 UTF-8 bytes. | -| Function value | Node `HOSTILE_INPUT`. Python `ACCESSOR_PROPERTY_FORBIDDEN`. | Both `REJECT_FIELD` / `UNSUPPORTED_COMPLEX_VALUE`. | -| Secret path with no host | Path absent and privacy event null. | Path absent. Privacy category `DESTINATION_COMPONENT_REDACTED`. | -| ASCII case fold of `AKIA`, `ghp_`, `Bearer`, `Basic`, `eyJ` | Case-swapped markers were stored. | Same disposition as the canonical-case sample. `MRN:` stays case-sensitive. | - -Character classes and the reported-reason order are in `contract/detector-classes.json`. String bounds are UTF-8 bytes. `MAX_SIZE_EXCEEDED` outranks `DETECTOR_MATCH`; the value is still omitted. An ASCII letter still suppresses PAN detection. - -## Pinned-Unicode revision - -Started from tip `4a34ce40645ba5aa4495437d4fdfb4f7e91ac156`. Privacy normalization and letter/number membership read the committed profile `PKG01-UCD-16.0.0` (Unicode 16.0.0). Node ICU and CPython `unicodedata` are not the privacy decision. NFC is comparison-only. NFKC is detection-only and is not stored. A code point absent from the profile is `UNKNOWN_TO_PROFILE` and fails closed inside an email-shaped span. Pinned format controls are removed only in the detector view; a hit omits the original. A governed prefix may contain one non-ASCII insertion and still match. A walk above 8192 bytes with no detector hit in the scanned prefix is `MAX_SIZE_EXCEEDED`, privacy null, scan state `SIZE_ONLY`. A candidate that crosses that cut is `SCAN_INCOMPLETE` and scan state `BOUNDARY`, without `DETECTOR_MATCH`. `Buffer`, `Uint8Array`, `bytes`, `bytearray`, and `memoryview` are `REJECT_FIELD` / `UNSUPPORTED_COMPLEX_VALUE`. - -This is not universal confusable detection, not live runtime protection, and not a shipment. Windows, macOS, and WSL are `NOT_TESTED`. - -## Corpus - -220 shared fixtures, including harness metadata for accessor, proxy, class instance, function, function-valued field, the isolated non-returning getter, and binary containers. The earlier 185-fixture counts below are the detector-parity baseline, not the pinned-Unicode total. - -Pinned-Unicode totals: `ACCEPT` 35, `NORMALIZE` 15, `STRIP` 23, `REJECT_FIELD` 121, `REPLACE_WITH_SAFE_CATEGORY` 9, `REJECT_RECORD` 17. - -Pinned-Unicode reasons: `REDACTION_DROP` 57, `OK` 36, `DETECTOR_MATCH` 36, `MAX_SIZE_EXCEEDED` 24, `NORMALIZED` 7, `UNKNOWN_FIELD_OMITTED` 6, `CONTEXT_REJECTED` 6, `PROHIBITED_FIELD_NAME` 6, `UNSUPPORTED_COMPLEX_VALUE` 6, `SESSION_ID_REJECTED` 5, `CONFLICTING_PROVENANCE` 5, `LEGACY_UNMARKED` 4, `MISSING_REQUIRED_STATUS` 4, `ACCESSOR_PROPERTY_FORBIDDEN` 3, `PROMPT_COMPLETION_EXCLUDED` 2, `UNKNOWN_FIELD_REDACTED` 2, and one each of `BAGGAGE_OMITTED`, `DESTINATION_CONFLICT`, `PROVENANCE_INSUFFICIENT`, `SIMULATED_DEMO`, `SCHEMA_STATUS_CORRECTED`, `ENFORCEMENT_ACTION_EXCLUDED`, `OPTICS_WRITE_FAILURE`, `ANNOTATION_ORIGIN_REFUSED`, `QUERY_STRIPPED`, `DUPLICATE_CANONICAL_FIELD`, `OPTIMISTIC_DEFAULT_FORBIDDEN`. - -Detector-parity baseline (185 fixtures, historical): `ACCEPT` 33, `NORMALIZE` 15, `STRIP` 23, `REJECT_FIELD` 88, `REPLACE_WITH_SAFE_CATEGORY` 9, `REJECT_RECORD` 17. - -Detector-parity baseline reasons: `REDACTION_DROP` 45, `OK` 34, `DETECTOR_MATCH` 25, `MAX_SIZE_EXCEEDED` 17, `NORMALIZED` 7, `UNKNOWN_FIELD_OMITTED` 6, `CONTEXT_REJECTED` 6, `PROHIBITED_FIELD_NAME` 6, `SESSION_ID_REJECTED` 5, `CONFLICTING_PROVENANCE` 5, `LEGACY_UNMARKED` 4, `MISSING_REQUIRED_STATUS` 4, `ACCESSOR_PROPERTY_FORBIDDEN` 3, `UNSUPPORTED_COMPLEX_VALUE` 3, `PROMPT_COMPLETION_EXCLUDED` 2, `UNKNOWN_FIELD_REDACTED` 2, and one each of `BAGGAGE_OMITTED`, `DESTINATION_CONFLICT`, `PROVENANCE_INSUFFICIENT`, `SIMULATED_DEMO`, `SCHEMA_STATUS_CORRECTED`, `ENFORCEMENT_ACTION_EXCLUDED`, `OPTICS_WRITE_FAILURE`, `ANNOTATION_ORIGIN_REFUSED`, `QUERY_STRIPPED`, `DUPLICATE_CANONICAL_FIELD`, `OPTIMISTIC_DEFAULT_FORBIDDEN`. - -Legacy `bytes` 0 and explicit `response_bytes` 0 remain the existing fixtures `legacy-call-zero-bytes` and `explicit-zero-bytes`. The legacy fixture's completeness impact is now `MISSING_REQUIRED_STATUS` because that call has no `optics_status`. Its reason stays `LEGACY_UNMARKED`. - -Canaries used in the corpus are absent from canonical output, including the secret-shaped field-name fixture. - -## Commands and results - -Linux host. Node `v22.14.0`. Python `3.10.21`, `3.11.16`, and `3.12.3`. No npm install and no pip install of this package. - -```bash -node --test tests/optics-evidence-contract/node.test.cjs -python3 -m unittest tests/optics-evidence-contract/python_test.py -python3.10 -m unittest tests/optics-evidence-contract/python_test.py -python3.11 -m unittest tests/optics-evidence-contract/python_test.py -``` - -Node: 13 tests, 13 pass. Python 3.10.21, 3.11.16, and 3.12.3: 12 tests, OK on each interpreter. Canonical JSON matched across Node and each Python interpreter for all 220 fixtures. Declared UTF-8 byte lengths matched both encoders. Profile file hashes matched `unicode-profile-metadata.json`. The offline generator reproduced those files. Verification vectors matched in both languages. A missing profile returned `VALIDATOR_FAULT` with scan state `UNAVAILABLE` and did not copy the input PAN. Canary scan of the canonical strings passed. Scope walk found no `optics-evidence-contract` import under the live CLI or Python SDK. Validator sources do not import network clients. Privacy and profile sources do not call host Unicode category or normalization APIs. No store file was created. - -Windows: `NOT_TESTED`. macOS: `NOT_TESTED`. WSL: `NOT_TESTED`. Other Node versions: `NOT_TESTED`. - -## Gates - -This Force opens Gate 8 for PKG-01 source only. S1-G1 through S1-G8 are not claimed as passed; S1-G8 is the separate council. S1-G9 and S1-G10 are out of scope. Other implementation packages stay blocked. The architecture gate file was not edited and still describes Gate 8 as closed. - -Founder decisions 2–13 remain unresolved. - -## Hard stop - -No merge. No seal. No publish. No live integration. No in-process universal timeout claim. Council status: `PENDING_INDEPENDENT_RECOUNCIL`. diff --git a/docs/internal/optics-pkg01/INDEPENDENT-COUNCIL-REPORT.md b/docs/internal/optics-pkg01/INDEPENDENT-COUNCIL-REPORT.md deleted file mode 100644 index c8f0ec0e..00000000 --- a/docs/internal/optics-pkg01/INDEPENDENT-COUNCIL-REPORT.md +++ /dev/null @@ -1,150 +0,0 @@ -# PKG-01 independent council report - -Audience: INTERNAL_RESTRICTED - -## Classification - -`OPTICS_PKG01_NEEDS_REVISION` - -This council does not assign `OPTICS_PKG01_COUNCIL_PASSED`. It does not authorize merge, seal, publication, live CLI or Python integration, SQLite, UI, alerting, or exporters. - -## Identity - -| Item | Value | -| --- | --- | -| Council agent | `bc-795c2ba1-73bc-5a15-beba-f1505acc58cf` | -| Council run | https://cursor.com/agents/bc-795c2ba1-73bc-5a15-beba-f1505acc58cf | -| Producer agent (judgments not reused) | https://cursor.com/agents/bc-9d2eaaed-8a23-520b-8476-c64f679ba455 | -| Repository | `vantioai/vantio-open-core` | -| Draft PR | https://github.com/vantioai/vantio-open-core/pull/58 | -| Branch | `implementation/optics-pkg01-evidence-privacy` | -| Tip reviewed | `aac796416d3e6f64223445086f4a649b779c29fe` | -| Authorized base | `311f260a5f1bee1d3dc9b3734fd6910fb1116094` | -| Implementation commit | `a25cdd00e6b0e4a531bf71538899b52b1efdb151` | -| Producer classification | `OPTICS_PKG01_READY_FOR_COUNCIL` | - -The council reviewed that tip and re-ran the isolated tests. It did not edit `packages/optics-evidence-contract/` or `tests/optics-evidence-contract/`. - -## Seats - -Overall is the worst material seat. `NEEDS_REVISION` is the worst result below. No seat is `BLOCKED`. - -| # | Seat | Result | -| --- | --- | --- | -| 1 | Privacy engineering | `NEEDS_REVISION` | -| 2 | Observability semantics | `NEEDS_REVISION` | -| 3 | Node security | `NEEDS_REVISION` | -| 4 | Python security | `NEEDS_REVISION` | -| 5 | Cross-package conformance | `NEEDS_REVISION` | -| 6 | Application fail-open behavior | `PASS` | -| 7 | Compatibility | `PASS` | -| 8 | Cross-platform engineering | `PASS_WITH_NONBLOCKING_NOTES` | -| 9 | Release and scope control | `PASS` | -| 10 | Customer diagnostics | `NEEDS_REVISION` | -| 11 | Evidence verification | `NEEDS_REVISION` | -| 12 | Product positioning | `PASS` | - -## Blocking findings - -1. **Allowlisted strings are stored without the prohibited-value scan.** `contract/normalization.json` requires a scan of allowlisted strings. These writers store a charset match and skip `containsProhibited` / `contains_prohibited`. The detector returns true for each sample below. Both Node and Python emitted the sample with `privacy_event` null and reason `NORMALIZED`. - - | Field | Sample stored in the record | Confidence / record | - | --- | --- | --- | - | `schema_status_seen` | `sk-CANARYSEEN00001` | `import_quarantine` | - | `schema_status_seen` | `eyJhbGciOiJIUzI1NiJ9.eyJzdWIiOiIxIn0.sig` | `import_quarantine` | - | `detail_code` | `AKIAIOSFODNN7EXAMPLE` | `product_health` | - | `detail_code` | `AIzaCANARY0001` | `product_health` | - | `reason_code` | `ghp_CANARYTOKEN0001` | `import_quarantine` | - | `provider_id` | `sk-canary0001` | `CATALOG` and `LOCAL_OLLAMA` on `localhost:11434` in both languages. Node also stored it for `REGIONAL_PATTERN`. Python uses that same non-`NONE` branch. | - - Source: `validate.cjs` schema-status-seen store, detail-code store, quarantine reason store, and provider-id store (`confidence === "NONE"` is the branch that forces `provider_id` to `unknown`). The Python module has the same stores. - -2. **A prohibited value in a field name is copied into diagnostics and classified as an unknown field.** Input key `sk-CANARYKEYNAME0001` with value `x` produced disposition `STRIP`, reason `UNKNOWN_FIELD_OMITTED`, `privacy_event` null, and `fields.stripped` / `completeness_inputs.stripped_fields` equal to that key. `PRIVACY-DISPOSITIONS.md` says the prohibited value is not copied into the result, the reason, or a diagnostic string. The key is the prohibited value. Node and Python matched. - -3. **Node stores a Unicode email in `path`. Python rejects that path.** With `destination_host` `api.example.com` and path `/user@exämple.com`, Node emitted the path, disposition `NORMALIZE`, reason `NORMALIZED`, privacy null. `privacy.cjs` `containsProhibited` was false. Python disposition was `REJECT_FIELD`, reason `REDACTION_DROP`, path absent. Python `contains_prohibited` was true. The email scanners differ: Node accepts only ASCII local and domain characters; Python uses Unicode `isalnum`. ASCII `canary.person@example.com` is rejected by both. - -4. **Prohibited-name folding differs, so a payload name does not drop the record on Python.** Key `prompt` plus a following newline, value `sk-CANARYPROMPTNL01`: Node disposition `REJECT_RECORD`, reason `PROMPT_COMPLETION_EXCLUDED`, record omitted. Python disposition `STRIP`, reason `REDACTION_DROP`, record emitted. The secret value was absent from both canonical results. Node `normalizeName` removes `\s`. Python `normalize_name` removes only `-`, `_`, space, and tab, so the name stays out of the payload set. `isPayloadName("prompt\n")` was true on Node and false on Python. - -5. **Inherited trace context keeps a caller basis of `OPTICS_GENERATED`.** `normalization.json` sets `inherited_trace_basis` to `ASSERTED_CONTEXT`. `PRIVACY-DISPOSITIONS.md` says `VANTIO_TRACE_ID` maps to basis `ASSERTED_CONTEXT`. For `vantio_trace_id` `0123456789abcdef0123456789abcdef` plus `trace_id_basis` `OPTICS_GENERATED`, plus a sufficient `node_interceptor` / `0.3.24` / `LOCAL_OBSERVATION` tuple, both languages stored `trace_id_basis` `OPTICS_GENERATED` and `evidence_origin` `LOCAL_OBSERVATION`. `diagnostics.trace_basis_meaning` was `ASSERTED_CONTEXT_NOT_OBSERVATION_PROOF`. The same basis override on `traceparent` `00-0123456789abcdef0123456789abcdef-0123456789abcdef-01` stored `OPTICS_GENERATED` and left `trace_basis_meaning` null. `applyTrace` / `_apply_trace` uses a present enum basis before the inherited-source default. - -## Nonblocking notes - -- The shared 75-fixture corpus matches across languages, including canary absence. The blocking cases are outside that corpus. -- Missing `optics_status` is stored as `SUCCESS` when an observation is emitted, including beside `http_status` 500 and `application_status` `APPLICATION_ERROR`. The field catalog says SUCCESS means the observation object was produced. Missing `application_status` with no HTTP status is omitted. Missing `action` is stored as the const `OBSERVED`. A present action other than `OBSERVED` drops the record. -- Legacy `bytes` `0` becomes `response_bytes` null. Explicit `response_bytes` `0` stays `0`. -- A secret `path` with no destination host is omitted and is not marked privacy, because destination collection returns before the explicit-path scan when no host is chosen. The value was absent from the result. The same path with a host is `REJECT_FIELD` / `REDACTION_DROP` on both languages for an ASCII `sk-` query. -- `error_class` and a non-token `detail_code` call the privacy marker for every rejected value, including values the detector would not call a secret. -- A getter that never returns can still hang. Throwing getters, cycles, depth 20, and a 2,000,000 character string return terminal results. -- Python string length is code points. Some Node checks use UTF-16 code units. The corpus is BMP. Documented in `KNOWN-LIMITATIONS.md`. -- One detection decode is documented. This council did not treat a second encoding layer as a new defect. -- Duplicate JSON object keys remain last-key-wins, as documented. -- Gate 8 in `docs/architecture/optics-foundation/09-IMPLEMENTATION-GATES.md` still says closed. That file is not in the diff. - -## Required questions - -1. **Can prohibited content cross the validator boundary?** Yes. Finding 1 stores detector-positive tokens in `schema_status_seen`, `detail_code`, `reason_code`, and `provider_id`. Finding 3 stores a Unicode email in Node `path`. Corpus canaries in scanned fields (`path` with an ASCII `sk-` value, prompts, headers, sessions) are omitted. Top-level arrays are dropped. - -2. **Can prohibited values leak through diagnostics?** Yes. Finding 2 copies the key `sk-CANARYKEYNAME0001` into `fields.stripped` and `completeness_inputs.stripped_fields` with reason `UNKNOWN_FIELD_OMITTED`. Closed reason codes and remediation codes do not interpolate values. `issue_location_label` is not `Provider fault` on the corpus. - -3. **Can Node and Python produce different dispositions?** Yes, outside the corpus. Finding 3: Node `NORMALIZE` versus Python `REJECT_FIELD`. Finding 4: Node `REJECT_RECORD` versus Python `STRIP`, and Python still emits the record. The 75 corpus canonical strings matched byte for byte in both runners. - -4. **Can hostile input hang or crash validation?** The tested hostile cases do not. Throwing getter → `HOSTILE_INPUT` and the getter message is absent. Cycle → `CYCLE_REJECTED`. Depth 20 → `EXCESSIVE_NESTING`. Malformed UTF-8 bytes → `MALFORMED_UTF8`. A 2,000,000 character string → `INPUT_BOUND` in under the test's 2 second bound, and the result does not contain `xxxx`. `validateEvidence` / `validate_evidence` catch failures and return `VALIDATOR_FAULT` without the injected exception text. A getter that never returns is not time-bounded. - -5. **Can validation mutate caller data?** Not on the inputs exercised. Probe objects compared equal before and after `validateEvidence` / `validate_evidence`. The Node freeze test keeps `{ record_type: "nope" }`. `plainCopy` / `plain_copy` builds a new tree. `application_result` is the same reference the caller passed. - -6. **Can a validator failure escape into host code?** Not on the paths exercised. Entry points catch and return a result. `http_status` `1.5` returned a result and the same `applicationResult` reference. Canonical JSON is a separate helper and is not called inside the validator. - -7. **Can imported or simulated data masquerade as local observation?** Not on the shapes exercised. `import_quarantine` with requested `LOCAL_OBSERVATION` stored `evidence_origin` `IMPORTED`, reader `IMPORTED`, reason `ORIGIN_NOT_PROMOTED`. `original_evidence_origin` may still say `LOCAL_OBSERVATION`, which is the claimed prior label. Host `optics-demo.invalid` with `demo_command` and requested `LOCAL_OBSERVATION` stored `SIMULATED_DEMO`. An annotation with `evidence_origin` `LOCAL_OBSERVATION` refused that origin, reader `LEGACY_UNMARKED`, and did not store `LOCAL_OBSERVATION`. - -8. **Can inherited trace context masquerade as observed evidence?** Yes. Finding 5 stores `trace_id_basis` `OPTICS_GENERATED` for `vantio_trace_id` and for `traceparent`, with `evidence_origin` `LOCAL_OBSERVATION` when the producer tuple is sufficient. The `vantio_trace_id` diagnostic says `ASSERTED_CONTEXT_NOT_OBSERVATION_PROOF`. The traceparent case does not set that diagnostic. A legacy envelope `trace_id` of `0xabc123` was stored as `run_id` and was not stored as contract `trace_id`. - -9. **Can missing fields become fabricated success or zero?** Missing `optics_status` becomes `SUCCESS` on an emitted observation, including when application status is `APPLICATION_ERROR`. Missing `action` becomes `OBSERVED`. Missing `application_status` without an HTTP status is omitted. Legacy byte count `0` becomes null. Explicit `response_bytes` `0` stays `0`. Missing import `accepted` becomes false. `sampling` becomes `UNSAMPLED`. `scope_complete` stays false. `integrity_state` stays `UNKNOWN`. - -10. **Did live CLI or Python imports change?** No. The diff against `311f260a5f1bee1d3dc9b3734fd6910fb1116094` is 27 added files under `packages/optics-evidence-contract/`, `tests/optics-evidence-contract/`, and `docs/internal/optics-pkg01/`. `git grep` of `optics-evidence-contract` under `packages/vantio-cli`, `packages/vantio-agent-sdk-py`, and `packages/vantio-agent-sdk` found no matches. CLI version is `0.3.24`. Python package version is `3.1.0`. The scope test walks those trees and passed. - -11. **Did any SQLite, UI, daemon, exporter, or alerting work enter the PR?** No. The 27-file diff has no sqlite, migration, UI, daemon, OTLP, SIEM, alerting, or workflow path. The private `package.json` has no `dependencies`. `store.sqlite` is absent. The scope test asserts that. - -12. **Are all privacy fixtures deterministic?** Yes. `corpus.json` is static. The validators do not call `Math.random`, `Date.now`, or a UUID generator. The Node timing check around the long string does not enter the result. - -13. **Are all canaries absent from outputs and test artifacts?** Yes for validator outputs. Both runners assert each case's `forbidden` list against canonical JSON, and those tests passed. Independent scans of `/tmp/pkg01-python-dump.json` (75 cases, 178558 bytes) and `/tmp/pkg01-node-dump.json` (75 cases, 178409 bytes) found zero occurrences of `CANARY`, `sk-`, `AKIA`, `BEGIN PRIVATE`, `canary.person`, `4111-1111`, and `123-45-6789`. The byte gap is the outer dump encoding (`json.dumps` spaces versus `JSON.stringify`). The inner canonical strings matched in the tests. Canary tokens remain in `corpus.json` and the test files as inputs. - -14. **Does any documentation imply shipment or a stable schema?** No. Package README, `contract-metadata.json`, and `docs/internal/optics-pkg01/` say `unstable-pre-1.0`, `schema_version` 0, private, and not loaded by the live CLI or Python runtime. `stable_schema` is false. The field catalog says it is not a JSON Schema and not a stable public schema. - -## Producer claims - -| Claim | Council check | -| --- | --- | -| Paths only under the contract package, its tests, and `docs/internal/optics-pkg01/` | Confirmed. 27 added files. No other paths in the diff. | -| Option B: live CLI and Python do not import the package | Confirmed by grep and by the passing scope tests. | -| 75 fixtures and the stated disposition counts | Confirmed. `ACCEPT` 11, `NORMALIZE` 9, `STRIP` 16, `REJECT_FIELD` 27, `REPLACE_WITH_SAFE_CATEGORY` 8, `REJECT_RECORD` 4. Reason counts in `IMPLEMENTATION-REPORT.md` match a fresh count of `corpus.json`. | -| Linux Node and Python tests; other environments `NOT_TESTED` | Re-ran on this host. See below. Python 3.10 and 3.11 are not installed. Windows, macOS, and WSL were not run. | -| `schema_status` `unstable-pre-1.0`; no store writes | Confirmed on every corpus result by the tests. No database file. | -| Gate 8 opened for PKG-01 source only; other packages not advanced | The architecture gate file is unchanged and still says Gate 8 is closed. The diff does not add another implementation package. This council does not treat that prose as a pass of S1-G8. | -| Founder decisions 2–13 unresolved | `contract-metadata.json` lists 2 through 13 unresolved, with the safe defaults. No alerting, SQLite, UI, OTLP, SIEM, cost field, or `CURRENT` freshness writer was added. | -| PR still draft | Confirmed at review time: PR 58 `isDraft` true, `state` OPEN, `headRefOid` `aac796416d3e6f64223445086f4a649b779c29fe`, `baseRefOid` `311f260a5f1bee1d3dc9b3734fd6910fb1116094`. | -| 120 field rows | Confirmed. `field-catalog.json` `fields` length is 120. | - -## Test re-run - -Host: Linux `6.12.94+` x86_64. Node `v22.14.0`. Python `3.12.3`. Offline. No npm install and no pip install. Tip `aac796416d3e6f64223445086f4a649b779c29fe`. - -```bash -node --test tests/optics-evidence-contract/node.test.cjs -python3 tests/optics-evidence-contract/python_test.py -v -``` - -Node: 7 tests, 7 pass, 0 fail. Python: 6 tests, OK. The cross-language subtest passed inside both commands. - -`NOT_TESTED`: Python 3.10, Python 3.11, Windows, macOS, WSL, Node versions other than v22.14.0. - -## Confirmations - -- No live CLI or Python integration was added or authorized. -- No SQLite, UI, daemon, OTLP, SIEM, or alerting work is in the diff. -- Founder decisions 2–13 remain unresolved. -- The architecture gate file still describes Gate 8 as closed. This review does not advance any other package. -- PR 58 stays draft. This council does not merge it and does not mark it ready. - -## Next Founder choice - -Revise PKG-01. The revision stays inside the private contract, its tests, and these internal notes. Merging PKG-01 source, and any live runtime integration, stay unauthorized until a later council pass. diff --git a/docs/internal/optics-pkg01/INDEPENDENT-PINNED-UNICODE-RECOUNCIL-REPORT.md b/docs/internal/optics-pkg01/INDEPENDENT-PINNED-UNICODE-RECOUNCIL-REPORT.md deleted file mode 100644 index 6e57f7e9..00000000 --- a/docs/internal/optics-pkg01/INDEPENDENT-PINNED-UNICODE-RECOUNCIL-REPORT.md +++ /dev/null @@ -1,230 +0,0 @@ -# PKG-01 pinned-Unicode independent re-council - -Audience: INTERNAL_RESTRICTED - -## Classification - -`OPTICS_PKG01_COUNCIL_PASSED` - -Overall seat result: `PASS_WITH_NONBLOCKING_NOTES` - -This council does not merge PR #58, does not mark it ready for review, and does not authorize seal, publication, live CLI or Python integration, SQLite, a database migration, UI, a daemon, an exporter, or alerting. - -## Identity - -| Item | Value | -| --- | --- | -| Re-council agent | `bc-1cc76959-8e57-5a6a-8ced-f51acd350637` | -| Re-council run | https://cursor.com/agents/bc-1cc76959-8e57-5a6a-8ced-f51acd350637 | -| This agent is not | `bc-10931acb-5cf2-55d6-9799-f2bed1299f79` or any earlier PKG-01 producer or council | -| Repository | `vantioai/vantio-open-core` | -| Draft PR | https://github.com/vantioai/vantio-open-core/pull/58 | -| Branch | `implementation/optics-pkg01-evidence-privacy` | -| Tip reviewed | `888121476bffd9451a0de2bc7e53bbbac1e373ab` | -| PR #58 HEAD at review | `888121476bffd9451a0de2bc7e53bbbac1e373ab` | -| PR #58 draft | yes | -| Prior pinned-Unicode start | `4a34ce40645ba5aa4495437d4fdfb4f7e91ac156` | -| Authorized base | `311f260a5f1bee1d3dc9b3734fd6910fb1116094` | -| Producer classification | `OPTICS_PKG01_REVISION_READY_FOR_COUNCIL` | - -`gh pr view 58` reported `headRefOid` equal to the tip above, `isDraft: true`, and `state: OPEN`. Local `HEAD` at the start of review was that same commit, message `Pin PKG-01 privacy Unicode to committed UCD 16.0.0 tables.` - -This council did not edit `packages/optics-evidence-contract/` or `tests/optics-evidence-contract/`. - -## Scope - -The diff from `311f260a5f1bee1d3dc9b3734fd6910fb1116094` to the reviewed tip is 42 files. Every path is under `packages/optics-evidence-contract/`, `tests/optics-evidence-contract/`, or `docs/internal/optics-pkg01/`. - -The diff from `4a34ce40645ba5aa4495437d4fdfb4f7e91ac156` to the reviewed tip is 29 files in those same trees. It adds the pinned profile, the UCD sources, the offline generator, and the privacy/validate/walk changes that read the profile. It does not touch `packages/vantio-cli/`, `packages/vantio-agent-sdk/`, or `packages/vantio-agent-sdk-py/`. - -CLI `packages/vantio-cli/package.json` version is `0.3.24`. Python `packages/vantio-agent-sdk-py/pyproject.toml` version is `3.1.0`. The private package version is `0.0.0-unstable-pre-1.0`. No SQLite module, migration, UI, daemon, OTLP, SIEM, or alerting path is in the diff. - -## Pinned profile - -| Field | Value | -| --- | --- | -| Profile id | `PKG01-UCD-16.0.0` | -| Profile version | `16.0.0` | -| Generator | `pkg01-unicode-gen-1` | -| Verification vectors | 15 | -| Letter ranges | 677 | -| Number ranges | 144 | -| Other ranges | 564 | -| Format-control ranges | 21 | -| Canonical mappings | 2081 | -| Compatibility mappings | 3832 | -| Nonzero combining classes | 934 | -| Full composition exclusions | 1120 | - -Verified SHA-256, file bytes against `unicode-profile-metadata.json`: - -| File | SHA-256 | -| --- | --- | -| `unicode-profile.json` | `edceba7880051fe2ca760d94f61ec8bf6b261ace47e23d1683bf1eab333ee6b6` | -| `unicode-nfkc-map.json` | `dbebb52f69eca51c733b2bab84491b40e7711baa37e2f3dc548c971d65dd7ba3` | -| `unicode-category-ranges.json` | `9930a19217d946b0de5d8d49318c058f4af53b8c3aad59fc4dbac03058553970` | -| `unicode-source/UnicodeData.txt` | `ff58e5823bd095166564a006e47d111130813dcf8bf234ef79fa51a870edb48f` | -| `unicode-source/CompositionExclusions.txt` | `89e83cf9cc8bef6c1f8bf77e42cf6f0341dfa42e66261f4dbe9b492e7a23c8ee` | - -`CompositionExclusions.txt` identifies itself as Unicode 16.0.0. An independent parse of the committed `UnicodeData.txt` and `CompositionExclusions.txt` reproduced the committed canonical map, compatibility map, combining classes, full composition-exclusion set, and letter, number, other, and format ranges. Coarse ranges do not overlap. Every format-control range sits inside `other`. First/Last rows agree on category, combining class, and decomposition. The runtime loader checks those hashes and the 15 vectors before `profile_ready()` is true. It does not re-parse `UnicodeData.txt` on the validation path. The offline generator rewrote the committed JSON in place during the Node suite and left the worktree clean, so the generator still reproduces the pinned bytes. - -## Normalization and category membership - -Privacy NFC and NFKC are the contract functions in `unicode_profile.cjs` and `unicode_profile.py`. They decompose from the pinned maps, reorder by pinned combining class, and compose with Hangul syllable arithmetic plus the primary composite map. NFC is used for field-name comparison, session ids, and email spans. NFKC is used only as a detection view. The original string is what a clean field stores. - -Letter and number membership is a binary search of `unicode-category-ranges.json`. `L*` is `LETTER`, `N*` is `NUMBER`, every other assigned general category is `OTHER`, and a scalar absent from those ranges is `UNKNOWN_TO_PROFILE`. Assigned `Cf` is `OTHER` and also a format control. - -Source search of `packages/optics-evidence-contract/src/` found no `unicodedata` import, no `String.normalize`, no Unicode property escape, and no `str.isalpha` / `str.isalnum`. The generator does not call `unicodedata`. `ord`, `chr`, and UTF-16 code-unit walks are scalar transport. They are not property or normalization lookups. - -On Python 3.12 (`unicodedata` 15.0.0) the council compared host category and host NFC/NFKC with the contract for host-assigned characters, including every decomposition and format control. Category mismatches on host-assigned characters: 0. Normalization mismatches on host-assigned characters: 0. Multi-character sequences the host fully assigns (combining-mark order, blocking, Hangul L+V+T, angstrom, fi ligature, NBSP, ZWSP) matched. 113 profile-assigned scalars are `Cn` in that host. For those, the contract result is the privacy decision. Node v22.14.0 reports ICU 76.1 and Unicode 16.0. Its `String.normalize("NFKC")` maps U+1CCF0 to U+0030. The validator does not call that API. Python 3.10, 3.11, and 3.12 leave U+1CCF0 unchanged under host NFKC, and they still omit the outlined PAN. - -Spot checks: - -| Scalar | Profile | Host Python 3.12 | Contract NFKC | -| --- | --- | --- | --- | -| U+0870 ARABIC LETTER ALEF WITH ATTACHED FATHA | `LETTER` | `Lo` on 3.11 and 3.12; `Cn` on 3.10 (UCD 13) | identity | -| U+1C89 CYRILLIC CAPITAL LETTER TJE | `LETTER` | `Cn` | identity | -| U+1CCF0 OUTLINED DIGIT ZERO | `NUMBER` | `Cn`; host NFKC identity | U+0030 | -| U+1CCF4 / U+1CCF9 | `NUMBER` | `Cn` | U+0034 / U+0039 | -| U+10D40 GARAY DIGIT ZERO | `NUMBER` | `Cn`; no compatibility decomposition in the UCD line | identity | -| U+0378 | `UNKNOWN_TO_PROFILE` | `Cn` | identity | -| U+200E, U+200B, U+00AD, U+061C, U+FEFF, U+E0001, U+E0020 | `OTHER` and format | `Cf` | identity | - -## Unknown profile and damaged tables - -A copy of the package with each of these faults, then a fresh import, returned `REJECT_RECORD` / `VALIDATOR_FAULT` / issue location `CONFIGURATION` / scan state `UNAVAILABLE` / `privacy_event` null / `record` null. The canonical JSON did not contain the input PAN `4111111111111111`. - -- `unicode-category-ranges.json` deleted -- one byte of that file flipped, so the metadata hash no longer matches -- the metadata hash for that file replaced with 64 zeroes, file bytes left intact -- one byte of `UnicodeData.txt` flipped, so the source hash no longer matches - -The suite's `setProfileUnavailableForTest(true)` path does the same for a present table. Input text is not copied into the result. - -## Corpus - -220 shared fixtures. Counts from the corpus expectations, and the suites asserted each fixture: - -| Disposition | Count | -| --- | --- | -| `ACCEPT` | 35 | -| `NORMALIZE` | 15 | -| `STRIP` | 23 | -| `REJECT_FIELD` | 121 | -| `REPLACE_WITH_SAFE_CATEGORY` | 9 | -| `REJECT_RECORD` | 17 | - -Reason counts: `REDACTION_DROP` 57, `OK` 36, `DETECTOR_MATCH` 36, `MAX_SIZE_EXCEEDED` 24, `NORMALIZED` 7, `UNKNOWN_FIELD_OMITTED` 6, `CONTEXT_REJECTED` 6, `PROHIBITED_FIELD_NAME` 6, `UNSUPPORTED_COMPLEX_VALUE` 6, `SESSION_ID_REJECTED` 5, `CONFLICTING_PROVENANCE` 5, `LEGACY_UNMARKED` 4, `MISSING_REQUIRED_STATUS` 4, `ACCESSOR_PROPERTY_FORBIDDEN` 3, `PROMPT_COMPLETION_EXCLUDED` 2, `UNKNOWN_FIELD_REDACTED` 2, and one each of `BAGGAGE_OMITTED`, `DESTINATION_CONFLICT`, `PROVENANCE_INSUFFICIENT`, `SIMULATED_DEMO`, `SCHEMA_STATUS_CORRECTED`, `ENFORCEMENT_ACTION_EXCLUDED`, `OPTICS_WRITE_FAILURE`, `ANNOTATION_ORIGIN_REFUSED`, `QUERY_STRIPPED`, `DUPLICATE_CANONICAL_FIELD`, `OPTIMISTIC_DEFAULT_FORBIDDEN`. - -## Test matrix - -| Runtime | Unicode data | Result | -| --- | --- | --- | -| Node v22.14.0, ICU 76.1, `process.versions.unicode` 16.0 | host Unicode 16.0 | `node --test tests/optics-evidence-contract/node.test.cjs`: 13 pass, 0 fail | -| Python 3.12.3 | `unicodedata` 15.0.0 | 12 tests OK, canonical JSON matched Node for all 220 fixtures | -| Python 3.11.16 | `unicodedata` 14.0.0 | 12 tests OK, canonical JSON matched Node for all 220 fixtures | -| Python 3.10.21 | `unicodedata` 13.0.0 | 12 tests OK, canonical JSON matched Node for all 220 fixtures | -| Windows | | `NOT_TESTED` | -| macOS | | `NOT_TESTED` | -| WSL | | `NOT_TESTED` | -| Node versions other than v22.14.0 | | `NOT_TESTED` | - -Python 3.10 and 3.11 were not on the image. The council installed CPython 3.10.21 and 3.11.16 with `uv` and ran the suite there. The host OS for every run was Linux. - -## Council probes outside the corpus - -Canonical JSON for these inputs matched across Node v22.14.0 and Python 3.10, 3.11, and 3.12. "Omitted" means the original scalar and the ASCII fold of a detected secret were absent from the canonical result. - -| Probe | Result on every claimed runtime | -| --- | --- | -| Path `/pay/` plus U+1CCF0–U+1CCF9 for `4111111111111111` | `REJECT_FIELD` / `REDACTION_DROP`. Path omitted. `privacy_event` `DESTINATION_COMPONENT_REDACTED` | -| Same outlined run, 12 digits | `ACCEPT` / `OK`. Stored. Below the 13-digit floor | -| Greek alpha before the 16 outlined digits | Omitted. A non-ASCII neighbor does not suppress | -| ASCII `a` before the 16 outlined digits | Stored. Suppression runs on the NFKC view | -| U+FF21 (fullwidth A) before the 16 outlined digits | Stored. NFKC of U+FF21 is ASCII `A`, so the existing letter-boundary rule suppresses | -| Four U+200E inside an ASCII PAN | Omitted | -| ZWSP, U+200E, U+00AD, U+061C, and U+E0020 together inside an ASCII PAN | Omitted | -| U+E0020 alone inside an ASCII PAN | Omitted | -| `/a` + U+0870 + `@b.co` | Omitted, including on Python 3.10 where host category is `Cn` | -| `/a` + U+1C89 + `@b.co` | Omitted | -| `/a` + U+1CCF0 + `@b.co` | Omitted. Profile `NUMBER` counts as email alnum | -| `/a` + U+10D40 + `@b.co` | Omitted. Garay digit is `NUMBER` and has no compatibility decomposition | -| `/a` + U+10FFFF + `@b.co` | Omitted. Absent from the profile, so `UNKNOWN_TO_PROFILE` | -| `/hello` plus U+0870, U+1C89, U+0378, or one ZWSP and no secret | Stored. No privacy event | -| `AKIA` with one U+1C89 or one U+1CCF0 inserted, plus an alnum tail | `REJECT_FIELD` / `DETECTOR_MATCH`. Value omitted | -| `AKIA` with two non-format insertions (U+1C89 and U+0870) | `ACCEPT` / `OK`. Label stored. This is outside the one-insertion bound | -| Six U+200E inside `AKIA`, five ZWSP inside `ghp_`, U+00AD inside `Bearer` | Omitted | -| `product_health.detail_code` `AK` + U+200E + `IAIOSFODNN7EXAMPLE` | `REJECT_FIELD` / `DETECTOR_MATCH`. Value omitted | -| Field name `sk-` + ZWSP + `CANARYEXTRA0001` | `REJECT_FIELD` / `DETECTOR_MATCH`. Locator `UNKNOWN_FIELD_REDACTED_1`. Raw name absent | -| Exact field name `api_key` | `STRIP` / `REDACTION_DROP`. Locator is the exact name. Value absent. Closed safe-grammar rule for an exact catalog name | -| Missing `optics_status` and `action` | `NORMALIZE` / `MISSING_REQUIRED_STATUS`. Action absent. `privacy_event` null | -| Inherited `vantio_trace_id` without producer and version | `REPLACE_WITH_SAFE_CATEGORY` / `PROVENANCE_INSUFFICIENT`. Basis `ASSERTED_CONTEXT` | -| 8193 `!` | `REJECT_FIELD` / `MAX_SIZE_EXCEEDED`. `privacy_event` null. Scan `SIZE_ONLY`. Invariant `UNKNOWN` | -| 600 `!` in `path` | `REJECT_FIELD` / `MAX_SIZE_EXCEEDED`. `privacy_event` null. Scan `FULL` | -| ASCII PAN crossing byte 8192 | `MAX_SIZE_EXCEEDED`. Scan `BOUNDARY`. Completeness `SCAN_INCOMPLETE`. `privacy_event` null. Value absent | -| Outlined PAN with 10 digits inside the 8192-byte window and 6 past it | `MAX_SIZE_EXCEEDED`. Scan `SIZE_ONLY`. Completeness `NONE`. `privacy_event` null. Value absent | -| Outlined PAN fully inside the scanned prefix of an oversized string | `MAX_SIZE_EXCEEDED`. Scan `MATCHED_IN_PREFIX`. `privacy_event` `DESTINATION_COMPONENT_REDACTED`. Value absent | -| Python `bytes`, `bytearray`, `memoryview` and Node `Buffer`, `Uint8Array`, and a `Uint8Array` subarray, as the root and as `path` | `REJECT_FIELD` / `UNSUPPORTED_COMPLEX_VALUE`. `privacy_event` null. No decoded PAN | - -## Seats - -| # | Seat | Result | Rationale | -| --- | --- | --- | --- | -| 1 | Privacy engineering | `PASS_WITH_NONBLOCKING_NOTES` | Outlined PANs, U+0870, and U+1C89 are omitted on every claimed runtime. Format controls do not hide a PAN or a one-insertion prefix. The one-insertion bound and ASCII-letter suppression after NFKC are unchanged limits. | -| 2 | Unicode/data-table integrity | `PASS` | Independent derivation matches the committed tables. Host-assigned NFC/NFKC matches the contract. Damaged hashes fail closed. | -| 3 | Observability semantics | `PASS_WITH_NONBLOCKING_NOTES` | Size-only input stays privacy-null. An ASCII candidate cut by the cap is `BOUNDARY` / `SCAN_INCOMPLETE`. An outlined-digit tail cut by the cap is `SIZE_ONLY` and still omits the value. | -| 4 | Node security | `PASS` | No ICU normalization or category API on the privacy path. Binary containers are rejected without a decode. | -| 5 | Python security | `PASS` | No `unicodedata` category or normalization on the privacy path. The same containers and table faults fail closed. | -| 6 | Cross-language conformance | `PASS` | Corpus canonical JSON matches across Node and Python 3.10, 3.11, and 3.12. Council probes matched the same way. | -| 7 | Application fail-open | `PASS` | Missing, corrupt, and hash-mismatched profile data returns `VALIDATOR_FAULT` and does not copy the input PAN. | -| 8 | Compatibility | `PASS` | Live CLI 0.3.24 and Python 3.1.0 are untouched. The frozen display helper test passed. | -| 9 | Cross-platform | `PASS_WITH_NONBLOCKING_NOTES` | Linux only. Windows, macOS, WSL, and other Node versions are `NOT_TESTED`. Three Python Unicode versions on this host did not change a disposition. | -| 10 | Release and scope control | `PASS` | Diff stays in the private package, its tests, and internal docs. PR #58 stays draft. | -| 11 | Customer diagnostics | `PASS_WITH_NONBLOCKING_NOTES` | Secrets probed here are absent from diagnostics. The outlined-digit cut is reported as size-only rather than an incomplete scan. | -| 12 | Evidence verification | `PASS` | Hashes, re-derivation, corpus, failure copies, and both-language probes were run in this council. | -| 13 | Product positioning | `PASS` | Docs keep the package private, unshipped, and not a live runtime control. They do not claim host-Unicode independence beyond the pinned 16.0.0 tables. | - -No seat is `NEEDS_REVISION` or `BLOCKED`. - -## Answers - -1. Host Unicode version does not alter a disposition. Python 3.10 (UCD 13), 3.11 (UCD 14), 3.12 (UCD 15), and Node Unicode 16 produced the same canonical JSON for the outlined PAN, the U+0870 email, and the U+1C89 email. -2. Host NFKC does not alter a disposition. Python host NFKC leaves U+1CCF0 in place. The contract maps it to U+0030 and omits the PAN. The privacy path does not call host NFKC. -3. Host letter/number membership does not alter a disposition. U+0870 is `Cn` on Python 3.10 and `Lo` on 3.11 and 3.12. U+1C89 is `Cn` on all three. The profile calls both `LETTER`, and every runtime omits the email. -4. U+1CCF0–U+1CCF9 are not stored for the PAN-shaped path or the mixed ASCII/outlined path. They are stored when the NFKC view has an adjacent ASCII letter, including when that letter is the NFKC of U+FF21. That is the existing suppression rule, and both languages agree. -5. U+0870 and U+1C89 do not produce divergent email outcomes. All four claimed runtimes omit `/a` + that letter + `@b.co`. -6. Format controls do not hide a PAN or a governed prefix. U+200E, repeated ZWSP, soft hyphen, Arabic letter mark, and non-BMP tag characters were removed in the detector view, and the original value was omitted. -7. One non-ASCII insertion does not hide `AKIA`. A second non-format insertion is outside the pinned budget of one and can leave the label stored. -8. A size-only input does not produce a privacy event. 8193 `!` is `MAX_SIZE_EXCEEDED`, `privacy_event` null, scan `SIZE_ONLY`, invariant `UNKNOWN`. -9. The listed binary containers do not receive divergent reason codes. Root and field forms are `REJECT_FIELD` / `UNSUPPORTED_COMPLEX_VALUE` on Node and Python. -10. Missing or corrupt table data does not fail open. Each damaged copy rejected the record and left the PAN out of the result. -11. Corpus canaries and the council's secret strings did not appear in canonical output when the case was a detection, a table fault, or a binary reject. An exact catalog name such as `api_key` is still echoed as a strip locator. Its value is not. -12. The closed blockers did not regress. The shared corpus, including the B1–B8 fixtures, passed on Node and on Python 3.10, 3.11, and 3.12. -13. Live product imports did not change. The diff against main contains none of the CLI or SDK trees, and the scope test found no `optics-evidence-contract` import there. -14. Out-of-scope capability did not enter the PR. No SQLite, migration, UI, daemon, exporter, alerting, stable schema, or release version bump of CLI 0.3.24 or Python 3.1.0. -15. The docs do not overclaim Unicode coverage or runtime protection. They name profile `PKG01-UCD-16.0.0`, say host ICU and `unicodedata` are not the privacy decision, and mark Windows, macOS, WSL, and other Node versions `NOT_TESTED`. - -## Former blockers - -B1 through B8 remain covered by the shared corpus. That corpus passed on every claimed runtime in this council. Additional probes for a detector-positive allowlisted `detail_code`, a secret-shaped field name with a format control, a missing status and action, and an inherited trace matched the closed outcomes and matched across languages. - -## Non-blocking notes - -- The boundary heuristic looks for an ASCII digit tail, an `AKIA` or OpenAI prefix, or an email in the raw scanned prefix. It does not run pinned NFKC first. A partial outlined-digit PAN that crosses the 8192-byte cut is therefore `SIZE_ONLY` with completeness `NONE`, not `BOUNDARY` / `SCAN_INCOMPLETE`. The field is still omitted, `privacy_event` is null, and `privacy_invariant` is `UNKNOWN`. A full outlined PAN inside the scanned prefix is `MATCHED_IN_PREFIX`. -- PAN suppression is decided after NFKC. U+FF21 plus outlined digits is stored because the detection view is ASCII `A` plus ASCII digits. A Greek letter beside the same digits is omitted. -- Governed prefixes allow one non-ASCII insertion. Two insertions can store the label. Format controls are stripped before that budget and do not consume it. -- Exact safe-grammar prohibited names are echoed as strip locators. Detector-shaped names are not. -- Runtime integrity is the metadata hash plus the 15 vectors plus the source-file hashes. A commit that changed a derived table and the metadata hash together would load. The generator suite and this council's re-derivation both match the current commit. -- A long base64-alphabet string can still be treated as a secret. That limit is already written in `KNOWN-LIMITATIONS.md`. The size-only probe used `!` so it would not trip that rule. - -## Gate 8 - -Gate 8 stays open only for this private package. `docs/architecture/optics-foundation/09-IMPLEMENTATION-GATES.md` is not in the diff. S1-G9 and S1-G10 are out of scope. Founder decisions 2–13 stay unresolved. The package is not loaded by the live CLI or the live Python SDK. - -## Recommendation - -No further revision is required for the pinned-Unicode privacy locks. Source-only merge of draft PR #58 is a separate founder authorization. This council does not merge, does not mark the PR ready, and does not seal or publish. - -## Confirmation - -No merge. No live CLI or Python integration. CLI 0.3.24 unchanged. Python 3.1.0 unchanged. No version change of those packages. No SQLite, database, or migration. No UI, daemon, exporter, or alerting. No stable schema. No RC, seal, or publication. No registry, credential, or announcement change. diff --git a/docs/internal/optics-pkg01/INDEPENDENT-RECOUNCIL-REPORT.md b/docs/internal/optics-pkg01/INDEPENDENT-RECOUNCIL-REPORT.md deleted file mode 100644 index 9001bdd8..00000000 --- a/docs/internal/optics-pkg01/INDEPENDENT-RECOUNCIL-REPORT.md +++ /dev/null @@ -1,178 +0,0 @@ -# PKG-01 independent re-council report - -Audience: INTERNAL_RESTRICTED - -## Classification - -`OPTICS_PKG01_NEEDS_REVISION` - -This re-council does not assign `OPTICS_PKG01_COUNCIL_PASSED`. It does not authorize merge, seal, publication, live CLI or Python integration, SQLite, UI, a daemon, OTLP, SIEM, or alerting. - -The first council record stays in `INDEPENDENT-COUNCIL-REPORT.md`. This file does not replace it. - -## Identity - -| Item | Value | -| --- | --- | -| Re-council agent | `bc-88b874ba-c80d-593c-be31-7332c8ba3f89` | -| Re-council run | https://cursor.com/agents/bc-88b874ba-c80d-593c-be31-7332c8ba3f89 | -| Original producer (judgments not reused) | `bc-9d2eaaed-8a23-520b-8476-c64f679ba455` | -| First council (judgments not reused) | `bc-795c2ba1-73bc-5a15-beba-f1505acc58cf` | -| Revision producer (judgments not reused) | `bc-a3731408-ea62-5894-8cd4-6f123ad7bc68` | -| Repository | `vantioai/vantio-open-core` | -| Draft PR | https://github.com/vantioai/vantio-open-core/pull/58 | -| Branch | `implementation/optics-pkg01-evidence-privacy` | -| Tip reviewed | `6da63f8aafceb7eed3950975d224848fec6c3ba5` | -| Prior council head | `ed2a45ee9f09a9056050f8082f0302ce24d4ad42` | -| Authorized base | `311f260a5f1bee1d3dc9b3734fd6910fb1116094` | -| Producer classification | `OPTICS_PKG01_REVISION_READY_FOR_COUNCIL` | - -The re-council reviewed that tip, re-ran the isolated tests, and ran an independent probe outside the corpus. It did not edit `packages/optics-evidence-contract/` or `tests/optics-evidence-contract/`. - -## Seats - -Overall is the worst material seat. `NEEDS_REVISION` is the worst result below. No seat is `BLOCKED`. - -| # | Seat | Result | -| --- | --- | --- | -| 1 | Privacy engineering | `NEEDS_REVISION` | -| 2 | Observability semantics | `PASS_WITH_NONBLOCKING_NOTES` | -| 3 | Node security | `PASS_WITH_NONBLOCKING_NOTES` | -| 4 | Python security | `NEEDS_REVISION` | -| 5 | Cross-language conformance | `NEEDS_REVISION` | -| 6 | Application fail-open | `PASS` | -| 7 | Compatibility | `PASS` | -| 8 | Cross-platform | `PASS_WITH_NONBLOCKING_NOTES` | -| 9 | Release and scope control | `PASS` | -| 10 | Customer diagnostics | `PASS_WITH_NONBLOCKING_NOTES` | -| 11 | Evidence verification | `PASS_WITH_NONBLOCKING_NOTES` | -| 12 | Product positioning | `PASS` | - -## Blocking finding - -**Python and Node use different character classes, so the same plain string gets two dispositions, and Python persists a PAN that Node redacts.** - -`privacy.cjs` classifies bearer, basic, OpenAI tails, JWT segments, MRN tails, card boundaries, and base64 runs with ASCII ranges. `privacy.py` uses `str.isalnum()` or `str.isalpha()` in `_has_bearer`, `_has_basic`, `_has_openai`, `_has_jwt`, `_has_mrn`, `_has_card`, and `_b64_char`. Python 3.10.21, 3.11.16, and 3.12.3 agreed with each other. They disagreed with Node. The 116-fixture corpus has no such input, so a green corpus run does not cover this. - -| Input | Node v22.14.0 | Python 3.10 / 3.11 / 3.12 | -| --- | --- | --- | -| `path` `/pay/4111111111111111α` with host `api.example.com` | `REJECT_FIELD` / `REDACTION_DROP`. Path absent. `privacy_event` `REDACTION_DROP` | `NORMALIZE` / `NORMALIZED`. Path stored. `privacy_event` null | -| `path` `/pay/α4111111111111111` | Same rejection. Path absent | Path stored. `privacy_event` null | -| `path` `/sk-ABCDEFGαHIJK` | `NORMALIZE`. Path stored. `privacy_event` null | `REJECT_FIELD` / `REDACTION_DROP`. Path absent | -| `source_label` `Bearer abcdefgαHIJK` | Value stored. `privacy_event` null | `REJECT_FIELD` / `DETECTOR_MATCH`. Value absent | -| `source_label` `eyJhbGciOiJIUzI1NiJ9.abcα` | Value stored. `privacy_event` null | `REJECT_FIELD` / `DETECTOR_MATCH`. Value absent | -| `duplicate_of` `Basic abcdefgαHIJK` | Value stored | `REJECT_FIELD` / `REDACTION_DROP`. Value absent | -| `path` `/` plus 300 U+03B1 letters | Path stored. `privacy_event` null | `REJECT_FIELD` / `REDACTION_DROP`. Path absent. Privacy set | - -`α` is U+03B1. Scanner checks on the same interpreters also disagreed for `MRN:ABCDEα` (Node false, Python true) and for ASCII controls that both already flag (`Bearer abcdefgh`, `Basic abcdefgh`, a bare 16-digit PAN, `4111-1111-1111-1111`). - -The PAN row is the privacy failure. Python's card rule treats a following or preceding non-ASCII letter as a letter boundary, so a 16-digit PAN in an allowlisted `path` is kept. Node's ASCII letter check redacts that path. The token and base64 rows are the other side of the same split: Node keeps strings Python's scanner calls prohibited, and a long Unicode letter run becomes a Python privacy drop because `_b64_char` treats those letters as base64. - -Required outcome for the next revision: - -- One canonical result on Node and on Python 3.10, 3.11, and 3.12 for each input above. -- A 13–19 digit PAN stays absent from both outputs when the adjacent character is a non-ASCII letter. Matching Python to Node's current ASCII card check does that. Copying `str.isalpha()` onto Node would persist the PAN on both sides. -- Bearer, basic, OpenAI, JWT, MRN, and base64 use one shared character class, so a non-ASCII letter cannot make only one language persist the string. -- Add these inputs to the shared corpus. The current 116 fixtures do not fail on this defect. - -`BOUNDARY.md` already says the scanners are loops and ASCII classes. `privacy.py` does not follow that for the functions named above. - -## Former blockers - -Independent inputs, both languages, tip `6da63f8aafceb7eed3950975d224848fec6c3ba5`. Canonical JSON matched on these rows. The summary fields that look like `undefined` versus `null` are absent values, not different stored strings. - -| ID | Result | -| --- | --- | -| B1 allowlisted detector values | Closed for the canonical samples. `schema_status_seen` `sk-CANARYSEEN00001` and the sample JWT, `detail_code` `AKIAIOSFODNN7EXAMPLE` and `AIzaCANARY0001`, `reason_code` `ghp_CANARYTOKEN0001`, and `provider_id` `sk-canary0001` at `CATALOG`, `LOCAL_OLLAMA`, `REGIONAL_PATTERN`, and `NONE` are `REJECT_FIELD` / `DETECTOR_MATCH`. The value is absent. `privacy_event` is `DETECTOR_MATCH`. On the provider rows the confidence enum remains and `provider_id` does not. | -| B2 secret-shaped field name | Closed. Key `sk-CANARYKEYNAME0001` and key `AKIAIOSFODNN7EXAMPLE` are `REJECT_FIELD` / `DETECTOR_MATCH` with stripped locator `UNKNOWN_FIELD_REDACTED_1`. The raw name is absent. | -| B3 Unicode email path | Closed. `/user@exämple.com` in NFC and in NFD is `REJECT_FIELD` / `REDACTION_DROP` on both languages. Path absent. `privacy_event` `REDACTION_DROP`. ASCII `canary.person@example.com` is rejected by both. | -| B4 `prompt` plus a control or fold | Closed. `prompt` plus newline, CR, tab, U+200B, U+2028, or U+FEFF, and the folded name `Prompt`, are `REJECT_RECORD` / `PROHIBITED_FIELD_NAME` with locator `PROHIBITED_FIELD_CATEGORY`. Exact `prompt` is `REJECT_RECORD` / `PROMPT_COMPLETION_EXCLUDED` and the locator is the catalog name `prompt`. The raw disguised name is absent. `privacy_event` is `REDACTION_DROP`. | -| B5 inherited trace | Closed for a caller basis without the witness. `vantio_trace_id` or `traceparent` plus caller basis `OPTICS_GENERATED` is stored as `ASSERTED_CONTEXT`, or `IMPORTED_UNVERIFIED` for `traceparent` on `import_quarantine`. `trace_basis_meaning` is set. `provenance_conflict` is `TRACE_BASIS_REPLACED`. | -| B6 missing status and action | Closed. Missing `optics_status` is stored as `UNAVAILABLE` with reason `MISSING_REQUIRED_STATUS`, including beside HTTP 500, which stays `application_status` `APPLICATION_ERROR`. Missing `action` stays absent. Missing both leaves `optics_status` `UNAVAILABLE`, action absent, and `application_status` absent. | -| B7 detached output | Closed on the exercised objects. Validation copies first. Mutating `destination_host` on the input after the call leaves the result on `api.example.com`. Mutating the result leaves the input on the caller's later value. The fail-open test keeps a nested `application_result` copy that is not the caller's object. | -| B8 hostile accessor | Closed on the exercised shapes. Own getter, nested getter, array element getter, and prototype getter: Node call count stays 0 and the reason is `ACCESSOR_PROPERTY_FORBIDDEN`. Python dict-subclass property and the harness proxy: call count stays 0. A plain class is `UNSUPPORTED_COMPLEX_VALUE`. The non-returning getter runs only in `hostile_worker.cjs` / `hostile_worker.py`; the parent reports `CALLS 0` and `ACCESSOR_PROPERTY_FORBIDDEN`, and the hang mode is killed by the parent's timeout. | - -Inherited trace plus a sufficient producer and version, with no destination and no HTTP status, does not store `evidence_origin`. Reader label is `LEGACY_UNMARKED`. With a destination or an HTTP status, `LOCAL_OBSERVATION` can remain. That remaining origin is the destination or HTTP evidence. - -The private witness `PKG01_OPTICS_GENERATED_WITNESS`, together with a recognized producer and a version, stores basis `OPTICS_GENERATED` for a direct `trace_id` and for `vantio_trace_id`. Without a destination or HTTP status, that witness still does not store `LOCAL_OBSERVATION`. The witness is the static contract value. It is not persisted. This matches `normalization.json` and `PRIVACY-DISPOSITIONS.md`. - -## Nonblocking notes - -- Case-swapped cloud markers are stored by both languages with `privacy_event` null. `akiaiosfodnn7example` was stored in `detail_code`, `provider_id`, `error_class`, `cli_or_sdk_version`, `path`, `source_label`, `duplicate_of`, `text`, and `session_id`. `aizacanary0001` was stored in `provider_id`. `GHP_CANARYTOKEN0001` was stored in quarantine `reason_code`. `XOXB-CANARY0001` was stored in `schema_status_seen`. The canonical-case samples `AKIA…`, `AIza…`, `ghp_…`, and `sk-…` are rejected. `sk-` is case-folded. `AKIA`, `AIza`, `ghp_`, `xoxb-`, and `ya29.` are literal. Both scanners agree, so this is coverage, not a language split. -- A digit run bounded by an ASCII letter is stored by both languages. `path` `/pay/4111111111111111a` stays in the record. `KNOWN-LIMITATIONS.md` already says a letter boundary suppresses card detection. -- A secret `path` with no destination host is omitted and `privacy_event` stays null. The probed value `/sk-CANARYPATH00001` was absent from the canonical result. Collection returns before the path scan when no host is chosen. -- A safe grammar name such as `customer_note` is echoed in `fields.stripped`. Unsafe names use `UNKNOWN_FIELD_REDACTED_n` or `PROHIBITED_FIELD_CATEGORY`. -- A function value is rejected by both languages and is not present in the record. Node's reason is `HOSTILE_INPUT`. Python's reason is `ACCESSOR_PROPERTY_FORBIDDEN`. -- There is no in-process timeout. The hang proof is the killable subprocess. The suite's hang mode returned `ETIMEDOUT` under the parent's 500 ms limit and did not fail the test. -- Python string length is code points. Some Node checks use UTF-16 code units. The corpus is BMP. That limit is already in `KNOWN-LIMITATIONS.md`. -- One detection decode is the documented scanner depth. -- Gate 8 in `docs/architecture/optics-foundation/09-IMPLEMENTATION-GATES.md` is outside this diff and still describes Gate 8 as closed. The package notes say this force opens Gate 8 only for the private package. -- Windows, macOS, WSL, and Node versions other than v22.14.0 were not run. - -## Required questions - -1. **Can detector-positive content cross through any allowlisted string?** Yes. Python stores `/pay/4111111111111111α` and `/pay/α4111111111111111`. Node stores `/sk-ABCDEFGαHIJK`, `Bearer abcdefgαHIJK`, `eyJhbGciOiJIUzI1NiJ9.abcα`, and `Basic abcdefgαHIJK` in allowlisted strings. The canonical B1 samples do not cross. A walk of the 110 plain corpus results found no stored string for which Node `containsProhibited` returned true. - -2. **Can a secret-shaped field name appear in diagnostics?** No for the names probed. `sk-CANARYKEYNAME0001` and `AKIAIOSFODNN7EXAMPLE` become `UNKNOWN_FIELD_REDACTED_1`. Disguised `prompt` names become `PROHIBITED_FIELD_CATEGORY`. A safe grammar name can still be echoed. - -3. **Can Node and Python disagree for Unicode or normalized field names?** Yes for the Unicode values in the blocking finding. The normalized names that were probed agree: `prompt` plus newline, CR, tab, space, case fold, ZWSP, line separator, and BOM. - -4. **Can inherited trace context claim `OPTICS_GENERATED`?** Only together with the private witness, a recognized producer, and a version. A caller basis `OPTICS_GENERATED` on `vantio_trace_id` or `traceparent` without that witness is stored as `ASSERTED_CONTEXT`, or `IMPORTED_UNVERIFIED` for import `traceparent`. - -5. **Can inherited trace context establish `LOCAL_OBSERVATION` by itself?** No. With producer `node_interceptor`, version `0.3.24`, and no destination or HTTP status, `evidence_origin` is absent. A destination or HTTP status can keep `LOCAL_OBSERVATION`. - -6. **Can a missing status become `SUCCESS`?** No. Missing `optics_status` is `UNAVAILABLE`. HTTP 500 stays `APPLICATION_ERROR`. Missing `application_status` with no HTTP status is omitted. The corpus case `missing-application-status-no-http` passed with that shape. - -7. **Can a missing action become `OBSERVED`?** No. The action key stays absent. Reason `MISSING_REQUIRED_STATUS` is recorded. - -8. **Can input mutation change validator output?** No on the objects exercised. The input compared equal to its pre-call snapshot. A later write to `destination_host` left the result on `api.example.com`. - -9. **Can output mutation change input?** No on the objects exercised. Writing the result host left the caller object on its own value. The nested `application_result` in the fail-open test is a separate tree. - -10. **Can arbitrary executable objects reach output?** No. A function value is rejected and omitted. Prototype getters, proxies, and class instances are rejected. The record is null. - -11. **Can accessor-bearing input execute during ordinary traversal?** No on the shapes exercised. Node own, nested, array, and prototype getters stayed at call count 0. Python property and dict-subclass hooks stayed at call count 0. The harness asserts the same for the accessor and proxy fixtures. - -12. **Can a non-returning hostility test hang the test suite?** No. `hostile_worker` validate mode printed `CALLS 0` and `ACCESSOR_PROPERTY_FORBIDDEN` inside the 2 second parent limit. Hang mode was killed by the parent timeout. The validator does not claim an in-process timeout. - -13. **Can privacy-triggered dispositions leave privacy result null?** No for the privacy reason codes checked. The 110 plain corpus results with reason `REDACTION_DROP`, `DETECTOR_MATCH`, `PROHIBITED_FIELD_NAME`, or `PROMPT_COMPLETION_EXCLUDED` all had a non-null `privacy_event`. A control-character unknown name is `STRIP` / `UNKNOWN_FIELD_REDACTED` with `privacy_event` null, which is the written non-privacy redaction. A secret path with no host is omitted without a privacy disposition. - -14. **Can diagnostics leak canaries?** The corpus ban list and each case `forbidden` list passed on Node and on Python 3.10, 3.11, and 3.12. Secret-shaped field names are replaced with locators. Case-swapped marker strings can still be stored in allowlisted record fields; see the nonblocking note. Those stored values are record fields, and the canonical-case canaries from B1 and B2 were absent. - -15. **Did live CLI or Python imports change?** No. The diff against `311f260a5f1bee1d3dc9b3734fd6910fb1116094` is 30 added files under `packages/optics-evidence-contract/`, `tests/optics-evidence-contract/`, and `docs/internal/optics-pkg01/`. `git diff` of `packages/vantio-cli/package.json` and `packages/vantio-agent-sdk-py/pyproject.toml` is empty. CLI version is `0.3.24`. Python package version is `3.1.0`. A search for `optics-evidence-contract` under `packages/vantio-cli`, `packages/vantio-agent-sdk-py`, and `packages/vantio-agent-sdk` found no matches. The scope test passed. - -16. **Did SQLite, UI, daemon, exporter, alerting, or release work enter the PR?** No. The 30-file diff has no sqlite, migration, UI, daemon, OTLP, SIEM, alerting, workflow, architecture, or planning path. The private `package.json` has no `dependencies`. `store.sqlite` is absent. Founder decisions 2–13 stay unresolved in `contract-metadata.json`. - -17. **Does documentation overclaim runtime protection or stable schema?** No. The package README, `contract-metadata.json`, and `docs/internal/optics-pkg01/` say `unstable-pre-1.0`, `schema_version` 0, private, and not loaded by the live CLI or Python runtime. `stable_schema` is false. Fail-open notes say they cover this validator only. The field catalog says it is not a JSON Schema and not a stable public schema. - -## Test matrix - -Host: Linux `6.12.94+` x86_64. Offline. No npm install and no pip install of this package. Tip `6da63f8aafceb7eed3950975d224848fec6c3ba5`. - -| Command | Interpreter | Result | -| --- | --- | --- | -| `node --test tests/optics-evidence-contract/node.test.cjs` | Node v22.14.0 | 10 tests, 10 pass, 0 fail | -| `python3 -m unittest tests/optics-evidence-contract/python_test.py` | Python 3.12.3 | 9 tests, OK | -| `python3.11 -m unittest tests/optics-evidence-contract/python_test.py` | Python 3.11.16 | 9 tests, OK | -| `python3.10 -m unittest tests/optics-evidence-contract/python_test.py` | Python 3.10.21 | 9 tests, OK | - -Each Python run compares canonical JSON with Node. The Node run compares canonical JSON with Python 3.12. All 116 fixtures matched inside those runs, including canary absence. Python 3.10, 3.11, and 3.12 then produced identical probe JSON for the out-of-corpus set, and that JSON disagreed with Node on the blocking rows. - -`NOT_TESTED`: Windows, macOS, WSL, Node versions other than v22.14.0. - -Corpus count checked from `corpus.json`: 116 cases. Disposition counts: `ACCEPT` 15, `NORMALIZE` 15, `STRIP` 22, `REJECT_FIELD` 39, `REPLACE_WITH_SAFE_CATEGORY` 9, `REJECT_RECORD` 16. `field-catalog.json` has 120 field rows. - -## Confirmations - -- PR 58 was draft at review time: `isDraft` true, `state` OPEN, `headRefOid` `6da63f8aafceb7eed3950975d224848fec6c3ba5`, `baseRefOid` `311f260a5f1bee1d3dc9b3734fd6910fb1116094`. This re-council does not merge it and does not mark it ready. -- No live CLI or Python integration was added or authorized. -- No SQLite, UI, daemon, OTLP, SIEM, or alerting work is in the diff. -- Founder decisions 2–13 remain unresolved. -- The architecture gate file still describes Gate 8 as closed. This review does not advance any other package. -- No in-process universal timeout is claimed. - -## Next Founder choice - -Revise PKG-01 again. The revision stays inside the private contract, its tests, and these internal notes. The blocking character-class split has to close before a later council can pass the package. - -Merging PKG-01 source, and any live runtime integration, stay unauthorized. diff --git a/docs/internal/optics-pkg01/KNOWN-LIMITATIONS.md b/docs/internal/optics-pkg01/KNOWN-LIMITATIONS.md deleted file mode 100644 index 4e8bfe63..00000000 --- a/docs/internal/optics-pkg01/KNOWN-LIMITATIONS.md +++ /dev/null @@ -1,21 +0,0 @@ -# PKG-01 known limitations - -Audience: INTERNAL_RESTRICTED - -- Gate 8 in `docs/architecture/optics-foundation/09-IMPLEMENTATION-GATES.md` still says closed. This Force opens Gate 8 only for this private package. That architecture file was not edited. -- Founder decisions 2–13 stay unresolved. Safe defaults are recorded in `contract/contract-metadata.json`: no usage or cost, no alerting, no numeric performance target, no at-rest encryption choice, no promotion of `LEGACY_UNMARKED`, no seventh annotation origin, no Windows ACL claim, no SQLite binding, no `CURRENT` freshness, no machine hostname, no OTLP or SIEM export, no UI. -- No host catalog. A legacy provider string is omitted rather than guessed. `LOCAL_OLLAMA` is kept only when the normalized host is `localhost`, `127.0.0.1`, or `::1` and the port is `11434`. Otherwise provider id becomes `unknown` and confidence `NONE`. -- `CATALOG` and `REGIONAL_PATTERN` are accepted only when the caller sends those tokens and a provider id that matches the id charset. They are not inferred from the host. -- Detection folds confusables and applies one percent-decode and one base64 pass. It does not store the folded or decoded text. A long base64-alphabet string can be treated as a secret even when the decoded bytes are not a credential. The oversize-path fixture uses `!` so the path rule is the one under test. -- Phone detection requires a separator or parentheses, so a hex trace is not classified as a phone. Card detection suppresses a 13–19 digit run only when an ASCII letter is adjacent. A non-ASCII neighbor does not suppress the run. `/pay/4111111111111111a` stays stored. That is a known gap, not a second character class. -- Credential prefixes in `contract/detector-classes.json` fold ASCII A–Z only. `MRN:` is the only intentionally case-sensitive prefix. Mixed-script insertion does not end a credential tail. A governed prefix may contain one non-ASCII insertion between its characters. Ordinary internationalized text without a governed prefix is not a credential. Format controls are stripped only in the detector view. This is not universal secret detection, not transliteration, and not confusable-homoglyph detection beyond the existing detection-only map. -- Non-zero timestamp offsets are rejected, not converted. Only `Z`, `+00:00`, and `-00:00` are accepted, and the stored form is `YYYY-MM-DDTHH:MM:SS.mmmZ`. -- Identical JSON object keys are not visible. Parsers keep the last key. Distinct keys that share a comparison form are rejected as `DUPLICATE_CANONICAL_FIELD`. -- Integers above `9007199254740991` are not a conformance claim. Fixtures stay inside that range. -- Contract string bounds are UTF-8 bytes. Historical `*_chars` keys in `normalization.json` are byte limits. A lone UTF-16 surrogate is malformed text; its byte length, when measured, counts as 3 so Node `Buffer.byteLength` and Python agree. Session overflow still reports `SESSION_ID_REJECTED`, measured in UTF-8 bytes. -- There is no importer and no annotation store. Import and annotation objects are contract fixtures only. An import does not receive a fresh observation basis in this slice. -- `scope_complete` is always false. Record acceptance is not a scope-wide completeness claim. -- The accepted input is plain JSON data: objects, arrays, and approved primitives. A function or other callable is `REJECT_FIELD` / `UNSUPPORTED_COMPLEX_VALUE`. Node `Buffer` and `Uint8Array`, and Python `bytes`, `bytearray`, and `memoryview`, use that same field disposition. A plain class instance stays `REJECT_RECORD` / `UNSUPPORTED_COMPLEX_VALUE`. An accessor, proxy, or descriptor is `REJECT_RECORD` / `ACCESSOR_PROPERTY_FORBIDDEN` before the getter runs. Other isolated adversity that is not one of those shapes is `HOSTILE_INPUT`. There is no in-process timeout for a getter that never returns. That case is tested only in a killable subprocess. -- Privacy NFC, NFKC, and letter/number membership are the committed profile `PKG01-UCD-16.0.0`. A scalar absent from that profile is `UNKNOWN_TO_PROFILE`. The profile does not claim every future Unicode assignment, and it does not claim visual confusable detection. If the profile files are missing or fail their hash check, the validator returns `VALIDATOR_FAULT` and does not accept the record. -- Python 3.10.21, 3.11.16, and 3.12.3 were run on this Linux host with Node v22.14.0. Windows, macOS, and WSL were not run. Those are `NOT_TESTED`. Node versions other than v22.14.0 are `NOT_TESTED`. -- The package is private, unversioned for release, and not loaded by the live CLI or Python runtime. diff --git a/docs/internal/optics-pkg01/PENDING-COUNCIL.md b/docs/internal/optics-pkg01/PENDING-COUNCIL.md deleted file mode 100644 index 3c005351..00000000 --- a/docs/internal/optics-pkg01/PENDING-COUNCIL.md +++ /dev/null @@ -1,39 +0,0 @@ -# PKG-01 council status - -Audience: INTERNAL_RESTRICTED - -`OPTICS_PKG01_COUNCIL_PASSED` (pinned-Unicode re-council) - -Overall seat result: `PASS_WITH_NONBLOCKING_NOTES` - -This pass is not a merge authorization. PR #58 stays draft. Do not seal, publish, or integrate the live CLI or Python runtime from this branch. - -Pinned-Unicode re-council record: `docs/internal/optics-pkg01/INDEPENDENT-PINNED-UNICODE-RECOUNCIL-REPORT.md` - -Reviewed tip: `888121476bffd9451a0de2bc7e53bbbac1e373ab` - -Re-council agent: `bc-1cc76959-8e57-5a6a-8ced-f51acd350637` - -The producer classification was `OPTICS_PKG01_REVISION_READY_FOR_COUNCIL`. The producer did not self-council. - -Detector-parity re-council record: `docs/internal/optics-pkg01/INDEPENDENT-RECOUNCIL-REPORT.md` - -Earlier re-council tip: `6da63f8aafceb7eed3950975d224848fec6c3ba5` - -Earlier re-council agent: `bc-88b874ba-c80d-593c-be31-7332c8ba3f89` - -Earlier re-council classification: `OPTICS_PKG01_NEEDS_REVISION` - -First council report: `docs/internal/optics-pkg01/INDEPENDENT-COUNCIL-REPORT.md` - -First council classification: `OPTICS_PKG01_NEEDS_REVISION` - -First council agent: `bc-795c2ba1-73bc-5a15-beba-f1505acc58cf` - -Draft PR: https://github.com/vantioai/vantio-open-core/pull/58 - -Branch: `implementation/optics-pkg01-evidence-privacy` - -Do not merge PR #58 or PR #59. Do not seal, publish, or integrate the live CLI or Python runtime from this branch. - -Founder choice: pin Unicode privacy truth to committed contract data. Runtime integration stays unauthorized. diff --git a/docs/internal/optics-pkg01/PRIVACY-DISPOSITIONS.md b/docs/internal/optics-pkg01/PRIVACY-DISPOSITIONS.md deleted file mode 100644 index e939724d..00000000 --- a/docs/internal/optics-pkg01/PRIVACY-DISPOSITIONS.md +++ /dev/null @@ -1,55 +0,0 @@ -# PKG-01 privacy dispositions - -Audience: INTERNAL_RESTRICTED - -One disposition is chosen per result, by the highest rank that occurred: - -`ACCEPT` < `NORMALIZE` < `STRIP` < `REPLACE_WITH_SAFE_CATEGORY` < `REJECT_FIELD` < `REJECT_RECORD` - -Detector character classes live in `contract/detector-classes.json`. Node and Python expand that file. Letter and number membership, NFC, and NFKC come from the committed profile `PKG01-UCD-16.0.0` (Unicode 16.0.0 tables under `contract/`). Governed detection does not call `str.isalpha`, `str.isalnum`, `unicodedata`, Node `String.normalize`, Unicode property escapes, locale case conversion, or Unicode casefold. ASCII case fold maps A–Z to a–z and leaves every other code point unchanged. `MRN:` stays case-sensitive. Other listed credential prefixes, including `AKIA`, `ASIA`, `AIza`, `ghp_`, `github_pat_`, `Bearer`, `Basic`, `eyJ`, and the OpenAI prefixes, fold ASCII case. A non-ASCII code point inside a credential tail is an insertion, not a terminator and not an ASCII letter. A governed prefix may also contain one non-ASCII insertion between its characters. That is a bounded prefix scan, not fuzzy matching and not universal confusable detection. PAN scans use ASCII digits after pinned NFKC, optional ASCII space or hyphen separators, and an ASCII-letter boundary only. Non-ASCII does not hide a 13–19 digit run. Pinned format controls, including U+200B, U+200C, U+200D, U+2060, and U+FEFF, are removed only in the detector view. If that view is detector-positive, the original value is omitted and is not stored in stripped form. Ordinary text that contains a format control and no governed secret is stored unchanged. `UNKNOWN_TO_PROFILE` inside an email-shaped span fails closed. - -One reason code is chosen by `reason_priority` in `contract/enums.json`. That order is the reported reason. `MAX_SIZE_EXCEEDED` outranks `DETECTOR_MATCH` and `REDACTION_DROP`. The value is still omitted. A walk above 8192 bytes with no detector hit in the scanned prefix sets scan state `SIZE_ONLY`, leaves `diagnostics.privacy_event` null, and does not claim the unscanned suffix is privacy-safe (`privacy_invariant` `UNKNOWN`). A candidate that crosses the scan cut sets scan state `BOUNDARY` and completeness `SCAN_INCOMPLETE`. That is not `DETECTOR_MATCH`. When a detector matches inside the scanned prefix, the privacy category can be set while the reason remains `MAX_SIZE_EXCEEDED` and the scan state is `MATCHED_IN_PREFIX`. A field that is over its own byte cap and at or under 8192 bytes stays scan state `FULL`. Session overflow at the 80-byte session cap keeps `SESSION_ID_REJECTED` and is measured in UTF-8 bytes. A privacy failure uses reason `REDACTION_DROP` when that rank is the highest one present. A detector match on an allowlisted free-form value, or on a field name, uses `DETECTOR_MATCH` and `diagnostics.privacy_event` `DETECTOR_MATCH`. The prohibited value is not copied into the result, the reason, or a diagnostic string. Raw unsafe field names are not copied either. A safe grammar name may be echoed. A disguised prohibited name uses locator `PROHIBITED_FIELD_CATEGORY`. A detector-positive, control, or otherwise unsafe name uses `UNKNOWN_FIELD_REDACTED_n`. - -When a destination component is omitted because it is sensitive, `diagnostics.privacy_event` is `DESTINATION_COMPONENT_REDACTED`. The category does not contain the path, host, query, userinfo, or canary. A destination that is only too long stays privacy-null unless a detector also matched. - -Removal is the disposition. This slice does not store a hash or a mask of a secret. - -| Situation | Disposition | Reason | What remains | -| --- | --- | --- | --- | -| Clean allowlisted observation with provenance | `ACCEPT` | `OK` | The observation | -| DNS case, timestamp padding, content-type parameters, trace hex case | `NORMALIZE` | `NORMALIZED` | Canonical value | -| Header map, clean unknown key, baggage without a secret, non-secret query | `STRIP` | `REDACTION_DROP`, `UNKNOWN_FIELD_OMITTED`, `BAGGAGE_OMITTED`, or `QUERY_STRIPPED` | Observation without that key | -| Secret inside an allowlisted string, username path, Unicode email-like path, database URL, PAN adjacent to non-ASCII | `REJECT_FIELD` | `REDACTION_DROP` | Observation without the destination or string field. Destination omissions use privacy category `DESTINATION_COMPONENT_REDACTED` | -| Detector-positive `schema_status_seen`, `detail_code`, quarantine `reason_code`, `provider_id`, `source_label`, `duplicate_of`, or `error_class`, including ASCII case fold and mixed-script tails | `REJECT_FIELD` | `DETECTOR_MATCH` | Value absent. Exact confidence enum may remain. Privacy category `DETECTOR_MATCH` | -| Secret-shaped unknown field name | `REJECT_FIELD` | `DETECTOR_MATCH` | Locator `UNKNOWN_FIELD_REDACTED_1`. Raw name absent | -| Control-character unknown field name that is not a detector | `STRIP` | `UNKNOWN_FIELD_REDACTED` | Locator `UNKNOWN_FIELD_REDACTED_n`. Privacy result stays null | -| Disguised payload name (newline, CR, tab, space, case, safe percent-encoding) | `REJECT_RECORD` | `PROHIBITED_FIELD_NAME` | Locator `PROHIBITED_FIELD_CATEGORY`. Exact catalog name `prompt` stays `PROMPT_COMPLETION_EXCLUDED` | -| Duplicate canonical field name after normalization | `REJECT_RECORD` | `DUPLICATE_CANONICAL_FIELD` | No record. Raw names absent | -| Oversized field name | `REJECT_RECORD` | `MAX_SIZE_EXCEEDED` | No record. Name absent | -| Caller `OPTICS_GENERATED` without the private trace witness | `NORMALIZE` or `STRIP` when the inherited key is removed | `CONFLICTING_PROVENANCE` | Basis replaced with `ASSERTED_CONTEXT`, or `IMPORTED_UNVERIFIED` for `traceparent` on import quarantine. Meaning is set. `provenance_conflict` is `TRACE_BASIS_REPLACED` | -| Inherited trace without local event evidence, claimed as `LOCAL_OBSERVATION` | `REPLACE_WITH_SAFE_CATEGORY` | `CONFLICTING_PROVENANCE` | Reader label `LEGACY_UNMARKED`. Origin not stored | -| Missing `optics_status` or missing `action` | `NORMALIZE` | `MISSING_REQUIRED_STATUS` | `optics_status` `UNAVAILABLE` when missing. Action omitted. HTTP evidence kept | -| Unknown non-enum `optics_status` token | `NORMALIZE` | `OPTIMISTIC_DEFAULT_FORBIDDEN` | Stored `UNAVAILABLE`. Token absent. Not a privacy incident | -| Accessor, proxy, or dict subclass with container hooks | `REJECT_RECORD` | `ACCESSOR_PROPERTY_FORBIDDEN` | No record. Getter not called | -| Plain class instance | `REJECT_RECORD` | `UNSUPPORTED_COMPLEX_VALUE` | No record | -| Function or other callable | `REJECT_FIELD` | `UNSUPPORTED_COMPLEX_VALUE` | No record. No function name, repr, or return value | -| Node `Buffer` or `Uint8Array`, Python `bytes`, `bytearray`, or `memoryview` | `REJECT_FIELD` | `UNSUPPORTED_COMPLEX_VALUE` | No record. No byte contents, encoding guess, or language type name | -| Oversized path, label, annotation, diagnostic, provider id, version, or trace, measured in UTF-8 bytes | `REJECT_FIELD` | `MAX_SIZE_EXCEEDED` | Value omitted, not truncated. Privacy stays null unless a detector matched the scanned prefix. `PATH_OVERSIZE` remains in the enum and is not the byte-limit outcome | -| Unicode profile missing or marked unavailable | `REJECT_RECORD` | `VALIDATOR_FAULT` | No record. Issue location `CONFIGURATION`. Scan state `UNAVAILABLE`. Input text is not copied | -| Invalid, overlong, or non-NFC session | `REJECT_FIELD` | `SESSION_ID_REJECTED` | Both session fields omitted | -| Session value that is also a secret | `REJECT_FIELD` | `REDACTION_DROP` | Both session fields omitted; both health counters increment | -| Malformed trace, or two contexts that disagree | `REJECT_FIELD` | `CONTEXT_REJECTED` | Trace stored as null; disagreeing case is `CONFIGURATION` when no earlier issue rule matches | -| Missing origin on a legacy shape | `REPLACE_WITH_SAFE_CATEGORY` | `LEGACY_UNMARKED` | Reader label `LEGACY_UNMARKED`; origin not stored | -| Claimed `LOCAL_OBSERVATION` without producer and version | `REPLACE_WITH_SAFE_CATEGORY` | `PROVENANCE_INSUFFICIENT` | Reader label `LEGACY_UNMARKED`; inherited trace kept as `ASSERTED_CONTEXT` | -| Host `optics-demo.invalid` | `REPLACE_WITH_SAFE_CATEGORY` | `SIMULATED_DEMO` | Origin `SIMULATED_DEMO` | -| Prompt, completion, message, or body | `REJECT_RECORD` | `PROMPT_COMPLETION_EXCLUDED` | No record; issue location `OPTICS` | -| Enforcement action other than `OBSERVED` | `REJECT_RECORD` | `ENFORCEMENT_ACTION_EXCLUDED` | No record | -| Validator fault, cycle, hostile getter, excessive nesting, malformed UTF-8, input bound | `REJECT_RECORD` | The matching terminal reason | No record; no exception text | - -Issue location is chosen in this order: `OPTICS` when the record is not stored or the failure is internal, then `NETWORK` when a network failure has no HTTP status, then `PROVIDER_INTERACTION` for HTTP 400–599, then `CUSTOMER_APPLICATION` for a wrapped or classed error with no HTTP status, then `COVERAGE`, then unevidenced coverage as `UNKNOWN`, then `CONFIGURATION`, then `ENVIRONMENT`, then HTTP 2xx/3xx as `NONE`. The customer label is `Provider interaction`. The string `Provider fault` is not a label. - -`VANTIO_TRACE_ID` maps to basis `ASSERTED_CONTEXT` and sets `diagnostics.trace_basis_meaning` to `ASSERTED_CONTEXT_NOT_OBSERVATION_PROOF`. `traceparent` on an observation uses the same basis. `traceparent` on `import_quarantine` uses `IMPORTED_UNVERIFIED`. Inherited context does not prove `LOCAL_OBSERVATION` unless the record also has stored destination or HTTP evidence. A caller label `OPTICS_GENERATED` is kept only when `optics_trace_witness` is the private fixture value and the producer plus `cli_or_sdk_version` are present. The witness is not persisted. Field names are compared after pinned NFC, one safe percent-decode, separator and control removal, and ASCII A–Z folding. Paths are classified after pinned NFC. If the profile cannot be loaded, validation returns `VALIDATOR_FAULT` and does not accept the record. - -Remediation codes are the closed set in `enums.json`. None of them ask for a raw evidence upload. - -Structural exclusions (`workflow`, `plane`, `free_mode`, `est_spend_usd`, usage, token counts, cost, `residual`, `data_note`, `status_labels`) are omitted without a privacy failure when the value itself is not a secret. A prohibited name that is not in that structural set, including `hostname_machine`, is a privacy failure and the value is omitted. diff --git a/docs/internal/optics-pkg02-reader-compat-gates/ARCHITECTURE-COUNCIL-NOTES.md b/docs/internal/optics-pkg02-reader-compat-gates/ARCHITECTURE-COUNCIL-NOTES.md deleted file mode 100644 index b4b01580..00000000 --- a/docs/internal/optics-pkg02-reader-compat-gates/ARCHITECTURE-COUNCIL-NOTES.md +++ /dev/null @@ -1,65 +0,0 @@ -# PKG-02 reader compatibility entry gates — architecture council notes - -PRIVATE | INERT | NOT SHIPPED | READ_AND_EXPLAIN | NO_WRITE_BACK | NO_LIVE_WRITER | NO_MIGRATION | NO_STABLE_SCHEMA - -Audience: INTERNAL_RESTRICTED - -These notes are the architecture record for this producer packet. They are not a council verdict. `council_verdict` in the gate report stays null. A later council agent accepts or rejects the packet. - -Starting commit: `89f95099d0dce463307eb75d78e7fcf2ef99feb2`. - -## 1. Decision - -Prove eleven reader gates on the merged Unit F reader before any Unit D or Unit E work. The proof is an inert evaluator plus direct and adversarial tests. Passing the proof classifies the packet `OPTICS_PKG02_READER_COMPAT_GATES_READY_FOR_COUNCIL`. Passing it does not authorize a writer, a version bump, or a merge. - -## 2. Why the gates sit in front of the writers - -`docs/planning/optics-pkg02/06-RELEASE-AND-ROLLBACK-BOUNDARY.md` makes Unit D depend on A, B, and F, and Unit E depend on A, C, and F. Both release gates also require that CLI `0.3.24` is not treated as the reader of a future file. Shipping either writer first would publish a record the frozen CLI labels `SUCCESS` for every call row. - -The entry gates make that pairing explicit and fail closed. They do not patch `displayCall`. - -## 3. Reader under test - -The evaluator calls `readRunFile` from `@vantio/optics-record-reader`. That function reads bytes, explains a copy through the Unit B adapter, and reads the same path again. The evaluator does not reimplement the contract mapper and does not import `@vantio/cli`. - -Tests pass in the frozen `displayCall` result as an oracle. The package itself does not load the CLI. If that oracle returns anything other than optics `SUCCESS` for the future call, the frozen-CLI gate fails. This force will not treat a changed CLI as if `0.3.24` had grown an honest future reader. - -## 4. Gate dispositions - -| Gate | Matrix class recorded on the proof | Pass condition | -| --- | --- | --- | -| Mixed-version directories | `PARTIAL` | A CLI `0.3.24` file, a Python `3.1.0` file, and a future canonical file stay side by side. Their bytes stay distinct and unchanged. | -| Legacy records | `REQUIRES_ADAPTER` | Both legacy files keep `schema_version` `2` and `vantio_run_log` `"1"`. The reading origin is `LEGACY_UNMARKED`. Python stored optics `SUCCESS` is refused. | -| Future records | `REQUIRES_ADAPTER` for the inert reader, frozen pairing `UNSUPPORTED` | Explicit `OBSERVED` with producer and version stays `OBSERVED` and `LOCAL_OBSERVATION`. Workload `SUCCESS` stays on `application_status`. | -| Unknown statuses | `REJECT_WITH_EXPLANATION` | An unknown optics token is class `unknown`, display `UNAVAILABLE`, `optimistic_default_forbidden`. The raw token is not echoed. | -| Absent fields | `PARTIAL` | Missing optics, HTTP status, bytes, and application status stay absent. Missing optics becomes `UNAVAILABLE`, not `OBSERVED`. | -| Origin preservation | `READ_ONLY` | `IMPORTED` keeps `original_evidence_origin`. A claimed local origin without provenance stays `LEGACY_UNMARKED`. Demo host `optics-demo.invalid` stays `SIMULATED_DEMO` on that observation. Provenanced `LOCAL_OBSERVATION` stays. | -| Reader fallback | `UNSUPPORTED` as the frozen outcome, disposition `NON_WRITING_FALLBACK` | Newer `schema_version` `99` and `schema_status` `stable-v9` remain on disk. Corrupt input is `OPTICS_ERROR`. A missing path is `UNAVAILABLE` / `ABSENT_FILE` and is not created. | -| No unknown to SUCCESS | `REJECT_WITH_EXPLANATION` | No evaluated explanation displays optics `SUCCESS`. Application `SUCCESS` is not copied into `optics_status`. | -| Frozen CLI honestly unsupported | `UNSUPPORTED` | `displayCall` on the future record still returns optics `SUCCESS`. The gate names that pairing unsupported. Node SDK `0.2.4` ingest does not become a local record. | -| Rollback without record rewriting | `UNSUPPORTED` | After a refused write, activate, and migrate option, the future file and the newer-schema file are still the same bytes, with origin and schema marker intact. | -| Reader refuses unsafe promotion | `READ_ONLY` | `promote` does not upgrade origin and does not rewrite bytes. Prohibited names and a secret canary are not echoed. | - -`achievement` on every gate stays `NOT_SHIPPED`. - -## 5. Fallback is not a migration - -A newer on-disk schema is explained on a detached copy. That copy uses contract `schema_version` `0` and `schema_status` `unstable-pre-1.0`, which is the current contract rule. The source file is not rewritten to those values. The gate report keeps the source `schema_version` and `schema_status` so a rollback notice can still show the marker the file carries. - -The frozen CLI cannot show that marker. Its display result is optics `SUCCESS` for a call row. The honest disclosure for that binary is `UNSUPPORTED`. - -## 6. What a pass does not decide - -- It does not select `PKG02-FUTURE-CLI-UNASSIGNED` or `PKG02-FUTURE-PYTHON-UNASSIGNED` as real versions. -- It does not satisfy the Unit D ordinary-client proof that still has to run on a machine with CLI `0.3.24` installed beside a future CLI. No future CLI exists in this force. -- It does not resolve Founder decision 6. No reader path stamps `LEGACY_UNMARKED` as `LOCAL_OBSERVATION`. -- It does not change fail-open for the workload. The evaluator never sees a caller return value to rewrite. -- It does not merge this pull request. - -## 7. Fail closed - -A missing role, a symlink, a name that leaves the directory, a missing frozen-display oracle, a rewritten byte, or any optics `SUCCESS` in an explanation yields `OPTICS_PKG02_READER_COMPAT_GATES_BLOCKED`. The ready token is not also present on that report. `units_d_e` remains `NOT_AUTHORIZED` in both outcomes. - -## 8. Council question - -The question for the independent council is whether these eleven proofs are sufficient entry evidence before a later force may start Unit D or Unit E. This producer does not sit that council. diff --git a/docs/internal/optics-pkg02-reader-compat-gates/BOUNDARY.md b/docs/internal/optics-pkg02-reader-compat-gates/BOUNDARY.md deleted file mode 100644 index 418767db..00000000 --- a/docs/internal/optics-pkg02-reader-compat-gates/BOUNDARY.md +++ /dev/null @@ -1,36 +0,0 @@ -# PKG-02 reader compatibility entry gates — boundary - -PRIVATE | INERT | NOT SHIPPED | READ_AND_EXPLAIN | NO_WRITE_BACK | NO_LIVE_WRITER | NO_MIGRATION | NO_STABLE_SCHEMA - -Audience: INTERNAL_RESTRICTED - -This force proves reader compatibility entry gates before Unit D and Unit E. The producer classification, when the suite passes, is `OPTICS_PKG02_READER_COMPAT_GATES_READY_FOR_COUNCIL`. - -That classification is a handoff to a separate council. It is not a council verdict, not a merge, and not permission to activate a writer. - -## Starting point - -Locked commit: `89f95099d0dce463307eb75d78e7fcf2ef99feb2`. - -Units A, B, C, and F are already merged and stay inert. This force does not reopen their packages. - -## What this force contains - -- `packages/optics-reader-compat-gates/` — private inert evaluator. -- `tests/optics-pkg02-reader-compat-gates/` — direct, adversarial, and isolation tests. -- `docs/internal/optics-pkg02-reader-compat-gates/` — these notes. - -The package is not a pnpm workspace member. `@vantio/cli` `0.3.24`, `vantio-agent-sdk` `3.1.0`, and `@vantio/agent-sdk` `0.2.4` do not import it. - -`schema_status` is `unstable-pre-1.0`. `schema_version` is `0`. The package version is `0.0.0-unstable-pre-1.0`. - -## What stays closed - -- CLI `0.3.24`, Node SDK `0.2.4`, and Python `3.1.0` bytes, versions, and tests. -- Unit D and Unit E. `PKG02-FUTURE-CLI-UNASSIGNED` and `PKG02-FUTURE-PYTHON-UNASSIGNED` are placeholders, not releases. -- Write-back, migration, SQLite, a UI, a daemon, an exporter, and alerting. -- A stable schema, a release candidate, a seal, a publish, and an announcement. -- Edits to `RECORD-COMPATIBILITY-MATRIX.json`. Every cell stays `NOT_SHIPPED`. -- A merge. The pull request stays draft. - -`units_d_e` on every gate report is `NOT_AUTHORIZED`. `activates_unit_d` and `activates_unit_e` stay false. `council_verdict` stays null. diff --git a/docs/internal/optics-pkg02-reader-compat-gates/DESIGN.md b/docs/internal/optics-pkg02-reader-compat-gates/DESIGN.md deleted file mode 100644 index bb395995..00000000 --- a/docs/internal/optics-pkg02-reader-compat-gates/DESIGN.md +++ /dev/null @@ -1,27 +0,0 @@ -# PKG-02 reader compatibility entry gates — design - -PRIVATE | INERT | NOT SHIPPED | READ_AND_EXPLAIN | NO_WRITE_BACK | NO_LIVE_WRITER | NO_MIGRATION | NO_STABLE_SCHEMA - -Audience: INTERNAL_RESTRICTED - -`evaluateEntryGates` scores one directory. The caller names each file's role and passes the frozen `displayCall` result for the future record. The evaluator returns a JSON report. It does not write the directory. - -## Steps - -1. Refuse a request that is missing the directory, the absent-file name, or the exact role set. -2. Refuse a symlink directory. Resolve each file name inside the directory. Refuse a symlink file and a name that escapes the directory. -3. Read each file, call `readRunFile`, and read it again. Record whether the bytes match. -4. Call `readRunFile` on the absent name. That path must stay missing, with reason `ABSENT_FILE` and health `UNAVAILABLE`. -5. Call `readRunFile` on the claimed-local file with `promote` set. The bytes and the reader origin must stay unpromoted. -6. Call `readRunFile` on the future file with `write`, `activate`, `migrate`, and `path` set. The reader returns `WRITER_INACTIVE` and the bytes stay. -7. Score the eleven gates. Any byte change fails every gate. - -The report lists safe markers: role, byte length, schema version, schema status, origin labels, classified optics tokens, and reader health. It does not copy raw file text, absolute paths, unknown optics tokens, or prohibited values. - -## Frozen CLI oracle - -The package does not import `optics-cx.cjs`. The test calls `displayCall` and passes the object in. The future gate passes only when that object's `opticsStatus` is `SUCCESS` and the future file's stored optics token is `OBSERVED`. The recorded disposition is `UNSUPPORTED`. - -## Placeholders - -`PKG02-FUTURE-CLI-UNASSIGNED` appears as the producer version on the future fixture so the existing contract can recognize provenance. It is not a published version. The report's `activates_unit_d` and `activates_unit_e` fields stay false. diff --git a/docs/internal/optics-pkg02-reader-compat-gates/GATE-CATALOG.md b/docs/internal/optics-pkg02-reader-compat-gates/GATE-CATALOG.md deleted file mode 100644 index acfa920d..00000000 --- a/docs/internal/optics-pkg02-reader-compat-gates/GATE-CATALOG.md +++ /dev/null @@ -1,23 +0,0 @@ -# PKG-02 reader compatibility entry gates — catalog - -PRIVATE | INERT | NOT SHIPPED | READ_AND_EXPLAIN | NO_WRITE_BACK | NO_LIVE_WRITER | NO_MIGRATION | NO_STABLE_SCHEMA - -Audience: INTERNAL_RESTRICTED - -Each gate id is fixed. `achievement` is `NOT_SHIPPED`. A pass still leaves Unit D and Unit E `NOT_AUTHORIZED`. - -| Id | What the proof has to show | -| --- | --- | -| `mixed_version_directories` | CLI `0.3.24`, Python `3.1.0`, and a future canonical file in one directory. Bytes differ. Bytes match before and after the read. Legacy readings stay `LEGACY_UNMARKED`. | -| `legacy_records` | Legacy `schema_version` `2` stays on the file and on `compatibility.legacy_schema_version` for the CLI file. Python stored optics `SUCCESS` is refused. Neither reading accepts `LOCAL_OBSERVATION`. | -| `future_records` | Source `schema_version` `0`, `schema_status` `unstable-pre-1.0`, optics `OBSERVED`, origin `LOCAL_OBSERVATION`. The inert reader keeps those tokens. Application `SUCCESS` stays on the application field. The frozen display pairing is `UNSUPPORTED`. | -| `unknown_statuses` | Source token outside the optics enum. Reader class `unknown`. Health and record optics `UNAVAILABLE`. `optimistic_default_forbidden` is true. The raw token is absent from the explanation. | -| `absent_fields` | Source optics key absent. Reader class `absent`, not `unknown`. HTTP status, response bytes, and application status stay absent. Optics health is `UNAVAILABLE`. | -| `origin_preservation` | Import stays `IMPORTED` with original `LEGACY_UNMARKED`. Claimed local without provenance is read as `LEGACY_UNMARKED` while the file still says `LOCAL_OBSERVATION`. Demo observation stays `SIMULATED_DEMO`. Provenanced local origin stays `LOCAL_OBSERVATION`. | -| `reader_fallback` | Newer schema file keeps `schema_version` `99` and `schema_status` `stable-v9`. The detached record uses schema version `0`. Corrupt input is `OPTICS_ERROR` and is not `NOT_OBSERVED`. The absent path is `UNAVAILABLE` and is not created. | -| `no_unknown_to_success` | Every role's explanation has optics success false. Unknown health is not `SUCCESS`. Explicit `OBSERVED` is not replaced by `SUCCESS`. | -| `frozen_cli_honestly_unsupported` | Frozen display `opticsStatus` is `SUCCESS`. Disposition is `UNSUPPORTED`. Node SDK `0.2.4` payload emits no local record and does not mention `LOCAL_OBSERVATION`. | -| `rollback_without_record_rewriting` | Future origin and newer schema marker are still on disk after a refused writer option. Directory membership is unchanged. | -| `reader_refuses_unsafe_promotion` | Promote option does not set the reader origin to `LOCAL_OBSERVATION` and does not change bytes. Prohibited names are not echoed. Writer option reason is `WRITER_INACTIVE`. | - -The direct test builds the CLI and Python files with the frozen `vantio run` and `shield()` writers in temporary homes, then copies those bytes into the gate directory. The original run files are hashed again after the evaluation. diff --git a/docs/internal/optics-pkg02-reader-compat-gates/IMPLEMENTATION-REPORT.md b/docs/internal/optics-pkg02-reader-compat-gates/IMPLEMENTATION-REPORT.md deleted file mode 100644 index 6b4e722c..00000000 --- a/docs/internal/optics-pkg02-reader-compat-gates/IMPLEMENTATION-REPORT.md +++ /dev/null @@ -1,42 +0,0 @@ -# PKG-02 reader compatibility entry gates — implementation report - -PRIVATE | INERT | NOT SHIPPED | READ_AND_EXPLAIN | NO_WRITE_BACK | NO_LIVE_WRITER | NO_MIGRATION | NO_STABLE_SCHEMA - -Audience: INTERNAL_RESTRICTED - -Producer classification before council: `OPTICS_PKG02_READER_COMPAT_GATES_READY_FOR_COUNCIL` - -This classification means the gate packet is ready for a separate council agent. It is not a council verdict, not a merge, and not authorization for Unit D or Unit E. - -The producer did not sit the council. Units D and E stay `NOT_AUTHORIZED`. - -Starting commit: `89f95099d0dce463307eb75d78e7fcf2ef99feb2`. - -## What landed - -Private package `@vantio/optics-reader-compat-gates` at `0.0.0-unstable-pre-1.0`. The evaluator calls the merged Unit F reader. It is not a bump of CLI `0.3.24`, Node SDK `0.2.4`, Python `3.1.0`, the evidence contract, the vocabulary package, the node adapter, or the Unit F reader. - -The package is not in `pnpm-workspace.yaml`. Live CLI and SDK sources do not import it. - -## Checks - -From the repository root: - -```sh -node --test tests/optics-pkg02-reader-compat-gates/*.test.cjs -``` - -The producer run of that command reported 15 tests and 0 failures. The direct test built a real CLI `0.3.24` run file and a real Python `3.1.0` `shield()` file in temporary homes, placed those bytes beside a future canonical record, and all eleven gates passed. Adversarial tests covered a forged frozen display, a missing role, a symlink, a path escape, promote and writer options, unknown tokens, canary suppression, and a non-directory path. - -A failed gate keeps the report classification at `OPTICS_PKG02_READER_COMPAT_GATES_BLOCKED`. The ready token in this file is the packet classification for the passing suite. It is not a council verdict. - -## Hard-stop attestations - -- No CLI `0.3.24`, Node SDK `0.2.4`, or Python `3.1.0` source change, and no version bump. -- No Unit D package and no Unit E package. -- No live writer and no write-back. Gate reads re-check file bytes. -- No SQLite, migration, UI, daemon, exporter, or alerting. -- No stable schema. -- No release candidate, seal, publish, tag, or announcement. -- Draft pull request only. Not marked ready. Not merged. -- Council is a separate agent. This producer did not run it. diff --git a/docs/internal/optics-pkg02-reader-compat-gates/INVENTORY.md b/docs/internal/optics-pkg02-reader-compat-gates/INVENTORY.md deleted file mode 100644 index 9db66571..00000000 --- a/docs/internal/optics-pkg02-reader-compat-gates/INVENTORY.md +++ /dev/null @@ -1,38 +0,0 @@ -# PKG-02 reader compatibility entry gates — inventory - -PRIVATE | INERT | NOT SHIPPED | READ_AND_EXPLAIN | NO_WRITE_BACK | NO_LIVE_WRITER | NO_MIGRATION | NO_STABLE_SCHEMA - -Audience: INTERNAL_RESTRICTED - -Starting commit: `89f95099d0dce463307eb75d78e7fcf2ef99feb2` (`Merge pull request #83`). - -## Frozen releases on that commit - -| Surface | Version | Writer or reader today | -| --- | --- | --- | -| `@vantio/cli` | `0.3.24` | Writer of `vantio_run_log` `"1"` with legacy `schema_version` `2`. `displayCall` assigns optics `SUCCESS` to every call row. | -| `@vantio/agent-sdk` | `0.2.4` | No local run-log writer and no local run-log reader. | -| `vantio-agent-sdk` Python | `3.1.0` | Writer. Stored call `opticsStatus` is `SUCCESS`. The package does not read run logs. | - -`packages/vantio-cli/bin/optics-cx.cjs` `opticsStatusForRecordedCall` returns `SUCCESS` and takes no arguments. This force leaves that function in place. - -## Merged inert units already on this commit - -| Unit | What is on main | Writer | -| --- | --- | --- | -| A | `packages/optics-record-vocabulary/` and the 34 conformance fixtures | None | -| B | `packages/optics-node-adapter/` calls the private contract on copies | None | -| C | `packages/optics-python-adapter/` scores the same fixtures | None | -| F | `packages/optics-record-reader/` explains a copy and re-reads the file | None | - -Unit F already refuses unknown optics tokens, keeps absent, null, and unknown classes apart, preserves imported and demo labels, and leaves input bytes unchanged. It is not wired into `@vantio/cli` `0.3.24`. - -## Gap this force closes - -Units D and E, in `docs/planning/optics-pkg02/05-INTEGRATION-SEQUENCING.md` and `06-RELEASE-AND-ROLLBACK-BOUNDARY.md`, wait on a reader proof that legacy files, future files, unknown status, and rollback can sit together before either writer turns on. That proof was scattered across Unit F tests. It was not one fail-closed entry gate. - -This force adds that gate. It does not add the writers. - -## Matrix - -`docs/planning/optics-pkg02/RECORD-COMPATIBILITY-MATRIX.json` stays `achievement` `NOT_SHIPPED` on every cell. This force does not edit that file. A passing gate is a reading proof. It is not a shipped compatibility cell. diff --git a/docs/internal/optics-pkg02-reader-compat-gates/KNOWN-LIMITATIONS.md b/docs/internal/optics-pkg02-reader-compat-gates/KNOWN-LIMITATIONS.md deleted file mode 100644 index cdd75e66..00000000 --- a/docs/internal/optics-pkg02-reader-compat-gates/KNOWN-LIMITATIONS.md +++ /dev/null @@ -1,14 +0,0 @@ -# PKG-02 reader compatibility entry gates — known limitations - -PRIVATE | INERT | NOT SHIPPED | READ_AND_EXPLAIN | NO_WRITE_BACK | NO_LIVE_WRITER | NO_MIGRATION | NO_STABLE_SCHEMA - -Audience: INTERNAL_RESTRICTED - -- A passing report does not authorize Unit D or Unit E. `PKG02-FUTURE-CLI-UNASSIGNED` and `PKG02-FUTURE-PYTHON-UNASSIGNED` are not versions. -- The detached reading of a newer `schema_version` uses contract schema version `0`. That normalization is not written back. It is not a migration and it is not permission to rewrite the file in a later writer force. -- Frozen `displayCall` still returns optics `SUCCESS` for a call row. This force records that pairing as `UNSUPPORTED` and does not change `optics-cx.cjs`. -- Node SDK `0.2.4` remains a non-writer. The gate checks that an ingest-shaped payload does not become a local observation. It does not add a reader to `0.2.4`. -- Python `3.1.0` remains a non-reader. The direct test runs frozen `shield()` only to obtain a legacy file. -- The Unit F isolation test that diffs `4e50dd9775d23899e1c68e5fa0e7a59c17066ea3` to `HEAD` is already failing on this starting commit because later shared-health vocabulary files sit outside that test's allowlist. This force does not edit that test. This force's own isolation check uses `89f95099d0dce463307eb75d78e7fcf2ef99feb2`. -- No SQLite, UI, daemon, exporter, alerting, release candidate, seal, or announcement. -- `council_verdict` stays null. This classification is not a council verdict and not a merge. diff --git a/docs/internal/optics-pkg02-reader-compat-gates/NO-WRITER.md b/docs/internal/optics-pkg02-reader-compat-gates/NO-WRITER.md deleted file mode 100644 index ebe5e399..00000000 --- a/docs/internal/optics-pkg02-reader-compat-gates/NO-WRITER.md +++ /dev/null @@ -1,17 +0,0 @@ -# PKG-02 reader compatibility entry gates — no writer - -PRIVATE | INERT | NOT SHIPPED | READ_AND_EXPLAIN | NO_WRITE_BACK | NO_LIVE_WRITER | NO_MIGRATION | NO_STABLE_SCHEMA - -Audience: INTERNAL_RESTRICTED - -Unit D and Unit E stay `NOT_AUTHORIZED`. - -This package exports `evaluateEntryGates` and constants. It does not export a writer, a migrator, or a promote operation. - -`readRunFile` options `write`, `activate`, `migrate`, and `path` produce `WRITER_INACTIVE` from the existing reader. The gate checks that result and then checks the file bytes. - -`promote` is not a writer flag on the Unit F reader. The gate still sends it. The claimed-local file must keep its bytes, and the reading must stay `LEGACY_UNMARKED`. - -No file under `packages/vantio-cli/`, `packages/vantio-agent-sdk/`, or `packages/vantio-agent-sdk-py/` is part of this change. `opticsStatusForRecordedCall` still returns `SUCCESS`. - -The future producer version string `PKG02-FUTURE-CLI-UNASSIGNED` is the planning placeholder. It does not create a CLI package and it does not bump `0.3.24`. diff --git a/docs/internal/optics-pkg02-unit-a/ALIASES.md b/docs/internal/optics-pkg02-unit-a/ALIASES.md deleted file mode 100644 index c98a949a..00000000 --- a/docs/internal/optics-pkg02-unit-a/ALIASES.md +++ /dev/null @@ -1,47 +0,0 @@ -# PKG-02 Unit A aliases - -PRIVATE | INERT | NOT SHIPPED | NO LIVE WRITER | NO LIVE READER | NO MIGRATION | NO STABLE SCHEMA - -Audience: INTERNAL_RESTRICTED - -Alias ownership is built only from canonical rows. A compatibility row documents a live name. It does not add a second owner. - -## Graph rules - -- An alias edge points from the legacy key to one canonical name. -- Fan-out per field is at most 8. The vocabulary uses 19 edges. The widest field has 2. -- Walk depth is capped at 4. The real edges are one hop. -- A self-alias is a cycle. -- One alias maps to one canonical name across record types. `trace_id` maps to `run_id` on both `run_envelope` and `observation_event`. That is one owner name, not two. -- When the alias string is also a different canonical field, the row records `collides_with_different_canonical_field`. - -## The trace_id collision - -Live envelope `trace_id` is the run boundary. The canonical field `trace_id` is validated trace context. The alias therefore belongs to `run_id`. - -The inherited-trace fixture stores `run_id` and `trace_id_basis` `ASSERTED_CONTEXT`. It does not store the live string in canonical `trace_id`. The witnessed-trace fixture is the only declared case of `OPTICS_GENERATED`, and only when the input carries `PKG01_OPTICS_GENERATED_WITNESS`. The witness is not copied onto the canonical record. - -## Other read aliases - -| Alias | Canonical field | -| --- | --- | -| `pid`, `ppid` | `process_id`, `parent_process_id` | -| `node_version` | `runtime_version` | -| `cli_version`, `producer_version` | `cli_or_sdk_version` | -| `ts` | `started_at` | -| `generated_at` | `ended_at` | -| `summary.total_calls` | `call_count` | -| `hostname`, `host` | `destination_host` | -| `provider` | `provider_id` | -| `status`, `httpStatus` | `http_status` | -| `applicationStatus` | `application_status` | -| `opticsStatus` | `optics_status` | -| `bytes` | `response_bytes` | - -`generated_at` remains a read alias of `ended_at`. The CLI fixture does not store write time as `ended_at`. - -`applicationStatus` does not write `optics_status`. `opticsStatus` `SUCCESS` on a Python 3.1.0 call is refused as canonical optics health. - -Prohibited live names (`plane`, `cost`, `machine`, and the rest of the PKG-01 prohibited list) are compatibility rows with dimension `prohibited_legacy`. They are not canonical aliases. - -No alias is removed. Removal waits for a later versioned release and a reader matrix. This unit does not perform that removal. diff --git a/docs/internal/optics-pkg02-unit-a/BOUNDARY.md b/docs/internal/optics-pkg02-unit-a/BOUNDARY.md deleted file mode 100644 index 3ffe6564..00000000 --- a/docs/internal/optics-pkg02-unit-a/BOUNDARY.md +++ /dev/null @@ -1,38 +0,0 @@ -# PKG-02 Unit A boundary - -PRIVATE | INERT | NOT SHIPPED | NO LIVE WRITER | NO LIVE READER | NO MIGRATION | NO STABLE SCHEMA - -Audience: INTERNAL_RESTRICTED - -Unit A is the shared record vocabulary and its conformance fixtures. It is a private package. It is not a release, not a stable schema, and not loaded by `@vantio/cli` 0.3.24, `vantio-agent-sdk` 3.1.0, or `@vantio/agent-sdk` 0.2.4. - -`schema_status` is `unstable-pre-1.0`. `schema_version` is `0`. JSON Schema is not the source of truth. - -## Starting point - -Locked main: `14249ba84ff1f3d5aa8ad7a7366172f29235c76e`. - -Branch: `implementation/optics-pkg02-unit-a-vocabulary`. - -## What this unit contains - -- `packages/optics-record-vocabulary/` — vocabulary, loaders, structural checks, fixture declarations. -- `tests/optics-record-vocabulary/` — the isolated suite, including the Python canonical-JSON check. -- `docs/internal/optics-pkg02-unit-a/` — these notes. - -The package is not a pnpm workspace member. Nothing in the live CLI, Python SDK, or Node SDK imports it. - -## What this unit does not do - -- It does not change PKG-01, and it does not import the PKG-01 validator or privacy detector. -- It does not write `~/.vantio/runs`, rewrite a record, or open a live run directory. -- It does not add SQLite, a migration, a UI, a daemon, an exporter, or alerting. -- It does not bump `@vantio/cli`, `@vantio/agent-sdk`, `vantio-agent-sdk`, or `@vantio/optics-evidence-contract`. -- It does not start Units B, C, D, E, or F. -- It does not mark a pull request ready, and it does not merge. - -The fixture runner checks declared interpretations. It does not convert an arbitrary live record, and a bare call object is rejected. - -## Unicode - -The diagnostic profile identity is `PKG01-UCD-16.0.0` version `16.0.0`. This unit does not add a payload field for it and does not generate a second profile. diff --git a/docs/internal/optics-pkg02-unit-a/COMPATIBILITY-FIXTURES.md b/docs/internal/optics-pkg02-unit-a/COMPATIBILITY-FIXTURES.md deleted file mode 100644 index 73a5afad..00000000 --- a/docs/internal/optics-pkg02-unit-a/COMPATIBILITY-FIXTURES.md +++ /dev/null @@ -1,57 +0,0 @@ -# PKG-02 Unit A compatibility fixtures - -PRIVATE | INERT | NOT SHIPPED | NO LIVE WRITER | NO LIVE READER | NO MIGRATION | NO STABLE SCHEMA - -Audience: INTERNAL_RESTRICTED - -File: `packages/optics-record-vocabulary/fixtures/conformance-fixtures.json`. - -34 fixtures. Each one sets `writes_live_run_directory` false, `achievement` `NOT_SHIPPED`, and `stable_schema` false. The runner returns a canonical comparison document. It does not write a file. - -No fixture uses compatibility class `FULL`. `FULL` would mean two conformant future records. Nothing here is shipped. - -## Force scenarios - -| Fixture | What it declares | -| --- | --- | -| `cli-0-3-24` | Frozen CLI envelope and one HTTP 200 call. Legacy `trace_id` becomes `run_id`. `ok` is not stored. Provider string is not an allowlisted `provider_id`. | -| `python-3-1-0` | Frozen Python call whose live `opticsStatus` is `SUCCESS`. Canonical optics health is `UNAVAILABLE`. Joined `mediation` is not one token. `+00:00` is declared as `Z` with three fractional digits. | -| `node-sdk-0-2-4` | Ingest payload. `record_emitted` false. `UNSUPPORTED`. `timestamp_ns` stays a decimal string. | -| `empty-shield` | Python empty shield. No file. `UNAVAILABLE`, not `NOT_OBSERVED`. | -| `no-file` | Reader path absent. `UNAVAILABLE`, not `NOT_OBSERVED`. | -| `missing-status` | Missing optics status, action, HTTP status, and bytes. | -| `unknown-status` | `SUPER_SUCCESS` becomes `UNAVAILABLE` with `OPTIMISTIC_DEFAULT_FORBIDDEN`. | -| `missing-action` | Action key omitted. | -| `bytes-missing` | `response_bytes` omitted. | -| `legacy-bytes-zero` | Legacy `bytes` 0 becomes `response_bytes` null. | -| `explicit-response-bytes-zero` | Canonical `response_bytes` 0 stays 0. Declared future input, frozen reader `UNSUPPORTED`. | -| `inherited-trace` | Basis `ASSERTED_CONTEXT`, not `OPTICS_GENERATED`. | -| `imported-evidence` | `IMPORTED` and original origin kept. Class `READ_ONLY`. | -| `simulated-evidence` | Host `optics-demo.invalid` is `SIMULATED_DEMO` on that observation. | -| `partial-run` | `lifecycle` `PARTIAL`. Per-call application tokens are not `PARTIAL`. | -| `interrupted-run` | `lifecycle` `INTERRUPTED`. Pre-completion `duration_ms` 0 is not stored. | -| `corrupt-record` | Malformed JSON. No record. `OPTICS_ERROR`. Not an empty object. | -| `unknown-enum` | Method `FLY` is omitted and named in the diagnostic. | -| `future-field` | `freshness` `CURRENT`, `widget_hint`, and `cost` are not promoted. | -| `compatibility-alias` | Alias keys are absent from the canonical object. Class `REQUIRES_ALIAS`. | -| `provider-http-error` | HTTP 500, `APPLICATION_ERROR`, `PROVIDER_INTERACTION`. | -| `dns-failure`, `connection-failure`, `tls-failure` | Transport kind kept. String `network_error` is not the enum. Issue location `NETWORK`. | -| `customer-application-exception` | `wrapped` plus `ValueError`. Issue location `CUSTOMER_APPLICATION`. | -| `successful-http-response` | HTTP 200 workload `SUCCESS`, optics `UNAVAILABLE`. | - -## Additional declarations - -These lock the same rules. They are not later units. - -| Fixture | Why it is here | -| --- | --- | -| `cli-empty-call-file` | A CLI file with `calls: []` is `NOT_OBSERVED`. A missing file is not. | -| `unreadable-record` | Unreadable bytes are `OPTICS_ERROR`, not `NOT_OBSERVED`. | -| `timeout-failure` | `failure_kind` `timeout` is the same network rule as DNS, connection, and TLS. | -| `sampling-not-success` | Invalid token `SAMPLED` is omitted. It is not stored as `UNSAMPLED` and it is not optics success. | -| `claimed-local-without-provenance` | Claimed `LOCAL_OBSERVATION` without producer and version stays `LEGACY_UNMARKED`. | -| `redirect-3xx` | HTTP 302 is workload `SUCCESS`. No hop is invented. | -| `witnessed-trace` | Basis `OPTICS_GENERATED` only with the witness present on input and absent on output. Placeholder version `PKG02-FUTURE-CLI-UNASSIGNED`. Not a writer authorization. | -| `explicit-observed-not-default` | Explicit `OBSERVED` is preserved. Missing status does not become `OBSERVED`. | - -Producer versions on these fixtures are only `0.3.24`, `3.1.0`, `0.2.4`, null, or the unassigned placeholder. The placeholder is not a release. diff --git a/docs/internal/optics-pkg02-unit-a/IMPLEMENTATION-REPORT.md b/docs/internal/optics-pkg02-unit-a/IMPLEMENTATION-REPORT.md deleted file mode 100644 index edff69a0..00000000 --- a/docs/internal/optics-pkg02-unit-a/IMPLEMENTATION-REPORT.md +++ /dev/null @@ -1,67 +0,0 @@ -# PKG-02 Unit A implementation report - -PRIVATE | INERT | NOT SHIPPED | NO LIVE WRITER | NO LIVE READER | NO MIGRATION | NO STABLE SCHEMA - -Audience: INTERNAL_RESTRICTED - -Producer classification before council: `OPTICS_PKG02_UNIT_A_READY_FOR_COUNCIL` - -This classification means the Unit A branch is ready for a separate council agent. It is not a council verdict, not a merge, and not a statement that a writer exists. - -The producer did not sit the council. - -## What landed - -Private package `@vantio/optics-record-vocabulary` at `0.0.0-unstable-pre-1.0`. That version matches the unstable posture. It is not a bump of CLI `0.3.24`, Node SDK `0.2.4`, Python `3.1.0`, or `@vantio/optics-evidence-contract`. - -The package is not in `pnpm-workspace.yaml`. - -| Item | Count | -| --- | --- | -| Canonical rows retained | 120 | -| Unique canonical names | 88 | -| Names that repeat across record types | 22 (32 extra rows, not merged away) | -| Compatibility rows retained | 67 | -| Alias edges | 19 | -| Widest alias fan-out | 2 (bound 8) | -| Fixtures | 34 | -| Force scenarios covered | 26 | - -Planning-row coverage: 120 `RETAINED` with no consolidation, 67 `RETAINED_AS_COMPATIBILITY` with an explicit reason. Row identity is `record_type` plus `canonical_name`. - -## Checks - -From the repository root: - -```sh -node --test tests/optics-record-vocabulary/*.test.cjs -``` - -The producer run of that command reported 26 tests and 0 failures. The suite covers vocabulary parse, unique row keys, alias fan-out, cycles, ownership, enum and absent behavior, dimension separation, optimistic defaults, fixture determinism, Node/Python canonical bytes, safe-integer bounds, PKG-01 field equality, source hashes, export surface, filesystem writes, frozen versions, protective-rule retention, builder sandbox paths, and the Unit A path limit on a clean or dirty checkout. - -Optimistic-default proof: no fixture stores `optics_status` `SUCCESS`; missing status is `UNAVAILABLE`; legacy `bytes` 0 is null; explicit `response_bytes` 0 stays 0; inherited trace is `ASSERTED_CONTEXT`; corrupt input has `expected_canonical` null; unreadable and absent paths are not `NOT_OBSERVED`. Invalid `sampling` `SAMPLED` is omitted and is not stored as `UNSAMPLED`. Forcing `SUCCESS` on the HTTP 200 fixture fails evaluation. Removing a shape-required protective rule, or the `optics_status` `SUCCESS` prohibition, fails evaluation. `missing_action`, `missing_byte_count`, `missing_evidence_origin`, and `status_dimensions_separated` are required from the input shape. Dropping one of them fails evaluation. Storing `action` `OBSERVED`, `response_bytes` `0`, a `SIMULATED_DEMO` reader label, stored `LOCAL_OBSERVATION`, or workload `PARTIAL` without that rule also fails. - -Dimension-separation proof: the six separated dimensions have disjoint canonical fields. HTTP 200 stores workload `SUCCESS` and optics `UNAVAILABLE`. HTTP 500 stores `APPLICATION_ERROR` and `PROVIDER_INTERACTION`. `lifecycle` `PARTIAL` is not `application_status`. - -PKG-01 proof: all 120 catalog fields match type, invalid disposition, privacy class, and metric, export, and proof eligibility. Enum samples match `enums.json`. Unicode profile id is `PKG01-UCD-16.0.0`. No second profile was added. Prohibited names match the PKG-01 list. Detector source is not imported. - -Live-import proof: `src/` has no product `require`, no `writeFile`, no `sqlite`, and no `child_process`. Evaluation of the fixture list performs no `writeFileSync`. The public API has no convert, migrate, or write function. Direct builder invocation writes only inside `vocabulary/` or `fixtures/`. A path outside those directories, a directory symlink out of them, or a final file symlink inside them is refused before a write. An outside file targeted by that file symlink is left unchanged. - -Schema-version proof: CLI `0.3.24`, Python `3.1.0`, and the empty CLI file keep live `schema_version` `2` on the declared input. Canonical `schema_version` is `0`. The diagnostics name `compatibility.legacy_schema_version`. Copying `2` into the canonical field fails evaluation. - -Path proof: committed paths are the diff of this tip against `14249ba84ff1f3d5aa8ad7a7366172f29235c76e`. Uncommitted paths are included separately. An empty `git status` is valid. An out-of-scope path is named in the failure. The check does not require a dirty worktree. - -## Hard-stop attestations - -- No CLI, Python SDK, or Node SDK source change. -- No PKG-01 change. -- No live import. -- No record conversion of arbitrary inputs. -- No SQLite. -- No migration. -- No UI, daemon, exporter, or alerting. -- No stable schema. -- No release candidate, seal, publish, tag, or announcement. -- No Units B–F. -- Draft pull request only. Not marked ready. Not merged. -- Council is a separate agent. This producer did not run it. diff --git a/docs/internal/optics-pkg02-unit-a/KNOWN-LIMITATIONS.md b/docs/internal/optics-pkg02-unit-a/KNOWN-LIMITATIONS.md deleted file mode 100644 index b8bbddeb..00000000 --- a/docs/internal/optics-pkg02-unit-a/KNOWN-LIMITATIONS.md +++ /dev/null @@ -1,20 +0,0 @@ -# PKG-02 Unit A known limitations - -PRIVATE | INERT | NOT SHIPPED | NO LIVE WRITER | NO LIVE READER | NO MIGRATION | NO STABLE SCHEMA - -Audience: INTERNAL_RESTRICTED - -- This unit does not read or write live run logs. Fixture inputs are declarations. -- The runner is not a record converter. It rejects a bare call object. It does not implement `legacyEnvelopeToContract`. -- Canonical rows repeat the planning prose on each row, including fallback text that is identical across rows. That keeps each row self-contained. The file is large because of that repetition. -- `integrity` has no catalog field of its own. It is the `product_health` name `integrity_state` and the tokens `OK`, `FAILED`, `UNKNOWN`. This unit does not add a field. -- There is no catalog field for a reader version. Version identity is `schema_version`, `runtime_version`, `cli_or_sdk_version`, and the Unicode profile compatibility names. -- Frozen CLI and Python envelopes still carry live `schema_version` `2` on the declared input. Canonical `schema_version` is `0`. The diagnostics name `compatibility.legacy_schema_version` as the only retention slot. These fixtures do not emit a compatibility object. -- `generated_at` is not stored as `ended_at` in the CLI fixture. The alias still exists for a later reader matrix. -- The witnessed-trace and explicit-`OBSERVED` fixtures use `PKG02-FUTURE-CLI-UNASSIGNED`. That string is not a version that exists. Those fixtures do not authorize Units B–F. -- Node SDK `timestamp_ns` is carried as a decimal string because the integer is outside the safe JSON integer range. Node and the Python encoder both reject integers outside `-9007199254740991` through `9007199254740991`. -- The Python check compares canonical JSON bytes for fixture comparison documents and the safe-integer bounds. It is not a second validator and it does not import `vantio-agent-sdk`. -- `tools/build-vocabulary.cjs` and `tools/emit-fixtures.cjs` write only inside `vocabulary/` and `fixtures/`. A direct path outside those directories, a directory symlink that leaves them, or a final path that is itself a file symlink, is refused before any write. The suite proves that refusal without leaving a probe file behind and without changing an outside file. -- The call bound of 64, the frozen writers, and the unresolved Founder decisions 2–13 are unchanged. -- `proof_manifest` stays out of this slice. -- No fixture claims matrix class `FULL`. diff --git a/docs/internal/optics-pkg02-unit-a/NO-OPTIMISTIC-DEFAULTS.md b/docs/internal/optics-pkg02-unit-a/NO-OPTIMISTIC-DEFAULTS.md deleted file mode 100644 index 4bfab2c0..00000000 --- a/docs/internal/optics-pkg02-unit-a/NO-OPTIMISTIC-DEFAULTS.md +++ /dev/null @@ -1,37 +0,0 @@ -# PKG-02 Unit A — no optimistic defaults - -PRIVATE | INERT | NOT SHIPPED | NO LIVE WRITER | NO LIVE READER | NO MIGRATION | NO STABLE SCHEMA - -Audience: INTERNAL_RESTRICTED - -`SUCCESS` stays in the `optics_status` enum because PKG-01 lists it. Unit A does not use it as a stored reading. Every fixture prohibits `optics_status` `SUCCESS`. A fixture edited to store that token fails evaluation. - -| Condition | Canonical reading | Fixture | -| --- | --- | --- | -| `optics_status` missing | `UNAVAILABLE`, not `SUCCESS`, not `OBSERVED` | `missing-status`, `successful-http-response` | -| Live `opticsStatus` `SUCCESS` | Refused. `UNAVAILABLE` and `OPTIMISTIC_DEFAULT_FORBIDDEN` | `python-3-1-0` | -| Unknown optics token | `UNAVAILABLE` and `OPTIMISTIC_DEFAULT_FORBIDDEN`. Raw token stays in the diagnostic | `unknown-status` | -| Explicit `OBSERVED` on a declared future input | Preserved. Not the missing-status default | `explicit-observed-not-default` | -| `action` missing | Key omitted | `missing-action` | -| HTTP status missing | Key omitted, not `200`, not `0` | `missing-status` | -| HTTP status null | Key omitted | `interrupted-run` | -| Bytes missing | `response_bytes` omitted | `bytes-missing` | -| Legacy `bytes` `0` | `response_bytes` null | `legacy-bytes-zero` | -| Explicit `response_bytes` `0` | `0` | `explicit-response-bytes-zero` | -| Origin missing | Reader label `LEGACY_UNMARKED`. Not stored as `LOCAL_OBSERVATION` | `cli-0-3-24` | -| Claimed local without producer and version | `LEGACY_UNMARKED` | `claimed-local-without-provenance` | -| Inherited trace | `ASSERTED_CONTEXT`, not `OPTICS_GENERATED` | `inherited-trace` | -| Unknown enum | Omitted from the canonical object. Raw token kept in the diagnostic | `unknown-enum` | -| Unreadable record | `OPTICS_ERROR`, not `NOT_OBSERVED` | `unreadable-record` | -| Absent file | `UNAVAILABLE`, not `NOT_OBSERVED` | `no-file`, `empty-shield` | -| Corrupt JSON | No record. Not `{}` | `corrupt-record` | -| Pre-completion `duration_ms` `0` | Omitted. Not a measured zero | `interrupted-run` | -| `sampling` other than `UNSAMPLED` | Omitted. Not rewritten to `UNSAMPLED`. Not optics success | `sampling-not-success` | -| `ok` | Not stored | `cli-0-3-24` | -| `failure_kind` `none` | Not copied as workload proof | `python-3-1-0` | - -`NOT_OBSERVED` appears only on `cli-empty-call-file`, where the CLI file exists and `calls` is empty. That is the wrap-ran, nothing-stored case. It is not the reading for a missing path, a corrupt file, or an unreadable file. - -HTTP 200–399 may set workload `application_status` `SUCCESS`, including 302. That token is not copied into `optics_status`. HTTP 400–599 sets `APPLICATION_ERROR`. The checker rejects a fixture that disagrees with that split. - -`missing_action`, `missing_byte_count`, `missing_evidence_origin`, and `status_dimensions_separated` are shape-required. An emitted call with no `action` must name `missing_action`. An emitted call with no byte count must name `missing_byte_count`. A legacy record whose input has no origin must name `missing_evidence_origin`. A fixture whose readings split two or more separated dimensions, or whose partial-run lock is present, must name `status_dimensions_separated`. Dropping one of those rules fails evaluation. Storing `action` `OBSERVED`, `response_bytes` `0`, a `SIMULATED_DEMO` reader label, stored `LOCAL_OBSERVATION`, or workload `PARTIAL` in place of the absent reading also fails. diff --git a/docs/internal/optics-pkg02-unit-a/VOCABULARY.md b/docs/internal/optics-pkg02-unit-a/VOCABULARY.md deleted file mode 100644 index 197c9bac..00000000 --- a/docs/internal/optics-pkg02-unit-a/VOCABULARY.md +++ /dev/null @@ -1,61 +0,0 @@ -# PKG-02 Unit A vocabulary - -PRIVATE | INERT | NOT SHIPPED | NO LIVE WRITER | NO LIVE READER | NO MIGRATION | NO STABLE SCHEMA - -Audience: INTERNAL_RESTRICTED - -Machine-readable file: `packages/optics-record-vocabulary/vocabulary/record-vocabulary.json`. - -The file is generated from the merged planning vocabulary and the PKG-01 catalog, enums, contract metadata, and prohibited-name list. Generation copies declared field attributes. It does not copy detector code. `tools/build-vocabulary.cjs` rebuilds the object in memory. The test suite does not write that file. - -## Row identity - -| Set | Count | Treatment | -| --- | --- | --- | -| Planning entries | 187 | All retained | -| Canonical rows | 120 | One row per `record_type` + `canonical_name`. None were merged away | -| Unique canonical names | 88 | 22 names occur on more than one record type, which adds 32 rows | -| Compatibility rows | 67 | Kept as compatibility rows because they are not PKG-01 catalog fields | - -`reason_code` is the only repeated name whose semantic dimension differs by record type: `import_disposition` on `import_quarantine`, `validation_structure` on `validation_result`. Every other repeated name keeps one dimension. - -Each canonical row carries the force attributes: canonical name, semantic dimension, type, optionality, allowed enum values, absent-value behavior, invalid-value behavior, compatibility aliases, legacy interpretation, evidence-origin effect, issue-location effect, completeness effect, privacy class, metric eligibility, export eligibility, proof eligibility, reader fallback, writer requirement, and deprecation posture. - -Unknown-enum posture is `NORMALIZE_UNAVAILABLE`, `NORMALIZE_DECLARED`, `REJECT_FIELD`, or `REJECT_RECORD`. It is never `COERCE_TO_SUCCESS`. - -## Semantic dimensions - -Required dimensions, each represented: - -| Dimension | What it holds | -| --- | --- | -| `schema_identity_status` | `record_type`, `schema_status`, `schema_status_seen` | -| `record_identity` | Event, annotation, subject, and content identifiers | -| `execution_identity` | Session, run, trace, span, and producer identity | -| `process_identity` | Process ids, runtime, platform, arch | -| `timestamps_duration` | Timestamps, duration, clock quality | -| `destination_provider_identity` | Host, port, scheme, method, path, provider, mediation | -| `http_network_outcomes` | HTTP status, failure kind, error class, byte counts | -| `optics_health` | `optics_status` and validation health counters | -| `workload_outcome` | `application_status` and the application outcome label | -| `dependency_outcome` | `provider_response_phrase` | -| `issue_location` | `issue_location` and its label | -| `evidence_origin_basis` | Origin, trace basis, session basis, reader origin label | -| `coverage` | `coverage_note`, `call_count` | -| `completeness` | `completeness_impact`, `completeness_inputs` | -| `integrity` | `product_health` value family `integrity_state`: `OK`, `FAILED`, `UNKNOWN` | -| `sampling` | `sampling` | -| `drop_state` | `dropped_count` | -| `version_identity` | `schema_version`, `runtime_version`, `cli_or_sdk_version`, plus the Unicode profile compatibility names | - -`lifecycle` is `attempt_lifecycle`, not completeness and not optics health. `action` is `observation_action`. Envelope `span_id` stays type `null` (`VALUE_IS_NULL`), which is different from an omitted span. - -`integrity_state` is not a new catalog field. PKG-02 does not add one. The tokens are disjoint from `optics_status`. - -## Privacy and versions - -Canonical privacy classes stay `STRUCTURAL`, `IDENTITY`, `DIAGNOSTIC`, and `CUSTOMER_TEXT`. Metric, export, and proof eligibility match the PKG-01 catalog booleans. - -Frozen versions recorded on the vocabulary: CLI `0.3.24`, Node SDK `0.2.4`, Python `3.1.0`, evidence contract `0.0.0-unstable-pre-1.0`. - -`SUCCESS` remains a member of `optics_status` because the catalog enum contains it. Absence does not store it. See `NO-OPTIMISTIC-DEFAULTS.md`. diff --git a/docs/internal/optics-pkg02-unit-b/BOUNDARY.md b/docs/internal/optics-pkg02-unit-b/BOUNDARY.md deleted file mode 100644 index 94573ede..00000000 --- a/docs/internal/optics-pkg02-unit-b/BOUNDARY.md +++ /dev/null @@ -1,37 +0,0 @@ -# PKG-02 Unit B boundary - -PRIVATE | INERT | NOT SHIPPED | NO LIVE WRITER | NO LIVE READER | NO MIGRATION | NO STABLE SCHEMA - -Audience: INTERNAL_RESTRICTED - -Unit B is the inert Node adapter. It calls the existing private mapper on copies. It is not a release, not a stable schema, and not loaded by `@vantio/cli` 0.3.24, `vantio-agent-sdk` 3.1.0, or `@vantio/agent-sdk` 0.2.4. - -`schema_status` is `unstable-pre-1.0`. `schema_version` is `0`. The package version is `0.0.0-unstable-pre-1.0`. The future writer placeholder is `PKG02-FUTURE-CLI-UNASSIGNED`. That string is not a version that exists. - -## Starting point - -Locked main: `587f3b94d47ea958f91d3a99125cd55931d995f1`. - -That commit is the merge of Unit A. This unit does not reopen the Unit A vocabulary. - -## What this unit contains - -- `packages/optics-node-adapter/` — the inert adapter. -- `tests/optics-node-adapter/` — direct and adversarial tests. -- `docs/internal/optics-pkg02-unit-b/` — these notes. -- `tests/optics-record-vocabulary/isolation.test.cjs` — the Unit A path proof now points at the Unit A branch tip `299651c429b588e1e982a26ba717a1b4f1ffeac4`, so later commits are not reported as Unit A scope violations. - -The package is not a pnpm workspace member. Nothing in the live CLI, Python SDK, or Node SDK imports it. - -## What this unit does not do - -- It does not change CLI `0.3.24`, Python `3.1.0`, or Node SDK `0.2.4`. -- It does not change PKG-01 contract behavior, Unicode tables, or the 220-fixture corpus. -- It does not write `~/.vantio/runs`, rewrite a record, or sit on the `vantio run` exit path. -- It does not add SQLite, a migration, a UI, a daemon, an exporter, or alerting. -- It does not start Units D, E, or F, and it does not activate a writer. -- It does not mark a pull request ready, and it does not merge. - -Producer classification before council: `OPTICS_PKG02_UNIT_B_READY_FOR_COUNCIL`. - -Revision after `OPTICS_PKG02_UNIT_B_NEEDS_REVISION` on `56ec23c3dd4c80d52596767eb557931768824d48`: `OPTICS_PKG02_UNIT_B_REVISION_READY_FOR_COUNCIL`. That revision classification is not a council verdict. diff --git a/docs/internal/optics-pkg02-unit-b/COMPATIBILITY-FIXTURES.md b/docs/internal/optics-pkg02-unit-b/COMPATIBILITY-FIXTURES.md deleted file mode 100644 index f4b0263c..00000000 --- a/docs/internal/optics-pkg02-unit-b/COMPATIBILITY-FIXTURES.md +++ /dev/null @@ -1,15 +0,0 @@ -# PKG-02 Unit B compatibility fixtures - -PRIVATE | INERT | NOT SHIPPED | NO LIVE WRITER | NO LIVE READER | NO MIGRATION | NO STABLE SCHEMA - -Audience: INTERNAL_RESTRICTED - -The adapter scores the 34 Unit A fixtures in `packages/optics-record-vocabulary/fixtures/conformance-fixtures.json`. It does not add a second fixture corpus and it does not edit those declarations. - -Each expected canonical key must appear with the same value on the detached envelope or on a detached event. `optics_health` is not counted as `optics_status`. `cli-empty-call-file` stores `optics_status` `NOT_OBSERVED` on the envelope. `inherited-trace` stores `optics_status` `UNAVAILABLE` on the envelope. Alias keys and `fields_not_promoted` tokens are absent from those records. `record_emitted` matches the fixture. Reader origin matches `evidence_origin` when the fixture names one. - -Python-shaped fixtures are scored here so the Node adapter and a later Python adapter can be compared on the same declarations. Scoring them does not import `vantio-agent-sdk` and does not change `3.1.0`. - -`generated_at` on the CLI fixture remains on the detached envelope as `ended_at`, labeled as write time. The Unit A expected object does not list that key. The score checks the keys the fixture does list. - -A frozen CLI reader of a future record is not updated. The adversarial test calls `displayCall` and records that it still says `SUCCESS` while the adapter says `UNAVAILABLE`. diff --git a/docs/internal/optics-pkg02-unit-b/DESIGN.md b/docs/internal/optics-pkg02-unit-b/DESIGN.md deleted file mode 100644 index 83bcab54..00000000 --- a/docs/internal/optics-pkg02-unit-b/DESIGN.md +++ /dev/null @@ -1,42 +0,0 @@ -# PKG-02 Unit B design - -PRIVATE | INERT | NOT SHIPPED | NO LIVE WRITER | NO LIVE READER | NO MIGRATION | NO STABLE SCHEMA - -Audience: INTERNAL_RESTRICTED - -The adapter is `@vantio/optics-node-adapter`. `adaptNodeCopy` passes a value the caller already holds to `validateEvidence` or `validateBytes`. Those functions copy the value before they map it. `adaptFixture` builds that copy from a Unit A fixture declaration, then uses the same path. - -The copy is discarded by the caller. The adapter has no writer, no path argument that reads a run file, and no export that activates Units D or E. - -## How a fixture becomes a copy - -Unit A stores an envelope and a call separately. The adapter joins them on the copy: - -- A `vantio_run_log` envelope keeps its runtime. A Python envelope stays a Python-shaped copy so the same mapper scores it. This package does not edit Python `3.1.0`. -- A call with no envelope becomes `calls: [call]` on a `vantio_run_log` `"1"` copy. -- Envelope `ts` is copied to `started_at` and the alias key is removed on the copy. -- A witnessed envelope is passed as `record_type` `run_envelope` with `trace_id_basis` `OPTICS_GENERATED` and the fixture's version placeholder. The witness value is not copied onto the detached result. -- Node SDK ingest and future-only extra fields are not passed to the mapper. The result is `UNSUPPORTED`, `record_emitted` false, and `optics_health` `UNAVAILABLE`. - -Absent files and unreadable paths do not open a filesystem path. Malformed text is passed to the mapper as text. - -## Detached reading - -A JSON string and a byte buffer are decoded only far enough to take the same Unit A snapshot an object receives. The original text or bytes still go to the mapper. Malformed text and malformed bytes keep an empty snapshot. The detached reading then applies the merged Unit A rules where the mapper output would disagree with those rules: - -- `optics_status` `SUCCESS` becomes `UNAVAILABLE`, with `optimistic_default_forbidden` true. Explicit `OBSERVED` stays. -- An unknown optics token stays `UNAVAILABLE` and sets the same flag. The raw token is not stored. -- Invalid `sampling` is omitted. It is not left as `UNSAMPLED`. -- An invalid method that the mapper stored as `unknown` is omitted. -- `failure_kind` `none` is omitted. -- Comma-joined `mediation` is omitted. -- Legacy `trace_id` stays `run_id` with `trace_id_basis` `ASSERTED_CONTEXT`. It is not canonical `trace_id` and not `OPTICS_GENERATED`. -- `IMPORTED` is written back onto the detached record with `original_evidence_origin` when that value is an allowlisted token. It is not upgraded to `LOCAL_OBSERVATION`. -- A span the source omitted stays omitted. A source `span_id` null stays null. -- `generated_at` may appear as `ended_at` because the mapper maps that alias. The diagnostic says that value is file write time. -- Pre-completion `duration_ms` `0` with null HTTP status omits the duration and sets `lifecycle` `INTERRUPTED`. -- Two application tokens `SUCCESS` and `APPLICATION_ERROR` set envelope `lifecycle` `PARTIAL`. They do not set `application_status` `PARTIAL`. -- An explicit empty `calls` array is `optics_health` `NOT_OBSERVED`, and that token is stored on the detached envelope as `optics_status`. An envelope with no events and no call list stores `optics_status` `UNAVAILABLE` on the detached record. `optics_health` is not a substitute for that field. A missing file is `UNAVAILABLE`. Corrupt or unreadable input is `OPTICS_ERROR`. -- Own getters and inherited accessors are left unread. The mapper then rejects the copy. - -`live_writer_modified` stays false. `schema_version` on the detached record is `0`. Legacy `2` remains `compatibility.legacy_schema_version`. diff --git a/docs/internal/optics-pkg02-unit-b/IMPLEMENTATION-REPORT.md b/docs/internal/optics-pkg02-unit-b/IMPLEMENTATION-REPORT.md deleted file mode 100644 index 2b41402d..00000000 --- a/docs/internal/optics-pkg02-unit-b/IMPLEMENTATION-REPORT.md +++ /dev/null @@ -1,46 +0,0 @@ -# PKG-02 Unit B implementation report - -PRIVATE | INERT | NOT SHIPPED | NO LIVE WRITER | NO LIVE READER | NO MIGRATION | NO STABLE SCHEMA - -Audience: INTERNAL_RESTRICTED - -Producer classification before council: `OPTICS_PKG02_UNIT_B_READY_FOR_COUNCIL` - -This classification means the Unit B branch is ready for a separate council agent. It is not a council verdict, not a merge, and not a statement that a writer exists. - -The producer did not sit the council. - -## What landed - -Private package `@vantio/optics-node-adapter` at `0.0.0-unstable-pre-1.0`. That version matches the unstable posture. It is not a bump of CLI `0.3.24`, Node SDK `0.2.4`, Python `3.1.0`, `@vantio/optics-evidence-contract`, or `@vantio/optics-record-vocabulary`. - -The package is not in `pnpm-workspace.yaml`. It calls `validateEvidence` and `validateBytes` on copies. Live CLI sources do not import it. - -## Checks - -From the repository root: - -```sh -node --test tests/optics-node-adapter/*.test.cjs -node --test tests/optics-record-vocabulary/*.test.cjs -``` - -The direct suite scores all 34 Unit A fixtures. Expected `optics_status` has to be on the detached envelope or event. `optics_health` is not accepted in its place. `cli-empty-call-file` stores `NOT_OBSERVED` on the envelope. `inherited-trace` stores `UNAVAILABLE` on the envelope. The suite also checks absent, null, and unknown readings, byte zero versus missing versus explicit zero, status dimensions, and origin preservation. - -The adversarial suite checks a prohibited canary, an enforcement token, a 65-call bound, an own getter and an inherited accessor that must not run, a path that must not be opened, a refused writer option, caller-object isolation, fail-open application results, an oversized session, a non-zero timestamp offset, null versus omitted span, frozen `displayCall` still returning `SUCCESS`, and a real CLI `0.3.24` run file whose bytes do not change when the adapter package is loaded and a copy is adapted. Object, JSON text, and bytes of that file share `optics_health` `NOT_OBSERVED` and `trace_id_basis` `ASSERTED_CONTEXT`. - -## Revision - -Council finding `OPTICS_PKG02_UNIT_B_NEEDS_REVISION` on `56ec23c3dd4c80d52596767eb557931768824d48` is addressed here. Text and byte copies use the Unit A snapshot. Envelope-only fixtures store `optics_status` on the detached record. Inherited accessors are not read. This revision's classification before council is `OPTICS_PKG02_UNIT_B_REVISION_READY_FOR_COUNCIL`. That is not a council verdict, not a merge, and not a writer. - -## Hard-stop attestations - -- No CLI, Python SDK, or Node SDK source change, and no version bump. -- No PKG-01 behavior change. -- No live writer and no live emission. -- No SQLite, migration, UI, daemon, exporter, or alerting. -- No stable schema. -- No release candidate, seal, publish, tag, or announcement. -- No Units D, E, or F. -- Draft pull request only. Not marked ready. Not merged. -- Council is a separate agent. This producer did not run it. diff --git a/docs/internal/optics-pkg02-unit-b/KNOWN-LIMITATIONS.md b/docs/internal/optics-pkg02-unit-b/KNOWN-LIMITATIONS.md deleted file mode 100644 index 356eecec..00000000 --- a/docs/internal/optics-pkg02-unit-b/KNOWN-LIMITATIONS.md +++ /dev/null @@ -1,17 +0,0 @@ -# PKG-02 Unit B known limitations - -PRIVATE | INERT | NOT SHIPPED | NO LIVE WRITER | NO LIVE READER | NO MIGRATION | NO STABLE SCHEMA - -Audience: INTERNAL_RESTRICTED - -- This unit does not activate a writer. Units D and E stay closed. `PKG02-FUTURE-CLI-UNASSIGNED` is not a release. -- The adapter is not on the `vantio run` exit path. A real CLI `0.3.24` run file stays byte-identical when this package is loaded and when a copy of that file is adapted. -- The Unit A runner still does not convert records. This package is the converter of copies. It does not rewrite the source file. -- The mapper stores invalid `sampling` as `UNSAMPLED`. The detached reading omits that key for an object, a JSON string, and a byte buffer. The mapper maps `generated_at` to `ended_at`. The detached note says that is write time. The mapper fills a null span when the source omitted span. The detached reading removes that null and keeps an explicit null. The mapper drops `IMPORTED` without provenance. The detached reading writes `IMPORTED` back and does not upgrade it. -- An explicit canonical `optics_status` `SUCCESS` is refused here even though the catalog allows the token when the caller sent it. This inert adapter does not store that token. -- Calls longer than 64 hit the contract copy bound `INPUT_BOUND`. The result has no envelope and no partial list of 64 events. This unit does not raise the bound. -- Node SDK `0.2.4` ingest is `UNSUPPORTED`. It is not turned into a local run log. -- Python fixture scoring uses the shared mapper. It is not Unit C and it does not publish or seal `3.1.0`. -- The frozen CLI display still reports optics `SUCCESS` for a call row. This unit does not change that display. -- No SQLite, migration, UI, daemon, exporter, alerting, release candidate, seal, or announcement. -- The Unit A isolation path check now diffs against the Unit A branch tip `299651c429b588e1e982a26ba717a1b4f1ffeac4`. The merge commit on main also contains the public manual, so a diff from that merge to the pre-Unit-A base names those manual files. diff --git a/docs/internal/optics-pkg02-unit-b/NO-OPTIMISTIC-DEFAULTS.md b/docs/internal/optics-pkg02-unit-b/NO-OPTIMISTIC-DEFAULTS.md deleted file mode 100644 index 320cb6ca..00000000 --- a/docs/internal/optics-pkg02-unit-b/NO-OPTIMISTIC-DEFAULTS.md +++ /dev/null @@ -1,32 +0,0 @@ -# PKG-02 Unit B — no optimistic defaults - -PRIVATE | INERT | NOT SHIPPED | NO LIVE WRITER | NO LIVE READER | NO MIGRATION | NO STABLE SCHEMA - -Audience: INTERNAL_RESTRICTED - -`SUCCESS` stays in the `optics_status` enum because PKG-01 lists it. This adapter does not store it. A missing token, an unknown token, and a legacy `opticsStatus` `SUCCESS` all read as `UNAVAILABLE`. Explicit `OBSERVED` is kept. - -| Condition | Detached reading | -| --- | --- | -| `optics_status` missing | `UNAVAILABLE`. Not `SUCCESS`. Not `OBSERVED`. | -| Legacy `opticsStatus` `SUCCESS` | `UNAVAILABLE` and `optimistic_default_forbidden` | -| Unknown token such as `SUPER_SUCCESS` | `UNAVAILABLE` and `optimistic_default_forbidden`. The raw token is absent. | -| Explicit `OBSERVED` | Preserved | -| Explicit canonical `SUCCESS` | Refused as `UNAVAILABLE` on this inert adapter | -| `action` missing | Key omitted | -| HTTP status missing or null | Key omitted. Not `200`. Not `0`. | -| Bytes missing | `response_bytes` omitted | -| Legacy `bytes` `0` | `response_bytes` null | -| Explicit `response_bytes` `0` | `0` | -| Origin missing | Reader label `LEGACY_UNMARKED`. Not stored as `LOCAL_OBSERVATION` | -| Claimed local without producer and version | `LEGACY_UNMARKED` | -| Inherited trace | `ASSERTED_CONTEXT` | -| Empty `calls` array | `NOT_OBSERVED` on `optics_health` and on the detached envelope `optics_status` | -| Inherited trace envelope | `optics_status` `UNAVAILABLE` on the detached record, `trace_id_basis` `ASSERTED_CONTEXT` | -| Absent file | `UNAVAILABLE`. Not `NOT_OBSERVED` | -| Corrupt JSON or unreadable bytes | `OPTICS_ERROR`. Not an empty success record | -| Invalid `sampling` | Omitted. Not stored as `UNSAMPLED`. The same omission applies to a JSON string and to bytes | -| HTTP 200–399 | Workload `application_status` `SUCCESS`, including 302. Not copied into `optics_status` | -| HTTP 500 | `application_status` `APPLICATION_ERROR`, `issue_location` `PROVIDER_INTERACTION`, optics `UNAVAILABLE` | - -Frozen `displayCall` still returns optics `SUCCESS` for a call row. That pairing is unsupported. This unit does not change `optics-cx.cjs`. diff --git a/docs/internal/optics-pkg02-unit-b/PRIVACY.md b/docs/internal/optics-pkg02-unit-b/PRIVACY.md deleted file mode 100644 index e218a966..00000000 --- a/docs/internal/optics-pkg02-unit-b/PRIVACY.md +++ /dev/null @@ -1,15 +0,0 @@ -# PKG-02 Unit B privacy - -PRIVATE | INERT | NOT SHIPPED | NO LIVE WRITER | NO LIVE READER | NO MIGRATION | NO STABLE SCHEMA - -Audience: INTERNAL_RESTRICTED - -The mapper strips prohibited names. This adapter does not log the rejected value. Diagnostics keep safe locator names only. A locator must match a short safe grammar or it is dropped from the detached result. - -A payload name such as `prompt` on a call drops that observation. The canary value is absent from the result JSON. An envelope that remains does not carry the value. Structural legacy names such as `plane`, `data_note`, `residual`, `free_mode`, and `est_spend_usd` are not stored on the detached record. - -An enforcement token such as `BLOCKED_EGRESS` is not stored. The observation is not emitted as optics `SUCCESS`. - -A filesystem path string is refused before any open. The path text is not copied into the result. An own getter is rejected without calling it. An inherited accessor is also left unread; the prototype getter is not invoked before the mapper rejects the copy. - -The application result is a detached copy. A validator rejection does not replace it and does not change the caller object. diff --git a/docs/internal/optics-pkg02-unit-c/ADAPTER.md b/docs/internal/optics-pkg02-unit-c/ADAPTER.md deleted file mode 100644 index b2de12ad..00000000 --- a/docs/internal/optics-pkg02-unit-c/ADAPTER.md +++ /dev/null @@ -1,19 +0,0 @@ -# PKG-02 Unit C adapter - -PRIVATE | INERT | NOT SHIPPED | NO LIVE WRITER | NO LIVE READER | NO MIGRATION | NO STABLE SCHEMA - -Audience: INTERNAL_RESTRICTED - -Public functions: - -| Function | Behavior | -| --- | --- | -| `adapt_copy(source)` | Adapts a dict copy. A path, string, or bytes value is not opened. | -| `adapt_fixture(fixture)` | Adapts one Unit A fixture, including absent, unreadable, and malformed parse states. | -| `canonical_json(value)` | Contract canonical JSON for the projection. | - -The returned reading always sets `writes_live_run_directory` false, `live_writer_modified` false, `events_invented` false, and `stable_schema` false. `posture` is the seven inert tokens. `claimed_cpython` is `3.12`. - -`record_emitted` follows the fixture: a canonical object is emitted, and a null canonical is not. `events` is set for a multi-call run. A one-call run is a single canonical object. - -Mapper defaults that Unit A does not declare (`sampling` `UNSAMPLED` when the input omitted sampling, `provider_id` `unknown` guessed from a provider string, `identity_conflict`, null spans, `ended_at` taken from `generated_at`) stay off the scored object. The mapper still ran on the copy. The projection is the Unit A reading. diff --git a/docs/internal/optics-pkg02-unit-c/BOUNDARY.md b/docs/internal/optics-pkg02-unit-c/BOUNDARY.md deleted file mode 100644 index 50d1f16c..00000000 --- a/docs/internal/optics-pkg02-unit-c/BOUNDARY.md +++ /dev/null @@ -1,35 +0,0 @@ -# PKG-02 Unit C boundary - -PRIVATE | INERT | NOT SHIPPED | NO LIVE WRITER | NO LIVE READER | NO MIGRATION | NO STABLE SCHEMA - -Audience: INTERNAL_RESTRICTED - -Unit C is the inert Python adapter. It depends on merged Unit A. It is parallel to Unit B. It is not a writer activation, not a reader release, and not a publish of Python 3.1.0. - -`schema_status` is `unstable-pre-1.0`. `schema_version` on a projected record is `0` when the source carried a legacy schema version. JSON Schema is not the source of truth. - -## Starting point - -Locked main: `587f3b94d47ea958f91d3a99125cd55931d995f1`. - -Branch: `cursor/pkg02-unit-c-inert-python-c7bb`. - -## In scope - -- A private Python package beside the evidence contract. -- Copy-in, projection-out adaptation. -- Scoring the Unit A fixtures on CPython 3.12. -- A byte-identity check that a 3.1.0-shaped file is unchanged after the adapter reads a parsed copy. - -## Out of scope - -- `packages/vantio-agent-sdk-py/vantio/` and `pyproject.toml` on the 3.1.0 line. -- `packages/vantio-cli/`. -- PKG-01 tables, Unicode data, and the evidence-contract modules. -- The Unit A vocabulary files. -- PyPI, TestPyPI, Twine, a release candidate, a seal, a tag. -- SQLite, migrations, UI, a daemon, OTLP, alerting. -- Units B, D, E, and F. -- Opening a live `~/.vantio/runs` path. A path argument is refused before any read. - -Producer classification before council: `OPTICS_PKG02_UNIT_C_READY_FOR_COUNCIL`. diff --git a/docs/internal/optics-pkg02-unit-c/DESIGN.md b/docs/internal/optics-pkg02-unit-c/DESIGN.md deleted file mode 100644 index d12a24e4..00000000 --- a/docs/internal/optics-pkg02-unit-c/DESIGN.md +++ /dev/null @@ -1,38 +0,0 @@ -# PKG-02 Unit C design - -PRIVATE | INERT | NOT SHIPPED | NO LIVE WRITER | NO LIVE READER | NO MIGRATION | NO STABLE SCHEMA - -Audience: INTERNAL_RESTRICTED - -## Pipeline - -Inventory, then this design, then the package, then the tests. The producer stops at `OPTICS_PKG02_UNIT_C_READY_FOR_COUNCIL`. Merge and writer activation stay closed. - -## Flow - -1. Deep-copy the input. The caller's object and any on-disk file stay as they were. -2. Present that copy to `validate_evidence` from `@vantio/optics-evidence-contract`. Run logs use the public mapper. A bare call renames `hostname`, `status`, `opticsStatus`, `applicationStatus`, and `ts` onto contract names before validation. Envelope fragments rename `trace_id` to `run_id`, `pid` to `process_id`, `ppid` to `parent_process_id`, and `ts` to `started_at`, then validate as `run_envelope`. A CLI identity fragment with no call stores `optics_status` `UNAVAILABLE`. `generated_at` is not stored as `ended_at` in the scored projection. -3. Project the mapper record onto the Unit A declared canonical object. -4. Return the projection, the reader label, and diagnostics. Discard the projection with the process. Nothing is appended to a run directory. - -## Projection rules - -- Live `opticsStatus` `SUCCESS`, and any optics token outside the enum, become `UNAVAILABLE` with `OPTIMISTIC_DEFAULT_FORBIDDEN`. Explicit `optics_status` `OBSERVED` stays `OBSERVED`. -- Missing optics status on an observation is `UNAVAILABLE`. -- An empty CLI `calls` array is `optics_status` `NOT_OBSERVED` plus `call_count` `0`. A missing file and an empty `shield()` are `UNAVAILABLE`. Corrupt JSON and unreadable bytes are `OPTICS_ERROR` and emit no record. -- Legacy `bytes` `0` is `response_bytes` null. Explicit `response_bytes` `0` stays `0`. A missing byte count omits the key. -- `failure_kind` `none` is omitted. Transport `error` `network_error` is omitted. A transport `error_class` stays in the diagnostic. `failure_kind` `wrapped` keeps `error_class` and `issue_location` `CUSTOMER_APPLICATION`. -- Invalid `method` and invalid `sampling` are omitted. `sampling` is not rewritten to `UNSAMPLED` in the scored object. -- A comma-joined `mediation` is the reading `unknown`. It is one field. It does not become extra events. -- `+00:00` timestamps normalize to `Z` with three fractional digits on the copy only. -- Mixed per-call application tokens set envelope `lifecycle` `PARTIAL`. They do not set `application_status` `PARTIAL`. -- `duration_ms` `0` with null HTTP status is pre-completion: the duration is omitted and `lifecycle` is `INTERRUPTED`. -- Inherited `trace_id` without the witness becomes `run_id` and `trace_id_basis` `ASSERTED_CONTEXT`. -- A witness plus a recognized producer and a version yields `trace_id_basis` `OPTICS_GENERATED`. The witness value is absent from the projection. -- `IMPORTED` keeps `original_evidence_origin`. Claimed `LOCAL_OBSERVATION` without producer and version is the reader label `LEGACY_UNMARKED` and is not stored as local. -- Node SDK 0.2.4 ingest is `UNSUPPORTED` and emits no local record. -- A `future_not_shipped` input still projects. `unsupported_state` is `UNSUPPORTED` because a frozen reader is outside this adapter. - -## Package identity - -`vantio-optics-python-adapter` `0.0.0-unstable-pre-1.0`. That name is not the 3.1.0 distribution name `vantio-agent-sdk`. diff --git a/docs/internal/optics-pkg02-unit-c/FIXTURE-SCORE.md b/docs/internal/optics-pkg02-unit-c/FIXTURE-SCORE.md deleted file mode 100644 index 721571a5..00000000 --- a/docs/internal/optics-pkg02-unit-c/FIXTURE-SCORE.md +++ /dev/null @@ -1,26 +0,0 @@ -# PKG-02 Unit C fixture score - -PRIVATE | INERT | NOT SHIPPED | NO LIVE WRITER | NO LIVE READER | NO MIGRATION | NO STABLE SCHEMA - -Audience: INTERNAL_RESTRICTED - -The score is the 34 fixtures in `packages/optics-record-vocabulary/fixtures/conformance-fixtures.json`. - -For each fixture the adapter result must match: - -- `expected_canonical` -- `expected_events` -- `record_emitted` -- `expected_unsupported_state` - -The fixture object itself must be unchanged. No fixture projection stores `optics_status` `SUCCESS`. - -Python `python-3-1-0` additionally requires `OPTIMISTIC_DEFAULT_FORBIDDEN`, `mediation_reading` `unknown`, and `started_at` `2026-07-01T00:00:00.100Z` while the input `ts` remains `2026-07-01T00:00:00.100000+00:00`. - -The canonical JSON of the Python and CLI projections must be byte-identical to `canonicalJson` in the Unit A package. - -Command: - -```sh -python3 -m unittest discover -s tests/optics-python-adapter -v -``` diff --git a/docs/internal/optics-pkg02-unit-c/IMPLEMENTATION-REPORT.md b/docs/internal/optics-pkg02-unit-c/IMPLEMENTATION-REPORT.md deleted file mode 100644 index df09445e..00000000 --- a/docs/internal/optics-pkg02-unit-c/IMPLEMENTATION-REPORT.md +++ /dev/null @@ -1,42 +0,0 @@ -# PKG-02 Unit C implementation report - -PRIVATE | INERT | NOT SHIPPED | NO LIVE WRITER | NO LIVE READER | NO MIGRATION | NO STABLE SCHEMA - -Audience: INTERNAL_RESTRICTED - -Producer classification before council: `OPTICS_PKG02_UNIT_C_READY_FOR_COUNCIL` - -This classification means the Unit C branch is ready for a separate council agent. It is not a council verdict, not a merge, and not a statement that a writer exists. - -The producer did not sit the council. - -## What landed - -Private package `vantio-optics-python-adapter` at `0.0.0-unstable-pre-1.0`. That version matches the unstable posture. It is not a bump of CLI `0.3.24`, Node SDK `0.2.4`, Python `3.1.0`, the evidence contract, or the Unit A vocabulary package. - -The package is not in `pnpm-workspace.yaml`. Its distribution name is not `vantio-agent-sdk`. - -Claimed CPython: 3.12. - -## Checks - -From the repository root: - -```sh -python3 -m unittest discover -s tests/optics-python-adapter -v -``` - -The producer run of that command reported 13 tests and 0 failures on CPython 3.12.3. One test scores all 34 Unit A fixtures. The suite also covers Python `SUCCESS` refusal, `+00:00` normalization on the copy, comma-joined `mediation` as `unknown`, absent and corrupt readings, sampling and unknown-method omission, Node canonical bytes, path refusal, 3.1.0 file byte identity, frozen versions, path scope, and a stable live-entrypoint identity. - -## Hard-stop attestations - -- No CLI source change. -- No Python 3.1.0 SDK source change and no seal or publish. -- No PKG-01 change and no Unit A vocabulary change. -- No live writer import and no `shield` redirect. -- No SQLite, migration, UI, daemon, exporter, or alerting. -- No stable schema. -- No release candidate, tag, or announcement. -- No Units B, D, E, or F. -- Draft pull request only. Not marked ready. Not merged. -- Council is a separate agent. This producer did not run it. diff --git a/docs/internal/optics-pkg02-unit-c/INVENTORY.md b/docs/internal/optics-pkg02-unit-c/INVENTORY.md deleted file mode 100644 index 4bbf7e90..00000000 --- a/docs/internal/optics-pkg02-unit-c/INVENTORY.md +++ /dev/null @@ -1,31 +0,0 @@ -# PKG-02 Unit C inventory - -PRIVATE | INERT | NOT SHIPPED | NO LIVE WRITER | NO LIVE READER | NO MIGRATION | NO STABLE SCHEMA - -Audience: INTERNAL_RESTRICTED - -Starting commit: `587f3b94d47ea958f91d3a99125cd55931d995f1` (`Merge pull request #63`, Unit A vocabulary on main). - -## Frozen surfaces this unit leaves in place - -| Surface | Location | Version | -| --- | --- | --- | -| CLI writer | `packages/vantio-cli/bin/interceptor.cjs` | `@vantio/cli` `0.3.24` | -| Python writer | `packages/vantio-agent-sdk-py/vantio/` | `vantio-agent-sdk` `3.1.0` | -| Node SDK | `packages/vantio-agent-sdk/` | `@vantio/agent-sdk` `0.2.4` | -| Evidence mapper | `packages/optics-evidence-contract/src/validate.py` | `0.0.0-unstable-pre-1.0` | -| Vocabulary | `packages/optics-record-vocabulary/` | `0.0.0-unstable-pre-1.0` | - -The Python writer entrypoint is `shield` in `packages/vantio-agent-sdk-py/vantio/sdk.py`. Call rows are built in `_record` (`vantio/_http_observe.py`), which assigns `opticsStatus` `SUCCESS` before `_append`. The run file is written under the home runs directory. Envelope `mediation` is `",".join(mediations)` in that same module. Empty `shield()` writes no file. - -## What Unit C adds - -- `packages/optics-python-adapter/` — private package `vantio-optics-python-adapter` `0.0.0-unstable-pre-1.0`. -- `tests/optics-python-adapter/` — fixture score and isolation. -- `docs/internal/optics-pkg02-unit-c/` — these notes. - -The package is not a pnpm workspace member. It is not `vantio-agent-sdk`. Claimed CPython for this force is 3.12, which is the interpreter that ran the suite. - -## Shared corpus - -Unit A fixtures: `packages/optics-record-vocabulary/fixtures/conformance-fixtures.json` (34 fixtures). This unit reads that file. It does not rewrite it. diff --git a/docs/internal/optics-pkg02-unit-c/KNOWN-LIMITATIONS.md b/docs/internal/optics-pkg02-unit-c/KNOWN-LIMITATIONS.md deleted file mode 100644 index ca3cfbcc..00000000 --- a/docs/internal/optics-pkg02-unit-c/KNOWN-LIMITATIONS.md +++ /dev/null @@ -1,15 +0,0 @@ -# PKG-02 Unit C known limitations - -PRIVATE | INERT | NOT SHIPPED | NO LIVE WRITER | NO LIVE READER | NO MIGRATION | NO STABLE SCHEMA - -Audience: INTERNAL_RESTRICTED - -- CPython claim is 3.12 only. 3.10 and 3.11 were not executed in this force. -- The adapter does not open live run directories, so ordinary-client proof here is a file in a temporary directory with a 3.1.0 shape, not a customer home directory. -- The scored projection omits a transport `error_class` such as `ENOTFOUND`. The network `failure_kind` is the stored classification. The class token remains in the diagnostic. -- Envelope `mediation` is reported on the reading. A single closed token is not copied into the scored canonical object in this unit. -- `generated_at` is not stored as `ended_at`. That follows the Unit A CLI fixture. -- Invalid `sampling` is omitted. The mapper's own record would store `UNSAMPLED`. The projection does not. -- Node SDK ingest and `future_not_shipped` inputs are marked `UNSUPPORTED` for a frozen reader. This unit does not ship that reader. -- Unit B, Unit D, Unit E, and Unit F are not in this branch. -- This is not a stable schema and not a release. diff --git a/docs/internal/optics-pkg02-unit-c/NO-WRITER.md b/docs/internal/optics-pkg02-unit-c/NO-WRITER.md deleted file mode 100644 index 541450f1..00000000 --- a/docs/internal/optics-pkg02-unit-c/NO-WRITER.md +++ /dev/null @@ -1,15 +0,0 @@ -# PKG-02 Unit C — no writer - -PRIVATE | INERT | NOT SHIPPED | NO LIVE WRITER | NO LIVE READER | NO MIGRATION | NO STABLE SCHEMA - -Audience: INTERNAL_RESTRICTED - -`shield` in `vantio-agent-sdk` 3.1.0 is not replaced, wrapped, or redirected. The adapter package does not import that module. - -A 3.1.0-shaped JSON file is hashed by the test, parsed, adapted, and hashed again. The file bytes match. The in-memory source still shows `opticsStatus` `SUCCESS` and the `+00:00` timestamp. The detached projection shows `UNAVAILABLE` and `Z`. - -Path objects are refused with `PATH_NOT_OPENED` and `UNAVAILABLE`. The adapter does not stat them and does not create `~/.vantio/runs`. - -Rollback of this unit is deletion of `packages/optics-python-adapter/`, `tests/optics-python-adapter/`, and `docs/internal/optics-pkg02-unit-c/`. Customer files are unchanged because this unit does not write them. - -Python 3.0.15 is not the vehicle. Python 3.1.0 is not republished. CLI 0.3.24 is not reopened. diff --git a/docs/internal/optics-pkg02-unit-d/BOUNDARY.md b/docs/internal/optics-pkg02-unit-d/BOUNDARY.md deleted file mode 100644 index 2e0b92c4..00000000 --- a/docs/internal/optics-pkg02-unit-d/BOUNDARY.md +++ /dev/null @@ -1,37 +0,0 @@ -# PKG-02 Unit D boundary - -PRIVATE | FUTURE LINE | NOT PUBLISHED | NOT SEALED | NO UNIT E | NO STABLE SCHEMA - -Audience: INTERNAL_RESTRICTED - -Unit D activates the Node Optics writer on `@vantio/cli` `0.4.0-pkg02-unit-d`. That version is the concrete future line for `PKG02-FUTURE-CLI-UNASSIGNED`. It is not `0.3.24`. - -`schema_status` is `unstable-pre-1.0`. `schema_version` is `0`. The Unicode diagnostic is `PKG01-UCD-16.0.0`. The contract package stays private at `0.0.0-unstable-pre-1.0`. `@vantio/agent-sdk` stays `0.2.4`. - -## Starting point - -Founder Force starting commit: `dd3344dcc636136ed22df75e8df3866c993efd27`. - -Prerequisites already on that commit: Unit A, Unit B, Unit F, and the T2a reader-compat gates. This unit does not re-implement them. - -## What this unit contains - -- `packages/vantio-cli-pkg02/` — the future CLI tree and writer. -- `tests/optics-pkg02-unit-d/` — proofs. -- `docs/internal/optics-pkg02-unit-d/` — these notes. -- Five cells in `docs/planning/optics-pkg02/RECORD-COMPATIBILITY-MATRIX.json` marked `UNIT_D_PROVED_NOT_SHIPPED`. - -The package is not a pnpm workspace member. `packages/vantio-cli/` is not edited. - -## What this unit does not do - -- It does not reopen, edit, or republish `@vantio/cli` `0.3.24`. -- It does not change Python `3.1.0` or start Unit E. -- It does not publish to npm, seal, or open a release candidate. -- It does not add SQLite, a migration, a UI, a daemon, OTLP, SIEM, or alerting. -- It does not store prompts, machine hostnames, or cost. -- It does not mark a council pass, and it does not merge. - -Producer classification before council: `OPTICS_PKG02_UNIT_D_READY_FOR_COUNCIL`. - -That classification is not a council verdict and not a statement that the line is shipped. diff --git a/docs/internal/optics-pkg02-unit-d/DELTA.md b/docs/internal/optics-pkg02-unit-d/DELTA.md deleted file mode 100644 index 0be7a1d8..00000000 --- a/docs/internal/optics-pkg02-unit-d/DELTA.md +++ /dev/null @@ -1,22 +0,0 @@ -# PKG-02 Unit D record delta - -PRIVATE | FUTURE LINE | NOT PUBLISHED | NOT SEALED | NO UNIT E | NO STABLE SCHEMA - -Audience: INTERNAL_RESTRICTED - -The same local `POST` workload was run with `@vantio/cli` `0.3.24` and with `0.4.0-pkg02-unit-d`. The written files differ as follows. - -| Fact | `0.3.24` file | `0.4.0-pkg02-unit-d` file | -| --- | --- | --- | -| Top-level marker | `vantio_run_log` `"1"` | `record_type` `run_envelope` plus `events[]` of `observation_event` | -| `schema_version` | `2` | `0`, with `2` only at `compatibility.legacy_schema_version` | -| Run identity | `trace_id` | `run_id` holding that same kind of `0x` value. `trace_id` is absent | -| Optics token | No stored optics token. Display fills `SUCCESS` | `OBSERVED` on the call that was seen | -| Response size | `bytes` from the frozen exit map | `response_bytes` when `Content-Length` was present | -| Origin | Absent on the file | `LOCAL_OBSERVATION` with `producer` `node_interceptor` and `cli_or_sdk_version` `0.4.0-pkg02-unit-d` | -| Action | Frozen action string | `OBSERVED` on the observation. Enforcement tokens are not stored | -| Issue location | Absent | `issue_location` on the observation | -| Unicode | Absent | `diagnostics.unicode_profile_id` `PKG01-UCD-16.0.0` | -| Prohibited keys | `plane`, `data_note`, `residual`, `free_mode`, and `summary.est_spend_usd` are on the frozen file | Those keys are absent | - -A Unit A reading of the frozen CLI fixture `cli-0-3-24` stays `UNAVAILABLE`, because that file has no optics token. The future writer of a seen call stores `OBSERVED`. Those are different acts: reading an old file, and writing a new one. diff --git a/docs/internal/optics-pkg02-unit-d/DESIGN.md b/docs/internal/optics-pkg02-unit-d/DESIGN.md deleted file mode 100644 index bd67651d..00000000 --- a/docs/internal/optics-pkg02-unit-d/DESIGN.md +++ /dev/null @@ -1,19 +0,0 @@ -# PKG-02 Unit D design - -PRIVATE | FUTURE LINE | NOT PUBLISHED | NOT SEALED | NO UNIT E | NO STABLE SCHEMA - -Audience: INTERNAL_RESTRICTED - -`vantio-pkg02 run node