{
  "schema_version": 1,
  "generated_at": "2026-08-23",
  "refresh": "regenerated with each release and each deployment",
  "registry": {
    "schema_version": 3,
    "as_of": "2026-08-23",
    "title": "What Exists Today",
    "capabilities": [
      {
        "id": "action-receipt",
        "label": "ActionReceipt",
        "maturity": "released",
        "availability": "PYPI_RELEASED",
        "established": "Portable ActionReceipt v0.2 records, canonical hashing, cryptographic verification, and reference vectors.",
        "not_established": "The worldly truth of the recorded claim or occurrence of the underlying event.",
        "evidence_class": "released implementation and reproducible fixtures",
        "evidence_provenance": {
          "author_origin": "TEAM_AUTHORED",
          "adjudication_origin": "MACHINE_CHECKED",
          "replay_mode": "INTERNAL_REPRODUCIBLE",
          "closure_warrant": "NOT_APPLICABLE"
        },
        "canonical_refs": [
          "bulla/spec/action-receipt-v0.2.md",
          "bulla/spec/vectors/expected.json",
          "glyph/data/external-reliance-decisions/ledger.json",
          "glyph/data/external-reliance-decisions/intake-context.json",
          "glyph/data/external-reliance-decisions/intake-key.json",
          "glyph/data/external-reliance-decisions/intake-key.schema.json",
          "glyph/data/external-reliance-decisions/intake-test-result.json",
          "glyph/data/external-reliance-decisions/record.schema.json",
          "glyph/data/external-reliance-decisions/member.schema.json",
          "glyph/data/external-reliance-decisions/PROFILE.md",
          "glyph/data/external-reliance-decisions/FIRST-D.md",
          "glyph/scripts/build_external_reliance_intake_test.py",
          "glyph/scripts/external_reliance_intake.py",
          "glyph/scripts/verify-intake-test-result.mjs",
          "glyph/scripts/test-intake-test-result.mjs",
          "glyph/scripts/check_external_reliance_evidence.py",
          "glyph/scripts/replay_external_reliance_runtime.py",
          "bulla/tests/test_external_reliance_evidence.py"
        ],
        "external_counts": {
          "authors": 0,
          "adjudicators": 0,
          "implementations": 0,
          "witnesses": 0
        },
        "supersession_refs": [],
        "correction_refs": [
          "bulla/spec/action-receipt-v0.4-draft.md"
        ],
        "external_replays": 0
      },
      {
        "id": "authority-scope",
        "label": "Authority and scope",
        "maturity": "released-draft",
        "availability": "PYPI_RELEASED",
        "established": "Opt-in v0.3 implementation binds issuer authorization, delegation, and structured scope checks.",
        "not_established": "The legality, legitimacy, or institutional sufficiency of the authored authority policy.",
        "evidence_class": "released draft with local conformance fixtures",
        "evidence_provenance": {
          "author_origin": "TEAM_AUTHORED",
          "adjudication_origin": "MACHINE_CHECKED",
          "replay_mode": "INTERNAL_REPRODUCIBLE",
          "closure_warrant": "NOT_APPLICABLE"
        },
        "canonical_refs": [
          "bulla/spec/action-receipt-v0.3-draft.md",
          "bulla/spec/delegation-design-note.md"
        ],
        "external_counts": {
          "authors": 0,
          "adjudicators": 0,
          "implementations": 0,
          "witnesses": 0
        },
        "supersession_refs": [],
        "correction_refs": [
          "bulla/spec/action-receipt-v0.4-draft.md"
        ],
        "external_replays": 0
      },
      {
        "id": "strict-receipt-ingestion",
        "label": "Strict receipt ingestion",
        "maturity": "released-draft",
        "availability": "PYPI_RELEASED",
        "established": "A single byte-oriented parser rejects duplicate members, non-finite values, off-schema closed objects, and declared size, depth, node, and string limits before cryptographic verification.",
        "not_established": "Independent hostile-input review or immunity to every parser implementation defect.",
        "evidence_class": "published in Bulla 0.44.4 with internal adversarial fixtures",
        "evidence_provenance": {
          "author_origin": "TEAM_AUTHORED",
          "adjudication_origin": "MACHINE_CHECKED",
          "replay_mode": "INTERNAL_REPRODUCIBLE",
          "closure_warrant": "NOT_APPLICABLE"
        },
        "canonical_refs": [
          "bulla/src/bulla/receipt_parser.py",
          "bulla/tests/test_action_receipt_v04.py",
          "bulla/releases/0.44.4.json"
        ],
        "external_counts": {
          "authors": 0,
          "adjudicators": 0,
          "implementations": 0,
          "witnesses": 0
        },
        "supersession_refs": [],
        "correction_refs": [],
        "external_replays": 0
      },
      {
        "id": "action-receipt-v04",
        "label": "ActionReceipt v0.4 occurrence binding",
        "maturity": "released-draft",
        "availability": "PYPI_RELEASED",
        "established": "The draft separately authenticates content, one claimed occurrence, and its authority envelope under a portable integer-only canonical data model; Python and Node reference checkers agree on the fixed vector.",
        "not_established": "Worldly occurrence, witnessed time, cross-platform independent parity, or promotion over the normative v0.2 default.",
        "evidence_class": "opt-in draft published in Bulla 0.44.4 with internal cross-language reference checks",
        "evidence_provenance": {
          "author_origin": "TEAM_AUTHORED",
          "adjudication_origin": "MACHINE_CHECKED",
          "replay_mode": "INTERNAL_REPRODUCIBLE",
          "closure_warrant": "NOT_APPLICABLE"
        },
        "canonical_refs": [
          "bulla/spec/action-receipt-v0.4-draft.md",
          "bulla/spec/vectors/v04-occurrence-bound.json",
          "bulla/releases/0.44.4.json"
        ],
        "external_counts": {
          "authors": 0,
          "adjudicators": 0,
          "implementations": 0,
          "witnesses": 0
        },
        "supersession_refs": [],
        "correction_refs": [],
        "external_replays": 0
      },
      {
        "id": "semantic-invention",
        "label": "Semantic invention",
        "maturity": "experimental",
        "availability": "PYPI_RELEASED",
        "established": "Finite FRSL-1 packages and negative certificates are independently replayable on the captive Golden corpus.",
        "not_established": "Foreign generality, open-world completeness, or a stable semantic API.",
        "evidence_class": "internal captive benchmark",
        "evidence_provenance": {
          "author_origin": "TEAM_AUTHORED",
          "adjudication_origin": "MACHINE_PLANTED",
          "replay_mode": "INTERNAL_REPRODUCIBLE",
          "closure_warrant": "FINITE_EXACT"
        },
        "canonical_refs": [
          "bulla/spec/semantic-boundary-v0.3-experimental.md",
          "bulla/bench/golden/v0.3/manifest.json"
        ],
        "external_counts": {
          "authors": 0,
          "adjudicators": 0,
          "implementations": 0,
          "witnesses": 0
        },
        "supersession_refs": [],
        "correction_refs": [],
        "external_replays": 0
      },
      {
        "id": "partial-envelopes",
        "label": "Partial envelopes",
        "maturity": "experimental",
        "availability": "PYPI_RELEASED",
        "established": "Checked RELY and REFUSE regions preserve residual escalation under a declared finite closure warrant.",
        "not_established": "Completeness outside the declared model class or safety under an unmodeled closure expansion.",
        "evidence_class": "internal formal and executable evidence",
        "evidence_provenance": {
          "author_origin": "TEAM_AUTHORED",
          "adjudication_origin": "MACHINE_CHECKED",
          "replay_mode": "INTERNAL_REPRODUCIBLE",
          "closure_warrant": "FINITE_EXACT"
        },
        "canonical_refs": [
          "bulla/bench/golden/v0.3/PROFILE.md",
          "papers/interpolant-envelope/lean/InterpolantEnvelope/GoldenV02.lean"
        ],
        "external_counts": {
          "authors": 0,
          "adjudicators": 0,
          "implementations": 0,
          "witnesses": 0
        },
        "supersession_refs": [],
        "correction_refs": [],
        "external_replays": 0
      },
      {
        "id": "semantic-finality",
        "label": "Semantic Finality",
        "maturity": "experimental",
        "availability": "PYPI_RELEASED",
        "established": "Replayable provisional, reserve, conflict, refinement, finalization, and stale-epoch transitions in a finite shadow model.",
        "not_established": "Production settlement, real custody, collectibility, actuarial value, or institutional efficacy.",
        "evidence_class": "internal state-machine and Golden evidence",
        "evidence_provenance": {
          "author_origin": "TEAM_AUTHORED",
          "adjudication_origin": "MACHINE_PLANTED",
          "replay_mode": "INTERNAL_REPRODUCIBLE",
          "closure_warrant": "BOUNDED_EXACT"
        },
        "canonical_refs": [
          "bulla/src/bulla/experimental/semantic_finality.py",
          "bulla/bench/golden/v0.1/manifest.json"
        ],
        "external_counts": {
          "authors": 0,
          "adjudicators": 0,
          "implementations": 0,
          "witnesses": 0
        },
        "supersession_refs": [],
        "correction_refs": [
          "bulla/bench/golden/v0.2/STATUS.md"
        ],
        "external_replays": 0
      },
      {
        "id": "claim-flow-v04",
        "label": "Claim Flow v0.4",
        "maturity": "experimental",
        "availability": "PYPI_RELEASED",
        "established": "Typed appraisal, forum, precedent, applicability, and settlement transitions with explicit authority provenance.",
        "not_established": "External legal validity, foreign applicability judgments, or automatic institutional authority.",
        "evidence_class": "internal formal and captive benchmark evidence",
        "evidence_provenance": {
          "author_origin": "TEAM_AUTHORED",
          "adjudication_origin": "MACHINE_PLANTED",
          "replay_mode": "INTERNAL_REPRODUCIBLE",
          "closure_warrant": "BOUNDED_EXACT"
        },
        "canonical_refs": [
          "bulla/spec/claim-flow-v0.4-experimental.md",
          "bulla/src/bulla/experimental/claim_flow.py"
        ],
        "external_counts": {
          "authors": 0,
          "adjudicators": 0,
          "implementations": 0,
          "witnesses": 0
        },
        "supersession_refs": [],
        "correction_refs": [],
        "external_replays": 0
      },
      {
        "id": "generalization-v05",
        "label": "Generalization Constitution v0.5",
        "maturity": "experimental",
        "availability": "SOURCE_ONLY",
        "established": "Candidate, adoption, and applicability remain separate, with checked finite safe-scope frontiers and effect-laundering controls.",
        "not_established": "Foreign transfer, external applicability judgments, or a stable precedent API.",
        "evidence_class": "internal formal and captive-control evidence",
        "evidence_provenance": {
          "author_origin": "TEAM_AUTHORED",
          "adjudication_origin": "MACHINE_PLANTED",
          "replay_mode": "INTERNAL_REPRODUCIBLE",
          "closure_warrant": "BOUNDED_EXACT"
        },
        "canonical_refs": [
          "bulla/spec/generalization-constitution-v0.5-experimental.md",
          "bulla/bench/golden/v0.5/PROFILE.md"
        ],
        "external_counts": {
          "authors": 0,
          "adjudicators": 0,
          "implementations": 0,
          "witnesses": 0
        },
        "supersession_refs": [],
        "correction_refs": [],
        "external_replays": 0
      },
      {
        "id": "golden-gate",
        "label": "Golden Gate qualification",
        "maturity": "experimental",
        "availability": "PYPI_RELEASED",
        "established": "The finite checker core supports typed abstention and reproducible qualification; benchmark packets add captive mutation, portability, custody, and control evidence.",
        "not_established": "Reviewer-originated results, independent validation, production safety, or open-world completeness.",
        "evidence_class": "implemented methods with internal captive evidence",
        "evidence_provenance": {
          "author_origin": "TEAM_AUTHORED",
          "adjudication_origin": "MACHINE_PLANTED",
          "replay_mode": "INTERNAL_REPRODUCIBLE",
          "closure_warrant": "BOUNDED_EXACT"
        },
        "canonical_refs": [
          "bulla/src/bulla/experimental/golden.py",
          "bulla/bench/golden/v0.3/PROFILE.md",
          "papers/golden-gate/paper.md"
        ],
        "external_counts": {
          "authors": 0,
          "adjudicators": 0,
          "implementations": 0,
          "witnesses": 0
        },
        "supersession_refs": [],
        "correction_refs": [],
        "external_replays": 0
      },
      {
        "id": "receipt-coupled-dispatch",
        "label": "Receipt-coupled dispatch",
        "maturity": "experimental",
        "availability": "SOURCE_ONLY",
        "established": "The reference boundary durably commits an authorized intent before external I/O, preserves uncertain outcomes, enforces committed adapter capabilities, and prevents duplicate effects under its captive verified-idempotency contract.",
        "not_established": "Distributed atomicity, production payment safety, external adapter conformance, or nonlocal integration value.",
        "evidence_class": "internal exhaustive model, crash fixtures, and captive adapters",
        "evidence_provenance": {
          "author_origin": "TEAM_AUTHORED",
          "adjudication_origin": "MACHINE_CHECKED",
          "replay_mode": "INTERNAL_REPRODUCIBLE",
          "closure_warrant": "BOUNDED_EXACT"
        },
        "canonical_refs": [
          "bulla/src/bulla/experimental/action_boundary.py",
          "bulla/bench/golden/v0.6/report.json"
        ],
        "external_counts": {
          "authors": 0,
          "adjudicators": 0,
          "implementations": 0,
          "witnesses": 0
        },
        "supersession_refs": [],
        "correction_refs": [],
        "external_replays": 0
      },
      {
        "id": "agent-incident-packet",
        "label": "Agent Incident Packet v0.1",
        "maturity": "experimental",
        "availability": "SOURCE_ONLY",
        "established": "The source profile requires an exact decision/effect anchor pair for each represented protocol and binds each reported denominator snapshot to a signed checkpoint whose issuer is accepted through external role context. Live timeline and publish receipts use ActionReceipt v0.4 with conventions: []; convention-bearing historical receipts remain opaque evidence artifacts only. Team-operated fixtures also bind non-circular redaction records and accepted reviewer statements, party statements, corrections, and witness evidence without collapsing their verification dimensions.",
        "not_established": "A packet supports zero or one witness reference. Multiple-witness aggregation remains unresolved. Cross-runtime convention evaluation, denominator completeness, organizational independence, production containment, disclosure safety, external implementation parity, independent witnessing, and incident truth also remain unestablished. The empty-convention rule narrows this experimental profile and does not change ActionReceipt v0.4. An accepted observer can self-shorten rows.",
        "evidence_class": "team-operated deterministic fixtures and isolated localhost HTTP/MCP pilots",
        "evidence_provenance": {
          "author_origin": "TEAM_AUTHORED",
          "adjudication_origin": "MACHINE_CHECKED",
          "replay_mode": "INTERNAL_REPRODUCIBLE",
          "closure_warrant": "NOT_APPLICABLE"
        },
        "canonical_refs": [
          "bulla/spec/agent-incident-packet/PROFILE.md",
          "bulla/src/bulla/experimental/incident_packet.py",
          "bulla/spec/agent-incident-packet/expected-verdict.json"
        ],
        "external_counts": {
          "authors": 0,
          "adjudicators": 0,
          "implementations": 0,
          "witnesses": 0
        },
        "supersession_refs": [],
        "correction_refs": [],
        "external_replays": 0
      },
      {
        "id": "acceptance-contract-alpha",
        "label": "Acceptance Contract alpha",
        "maturity": "experimental",
        "availability": "SOURCE_ONLY",
        "established": "Three synthetic deployment-handoff bundles retain one staging claim under one precommitted receiver policy. Missing rollback evidence produces HOLD_FOR_EVIDENCE and a conditional request; an accepted PASS produces PROCEED and ELIGIBLE; an accepted FAIL produces REFUSE. Authorization remains NOT_ISSUED and execution remains NOT_ATTEMPTED in every canonical result.",
        "not_established": "Deployment occurrence, worldly truth, receiver-record completeness, legal enforceability, production use, organizational independence, or external implementation parity.",
        "evidence_class": "three deterministic bundles, project-authored strict evaluator, hostile mutations, distribution-boundary tests, and a finite abstract model",
        "evidence_provenance": {
          "author_origin": "TEAM_AUTHORED",
          "adjudication_origin": "MACHINE_CHECKED",
          "replay_mode": "INTERNAL_REPRODUCIBLE",
          "closure_warrant": "FINITE_EXACT"
        },
        "canonical_refs": [
          "bulla/spec/acceptance-contract/PROFILE.md",
          "bulla/spec/acceptance-contract/generated/site-projection.json",
          "bulla/src/bulla/experimental/acceptance_contract.py"
        ],
        "external_counts": {
          "authors": 0,
          "adjudicators": 0,
          "implementations": 0,
          "witnesses": 0
        },
        "supersession_refs": [],
        "correction_refs": [],
        "external_replays": 0
      },
      {
        "id": "inference-clearing-alpha",
        "label": "Recheckable Inference alpha",
        "maturity": "experimental",
        "availability": "SOURCE_ONLY",
        "established": "Two synthetic providers return byte-identical BACKUP artifacts. After both provider processes terminate, the retained, term-bound integer model reproduces one input-to-output relation while the opaque record supplies no model to rerun. Under the separately supplied buyer policy, the first relation is payment-eligible but not authorized or settled; the opaque response is refused. Adding one unmatched receiver effect leaves receipt integrity verified, changes coverage from 1/1 to 1/2, and makes payment ineligible. Project-authored Python, standalone Node, and browser verifiers reproduce these bounded reports.",
        "not_established": "Historical provider execution, answer truth, model quality, complete receiver denominators, payment execution, external implementation parity, organizational independence, custody, collectibility, production clearing, or worldly truth. All roles and evidence remain synthetic and team-controlled.",
        "evidence_class": "three deterministic bundles, team-operated localhost roles, project-authored Python, standalone Node, and browser parity, transient hostile mutations, and a finite abstract model",
        "evidence_provenance": {
          "author_origin": "TEAM_AUTHORED",
          "adjudication_origin": "MACHINE_CHECKED",
          "replay_mode": "INTERNAL_REPRODUCIBLE",
          "closure_warrant": "FINITE_EXACT"
        },
        "canonical_refs": [
          "bulla/spec/inference-clearing/PROFILE.md",
          "bulla/spec/inference-clearing/expected-verdict.json",
          "bulla/spec/inference-clearing/inference-clearing-reproduction-kit.tar.sha256",
          "bulla/src/bulla/experimental/inference_clearing.py"
        ],
        "external_counts": {
          "authors": 0,
          "adjudicators": 0,
          "implementations": 0,
          "witnesses": 0
        },
        "supersession_refs": [],
        "correction_refs": [],
        "external_replays": 0
      },
      {
        "id": "witness-covenant",
        "label": "Bonded witness covenant",
        "maturity": "experimental",
        "availability": "SOURCE_ONLY",
        "established": "The source profile verifies an objective same-size log-equivocation predicate, challenge chronology, a dedicated fixture-reported allocation, bounded remedy eligibility, exact authorization, and Test-ledger attempt reporting. Adding the reported bond changes capital and recourse only.",
        "not_established": "Witness independence, missing-event detection, provider truth, real custody, collectibility, deterrence, actual recovery, production operation, or a witness market.",
        "evidence_class": "project-authored deterministic fixtures, Python and standalone Node parity, hostile mutations, and finite abstract-model checks",
        "evidence_provenance": {
          "author_origin": "TEAM_AUTHORED",
          "adjudication_origin": "MACHINE_CHECKED",
          "replay_mode": "INTERNAL_REPRODUCIBLE",
          "closure_warrant": "FINITE_EXACT"
        },
        "canonical_refs": [
          "bulla/spec/witness-covenant/PROFILE.md",
          "bulla/spec/witness-covenant/WIRE-FORMAT.md",
          "bulla/spec/witness-covenant/PREREGISTRATION.md",
          "bulla/spec/witness-covenant/reports/fork-authorized.json",
          "bulla/tests/test_witness_covenant.py",
          "papers/interpolant-envelope/lean/InterpolantEnvelope/AssuranceLinker.lean"
        ],
        "external_counts": {
          "authors": 0,
          "adjudicators": 0,
          "implementations": 0,
          "witnesses": 0
        },
        "supersession_refs": [],
        "correction_refs": [
          "bulla/spec/witness-covenant/CORRECTION-001.md"
        ],
        "external_replays": 0
      },
      {
        "id": "answerability-network",
        "label": "Answerability Network",
        "maturity": "experimental",
        "availability": "SOURCE_ONLY",
        "established": "The source profile composes one synthetic inference procurement, a selected ActionReceipt, leaf-bound witnessed history, objective fork handling, bounded recourse, and exact tri-state recall over 10,000 declared decisions. Python, standalone Node, and browser reports agree on six frozen stages.",
        "not_established": "Provider-result truth, complete dependency capture, independent witnessing, real custody, collectibility, dollars moved, production operation, customer activity, or adoption.",
        "evidence_class": "project-authored deterministic corpus, Python/standalone-Node/browser parity, hostile mutations, generated presentation projection, and finite abstract-model checks",
        "evidence_provenance": {
          "author_origin": "TEAM_AUTHORED",
          "adjudication_origin": "MACHINE_CHECKED",
          "replay_mode": "INTERNAL_REPRODUCIBLE",
          "closure_warrant": "FINITE_EXACT"
        },
        "canonical_refs": [
          "bulla/spec/answerability-network/PROFILE.md",
          "bulla/spec/answerability-network/WIRE-FORMAT.md",
          "bulla/spec/answerability-network/PREREGISTRATION.md",
          "bulla/spec/answerability-network/manifest.json",
          "bulla/spec/answerability-network/reports/fork-authorized.json",
          "bulla/src/bulla/experimental/answerability_network.py",
          "bulla/spec/answerability-network/kernel.mjs",
          "bulla/tests/test_answerability_network.py",
          "glyph/scripts/answerability-network.test.ts",
          "glyph/src/workers/answerability-network.worker.ts"
        ],
        "external_counts": {
          "authors": 0,
          "adjudicators": 0,
          "implementations": 0,
          "witnesses": 0
        },
        "supersession_refs": [],
        "correction_refs": [],
        "external_replays": 0
      },
      {
        "id": "assurance-linker-alpha",
        "label": "Assurance Linker alpha",
        "maturity": "experimental",
        "availability": "SOURCE_ONLY",
        "established": "Assurance Linker 0.1 deterministically compiles a closed structured promise into explicit evidence, authority, coverage, capital, recourse, and consequence requirements. The additive source-only 0.2 accountability-circuit profile computes five synthetic USD-cent dossiers: signed receipt and receiver bindings, externally supplied witness roots, leaf-bound inclusion, RFC 6962 history consistency, authenticated causal order and adjacent mismatch checkpoints, exact byte equality or mismatch, a pinned challenge state, declared capital allocations, bounded consequence eligibility, exact authorization, and a signed team-operated fixture-attempt report. Python, standalone Node, and the browser kernel deep-equal on canonical reports and protected hostile outcomes. The formal refinement proves mismatch/conformance exclusion plus witnessed ordering, deadline, and recourse guards. The candidate route commits to the presentation and verification source closure. Existing Bitcoin Core 31.1 regtest evidence remains separate and sat-denominated.",
        "not_established": "The accountability-circuit candidate has no bound anonymous deployment or reader attempts; comprehension remains NOT_COMPUTED. Trial 0.2-r5 also has no cold-reader calibration, candidate round, or foreign checker attempt. Foreign authorability, independent checker reproduction, external institutional handling, operational separation, marginal decision value, economic adoptability, representative demand, worldly truth, complete observation, external collateral encumbrance, custody, collectibility, legal enforceability, organizational independence, production safety, actual settlement, actuarial calibration, or mainnet readiness remain unestablished. The witness and fixture settlement roles are team-operated. The Bitcoin adapter is optional and does not evaluate predicates or replace the named settlement authority.",
        "evidence_class": "team-authored deterministic fixtures, Python/standalone-Node/browser parity, finite abstract-model checks, one prior local Bitcoin Core regtest execution, and team-operated source-only trial and candidate materials",
        "evidence_provenance": {
          "author_origin": "TEAM_AUTHORED",
          "adjudication_origin": "MACHINE_CHECKED",
          "replay_mode": "INTERNAL_REPRODUCIBLE",
          "closure_warrant": "FINITE_EXACT"
        },
        "canonical_refs": [
          "bulla/spec/assurance-linker/PROFILE.md",
          "bulla/spec/assurance-linker/expected-verdict.json",
          "bulla/spec/assurance-linker/accountability-circuit-v0.2/PROFILE.md",
          "bulla/spec/assurance-linker/accountability-circuit-v0.2/expected-verdicts.json",
          "bulla/spec/assurance-linker/accountability-circuit-v0.2/manifest.json",
          "glyph/reviews/2026-08-17-accountability-circuit/PROTOCOL.md",
          "glyph/src/lib/accountability-circuit.generated.json",
          "bulla/spec/assurance-linker/formal-fixture-map.json",
          "bulla/spec/assurance-linker/trial-v0.2/results.json",
          "bulla/spec/assurance-linker/trial-v0.2/freeze.json",
          "bulla/spec/assurance-linker/stranger-doorway-v0.2-r5/readiness.json",
          "bulla/spec/assurance-linker/stranger-doorway-v0.2-r5/correction.json",
          "bulla/spec/assurance-linker/stranger-doorway-v0.2-r5/scoring-capsule-freeze.json",
          "bulla/spec/assurance-linker/stranger-doorway-v0.2-r5/prior-revisions-preservation.json",
          "bulla/spec/assurance-linker/stranger-doorway-v0.2-r5/semantic-root.json",
          "bulla/spec/assurance-linker/stranger-doorway-v0.2-r5/ceremony-root.json",
          "bulla/spec/assurance-linker/stranger-doorway-v0.2-r5/trial-envelope.json",
          "bulla/spec/assurance-linker/stranger-doorway-v0.2-r5/corpus-reuse.json",
          "bulla/spec/assurance-linker/stranger-doorway-v0.2-r5/publication-identity.json",
          "papers/interpolant-envelope/lean/InterpolantEnvelope/AssuranceLinker.lean"
        ],
        "external_counts": {
          "authors": 0,
          "adjudicators": 0,
          "implementations": 0,
          "witnesses": 0
        },
        "supersession_refs": [
          "bulla/spec/assurance-linker/stranger-doorway-v0.2-r5/correction.json"
        ],
        "correction_refs": [
          "bulla/spec/assurance-linker/stranger-doorway-v0.2-r5/correction.json"
        ],
        "external_replays": 0
      },
      {
        "id": "executable-recourse",
        "label": "Executable recourse",
        "maturity": "experimental",
        "availability": "SOURCE_ONLY",
        "established": "A local receipt trace can open, acknowledge, evidence, decide, authorize, complete, route, expire, and close a challenge while keeping forum and remedy authority distinct.",
        "not_established": "A separately controlled forum, operational reachability, institutional efficacy, or automatic enforcement of a semantic finding.",
        "evidence_class": "internal replay and authority-separation fixtures; reachability captive",
        "evidence_provenance": {
          "author_origin": "TEAM_AUTHORED",
          "adjudication_origin": "MACHINE_CHECKED",
          "replay_mode": "INTERNAL_REPRODUCIBLE",
          "closure_warrant": "BOUNDED_EXACT"
        },
        "canonical_refs": [
          "bulla/src/bulla/experimental/challenge.py",
          "bulla/tests/test_executable_challenge.py"
        ],
        "external_counts": {
          "authors": 0,
          "adjudicators": 0,
          "implementations": 0,
          "witnesses": 0
        },
        "supersession_refs": [],
        "correction_refs": [],
        "external_replays": 0
      },
      {
        "id": "precedent-compounding",
        "label": "Precedent compounding",
        "maturity": "research",
        "availability": "RESEARCH_ONLY",
        "established": "Compounding was observed in a team-authored, machine-planted, bounded-exact lineage benchmark and survives the declared captive controls.",
        "not_established": "Generalized compounding on foreign meanings, independent adjudication, or economic value.",
        "evidence_class": "internal captive observation",
        "evidence_provenance": {
          "author_origin": "TEAM_AUTHORED",
          "adjudication_origin": "MACHINE_PLANTED",
          "replay_mode": "INTERNAL",
          "closure_warrant": "BOUNDED_EXACT"
        },
        "canonical_refs": [
          "bulla/bench/golden/v0.4/interpretation.json",
          "bulla/bench/golden/v0.5/report.json"
        ],
        "external_counts": {
          "authors": 0,
          "adjudicators": 0,
          "implementations": 0,
          "witnesses": 0
        },
        "supersession_refs": [
          "bulla/bench/golden/v0.5/PROFILE.md"
        ],
        "correction_refs": [
          "bulla/bench/golden/v0.4/INTERPRETATION.md"
        ],
        "external_replays": 0
      },
      {
        "id": "control-plane-alpha",
        "label": "Public control-plane alpha candidate",
        "maturity": "experimental",
        "availability": "SOURCE_ONLY",
        "established": "Deterministic fixtures, source checkers, and local Cloudflare-runtime tests exercise one closed synthetic MCP authorization, receiver, denominator, witness, coverage, and packet-publication loop.",
        "not_established": "The generated control-plane evidence ledger reports whether a public endpoint has tracked deployment evidence. Customer authority, denominator completeness, organizational independence, production safety, and incident truth remain unestablished.",
        "evidence_class": "team-authored deterministic fixtures and local Cloudflare-runtime tests",
        "evidence_provenance": {
          "author_origin": "TEAM_AUTHORED",
          "adjudication_origin": "MACHINE_CHECKED",
          "replay_mode": "INTERNAL_REPRODUCIBLE",
          "closure_warrant": "BOUNDED_EXACT"
        },
        "canonical_refs": [
          "bulla/spec/control-plane-alpha/PROFILE.md",
          "bulla/spec/control-plane-alpha/expected-verdict.json",
          "packages/bulla-control-plane-alpha/README.md"
        ],
        "external_counts": {
          "authors": 0,
          "adjudicators": 0,
          "implementations": 0,
          "witnesses": 0
        },
        "supersession_refs": [],
        "correction_refs": [],
        "external_replays": 0
      },
      {
        "id": "witness-plurality",
        "label": "Witness plurality",
        "maturity": "blocked",
        "availability": "BLOCKED",
        "established": "A local checkpoint and inclusion-proof primitive is specified and tested.",
        "not_established": "Independent witness operators, plurality, stake, or a production witness network.",
        "evidence_class": "local fixture only",
        "evidence_provenance": {
          "author_origin": "TEAM_AUTHORED",
          "adjudication_origin": "MACHINE_CHECKED",
          "replay_mode": "INTERNAL",
          "closure_warrant": "NOT_APPLICABLE"
        },
        "canonical_refs": [
          "bulla/src/bulla/experimental/checkpoint.py",
          "glyph/data/operator-state.json"
        ],
        "external_counts": {
          "authors": 0,
          "adjudicators": 0,
          "implementations": 0,
          "witnesses": 0
        },
        "supersession_refs": [],
        "correction_refs": [],
        "external_replays": 0
      },
      {
        "id": "risk-insurance",
        "label": "Risk and insurance",
        "maturity": "research",
        "availability": "RESEARCH_ONLY",
        "established": "The program contains mathematical ambiguity-reserve and worst-case exposure mechanisms under declared finite models.",
        "not_established": "Underwriter validation, actuarial calibration, product pricing, or real collateral custody.",
        "evidence_class": "internal research architecture",
        "evidence_provenance": {
          "author_origin": "TEAM_AUTHORED",
          "adjudication_origin": "NOT_ADJUDICATED",
          "replay_mode": "INTERNAL",
          "closure_warrant": "BOUNDED_EXACT"
        },
        "canonical_refs": [
          "bulla/src/bulla/experimental/semantic_finality.py",
          "papers/research-status.yaml"
        ],
        "external_counts": {
          "authors": 0,
          "adjudicators": 0,
          "implementations": 0,
          "witnesses": 0
        },
        "supersession_refs": [],
        "correction_refs": [],
        "external_replays": 0
      }
    ],
    "evidence_contract_ref": "glyph/data/evidence-contract.json"
  },
  "evidence_contract": {
    "schema_version": 1,
    "as_of": "2026-08-22",
    "authority": "Normative definitions for the external counters on the status registry. A counter may change only together with evidence that satisfies the definition here. The prose companion is bulla/docs/EVIDENCE-CONTRACT.md; if they disagree, this file governs.",
    "counters": {
      "authors": {
        "label": "External authors",
        "increments_when": "A person or organization outside the team authors previously unseen cases, seams, or interpretations that the system is then evaluated against.",
        "requires": [
          "authored material was not visible to the team before freezing the evaluation",
          "authorship is attributable and disclosed",
          "team assistance limited to format documentation and intake mechanics"
        ],
        "does_not_count": [
          "team-authored cases with external review",
          "synthetic identities or agents operated by the team",
          "cases derived from team-supplied templates with cosmetic changes"
        ]
      },
      "adjudicators": {
        "label": "External adjudicators",
        "increments_when": "A person outside the team decides contested semantic or conformance cases whose outcomes were not known to the team in advance.",
        "requires": [
          "adjudicator is organizationally separate from the team",
          "blind to team-preferred outcomes where the protocol requires blindness",
          "decisions recorded and retained verbatim, including disagreements"
        ],
        "does_not_count": [
          "machine oracles authored by the team",
          "advisory review of team-decided outcomes"
        ]
      },
      "implementations": {
        "label": "Independent implementations",
        "increments_when": "An outside party implements the normative format from the specification, without importing Bulla or adapting team-authored verifier code, and passes the public vectors plus previously unseen adversarial vectors.",
        "requires": [
          "no Bulla imports and no adaptation of team-authored checker source",
          "implementation and build instructions published",
          "byte-identical hashes and equivalent rejection behavior on the vector suite",
          "contact with the team during development documented"
        ],
        "does_not_count": [
          "running a supplied checker on supplied artifacts (see external_replays)",
          "ports produced with team pairing or code review beyond specification clarification"
        ]
      },
      "witnesses": {
        "label": "Independent witnesses",
        "shorthand": "W",
        "increments_when": "A merged QUALIFY event records one service under a unique outside organizational control domain that completed the published witness exercise: it verified and retained the exact release ActionReceipts, proved inclusion under signed checkpoints, and proved an append-only checkpoint extension.",
        "requires": [
          "separate control domain: distinct legal control, key custody, and operational authority",
          "verified intake, inclusion proofs, consistency proofs, and signed checkpoints",
          "a stable public endpoint during the qualification probe",
          "published retention and privacy policy",
          "an attributable repository review of the operator's relationship with Glyph"
        ],
        "does_not_count": [
          "team-controlled instances on separate infrastructure (fault-domain diversity is not independence)",
          "read-only mirrors of a team-operated log",
          "multiple keys or logs under a control domain already represented in W",
          "a cryptographically valid candidate with no merged QUALIFY event"
        ],
        "establishes": "One separately controlled witness operation retained and proved inclusion of the submitted public release records under the published exercise.",
        "does_not_establish": "Receipt truth, occurrence, present availability, policy compliance, production fitness, bond value, recourse, or a witness market. Outside control is an attributable institutional determination, not a cryptographic fact."
      },
      "external_reliance_decisions": {
        "label": "External reliance decisions",
        "shorthand": "D",
        "increments_when": "A dedicated evidence-intake authority signs a QUALIFY event for a closed candidate package containing an authenticated provider receipt, receiver-signed bulla.rely receipt, and receiver-signed boundary receipt; the decision recomputes under the bound runtime and policy, and the signed ledger head includes the event.",
        "requires": [
          "the receiver-signed boundary receipt binds the record, relied-on and reliance attestations, policy, decision, receiving system, exact boundary action and reference, and actor-reported time",
          "provider and receiver organization-key attestations bind distinct signing methods and control domains to hash-bound review evidence",
          "a dedicated intake signer accepted outside the submitted packet records separate REVIEWED_OUTSIDE_GLYPH_CONTROL findings; this is an attributable institutional determination, not cryptographic proof of organizational identity",
          "the relied-on ActionReceipt, receiver-signed bulla.rely ActionReceipt, boundary receipt, organization attestations, control evidence, and runtime replay report are retained byte-for-byte in a closed package",
          "verify_reliance returns ok and the claimed decision equals the recomputed decision under the exact named policy",
          "the exact Bulla version, policy hash, checker digest, and published wheel digest are bound into the qualification",
          "a signed ledger head includes the hash-chained qualification event; returning verifiers can supply a retained prior head to detect rollback or divergence"
        ],
        "does_not_require": [
          "observing whether the receiver later paid, deployed, granted control, or completed a handoff"
        ],
        "does_not_count": [
          "team-authored fixtures, browser demonstrations, or supplied-checker replays",
          "an unsigned policy decision or a bulla.rely receipt that does not recompute",
          "a decision with no receiver-signed boundary record",
          "a candidate whose external-control status is self-declared or carried only inside the submitted packet",
          "a submission from an organization under project control"
        ],
        "establishes": "A named intake reviewer accepted one receiver-signed, locally reproducible policy decision and boundary record under the published external-control review rule.",
        "does_not_establish": "Organizational identity as a worldly fact, that the named policy was sound or appropriate, that the provider claim was true, that the receiver acted on the decision, or that any worldly effect occurred."
      },
      "external_replays": {
        "label": "External replays",
        "auxiliary": true,
        "never_increments": [
          "implementations",
          "external_reliance_decisions"
        ],
        "increments_when": "A person outside the team runs a supplied checker on supplied artifacts and reports the result.",
        "establishes": "An external person reproduced the team's supplied procedure on the team's supplied artifacts.",
        "does_not_establish": "An independent implementation, an external author, or any adjudication."
      }
    },
    "ladder": [
      {
        "evidence": "Outsider runs supplied checker on supplied artifacts",
        "counts_as": "external_replays"
      },
      {
        "evidence": "Dedicated intake authority qualifies a receiver-signed reliance and boundary package under a signed ledger head",
        "counts_as": "external_reliance_decisions"
      },
      {
        "evidence": "Outsider writes a second checker from the specification",
        "counts_as": "implementations"
      },
      {
        "evidence": "Outsider authors previously unseen cases",
        "counts_as": "authors"
      },
      {
        "evidence": "Outsider decides contested semantic cases",
        "counts_as": "adjudicators"
      },
      {
        "evidence": "Separately controlled service retains receipts",
        "counts_as": "witnesses"
      }
    ],
    "disclosure": {
      "paid_work": "Paid external participation may count, with the engagement and payment disclosed alongside the evidence.",
      "team_assistance": "Specification clarification and intake mechanics are permitted. Shared code, pairing, debugging of the external artifact, or outcome discussion before freeze disqualify the counter increment."
    },
    "temporal_labels": {
      "claimed_at": "Supplied by the actor. Not bound into the signed occurrence identity under wire v0.2/v0.3; see action-receipt v0.4 draft.",
      "received_at": "Observed by a witness at intake.",
      "witnessed_at": "Included in a signed witness checkpoint.",
      "anchored_before": "Externally timestamped upper bound (for example OpenTimestamps confirmation)."
    },
    "release_coverage": {
      "release_receipt_required_since": "0.44.0",
      "contemporaneous": "producer.minted == post-publication, minted by the release workflow after PyPI acceptance",
      "reconstructed": "retroactively assembled from surviving artifacts; never reclassified as contemporaneous",
      "policy": "Historical unreceipted releases remain missing. The enforcement epoch is immutable."
    }
  },
  "external_reliance_decisions": {
    "profile": "glyph.external-reliance-decision-ledger/0.1",
    "schema_version": 1,
    "as_of": "2026-08-23",
    "counter": "external_reliance_decisions",
    "gate": "VERIFIED_DECISION_NOT_OBSERVED_EFFECT",
    "intake_status": "ACTIVE",
    "qualified_count": 0,
    "historical_qualifications": 0,
    "events": [],
    "heads": []
  },
  "external_reliance_intake_context": {
    "profile": "glyph.external-reliance-intake-context/0.1",
    "status": "ACTIVE",
    "accepted_intake_methods": [
      "did:key:z6Mkv8R9kYth8QGmHfLVUhhtJAxweFD1bY8vHrip5WzBuHCT"
    ],
    "trust_source": "Glyph Standard repository publication and its designated owner-dispatched issuance process linked to a public Bulla issue and candidate root",
    "limitation": "GitHub's current repository plan does not provide a native required environment reviewer. The owner workflow and public labels are the published issuance policy, not a cryptographic restriction on offline key use. A count changes only after a reviewable repository PR merges. At D0 no intake event or head exists, so no append-only or independent-review claim is made."
  },
  "external_reliance_intake_key": {
    "profile": "glyph.external-reliance-intake-key/0.1",
    "verification_method": "did:key:z6Mkv8R9kYth8QGmHfLVUhhtJAxweFD1bY8vHrip5WzBuHCT",
    "algorithm": "Ed25519",
    "purpose": "external-reliance intake tests, qualification events, and ledger heads",
    "status": "ACTIVE",
    "created_at": "2026-08-23",
    "release_key_reused": false,
    "manual_approval_mode": "OWNER_WORKFLOW_DISPATCH_AND_APPROVED_PUBLIC_ISSUE",
    "native_environment_reviewers": false,
    "recovery_copy": "OFFLINE_ENCRYPTED",
    "limitation": "Glyph Standard designates this key for intake events issued through the owner-dispatched workflow and publishes a count only after the resulting repository PR merges. The offline recovery key can produce signatures outside that workflow; such a signature does not by itself establish that the issuance policy or external-control review occurred."
  },
  "external_reliance_intake_test_result": {
    "approval": "TEST sha256:0899a0e3313fd7a07fc5fd8a562da4578f64e6a876da5f1193d944f983fa476c",
    "authority_authentic": "verified",
    "candidate_root": "sha256:0899a0e3313fd7a07fc5fd8a562da4578f64e6a876da5f1193d944f983fa476c",
    "candidate_url": "https://gist.githubusercontent.com/jkomkov/43dd07587c75e4e8e5d20de6ac29f35b/raw/4323d5f6878ae236f1ae775ebb08fbdc45ead192/package.json",
    "counter_status": "NOT_COUNTED",
    "intake_method": "did:key:z6Mkv8R9kYth8QGmHfLVUhhtJAxweFD1bY8vHrip5WzBuHCT",
    "issued_at": "2026-08-23T20:29:41Z",
    "profile": "glyph.external-reliance-intake-test-result/1",
    "public_issue": "https://github.com/jkomkov/bulla/issues/50",
    "qualified_count_after": 0,
    "qualified_count_before": 0,
    "test_attestation": "sha256:cd9660db706adf8d767432fc8192be0a8ae1d0bd7639eca8c0bca6edad6cfab2",
    "test_receipt": {
      "action": {
        "subject": {
          "approval": "TEST sha256:0899a0e3313fd7a07fc5fd8a562da4578f64e6a876da5f1193d944f983fa476c",
          "candidate_root": "sha256:0899a0e3313fd7a07fc5fd8a562da4578f64e6a876da5f1193d944f983fa476c",
          "candidate_url": "https://gist.githubusercontent.com/jkomkov/43dd07587c75e4e8e5d20de6ac29f35b/raw/4323d5f6878ae236f1ae775ebb08fbdc45ead192/package.json",
          "counter_status": "NOT_COUNTED",
          "intake_method": "did:key:z6Mkv8R9kYth8QGmHfLVUhhtJAxweFD1bY8vHrip5WzBuHCT",
          "issued_at": "2026-08-23T20:29:41Z",
          "public_issue": "https://github.com/jkomkov/bulla/issues/50",
          "qualified_count_after": 0,
          "qualified_count_before": 0,
          "workflow_head": "b0b8d809ec65d59f61fe23b861b8bef8710ed504",
          "workflow_run": "https://github.com/jkomkov/res-agentica/actions/runs/32664553129"
        },
        "type": "glyph.external-reliance.intake-test"
      },
      "anchor_ref": {},
      "authorization": {
        "issuer": "did:key:z6Mkv8R9kYth8QGmHfLVUhhtJAxweFD1bY8vHrip5WzBuHCT",
        "proofValue": "WbwxNIWwpvkMSxp1rVMVAz2o8zI0b3X+ETHHTPujpL23yXNLZHeCvkVCRUJAlgBGbAs9nPFnS5dpfdn1hzeFAg==",
        "purpose": "authorization",
        "type": "bulla/ed25519-2026",
        "verificationMethod": "did:key:z6Mkv8R9kYth8QGmHfLVUhhtJAxweFD1bY8vHrip5WzBuHCT"
      },
      "conventions": [],
      "diagnostic_ref": {
        "ref": "sha256:461abf799527ae755bb7c82e8e5ce12d58f29b8ea6174ada084123a2392cd0e1",
        "status": "reference"
      },
      "evidence_refs": [],
      "hashes": {
        "attestation": "sha256:cd9660db706adf8d767432fc8192be0a8ae1d0bd7639eca8c0bca6edad6cfab2",
        "content": "sha256:0d4e14014770bb614d69fe3318b1c57e8416d90240fa7119643826668a4fe2e9",
        "event": "sha256:00d4cf3f60511dbe59e6861da51e2d9f1810df7b6f8566786d9e965a118cafca",
        "log_leaf": "sha256:d42f57df1265d03dc4a454e4323fd84493e711b4bbf04536c27f1d7a246a975f"
      },
      "kind": "action_receipt",
      "mandate": {
        "authority": {
          "delegation": [],
          "policy": "policy://glyph/external-reliance-intake",
          "principal": "did:key:z6Mkv8R9kYth8QGmHfLVUhhtJAxweFD1bY8vHrip5WzBuHCT"
        }
      },
      "producer": {},
      "remedy": {},
      "retention": {},
      "schema_version": "0.3",
      "signature": {
        "issuer": "did:key:z6Mkv8R9kYth8QGmHfLVUhhtJAxweFD1bY8vHrip5WzBuHCT",
        "proofValue": "L5AAU5fOMIxYh9Vw2r37uk9EpQjbcxDUdDbHLBSRqMum5XaiGWBgfBQpNCWemYCm2ToTdTiz5YR0ePlrmPYvDw==",
        "purpose": "content",
        "type": "bulla/ed25519-2026",
        "verificationMethod": "did:key:z6Mkv8R9kYth8QGmHfLVUhhtJAxweFD1bY8vHrip5WzBuHCT"
      },
      "stake": null,
      "timestamp": "2026-08-23T20:29:41Z"
    },
    "verified_to": "attestation",
    "workflow_head": "b0b8d809ec65d59f61fe23b861b8bef8710ed504",
    "workflow_run": "https://github.com/jkomkov/res-agentica/actions/runs/32664553129"
  },
  "independent_witnesses": {
    "as_of": "2026-08-24T17:04:00Z",
    "counter": "witnesses",
    "events": [],
    "historical_qualifications": 0,
    "intake_status": "ACTIVE",
    "ledger_root": "sha256:a1cb7680e94b1d309aa9bc782868e2449ec9b9ca57df23972434dacf817704e5",
    "profile": "glyph.independent-witness-ledger/2",
    "qualified_count": 0,
    "schema_version": 2
  },
  "independent_witness_intake_test_result": {
    "boundary": "Valid candidate mechanics do not establish outside organizational control.",
    "candidate_for": "independent_witnesses",
    "candidate_root": "sha256:d546d010fbde7151f7f56c375ea6244cfa04dbfd4a89c1935f50da2f939a2f5d",
    "candidate_status": "VALID_CANDIDATE",
    "counter_status": "NOT_COUNTED",
    "kit_root": "sha256:0e53371bf646c574fd32575d33c92d44e32c3041b4030051ae1edfbbec811c37",
    "log_id": "glyph-project-controlled:witness-intake-test",
    "never_counts_toward": [
      "independent_implementations",
      "external_reliance_decisions",
      "external_replays"
    ],
    "operator_did": "did:key:z6Mkqysosbx3CQr7xzXgAKDXLMy2TU9rBCgwNQn3xj7hVXsE",
    "profile": "glyph.independent-witness-intake-test-result/1",
    "project_controlled": true,
    "qualified_count_after": 0,
    "qualified_count_before": 0,
    "source_kit_root": "sha256:060051b128c139338aacc6bee12f8597700e2f7644b98cf7688bcc3ef7d35fff"
  }
}
