Depends on: #10
Related runtime work: samovers/OFARM2#177, samovers/OFARM2#182, samovers/OFARM2#353
Outcome
Define the canonical decision that controls whether already committed filing bytes may cross an external boundary now, without impersonating the human or re-exercising the completed filing authorization.
Primary trust boundary
External disclosure and data sovereignty: the boundary between an immutable internal filing-outbox record and release of protected bytes to a recipient endpoint.
Acceptance criteria
- Keep the authenticated human outbox commitment and later byte release as separate decisions and receipts.
- Bind release to an immutable regime-specific policy covering destination and recipient eligibility, current SharingGrant or statutory basis where applicable, data-sovereignty posture, custody and endpoint identity, and cancellation/hold state.
- Re-evaluate release eligibility before every first send or retry that may disclose protected bytes.
- Preserve the historical filing act when current release becomes blocked.
- Permit irrevocable delivery at outbox commitment only through an explicit content-addressed regime rule; never infer it from idempotency or filing completion.
- Bind the release-policy ref/digest and disposition into the transport receipt.
- Add hostile cases for sharing revocation, recipient loss of eligibility, endpoint substitution, custody change, active hold, changed bytes/destination, and an unsupported irrevocability claim.
Non-goals
No change to human filing authority, no dispatcher or provider implementation, no receiver protocol, no credential/key custody, no grant mutation, and no production deployment claim.
Delivery rule
Canonical release semantics and runtime enforcement must remain separately reviewable. Any provider-specific custody or receiver protocol gets its own dependent issue and PR.
What is next: identify the active sovereignty/sharing authorities and draft the smallest regime-neutral release decision contract.
Depends on: #10
Related runtime work: samovers/OFARM2#177, samovers/OFARM2#182, samovers/OFARM2#353
Outcome
Define the canonical decision that controls whether already committed filing bytes may cross an external boundary now, without impersonating the human or re-exercising the completed filing authorization.
Primary trust boundary
External disclosure and data sovereignty: the boundary between an immutable internal filing-outbox record and release of protected bytes to a recipient endpoint.
Acceptance criteria
Non-goals
No change to human filing authority, no dispatcher or provider implementation, no receiver protocol, no credential/key custody, no grant mutation, and no production deployment claim.
Delivery rule
Canonical release semantics and runtime enforcement must remain separately reviewable. Any provider-specific custody or receiver protocol gets its own dependent issue and PR.
What is next: identify the active sovereignty/sharing authorities and draft the smallest regime-neutral release decision contract.