Skip to content

Promote executable authorization constraints and decision evidence RFC v0.2 #21

Description

@samovers

Parent: #10

Status: future staged-delivery step 7; blocked until the exact prerequisites below are reviewed and complete.

Approved semantic source: PR #11 at 4494924998183fe3fa7bc1b63b76a85893335044, with renewed Phase A approval. Scope aligned 2026-09-11; the earlier source and body are preserved below as history.

Outcome

Promote the newly approved PR #11 semantics and exact initial two-action executable scope into the accepted-RFC lane while pinning the reviewed schema and manifest bytes. Preserve the full twenty-action catalogue without activating its unselected rows. The initial set is exactly ASSERT_OPERATION_CLAIM and RECEIVE_READ_DATA with complete unchanged rule semantics and all required transitive dependencies. Accepted-law promotion remains separate from machine-contract current/default promotion and OFARM2 implementation; the remaining full-catalogue programme stays under #10.

Primary trust boundary

Canonical authorization law and decision evidence: the boundary that defines the facts, path rules, failure posture, aggregation, validity, human-finalization requirements, single-use decision obligations, and durable evidence required before an authorization decision may truthfully claim ALLOW or another governed outcome.

Required predecessors

The exact approved PR #11 staged-delivery sequence controls. All eight predecessor categories remain accounted for, applied to the complete selected scope rather than an optional example. This promotion cannot start until:

  1. every content-addressed protected-effect contract required by a selected state-affecting rule is reviewed under Define protected-effect contracts for authorization-bound state changes #12, including the operation-claim AssertionRecord submission contract; final ReviewDecision and other independent effects may be deferred only with an explicit closure finding;
  2. required Event Grammar and CP2 public-result/read-qualification bindings are separately closed, including CP2A-DEP01 source-history completeness and historical-admission verification under Define authorization-evidence source-history qualification and producer contract #32 and its actual source dependencies; the open question in PR RFC candidate: executable authorization evidence v0.2 #11 section 24.1 is not waived;
  3. every selected retention/proof-strength requirement is closed under Define authorization evidence retention and proof-strength postures #14, including governed-read evidence; display-specific work may be deferred only if proven unrelated;
  4. every applicable human-transaction dependency is accounted for. PR RFC candidate: governed human-finalization transaction protocol #20 at 98f8c4fafbae42c8f7fd931f43f53adcb4733713 is an approved semantic candidate under Define governed human-approval transaction and consumption protocol #19, not executable materialization. Human-finalization profiles may be deferred only where the selected closure proves them unrelated; no shared transaction requirement is waived;
  5. the selected NOT_REQUIRED atomic transaction profile under Define the NOT_REQUIRED atomic transaction and single-use consumption profile #25 is closed, including durable NO_EFFECT, exact identity/caller-projection comparison, no unsafe forgetting, independent reconciliation and the first ASSERT_OPERATION_CLAIM handoff. The separately owned governed-read transaction/coverage/receipt/disclosure protocol must also be closed; PR Define the NOT_REQUIRED transaction and consumption protocol v0.1 #26's write-only profile is not that read protocol;
  6. a non-default authorization-policy PR materializes the exact scoped AuthorizationPolicyBundle v0.2, all selected intent/projection/evidence/protected-effect bindings and transitive profiles, and an immutable manifest with real digests, exact admitted-set/resolved-rule equality and no placeholders;
  7. a separate authorization-source PR materializes the closed AuthorityGrant, DelegationGrant and SharingGrant v0.2 contracts required by the full selected paths; reading their evidence is not deferred because mutation commands are later; and
  8. separate bounded decision-evidence PRs materialize the complete selected AuthorizationDecisionEvidence v0.2 and AuthorizationFinalizationEvidence v0.2 profiles, with every omitted independent profile recorded in the reviewed deferred-obligation ledger.

Exact schema/manifest bytes, complete dependency closure and exact variant/currentness handling must receive binding review before this promotion begins. No family-level pointer may silently activate the remaining eighteen actions or omitted profiles. Any semantic contradiction or demonstrated need for another action returns to PR #11 for a separately approved amendment; no second policy or permanently unavailable history implementation is a workaround.

Intended future PR boundary

Once the predecessors are complete, one accepted-RFC promotion PR may:

  • create 02_accepted_rfcs/OFARM_Executable_Authorization_Constraints_and_Decision_Evidence_RFC_v0_2.md from the exact approved PR RFC candidate: executable authorization evidence v0.2 #11 source;
  • replace only Phase A/candidate governance-state wording needed for an internally consistent accepted RFC;
  • pin the exact reviewed schema and manifest digests and explicitly preserve the approved admitted set, deferred catalogue rows and dependency-closure disposition;
  • update accepted-RFC navigation and current-view files; and
  • refresh mechanically required manifests, material-status records, package indexes, generated indexes, and repository cross-reference reports.

It must not edit the historical PR #11 candidate, the active baseline, companion policies, machine schemas, machine-contract current/default selection, protected-effect contracts, transaction coordination, transport release, retention or key custody, database authority, OFARM2, or runtime code.

Acceptance criteria

  • The promoted semantic source is exactly PR RFC candidate: executable authorization evidence v0.2 #11 head 4494924998183fe3fa7bc1b63b76a85893335044, with renewed steward semantic approval. The equivalence report separately identifies the approved scope delta from historical head 03a21f669ee04f96d444e14f00ae7212cab04803; do not claim this scope is identical to the former all-action promotion requirement.
  • Every catalogue row, selected-rule meaning, target policy, authority path, outcome/reason rule, digest projection, applicable invariant, hostile case, migration rule, release-scope rule and approval-card answer remains semantically identical to the new approved source. Unselected action-specific obligations stay explicit and non-executable for this package, not deleted or marked passed.
  • Every prerequisite schema, contract, and manifest reference resolves to the exact reviewed bytes and digest.
  • Candidate-only wording is changed only where necessary to state accepted/effective-on-merge posture and the still-separate downstream stages.
  • A reviewable equivalence report identifies every intentional text delta from the approved source and proves that each delta is governance framing, exact binding, or mechanical navigation rather than an unreviewed semantic amendment.
  • Accepted-RFC README/current views and all derived indexes or reports identify the new accepted RFC consistently.
  • The promotion does not change the active baseline, promote a machine contract to current/default, or claim implementation or production readiness.
  • Repository validation, generated-currentness, cross-reference, Markdown structure, and diff-hygiene checks pass.
  • The final PR description names the exact approved source head, approval record, prerequisite digests, and one-boundary scope.

Non-goals

  • No schema, example, manifest, or hostile-conformance creation in the promotion PR.
  • No current/default machine-contract promotion.
  • No source-record migration.
  • No protected-effect, approval-transaction, transport, retention, custody, database, or OFARM2 runtime work.
  • No merge or deployment authorization.

Reapproval rule

If promotion requires changing any approved semantic rule rather than governance-state wording or inserting already reviewed exact bindings, stop before editing it and return to PR #11 for renewed exact-head semantic review. If a generated or current-view update would create authority outside the accepted-RFC lane, split it into a separate issue and PR.

Previous issue body — superseded scope history, captured 2026-09-11

This is the complete previous body. Its scope, source pins and next-step wording are historical; the amended current text above controls. Prior decisions and approvals remain attached to their original revisions.

Parent: #10

Status: future staged-delivery step 7; blocked until the exact prerequisites below are reviewed and complete.

Approved semantic source: PR #11 at 03a21f669ee04f96d444e14f00ae7212cab04803.

Outcome

Promote the approved executable authorization constraints and decision-evidence semantics into the accepted-RFC authority lane while pinning the exact reviewed schema and manifest digests required by that design. The promotion must not change the approved meaning or prematurely change machine-contract current/default selection or runtime behavior.

Primary trust boundary

Canonical authorization law and decision evidence: the boundary that defines the facts, path rules, failure posture, aggregation, validity, human-finalization requirements, single-use decision obligations, and durable evidence required before an authorization decision may truthfully claim ALLOW or another governed outcome.

Required predecessors

The exact approved PR #11 staged-delivery sequence controls over the older summary ordering in issue #10. This promotion cannot start until:

  1. the remaining content-addressed protected-effect contracts required by state-affecting rules are reviewed under Define protected-effect contracts for authorization-bound state changes #12; PR RFC candidate: final ReviewDecision protected-effect contract #17 / Define final ReviewDecision protected-effect contract #15 closes only the final ReviewDecision family;
  2. any required Event Grammar classification and the CP2 authorization-result surface/public reason-code contract are separately closed;
  3. the evidence-retention proof postures required by approval displays and governed reads are closed under Define authorization evidence retention and proof-strength postures #14;
  4. the governed interactive-approval transaction protocol is closed under Define governed human-approval transaction and consumption protocol #19, which is complete at approved PR RFC candidate: governed human-finalization transaction protocol #20 head 98f8c4fafbae42c8f7fd931f43f53adcb4733713;
  5. the NOT_REQUIRED atomic transaction and single-use consumption profile is closed under Define the NOT_REQUIRED atomic transaction and single-use consumption profile #25, including its durable NO_EFFECT lifecycle, idempotency-key equality and no-unsafe-forgetting rules, authoritative reconciliation, and first ASSERT_OPERATION_CLAIM handoff;
  6. a non-default authorization-policy PR materializes AuthorizationPolicyBundle v0.2, all effect-intent schemas, declarative projections, evidence and approval-cutoff bindings, protected-effect bindings, and one immutable digest manifest;
  7. a separate authorization-source PR materializes the closed AuthorityGrant, DelegationGrant, and SharingGrant v0.2 contracts; and
  8. separate bounded decision-evidence PRs materialize AuthorizationDecisionEvidence v0.2 and AuthorizationFinalizationEvidence v0.2.

The exact schema and manifest bytes must receive binding review before this promotion begins. Any semantic contradiction found there returns to PR #11 for renewed approval.

Intended future PR boundary

Once the predecessors are complete, one accepted-RFC promotion PR may:

  • create 02_accepted_rfcs/OFARM_Executable_Authorization_Constraints_and_Decision_Evidence_RFC_v0_2.md from the exact approved PR RFC candidate: executable authorization evidence v0.2 #11 source;
  • replace only Phase A/candidate governance-state wording needed for an internally consistent accepted RFC;
  • pin the exact reviewed schema and manifest digests;
  • update accepted-RFC navigation and current-view files; and
  • refresh mechanically required manifests, material-status records, package indexes, generated indexes, and repository cross-reference reports.

It must not edit the historical PR #11 candidate, the active baseline, companion policies, machine schemas, machine-contract current/default selection, protected-effect contracts, transaction coordination, transport release, retention or key custody, database authority, OFARM2, or runtime code.

Acceptance criteria

  • The promoted semantic source is exactly PR RFC candidate: executable authorization evidence v0.2 #11 head 03a21f669ee04f96d444e14f00ae7212cab04803, whose renewed steward semantic approval is recorded at RFC candidate: executable authorization evidence v0.2 #11 (comment).
  • Every action row, target policy, authority-path rule, outcome/reason rule, digest projection, invariant, hostile case, migration rule, and approval-card answer remains semantically identical to the approved source.
  • Every prerequisite schema, contract, and manifest reference resolves to the exact reviewed bytes and digest.
  • Candidate-only wording is changed only where necessary to state accepted/effective-on-merge posture and the still-separate downstream stages.
  • A reviewable equivalence report identifies every intentional text delta from the approved source and proves that each delta is governance framing, exact binding, or mechanical navigation rather than an unreviewed semantic amendment.
  • Accepted-RFC README/current views and all derived indexes or reports identify the new accepted RFC consistently.
  • The promotion does not change the active baseline, promote a machine contract to current/default, or claim implementation or production readiness.
  • Repository validation, generated-currentness, cross-reference, Markdown structure, and diff-hygiene checks pass.
  • The final PR description names the exact approved source head, approval record, prerequisite digests, and one-boundary scope.

Non-goals

  • No schema, example, manifest, or hostile-conformance creation in the promotion PR.
  • No current/default machine-contract promotion.
  • No source-record migration.
  • No protected-effect, approval-transaction, transport, retention, custody, database, or OFARM2 runtime work.
  • No merge or deployment authorization.

Reapproval rule

If promotion requires changing any approved semantic rule rather than governance-state wording or inserting already reviewed exact bindings, stop before editing it and return to PR #11 for renewed exact-head semantic review. If a generated or current-view update would create authority outside the accepted-RFC lane, split it into a separate issue and PR.

What is next: keep this promotion issue blocked while #25 and the remaining listed prerequisites proceed as separately governed issues and PRs.

What is next: keep this promotion issue blocked until the complete selected prerequisites, history proof and exact binding review are satisfied. This issue update performs no promotion, materialization, extraction or implementation.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions