Corobate
A NIST-regulated enterprise · seven sealed decisions · six scoped copies each

Corobate inside a NIST-regulated enterprise

A federal-facing enterprise is a hard case for a provenance gate for a specific reason: it is simultaneously the party being assessed and the party doing the assessing. NIST controls are written as obligations on an organisation — "the organization employs", "the organization documents" — and the naive encoding turns each one into a checkbox an employee ticks. That produces exactly the compliance theatre the catalogues exist to prevent: a self-attested control is a seller assertion about oneself, and a programme built entirely of them has no independent evidence in it anywhere.

The seven decisions below are chosen to expose that rather than hide it. Each one is real: the engine ran, a receipt was sealed, and the six scoped copies were derived and checked against the digest the receipt committed to before this page was written. The instruments are NIST publications, encoded by control identifier, edition and document digest.

The pair worth reading first. Tabs three and four are the same AI system, minutes apart. On its own evaluation it reports F1 0.94 and is REFUSED. With an external red team reporting 0.89 it is APPROVED. The lower number satisfies the requirement the higher one did not, because the requirement was never about the number — it was about who was in a position to produce it.

Machine-generated evidence: the option to admit it, or refuse it

Every organisation running models inside a control programme is now answering a question no catalogue answers for them: may a model's own output carry a control? The three tabs at the end are the same system, the same 412 scanner findings and the same exposure, differing only in where the enterprise stands on that question.

It is a separate axis from provenance class, and the separation is the whole point. The class table already caps anything signed as a model at MODELED — but MODELED is a bucket holding two very different things: an unclassified telemetry feed, and a language model's account of work it did itself. An officer who tries to express "no model output behind this control" as a class floor of VERIFIED writes an AI policy that also silently bans thermometers. So the position is stated on its own axis, by an authority, with a citation, and it composes with every other instrument in force by the same rule everything else does: the strictest wins, and the authority that asked for less is recorded rather than dropped.

Four positions, and the fourth is the one that matters. ADMIT lets model output carry the control, capped at MODELED as it always was. CORROBORATION_ONLY lets a model agree with an analyst but not be the whole of it — the rung most real programmes actually want, and the one a simple on/off switch cannot express. EXCLUDE makes model-authored evidence inadmissible for that control at any score and any exposure. EXCLUDE_TAINTED_LINEAGE additionally refuses a sealed receipt that itself rested on a model — because without it, an exclusion is defeated by one round trip: cite the model, seal a decision, present the decision through a reputable party. The last tab is that exact attempt, made honestly by an accredited laboratory, and refused.
What this does NOT do, stated plainly. It enforces a DECLARED identity. A party enrolled as a model is caught; an organisation that runs a model and signs the output under its own name is not, and no gate logic can reach that, because the gate reads a signed credential rather than a mind. That is an enrolment obligation — whoever admits a party to the registry warrants what kind of party it is — and any product claiming to "detect AI content" at this layer is overstating what a signature can tell you.
And the dial nobody set. Where no instrument in force has taken a position, model output is ADMITTED — and the receipt records that it was a default. It appears in its own block, saying in words that no authority set it and the deploying organisation's own default allowed it. That distinction is the point: in two years, when somebody asks whether your controls admitted machine-generated evidence, "the standard permitted it" and "nobody had considered it yet" are very different answers, and a record that cannot tell them apart is answering neither.

The strong evidence here is independent by construction: a third-party assessment organisation, an accredited laboratory, and a public vulnerability registry. The one weak item is the provider's own statement about its own subservice organisations — which is exactly the item a control questionnaire would have recorded as a tick.

Subject
system:CLOUDVANE-GOV-REGION-3
Question
May this cloud service be brought inside the authorisation boundary?
Exposure
$2,200,000
Instruments
National Institute of Standards and Technology · National Institute of Standards and Technology
Outcome
WITHHELD — the action is not permitted; outstanding: supplier assessment
Receipt
sha256:cc116c0bdb3d3f998c71834f6a365315765375dd99ed77c20c2a9ed4e007625e
The gate variables this decision ran under — a dial per question, read back off the sealed receipt
component provenancerequired
necessity
requiredNational Institute of Standards and Technology — SR-4 provenance [VERIFY]
staleness
90 daysNo instrument set an age limit for this claim, so the deploying organisation's own freshness policy binds at 90 days. It is not unlimited.
reputation class
seller-assertedNational Institute of Standards and Technology — SR-4 [VERIFY]
reputation record
No reliability floor beyond the exposure tier's own threshold, which still binds.
completion
No satisfaction window was set. The requirement is due now: there is no period in which it may be outstanding, and nothing proceeds without it.
ai provenance
admitNo instrument in force stated a position on AI-authored evidence for "component_provenance". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway.
control assessmentrequired
necessity
requiredNational Institute of Standards and Technology — CA-2 [VERIFY]
staleness
365 daysNational Institute of Standards and Technology — CA-2 [VERIFY]
reputation class
verifiedNational Institute of Standards and Technology — CA-2(1) independent assessors [VERIFY]
reputation record
No reliability floor beyond the exposure tier's own threshold, which still binds.
completion
No satisfaction window was set. The requirement is due now: there is no period in which it may be outstanding, and nothing proceeds without it.
ai provenance
admitNo instrument in force stated a position on AI-authored evidence for "control_assessment". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway.
penetration testrequired
necessity
requiredNational Institute of Standards and Technology — CA-8 [VERIFY]
staleness
90 daysNo instrument set an age limit for this claim, so the deploying organisation's own freshness policy binds at 90 days. It is not unlimited.
reputation class
verifiedNational Institute of Standards and Technology — CA-8(1) independent penetration agent [VERIFY]
reputation record
No reliability floor beyond the exposure tier's own threshold, which still binds.
completion
No satisfaction window was set. The requirement is due now: there is no period in which it may be outstanding, and nothing proceeds without it.
ai provenance
admitNo instrument in force stated a position on AI-authored evidence for "penetration_test". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway.
supplier assessmentrequired
necessity
requiredNational Institute of Standards and Technology — SR-6 [VERIFY]
staleness
90 daysNo instrument set an age limit for this claim, so the deploying organisation's own freshness policy binds at 90 days. It is not unlimited.
reputation class
No class floor was set, so the seller's own assertion is admissible for this claim up to the ceiling that class carries. That is a setting, not an absence.
reputation record
No reliability floor beyond the exposure tier's own threshold, which still binds.
completion
No satisfaction window was set. The requirement is due now: there is no period in which it may be outstanding, and nothing proceeds without it.
ai provenance
admitNo instrument in force stated a position on AI-authored evidence for "supplier_assessment". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway.
vulnerability scanrequired
necessity
requiredNational Institute of Standards and Technology — RA-5 [VERIFY]
staleness
30 daysNational Institute of Standards and Technology — RA-5(a) [VERIFY]
reputation class
No class floor was set, so the seller's own assertion is admissible for this claim up to the ceiling that class carries. That is a setting, not an absence.
reputation record
No reliability floor beyond the exposure tier's own threshold, which still binds.
completion
No satisfaction window was set. The requirement is due now: there is no period in which it may be outstanding, and nothing proceeds without it.
ai provenance
admitNo instrument in force stated a position on AI-authored evidence for "vulnerability_scan". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway.

Every bar above was re-derived from the regulatory bindings inside this receipt’s hashed body, not from the configuration that produced it. A bar in grey is a setting no instrument made — the deploying organisation’s own default, which still binds and is not an absence. A bar position renders an ordinal on a declared ladder: it is a way to draw a control and to compare two settings on the same axis, and it is not a measurement. The value printed beside each bar is the authoritative one.

Whoever must act now

The engineer with the deployment in their hands, the release manager, the person who must publish or hold.

One instruction and the reason in words. No score, no money, no signatures.

DO NOT PROCEED
system:CLOUDVANE-GOV-REGION-3
Missing or out of date: supplier assessment

Seven or eight fields, and not one of them is a number somebody can argue with. This person is not being asked to re-judge the evidence; somebody already did, and it is on the record.

The scoped copy itself — partial — something outside this role’s remit was removed
FAITHFUL digest sha256:df8b6522881a6c186dbd5d96ae5616fc7204824773c1d8b2c2c1677f935c5152 matches the commitment sealed in the receipt.
{
 "spec": "corobate:role-view:2",
 "role": "OPERATOR",
 "purpose": "Whoever must act on this decision now — release the goods, fund the draw, dispatch the agent, ship the title. Sees one instruction and the reason in plain words, and nothing that could be argued about while somebody waits.",
 "is_a_receipt": false,
 "warning": "This is a SCOPED COPY of a sealed decision, not the decision record itself. It will not verify as a receipt and must not be presented as one. To confirm it is faithful, recompute its `view` digest under the same canonicalisation that produces receipt_hash and compare it with the entry for this role in the source receipt’s `views` block.",
 "derived_from": {
  "receipt_hash": "sha256:cc116c0bdb3d3f998c71834f6a365315765375dd99ed77c20c2a9ed4e007625e",
  "entry_hash": "sha256:d60b7a4f6b95aa315ea2d3ca369db1f2c20a5eea0fd5b641c3e36f23f6e23cff",
  "issued_at": "2026-08-08T16:00:00.000Z"
 },
 "view_digest": "sha256:df8b6522881a6c186dbd5d96ae5616fc7204824773c1d8b2c2c1677f935c5152",
 "withheld": {
  "anything_withheld": true,
  "note": "Facts outside this role’s remit were removed. That something was removed is stated so a partial record is never mistaken for a complete one. How much, and what, is not stated — a count is an inference about the part you are not entitled to see."
 },
 "view": {
  "spec": "urn:ietf:params:corobate:receipt:1",
  "receipt_version": "1.8",
  "issued_at": "2026-08-08T16:00:00.000Z",
  "decision": {
   "id": "ato_CLOUDVANE_R3",
   "subject": "system:CLOUDVANE-GOV-REGION-3"
  },
  "memory": {
   "state_digest": "sha256:01827de72fd2a97521310c759fdc925c1c51ca2f43949aa72b79b19221e6ff88",
   "ledger_head": "sha256:5bbeec39ca2744b408818488f7595e4b119e254325fd84642a3c66c636794c9c",
   "coverage_gaps": [
    "system:CLOUDVANE-GOV-REGION-3|supplier_assessment"
   ]
  },
  "verdict": {
   "value": "WITHHELD"
  },
  "release": {
   "state": "WITHHELD_NO_EVIDENCE"
  }
 }
}

Provider / assessed party

The cloud service provider, the release team, or the party operating the AI system — whoever is being assessed.

Sees which controls were required of them and by which publication and control identifier. Does not see the authorising official’s exposure figure or how any shortfall was priced.

What is outstanding on your file

  • supplier assessment — required by National Institute of Standards and Technology, SR-6 [VERIFY]
ClaimRequiredEvidence classWhoAgeOutcome
vulnerability_scanyesVERIFIED2026-08-02admitted
component_provenanceyesVERIFIED2026-05-10admitted
penetration_testyesVERIFIED2026-03-11admitted
control_assessmentyesVERIFIED2026-04-10admitted
supplier_assessmentnoSELLER-ASSERTED2026-06-29withheld
supplier_assessmentyesMISSING2026-08-08coverage gap

The clause is here because it turns an argument into an errand. What is not here: what the bank had at stake, and whether anyone priced the shortfall.

The scoped copy itself — partial — something outside this role’s remit was removed
FAITHFUL digest sha256:fb3ec1004ea6e7f7012833cd6236f14ead6c7a07897c8d7629f5b248ca77a6fb matches the commitment sealed in the receipt.
{
 "spec": "corobate:role-view:2",
 "role": "SUPPLIER",
 "purpose": "The party whose evidence was judged. Sees every claim the decision required, which fell short, and the clause that required it — and nothing about what the buyer had at stake or how the buyer priced any shortfall. NOTE, because an earlier draft of this sentence was untrue: this projection carries the WHOLE inputs array, so where several parties supplied evidence for one decision, each of them sees all of it. Per-party scoping cannot be expressed by a commitment scheme with one digest per role, and claiming it anyway would be the kind of promise this file exists to stop making.",
 "is_a_receipt": false,
 "warning": "This is a SCOPED COPY of a sealed decision, not the decision record itself. It will not verify as a receipt and must not be presented as one. To confirm it is faithful, recompute its `view` digest under the same canonicalisation that produces receipt_hash and compare it with the entry for this role in the source receipt’s `views` block.",
 "derived_from": {
  "receipt_hash": "sha256:cc116c0bdb3d3f998c71834f6a365315765375dd99ed77c20c2a9ed4e007625e",
  "entry_hash": "sha256:d60b7a4f6b95aa315ea2d3ca369db1f2c20a5eea0fd5b641c3e36f23f6e23cff",
  "issued_at": "2026-08-08T16:00:00.000Z"
 },
 "view_digest": "sha256:fb3ec1004ea6e7f7012833cd6236f14ead6c7a07897c8d7629f5b248ca77a6fb",
 "withheld": {
  "anything_withheld": true,
  "note": "Facts outside this role’s remit were removed. That something was removed is stated so a partial record is never mistaken for a complete one. How much, and what, is not stated — a count is an inference about the part you are not entitled to see."
 },
 "view": {
  "spec": "urn:ietf:params:corobate:receipt:1",
  "receipt_version": "1.8",
  "issued_at": "2026-08-08T16:00:00.000Z",
  "decision": {
   "id": "ato_CLOUDVANE_R3",
   "subject": "system:CLOUDVANE-GOV-REGION-3",
   "question": "May this cloud service be brought inside the authorisation boundary?"
  },
  "memory": {
   "state_digest": "sha256:01827de72fd2a97521310c759fdc925c1c51ca2f43949aa72b79b19221e6ff88",
   "ledger_head": "sha256:5bbeec39ca2744b408818488f7595e4b119e254325fd84642a3c66c636794c9c",
   "coverage_gaps": [
    "system:CLOUDVANE-GOV-REGION-3|supplier_assessment"
   ]
  },
  "verdict": {
   "value": "WITHHELD"
  },
  "inputs": [
   {
    "key": "system:CLOUDVANE-GOV-REGION-3::vulnerability_scan",
    "provenance": "VERIFIED",
    "observed_at": "2026-08-02T16:00:00.000Z",
    "memory_status": "admitted",
    "critical": true
   },
   {
    "key": "system:CLOUDVANE-GOV-REGION-3::component_provenance",
    "provenance": "VERIFIED",
    "observed_at": "2026-05-10T16:00:00.000Z",
    "memory_status": "admitted",
    "critical": true
   },
   {
    "key": "system:CLOUDVANE-GOV-REGION-3::penetration_test",
    "provenance": "VERIFIED",
    "observed_at": "2026-03-11T16:00:00.000Z",
    "memory_status": "admitted",
    "critical": true
   },
   {
    "key": "system:CLOUDVANE-GOV-REGION-3::control_assessment",
    "provenance": "VERIFIED",
    "observed_at": "2026-04-10T16:00:00.000Z",
    "memory_status": "admitted",
    "critical": true
   },
   {
    "key": "system:CLOUDVANE-GOV-REGION-3::supplier_assessment",
    "provenance": "SELLER-ASSERTED",
    "observed_at": "2026-06-29T16:00:00.000Z",
    "memory_status": "withheld",
    "critical": false
   },
   {
    "key": "system:CLOUDVANE-GOV-REGION-3::supplier_assessment",
    "provenance": "MISSING",
    "observed_at": "2026-08-08T16:00:00.000Z",
    "memory_status": "coverage_gap",
    "critical": true
   }
  ],
  "regulatory": {
   "bindings": [
    {
     "claim": "component_provenance",
     "requirement": "min_class",
     "value": "SELLER-ASSERTED",
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-161 Rev. 1 — C-SCRM Practices for Systems and Organizations",
      "instrument_id": "nist-sp-800-161r1-cscrm",
      "version": 1,
      "edition": "Rev. 1",
      "citation": "SR-4 [VERIFY]",
      "source_digest": "sha256:6161616161616161616161616161616161616161616161616161616161616161"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "component_provenance",
     "requirement": "required",
     "value": true,
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-161 Rev. 1 — C-SCRM Practices for Systems and Organizations",
      "instrument_id": "nist-sp-800-161r1-cscrm",
      "version": 1,
      "edition": "Rev. 1",
      "citation": "SR-4 provenance [VERIFY]",
      "source_digest": "sha256:6161616161616161616161616161616161616161616161616161616161616161"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "control_assessment",
     "requirement": "max_age_days",
     "value": 365,
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
      "instrument_id": "nist-sp-800-53r5-moderate",
      "version": 5,
      "edition": "Rev. 5",
      "citation": "CA-2 [VERIFY]",
      "source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "control_assessment",
     "requirement": "min_class",
     "value": "VERIFIED",
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
      "instrument_id": "nist-sp-800-53r5-moderate",
      "version": 5,
      "edition": "Rev. 5",
      "citation": "CA-2(1) independent assessors [VERIFY]",
      "source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "control_assessment",
     "requirement": "required",
     "value": true,
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
      "instrument_id": "nist-sp-800-53r5-moderate",
      "version": 5,
      "edition": "Rev. 5",
      "citation": "CA-2 [VERIFY]",
      "source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "penetration_test",
     "requirement": "min_class",
     "value": "VERIFIED",
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
      "instrument_id": "nist-sp-800-53r5-moderate",
      "version": 5,
      "edition": "Rev. 5",
      "citation": "CA-8(1) independent penetration agent [VERIFY]",
      "source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "penetration_test",
     "requirement": "required",
     "value": true,
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
      "instrument_id": "nist-sp-800-53r5-moderate",
      "version": 5,
      "edition": "Rev. 5",
      "citation": "CA-8 [VERIFY]",
      "source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "supplier_assessment",
     "requirement": "required",
     "value": true,
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-161 Rev. 1 — C-SCRM Practices for Systems and Organizations",
      "instrument_id": "nist-sp-800-161r1-cscrm",
      "version": 1,
      "edition": "Rev. 1",
      "citation": "SR-6 [VERIFY]",
      "source_digest": "sha256:6161616161616161616161616161616161616161616161616161616161616161"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "vulnerability_scan",
     "requirement": "max_age_days",
     "value": 30,
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
      "instrument_id": "nist-sp-800-53r5-moderate",
      "version": 5,
      "edition": "Rev. 5",
      "citation": "RA-5(a) [VERIFY]",
      "source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "vulnerability_scan",
     "requirement": "required",
     "value": true,
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
      "instrument_id": "nist-sp-800-53r5-moderate",
      "version": 5,
      "edition": "Rev. 5",
      "citation": "RA-5 [VERIFY]",
      "source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    }
   ],
   "applied": [
    {
     "instrument_id": "nist-sp-800-53r5-moderate",
     "version": 5,
     "authority": "National Institute of Standards and Technology",
     "instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
     "edition": "Rev. 5",
     "citation": "CA-2, CA-8, RA-5, SR-6 [VERIFY]",
     "source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353",
     "entered_by": "actor:human:issm",
     "entered_at": "2026-08-08T16:00:00.000Z"
    },
    {
     "instrument_id": "nist-sp-800-161r1-cscrm",
     "version": 1,
     "authority": "National Institute of Standards and Technology",
     "instrument": "SP 800-161 Rev. 1 — C-SCRM Practices for Systems and Organizations",
     "edition": "Rev. 1",
     "citation": "SR-3, SR-4, SR-11 [VERIFY]",
     "source_digest": "sha256:6161616161616161616161616161616161616161616161616161616161616161",
     "entered_by": "actor:human:issm",
     "entered_at": "2026-08-08T16:00:00.000Z"
    }
   ],
   "defaults": [
    {
     "claim": "component_provenance",
     "requirement": "ai_position",
     "value": "ADMIT",
     "because": "No instrument in force stated a position on AI-authored evidence for \"component_provenance\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
    },
    {
     "claim": "control_assessment",
     "requirement": "ai_position",
     "value": "ADMIT",
     "because": "No instrument in force stated a position on AI-authored evidence for \"control_assessment\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
    },
    {
     "claim": "penetration_test",
     "requirement": "ai_position",
     "value": "ADMIT",
     "because": "No instrument in force stated a position on AI-authored evidence for \"penetration_test\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
    },
    {
     "claim": "supplier_assessment",
     "requirement": "ai_position",
     "value": "ADMIT",
     "because": "No instrument in force stated a position on AI-authored evidence for \"supplier_assessment\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
    },
    {
     "claim": "vulnerability_scan",
     "requirement": "ai_position",
     "value": "ADMIT",
     "because": "No instrument in force stated a position on AI-authored evidence for \"vulnerability_scan\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
    }
   ]
  }
 }
}

Assessor / authorising official

A third-party assessment organisation, an agency assessor, or an inspector general reviewing the package. Same position as a customs officer: a public mandate over the record.

The control record in full — each publication by control identifier, edition and document digest, and every required claim with who supplied it and when. No exposure figure, no risk pricing, no confidence score.

National Institute of Standards and Technology
SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)
CA-2, CA-8, RA-5, SR-6 [VERIFY] · edition Rev. 5
document sha256:5353535353535353535353535353535353535353535353535353535353535353
entered by actor:human:issm
National Institute of Standards and Technology
SP 800-161 Rev. 1 — C-SCRM Practices for Systems and Organizations
SR-3, SR-4, SR-11 [VERIFY] · edition Rev. 1
document sha256:6161616161616161616161616161616161616161616161616161616161616161
entered by actor:human:issm

What each authority bound

ClaimRequirementLevelBound by
component_provenancemin classSELLER-ASSERTEDNational Institute of Standards and Technology
SR-4 [VERIFY] · SP 800-161 Rev. 1 — C-SCRM Practices for Systems and Organizations
component_provenancerequiredtrueNational Institute of Standards and Technology
SR-4 provenance [VERIFY] · SP 800-161 Rev. 1 — C-SCRM Practices for Systems and Organizations
control_assessmentmax age days365National Institute of Standards and Technology
CA-2 [VERIFY] · SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)
control_assessmentmin classVERIFIEDNational Institute of Standards and Technology
CA-2(1) independent assessors [VERIFY] · SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)
control_assessmentrequiredtrueNational Institute of Standards and Technology
CA-2 [VERIFY] · SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)
penetration_testmin classVERIFIEDNational Institute of Standards and Technology
CA-8(1) independent penetration agent [VERIFY] · SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)
penetration_testrequiredtrueNational Institute of Standards and Technology
CA-8 [VERIFY] · SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)
supplier_assessmentrequiredtrueNational Institute of Standards and Technology
SR-6 [VERIFY] · SP 800-161 Rev. 1 — C-SCRM Practices for Systems and Organizations
vulnerability_scanmax age days30National Institute of Standards and Technology
RA-5(a) [VERIFY] · SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)
vulnerability_scanrequiredtrueNational Institute of Standards and Technology
RA-5 [VERIFY] · SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)

Every required claim, and what was actually held

ClaimRequiredEvidence classWhoAgeOutcome
vulnerability_scanyesVERIFIEDactor:sys:registry:nvd-cve2026-08-02admitted
component_provenanceyesVERIFIEDactor:sys:registry:contract-repository2026-05-10admitted
penetration_testyesVERIFIEDactor:org:LAB-NVLAP-04122026-03-11admitted
control_assessmentyesVERIFIEDactor:org:CERT-3PAO-ATLANTIC2026-04-10admitted
supplier_assessmentnoSELLER-ASSERTEDactor:org:CLOUDVANE-GOV2026-06-29withheld
supplier_assessmentyesMISSING2026-08-08coverage gap
Absent from this copy, deliberatelyNo exposure figure, no risk pricing, no confidence score, no release quorum. The examiner’s claim is on the record of what was required and what was held — answered here completely, down to the digest of the document each requirement was configured from. The institution’s commercial position is a different question and this document does not answer it. The published verifier checks that on the content of the copy, not on the intentions of whoever produced it.
The scoped copy itself — partial — something outside this role’s remit was removed
FAITHFUL digest sha256:e102db692451fc9dbd6a121ecc0bde60e54740537e0b652fe25ac735c5636f85 matches the commitment sealed in the receipt.
{
 "spec": "corobate:role-view:2",
 "role": "REGULATOR",
 "purpose": "An official holding a public mandate over this record — a customs officer, a bank examiner, a market conduct supervisor. Sees the regulatory record in full: their own instrument named, every required claim and whether it was met, by whom, how old. No commercial figure of any kind.",
 "is_a_receipt": false,
 "warning": "This is a SCOPED COPY of a sealed decision, not the decision record itself. It will not verify as a receipt and must not be presented as one. To confirm it is faithful, recompute its `view` digest under the same canonicalisation that produces receipt_hash and compare it with the entry for this role in the source receipt’s `views` block.",
 "derived_from": {
  "receipt_hash": "sha256:cc116c0bdb3d3f998c71834f6a365315765375dd99ed77c20c2a9ed4e007625e",
  "entry_hash": "sha256:d60b7a4f6b95aa315ea2d3ca369db1f2c20a5eea0fd5b641c3e36f23f6e23cff",
  "issued_at": "2026-08-08T16:00:00.000Z"
 },
 "view_digest": "sha256:e102db692451fc9dbd6a121ecc0bde60e54740537e0b652fe25ac735c5636f85",
 "withheld": {
  "anything_withheld": true,
  "note": "Facts outside this role’s remit were removed. That something was removed is stated so a partial record is never mistaken for a complete one. How much, and what, is not stated — a count is an inference about the part you are not entitled to see."
 },
 "view": {
  "spec": "urn:ietf:params:corobate:receipt:1",
  "receipt_version": "1.8",
  "issued_at": "2026-08-08T16:00:00.000Z",
  "decision": {
   "id": "ato_CLOUDVANE_R3",
   "subject": "system:CLOUDVANE-GOV-REGION-3",
   "question": "May this cloud service be brought inside the authorisation boundary?"
  },
  "memory": {
   "state_digest": "sha256:01827de72fd2a97521310c759fdc925c1c51ca2f43949aa72b79b19221e6ff88",
   "ledger_head": "sha256:5bbeec39ca2744b408818488f7595e4b119e254325fd84642a3c66c636794c9c",
   "coverage_gaps": [
    "system:CLOUDVANE-GOV-REGION-3|supplier_assessment"
   ]
  },
  "data_horizon": "2026-08-08T16:00:00.000Z",
  "verdict": {
   "value": "WITHHELD"
  },
  "regulatory": {
   "spec": "corobate:regulatory:2",
   "resolved": true,
   "applied": [
    {
     "instrument_id": "nist-sp-800-53r5-moderate",
     "version": 5,
     "authority": "National Institute of Standards and Technology",
     "instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
     "edition": "Rev. 5",
     "citation": "CA-2, CA-8, RA-5, SR-6 [VERIFY]",
     "source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353",
     "entered_by": "actor:human:issm",
     "entered_at": "2026-08-08T16:00:00.000Z"
    },
    {
     "instrument_id": "nist-sp-800-161r1-cscrm",
     "version": 1,
     "authority": "National Institute of Standards and Technology",
     "instrument": "SP 800-161 Rev. 1 — C-SCRM Practices for Systems and Organizations",
     "edition": "Rev. 1",
     "citation": "SR-3, SR-4, SR-11 [VERIFY]",
     "source_digest": "sha256:6161616161616161616161616161616161616161616161616161616161616161",
     "entered_by": "actor:human:issm",
     "entered_at": "2026-08-08T16:00:00.000Z"
    }
   ],
   "skipped": [],
   "conflicts": [],
   "bindings": [
    {
     "claim": "component_provenance",
     "requirement": "min_class",
     "value": "SELLER-ASSERTED",
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-161 Rev. 1 — C-SCRM Practices for Systems and Organizations",
      "instrument_id": "nist-sp-800-161r1-cscrm",
      "version": 1,
      "edition": "Rev. 1",
      "citation": "SR-4 [VERIFY]",
      "source_digest": "sha256:6161616161616161616161616161616161616161616161616161616161616161"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "component_provenance",
     "requirement": "required",
     "value": true,
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-161 Rev. 1 — C-SCRM Practices for Systems and Organizations",
      "instrument_id": "nist-sp-800-161r1-cscrm",
      "version": 1,
      "edition": "Rev. 1",
      "citation": "SR-4 provenance [VERIFY]",
      "source_digest": "sha256:6161616161616161616161616161616161616161616161616161616161616161"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "control_assessment",
     "requirement": "max_age_days",
     "value": 365,
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
      "instrument_id": "nist-sp-800-53r5-moderate",
      "version": 5,
      "edition": "Rev. 5",
      "citation": "CA-2 [VERIFY]",
      "source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "control_assessment",
     "requirement": "min_class",
     "value": "VERIFIED",
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
      "instrument_id": "nist-sp-800-53r5-moderate",
      "version": 5,
      "edition": "Rev. 5",
      "citation": "CA-2(1) independent assessors [VERIFY]",
      "source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "control_assessment",
     "requirement": "required",
     "value": true,
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
      "instrument_id": "nist-sp-800-53r5-moderate",
      "version": 5,
      "edition": "Rev. 5",
      "citation": "CA-2 [VERIFY]",
      "source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "penetration_test",
     "requirement": "min_class",
     "value": "VERIFIED",
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
      "instrument_id": "nist-sp-800-53r5-moderate",
      "version": 5,
      "edition": "Rev. 5",
      "citation": "CA-8(1) independent penetration agent [VERIFY]",
      "source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "penetration_test",
     "requirement": "required",
     "value": true,
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
      "instrument_id": "nist-sp-800-53r5-moderate",
      "version": 5,
      "edition": "Rev. 5",
      "citation": "CA-8 [VERIFY]",
      "source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "supplier_assessment",
     "requirement": "required",
     "value": true,
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-161 Rev. 1 — C-SCRM Practices for Systems and Organizations",
      "instrument_id": "nist-sp-800-161r1-cscrm",
      "version": 1,
      "edition": "Rev. 1",
      "citation": "SR-6 [VERIFY]",
      "source_digest": "sha256:6161616161616161616161616161616161616161616161616161616161616161"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "vulnerability_scan",
     "requirement": "max_age_days",
     "value": 30,
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
      "instrument_id": "nist-sp-800-53r5-moderate",
      "version": 5,
      "edition": "Rev. 5",
      "citation": "RA-5(a) [VERIFY]",
      "source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "vulnerability_scan",
     "requirement": "required",
     "value": true,
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
      "instrument_id": "nist-sp-800-53r5-moderate",
      "version": 5,
      "edition": "Rev. 5",
      "citation": "RA-5 [VERIFY]",
      "source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    }
   ],
   "defaults": [
    {
     "claim": "component_provenance",
     "requirement": "ai_position",
     "value": "ADMIT",
     "because": "No instrument in force stated a position on AI-authored evidence for \"component_provenance\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
    },
    {
     "claim": "control_assessment",
     "requirement": "ai_position",
     "value": "ADMIT",
     "because": "No instrument in force stated a position on AI-authored evidence for \"control_assessment\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
    },
    {
     "claim": "penetration_test",
     "requirement": "ai_position",
     "value": "ADMIT",
     "because": "No instrument in force stated a position on AI-authored evidence for \"penetration_test\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
    },
    {
     "claim": "supplier_assessment",
     "requirement": "ai_position",
     "value": "ADMIT",
     "because": "No instrument in force stated a position on AI-authored evidence for \"supplier_assessment\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
    },
    {
     "claim": "vulnerability_scan",
     "requirement": "ai_position",
     "value": "ADMIT",
     "because": "No instrument in force stated a position on AI-authored evidence for \"vulnerability_scan\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
    }
   ]
  },
  "inputs": [
   {
    "key": "system:CLOUDVANE-GOV-REGION-3::vulnerability_scan",
    "provenance": "VERIFIED",
    "source": "nvd-cve:vulnerability_scan",
    "observed_at": "2026-08-02T16:00:00.000Z",
    "critical": true,
    "memory_status": "admitted",
    "memory_actor": "actor:sys:registry:nvd-cve"
   },
   {
    "key": "system:CLOUDVANE-GOV-REGION-3::component_provenance",
    "provenance": "VERIFIED",
    "source": "contract-repository:component_provenance",
    "observed_at": "2026-05-10T16:00:00.000Z",
    "critical": true,
    "memory_status": "admitted",
    "memory_actor": "actor:sys:registry:contract-repository"
   },
   {
    "key": "system:CLOUDVANE-GOV-REGION-3::penetration_test",
    "provenance": "VERIFIED",
    "source": "LAB-NVLAP-0412:penetration_test",
    "observed_at": "2026-03-11T16:00:00.000Z",
    "critical": true,
    "memory_status": "admitted",
    "memory_actor": "actor:org:LAB-NVLAP-0412"
   },
   {
    "key": "system:CLOUDVANE-GOV-REGION-3::control_assessment",
    "provenance": "VERIFIED",
    "source": "CERT-3PAO-ATLANTIC:control_assessment",
    "observed_at": "2026-04-10T16:00:00.000Z",
    "critical": true,
    "memory_status": "admitted",
    "memory_actor": "actor:org:CERT-3PAO-ATLANTIC"
   },
   {
    "key": "system:CLOUDVANE-GOV-REGION-3::supplier_assessment",
    "provenance": "SELLER-ASSERTED",
    "source": "CLOUDVANE-GOV:supplier_assessment",
    "observed_at": "2026-06-29T16:00:00.000Z",
    "critical": false,
    "memory_status": "withheld",
    "memory_actor": "actor:org:CLOUDVANE-GOV"
   },
   {
    "key": "system:CLOUDVANE-GOV-REGION-3::supplier_assessment",
    "provenance": "MISSING",
    "source": null,
    "observed_at": "2026-08-08T16:00:00.000Z",
    "critical": true,
    "memory_status": "coverage_gap"
   }
  ],
  "crypto_suite": {
   "spec": "corobate:suite:1",
   "id": "CB-1-ES256-SHA256",
   "receipt_digest": "sha256",
   "chain_digest": "sha256",
   "content_digest": "sha256",
   "envelope_signature": "ES256",
   "signature_curve": "P-256",
   "canonicalisation": "attest-canon/2",
   "quantum_resistant": false
  }
 }
}

ISSM / control owner

The information system security manager and the control owners who hold the package.

The fullest internal view: every input, its class, its age, its score, the exposure, and every publication in force.

VerdictWITHHELD
Confidence0%
bound by supplier_assessment
Exposure$2,200,000
ReleaseWITHHELD_NO_EVIDENCE
Risk acceptedNONE

Every input the gate saw

ClaimRequiredEvidence classWhoAgeScoreOutcome
vulnerability_scanyesVERIFIEDactor:sys:registry:nvd-cve6d95%admitted
component_provenanceyesVERIFIEDactor:sys:registry:contract-repository90d95%admitted
penetration_testyesVERIFIEDactor:org:LAB-NVLAP-0412150d95%admitted
control_assessmentyesVERIFIEDactor:org:CERT-3PAO-ATLANTIC120d95%admitted
supplier_assessmentnoSELLER-ASSERTEDactor:org:CLOUDVANE-GOV40d40%withheld
supplier_assessmentyesMISSING2026-08-080%coverage gap

Instruments in force

National Institute of Standards and Technology
SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)
CA-2, CA-8, RA-5, SR-6 [VERIFY] · edition Rev. 5
document sha256:5353535353535353535353535353535353535353535353535353535353535353
entered by actor:human:issm
National Institute of Standards and Technology
SP 800-161 Rev. 1 — C-SCRM Practices for Systems and Organizations
SR-3, SR-4, SR-11 [VERIFY] · edition Rev. 1
document sha256:6161616161616161616161616161616161616161616161616161616161616161
entered by actor:human:issm

Why

  • Coverage gap: no admissible memory for required claim(s) system:CLOUDVANE-GOV-REGION-3|supplier_assessment.
  • Confidence 0.00% is bound by "system:CLOUDVANE-GOV-REGION-3|supplier_assessment".
  • 1 memory was withheld from the context block: system:CLOUDVANE-GOV-REGION-3|supplier_assessment (sparse track record: 1 independent observation(s); no failure recorded, so the class ceiling stands).
  • Thresholds for $2,200,000 exposure: approve 90%, caution 70%.
The scoped copy itself — partial — something outside this role’s remit was removed
FAITHFUL digest sha256:a89d4b30651ea80c88f153e1b4d7c6126ff521b6659ee0f6f07e8117f4a182f1 matches the commitment sealed in the receipt.
{
 "spec": "corobate:role-view:2",
 "role": "COMPLIANCE",
 "purpose": "The operator’s own compliance function. The fullest internal view: every gap, every instrument in force, the waivability of each requirement and who accepted what.",
 "is_a_receipt": false,
 "warning": "This is a SCOPED COPY of a sealed decision, not the decision record itself. It will not verify as a receipt and must not be presented as one. To confirm it is faithful, recompute its `view` digest under the same canonicalisation that produces receipt_hash and compare it with the entry for this role in the source receipt’s `views` block.",
 "derived_from": {
  "receipt_hash": "sha256:cc116c0bdb3d3f998c71834f6a365315765375dd99ed77c20c2a9ed4e007625e",
  "entry_hash": "sha256:d60b7a4f6b95aa315ea2d3ca369db1f2c20a5eea0fd5b641c3e36f23f6e23cff",
  "issued_at": "2026-08-08T16:00:00.000Z"
 },
 "view_digest": "sha256:a89d4b30651ea80c88f153e1b4d7c6126ff521b6659ee0f6f07e8117f4a182f1",
 "withheld": {
  "anything_withheld": true,
  "note": "Facts outside this role’s remit were removed. That something was removed is stated so a partial record is never mistaken for a complete one. How much, and what, is not stated — a count is an inference about the part you are not entitled to see."
 },
 "view": {
  "spec": "urn:ietf:params:corobate:receipt:1",
  "receipt_version": "1.8",
  "issued_at": "2026-08-08T16:00:00.000Z",
  "decision": {
   "id": "ato_CLOUDVANE_R3",
   "domain": "supply-chain",
   "subject": "system:CLOUDVANE-GOV-REGION-3",
   "question": "May this cloud service be brought inside the authorisation boundary?"
  },
  "memory": {
   "state_digest": "sha256:01827de72fd2a97521310c759fdc925c1c51ca2f43949aa72b79b19221e6ff88",
   "ledger_head": "sha256:5bbeec39ca2744b408818488f7595e4b119e254325fd84642a3c66c636794c9c",
   "coverage_gaps": [
    "system:CLOUDVANE-GOV-REGION-3|supplier_assessment"
   ],
   "exposure": {
    "usd": 2200000,
    "declared_by": "actor:human:ao-authorizing-official",
    "ledger_seq": 5
   },
   "policy_digest": "sha256:a6b69b7d20f7fb04d522364af1d92992058b04a5835fcec9d1c9f2261c7ef636"
  },
  "data_horizon": "2026-08-08T16:00:00.000Z",
  "verdict": {
   "value": "WITHHELD",
   "threshold_approve": 0.9,
   "threshold_caution": 0.7,
   "rule": "confidence>=threshold"
  },
  "confidence": {
   "value": 0,
   "method": "min-over-critical-inputs",
   "bound_by": "system:CLOUDVANE-GOV-REGION-3::supplier_assessment"
  },
  "release": {
   "required": false,
   "required_by_tier": false,
   "escalated_by_acceptance": false,
   "risk_accepted": false,
   "state": "WITHHELD_NO_EVIDENCE",
   "code": "QUORUM_EVIDENCE_WITHHELD",
   "reason": "the evidence did not clear the threshold for this exposure, so there is nothing to release. Signatures do not substitute for evidence, and this state is deliberately distinct from WITHHELD_PENDING_SIGNATURES: a reader must be able to tell \"the evidence is not there\" from \"the evidence is there and 0 of 2 people have signed\".",
   "tier_floor_cents": 1000000000,
   "exposure_usd_cents": 220000000,
   "required_m": 2,
   "declared_n": 3,
   "floor_m": 2,
   "distinct_signers": 0,
   "superseded": 0,
   "collapsed": 0,
   "release_digest": "sha256:8ef23045c8d8714e4d68ec83739091959dcb5765515b96c8c66ebbf99a4558ec",
   "governance_digest": "sha256:8b0a45a27fcce9c1c243c764e855e67c6fe6dfd7f02a563bd90809b419731905",
   "governance_signed": true,
   "counted_voices": [],
   "signatures": [],
   "ledger_seq": null
  },
  "acceptance": {
   "state": "NONE",
   "code": "ACCEPTANCE_NONE",
   "reason": "no risk acceptance was presented for this decision. This is the ordinary case: a refusal is a refusal unless a named person has priced it.",
   "permitted_basis": null,
   "presented": 0,
   "superseded": 0,
   "expired": 0,
   "gaps_not_covered": 0,
   "coverage_gaps_in_force": [
    "system:CLOUDVANE-GOV-REGION-3|supplier_assessment"
   ],
   "evidentiary_digest": "sha256:8ef23045c8d8714e4d68ec83739091959dcb5765515b96c8c66ebbf99a4558ec",
   "margin_floor_bp": 100,
   "authority_ceiling_cents": {
    "SUPERVISOR": 1000000,
    "MANAGER": 25000000,
    "DIRECTOR": 500000000,
    "OFFICER": 5000000000
   },
   "acceptances": [],
   "escalated": false,
   "live": false,
   "ledger_seq": null
  },
  "regulatory": {
   "spec": "corobate:regulatory:2",
   "resolved": true,
   "applied": [
    {
     "instrument_id": "nist-sp-800-53r5-moderate",
     "version": 5,
     "authority": "National Institute of Standards and Technology",
     "instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
     "edition": "Rev. 5",
     "citation": "CA-2, CA-8, RA-5, SR-6 [VERIFY]",
     "source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353",
     "entered_by": "actor:human:issm",
     "entered_at": "2026-08-08T16:00:00.000Z"
    },
    {
     "instrument_id": "nist-sp-800-161r1-cscrm",
     "version": 1,
     "authority": "National Institute of Standards and Technology",
     "instrument": "SP 800-161 Rev. 1 — C-SCRM Practices for Systems and Organizations",
     "edition": "Rev. 1",
     "citation": "SR-3, SR-4, SR-11 [VERIFY]",
     "source_digest": "sha256:6161616161616161616161616161616161616161616161616161616161616161",
     "entered_by": "actor:human:issm",
     "entered_at": "2026-08-08T16:00:00.000Z"
    }
   ],
   "skipped": [],
   "conflicts": [],
   "bindings": [
    {
     "claim": "component_provenance",
     "requirement": "min_class",
     "value": "SELLER-ASSERTED",
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-161 Rev. 1 — C-SCRM Practices for Systems and Organizations",
      "instrument_id": "nist-sp-800-161r1-cscrm",
      "version": 1,
      "edition": "Rev. 1",
      "citation": "SR-4 [VERIFY]",
      "source_digest": "sha256:6161616161616161616161616161616161616161616161616161616161616161"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "component_provenance",
     "requirement": "required",
     "value": true,
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-161 Rev. 1 — C-SCRM Practices for Systems and Organizations",
      "instrument_id": "nist-sp-800-161r1-cscrm",
      "version": 1,
      "edition": "Rev. 1",
      "citation": "SR-4 provenance [VERIFY]",
      "source_digest": "sha256:6161616161616161616161616161616161616161616161616161616161616161"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "control_assessment",
     "requirement": "max_age_days",
     "value": 365,
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
      "instrument_id": "nist-sp-800-53r5-moderate",
      "version": 5,
      "edition": "Rev. 5",
      "citation": "CA-2 [VERIFY]",
      "source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "control_assessment",
     "requirement": "min_class",
     "value": "VERIFIED",
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
      "instrument_id": "nist-sp-800-53r5-moderate",
      "version": 5,
      "edition": "Rev. 5",
      "citation": "CA-2(1) independent assessors [VERIFY]",
      "source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "control_assessment",
     "requirement": "required",
     "value": true,
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
      "instrument_id": "nist-sp-800-53r5-moderate",
      "version": 5,
      "edition": "Rev. 5",
      "citation": "CA-2 [VERIFY]",
      "source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "penetration_test",
     "requirement": "min_class",
     "value": "VERIFIED",
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
      "instrument_id": "nist-sp-800-53r5-moderate",
      "version": 5,
      "edition": "Rev. 5",
      "citation": "CA-8(1) independent penetration agent [VERIFY]",
      "source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "penetration_test",
     "requirement": "required",
     "value": true,
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
      "instrument_id": "nist-sp-800-53r5-moderate",
      "version": 5,
      "edition": "Rev. 5",
      "citation": "CA-8 [VERIFY]",
      "source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "supplier_assessment",
     "requirement": "required",
     "value": true,
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-161 Rev. 1 — C-SCRM Practices for Systems and Organizations",
      "instrument_id": "nist-sp-800-161r1-cscrm",
      "version": 1,
      "edition": "Rev. 1",
      "citation": "SR-6 [VERIFY]",
      "source_digest": "sha256:6161616161616161616161616161616161616161616161616161616161616161"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "vulnerability_scan",
     "requirement": "max_age_days",
     "value": 30,
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
      "instrument_id": "nist-sp-800-53r5-moderate",
      "version": 5,
      "edition": "Rev. 5",
      "citation": "RA-5(a) [VERIFY]",
      "source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "vulnerability_scan",
     "requirement": "required",
     "value": true,
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
      "instrument_id": "nist-sp-800-53r5-moderate",
      "version": 5,
      "edition": "Rev. 5",
      "citation": "RA-5 [VERIFY]",
      "source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    }
   ],
   "defaults": [
    {
     "claim": "component_provenance",
     "requirement": "ai_position",
     "value": "ADMIT",
     "because": "No instrument in force stated a position on AI-authored evidence for \"component_provenance\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
    },
    {
     "claim": "control_assessment",
     "requirement": "ai_position",
     "value": "ADMIT",
     "because": "No instrument in force stated a position on AI-authored evidence for \"control_assessment\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
    },
    {
     "claim": "penetration_test",
     "requirement": "ai_position",
     "value": "ADMIT",
     "because": "No instrument in force stated a position on AI-authored evidence for \"penetration_test\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
    },
    {
     "claim": "supplier_assessment",
     "requirement": "ai_position",
     "value": "ADMIT",
     "because": "No instrument in force stated a position on AI-authored evidence for \"supplier_assessment\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
    },
    {
     "claim": "vulnerability_scan",
     "requirement": "ai_position",
     "value": "ADMIT",
     "because": "No instrument in force stated a position on AI-authored evidence for \"vulnerability_scan\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
    }
   ]
  },
  "reasons": [
   "Coverage gap: no admissible memory for required claim(s) system:CLOUDVANE-GOV-REGION-3|supplier_assessment.",
   "Confidence 0.00% is bound by \"system:CLOUDVANE-GOV-REGION-3|supplier_assessment\".",
   "1 memory was withheld from the context block: system:CLOUDVANE-GOV-REGION-3|supplier_assessment (sparse track record: 1 independent observation(s); no failure recorded, so the class ceiling stands).",
   "Thresholds for $2,200,000 exposure: approve 90%, caution 70%."
  ],
  "inputs": [
   {
    "key": "system:CLOUDVANE-GOV-REGION-3::vulnerability_scan",
    "value": "clean-at-scan",
    "provenance": "VERIFIED",
    "source": "nvd-cve:vulnerability_scan",
    "observed_at": "2026-08-02T16:00:00.000Z",
    "reliability": 0.95,
    "critical": true,
    "memory_status": "admitted",
    "memory_kind": "status",
    "memory_actor": "actor:sys:registry:nvd-cve",
    "memory_age_days": 6
   },
   {
    "key": "system:CLOUDVANE-GOV-REGION-3::component_provenance",
    "value": "schedule",
    "provenance": "VERIFIED",
    "source": "contract-repository:component_provenance",
    "observed_at": "2026-05-10T16:00:00.000Z",
    "reliability": 0.95,
    "critical": true,
    "memory_status": "admitted",
    "memory_kind": "certificate",
    "memory_actor": "actor:sys:registry:contract-repository",
    "memory_age_days": 90
   },
   {
    "key": "system:CLOUDVANE-GOV-REGION-3::penetration_test",
    "value": "no-critical",
    "provenance": "VERIFIED",
    "source": "LAB-NVLAP-0412:penetration_test",
    "observed_at": "2026-03-11T16:00:00.000Z",
    "reliability": 0.95,
    "critical": true,
    "memory_status": "admitted",
    "memory_kind": "test_report",
    "memory_actor": "actor:org:LAB-NVLAP-0412",
    "memory_age_days": 150
   },
   {
    "key": "system:CLOUDVANE-GOV-REGION-3::control_assessment",
    "value": "satisfied-with-poams",
    "provenance": "VERIFIED",
    "source": "CERT-3PAO-ATLANTIC:control_assessment",
    "observed_at": "2026-04-10T16:00:00.000Z",
    "reliability": 0.95,
    "critical": true,
    "memory_status": "admitted",
    "memory_kind": "certificate",
    "memory_actor": "actor:org:CERT-3PAO-ATLANTIC",
    "memory_age_days": 120
   },
   {
    "key": "system:CLOUDVANE-GOV-REGION-3::supplier_assessment",
    "value": null,
    "provenance": "SELLER-ASSERTED",
    "source": "CLOUDVANE-GOV:supplier_assessment",
    "observed_at": "2026-06-29T16:00:00.000Z",
    "reliability": 0.4,
    "critical": false,
    "memory_status": "withheld",
    "memory_kind": "status",
    "memory_actor": "actor:org:CLOUDVANE-GOV",
    "memory_age_days": 40
   },
   {
    "key": "system:CLOUDVANE-GOV-REGION-3::supplier_assessment",
    "value": null,
    "provenance": "MISSING",
    "source": null,
    "observed_at": "2026-08-08T16:00:00.000Z",
    "reliability": 0,
    "critical": true,
    "memory_status": "coverage_gap"
   }
  ],
  "crypto_suite": {
   "spec": "corobate:suite:1",
   "id": "CB-1-ES256-SHA256",
   "receipt_digest": "sha256",
   "chain_digest": "sha256",
   "content_digest": "sha256",
   "envelope_signature": "ES256",
   "signature_curve": "P-256",
   "canonicalisation": "attest-canon/2",
   "quantum_resistant": false
  }
 }
}

Authorising official (signer)

The named official whose signature carries the authorisation decision.

What is at stake, what the evidence supports, what is missing, and the digest they are signing over.

You are being asked to sign

May this cloud service be brought inside the authorisation boundary?

At stake$2,200,000
Evidence saysWITHHELD
Release stateWITHHELD_NO_EVIDENCE
signing over evidentiary digest sha256:8ef23045c8d8714e4d68ec83739091959dcb5765515b96c8c66ebbf99a4558ec

The signature is over the STATE OF THE EVIDENCE. Move one fact behind this decision and the digest moves and the signature stops counting — which is what makes it safe to collect signatures before everyone is in the room.

What is missing

  • supplier assessment
The scoped copy itself — partial — something outside this role’s remit was removed
FAITHFUL digest sha256:0cf465714d0c4787762ad88079ddd218dbc696be4ca734ca4b713c0b5ac783c7 matches the commitment sealed in the receipt.
{
 "spec": "corobate:role-view:2",
 "role": "EXECUTIVE",
 "purpose": "A named signer on the release gate. Sees what is at stake, what the evidence supports, who else has signed and what they are being asked to sign over.",
 "is_a_receipt": false,
 "warning": "This is a SCOPED COPY of a sealed decision, not the decision record itself. It will not verify as a receipt and must not be presented as one. To confirm it is faithful, recompute its `view` digest under the same canonicalisation that produces receipt_hash and compare it with the entry for this role in the source receipt’s `views` block.",
 "derived_from": {
  "receipt_hash": "sha256:cc116c0bdb3d3f998c71834f6a365315765375dd99ed77c20c2a9ed4e007625e",
  "entry_hash": "sha256:d60b7a4f6b95aa315ea2d3ca369db1f2c20a5eea0fd5b641c3e36f23f6e23cff",
  "issued_at": "2026-08-08T16:00:00.000Z"
 },
 "view_digest": "sha256:0cf465714d0c4787762ad88079ddd218dbc696be4ca734ca4b713c0b5ac783c7",
 "withheld": {
  "anything_withheld": true,
  "note": "Facts outside this role’s remit were removed. That something was removed is stated so a partial record is never mistaken for a complete one. How much, and what, is not stated — a count is an inference about the part you are not entitled to see."
 },
 "view": {
  "spec": "urn:ietf:params:corobate:receipt:1",
  "receipt_version": "1.8",
  "issued_at": "2026-08-08T16:00:00.000Z",
  "decision": {
   "id": "ato_CLOUDVANE_R3",
   "domain": "supply-chain",
   "subject": "system:CLOUDVANE-GOV-REGION-3",
   "question": "May this cloud service be brought inside the authorisation boundary?"
  },
  "memory": {
   "state_digest": "sha256:01827de72fd2a97521310c759fdc925c1c51ca2f43949aa72b79b19221e6ff88",
   "ledger_head": "sha256:5bbeec39ca2744b408818488f7595e4b119e254325fd84642a3c66c636794c9c",
   "coverage_gaps": [
    "system:CLOUDVANE-GOV-REGION-3|supplier_assessment"
   ],
   "exposure": {
    "usd": 2200000,
    "declared_by": "actor:human:ao-authorizing-official",
    "ledger_seq": 5
   }
  },
  "verdict": {
   "value": "WITHHELD",
   "threshold_approve": 0.9,
   "threshold_caution": 0.7,
   "rule": "confidence>=threshold"
  },
  "confidence": {
   "value": 0,
   "method": "min-over-critical-inputs",
   "bound_by": "system:CLOUDVANE-GOV-REGION-3::supplier_assessment"
  },
  "release": {
   "required": false,
   "required_by_tier": false,
   "escalated_by_acceptance": false,
   "risk_accepted": false,
   "state": "WITHHELD_NO_EVIDENCE",
   "code": "QUORUM_EVIDENCE_WITHHELD",
   "reason": "the evidence did not clear the threshold for this exposure, so there is nothing to release. Signatures do not substitute for evidence, and this state is deliberately distinct from WITHHELD_PENDING_SIGNATURES: a reader must be able to tell \"the evidence is not there\" from \"the evidence is there and 0 of 2 people have signed\".",
   "tier_floor_cents": 1000000000,
   "exposure_usd_cents": 220000000,
   "required_m": 2,
   "declared_n": 3,
   "floor_m": 2,
   "distinct_signers": 0,
   "superseded": 0,
   "collapsed": 0,
   "release_digest": "sha256:8ef23045c8d8714e4d68ec83739091959dcb5765515b96c8c66ebbf99a4558ec",
   "governance_digest": "sha256:8b0a45a27fcce9c1c243c764e855e67c6fe6dfd7f02a563bd90809b419731905",
   "governance_signed": true,
   "counted_voices": [],
   "signatures": [],
   "ledger_seq": null
  },
  "acceptance": {
   "state": "NONE",
   "code": "ACCEPTANCE_NONE",
   "reason": "no risk acceptance was presented for this decision. This is the ordinary case: a refusal is a refusal unless a named person has priced it.",
   "permitted_basis": null,
   "presented": 0,
   "superseded": 0,
   "expired": 0,
   "gaps_not_covered": 0,
   "coverage_gaps_in_force": [
    "system:CLOUDVANE-GOV-REGION-3|supplier_assessment"
   ],
   "evidentiary_digest": "sha256:8ef23045c8d8714e4d68ec83739091959dcb5765515b96c8c66ebbf99a4558ec",
   "margin_floor_bp": 100,
   "authority_ceiling_cents": {
    "SUPERVISOR": 1000000,
    "MANAGER": 25000000,
    "DIRECTOR": 500000000,
    "OFFICER": 5000000000
   },
   "acceptances": [],
   "escalated": false,
   "live": false,
   "ledger_seq": null
  },
  "reasons": [
   "Coverage gap: no admissible memory for required claim(s) system:CLOUDVANE-GOV-REGION-3|supplier_assessment.",
   "Confidence 0.00% is bound by \"system:CLOUDVANE-GOV-REGION-3|supplier_assessment\".",
   "1 memory was withheld from the context block: system:CLOUDVANE-GOV-REGION-3|supplier_assessment (sparse track record: 1 independent observation(s); no failure recorded, so the class ceiling stands).",
   "Thresholds for $2,200,000 exposure: approve 90%, caution 70%."
  ],
  "regulatory": {
   "applied": [
    {
     "instrument_id": "nist-sp-800-53r5-moderate",
     "version": 5,
     "authority": "National Institute of Standards and Technology",
     "instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
     "edition": "Rev. 5",
     "citation": "CA-2, CA-8, RA-5, SR-6 [VERIFY]",
     "source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353",
     "entered_by": "actor:human:issm",
     "entered_at": "2026-08-08T16:00:00.000Z"
    },
    {
     "instrument_id": "nist-sp-800-161r1-cscrm",
     "version": 1,
     "authority": "National Institute of Standards and Technology",
     "instrument": "SP 800-161 Rev. 1 — C-SCRM Practices for Systems and Organizations",
     "edition": "Rev. 1",
     "citation": "SR-3, SR-4, SR-11 [VERIFY]",
     "source_digest": "sha256:6161616161616161616161616161616161616161616161616161616161616161",
     "entered_by": "actor:human:issm",
     "entered_at": "2026-08-08T16:00:00.000Z"
    }
   ],
   "conflicts": [],
   "defaults": [
    {
     "claim": "component_provenance",
     "requirement": "ai_position",
     "value": "ADMIT",
     "because": "No instrument in force stated a position on AI-authored evidence for \"component_provenance\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
    },
    {
     "claim": "control_assessment",
     "requirement": "ai_position",
     "value": "ADMIT",
     "because": "No instrument in force stated a position on AI-authored evidence for \"control_assessment\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
    },
    {
     "claim": "penetration_test",
     "requirement": "ai_position",
     "value": "ADMIT",
     "because": "No instrument in force stated a position on AI-authored evidence for \"penetration_test\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
    },
    {
     "claim": "supplier_assessment",
     "requirement": "ai_position",
     "value": "ADMIT",
     "because": "No instrument in force stated a position on AI-authored evidence for \"supplier_assessment\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
    },
    {
     "claim": "vulnerability_scan",
     "requirement": "ai_position",
     "value": "ADMIT",
     "because": "No instrument in force stated a position on AI-authored evidence for \"vulnerability_scan\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
    }
   ]
  },
  "inputs": [
   {
    "key": "system:CLOUDVANE-GOV-REGION-3::vulnerability_scan",
    "provenance": "VERIFIED",
    "reliability": 0.95,
    "critical": true,
    "memory_status": "admitted"
   },
   {
    "key": "system:CLOUDVANE-GOV-REGION-3::component_provenance",
    "provenance": "VERIFIED",
    "reliability": 0.95,
    "critical": true,
    "memory_status": "admitted"
   },
   {
    "key": "system:CLOUDVANE-GOV-REGION-3::penetration_test",
    "provenance": "VERIFIED",
    "reliability": 0.95,
    "critical": true,
    "memory_status": "admitted"
   },
   {
    "key": "system:CLOUDVANE-GOV-REGION-3::control_assessment",
    "provenance": "VERIFIED",
    "reliability": 0.95,
    "critical": true,
    "memory_status": "admitted"
   },
   {
    "key": "system:CLOUDVANE-GOV-REGION-3::supplier_assessment",
    "provenance": "SELLER-ASSERTED",
    "reliability": 0.4,
    "critical": false,
    "memory_status": "withheld"
   },
   {
    "key": "system:CLOUDVANE-GOV-REGION-3::supplier_assessment",
    "provenance": "MISSING",
    "reliability": 0,
    "critical": true,
    "memory_status": "coverage_gap"
   }
  ]
 }
}

Independent audit / IG

Internal audit, an inspector general, or an external auditor testing the programme.

Everything, plus the verifier’s own findings over the sealed record.

This view withholds nothing. What it adds is the 22 checks the published verifier ran over the sealed record behind every other view of this decision — recomputed at build time, not asserted.

#CheckDetail
1Content reproduces (JCS + SHA-256)PASSmatches sha256:cc116c0bdb3d3f998c71834f6a365315765375dd99ed77c20c2a9ed4e007625e
2Hash chain links (entry = H(prev||content))PASShead sha256:d60b7a4f6b95aa315ea2d3ca369db1f2c20a5eea0fd5b641c3e36f23f6e23cff
3Confidence gated by weakest critical inputPASSmin over critical = 0, bound_by system:CLOUDVANE-GOV-REGION-3::supplier_assessment (MISSING)
3bVerdict follows the threshold rulePASS0 => WITHHELD; recorded WITHHELD
4Point-in-time seal (no input past data_horizon)PASSall inputs <= 2026-08-08T16:00:00.000Z
5Anchor covers the head, and the timestamp token re-readsPASSinternally consistent; NO external anchor was requested — this is not a validated timestamp
6Criteria travel with the receipt and reproducePASSpolicy_body hashes to sha256:a6b69b7d20f7fb04d522364af1d92992058b04a5835fcec9d1c9f2261c7ef636
7Reliability re-derives from recorded evidencePASSall 6 inputs re-derive exactly
8Outcome trials and lineage discounts re-derivePASS5 input(s) re-derive: 0 credited outcome trial(s), 0 lineage-discounted corroboration(s); every reliability is at or under its class ceiling
9Re-ingested receipts respect their weakest-input ceilingPASSno re-ingested receipts: every input rests on a primary observation
10Release quorum re-derivesPASSWITHHELD_NO_EVIDENCE - below the top exposure tier, no multi-party requirement applies
11Risk acceptance re-derivesPASSno risk acceptance: this decision stands or falls on its evidence
12Observer credentials were not revoked as of observation timePASSrevocation list 5 (0 entries, issued 2026-08-06T00:00:00.000Z, next update due 2026-08-13T00:00:00.000Z) reproduces; 4 observer signature(s) judged as of their own instant, none under a key revoked as compromised or retired by then
13The cryptographic suite is named and is one this verifier implementsPASSsealed under CB-1-ES256-SHA256 (ES256 / sha256, attest-canon/2); this verifier implements it; the suite states it is NOT quantum resistant
14Regulatory bindings are attributed and were enforcedPASS10 binding(s) from 2 instrument(s) in force, each attributed to an authority, a citation and a document digest; 5 required claim(s) all reached the gate
15Role-view commitments re-derive, and the customs view carries no moneyPASS6 role-view commitment(s) re-derived from this receipt’s own body by this verifier’s independent projection; the REGULATOR view carries no commercial figure
16AI-authored input was admitted only where an authority allowed itPASS0 claim(s) carry a position on AI-authored evidence set by an authority and 5 carry a recorded default nobody set; 0 exclusion(s) and 0 corroboration-only rule(s) re-derived against this receipt's own admitted inputs; 0 admitted input(s) are AI-authored by their enrolled identity
17State digest recomputes from the ledger aloneUNVERIFIABLENOT APPLICABLE — you supplied no ledger, so the state digest cannot be re-derived from anything. This receipt commits to the corpus the deciding system held at the instant it sealed, and that commitment is checked by recomputing it from the append-only ledger and comparing; with no ledger in hand there is no second artefact to recompute from. The receipt is not at fault and nothing here is missing from it. Obtain the ledger from the issuer and re-run with --ledger <file>, or verifyReceipt(r, {ledger}). Nothing here has failed and nothing here has passed.
18Registry membership re-derives for every key relied onPASSall 4 key(s) relied on re-derive to the entries root registry v3 committed to and the trust root signed
20Geometric support re-derives, and an unevaluated record is not a supported onePASSno authority bound a metric to any claim on this receipt, so no geometric test applied. A claim nobody bound a metric to is not a claim about geometry, and this is a stated absence rather than a silent one
19The cause of every uncovered requirement re-derivesPASSall 1 uncovered requirement(s) re-derive their cause from this receipt's own rows. What notice is ADEQUATE is not decided here: this check establishes what the record says and that the record agrees with itself.
21The sealing party is the one you were told to expectUNVERIFIABLENOT APPLICABLE — you supplied no trust bundle, so nothing here establishes who sealed this. Identities 1 to 20 prove that this document agrees with itself; not one of them asks whose trust root it was sealed under, and a document that agrees with itself about a decision nobody made agrees with itself perfectly. Obtain the issuer's corobate:trust-bundle:1 out of band, confirm its spoken fingerprint with them by voice, and re-run with --trust-bundle <file> --expect-fingerprint <what you heard>. Nothing here has failed and nothing here has passed.
The scoped copy itself — complete for this role
FAITHFUL digest sha256:d350145dbd32a6ab5a4433eb3725702c7aa4ec780bf40041798b3d7233f20643 matches the commitment sealed in the receipt.
{
 "spec": "corobate:role-view:2",
 "role": "AUDITOR",
 "purpose": "An external assessor. Sees the complete sealed record: this view withholds nothing and exists so the identity case is a case rather than an exception.",
 "is_a_receipt": false,
 "warning": "This is a SCOPED COPY of a sealed decision, not the decision record itself. It will not verify as a receipt and must not be presented as one. To confirm it is faithful, recompute its `view` digest under the same canonicalisation that produces receipt_hash and compare it with the entry for this role in the source receipt’s `views` block.",
 "derived_from": {
  "receipt_hash": "sha256:cc116c0bdb3d3f998c71834f6a365315765375dd99ed77c20c2a9ed4e007625e",
  "entry_hash": "sha256:d60b7a4f6b95aa315ea2d3ca369db1f2c20a5eea0fd5b641c3e36f23f6e23cff",
  "issued_at": "2026-08-08T16:00:00.000Z"
 },
 "view_digest": "sha256:d350145dbd32a6ab5a4433eb3725702c7aa4ec780bf40041798b3d7233f20643",
 "withheld": {
  "anything_withheld": false,
  "note": "Nothing outside the seal was removed for this role."
 },
 "view": {
  "spec": "urn:ietf:params:corobate:receipt:1",
  "receipt_version": "1.8",
  "engine": {
   "name": "corobate-memory",
   "version": "1.0.0"
  },
  "decision": {
   "id": "ato_CLOUDVANE_R3",
   "domain": "supply-chain",
   "subject": "system:CLOUDVANE-GOV-REGION-3",
   "question": "May this cloud service be brought inside the authorisation boundary?"
  },
  "issued_at": "2026-08-08T16:00:00.000Z",
  "data_horizon": "2026-08-08T16:00:00.000Z",
  "inputs": [
   {
    "key": "system:CLOUDVANE-GOV-REGION-3::vulnerability_scan",
    "value": "clean-at-scan",
    "provenance": "VERIFIED",
    "source": "nvd-cve:vulnerability_scan",
    "observed_at": "2026-08-02T16:00:00.000Z",
    "last_corroborated_at": null,
    "memory_refreshed_by": [],
    "reliability": 0.95,
    "critical": true,
    "memory_id": "mem_6d2e9d3452ab",
    "memory_status": "admitted",
    "memory_kind": "status",
    "memory_actor": "actor:sys:registry:nvd-cve",
    "memory_age_days": 6,
    "memory_track": {
     "n": 1,
     "successes": 1
    },
    "memory_promoted_by": [],
    "memory_content_digest": "sha256:5b21c1afb32830893109c15819f205ccf5bf45d924ae231a0e80f2d4d5750c56",
    "memory_outcomes": {
     "verified": 0,
     "falsified": 0,
     "modified": 0,
     "counted": 0,
     "recorded": 0
    },
    "memory_outcome_attestations": [],
    "memory_observer_lineage": null,
    "memory_corroborations": [],
    "memory_reingest": null,
    "memory_reasons": [
     "sparse track record: 1 independent observation(s); no failure recorded, so the class ceiling stands"
    ],
    "memory_class_floor": null,
    "memory_below_class_floor": false,
    "memory_not_attested": false,
    "memory_below_claim_reliability_floor": false,
    "memory_not_competent_authority": false,
    "memory_out_of_specification": false,
    "memory_ai_authored": false,
    "memory_ai_in_lineage": false,
    "memory_ai_position": "ADMIT",
    "memory_ai_inadmissible": false,
    "memory_geo_inadmissible": false,
    "memory_geo_rung": null,
    "memory_geo_metric": null,
    "memory_geo_required_metric": null,
    "observer_attested": true,
    "observer_auth_code": "VERIFIED",
    "observer_key_id": "k_5873dd9e7169def3",
    "attestation": null,
    "derivation": {
     "provenance": "VERIFIED",
     "ceiling_bp": 9500,
     "track": {
      "n": 1,
      "successes": 1
     },
     "wilson_bp": null,
     "age_days": 6,
     "max_age_days": 14,
     "house_max_age_days": 14,
     "instrument_max_age_days": 30,
     "freshness_cap_bp": 4000,
     "min_track_n": 5,
     "wilson_z_milli": 1960,
     "source_present": true,
     "seller_asserted_cap_bp": 5000,
     "retracted": false,
     "contradicted": false,
     "outcome_trials": 0,
     "outcomes": {
      "verified": 0,
      "falsified": 0,
      "modified": 0,
      "counted": 0,
      "recorded": 0
     },
     "corroborations_counted": 0,
     "corroborations_discounted": 0,
     "reingest_ceiling_bp": null,
     "reingest_depth": null,
     "reingest_weakest_class": null,
     "reingest_source_confidence_bp": null,
     "ai_authored": false,
     "ai_authored_because": null,
     "ai_in_lineage": false,
     "ai_position": "ADMIT"
    },
    "memory_reason_codes": [
     {
      "code": "SPARSE_TRACK_RECORD",
      "observed": 1,
      "limit": 5,
      "binding": false
     }
    ],
    "context_line": "[VERIFIED · r=95.0% · 6d · nvd-cve:vulnerability_scan] system:CLOUDVANE-GOV-REGION-3 / vulnerability_scan: clean-at-scan"
   },
   {
    "key": "system:CLOUDVANE-GOV-REGION-3::component_provenance",
    "value": "schedule",
    "provenance": "VERIFIED",
    "source": "contract-repository:component_provenance",
    "observed_at": "2026-05-10T16:00:00.000Z",
    "last_corroborated_at": null,
    "memory_refreshed_by": [],
    "reliability": 0.95,
    "critical": true,
    "memory_id": "mem_e29e9c84fa74",
    "memory_status": "admitted",
    "memory_kind": "certificate",
    "memory_actor": "actor:sys:registry:contract-repository",
    "memory_age_days": 90,
    "memory_track": {
     "n": 1,
     "successes": 1
    },
    "memory_promoted_by": [],
    "memory_content_digest": "sha256:5a5215268a700967ccc165c44f865e2dc842606621ac09382cefe34705724a21",
    "memory_outcomes": {
     "verified": 0,
     "falsified": 0,
     "modified": 0,
     "counted": 0,
     "recorded": 0
    },
    "memory_outcome_attestations": [],
    "memory_observer_lineage": null,
    "memory_corroborations": [],
    "memory_reingest": null,
    "memory_reasons": [
     "sparse track record: 1 independent observation(s); no failure recorded, so the class ceiling stands"
    ],
    "memory_class_floor": "SELLER-ASSERTED",
    "memory_below_class_floor": false,
    "memory_not_attested": false,
    "memory_below_claim_reliability_floor": false,
    "memory_not_competent_authority": false,
    "memory_out_of_specification": false,
    "memory_ai_authored": false,
    "memory_ai_in_lineage": false,
    "memory_ai_position": "ADMIT",
    "memory_ai_inadmissible": false,
    "memory_geo_inadmissible": false,
    "memory_geo_rung": null,
    "memory_geo_metric": null,
    "memory_geo_required_metric": null,
    "observer_attested": true,
    "observer_auth_code": "VERIFIED",
    "observer_key_id": "k_1fa747666eaebac1",
    "attestation": null,
    "derivation": {
     "provenance": "VERIFIED",
     "ceiling_bp": 9500,
     "track": {
      "n": 1,
      "successes": 1
     },
     "wilson_bp": null,
     "age_days": 90,
     "max_age_days": 365,
     "house_max_age_days": 365,
     "instrument_max_age_days": null,
     "freshness_cap_bp": 4000,
     "min_track_n": 5,
     "wilson_z_milli": 1960,
     "source_present": true,
     "seller_asserted_cap_bp": 5000,
     "retracted": false,
     "contradicted": false,
     "outcome_trials": 0,
     "outcomes": {
      "verified": 0,
      "falsified": 0,
      "modified": 0,
      "counted": 0,
      "recorded": 0
     },
     "corroborations_counted": 0,
     "corroborations_discounted": 0,
     "reingest_ceiling_bp": null,
     "reingest_depth": null,
     "reingest_weakest_class": null,
     "reingest_source_confidence_bp": null,
     "min_class_floor": "SELLER-ASSERTED",
     "ai_authored": false,
     "ai_authored_because": null,
     "ai_in_lineage": false,
     "ai_position": "ADMIT"
    },
    "memory_reason_codes": [
     {
      "code": "SPARSE_TRACK_RECORD",
      "observed": 1,
      "limit": 5,
      "binding": false
     }
    ],
    "context_line": "[VERIFIED · r=95.0% · 90d · contract-repository:component_provenance] system:CLOUDVANE-GOV-REGION-3 / component_provenance: schedule"
   },
   {
    "key": "system:CLOUDVANE-GOV-REGION-3::penetration_test",
    "value": "no-critical",
    "provenance": "VERIFIED",
    "source": "LAB-NVLAP-0412:penetration_test",
    "observed_at": "2026-03-11T16:00:00.000Z",
    "last_corroborated_at": null,
    "memory_refreshed_by": [],
    "reliability": 0.95,
    "critical": true,
    "memory_id": "mem_90a2f98fe191",
    "memory_status": "admitted",
    "memory_kind": "test_report",
    "memory_actor": "actor:org:LAB-NVLAP-0412",
    "memory_age_days": 150,
    "memory_track": {
     "n": 1,
     "successes": 1
    },
    "memory_promoted_by": [],
    "memory_content_digest": "sha256:b311aa9e0ab8603002bba31e48e377d009a9cfbba410090796cfcacffcc3ec25",
    "memory_outcomes": {
     "verified": 0,
     "falsified": 0,
     "modified": 0,
     "counted": 0,
     "recorded": 0
    },
    "memory_outcome_attestations": [],
    "memory_observer_lineage": null,
    "memory_corroborations": [],
    "memory_reingest": null,
    "memory_reasons": [
     "sparse track record: 1 independent observation(s); no failure recorded, so the class ceiling stands"
    ],
    "memory_class_floor": "VERIFIED",
    "memory_below_class_floor": false,
    "memory_not_attested": false,
    "memory_below_claim_reliability_floor": false,
    "memory_not_competent_authority": false,
    "memory_out_of_specification": false,
    "memory_ai_authored": false,
    "memory_ai_in_lineage": false,
    "memory_ai_position": "ADMIT",
    "memory_ai_inadmissible": false,
    "memory_geo_inadmissible": false,
    "memory_geo_rung": null,
    "memory_geo_metric": null,
    "memory_geo_required_metric": null,
    "observer_attested": true,
    "observer_auth_code": "VERIFIED",
    "observer_key_id": "k_17d23885943ae529",
    "attestation": null,
    "derivation": {
     "provenance": "VERIFIED",
     "ceiling_bp": 9500,
     "track": {
      "n": 1,
      "successes": 1
     },
     "wilson_bp": null,
     "age_days": 150,
     "max_age_days": 180,
     "house_max_age_days": 180,
     "instrument_max_age_days": null,
     "freshness_cap_bp": 4000,
     "min_track_n": 5,
     "wilson_z_milli": 1960,
     "source_present": true,
     "seller_asserted_cap_bp": 5000,
     "retracted": false,
     "contradicted": false,
     "outcome_trials": 0,
     "outcomes": {
      "verified": 0,
      "falsified": 0,
      "modified": 0,
      "counted": 0,
      "recorded": 0
     },
     "corroborations_counted": 0,
     "corroborations_discounted": 0,
     "reingest_ceiling_bp": null,
     "reingest_depth": null,
     "reingest_weakest_class": null,
     "reingest_source_confidence_bp": null,
     "min_class_floor": "VERIFIED",
     "ai_authored": false,
     "ai_authored_because": null,
     "ai_in_lineage": false,
     "ai_position": "ADMIT"
    },
    "memory_reason_codes": [
     {
      "code": "SPARSE_TRACK_RECORD",
      "observed": 1,
      "limit": 5,
      "binding": false
     }
    ],
    "context_line": "[VERIFIED · r=95.0% · 150d · LAB-NVLAP-0412:penetration_test] system:CLOUDVANE-GOV-REGION-3 / penetration_test: no-critical"
   },
   {
    "key": "system:CLOUDVANE-GOV-REGION-3::control_assessment",
    "value": "satisfied-with-poams",
    "provenance": "VERIFIED",
    "source": "CERT-3PAO-ATLANTIC:control_assessment",
    "observed_at": "2026-04-10T16:00:00.000Z",
    "last_corroborated_at": null,
    "memory_refreshed_by": [],
    "reliability": 0.95,
    "critical": true,
    "memory_id": "mem_ecad7667d650",
    "memory_status": "admitted",
    "memory_kind": "certificate",
    "memory_actor": "actor:org:CERT-3PAO-ATLANTIC",
    "memory_age_days": 120,
    "memory_track": {
     "n": 1,
     "successes": 1
    },
    "memory_promoted_by": [],
    "memory_content_digest": "sha256:4876ae25906e54c009f92eed417815877d7ff5deabc9bff96f51cb05c1ced026",
    "memory_outcomes": {
     "verified": 0,
     "falsified": 0,
     "modified": 0,
     "counted": 0,
     "recorded": 0
    },
    "memory_outcome_attestations": [],
    "memory_observer_lineage": null,
    "memory_corroborations": [],
    "memory_reingest": null,
    "memory_reasons": [
     "sparse track record: 1 independent observation(s); no failure recorded, so the class ceiling stands"
    ],
    "memory_class_floor": "VERIFIED",
    "memory_below_class_floor": false,
    "memory_not_attested": false,
    "memory_below_claim_reliability_floor": false,
    "memory_not_competent_authority": false,
    "memory_out_of_specification": false,
    "memory_ai_authored": false,
    "memory_ai_in_lineage": false,
    "memory_ai_position": "ADMIT",
    "memory_ai_inadmissible": false,
    "memory_geo_inadmissible": false,
    "memory_geo_rung": null,
    "memory_geo_metric": null,
    "memory_geo_required_metric": null,
    "observer_attested": true,
    "observer_auth_code": "VERIFIED",
    "observer_key_id": "k_307e4bfd710ec9b3",
    "attestation": null,
    "derivation": {
     "provenance": "VERIFIED",
     "ceiling_bp": 9500,
     "track": {
      "n": 1,
      "successes": 1
     },
     "wilson_bp": null,
     "age_days": 120,
     "max_age_days": 365,
     "house_max_age_days": 365,
     "instrument_max_age_days": 365,
     "freshness_cap_bp": 4000,
     "min_track_n": 5,
     "wilson_z_milli": 1960,
     "source_present": true,
     "seller_asserted_cap_bp": 5000,
     "retracted": false,
     "contradicted": false,
     "outcome_trials": 0,
     "outcomes": {
      "verified": 0,
      "falsified": 0,
      "modified": 0,
      "counted": 0,
      "recorded": 0
     },
     "corroborations_counted": 0,
     "corroborations_discounted": 0,
     "reingest_ceiling_bp": null,
     "reingest_depth": null,
     "reingest_weakest_class": null,
     "reingest_source_confidence_bp": null,
     "min_class_floor": "VERIFIED",
     "ai_authored": false,
     "ai_authored_because": null,
     "ai_in_lineage": false,
     "ai_position": "ADMIT"
    },
    "memory_reason_codes": [
     {
      "code": "SPARSE_TRACK_RECORD",
      "observed": 1,
      "limit": 5,
      "binding": false
     }
    ],
    "context_line": "[VERIFIED · r=95.0% · 120d · CERT-3PAO-ATLANTIC:control_assessment] system:CLOUDVANE-GOV-REGION-3 / control_assessment: satisfied-with-poams"
   },
   {
    "key": "system:CLOUDVANE-GOV-REGION-3::supplier_assessment",
    "value": null,
    "provenance": "SELLER-ASSERTED",
    "source": "CLOUDVANE-GOV:supplier_assessment",
    "observed_at": "2026-06-29T16:00:00.000Z",
    "last_corroborated_at": null,
    "memory_refreshed_by": [],
    "reliability": 0.4,
    "critical": false,
    "memory_id": "mem_d33e14759cf8",
    "memory_status": "withheld",
    "memory_kind": "status",
    "memory_actor": "actor:org:CLOUDVANE-GOV",
    "memory_age_days": 40,
    "memory_track": {
     "n": 1,
     "successes": 1
    },
    "memory_promoted_by": [],
    "memory_content_digest": "sha256:bde7cbac63dcfd998e3e446beb25e8e93acf950045317f20eaf8d3e3204fc090",
    "memory_outcomes": {
     "verified": 0,
     "falsified": 0,
     "modified": 0,
     "counted": 0,
     "recorded": 0
    },
    "memory_outcome_attestations": [],
    "memory_observer_lineage": null,
    "memory_corroborations": [],
    "memory_reingest": null,
    "memory_reasons": [
     "sparse track record: 1 independent observation(s); no failure recorded, so the class ceiling stands",
     "stale field: observed 40d ago, limit 14d for kind \"status\"; reliability capped at 40%"
    ],
    "memory_class_floor": null,
    "memory_below_class_floor": false,
    "memory_not_attested": false,
    "memory_below_claim_reliability_floor": false,
    "memory_not_competent_authority": false,
    "memory_out_of_specification": false,
    "memory_ai_authored": false,
    "memory_ai_in_lineage": false,
    "memory_ai_position": "ADMIT",
    "memory_ai_inadmissible": false,
    "memory_geo_inadmissible": false,
    "memory_geo_rung": null,
    "memory_geo_metric": null,
    "memory_geo_required_metric": null,
    "observer_attested": false,
    "observer_auth_code": "NO_ENVELOPE",
    "observer_key_id": null,
    "attestation": null,
    "derivation": {
     "provenance": "SELLER-ASSERTED",
     "ceiling_bp": 5000,
     "track": {
      "n": 1,
      "successes": 1
     },
     "wilson_bp": null,
     "age_days": 40,
     "max_age_days": 14,
     "house_max_age_days": 14,
     "instrument_max_age_days": null,
     "freshness_cap_bp": 4000,
     "min_track_n": 5,
     "wilson_z_milli": 1960,
     "source_present": true,
     "seller_asserted_cap_bp": 5000,
     "retracted": false,
     "contradicted": false,
     "outcome_trials": 0,
     "outcomes": {
      "verified": 0,
      "falsified": 0,
      "modified": 0,
      "counted": 0,
      "recorded": 0
     },
     "corroborations_counted": 0,
     "corroborations_discounted": 0,
     "reingest_ceiling_bp": null,
     "reingest_depth": null,
     "reingest_weakest_class": null,
     "reingest_source_confidence_bp": null,
     "ai_authored": false,
     "ai_authored_because": null,
     "ai_in_lineage": false,
     "ai_position": "ADMIT"
    },
    "memory_reason_codes": [
     {
      "code": "SPARSE_TRACK_RECORD",
      "observed": 1,
      "limit": 5,
      "binding": false
     },
     {
      "code": "STALE_FIELD",
      "observed": 40,
      "limit": 14,
      "cap_bp": 4000,
      "resulting_bp": 4000,
      "binding": true
     }
    ]
   },
   {
    "key": "system:CLOUDVANE-GOV-REGION-3::supplier_assessment",
    "value": null,
    "provenance": "MISSING",
    "source": null,
    "observed_at": "2026-08-08T16:00:00.000Z",
    "reliability": 0,
    "critical": true,
    "memory_status": "coverage_gap",
    "gap_cause": "EVIDENCE_PRESENTED_FAILED",
    "gap_request": null,
    "gap_origin": "BUSINESS_EVIDENCE",
    "gap_conditions": []
   }
  ],
  "serialization": {
   "algorithm": "RFC8785-JCS",
   "hash": "sha256"
  },
  "crypto_suite": {
   "spec": "corobate:suite:1",
   "id": "CB-1-ES256-SHA256",
   "receipt_digest": "sha256",
   "chain_digest": "sha256",
   "content_digest": "sha256",
   "envelope_signature": "ES256",
   "signature_curve": "P-256",
   "canonicalisation": "attest-canon/2",
   "quantum_resistant": false
  },
  "confidence": {
   "value": 0,
   "method": "min-over-critical-inputs",
   "bound_by": "system:CLOUDVANE-GOV-REGION-3::supplier_assessment"
  },
  "verdict": {
   "value": "WITHHELD",
   "threshold_approve": 0.9,
   "threshold_caution": 0.7,
   "rule": "confidence>=threshold"
  },
  "release": {
   "required": false,
   "required_by_tier": false,
   "escalated_by_acceptance": false,
   "risk_accepted": false,
   "state": "WITHHELD_NO_EVIDENCE",
   "code": "QUORUM_EVIDENCE_WITHHELD",
   "reason": "the evidence did not clear the threshold for this exposure, so there is nothing to release. Signatures do not substitute for evidence, and this state is deliberately distinct from WITHHELD_PENDING_SIGNATURES: a reader must be able to tell \"the evidence is not there\" from \"the evidence is there and 0 of 2 people have signed\".",
   "tier_floor_cents": 1000000000,
   "exposure_usd_cents": 220000000,
   "required_m": 2,
   "declared_n": 3,
   "floor_m": 2,
   "distinct_signers": 0,
   "superseded": 0,
   "collapsed": 0,
   "release_digest": "sha256:8ef23045c8d8714e4d68ec83739091959dcb5765515b96c8c66ebbf99a4558ec",
   "governance_digest": "sha256:8b0a45a27fcce9c1c243c764e855e67c6fe6dfd7f02a563bd90809b419731905",
   "governance_signed": true,
   "counted_voices": [],
   "signatures": [],
   "ledger_seq": null
  },
  "acceptance": {
   "state": "NONE",
   "code": "ACCEPTANCE_NONE",
   "reason": "no risk acceptance was presented for this decision. This is the ordinary case: a refusal is a refusal unless a named person has priced it.",
   "permitted_basis": null,
   "presented": 0,
   "superseded": 0,
   "expired": 0,
   "gaps_not_covered": 0,
   "coverage_gaps_in_force": [
    "system:CLOUDVANE-GOV-REGION-3|supplier_assessment"
   ],
   "evidentiary_digest": "sha256:8ef23045c8d8714e4d68ec83739091959dcb5765515b96c8c66ebbf99a4558ec",
   "margin_floor_bp": 100,
   "authority_ceiling_cents": {
    "SUPERVISOR": 1000000,
    "MANAGER": 25000000,
    "DIRECTOR": 500000000,
    "OFFICER": 5000000000
   },
   "acceptances": [],
   "escalated": false,
   "live": false,
   "ledger_seq": null
  },
  "regulatory": {
   "spec": "corobate:regulatory:2",
   "resolved": true,
   "applied": [
    {
     "instrument_id": "nist-sp-800-53r5-moderate",
     "version": 5,
     "authority": "National Institute of Standards and Technology",
     "instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
     "edition": "Rev. 5",
     "citation": "CA-2, CA-8, RA-5, SR-6 [VERIFY]",
     "source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353",
     "entered_by": "actor:human:issm",
     "entered_at": "2026-08-08T16:00:00.000Z"
    },
    {
     "instrument_id": "nist-sp-800-161r1-cscrm",
     "version": 1,
     "authority": "National Institute of Standards and Technology",
     "instrument": "SP 800-161 Rev. 1 — C-SCRM Practices for Systems and Organizations",
     "edition": "Rev. 1",
     "citation": "SR-3, SR-4, SR-11 [VERIFY]",
     "source_digest": "sha256:6161616161616161616161616161616161616161616161616161616161616161",
     "entered_by": "actor:human:issm",
     "entered_at": "2026-08-08T16:00:00.000Z"
    }
   ],
   "skipped": [],
   "conflicts": [],
   "bindings": [
    {
     "claim": "component_provenance",
     "requirement": "min_class",
     "value": "SELLER-ASSERTED",
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-161 Rev. 1 — C-SCRM Practices for Systems and Organizations",
      "instrument_id": "nist-sp-800-161r1-cscrm",
      "version": 1,
      "edition": "Rev. 1",
      "citation": "SR-4 [VERIFY]",
      "source_digest": "sha256:6161616161616161616161616161616161616161616161616161616161616161"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "component_provenance",
     "requirement": "required",
     "value": true,
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-161 Rev. 1 — C-SCRM Practices for Systems and Organizations",
      "instrument_id": "nist-sp-800-161r1-cscrm",
      "version": 1,
      "edition": "Rev. 1",
      "citation": "SR-4 provenance [VERIFY]",
      "source_digest": "sha256:6161616161616161616161616161616161616161616161616161616161616161"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "control_assessment",
     "requirement": "max_age_days",
     "value": 365,
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
      "instrument_id": "nist-sp-800-53r5-moderate",
      "version": 5,
      "edition": "Rev. 5",
      "citation": "CA-2 [VERIFY]",
      "source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "control_assessment",
     "requirement": "min_class",
     "value": "VERIFIED",
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
      "instrument_id": "nist-sp-800-53r5-moderate",
      "version": 5,
      "edition": "Rev. 5",
      "citation": "CA-2(1) independent assessors [VERIFY]",
      "source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "control_assessment",
     "requirement": "required",
     "value": true,
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
      "instrument_id": "nist-sp-800-53r5-moderate",
      "version": 5,
      "edition": "Rev. 5",
      "citation": "CA-2 [VERIFY]",
      "source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "penetration_test",
     "requirement": "min_class",
     "value": "VERIFIED",
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
      "instrument_id": "nist-sp-800-53r5-moderate",
      "version": 5,
      "edition": "Rev. 5",
      "citation": "CA-8(1) independent penetration agent [VERIFY]",
      "source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "penetration_test",
     "requirement": "required",
     "value": true,
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
      "instrument_id": "nist-sp-800-53r5-moderate",
      "version": 5,
      "edition": "Rev. 5",
      "citation": "CA-8 [VERIFY]",
      "source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "supplier_assessment",
     "requirement": "required",
     "value": true,
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-161 Rev. 1 — C-SCRM Practices for Systems and Organizations",
      "instrument_id": "nist-sp-800-161r1-cscrm",
      "version": 1,
      "edition": "Rev. 1",
      "citation": "SR-6 [VERIFY]",
      "source_digest": "sha256:6161616161616161616161616161616161616161616161616161616161616161"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "vulnerability_scan",
     "requirement": "max_age_days",
     "value": 30,
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
      "instrument_id": "nist-sp-800-53r5-moderate",
      "version": 5,
      "edition": "Rev. 5",
      "citation": "RA-5(a) [VERIFY]",
      "source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "vulnerability_scan",
     "requirement": "required",
     "value": true,
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
      "instrument_id": "nist-sp-800-53r5-moderate",
      "version": 5,
      "edition": "Rev. 5",
      "citation": "RA-5 [VERIFY]",
      "source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    }
   ],
   "defaults": [
    {
     "claim": "component_provenance",
     "requirement": "ai_position",
     "value": "ADMIT",
     "because": "No instrument in force stated a position on AI-authored evidence for \"component_provenance\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
    },
    {
     "claim": "control_assessment",
     "requirement": "ai_position",
     "value": "ADMIT",
     "because": "No instrument in force stated a position on AI-authored evidence for \"control_assessment\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
    },
    {
     "claim": "penetration_test",
     "requirement": "ai_position",
     "value": "ADMIT",
     "because": "No instrument in force stated a position on AI-authored evidence for \"penetration_test\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
    },
    {
     "claim": "supplier_assessment",
     "requirement": "ai_position",
     "value": "ADMIT",
     "because": "No instrument in force stated a position on AI-authored evidence for \"supplier_assessment\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
    },
    {
     "claim": "vulnerability_scan",
     "requirement": "ai_position",
     "value": "ADMIT",
     "because": "No instrument in force stated a position on AI-authored evidence for \"vulnerability_scan\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
    }
   ]
  },
  "reasons": [
   "Coverage gap: no admissible memory for required claim(s) system:CLOUDVANE-GOV-REGION-3|supplier_assessment.",
   "Confidence 0.00% is bound by \"system:CLOUDVANE-GOV-REGION-3|supplier_assessment\".",
   "1 memory was withheld from the context block: system:CLOUDVANE-GOV-REGION-3|supplier_assessment (sparse track record: 1 independent observation(s); no failure recorded, so the class ceiling stands).",
   "Thresholds for $2,200,000 exposure: approve 90%, caution 70%."
  ],
  "memory": {
   "layer": "capture->store->recall->act",
   "ledger_head": "sha256:5bbeec39ca2744b408818488f7595e4b119e254325fd84642a3c66c636794c9c",
   "ledger_entries": 7,
   "context_digest": null,
   "context_memory_ids": [],
   "state_digest": "sha256:01827de72fd2a97521310c759fdc925c1c51ca2f43949aa72b79b19221e6ff88",
   "retrieval_method": "idf-lexical",
   "corpus_size": 5,
   "considered": 5,
   "admitted": 4,
   "withheld": 1,
   "not_considered": 0,
   "coverage_gaps": [
    "system:CLOUDVANE-GOV-REGION-3|supplier_assessment"
   ],
   "exposure": {
    "usd": 2200000,
    "declared_by": "actor:human:ao-authorizing-official",
    "ledger_seq": 5
   },
   "salience_policy": {
    "half_life_days": 90,
    "grace_days": 7,
    "access_boost_bp": 500,
    "access_boost_cap_bp": 2500,
    "relevance_weight_bp": 6000,
    "recency_weight_bp": 3000,
    "usage_weight_bp": 1000,
    "context_cap": 12,
    "method": "idf-lexical",
    "candidate_list_digest": "sha256:a0a517898454c11e39c80e688bd1f37bd556d635f7242d58d4a695ae3443279d",
    "note": "salience orders retrieval only; it never contributes to reliability"
   },
   "policy_digest": "sha256:a6b69b7d20f7fb04d522364af1d92992058b04a5835fcec9d1c9f2261c7ef636",
   "policy_body": {
    "class_ceiling_bp": {
     "VERIFIED": 9500,
     "MODELED": 8000,
     "SELLER-ASSERTED": 5000,
     "MISSING": 0
    },
    "actor_class_ceiling": [
     [
      "^actor:ai:",
      "MODELED"
     ],
     [
      "^actor:agent:",
      "MODELED"
     ],
     [
      "^actor:human:",
      "SELLER-ASSERTED"
     ],
     [
      "^actor:org:LAB-",
      "VERIFIED"
     ],
     [
      "^actor:org:CERT-",
      "VERIFIED"
     ],
     [
      "^actor:org:",
      "SELLER-ASSERTED"
     ],
     [
      "^actor:sys:registry:",
      "VERIFIED"
     ],
     [
      "^actor:sys:sensor:",
      "VERIFIED"
     ],
     [
      "^actor:sys:",
      "MODELED"
     ]
    ],
    "freshness_cap_bp": 4000,
    "max_age_days": {
     "telemetry": 1,
     "price": 7,
     "status": 14,
     "certificate": 365,
     "test_report": 180,
     "filing": 90,
     "transcript": 120,
     "highlight": 365,
     "voice_note": 120,
     "note": 365,
     "preference": 540,
     "decision": 1825,
     "receipt": 365,
     "default": 90
    },
    "wilson_z_milli": 1960,
    "min_track_n": 5,
    "exposure_tiers_bp": [
     [
      1000000000,
      9500,
      8000
     ],
     [
      100000000,
      9000,
      7000
     ],
     [
      1000000,
      8500,
      6000
     ],
     [
      0,
      8000,
      5000
     ]
    ],
    "max_context_memories": 12,
    "contradiction_resolve_margin": 2,
    "salience": {
     "half_life_days": 90,
     "grace_days": 7,
     "access_boost_bp": 500,
     "access_boost_cap_bp": 2500,
     "relevance_weight_bp": 6000,
     "recency_weight_bp": 3000,
     "usage_weight_bp": 1000
    }
   },
   "observer_auth": {
    "mode": "required",
    "registry_version": 3,
    "registry_digest": "sha256:460aeaafe345f69542a302e6619dff0712af98de6518838ee4c8585e448c3a7d",
    "entries_root": "sha256:5670469f96484a814462814ed74f0f992b5f19e8ad6afced548e4956e4835ba5",
    "memberships": [
     {
      "key_id": "k_17d23885943ae529",
      "index": 1,
      "entry": {
       "actor": "actor:org:LAB-NVLAP-0412",
       "class": "VERIFIED",
       "kind": "org",
       "key_id": "k_17d23885943ae529",
       "jwk": {
        "kty": "EC",
        "crv": "P-256",
        "x": "3TTw47-PkYfo3ZaKTq_qtHghnGvninAVj25kyOwONno",
        "y": "16PMaR8ofeF5IcZk6ZLml8gDs8uE1s1sBLdciH5e4vg"
       },
       "valid_from": "2025-01-01T00:00:00.000Z",
       "valid_to": "2027-06-01T00:00:00.000Z"
      },
      "path": [
       {
        "side": "left",
        "sibling": "sha256:500f2ba5949d5256ae0f563530b0b270db41ce99d2d7c4b4b60e4bd558ca353d"
       },
       {
        "side": "right",
        "sibling": "sha256:a0b47ea437bf4f1042a1dd50a5a3f411f9a17971812fc6bafccd434eb7d78ccc"
       },
       {
        "side": "right",
        "sibling": "sha256:d3c2347eb675e865fc17ef0204cacda7b02e8784a811fdd1c8a015d1865e6dfb"
       },
       {
        "side": "right",
        "sibling": "sha256:7071adf5e21a94147d31f42f1028b4867b6562e5b78726259c2515b03b213e52"
       }
      ]
     },
     {
      "key_id": "k_1fa747666eaebac1",
      "index": 3,
      "entry": {
       "actor": "actor:sys:registry:contract-repository",
       "class": "VERIFIED",
       "kind": "system",
       "key_id": "k_1fa747666eaebac1",
       "jwk": {
        "kty": "EC",
        "crv": "P-256",
        "x": "41rFxJFoXZce5-6xjOTknC2gQCVb0skbk4cmn1olvNQ",
        "y": "4hEvB6nrEDYLOe5NUMev83ShXuBe_KwoDZiYjFAAN1c"
       },
       "valid_from": "2025-01-01T00:00:00.000Z",
       "valid_to": "2027-06-01T00:00:00.000Z"
      },
      "path": [
       {
        "side": "left",
        "sibling": "sha256:e2e716026353b5cc8c43a2af49ee6dc31d111d1ec3f275262d0c4601ae124c27"
       },
       {
        "side": "left",
        "sibling": "sha256:e8b9cba101f13538b909a2e686e9e6e9a8d77212036ed567eaebc205a443e83f"
       },
       {
        "side": "right",
        "sibling": "sha256:d3c2347eb675e865fc17ef0204cacda7b02e8784a811fdd1c8a015d1865e6dfb"
       },
       {
        "side": "right",
        "sibling": "sha256:7071adf5e21a94147d31f42f1028b4867b6562e5b78726259c2515b03b213e52"
       }
      ]
     },
     {
      "key_id": "k_307e4bfd710ec9b3",
      "index": 0,
      "entry": {
       "actor": "actor:org:CERT-3PAO-ATLANTIC",
       "class": "VERIFIED",
       "kind": "org",
       "key_id": "k_307e4bfd710ec9b3",
       "jwk": {
        "kty": "EC",
        "crv": "P-256",
        "x": "MGtV26TezLMPjiD3SecQtnje6eLqYyx4qkKzzAkbiY4",
        "y": "SMMdLYnn-FpKbb2sJQ8EAZnzvozNm-cGO0VbUUpniPY"
       },
       "valid_from": "2025-01-01T00:00:00.000Z",
       "valid_to": "2027-06-01T00:00:00.000Z"
      },
      "path": [
       {
        "side": "right",
        "sibling": "sha256:4148869fc259d2c5fc19fe5831065b165a9acf81812e123162035acfdecade1d"
       },
       {
        "side": "right",
        "sibling": "sha256:a0b47ea437bf4f1042a1dd50a5a3f411f9a17971812fc6bafccd434eb7d78ccc"
       },
       {
        "side": "right",
        "sibling": "sha256:d3c2347eb675e865fc17ef0204cacda7b02e8784a811fdd1c8a015d1865e6dfb"
       },
       {
        "side": "right",
        "sibling": "sha256:7071adf5e21a94147d31f42f1028b4867b6562e5b78726259c2515b03b213e52"
       }
      ]
     },
     {
      "key_id": "k_5873dd9e7169def3",
      "index": 2,
      "entry": {
       "actor": "actor:sys:registry:nvd-cve",
       "class": "VERIFIED",
       "kind": "system",
       "key_id": "k_5873dd9e7169def3",
       "jwk": {
        "kty": "EC",
        "crv": "P-256",
        "x": "O9OY6oMuJg0df_INePO19_3b11VaSyMwIPdxoqvV2ak",
        "y": "k7Orm5pxDxMdTF-H2S4h6ixRywzk1WxvquOQeqxLFx0"
       },
       "valid_from": "2025-01-01T00:00:00.000Z",
       "valid_to": "2027-06-01T00:00:00.000Z"
      },
      "path": [
       {
        "side": "right",
        "sibling": "sha256:e1fe36fe7c8e4695327c25d6d722630b6249c93293bfdc5894c58aaf961ab6f8"
       },
       {
        "side": "left",
        "sibling": "sha256:e8b9cba101f13538b909a2e686e9e6e9a8d77212036ed567eaebc205a443e83f"
       },
       {
        "side": "right",
        "sibling": "sha256:d3c2347eb675e865fc17ef0204cacda7b02e8784a811fdd1c8a015d1865e6dfb"
       },
       {
        "side": "right",
        "sibling": "sha256:7071adf5e21a94147d31f42f1028b4867b6562e5b78726259c2515b03b213e52"
       }
      ]
     }
    ],
    "memberships_unproven": [],
    "revocation": {
     "source": "SIGNED_LIST",
     "digest": "sha256:12f73b1fbf27d38cf137b86a1ce13bbcd98161123a6aa7d79b107db8189966b9",
     "sequence": 5,
     "registry_version": 3,
     "issued_at": "2026-08-06T00:00:00.000Z",
     "next_update_due": "2026-08-13T00:00:00.000Z",
     "entry_count": 0,
     "body": {
      "sequence": 5,
      "registry_version": 3,
      "issuer": {
       "name": "NIST-regulated enterprise demonstration trust root",
       "key_id": "k_3793b8e35f8acac1"
      },
      "issued_at": "2026-08-06T00:00:00.000Z",
      "next_update_due": "2026-08-13T00:00:00.000Z",
      "entries": [],
      "spec": "corobate:revocation-list:1"
     }
    }
   },
   "governance": {
    "digest": "sha256:8b0a45a27fcce9c1c243c764e855e67c6fe6dfd7f02a563bd90809b419731905",
    "signed": true,
    "actor_trust": "FLOOR_TO_SELLER_ASSERTED",
    "outcome_trial_weight": 1,
    "max_reingest_depth": 3,
    "release_quorum_m": 2,
    "release_quorum_n": 3,
    "risk_acceptance_margin_bp": 500,
    "risk_acceptance_max_days": 30,
    "risk_acceptance_authority_cents": {
     "SUPERVISOR": 1000000,
     "MANAGER": 25000000,
     "DIRECTOR": 500000000,
     "OFFICER": 5000000000
    },
    "template_author_roles": [
     "MANAGER",
     "DIRECTOR",
     "OFFICER"
    ]
   },
   "observers_attested": 4,
   "outcomes": {
    "attestations_counted": 0,
    "attestations_recorded": 0,
    "records_with_outcomes": 0
   },
   "lineage": {
    "corroborations_counted": 0,
    "corroborations_discounted": 0,
    "records_with_discounted_corroborations": 0
   },
   "reingest": {
    "records": 0,
    "max_depth": 0,
    "weakest_class": null,
    "chain_weakest_bp": 10000,
    "chain": []
   },
   "template": null
  }
 }
}

Two NIST publications require component provenance and they require it at different strengths. The bill of materials is genuine, produced by the build, and it is still the producer describing its own product — so at this exposure it does not carry the requirement on its own.

Subject
release:PLATFORM-CORE-2026.8.0
Question
May this release be published to the government-facing environment?
Exposure
$640,000
Instruments
National Institute of Standards and Technology · National Institute of Standards and Technology
Outcome
WITHHELD — the action is not permitted; outstanding: code review, component provenance
Receipt
sha256:90a20c5dcda8ab70e32d7b08521e24e2f271d03ac079f47c2a047dfd3ed9cb4c
Fourth party
68 components ingested from a CycloneDX 1.5 bill of materials · sha256:e4daced4f23c89e…
The gate variables this decision ran under — a dial per question, read back off the sealed receipt
code reviewrequired
necessity
requiredNational Institute of Standards and Technology — PW.7 [VERIFY]
staleness
90 daysNo instrument set an age limit for this claim, so the deploying organisation's own freshness policy binds at 90 days. It is not unlimited.
reputation class
No class floor was set, so the seller's own assertion is admissible for this claim up to the ceiling that class carries. That is a setting, not an absence.
reputation record
No reliability floor beyond the exposure tier's own threshold, which still binds.
completion
No satisfaction window was set. The requirement is due now: there is no period in which it may be outstanding, and nothing proceeds without it.
ai provenance
admitNo instrument in force stated a position on AI-authored evidence for "code_review". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway.
component provenancerequired
necessity
requiredNational Institute of Standards and Technology — PS.3.2 [VERIFY]
staleness
90 daysNo instrument set an age limit for this claim, so the deploying organisation's own freshness policy binds at 90 days. It is not unlimited.
reputation class
seller-assertedNational Institute of Standards and Technology — SR-4 [VERIFY]
reputation record
No reliability floor beyond the exposure tier's own threshold, which still binds.
completion
No satisfaction window was set. The requirement is due now: there is no period in which it may be outstanding, and nothing proceeds without it.
ai provenance
admitNo instrument in force stated a position on AI-authored evidence for "component_provenance". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway.
release integrity mechanismrequired never waivable
necessity
required never waivableNational Institute of Standards and Technology — PS.2 [VERIFY]
staleness
90 daysNo instrument set an age limit for this claim, so the deploying organisation's own freshness policy binds at 90 days. It is not unlimited.
reputation class
verifiedNational Institute of Standards and Technology — PS.2 [VERIFY]
reputation record
No reliability floor beyond the exposure tier's own threshold, which still binds.
completion
No satisfaction window was set. The requirement is due now: there is no period in which it may be outstanding, and nothing proceeds without it.
ai provenance
admitNo instrument in force stated a position on AI-authored evidence for "release_integrity_mechanism". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway.
supplier assessmentrequired
necessity
requiredNational Institute of Standards and Technology — SR-6 [VERIFY]
staleness
90 daysNo instrument set an age limit for this claim, so the deploying organisation's own freshness policy binds at 90 days. It is not unlimited.
reputation class
No class floor was set, so the seller's own assertion is admissible for this claim up to the ceiling that class carries. That is a setting, not an absence.
reputation record
No reliability floor beyond the exposure tier's own threshold, which still binds.
completion
No satisfaction window was set. The requirement is due now: there is no period in which it may be outstanding, and nothing proceeds without it.
ai provenance
admitNo instrument in force stated a position on AI-authored evidence for "supplier_assessment". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway.

Every bar above was re-derived from the regulatory bindings inside this receipt’s hashed body, not from the configuration that produced it. A bar in grey is a setting no instrument made — the deploying organisation’s own default, which still binds and is not an absence. A bar position renders an ordinal on a declared ladder: it is a way to draw a control and to compare two settings on the same axis, and it is not a measurement. The value printed beside each bar is the authoritative one.

Whoever must act now

The engineer with the deployment in their hands, the release manager, the person who must publish or hold.

One instruction and the reason in words. No score, no money, no signatures.

DO NOT PROCEED
release:PLATFORM-CORE-2026.8.0
Missing or out of date: code review, component provenance

Seven or eight fields, and not one of them is a number somebody can argue with. This person is not being asked to re-judge the evidence; somebody already did, and it is on the record.

The scoped copy itself — partial — something outside this role’s remit was removed
FAITHFUL digest sha256:d06346a284746171de8dc76beb511144a8edd0f0e33aa231cd18f9e1be8c85eb matches the commitment sealed in the receipt.
{
 "spec": "corobate:role-view:2",
 "role": "OPERATOR",
 "purpose": "Whoever must act on this decision now — release the goods, fund the draw, dispatch the agent, ship the title. Sees one instruction and the reason in plain words, and nothing that could be argued about while somebody waits.",
 "is_a_receipt": false,
 "warning": "This is a SCOPED COPY of a sealed decision, not the decision record itself. It will not verify as a receipt and must not be presented as one. To confirm it is faithful, recompute its `view` digest under the same canonicalisation that produces receipt_hash and compare it with the entry for this role in the source receipt’s `views` block.",
 "derived_from": {
  "receipt_hash": "sha256:90a20c5dcda8ab70e32d7b08521e24e2f271d03ac079f47c2a047dfd3ed9cb4c",
  "entry_hash": "sha256:62842a7dbe06d36b693bfd2f62a3c8123aede49a1a9092bc52a75f26ff260df5",
  "issued_at": "2026-08-08T16:00:00.000Z"
 },
 "view_digest": "sha256:d06346a284746171de8dc76beb511144a8edd0f0e33aa231cd18f9e1be8c85eb",
 "withheld": {
  "anything_withheld": true,
  "note": "Facts outside this role’s remit were removed. That something was removed is stated so a partial record is never mistaken for a complete one. How much, and what, is not stated — a count is an inference about the part you are not entitled to see."
 },
 "view": {
  "spec": "urn:ietf:params:corobate:receipt:1",
  "receipt_version": "1.8",
  "issued_at": "2026-08-08T16:00:00.000Z",
  "decision": {
   "id": "rel_PLATFORM_2026_8_0",
   "subject": "release:PLATFORM-CORE-2026.8.0"
  },
  "memory": {
   "state_digest": "sha256:b69314201d2e10631d7179b82717dd6079b7dc7408b3ee37281eb56729ce59f2",
   "ledger_head": "sha256:fdadc9eed6746ad514ec9f681a2910b2fa04006a84e45cb24a08e5bdcd9e97b3",
   "coverage_gaps": [
    "release:PLATFORM-CORE-2026.8.0|code_review",
    "release:PLATFORM-CORE-2026.8.0|component_provenance"
   ]
  },
  "verdict": {
   "value": "WITHHELD"
  },
  "release": {
   "state": "WITHHELD_NO_EVIDENCE"
  }
 }
}

Provider / assessed party

The cloud service provider, the release team, or the party operating the AI system — whoever is being assessed.

Sees which controls were required of them and by which publication and control identifier. Does not see the authorising official’s exposure figure or how any shortfall was priced.

What is outstanding on your file

  • code review — required by National Institute of Standards and Technology, PW.7 [VERIFY]
  • component provenance — required by National Institute of Standards and Technology, PS.3.2 [VERIFY]
ClaimRequiredEvidence classWhoAgeOutcome
release_integrity_mechanismyesVERIFIED2026-05-30admitted
supplier_assessmentyesVERIFIED2026-01-20admitted
code_reviewnoSELLER-ASSERTED2026-08-06withheld
component_provenancenoSELLER-ASSERTED2026-08-07withheld
code_reviewyesMISSING2026-08-08coverage gap
component_provenanceyesMISSING2026-08-08coverage gap

The clause is here because it turns an argument into an errand. What is not here: what the bank had at stake, and whether anyone priced the shortfall.

The scoped copy itself — partial — something outside this role’s remit was removed
FAITHFUL digest sha256:0535e361c75eb51ca23b8063e86fda7be235ab66839af88fc2bc1920588ed492 matches the commitment sealed in the receipt.
{
 "spec": "corobate:role-view:2",
 "role": "SUPPLIER",
 "purpose": "The party whose evidence was judged. Sees every claim the decision required, which fell short, and the clause that required it — and nothing about what the buyer had at stake or how the buyer priced any shortfall. NOTE, because an earlier draft of this sentence was untrue: this projection carries the WHOLE inputs array, so where several parties supplied evidence for one decision, each of them sees all of it. Per-party scoping cannot be expressed by a commitment scheme with one digest per role, and claiming it anyway would be the kind of promise this file exists to stop making.",
 "is_a_receipt": false,
 "warning": "This is a SCOPED COPY of a sealed decision, not the decision record itself. It will not verify as a receipt and must not be presented as one. To confirm it is faithful, recompute its `view` digest under the same canonicalisation that produces receipt_hash and compare it with the entry for this role in the source receipt’s `views` block.",
 "derived_from": {
  "receipt_hash": "sha256:90a20c5dcda8ab70e32d7b08521e24e2f271d03ac079f47c2a047dfd3ed9cb4c",
  "entry_hash": "sha256:62842a7dbe06d36b693bfd2f62a3c8123aede49a1a9092bc52a75f26ff260df5",
  "issued_at": "2026-08-08T16:00:00.000Z"
 },
 "view_digest": "sha256:0535e361c75eb51ca23b8063e86fda7be235ab66839af88fc2bc1920588ed492",
 "withheld": {
  "anything_withheld": true,
  "note": "Facts outside this role’s remit were removed. That something was removed is stated so a partial record is never mistaken for a complete one. How much, and what, is not stated — a count is an inference about the part you are not entitled to see."
 },
 "view": {
  "spec": "urn:ietf:params:corobate:receipt:1",
  "receipt_version": "1.8",
  "issued_at": "2026-08-08T16:00:00.000Z",
  "decision": {
   "id": "rel_PLATFORM_2026_8_0",
   "subject": "release:PLATFORM-CORE-2026.8.0",
   "question": "May this release be published to the government-facing environment?"
  },
  "memory": {
   "state_digest": "sha256:b69314201d2e10631d7179b82717dd6079b7dc7408b3ee37281eb56729ce59f2",
   "ledger_head": "sha256:fdadc9eed6746ad514ec9f681a2910b2fa04006a84e45cb24a08e5bdcd9e97b3",
   "coverage_gaps": [
    "release:PLATFORM-CORE-2026.8.0|code_review",
    "release:PLATFORM-CORE-2026.8.0|component_provenance"
   ]
  },
  "verdict": {
   "value": "WITHHELD"
  },
  "inputs": [
   {
    "key": "release:PLATFORM-CORE-2026.8.0::release_integrity_mechanism",
    "provenance": "VERIFIED",
    "observed_at": "2026-05-30T16:00:00.000Z",
    "memory_status": "admitted",
    "critical": true
   },
   {
    "key": "release:PLATFORM-CORE-2026.8.0::supplier_assessment",
    "provenance": "VERIFIED",
    "observed_at": "2026-01-20T16:00:00.000Z",
    "memory_status": "admitted",
    "critical": true
   },
   {
    "key": "release:PLATFORM-CORE-2026.8.0::code_review",
    "provenance": "SELLER-ASSERTED",
    "observed_at": "2026-08-06T16:00:00.000Z",
    "memory_status": "withheld",
    "critical": false
   },
   {
    "key": "release:PLATFORM-CORE-2026.8.0::component_provenance",
    "provenance": "SELLER-ASSERTED",
    "observed_at": "2026-08-07T16:00:00.000Z",
    "memory_status": "withheld",
    "critical": false
   },
   {
    "key": "release:PLATFORM-CORE-2026.8.0::code_review",
    "provenance": "MISSING",
    "observed_at": "2026-08-08T16:00:00.000Z",
    "memory_status": "coverage_gap",
    "critical": true
   },
   {
    "key": "release:PLATFORM-CORE-2026.8.0::component_provenance",
    "provenance": "MISSING",
    "observed_at": "2026-08-08T16:00:00.000Z",
    "memory_status": "coverage_gap",
    "critical": true
   }
  ],
  "regulatory": {
   "bindings": [
    {
     "claim": "code_review",
     "requirement": "required",
     "value": true,
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-218 — Secure Software Development Framework v1.1",
      "instrument_id": "nist-sp-800-218-ssdf",
      "version": 1,
      "edition": "1.1",
      "citation": "PW.7 [VERIFY]",
      "source_digest": "sha256:1818181818181818181818181818181818181818181818181818181818181818"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "component_provenance",
     "requirement": "min_class",
     "value": "SELLER-ASSERTED",
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-161 Rev. 1 — C-SCRM Practices for Systems and Organizations",
      "instrument_id": "nist-sp-800-161r1-cscrm",
      "version": 1,
      "edition": "Rev. 1",
      "citation": "SR-4 [VERIFY]",
      "source_digest": "sha256:6161616161616161616161616161616161616161616161616161616161616161"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "component_provenance",
     "requirement": "required",
     "value": true,
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-218 — Secure Software Development Framework v1.1",
      "instrument_id": "nist-sp-800-218-ssdf",
      "version": 1,
      "edition": "1.1",
      "citation": "PS.3.2 [VERIFY]",
      "source_digest": "sha256:1818181818181818181818181818181818181818181818181818181818181818"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "release_integrity_mechanism",
     "requirement": "min_class",
     "value": "VERIFIED",
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-218 — Secure Software Development Framework v1.1",
      "instrument_id": "nist-sp-800-218-ssdf",
      "version": 1,
      "edition": "1.1",
      "citation": "PS.2 [VERIFY]",
      "source_digest": "sha256:1818181818181818181818181818181818181818181818181818181818181818"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "release_integrity_mechanism",
     "requirement": "never_waivable",
     "value": true,
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-218 — Secure Software Development Framework v1.1",
      "instrument_id": "nist-sp-800-218-ssdf",
      "version": 1,
      "edition": "1.1",
      "citation": "PS.2 [VERIFY]",
      "source_digest": "sha256:1818181818181818181818181818181818181818181818181818181818181818"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "release_integrity_mechanism",
     "requirement": "required",
     "value": true,
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-218 — Secure Software Development Framework v1.1",
      "instrument_id": "nist-sp-800-218-ssdf",
      "version": 1,
      "edition": "1.1",
      "citation": "PS.2 [VERIFY]",
      "source_digest": "sha256:1818181818181818181818181818181818181818181818181818181818181818"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "supplier_assessment",
     "requirement": "required",
     "value": true,
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-161 Rev. 1 — C-SCRM Practices for Systems and Organizations",
      "instrument_id": "nist-sp-800-161r1-cscrm",
      "version": 1,
      "edition": "Rev. 1",
      "citation": "SR-6 [VERIFY]",
      "source_digest": "sha256:6161616161616161616161616161616161616161616161616161616161616161"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    }
   ],
   "applied": [
    {
     "instrument_id": "nist-sp-800-218-ssdf",
     "version": 1,
     "authority": "National Institute of Standards and Technology",
     "instrument": "SP 800-218 — Secure Software Development Framework v1.1",
     "edition": "1.1",
     "citation": "PS.3.2, PS.2, PW.7 [VERIFY]",
     "source_digest": "sha256:1818181818181818181818181818181818181818181818181818181818181818",
     "entered_by": "actor:human:issm",
     "entered_at": "2026-08-08T16:00:00.000Z"
    },
    {
     "instrument_id": "nist-sp-800-161r1-cscrm",
     "version": 1,
     "authority": "National Institute of Standards and Technology",
     "instrument": "SP 800-161 Rev. 1 — C-SCRM Practices for Systems and Organizations",
     "edition": "Rev. 1",
     "citation": "SR-3, SR-4, SR-11 [VERIFY]",
     "source_digest": "sha256:6161616161616161616161616161616161616161616161616161616161616161",
     "entered_by": "actor:human:issm",
     "entered_at": "2026-08-08T16:00:00.000Z"
    }
   ],
   "defaults": [
    {
     "claim": "code_review",
     "requirement": "ai_position",
     "value": "ADMIT",
     "because": "No instrument in force stated a position on AI-authored evidence for \"code_review\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
    },
    {
     "claim": "component_provenance",
     "requirement": "ai_position",
     "value": "ADMIT",
     "because": "No instrument in force stated a position on AI-authored evidence for \"component_provenance\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
    },
    {
     "claim": "release_integrity_mechanism",
     "requirement": "ai_position",
     "value": "ADMIT",
     "because": "No instrument in force stated a position on AI-authored evidence for \"release_integrity_mechanism\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
    },
    {
     "claim": "supplier_assessment",
     "requirement": "ai_position",
     "value": "ADMIT",
     "because": "No instrument in force stated a position on AI-authored evidence for \"supplier_assessment\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
    }
   ]
  }
 }
}

Assessor / authorising official

A third-party assessment organisation, an agency assessor, or an inspector general reviewing the package. Same position as a customs officer: a public mandate over the record.

The control record in full — each publication by control identifier, edition and document digest, and every required claim with who supplied it and when. No exposure figure, no risk pricing, no confidence score.

National Institute of Standards and Technology
SP 800-218 — Secure Software Development Framework v1.1
PS.3.2, PS.2, PW.7 [VERIFY] · edition 1.1
document sha256:1818181818181818181818181818181818181818181818181818181818181818
entered by actor:human:issm
National Institute of Standards and Technology
SP 800-161 Rev. 1 — C-SCRM Practices for Systems and Organizations
SR-3, SR-4, SR-11 [VERIFY] · edition Rev. 1
document sha256:6161616161616161616161616161616161616161616161616161616161616161
entered by actor:human:issm

What each authority bound

ClaimRequirementLevelBound by
code_reviewrequiredtrueNational Institute of Standards and Technology
PW.7 [VERIFY] · SP 800-218 — Secure Software Development Framework v1.1
component_provenancemin classSELLER-ASSERTEDNational Institute of Standards and Technology
SR-4 [VERIFY] · SP 800-161 Rev. 1 — C-SCRM Practices for Systems and Organizations
component_provenancerequiredtrueNational Institute of Standards and Technology
PS.3.2 [VERIFY] · SP 800-218 — Secure Software Development Framework v1.1
release_integrity_mechanismmin classVERIFIEDNational Institute of Standards and Technology
PS.2 [VERIFY] · SP 800-218 — Secure Software Development Framework v1.1
release_integrity_mechanismnever waivabletrueNational Institute of Standards and Technology
PS.2 [VERIFY] · SP 800-218 — Secure Software Development Framework v1.1
release_integrity_mechanismrequiredtrueNational Institute of Standards and Technology
PS.2 [VERIFY] · SP 800-218 — Secure Software Development Framework v1.1
supplier_assessmentrequiredtrueNational Institute of Standards and Technology
SR-6 [VERIFY] · SP 800-161 Rev. 1 — C-SCRM Practices for Systems and Organizations

Every required claim, and what was actually held

ClaimRequiredEvidence classWhoAgeOutcome
release_integrity_mechanismyesVERIFIEDactor:org:LAB-NVLAP-04122026-05-30admitted
supplier_assessmentyesVERIFIEDactor:org:CERT-3PAO-ATLANTIC2026-01-20admitted
code_reviewnoSELLER-ASSERTEDactor:org:INTERNAL-PLATFORM-ENG2026-08-06withheld
component_provenancenoSELLER-ASSERTEDactor:org:INTERNAL-PLATFORM-ENG2026-08-07withheld
code_reviewyesMISSING2026-08-08coverage gap
component_provenanceyesMISSING2026-08-08coverage gap
Absent from this copy, deliberatelyNo exposure figure, no risk pricing, no confidence score, no release quorum. The examiner’s claim is on the record of what was required and what was held — answered here completely, down to the digest of the document each requirement was configured from. The institution’s commercial position is a different question and this document does not answer it. The published verifier checks that on the content of the copy, not on the intentions of whoever produced it.
The scoped copy itself — partial — something outside this role’s remit was removed
FAITHFUL digest sha256:20e00f18ba29e2adbe6ae05018470dba5bd4a2da12380cf4261809524035cd94 matches the commitment sealed in the receipt.
{
 "spec": "corobate:role-view:2",
 "role": "REGULATOR",
 "purpose": "An official holding a public mandate over this record — a customs officer, a bank examiner, a market conduct supervisor. Sees the regulatory record in full: their own instrument named, every required claim and whether it was met, by whom, how old. No commercial figure of any kind.",
 "is_a_receipt": false,
 "warning": "This is a SCOPED COPY of a sealed decision, not the decision record itself. It will not verify as a receipt and must not be presented as one. To confirm it is faithful, recompute its `view` digest under the same canonicalisation that produces receipt_hash and compare it with the entry for this role in the source receipt’s `views` block.",
 "derived_from": {
  "receipt_hash": "sha256:90a20c5dcda8ab70e32d7b08521e24e2f271d03ac079f47c2a047dfd3ed9cb4c",
  "entry_hash": "sha256:62842a7dbe06d36b693bfd2f62a3c8123aede49a1a9092bc52a75f26ff260df5",
  "issued_at": "2026-08-08T16:00:00.000Z"
 },
 "view_digest": "sha256:20e00f18ba29e2adbe6ae05018470dba5bd4a2da12380cf4261809524035cd94",
 "withheld": {
  "anything_withheld": true,
  "note": "Facts outside this role’s remit were removed. That something was removed is stated so a partial record is never mistaken for a complete one. How much, and what, is not stated — a count is an inference about the part you are not entitled to see."
 },
 "view": {
  "spec": "urn:ietf:params:corobate:receipt:1",
  "receipt_version": "1.8",
  "issued_at": "2026-08-08T16:00:00.000Z",
  "decision": {
   "id": "rel_PLATFORM_2026_8_0",
   "subject": "release:PLATFORM-CORE-2026.8.0",
   "question": "May this release be published to the government-facing environment?"
  },
  "memory": {
   "state_digest": "sha256:b69314201d2e10631d7179b82717dd6079b7dc7408b3ee37281eb56729ce59f2",
   "ledger_head": "sha256:fdadc9eed6746ad514ec9f681a2910b2fa04006a84e45cb24a08e5bdcd9e97b3",
   "coverage_gaps": [
    "release:PLATFORM-CORE-2026.8.0|code_review",
    "release:PLATFORM-CORE-2026.8.0|component_provenance"
   ]
  },
  "data_horizon": "2026-08-08T16:00:00.000Z",
  "verdict": {
   "value": "WITHHELD"
  },
  "regulatory": {
   "spec": "corobate:regulatory:2",
   "resolved": true,
   "applied": [
    {
     "instrument_id": "nist-sp-800-218-ssdf",
     "version": 1,
     "authority": "National Institute of Standards and Technology",
     "instrument": "SP 800-218 — Secure Software Development Framework v1.1",
     "edition": "1.1",
     "citation": "PS.3.2, PS.2, PW.7 [VERIFY]",
     "source_digest": "sha256:1818181818181818181818181818181818181818181818181818181818181818",
     "entered_by": "actor:human:issm",
     "entered_at": "2026-08-08T16:00:00.000Z"
    },
    {
     "instrument_id": "nist-sp-800-161r1-cscrm",
     "version": 1,
     "authority": "National Institute of Standards and Technology",
     "instrument": "SP 800-161 Rev. 1 — C-SCRM Practices for Systems and Organizations",
     "edition": "Rev. 1",
     "citation": "SR-3, SR-4, SR-11 [VERIFY]",
     "source_digest": "sha256:6161616161616161616161616161616161616161616161616161616161616161",
     "entered_by": "actor:human:issm",
     "entered_at": "2026-08-08T16:00:00.000Z"
    }
   ],
   "skipped": [],
   "conflicts": [],
   "bindings": [
    {
     "claim": "code_review",
     "requirement": "required",
     "value": true,
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-218 — Secure Software Development Framework v1.1",
      "instrument_id": "nist-sp-800-218-ssdf",
      "version": 1,
      "edition": "1.1",
      "citation": "PW.7 [VERIFY]",
      "source_digest": "sha256:1818181818181818181818181818181818181818181818181818181818181818"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "component_provenance",
     "requirement": "min_class",
     "value": "SELLER-ASSERTED",
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-161 Rev. 1 — C-SCRM Practices for Systems and Organizations",
      "instrument_id": "nist-sp-800-161r1-cscrm",
      "version": 1,
      "edition": "Rev. 1",
      "citation": "SR-4 [VERIFY]",
      "source_digest": "sha256:6161616161616161616161616161616161616161616161616161616161616161"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "component_provenance",
     "requirement": "required",
     "value": true,
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-218 — Secure Software Development Framework v1.1",
      "instrument_id": "nist-sp-800-218-ssdf",
      "version": 1,
      "edition": "1.1",
      "citation": "PS.3.2 [VERIFY]",
      "source_digest": "sha256:1818181818181818181818181818181818181818181818181818181818181818"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "release_integrity_mechanism",
     "requirement": "min_class",
     "value": "VERIFIED",
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-218 — Secure Software Development Framework v1.1",
      "instrument_id": "nist-sp-800-218-ssdf",
      "version": 1,
      "edition": "1.1",
      "citation": "PS.2 [VERIFY]",
      "source_digest": "sha256:1818181818181818181818181818181818181818181818181818181818181818"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "release_integrity_mechanism",
     "requirement": "never_waivable",
     "value": true,
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-218 — Secure Software Development Framework v1.1",
      "instrument_id": "nist-sp-800-218-ssdf",
      "version": 1,
      "edition": "1.1",
      "citation": "PS.2 [VERIFY]",
      "source_digest": "sha256:1818181818181818181818181818181818181818181818181818181818181818"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "release_integrity_mechanism",
     "requirement": "required",
     "value": true,
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-218 — Secure Software Development Framework v1.1",
      "instrument_id": "nist-sp-800-218-ssdf",
      "version": 1,
      "edition": "1.1",
      "citation": "PS.2 [VERIFY]",
      "source_digest": "sha256:1818181818181818181818181818181818181818181818181818181818181818"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "supplier_assessment",
     "requirement": "required",
     "value": true,
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-161 Rev. 1 — C-SCRM Practices for Systems and Organizations",
      "instrument_id": "nist-sp-800-161r1-cscrm",
      "version": 1,
      "edition": "Rev. 1",
      "citation": "SR-6 [VERIFY]",
      "source_digest": "sha256:6161616161616161616161616161616161616161616161616161616161616161"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    }
   ],
   "defaults": [
    {
     "claim": "code_review",
     "requirement": "ai_position",
     "value": "ADMIT",
     "because": "No instrument in force stated a position on AI-authored evidence for \"code_review\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
    },
    {
     "claim": "component_provenance",
     "requirement": "ai_position",
     "value": "ADMIT",
     "because": "No instrument in force stated a position on AI-authored evidence for \"component_provenance\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
    },
    {
     "claim": "release_integrity_mechanism",
     "requirement": "ai_position",
     "value": "ADMIT",
     "because": "No instrument in force stated a position on AI-authored evidence for \"release_integrity_mechanism\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
    },
    {
     "claim": "supplier_assessment",
     "requirement": "ai_position",
     "value": "ADMIT",
     "because": "No instrument in force stated a position on AI-authored evidence for \"supplier_assessment\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
    }
   ]
  },
  "inputs": [
   {
    "key": "release:PLATFORM-CORE-2026.8.0::release_integrity_mechanism",
    "provenance": "VERIFIED",
    "source": "LAB-NVLAP-0412:release_integrity_mechanism",
    "observed_at": "2026-05-30T16:00:00.000Z",
    "critical": true,
    "memory_status": "admitted",
    "memory_actor": "actor:org:LAB-NVLAP-0412"
   },
   {
    "key": "release:PLATFORM-CORE-2026.8.0::supplier_assessment",
    "provenance": "VERIFIED",
    "source": "CERT-3PAO-ATLANTIC:supplier_assessment",
    "observed_at": "2026-01-20T16:00:00.000Z",
    "critical": true,
    "memory_status": "admitted",
    "memory_actor": "actor:org:CERT-3PAO-ATLANTIC"
   },
   {
    "key": "release:PLATFORM-CORE-2026.8.0::code_review",
    "provenance": "SELLER-ASSERTED",
    "source": "INTERNAL-PLATFORM-ENG:code_review",
    "observed_at": "2026-08-06T16:00:00.000Z",
    "critical": false,
    "memory_status": "withheld",
    "memory_actor": "actor:org:INTERNAL-PLATFORM-ENG"
   },
   {
    "key": "release:PLATFORM-CORE-2026.8.0::component_provenance",
    "provenance": "SELLER-ASSERTED",
    "source": "INTERNAL-PLATFORM-ENG:component_provenance",
    "observed_at": "2026-08-07T16:00:00.000Z",
    "critical": false,
    "memory_status": "withheld",
    "memory_actor": "actor:org:INTERNAL-PLATFORM-ENG"
   },
   {
    "key": "release:PLATFORM-CORE-2026.8.0::code_review",
    "provenance": "MISSING",
    "source": null,
    "observed_at": "2026-08-08T16:00:00.000Z",
    "critical": true,
    "memory_status": "coverage_gap"
   },
   {
    "key": "release:PLATFORM-CORE-2026.8.0::component_provenance",
    "provenance": "MISSING",
    "source": null,
    "observed_at": "2026-08-08T16:00:00.000Z",
    "critical": true,
    "memory_status": "coverage_gap"
   }
  ],
  "crypto_suite": {
   "spec": "corobate:suite:1",
   "id": "CB-1-ES256-SHA256",
   "receipt_digest": "sha256",
   "chain_digest": "sha256",
   "content_digest": "sha256",
   "envelope_signature": "ES256",
   "signature_curve": "P-256",
   "canonicalisation": "attest-canon/2",
   "quantum_resistant": false
  }
 }
}

ISSM / control owner

The information system security manager and the control owners who hold the package.

The fullest internal view: every input, its class, its age, its score, the exposure, and every publication in force.

VerdictWITHHELD
Confidence0%
bound by code_review
Exposure$640,000
ReleaseWITHHELD_NO_EVIDENCE
Risk acceptedNONE

Every input the gate saw

ClaimRequiredEvidence classWhoAgeScoreOutcome
release_integrity_mechanismyesVERIFIEDactor:org:LAB-NVLAP-041270d95%admitted
supplier_assessmentyesVERIFIEDactor:org:CERT-3PAO-ATLANTIC200d95%admitted
code_reviewnoSELLER-ASSERTEDactor:org:INTERNAL-PLATFORM-ENG2d50%withheld
component_provenancenoSELLER-ASSERTEDactor:org:INTERNAL-PLATFORM-ENG1d50%withheld
code_reviewyesMISSING2026-08-080%coverage gap
component_provenanceyesMISSING2026-08-080%coverage gap

Instruments in force

National Institute of Standards and Technology
SP 800-218 — Secure Software Development Framework v1.1
PS.3.2, PS.2, PW.7 [VERIFY] · edition 1.1
document sha256:1818181818181818181818181818181818181818181818181818181818181818
entered by actor:human:issm
National Institute of Standards and Technology
SP 800-161 Rev. 1 — C-SCRM Practices for Systems and Organizations
SR-3, SR-4, SR-11 [VERIFY] · edition Rev. 1
document sha256:6161616161616161616161616161616161616161616161616161616161616161
entered by actor:human:issm

Why

  • Coverage gap: no admissible memory for required claim(s) release:PLATFORM-CORE-2026.8.0|code_review, release:PLATFORM-CORE-2026.8.0|component_provenance.
  • Confidence 0.00% is bound by "release:PLATFORM-CORE-2026.8.0|code_review".
  • 2 memories were withheld from the context block: release:PLATFORM-CORE-2026.8.0|code_review (sparse track record: 1 independent observation(s); no failure recorded, so the class ceiling stands); release:PLATFORM-CORE-2026.8.0|component_provenance (sparse track record: 1 independent observation(s); no failure recorded, so the class ceiling stands).
  • Thresholds for $640,000 exposure: approve 85%, caution 60%.
The scoped copy itself — partial — something outside this role’s remit was removed
FAITHFUL digest sha256:7995bc6450131c6fc43f7b94490b44e0f6267dea9c4eafb830c5ab7aff52a688 matches the commitment sealed in the receipt.
{
 "spec": "corobate:role-view:2",
 "role": "COMPLIANCE",
 "purpose": "The operator’s own compliance function. The fullest internal view: every gap, every instrument in force, the waivability of each requirement and who accepted what.",
 "is_a_receipt": false,
 "warning": "This is a SCOPED COPY of a sealed decision, not the decision record itself. It will not verify as a receipt and must not be presented as one. To confirm it is faithful, recompute its `view` digest under the same canonicalisation that produces receipt_hash and compare it with the entry for this role in the source receipt’s `views` block.",
 "derived_from": {
  "receipt_hash": "sha256:90a20c5dcda8ab70e32d7b08521e24e2f271d03ac079f47c2a047dfd3ed9cb4c",
  "entry_hash": "sha256:62842a7dbe06d36b693bfd2f62a3c8123aede49a1a9092bc52a75f26ff260df5",
  "issued_at": "2026-08-08T16:00:00.000Z"
 },
 "view_digest": "sha256:7995bc6450131c6fc43f7b94490b44e0f6267dea9c4eafb830c5ab7aff52a688",
 "withheld": {
  "anything_withheld": true,
  "note": "Facts outside this role’s remit were removed. That something was removed is stated so a partial record is never mistaken for a complete one. How much, and what, is not stated — a count is an inference about the part you are not entitled to see."
 },
 "view": {
  "spec": "urn:ietf:params:corobate:receipt:1",
  "receipt_version": "1.8",
  "issued_at": "2026-08-08T16:00:00.000Z",
  "decision": {
   "id": "rel_PLATFORM_2026_8_0",
   "domain": "supply-chain",
   "subject": "release:PLATFORM-CORE-2026.8.0",
   "question": "May this release be published to the government-facing environment?"
  },
  "memory": {
   "state_digest": "sha256:b69314201d2e10631d7179b82717dd6079b7dc7408b3ee37281eb56729ce59f2",
   "ledger_head": "sha256:fdadc9eed6746ad514ec9f681a2910b2fa04006a84e45cb24a08e5bdcd9e97b3",
   "coverage_gaps": [
    "release:PLATFORM-CORE-2026.8.0|code_review",
    "release:PLATFORM-CORE-2026.8.0|component_provenance"
   ],
   "exposure": {
    "usd": 640000,
    "declared_by": "actor:human:issm",
    "ledger_seq": 4
   },
   "policy_digest": "sha256:a6b69b7d20f7fb04d522364af1d92992058b04a5835fcec9d1c9f2261c7ef636"
  },
  "data_horizon": "2026-08-08T16:00:00.000Z",
  "verdict": {
   "value": "WITHHELD",
   "threshold_approve": 0.85,
   "threshold_caution": 0.6,
   "rule": "confidence>=threshold"
  },
  "confidence": {
   "value": 0,
   "method": "min-over-critical-inputs",
   "bound_by": "release:PLATFORM-CORE-2026.8.0::code_review"
  },
  "release": {
   "required": false,
   "required_by_tier": false,
   "escalated_by_acceptance": false,
   "risk_accepted": false,
   "state": "WITHHELD_NO_EVIDENCE",
   "code": "QUORUM_EVIDENCE_WITHHELD",
   "reason": "the evidence did not clear the threshold for this exposure, so there is nothing to release. Signatures do not substitute for evidence, and this state is deliberately distinct from WITHHELD_PENDING_SIGNATURES: a reader must be able to tell \"the evidence is not there\" from \"the evidence is there and 0 of 2 people have signed\".",
   "tier_floor_cents": 1000000000,
   "exposure_usd_cents": 64000000,
   "required_m": 2,
   "declared_n": 3,
   "floor_m": 2,
   "distinct_signers": 0,
   "superseded": 0,
   "collapsed": 0,
   "release_digest": "sha256:dab60630adae29904fb52f9577e707f91834a0c7d6e315e4382ceebcc01b11d7",
   "governance_digest": "sha256:8b0a45a27fcce9c1c243c764e855e67c6fe6dfd7f02a563bd90809b419731905",
   "governance_signed": true,
   "counted_voices": [],
   "signatures": [],
   "ledger_seq": null
  },
  "acceptance": {
   "state": "NONE",
   "code": "ACCEPTANCE_NONE",
   "reason": "no risk acceptance was presented for this decision. This is the ordinary case: a refusal is a refusal unless a named person has priced it.",
   "permitted_basis": null,
   "presented": 0,
   "superseded": 0,
   "expired": 0,
   "gaps_not_covered": 0,
   "coverage_gaps_in_force": [
    "release:PLATFORM-CORE-2026.8.0|code_review",
    "release:PLATFORM-CORE-2026.8.0|component_provenance"
   ],
   "evidentiary_digest": "sha256:dab60630adae29904fb52f9577e707f91834a0c7d6e315e4382ceebcc01b11d7",
   "margin_floor_bp": 100,
   "authority_ceiling_cents": {
    "SUPERVISOR": 1000000,
    "MANAGER": 25000000,
    "DIRECTOR": 500000000,
    "OFFICER": 5000000000
   },
   "acceptances": [],
   "escalated": false,
   "live": false,
   "ledger_seq": null
  },
  "regulatory": {
   "spec": "corobate:regulatory:2",
   "resolved": true,
   "applied": [
    {
     "instrument_id": "nist-sp-800-218-ssdf",
     "version": 1,
     "authority": "National Institute of Standards and Technology",
     "instrument": "SP 800-218 — Secure Software Development Framework v1.1",
     "edition": "1.1",
     "citation": "PS.3.2, PS.2, PW.7 [VERIFY]",
     "source_digest": "sha256:1818181818181818181818181818181818181818181818181818181818181818",
     "entered_by": "actor:human:issm",
     "entered_at": "2026-08-08T16:00:00.000Z"
    },
    {
     "instrument_id": "nist-sp-800-161r1-cscrm",
     "version": 1,
     "authority": "National Institute of Standards and Technology",
     "instrument": "SP 800-161 Rev. 1 — C-SCRM Practices for Systems and Organizations",
     "edition": "Rev. 1",
     "citation": "SR-3, SR-4, SR-11 [VERIFY]",
     "source_digest": "sha256:6161616161616161616161616161616161616161616161616161616161616161",
     "entered_by": "actor:human:issm",
     "entered_at": "2026-08-08T16:00:00.000Z"
    }
   ],
   "skipped": [],
   "conflicts": [],
   "bindings": [
    {
     "claim": "code_review",
     "requirement": "required",
     "value": true,
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-218 — Secure Software Development Framework v1.1",
      "instrument_id": "nist-sp-800-218-ssdf",
      "version": 1,
      "edition": "1.1",
      "citation": "PW.7 [VERIFY]",
      "source_digest": "sha256:1818181818181818181818181818181818181818181818181818181818181818"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "component_provenance",
     "requirement": "min_class",
     "value": "SELLER-ASSERTED",
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-161 Rev. 1 — C-SCRM Practices for Systems and Organizations",
      "instrument_id": "nist-sp-800-161r1-cscrm",
      "version": 1,
      "edition": "Rev. 1",
      "citation": "SR-4 [VERIFY]",
      "source_digest": "sha256:6161616161616161616161616161616161616161616161616161616161616161"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "component_provenance",
     "requirement": "required",
     "value": true,
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-218 — Secure Software Development Framework v1.1",
      "instrument_id": "nist-sp-800-218-ssdf",
      "version": 1,
      "edition": "1.1",
      "citation": "PS.3.2 [VERIFY]",
      "source_digest": "sha256:1818181818181818181818181818181818181818181818181818181818181818"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "release_integrity_mechanism",
     "requirement": "min_class",
     "value": "VERIFIED",
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-218 — Secure Software Development Framework v1.1",
      "instrument_id": "nist-sp-800-218-ssdf",
      "version": 1,
      "edition": "1.1",
      "citation": "PS.2 [VERIFY]",
      "source_digest": "sha256:1818181818181818181818181818181818181818181818181818181818181818"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "release_integrity_mechanism",
     "requirement": "never_waivable",
     "value": true,
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-218 — Secure Software Development Framework v1.1",
      "instrument_id": "nist-sp-800-218-ssdf",
      "version": 1,
      "edition": "1.1",
      "citation": "PS.2 [VERIFY]",
      "source_digest": "sha256:1818181818181818181818181818181818181818181818181818181818181818"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "release_integrity_mechanism",
     "requirement": "required",
     "value": true,
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-218 — Secure Software Development Framework v1.1",
      "instrument_id": "nist-sp-800-218-ssdf",
      "version": 1,
      "edition": "1.1",
      "citation": "PS.2 [VERIFY]",
      "source_digest": "sha256:1818181818181818181818181818181818181818181818181818181818181818"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "supplier_assessment",
     "requirement": "required",
     "value": true,
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-161 Rev. 1 — C-SCRM Practices for Systems and Organizations",
      "instrument_id": "nist-sp-800-161r1-cscrm",
      "version": 1,
      "edition": "Rev. 1",
      "citation": "SR-6 [VERIFY]",
      "source_digest": "sha256:6161616161616161616161616161616161616161616161616161616161616161"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    }
   ],
   "defaults": [
    {
     "claim": "code_review",
     "requirement": "ai_position",
     "value": "ADMIT",
     "because": "No instrument in force stated a position on AI-authored evidence for \"code_review\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
    },
    {
     "claim": "component_provenance",
     "requirement": "ai_position",
     "value": "ADMIT",
     "because": "No instrument in force stated a position on AI-authored evidence for \"component_provenance\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
    },
    {
     "claim": "release_integrity_mechanism",
     "requirement": "ai_position",
     "value": "ADMIT",
     "because": "No instrument in force stated a position on AI-authored evidence for \"release_integrity_mechanism\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
    },
    {
     "claim": "supplier_assessment",
     "requirement": "ai_position",
     "value": "ADMIT",
     "because": "No instrument in force stated a position on AI-authored evidence for \"supplier_assessment\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
    }
   ]
  },
  "reasons": [
   "Coverage gap: no admissible memory for required claim(s) release:PLATFORM-CORE-2026.8.0|code_review, release:PLATFORM-CORE-2026.8.0|component_provenance.",
   "Confidence 0.00% is bound by \"release:PLATFORM-CORE-2026.8.0|code_review\".",
   "2 memories were withheld from the context block: release:PLATFORM-CORE-2026.8.0|code_review (sparse track record: 1 independent observation(s); no failure recorded, so the class ceiling stands); release:PLATFORM-CORE-2026.8.0|component_provenance (sparse track record: 1 independent observation(s); no failure recorded, so the class ceiling stands).",
   "Thresholds for $640,000 exposure: approve 85%, caution 60%."
  ],
  "inputs": [
   {
    "key": "release:PLATFORM-CORE-2026.8.0::release_integrity_mechanism",
    "value": "assessed",
    "provenance": "VERIFIED",
    "source": "LAB-NVLAP-0412:release_integrity_mechanism",
    "observed_at": "2026-05-30T16:00:00.000Z",
    "reliability": 0.95,
    "critical": true,
    "memory_status": "admitted",
    "memory_kind": "certificate",
    "memory_actor": "actor:org:LAB-NVLAP-0412",
    "memory_age_days": 70
   },
   {
    "key": "release:PLATFORM-CORE-2026.8.0::supplier_assessment",
    "value": "assessed",
    "provenance": "VERIFIED",
    "source": "CERT-3PAO-ATLANTIC:supplier_assessment",
    "observed_at": "2026-01-20T16:00:00.000Z",
    "reliability": 0.95,
    "critical": true,
    "memory_status": "admitted",
    "memory_kind": "certificate",
    "memory_actor": "actor:org:CERT-3PAO-ATLANTIC",
    "memory_age_days": 200
   },
   {
    "key": "release:PLATFORM-CORE-2026.8.0::code_review",
    "value": null,
    "provenance": "SELLER-ASSERTED",
    "source": "INTERNAL-PLATFORM-ENG:code_review",
    "observed_at": "2026-08-06T16:00:00.000Z",
    "reliability": 0.5,
    "critical": false,
    "memory_status": "withheld",
    "memory_kind": "status",
    "memory_actor": "actor:org:INTERNAL-PLATFORM-ENG",
    "memory_age_days": 2
   },
   {
    "key": "release:PLATFORM-CORE-2026.8.0::component_provenance",
    "value": null,
    "provenance": "SELLER-ASSERTED",
    "source": "INTERNAL-PLATFORM-ENG:component_provenance",
    "observed_at": "2026-08-07T16:00:00.000Z",
    "reliability": 0.5,
    "critical": false,
    "memory_status": "withheld",
    "memory_kind": "test_report",
    "memory_actor": "actor:org:INTERNAL-PLATFORM-ENG",
    "memory_age_days": 1
   },
   {
    "key": "release:PLATFORM-CORE-2026.8.0::code_review",
    "value": null,
    "provenance": "MISSING",
    "source": null,
    "observed_at": "2026-08-08T16:00:00.000Z",
    "reliability": 0,
    "critical": true,
    "memory_status": "coverage_gap"
   },
   {
    "key": "release:PLATFORM-CORE-2026.8.0::component_provenance",
    "value": null,
    "provenance": "MISSING",
    "source": null,
    "observed_at": "2026-08-08T16:00:00.000Z",
    "reliability": 0,
    "critical": true,
    "memory_status": "coverage_gap"
   }
  ],
  "crypto_suite": {
   "spec": "corobate:suite:1",
   "id": "CB-1-ES256-SHA256",
   "receipt_digest": "sha256",
   "chain_digest": "sha256",
   "content_digest": "sha256",
   "envelope_signature": "ES256",
   "signature_curve": "P-256",
   "canonicalisation": "attest-canon/2",
   "quantum_resistant": false
  }
 }
}

Authorising official (signer)

The named official whose signature carries the authorisation decision.

What is at stake, what the evidence supports, what is missing, and the digest they are signing over.

You are being asked to sign

May this release be published to the government-facing environment?

At stake$640,000
Evidence saysWITHHELD
Release stateWITHHELD_NO_EVIDENCE
signing over evidentiary digest sha256:dab60630adae29904fb52f9577e707f91834a0c7d6e315e4382ceebcc01b11d7

The signature is over the STATE OF THE EVIDENCE. Move one fact behind this decision and the digest moves and the signature stops counting — which is what makes it safe to collect signatures before everyone is in the room.

What is missing

  • code review
  • component provenance
The scoped copy itself — partial — something outside this role’s remit was removed
FAITHFUL digest sha256:2cb0c1c6e97925924b71cdca6e8cb1c513682ab78fc48f6a5a84be91b3c5b833 matches the commitment sealed in the receipt.
{
 "spec": "corobate:role-view:2",
 "role": "EXECUTIVE",
 "purpose": "A named signer on the release gate. Sees what is at stake, what the evidence supports, who else has signed and what they are being asked to sign over.",
 "is_a_receipt": false,
 "warning": "This is a SCOPED COPY of a sealed decision, not the decision record itself. It will not verify as a receipt and must not be presented as one. To confirm it is faithful, recompute its `view` digest under the same canonicalisation that produces receipt_hash and compare it with the entry for this role in the source receipt’s `views` block.",
 "derived_from": {
  "receipt_hash": "sha256:90a20c5dcda8ab70e32d7b08521e24e2f271d03ac079f47c2a047dfd3ed9cb4c",
  "entry_hash": "sha256:62842a7dbe06d36b693bfd2f62a3c8123aede49a1a9092bc52a75f26ff260df5",
  "issued_at": "2026-08-08T16:00:00.000Z"
 },
 "view_digest": "sha256:2cb0c1c6e97925924b71cdca6e8cb1c513682ab78fc48f6a5a84be91b3c5b833",
 "withheld": {
  "anything_withheld": true,
  "note": "Facts outside this role’s remit were removed. That something was removed is stated so a partial record is never mistaken for a complete one. How much, and what, is not stated — a count is an inference about the part you are not entitled to see."
 },
 "view": {
  "spec": "urn:ietf:params:corobate:receipt:1",
  "receipt_version": "1.8",
  "issued_at": "2026-08-08T16:00:00.000Z",
  "decision": {
   "id": "rel_PLATFORM_2026_8_0",
   "domain": "supply-chain",
   "subject": "release:PLATFORM-CORE-2026.8.0",
   "question": "May this release be published to the government-facing environment?"
  },
  "memory": {
   "state_digest": "sha256:b69314201d2e10631d7179b82717dd6079b7dc7408b3ee37281eb56729ce59f2",
   "ledger_head": "sha256:fdadc9eed6746ad514ec9f681a2910b2fa04006a84e45cb24a08e5bdcd9e97b3",
   "coverage_gaps": [
    "release:PLATFORM-CORE-2026.8.0|code_review",
    "release:PLATFORM-CORE-2026.8.0|component_provenance"
   ],
   "exposure": {
    "usd": 640000,
    "declared_by": "actor:human:issm",
    "ledger_seq": 4
   }
  },
  "verdict": {
   "value": "WITHHELD",
   "threshold_approve": 0.85,
   "threshold_caution": 0.6,
   "rule": "confidence>=threshold"
  },
  "confidence": {
   "value": 0,
   "method": "min-over-critical-inputs",
   "bound_by": "release:PLATFORM-CORE-2026.8.0::code_review"
  },
  "release": {
   "required": false,
   "required_by_tier": false,
   "escalated_by_acceptance": false,
   "risk_accepted": false,
   "state": "WITHHELD_NO_EVIDENCE",
   "code": "QUORUM_EVIDENCE_WITHHELD",
   "reason": "the evidence did not clear the threshold for this exposure, so there is nothing to release. Signatures do not substitute for evidence, and this state is deliberately distinct from WITHHELD_PENDING_SIGNATURES: a reader must be able to tell \"the evidence is not there\" from \"the evidence is there and 0 of 2 people have signed\".",
   "tier_floor_cents": 1000000000,
   "exposure_usd_cents": 64000000,
   "required_m": 2,
   "declared_n": 3,
   "floor_m": 2,
   "distinct_signers": 0,
   "superseded": 0,
   "collapsed": 0,
   "release_digest": "sha256:dab60630adae29904fb52f9577e707f91834a0c7d6e315e4382ceebcc01b11d7",
   "governance_digest": "sha256:8b0a45a27fcce9c1c243c764e855e67c6fe6dfd7f02a563bd90809b419731905",
   "governance_signed": true,
   "counted_voices": [],
   "signatures": [],
   "ledger_seq": null
  },
  "acceptance": {
   "state": "NONE",
   "code": "ACCEPTANCE_NONE",
   "reason": "no risk acceptance was presented for this decision. This is the ordinary case: a refusal is a refusal unless a named person has priced it.",
   "permitted_basis": null,
   "presented": 0,
   "superseded": 0,
   "expired": 0,
   "gaps_not_covered": 0,
   "coverage_gaps_in_force": [
    "release:PLATFORM-CORE-2026.8.0|code_review",
    "release:PLATFORM-CORE-2026.8.0|component_provenance"
   ],
   "evidentiary_digest": "sha256:dab60630adae29904fb52f9577e707f91834a0c7d6e315e4382ceebcc01b11d7",
   "margin_floor_bp": 100,
   "authority_ceiling_cents": {
    "SUPERVISOR": 1000000,
    "MANAGER": 25000000,
    "DIRECTOR": 500000000,
    "OFFICER": 5000000000
   },
   "acceptances": [],
   "escalated": false,
   "live": false,
   "ledger_seq": null
  },
  "reasons": [
   "Coverage gap: no admissible memory for required claim(s) release:PLATFORM-CORE-2026.8.0|code_review, release:PLATFORM-CORE-2026.8.0|component_provenance.",
   "Confidence 0.00% is bound by \"release:PLATFORM-CORE-2026.8.0|code_review\".",
   "2 memories were withheld from the context block: release:PLATFORM-CORE-2026.8.0|code_review (sparse track record: 1 independent observation(s); no failure recorded, so the class ceiling stands); release:PLATFORM-CORE-2026.8.0|component_provenance (sparse track record: 1 independent observation(s); no failure recorded, so the class ceiling stands).",
   "Thresholds for $640,000 exposure: approve 85%, caution 60%."
  ],
  "regulatory": {
   "applied": [
    {
     "instrument_id": "nist-sp-800-218-ssdf",
     "version": 1,
     "authority": "National Institute of Standards and Technology",
     "instrument": "SP 800-218 — Secure Software Development Framework v1.1",
     "edition": "1.1",
     "citation": "PS.3.2, PS.2, PW.7 [VERIFY]",
     "source_digest": "sha256:1818181818181818181818181818181818181818181818181818181818181818",
     "entered_by": "actor:human:issm",
     "entered_at": "2026-08-08T16:00:00.000Z"
    },
    {
     "instrument_id": "nist-sp-800-161r1-cscrm",
     "version": 1,
     "authority": "National Institute of Standards and Technology",
     "instrument": "SP 800-161 Rev. 1 — C-SCRM Practices for Systems and Organizations",
     "edition": "Rev. 1",
     "citation": "SR-3, SR-4, SR-11 [VERIFY]",
     "source_digest": "sha256:6161616161616161616161616161616161616161616161616161616161616161",
     "entered_by": "actor:human:issm",
     "entered_at": "2026-08-08T16:00:00.000Z"
    }
   ],
   "conflicts": [],
   "defaults": [
    {
     "claim": "code_review",
     "requirement": "ai_position",
     "value": "ADMIT",
     "because": "No instrument in force stated a position on AI-authored evidence for \"code_review\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
    },
    {
     "claim": "component_provenance",
     "requirement": "ai_position",
     "value": "ADMIT",
     "because": "No instrument in force stated a position on AI-authored evidence for \"component_provenance\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
    },
    {
     "claim": "release_integrity_mechanism",
     "requirement": "ai_position",
     "value": "ADMIT",
     "because": "No instrument in force stated a position on AI-authored evidence for \"release_integrity_mechanism\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
    },
    {
     "claim": "supplier_assessment",
     "requirement": "ai_position",
     "value": "ADMIT",
     "because": "No instrument in force stated a position on AI-authored evidence for \"supplier_assessment\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
    }
   ]
  },
  "inputs": [
   {
    "key": "release:PLATFORM-CORE-2026.8.0::release_integrity_mechanism",
    "provenance": "VERIFIED",
    "reliability": 0.95,
    "critical": true,
    "memory_status": "admitted"
   },
   {
    "key": "release:PLATFORM-CORE-2026.8.0::supplier_assessment",
    "provenance": "VERIFIED",
    "reliability": 0.95,
    "critical": true,
    "memory_status": "admitted"
   },
   {
    "key": "release:PLATFORM-CORE-2026.8.0::code_review",
    "provenance": "SELLER-ASSERTED",
    "reliability": 0.5,
    "critical": false,
    "memory_status": "withheld"
   },
   {
    "key": "release:PLATFORM-CORE-2026.8.0::component_provenance",
    "provenance": "SELLER-ASSERTED",
    "reliability": 0.5,
    "critical": false,
    "memory_status": "withheld"
   },
   {
    "key": "release:PLATFORM-CORE-2026.8.0::code_review",
    "provenance": "MISSING",
    "reliability": 0,
    "critical": true,
    "memory_status": "coverage_gap"
   },
   {
    "key": "release:PLATFORM-CORE-2026.8.0::component_provenance",
    "provenance": "MISSING",
    "reliability": 0,
    "critical": true,
    "memory_status": "coverage_gap"
   }
  ]
 }
}

Independent audit / IG

Internal audit, an inspector general, or an external auditor testing the programme.

Everything, plus the verifier’s own findings over the sealed record.

This view withholds nothing. What it adds is the 22 checks the published verifier ran over the sealed record behind every other view of this decision — recomputed at build time, not asserted.

#CheckDetail
1Content reproduces (JCS + SHA-256)PASSmatches sha256:90a20c5dcda8ab70e32d7b08521e24e2f271d03ac079f47c2a047dfd3ed9cb4c
2Hash chain links (entry = H(prev||content))PASShead sha256:62842a7dbe06d36b693bfd2f62a3c8123aede49a1a9092bc52a75f26ff260df5
3Confidence gated by weakest critical inputPASSmin over critical = 0, bound_by release:PLATFORM-CORE-2026.8.0::code_review (MISSING)
3bVerdict follows the threshold rulePASS0 => WITHHELD; recorded WITHHELD
4Point-in-time seal (no input past data_horizon)PASSall inputs <= 2026-08-08T16:00:00.000Z
5Anchor covers the head, and the timestamp token re-readsPASSinternally consistent; NO external anchor was requested — this is not a validated timestamp
6Criteria travel with the receipt and reproducePASSpolicy_body hashes to sha256:a6b69b7d20f7fb04d522364af1d92992058b04a5835fcec9d1c9f2261c7ef636
7Reliability re-derives from recorded evidencePASSall 6 inputs re-derive exactly
8Outcome trials and lineage discounts re-derivePASS4 input(s) re-derive: 0 credited outcome trial(s), 0 lineage-discounted corroboration(s); every reliability is at or under its class ceiling
9Re-ingested receipts respect their weakest-input ceilingPASSno re-ingested receipts: every input rests on a primary observation
10Release quorum re-derivesPASSWITHHELD_NO_EVIDENCE - below the top exposure tier, no multi-party requirement applies
11Risk acceptance re-derivesPASSno risk acceptance: this decision stands or falls on its evidence
12Observer credentials were not revoked as of observation timePASSrevocation list 5 (0 entries, issued 2026-08-06T00:00:00.000Z, next update due 2026-08-13T00:00:00.000Z) reproduces; 2 observer signature(s) judged as of their own instant, none under a key revoked as compromised or retired by then
13The cryptographic suite is named and is one this verifier implementsPASSsealed under CB-1-ES256-SHA256 (ES256 / sha256, attest-canon/2); this verifier implements it; the suite states it is NOT quantum resistant
14Regulatory bindings are attributed and were enforcedPASS7 binding(s) from 2 instrument(s) in force, each attributed to an authority, a citation and a document digest; 4 required claim(s) all reached the gate
15Role-view commitments re-derive, and the customs view carries no moneyPASS6 role-view commitment(s) re-derived from this receipt’s own body by this verifier’s independent projection; the REGULATOR view carries no commercial figure
16AI-authored input was admitted only where an authority allowed itPASS0 claim(s) carry a position on AI-authored evidence set by an authority and 4 carry a recorded default nobody set; 0 exclusion(s) and 0 corroboration-only rule(s) re-derived against this receipt's own admitted inputs; 0 admitted input(s) are AI-authored by their enrolled identity
17State digest recomputes from the ledger aloneUNVERIFIABLENOT APPLICABLE — you supplied no ledger, so the state digest cannot be re-derived from anything. This receipt commits to the corpus the deciding system held at the instant it sealed, and that commitment is checked by recomputing it from the append-only ledger and comparing; with no ledger in hand there is no second artefact to recompute from. The receipt is not at fault and nothing here is missing from it. Obtain the ledger from the issuer and re-run with --ledger <file>, or verifyReceipt(r, {ledger}). Nothing here has failed and nothing here has passed.
18Registry membership re-derives for every key relied onPASSall 2 key(s) relied on re-derive to the entries root registry v3 committed to and the trust root signed
20Geometric support re-derives, and an unevaluated record is not a supported onePASSno authority bound a metric to any claim on this receipt, so no geometric test applied. A claim nobody bound a metric to is not a claim about geometry, and this is a stated absence rather than a silent one
19The cause of every uncovered requirement re-derivesPASSall 2 uncovered requirement(s) re-derive their cause from this receipt's own rows. What notice is ADEQUATE is not decided here: this check establishes what the record says and that the record agrees with itself.
21The sealing party is the one you were told to expectUNVERIFIABLENOT APPLICABLE — you supplied no trust bundle, so nothing here establishes who sealed this. Identities 1 to 20 prove that this document agrees with itself; not one of them asks whose trust root it was sealed under, and a document that agrees with itself about a decision nobody made agrees with itself perfectly. Obtain the issuer's corobate:trust-bundle:1 out of band, confirm its spoken fingerprint with them by voice, and re-run with --trust-bundle <file> --expect-fingerprint <what you heard>. Nothing here has failed and nothing here has passed.
The scoped copy itself — complete for this role
FAITHFUL digest sha256:656bcf3729e45b526de2bb0e61590b5a1cf2d464f51a5a52a0ad444f59178cf0 matches the commitment sealed in the receipt.
{
 "spec": "corobate:role-view:2",
 "role": "AUDITOR",
 "purpose": "An external assessor. Sees the complete sealed record: this view withholds nothing and exists so the identity case is a case rather than an exception.",
 "is_a_receipt": false,
 "warning": "This is a SCOPED COPY of a sealed decision, not the decision record itself. It will not verify as a receipt and must not be presented as one. To confirm it is faithful, recompute its `view` digest under the same canonicalisation that produces receipt_hash and compare it with the entry for this role in the source receipt’s `views` block.",
 "derived_from": {
  "receipt_hash": "sha256:90a20c5dcda8ab70e32d7b08521e24e2f271d03ac079f47c2a047dfd3ed9cb4c",
  "entry_hash": "sha256:62842a7dbe06d36b693bfd2f62a3c8123aede49a1a9092bc52a75f26ff260df5",
  "issued_at": "2026-08-08T16:00:00.000Z"
 },
 "view_digest": "sha256:656bcf3729e45b526de2bb0e61590b5a1cf2d464f51a5a52a0ad444f59178cf0",
 "withheld": {
  "anything_withheld": false,
  "note": "Nothing outside the seal was removed for this role."
 },
 "view": {
  "spec": "urn:ietf:params:corobate:receipt:1",
  "receipt_version": "1.8",
  "engine": {
   "name": "corobate-memory",
   "version": "1.0.0"
  },
  "decision": {
   "id": "rel_PLATFORM_2026_8_0",
   "domain": "supply-chain",
   "subject": "release:PLATFORM-CORE-2026.8.0",
   "question": "May this release be published to the government-facing environment?"
  },
  "issued_at": "2026-08-08T16:00:00.000Z",
  "data_horizon": "2026-08-08T16:00:00.000Z",
  "inputs": [
   {
    "key": "release:PLATFORM-CORE-2026.8.0::release_integrity_mechanism",
    "value": "assessed",
    "provenance": "VERIFIED",
    "source": "LAB-NVLAP-0412:release_integrity_mechanism",
    "observed_at": "2026-05-30T16:00:00.000Z",
    "last_corroborated_at": null,
    "memory_refreshed_by": [],
    "reliability": 0.95,
    "critical": true,
    "memory_id": "mem_9ab88c5965f8",
    "memory_status": "admitted",
    "memory_kind": "certificate",
    "memory_actor": "actor:org:LAB-NVLAP-0412",
    "memory_age_days": 70,
    "memory_track": {
     "n": 1,
     "successes": 1
    },
    "memory_promoted_by": [],
    "memory_content_digest": "sha256:271e63573c09d9e0c5d40662165956bcc8a6b4bf65e11baf3f8029a293a9effe",
    "memory_outcomes": {
     "verified": 0,
     "falsified": 0,
     "modified": 0,
     "counted": 0,
     "recorded": 0
    },
    "memory_outcome_attestations": [],
    "memory_observer_lineage": null,
    "memory_corroborations": [],
    "memory_reingest": null,
    "memory_reasons": [
     "sparse track record: 1 independent observation(s); no failure recorded, so the class ceiling stands"
    ],
    "memory_class_floor": "VERIFIED",
    "memory_below_class_floor": false,
    "memory_not_attested": false,
    "memory_below_claim_reliability_floor": false,
    "memory_not_competent_authority": false,
    "memory_out_of_specification": false,
    "memory_ai_authored": false,
    "memory_ai_in_lineage": false,
    "memory_ai_position": "ADMIT",
    "memory_ai_inadmissible": false,
    "memory_geo_inadmissible": false,
    "memory_geo_rung": null,
    "memory_geo_metric": null,
    "memory_geo_required_metric": null,
    "observer_attested": true,
    "observer_auth_code": "VERIFIED",
    "observer_key_id": "k_17d23885943ae529",
    "attestation": null,
    "derivation": {
     "provenance": "VERIFIED",
     "ceiling_bp": 9500,
     "track": {
      "n": 1,
      "successes": 1
     },
     "wilson_bp": null,
     "age_days": 70,
     "max_age_days": 365,
     "house_max_age_days": 365,
     "instrument_max_age_days": null,
     "freshness_cap_bp": 4000,
     "min_track_n": 5,
     "wilson_z_milli": 1960,
     "source_present": true,
     "seller_asserted_cap_bp": 5000,
     "retracted": false,
     "contradicted": false,
     "outcome_trials": 0,
     "outcomes": {
      "verified": 0,
      "falsified": 0,
      "modified": 0,
      "counted": 0,
      "recorded": 0
     },
     "corroborations_counted": 0,
     "corroborations_discounted": 0,
     "reingest_ceiling_bp": null,
     "reingest_depth": null,
     "reingest_weakest_class": null,
     "reingest_source_confidence_bp": null,
     "min_class_floor": "VERIFIED",
     "ai_authored": false,
     "ai_authored_because": null,
     "ai_in_lineage": false,
     "ai_position": "ADMIT"
    },
    "memory_reason_codes": [
     {
      "code": "SPARSE_TRACK_RECORD",
      "observed": 1,
      "limit": 5,
      "binding": false
     }
    ],
    "context_line": "[VERIFIED · r=95.0% · 70d · LAB-NVLAP-0412:release_integrity_mechanism] release:PLATFORM-CORE-2026.8.0 / release_integrity_mechanism: assessed"
   },
   {
    "key": "release:PLATFORM-CORE-2026.8.0::supplier_assessment",
    "value": "assessed",
    "provenance": "VERIFIED",
    "source": "CERT-3PAO-ATLANTIC:supplier_assessment",
    "observed_at": "2026-01-20T16:00:00.000Z",
    "last_corroborated_at": null,
    "memory_refreshed_by": [],
    "reliability": 0.95,
    "critical": true,
    "memory_id": "mem_849b47b67301",
    "memory_status": "admitted",
    "memory_kind": "certificate",
    "memory_actor": "actor:org:CERT-3PAO-ATLANTIC",
    "memory_age_days": 200,
    "memory_track": {
     "n": 1,
     "successes": 1
    },
    "memory_promoted_by": [],
    "memory_content_digest": "sha256:f62959286a450d4bc998869a2fc8db63d444dc498c9af3fa109595b74e7d0983",
    "memory_outcomes": {
     "verified": 0,
     "falsified": 0,
     "modified": 0,
     "counted": 0,
     "recorded": 0
    },
    "memory_outcome_attestations": [],
    "memory_observer_lineage": null,
    "memory_corroborations": [],
    "memory_reingest": null,
    "memory_reasons": [
     "sparse track record: 1 independent observation(s); no failure recorded, so the class ceiling stands"
    ],
    "memory_class_floor": null,
    "memory_below_class_floor": false,
    "memory_not_attested": false,
    "memory_below_claim_reliability_floor": false,
    "memory_not_competent_authority": false,
    "memory_out_of_specification": false,
    "memory_ai_authored": false,
    "memory_ai_in_lineage": false,
    "memory_ai_position": "ADMIT",
    "memory_ai_inadmissible": false,
    "memory_geo_inadmissible": false,
    "memory_geo_rung": null,
    "memory_geo_metric": null,
    "memory_geo_required_metric": null,
    "observer_attested": true,
    "observer_auth_code": "VERIFIED",
    "observer_key_id": "k_307e4bfd710ec9b3",
    "attestation": null,
    "derivation": {
     "provenance": "VERIFIED",
     "ceiling_bp": 9500,
     "track": {
      "n": 1,
      "successes": 1
     },
     "wilson_bp": null,
     "age_days": 200,
     "max_age_days": 365,
     "house_max_age_days": 365,
     "instrument_max_age_days": null,
     "freshness_cap_bp": 4000,
     "min_track_n": 5,
     "wilson_z_milli": 1960,
     "source_present": true,
     "seller_asserted_cap_bp": 5000,
     "retracted": false,
     "contradicted": false,
     "outcome_trials": 0,
     "outcomes": {
      "verified": 0,
      "falsified": 0,
      "modified": 0,
      "counted": 0,
      "recorded": 0
     },
     "corroborations_counted": 0,
     "corroborations_discounted": 0,
     "reingest_ceiling_bp": null,
     "reingest_depth": null,
     "reingest_weakest_class": null,
     "reingest_source_confidence_bp": null,
     "ai_authored": false,
     "ai_authored_because": null,
     "ai_in_lineage": false,
     "ai_position": "ADMIT"
    },
    "memory_reason_codes": [
     {
      "code": "SPARSE_TRACK_RECORD",
      "observed": 1,
      "limit": 5,
      "binding": false
     }
    ],
    "context_line": "[VERIFIED · r=95.0% · 200d · CERT-3PAO-ATLANTIC:supplier_assessment] release:PLATFORM-CORE-2026.8.0 / supplier_assessment: assessed"
   },
   {
    "key": "release:PLATFORM-CORE-2026.8.0::code_review",
    "value": null,
    "provenance": "SELLER-ASSERTED",
    "source": "INTERNAL-PLATFORM-ENG:code_review",
    "observed_at": "2026-08-06T16:00:00.000Z",
    "last_corroborated_at": null,
    "memory_refreshed_by": [],
    "reliability": 0.5,
    "critical": false,
    "memory_id": "mem_c68678e73e95",
    "memory_status": "withheld",
    "memory_kind": "status",
    "memory_actor": "actor:org:INTERNAL-PLATFORM-ENG",
    "memory_age_days": 2,
    "memory_track": {
     "n": 1,
     "successes": 1
    },
    "memory_promoted_by": [],
    "memory_content_digest": "sha256:e0e5ab071d9b9c8dfaa4e76d8c3ce2dfa5ad4fa4674d24c68b4d1c962705926d",
    "memory_outcomes": {
     "verified": 0,
     "falsified": 0,
     "modified": 0,
     "counted": 0,
     "recorded": 0
    },
    "memory_outcome_attestations": [],
    "memory_observer_lineage": null,
    "memory_corroborations": [],
    "memory_reingest": null,
    "memory_reasons": [
     "sparse track record: 1 independent observation(s); no failure recorded, so the class ceiling stands"
    ],
    "memory_class_floor": null,
    "memory_below_class_floor": false,
    "memory_not_attested": false,
    "memory_below_claim_reliability_floor": false,
    "memory_not_competent_authority": false,
    "memory_out_of_specification": false,
    "memory_ai_authored": false,
    "memory_ai_in_lineage": false,
    "memory_ai_position": "ADMIT",
    "memory_ai_inadmissible": false,
    "memory_geo_inadmissible": false,
    "memory_geo_rung": null,
    "memory_geo_metric": null,
    "memory_geo_required_metric": null,
    "observer_attested": false,
    "observer_auth_code": "NO_ENVELOPE",
    "observer_key_id": null,
    "attestation": null,
    "derivation": {
     "provenance": "SELLER-ASSERTED",
     "ceiling_bp": 5000,
     "track": {
      "n": 1,
      "successes": 1
     },
     "wilson_bp": null,
     "age_days": 2,
     "max_age_days": 14,
     "house_max_age_days": 14,
     "instrument_max_age_days": null,
     "freshness_cap_bp": 4000,
     "min_track_n": 5,
     "wilson_z_milli": 1960,
     "source_present": true,
     "seller_asserted_cap_bp": 5000,
     "retracted": false,
     "contradicted": false,
     "outcome_trials": 0,
     "outcomes": {
      "verified": 0,
      "falsified": 0,
      "modified": 0,
      "counted": 0,
      "recorded": 0
     },
     "corroborations_counted": 0,
     "corroborations_discounted": 0,
     "reingest_ceiling_bp": null,
     "reingest_depth": null,
     "reingest_weakest_class": null,
     "reingest_source_confidence_bp": null,
     "ai_authored": false,
     "ai_authored_because": null,
     "ai_in_lineage": false,
     "ai_position": "ADMIT"
    },
    "memory_reason_codes": [
     {
      "code": "SPARSE_TRACK_RECORD",
      "observed": 1,
      "limit": 5,
      "binding": false
     }
    ]
   },
   {
    "key": "release:PLATFORM-CORE-2026.8.0::component_provenance",
    "value": null,
    "provenance": "SELLER-ASSERTED",
    "source": "INTERNAL-PLATFORM-ENG:component_provenance",
    "observed_at": "2026-08-07T16:00:00.000Z",
    "last_corroborated_at": null,
    "memory_refreshed_by": [],
    "reliability": 0.5,
    "critical": false,
    "memory_id": "mem_bd32f4c2a701",
    "memory_status": "withheld",
    "memory_kind": "test_report",
    "memory_actor": "actor:org:INTERNAL-PLATFORM-ENG",
    "memory_age_days": 1,
    "memory_track": {
     "n": 1,
     "successes": 1
    },
    "memory_promoted_by": [],
    "memory_content_digest": "sha256:e9200f9f7a7149856d85d9b6b00a4492b79fa414610af4d974963bb291396246",
    "memory_outcomes": {
     "verified": 0,
     "falsified": 0,
     "modified": 0,
     "counted": 0,
     "recorded": 0
    },
    "memory_outcome_attestations": [],
    "memory_observer_lineage": null,
    "memory_corroborations": [],
    "memory_reingest": null,
    "memory_reasons": [
     "sparse track record: 1 independent observation(s); no failure recorded, so the class ceiling stands"
    ],
    "memory_class_floor": "SELLER-ASSERTED",
    "memory_below_class_floor": false,
    "memory_not_attested": false,
    "memory_below_claim_reliability_floor": false,
    "memory_not_competent_authority": false,
    "memory_out_of_specification": false,
    "memory_ai_authored": false,
    "memory_ai_in_lineage": false,
    "memory_ai_position": "ADMIT",
    "memory_ai_inadmissible": false,
    "memory_geo_inadmissible": false,
    "memory_geo_rung": null,
    "memory_geo_metric": null,
    "memory_geo_required_metric": null,
    "observer_attested": false,
    "observer_auth_code": "NO_ENVELOPE",
    "observer_key_id": null,
    "attestation": null,
    "derivation": {
     "provenance": "SELLER-ASSERTED",
     "ceiling_bp": 5000,
     "track": {
      "n": 1,
      "successes": 1
     },
     "wilson_bp": null,
     "age_days": 1,
     "max_age_days": 180,
     "house_max_age_days": 180,
     "instrument_max_age_days": null,
     "freshness_cap_bp": 4000,
     "min_track_n": 5,
     "wilson_z_milli": 1960,
     "source_present": true,
     "seller_asserted_cap_bp": 5000,
     "retracted": false,
     "contradicted": false,
     "outcome_trials": 0,
     "outcomes": {
      "verified": 0,
      "falsified": 0,
      "modified": 0,
      "counted": 0,
      "recorded": 0
     },
     "corroborations_counted": 0,
     "corroborations_discounted": 0,
     "reingest_ceiling_bp": null,
     "reingest_depth": null,
     "reingest_weakest_class": null,
     "reingest_source_confidence_bp": null,
     "min_class_floor": "SELLER-ASSERTED",
     "ai_authored": false,
     "ai_authored_because": null,
     "ai_in_lineage": false,
     "ai_position": "ADMIT"
    },
    "memory_reason_codes": [
     {
      "code": "SPARSE_TRACK_RECORD",
      "observed": 1,
      "limit": 5,
      "binding": false
     }
    ]
   },
   {
    "key": "release:PLATFORM-CORE-2026.8.0::code_review",
    "value": null,
    "provenance": "MISSING",
    "source": null,
    "observed_at": "2026-08-08T16:00:00.000Z",
    "reliability": 0,
    "critical": true,
    "memory_status": "coverage_gap",
    "gap_cause": "EVIDENCE_PRESENTED_FAILED",
    "gap_request": null,
    "gap_origin": "BUSINESS_EVIDENCE",
    "gap_conditions": []
   },
   {
    "key": "release:PLATFORM-CORE-2026.8.0::component_provenance",
    "value": null,
    "provenance": "MISSING",
    "source": null,
    "observed_at": "2026-08-08T16:00:00.000Z",
    "reliability": 0,
    "critical": true,
    "memory_status": "coverage_gap",
    "gap_cause": "EVIDENCE_PRESENTED_FAILED",
    "gap_request": null,
    "gap_origin": "BUSINESS_EVIDENCE",
    "gap_conditions": []
   }
  ],
  "serialization": {
   "algorithm": "RFC8785-JCS",
   "hash": "sha256"
  },
  "crypto_suite": {
   "spec": "corobate:suite:1",
   "id": "CB-1-ES256-SHA256",
   "receipt_digest": "sha256",
   "chain_digest": "sha256",
   "content_digest": "sha256",
   "envelope_signature": "ES256",
   "signature_curve": "P-256",
   "canonicalisation": "attest-canon/2",
   "quantum_resistant": false
  },
  "confidence": {
   "value": 0,
   "method": "min-over-critical-inputs",
   "bound_by": "release:PLATFORM-CORE-2026.8.0::code_review"
  },
  "verdict": {
   "value": "WITHHELD",
   "threshold_approve": 0.85,
   "threshold_caution": 0.6,
   "rule": "confidence>=threshold"
  },
  "release": {
   "required": false,
   "required_by_tier": false,
   "escalated_by_acceptance": false,
   "risk_accepted": false,
   "state": "WITHHELD_NO_EVIDENCE",
   "code": "QUORUM_EVIDENCE_WITHHELD",
   "reason": "the evidence did not clear the threshold for this exposure, so there is nothing to release. Signatures do not substitute for evidence, and this state is deliberately distinct from WITHHELD_PENDING_SIGNATURES: a reader must be able to tell \"the evidence is not there\" from \"the evidence is there and 0 of 2 people have signed\".",
   "tier_floor_cents": 1000000000,
   "exposure_usd_cents": 64000000,
   "required_m": 2,
   "declared_n": 3,
   "floor_m": 2,
   "distinct_signers": 0,
   "superseded": 0,
   "collapsed": 0,
   "release_digest": "sha256:dab60630adae29904fb52f9577e707f91834a0c7d6e315e4382ceebcc01b11d7",
   "governance_digest": "sha256:8b0a45a27fcce9c1c243c764e855e67c6fe6dfd7f02a563bd90809b419731905",
   "governance_signed": true,
   "counted_voices": [],
   "signatures": [],
   "ledger_seq": null
  },
  "acceptance": {
   "state": "NONE",
   "code": "ACCEPTANCE_NONE",
   "reason": "no risk acceptance was presented for this decision. This is the ordinary case: a refusal is a refusal unless a named person has priced it.",
   "permitted_basis": null,
   "presented": 0,
   "superseded": 0,
   "expired": 0,
   "gaps_not_covered": 0,
   "coverage_gaps_in_force": [
    "release:PLATFORM-CORE-2026.8.0|code_review",
    "release:PLATFORM-CORE-2026.8.0|component_provenance"
   ],
   "evidentiary_digest": "sha256:dab60630adae29904fb52f9577e707f91834a0c7d6e315e4382ceebcc01b11d7",
   "margin_floor_bp": 100,
   "authority_ceiling_cents": {
    "SUPERVISOR": 1000000,
    "MANAGER": 25000000,
    "DIRECTOR": 500000000,
    "OFFICER": 5000000000
   },
   "acceptances": [],
   "escalated": false,
   "live": false,
   "ledger_seq": null
  },
  "regulatory": {
   "spec": "corobate:regulatory:2",
   "resolved": true,
   "applied": [
    {
     "instrument_id": "nist-sp-800-218-ssdf",
     "version": 1,
     "authority": "National Institute of Standards and Technology",
     "instrument": "SP 800-218 — Secure Software Development Framework v1.1",
     "edition": "1.1",
     "citation": "PS.3.2, PS.2, PW.7 [VERIFY]",
     "source_digest": "sha256:1818181818181818181818181818181818181818181818181818181818181818",
     "entered_by": "actor:human:issm",
     "entered_at": "2026-08-08T16:00:00.000Z"
    },
    {
     "instrument_id": "nist-sp-800-161r1-cscrm",
     "version": 1,
     "authority": "National Institute of Standards and Technology",
     "instrument": "SP 800-161 Rev. 1 — C-SCRM Practices for Systems and Organizations",
     "edition": "Rev. 1",
     "citation": "SR-3, SR-4, SR-11 [VERIFY]",
     "source_digest": "sha256:6161616161616161616161616161616161616161616161616161616161616161",
     "entered_by": "actor:human:issm",
     "entered_at": "2026-08-08T16:00:00.000Z"
    }
   ],
   "skipped": [],
   "conflicts": [],
   "bindings": [
    {
     "claim": "code_review",
     "requirement": "required",
     "value": true,
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-218 — Secure Software Development Framework v1.1",
      "instrument_id": "nist-sp-800-218-ssdf",
      "version": 1,
      "edition": "1.1",
      "citation": "PW.7 [VERIFY]",
      "source_digest": "sha256:1818181818181818181818181818181818181818181818181818181818181818"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "component_provenance",
     "requirement": "min_class",
     "value": "SELLER-ASSERTED",
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-161 Rev. 1 — C-SCRM Practices for Systems and Organizations",
      "instrument_id": "nist-sp-800-161r1-cscrm",
      "version": 1,
      "edition": "Rev. 1",
      "citation": "SR-4 [VERIFY]",
      "source_digest": "sha256:6161616161616161616161616161616161616161616161616161616161616161"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "component_provenance",
     "requirement": "required",
     "value": true,
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-218 — Secure Software Development Framework v1.1",
      "instrument_id": "nist-sp-800-218-ssdf",
      "version": 1,
      "edition": "1.1",
      "citation": "PS.3.2 [VERIFY]",
      "source_digest": "sha256:1818181818181818181818181818181818181818181818181818181818181818"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "release_integrity_mechanism",
     "requirement": "min_class",
     "value": "VERIFIED",
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-218 — Secure Software Development Framework v1.1",
      "instrument_id": "nist-sp-800-218-ssdf",
      "version": 1,
      "edition": "1.1",
      "citation": "PS.2 [VERIFY]",
      "source_digest": "sha256:1818181818181818181818181818181818181818181818181818181818181818"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "release_integrity_mechanism",
     "requirement": "never_waivable",
     "value": true,
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-218 — Secure Software Development Framework v1.1",
      "instrument_id": "nist-sp-800-218-ssdf",
      "version": 1,
      "edition": "1.1",
      "citation": "PS.2 [VERIFY]",
      "source_digest": "sha256:1818181818181818181818181818181818181818181818181818181818181818"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "release_integrity_mechanism",
     "requirement": "required",
     "value": true,
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-218 — Secure Software Development Framework v1.1",
      "instrument_id": "nist-sp-800-218-ssdf",
      "version": 1,
      "edition": "1.1",
      "citation": "PS.2 [VERIFY]",
      "source_digest": "sha256:1818181818181818181818181818181818181818181818181818181818181818"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "supplier_assessment",
     "requirement": "required",
     "value": true,
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-161 Rev. 1 — C-SCRM Practices for Systems and Organizations",
      "instrument_id": "nist-sp-800-161r1-cscrm",
      "version": 1,
      "edition": "Rev. 1",
      "citation": "SR-6 [VERIFY]",
      "source_digest": "sha256:6161616161616161616161616161616161616161616161616161616161616161"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    }
   ],
   "defaults": [
    {
     "claim": "code_review",
     "requirement": "ai_position",
     "value": "ADMIT",
     "because": "No instrument in force stated a position on AI-authored evidence for \"code_review\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
    },
    {
     "claim": "component_provenance",
     "requirement": "ai_position",
     "value": "ADMIT",
     "because": "No instrument in force stated a position on AI-authored evidence for \"component_provenance\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
    },
    {
     "claim": "release_integrity_mechanism",
     "requirement": "ai_position",
     "value": "ADMIT",
     "because": "No instrument in force stated a position on AI-authored evidence for \"release_integrity_mechanism\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
    },
    {
     "claim": "supplier_assessment",
     "requirement": "ai_position",
     "value": "ADMIT",
     "because": "No instrument in force stated a position on AI-authored evidence for \"supplier_assessment\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
    }
   ]
  },
  "reasons": [
   "Coverage gap: no admissible memory for required claim(s) release:PLATFORM-CORE-2026.8.0|code_review, release:PLATFORM-CORE-2026.8.0|component_provenance.",
   "Confidence 0.00% is bound by \"release:PLATFORM-CORE-2026.8.0|code_review\".",
   "2 memories were withheld from the context block: release:PLATFORM-CORE-2026.8.0|code_review (sparse track record: 1 independent observation(s); no failure recorded, so the class ceiling stands); release:PLATFORM-CORE-2026.8.0|component_provenance (sparse track record: 1 independent observation(s); no failure recorded, so the class ceiling stands).",
   "Thresholds for $640,000 exposure: approve 85%, caution 60%."
  ],
  "memory": {
   "layer": "capture->store->recall->act",
   "ledger_head": "sha256:fdadc9eed6746ad514ec9f681a2910b2fa04006a84e45cb24a08e5bdcd9e97b3",
   "ledger_entries": 6,
   "context_digest": null,
   "context_memory_ids": [],
   "state_digest": "sha256:b69314201d2e10631d7179b82717dd6079b7dc7408b3ee37281eb56729ce59f2",
   "retrieval_method": "idf-lexical",
   "corpus_size": 4,
   "considered": 4,
   "admitted": 2,
   "withheld": 2,
   "not_considered": 0,
   "coverage_gaps": [
    "release:PLATFORM-CORE-2026.8.0|code_review",
    "release:PLATFORM-CORE-2026.8.0|component_provenance"
   ],
   "exposure": {
    "usd": 640000,
    "declared_by": "actor:human:issm",
    "ledger_seq": 4
   },
   "salience_policy": {
    "half_life_days": 90,
    "grace_days": 7,
    "access_boost_bp": 500,
    "access_boost_cap_bp": 2500,
    "relevance_weight_bp": 6000,
    "recency_weight_bp": 3000,
    "usage_weight_bp": 1000,
    "context_cap": 12,
    "method": "idf-lexical",
    "candidate_list_digest": "sha256:d92593a9b72082ce2d91610f9d21bce314f3b5f4d35c034d0d89f2beefc552d7",
    "note": "salience orders retrieval only; it never contributes to reliability"
   },
   "policy_digest": "sha256:a6b69b7d20f7fb04d522364af1d92992058b04a5835fcec9d1c9f2261c7ef636",
   "policy_body": {
    "class_ceiling_bp": {
     "VERIFIED": 9500,
     "MODELED": 8000,
     "SELLER-ASSERTED": 5000,
     "MISSING": 0
    },
    "actor_class_ceiling": [
     [
      "^actor:ai:",
      "MODELED"
     ],
     [
      "^actor:agent:",
      "MODELED"
     ],
     [
      "^actor:human:",
      "SELLER-ASSERTED"
     ],
     [
      "^actor:org:LAB-",
      "VERIFIED"
     ],
     [
      "^actor:org:CERT-",
      "VERIFIED"
     ],
     [
      "^actor:org:",
      "SELLER-ASSERTED"
     ],
     [
      "^actor:sys:registry:",
      "VERIFIED"
     ],
     [
      "^actor:sys:sensor:",
      "VERIFIED"
     ],
     [
      "^actor:sys:",
      "MODELED"
     ]
    ],
    "freshness_cap_bp": 4000,
    "max_age_days": {
     "telemetry": 1,
     "price": 7,
     "status": 14,
     "certificate": 365,
     "test_report": 180,
     "filing": 90,
     "transcript": 120,
     "highlight": 365,
     "voice_note": 120,
     "note": 365,
     "preference": 540,
     "decision": 1825,
     "receipt": 365,
     "default": 90
    },
    "wilson_z_milli": 1960,
    "min_track_n": 5,
    "exposure_tiers_bp": [
     [
      1000000000,
      9500,
      8000
     ],
     [
      100000000,
      9000,
      7000
     ],
     [
      1000000,
      8500,
      6000
     ],
     [
      0,
      8000,
      5000
     ]
    ],
    "max_context_memories": 12,
    "contradiction_resolve_margin": 2,
    "salience": {
     "half_life_days": 90,
     "grace_days": 7,
     "access_boost_bp": 500,
     "access_boost_cap_bp": 2500,
     "relevance_weight_bp": 6000,
     "recency_weight_bp": 3000,
     "usage_weight_bp": 1000
    }
   },
   "observer_auth": {
    "mode": "required",
    "registry_version": 3,
    "registry_digest": "sha256:460aeaafe345f69542a302e6619dff0712af98de6518838ee4c8585e448c3a7d",
    "entries_root": "sha256:5670469f96484a814462814ed74f0f992b5f19e8ad6afced548e4956e4835ba5",
    "memberships": [
     {
      "key_id": "k_17d23885943ae529",
      "index": 1,
      "entry": {
       "actor": "actor:org:LAB-NVLAP-0412",
       "class": "VERIFIED",
       "kind": "org",
       "key_id": "k_17d23885943ae529",
       "jwk": {
        "kty": "EC",
        "crv": "P-256",
        "x": "3TTw47-PkYfo3ZaKTq_qtHghnGvninAVj25kyOwONno",
        "y": "16PMaR8ofeF5IcZk6ZLml8gDs8uE1s1sBLdciH5e4vg"
       },
       "valid_from": "2025-01-01T00:00:00.000Z",
       "valid_to": "2027-06-01T00:00:00.000Z"
      },
      "path": [
       {
        "side": "left",
        "sibling": "sha256:500f2ba5949d5256ae0f563530b0b270db41ce99d2d7c4b4b60e4bd558ca353d"
       },
       {
        "side": "right",
        "sibling": "sha256:a0b47ea437bf4f1042a1dd50a5a3f411f9a17971812fc6bafccd434eb7d78ccc"
       },
       {
        "side": "right",
        "sibling": "sha256:d3c2347eb675e865fc17ef0204cacda7b02e8784a811fdd1c8a015d1865e6dfb"
       },
       {
        "side": "right",
        "sibling": "sha256:7071adf5e21a94147d31f42f1028b4867b6562e5b78726259c2515b03b213e52"
       }
      ]
     },
     {
      "key_id": "k_307e4bfd710ec9b3",
      "index": 0,
      "entry": {
       "actor": "actor:org:CERT-3PAO-ATLANTIC",
       "class": "VERIFIED",
       "kind": "org",
       "key_id": "k_307e4bfd710ec9b3",
       "jwk": {
        "kty": "EC",
        "crv": "P-256",
        "x": "MGtV26TezLMPjiD3SecQtnje6eLqYyx4qkKzzAkbiY4",
        "y": "SMMdLYnn-FpKbb2sJQ8EAZnzvozNm-cGO0VbUUpniPY"
       },
       "valid_from": "2025-01-01T00:00:00.000Z",
       "valid_to": "2027-06-01T00:00:00.000Z"
      },
      "path": [
       {
        "side": "right",
        "sibling": "sha256:4148869fc259d2c5fc19fe5831065b165a9acf81812e123162035acfdecade1d"
       },
       {
        "side": "right",
        "sibling": "sha256:a0b47ea437bf4f1042a1dd50a5a3f411f9a17971812fc6bafccd434eb7d78ccc"
       },
       {
        "side": "right",
        "sibling": "sha256:d3c2347eb675e865fc17ef0204cacda7b02e8784a811fdd1c8a015d1865e6dfb"
       },
       {
        "side": "right",
        "sibling": "sha256:7071adf5e21a94147d31f42f1028b4867b6562e5b78726259c2515b03b213e52"
       }
      ]
     }
    ],
    "memberships_unproven": [],
    "revocation": {
     "source": "SIGNED_LIST",
     "digest": "sha256:12f73b1fbf27d38cf137b86a1ce13bbcd98161123a6aa7d79b107db8189966b9",
     "sequence": 5,
     "registry_version": 3,
     "issued_at": "2026-08-06T00:00:00.000Z",
     "next_update_due": "2026-08-13T00:00:00.000Z",
     "entry_count": 0,
     "body": {
      "sequence": 5,
      "registry_version": 3,
      "issuer": {
       "name": "NIST-regulated enterprise demonstration trust root",
       "key_id": "k_3793b8e35f8acac1"
      },
      "issued_at": "2026-08-06T00:00:00.000Z",
      "next_update_due": "2026-08-13T00:00:00.000Z",
      "entries": [],
      "spec": "corobate:revocation-list:1"
     }
    }
   },
   "governance": {
    "digest": "sha256:8b0a45a27fcce9c1c243c764e855e67c6fe6dfd7f02a563bd90809b419731905",
    "signed": true,
    "actor_trust": "FLOOR_TO_SELLER_ASSERTED",
    "outcome_trial_weight": 1,
    "max_reingest_depth": 3,
    "release_quorum_m": 2,
    "release_quorum_n": 3,
    "risk_acceptance_margin_bp": 500,
    "risk_acceptance_max_days": 30,
    "risk_acceptance_authority_cents": {
     "SUPERVISOR": 1000000,
     "MANAGER": 25000000,
     "DIRECTOR": 500000000,
     "OFFICER": 5000000000
    },
    "template_author_roles": [
     "MANAGER",
     "DIRECTOR",
     "OFFICER"
    ]
   },
   "observers_attested": 2,
   "outcomes": {
    "attestations_counted": 0,
    "attestations_recorded": 0,
    "records_with_outcomes": 0
   },
   "lineage": {
    "corroborations_counted": 0,
    "corroborations_discounted": 0,
    "records_with_discounted_corroborations": 0
   },
   "reingest": {
    "records": 0,
    "max_depth": 0,
    "weakest_class": null,
    "chain_weakest_bp": 10000,
    "chain": []
   },
   "template": null
  }
 }
}

Every control here is met except one, and the one is the control the organisation most wants to claim. A model's evaluation of itself is a modelled assertion and the policy table will not read it higher, whatever the reported score.

Subject
ai-system:TRIAGE-ASSISTANT-V4
Question
May this AI system be deployed to triage citizen-facing casework?
Exposure
$1,400,000
Instruments
National Institute of Standards and Technology · National Institute of Standards and Technology
Outcome
WITHHELD — the action is not permitted; outstanding: model evaluation
Receipt
sha256:6cfa106851e42c578947d59d107ffb474e39c813bc52723eb7102a95dc5a5e81
The gate variables this decision ran under — a dial per question, read back off the sealed receipt
control assessmentrequired
necessity
requiredNational Institute of Standards and Technology — CA-2 [VERIFY]
staleness
365 daysNational Institute of Standards and Technology — CA-2 [VERIFY]
reputation class
verifiedNational Institute of Standards and Technology — CA-2(1) independent assessors [VERIFY]
reputation record
No reliability floor beyond the exposure tier's own threshold, which still binds.
completion
No satisfaction window was set. The requirement is due now: there is no period in which it may be outstanding, and nothing proceeds without it.
ai provenance
admitNo instrument in force stated a position on AI-authored evidence for "control_assessment". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway.
incident response plan testrequired
necessity
requiredNational Institute of Standards and Technology — MANAGE-4.1 [VERIFY]
staleness
90 daysNo instrument set an age limit for this claim, so the deploying organisation's own freshness policy binds at 90 days. It is not unlimited.
reputation class
No class floor was set, so the seller's own assertion is admissible for this claim up to the ceiling that class carries. That is a setting, not an absence.
reputation record
No reliability floor beyond the exposure tier's own threshold, which still binds.
completion
No satisfaction window was set. The requirement is due now: there is no period in which it may be outstanding, and nothing proceeds without it.
ai provenance
admitNo instrument in force stated a position on AI-authored evidence for "incident_response_plan_test". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway.
model evaluationrequired
necessity
requiredNational Institute of Standards and Technology — MEASURE-2.3 [VERIFY]
staleness
180 daysNational Institute of Standards and Technology — MEASURE-2.3 [VERIFY]
reputation class
verifiedNational Institute of Standards and Technology — MEASURE-2.3 independent evaluation [VERIFY]
reputation record
No reliability floor beyond the exposure tier's own threshold, which still binds.
completion
No satisfaction window was set. The requirement is due now: there is no period in which it may be outstanding, and nothing proceeds without it.
ai provenance
admitNo instrument in force stated a position on AI-authored evidence for "model_evaluation". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway.
penetration testrequired
necessity
requiredNational Institute of Standards and Technology — CA-8 [VERIFY]
staleness
90 daysNo instrument set an age limit for this claim, so the deploying organisation's own freshness policy binds at 90 days. It is not unlimited.
reputation class
verifiedNational Institute of Standards and Technology — CA-8(1) independent penetration agent [VERIFY]
reputation record
No reliability floor beyond the exposure tier's own threshold, which still binds.
completion
No satisfaction window was set. The requirement is due now: there is no period in which it may be outstanding, and nothing proceeds without it.
ai provenance
admitNo instrument in force stated a position on AI-authored evidence for "penetration_test". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway.
security resilience evaluationrequired
necessity
requiredNational Institute of Standards and Technology — MEASURE-2.7 [VERIFY]
staleness
90 daysNo instrument set an age limit for this claim, so the deploying organisation's own freshness policy binds at 90 days. It is not unlimited.
reputation class
No class floor was set, so the seller's own assertion is admissible for this claim up to the ceiling that class carries. That is a setting, not an absence.
reputation record
No reliability floor beyond the exposure tier's own threshold, which still binds.
completion
No satisfaction window was set. The requirement is due now: there is no period in which it may be outstanding, and nothing proceeds without it.
ai provenance
admitNo instrument in force stated a position on AI-authored evidence for "security_resilience_evaluation". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway.
vulnerability scanrequired
necessity
requiredNational Institute of Standards and Technology — RA-5 [VERIFY]
staleness
30 daysNational Institute of Standards and Technology — RA-5(a) [VERIFY]
reputation class
No class floor was set, so the seller's own assertion is admissible for this claim up to the ceiling that class carries. That is a setting, not an absence.
reputation record
No reliability floor beyond the exposure tier's own threshold, which still binds.
completion
No satisfaction window was set. The requirement is due now: there is no period in which it may be outstanding, and nothing proceeds without it.
ai provenance
admitNo instrument in force stated a position on AI-authored evidence for "vulnerability_scan". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway.

Every bar above was re-derived from the regulatory bindings inside this receipt’s hashed body, not from the configuration that produced it. A bar in grey is a setting no instrument made — the deploying organisation’s own default, which still binds and is not an absence. A bar position renders an ordinal on a declared ladder: it is a way to draw a control and to compare two settings on the same axis, and it is not a measurement. The value printed beside each bar is the authoritative one.

Whoever must act now

The engineer with the deployment in their hands, the release manager, the person who must publish or hold.

One instruction and the reason in words. No score, no money, no signatures.

DO NOT PROCEED
ai-system:TRIAGE-ASSISTANT-V4
Missing or out of date: model evaluation

Seven or eight fields, and not one of them is a number somebody can argue with. This person is not being asked to re-judge the evidence; somebody already did, and it is on the record.

The scoped copy itself — partial — something outside this role’s remit was removed
FAITHFUL digest sha256:a55ee71351234dcdcf42d90a2a316a5b4fb4f94f4fddc1d9017af6c4d3360bba matches the commitment sealed in the receipt.
{
 "spec": "corobate:role-view:2",
 "role": "OPERATOR",
 "purpose": "Whoever must act on this decision now — release the goods, fund the draw, dispatch the agent, ship the title. Sees one instruction and the reason in plain words, and nothing that could be argued about while somebody waits.",
 "is_a_receipt": false,
 "warning": "This is a SCOPED COPY of a sealed decision, not the decision record itself. It will not verify as a receipt and must not be presented as one. To confirm it is faithful, recompute its `view` digest under the same canonicalisation that produces receipt_hash and compare it with the entry for this role in the source receipt’s `views` block.",
 "derived_from": {
  "receipt_hash": "sha256:6cfa106851e42c578947d59d107ffb474e39c813bc52723eb7102a95dc5a5e81",
  "entry_hash": "sha256:2955bbd1e87ad0cde1c0780e46dbe791796688fe9d626f467577319c4d1158ca",
  "issued_at": "2026-08-08T16:00:00.000Z"
 },
 "view_digest": "sha256:a55ee71351234dcdcf42d90a2a316a5b4fb4f94f4fddc1d9017af6c4d3360bba",
 "withheld": {
  "anything_withheld": true,
  "note": "Facts outside this role’s remit were removed. That something was removed is stated so a partial record is never mistaken for a complete one. How much, and what, is not stated — a count is an inference about the part you are not entitled to see."
 },
 "view": {
  "spec": "urn:ietf:params:corobate:receipt:1",
  "receipt_version": "1.8",
  "issued_at": "2026-08-08T16:00:00.000Z",
  "decision": {
   "id": "ai_TRIAGE_V4_before",
   "subject": "ai-system:TRIAGE-ASSISTANT-V4"
  },
  "memory": {
   "state_digest": "sha256:2d93db16d55c8de970115a836b580dcfdc4be9a6747a75d2d04c931322b48f90",
   "ledger_head": "sha256:7529436da173e2905b4859118dac726b0cd5c4c379029c2afc524393c0d06822",
   "coverage_gaps": [
    "ai-system:TRIAGE-ASSISTANT-V4|model_evaluation"
   ]
  },
  "verdict": {
   "value": "WITHHELD"
  },
  "release": {
   "state": "WITHHELD_NO_EVIDENCE"
  }
 }
}

Provider / assessed party

The cloud service provider, the release team, or the party operating the AI system — whoever is being assessed.

Sees which controls were required of them and by which publication and control identifier. Does not see the authorising official’s exposure figure or how any shortfall was priced.

What is outstanding on your file

  • model evaluation — required by National Institute of Standards and Technology, MEASURE-2.3 [VERIFY]
ClaimRequiredEvidence classWhoAgeOutcome
vulnerability_scanyesVERIFIED2026-08-04admitted
incident_response_plan_testyesVERIFIED2026-06-24admitted
security_resilience_evaluationyesVERIFIED2026-07-09admitted
penetration_testyesVERIFIED2026-06-09admitted
control_assessmentyesVERIFIED2026-04-30admitted
model_evaluationnoSELLER-ASSERTED2026-07-30withheld
model_evaluationyesMISSING2026-08-08coverage gap

The clause is here because it turns an argument into an errand. What is not here: what the bank had at stake, and whether anyone priced the shortfall.

The scoped copy itself — partial — something outside this role’s remit was removed
FAITHFUL digest sha256:52c328d680bca2ee092e2ee7075cfc8db037a9e77f8cbec6dcf6e12dcc12dee6 matches the commitment sealed in the receipt.
{
 "spec": "corobate:role-view:2",
 "role": "SUPPLIER",
 "purpose": "The party whose evidence was judged. Sees every claim the decision required, which fell short, and the clause that required it — and nothing about what the buyer had at stake or how the buyer priced any shortfall. NOTE, because an earlier draft of this sentence was untrue: this projection carries the WHOLE inputs array, so where several parties supplied evidence for one decision, each of them sees all of it. Per-party scoping cannot be expressed by a commitment scheme with one digest per role, and claiming it anyway would be the kind of promise this file exists to stop making.",
 "is_a_receipt": false,
 "warning": "This is a SCOPED COPY of a sealed decision, not the decision record itself. It will not verify as a receipt and must not be presented as one. To confirm it is faithful, recompute its `view` digest under the same canonicalisation that produces receipt_hash and compare it with the entry for this role in the source receipt’s `views` block.",
 "derived_from": {
  "receipt_hash": "sha256:6cfa106851e42c578947d59d107ffb474e39c813bc52723eb7102a95dc5a5e81",
  "entry_hash": "sha256:2955bbd1e87ad0cde1c0780e46dbe791796688fe9d626f467577319c4d1158ca",
  "issued_at": "2026-08-08T16:00:00.000Z"
 },
 "view_digest": "sha256:52c328d680bca2ee092e2ee7075cfc8db037a9e77f8cbec6dcf6e12dcc12dee6",
 "withheld": {
  "anything_withheld": true,
  "note": "Facts outside this role’s remit were removed. That something was removed is stated so a partial record is never mistaken for a complete one. How much, and what, is not stated — a count is an inference about the part you are not entitled to see."
 },
 "view": {
  "spec": "urn:ietf:params:corobate:receipt:1",
  "receipt_version": "1.8",
  "issued_at": "2026-08-08T16:00:00.000Z",
  "decision": {
   "id": "ai_TRIAGE_V4_before",
   "subject": "ai-system:TRIAGE-ASSISTANT-V4",
   "question": "May this AI system be deployed to triage citizen-facing casework?"
  },
  "memory": {
   "state_digest": "sha256:2d93db16d55c8de970115a836b580dcfdc4be9a6747a75d2d04c931322b48f90",
   "ledger_head": "sha256:7529436da173e2905b4859118dac726b0cd5c4c379029c2afc524393c0d06822",
   "coverage_gaps": [
    "ai-system:TRIAGE-ASSISTANT-V4|model_evaluation"
   ]
  },
  "verdict": {
   "value": "WITHHELD"
  },
  "inputs": [
   {
    "key": "ai-system:TRIAGE-ASSISTANT-V4::vulnerability_scan",
    "provenance": "VERIFIED",
    "observed_at": "2026-08-04T16:00:00.000Z",
    "memory_status": "admitted",
    "critical": true
   },
   {
    "key": "ai-system:TRIAGE-ASSISTANT-V4::incident_response_plan_test",
    "provenance": "VERIFIED",
    "observed_at": "2026-06-24T16:00:00.000Z",
    "memory_status": "admitted",
    "critical": true
   },
   {
    "key": "ai-system:TRIAGE-ASSISTANT-V4::security_resilience_evaluation",
    "provenance": "VERIFIED",
    "observed_at": "2026-07-09T16:00:00.000Z",
    "memory_status": "admitted",
    "critical": true
   },
   {
    "key": "ai-system:TRIAGE-ASSISTANT-V4::penetration_test",
    "provenance": "VERIFIED",
    "observed_at": "2026-06-09T16:00:00.000Z",
    "memory_status": "admitted",
    "critical": true
   },
   {
    "key": "ai-system:TRIAGE-ASSISTANT-V4::control_assessment",
    "provenance": "VERIFIED",
    "observed_at": "2026-04-30T16:00:00.000Z",
    "memory_status": "admitted",
    "critical": true
   },
   {
    "key": "ai-system:TRIAGE-ASSISTANT-V4::model_evaluation",
    "provenance": "SELLER-ASSERTED",
    "observed_at": "2026-07-30T16:00:00.000Z",
    "memory_status": "withheld",
    "critical": false
   },
   {
    "key": "ai-system:TRIAGE-ASSISTANT-V4::model_evaluation",
    "provenance": "MISSING",
    "observed_at": "2026-08-08T16:00:00.000Z",
    "memory_status": "coverage_gap",
    "critical": true
   }
  ],
  "regulatory": {
   "bindings": [
    {
     "claim": "control_assessment",
     "requirement": "max_age_days",
     "value": 365,
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
      "instrument_id": "nist-sp-800-53r5-moderate",
      "version": 5,
      "edition": "Rev. 5",
      "citation": "CA-2 [VERIFY]",
      "source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "control_assessment",
     "requirement": "min_class",
     "value": "VERIFIED",
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
      "instrument_id": "nist-sp-800-53r5-moderate",
      "version": 5,
      "edition": "Rev. 5",
      "citation": "CA-2(1) independent assessors [VERIFY]",
      "source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "control_assessment",
     "requirement": "required",
     "value": true,
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
      "instrument_id": "nist-sp-800-53r5-moderate",
      "version": 5,
      "edition": "Rev. 5",
      "citation": "CA-2 [VERIFY]",
      "source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "incident_response_plan_test",
     "requirement": "required",
     "value": true,
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "AI Risk Management Framework 1.0",
      "instrument_id": "nist-ai-rmf-1-0",
      "version": 1,
      "edition": "1.0",
      "citation": "MANAGE-4.1 [VERIFY]",
      "source_digest": "sha256:a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "model_evaluation",
     "requirement": "max_age_days",
     "value": 180,
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "AI Risk Management Framework 1.0",
      "instrument_id": "nist-ai-rmf-1-0",
      "version": 1,
      "edition": "1.0",
      "citation": "MEASURE-2.3 [VERIFY]",
      "source_digest": "sha256:a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "model_evaluation",
     "requirement": "min_class",
     "value": "VERIFIED",
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "AI Risk Management Framework 1.0",
      "instrument_id": "nist-ai-rmf-1-0",
      "version": 1,
      "edition": "1.0",
      "citation": "MEASURE-2.3 independent evaluation [VERIFY]",
      "source_digest": "sha256:a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "model_evaluation",
     "requirement": "required",
     "value": true,
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "AI Risk Management Framework 1.0",
      "instrument_id": "nist-ai-rmf-1-0",
      "version": 1,
      "edition": "1.0",
      "citation": "MEASURE-2.3 [VERIFY]",
      "source_digest": "sha256:a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "penetration_test",
     "requirement": "min_class",
     "value": "VERIFIED",
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
      "instrument_id": "nist-sp-800-53r5-moderate",
      "version": 5,
      "edition": "Rev. 5",
      "citation": "CA-8(1) independent penetration agent [VERIFY]",
      "source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "penetration_test",
     "requirement": "required",
     "value": true,
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
      "instrument_id": "nist-sp-800-53r5-moderate",
      "version": 5,
      "edition": "Rev. 5",
      "citation": "CA-8 [VERIFY]",
      "source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "security_resilience_evaluation",
     "requirement": "required",
     "value": true,
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "AI Risk Management Framework 1.0",
      "instrument_id": "nist-ai-rmf-1-0",
      "version": 1,
      "edition": "1.0",
      "citation": "MEASURE-2.7 [VERIFY]",
      "source_digest": "sha256:a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "vulnerability_scan",
     "requirement": "max_age_days",
     "value": 30,
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
      "instrument_id": "nist-sp-800-53r5-moderate",
      "version": 5,
      "edition": "Rev. 5",
      "citation": "RA-5(a) [VERIFY]",
      "source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "vulnerability_scan",
     "requirement": "required",
     "value": true,
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
      "instrument_id": "nist-sp-800-53r5-moderate",
      "version": 5,
      "edition": "Rev. 5",
      "citation": "RA-5 [VERIFY]",
      "source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    }
   ],
   "applied": [
    {
     "instrument_id": "nist-ai-rmf-1-0",
     "version": 1,
     "authority": "National Institute of Standards and Technology",
     "instrument": "AI Risk Management Framework 1.0",
     "edition": "1.0",
     "citation": "MEASURE-2.3, MEASURE-2.7, MANAGE-2.2 [VERIFY]",
     "source_digest": "sha256:a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1",
     "entered_by": "actor:human:issm",
     "entered_at": "2026-08-08T16:00:00.000Z"
    },
    {
     "instrument_id": "nist-sp-800-53r5-moderate",
     "version": 5,
     "authority": "National Institute of Standards and Technology",
     "instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
     "edition": "Rev. 5",
     "citation": "CA-2, CA-8, RA-5, SR-6 [VERIFY]",
     "source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353",
     "entered_by": "actor:human:issm",
     "entered_at": "2026-08-08T16:00:00.000Z"
    }
   ],
   "defaults": [
    {
     "claim": "control_assessment",
     "requirement": "ai_position",
     "value": "ADMIT",
     "because": "No instrument in force stated a position on AI-authored evidence for \"control_assessment\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
    },
    {
     "claim": "incident_response_plan_test",
     "requirement": "ai_position",
     "value": "ADMIT",
     "because": "No instrument in force stated a position on AI-authored evidence for \"incident_response_plan_test\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
    },
    {
     "claim": "model_evaluation",
     "requirement": "ai_position",
     "value": "ADMIT",
     "because": "No instrument in force stated a position on AI-authored evidence for \"model_evaluation\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
    },
    {
     "claim": "penetration_test",
     "requirement": "ai_position",
     "value": "ADMIT",
     "because": "No instrument in force stated a position on AI-authored evidence for \"penetration_test\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
    },
    {
     "claim": "security_resilience_evaluation",
     "requirement": "ai_position",
     "value": "ADMIT",
     "because": "No instrument in force stated a position on AI-authored evidence for \"security_resilience_evaluation\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
    },
    {
     "claim": "vulnerability_scan",
     "requirement": "ai_position",
     "value": "ADMIT",
     "because": "No instrument in force stated a position on AI-authored evidence for \"vulnerability_scan\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
    }
   ]
  }
 }
}

Assessor / authorising official

A third-party assessment organisation, an agency assessor, or an inspector general reviewing the package. Same position as a customs officer: a public mandate over the record.

The control record in full — each publication by control identifier, edition and document digest, and every required claim with who supplied it and when. No exposure figure, no risk pricing, no confidence score.

National Institute of Standards and Technology
AI Risk Management Framework 1.0
MEASURE-2.3, MEASURE-2.7, MANAGE-2.2 [VERIFY] · edition 1.0
document sha256:a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1
entered by actor:human:issm
National Institute of Standards and Technology
SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)
CA-2, CA-8, RA-5, SR-6 [VERIFY] · edition Rev. 5
document sha256:5353535353535353535353535353535353535353535353535353535353535353
entered by actor:human:issm

What each authority bound

ClaimRequirementLevelBound by
control_assessmentmax age days365National Institute of Standards and Technology
CA-2 [VERIFY] · SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)
control_assessmentmin classVERIFIEDNational Institute of Standards and Technology
CA-2(1) independent assessors [VERIFY] · SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)
control_assessmentrequiredtrueNational Institute of Standards and Technology
CA-2 [VERIFY] · SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)
incident_response_plan_testrequiredtrueNational Institute of Standards and Technology
MANAGE-4.1 [VERIFY] · AI Risk Management Framework 1.0
model_evaluationmax age days180National Institute of Standards and Technology
MEASURE-2.3 [VERIFY] · AI Risk Management Framework 1.0
model_evaluationmin classVERIFIEDNational Institute of Standards and Technology
MEASURE-2.3 independent evaluation [VERIFY] · AI Risk Management Framework 1.0
model_evaluationrequiredtrueNational Institute of Standards and Technology
MEASURE-2.3 [VERIFY] · AI Risk Management Framework 1.0
penetration_testmin classVERIFIEDNational Institute of Standards and Technology
CA-8(1) independent penetration agent [VERIFY] · SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)
penetration_testrequiredtrueNational Institute of Standards and Technology
CA-8 [VERIFY] · SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)
security_resilience_evaluationrequiredtrueNational Institute of Standards and Technology
MEASURE-2.7 [VERIFY] · AI Risk Management Framework 1.0
vulnerability_scanmax age days30National Institute of Standards and Technology
RA-5(a) [VERIFY] · SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)
vulnerability_scanrequiredtrueNational Institute of Standards and Technology
RA-5 [VERIFY] · SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)

Every required claim, and what was actually held

ClaimRequiredEvidence classWhoAgeOutcome
vulnerability_scanyesVERIFIEDactor:sys:registry:nvd-cve2026-08-04admitted
incident_response_plan_testyesVERIFIEDactor:org:CERT-3PAO-ATLANTIC2026-06-24admitted
security_resilience_evaluationyesVERIFIEDactor:org:LAB-NVLAP-04122026-07-09admitted
penetration_testyesVERIFIEDactor:org:LAB-NVLAP-04122026-06-09admitted
control_assessmentyesVERIFIEDactor:org:CERT-3PAO-ATLANTIC2026-04-30admitted
model_evaluationnoSELLER-ASSERTEDactor:ai:triage-assistant-v42026-07-30withheld
model_evaluationyesMISSING2026-08-08coverage gap
Absent from this copy, deliberatelyNo exposure figure, no risk pricing, no confidence score, no release quorum. The examiner’s claim is on the record of what was required and what was held — answered here completely, down to the digest of the document each requirement was configured from. The institution’s commercial position is a different question and this document does not answer it. The published verifier checks that on the content of the copy, not on the intentions of whoever produced it.
The scoped copy itself — partial — something outside this role’s remit was removed
FAITHFUL digest sha256:d30bc8c891dbcff157241a0529b9c212ecdf2739b6af22a057b1aab77f437d40 matches the commitment sealed in the receipt.
{
 "spec": "corobate:role-view:2",
 "role": "REGULATOR",
 "purpose": "An official holding a public mandate over this record — a customs officer, a bank examiner, a market conduct supervisor. Sees the regulatory record in full: their own instrument named, every required claim and whether it was met, by whom, how old. No commercial figure of any kind.",
 "is_a_receipt": false,
 "warning": "This is a SCOPED COPY of a sealed decision, not the decision record itself. It will not verify as a receipt and must not be presented as one. To confirm it is faithful, recompute its `view` digest under the same canonicalisation that produces receipt_hash and compare it with the entry for this role in the source receipt’s `views` block.",
 "derived_from": {
  "receipt_hash": "sha256:6cfa106851e42c578947d59d107ffb474e39c813bc52723eb7102a95dc5a5e81",
  "entry_hash": "sha256:2955bbd1e87ad0cde1c0780e46dbe791796688fe9d626f467577319c4d1158ca",
  "issued_at": "2026-08-08T16:00:00.000Z"
 },
 "view_digest": "sha256:d30bc8c891dbcff157241a0529b9c212ecdf2739b6af22a057b1aab77f437d40",
 "withheld": {
  "anything_withheld": true,
  "note": "Facts outside this role’s remit were removed. That something was removed is stated so a partial record is never mistaken for a complete one. How much, and what, is not stated — a count is an inference about the part you are not entitled to see."
 },
 "view": {
  "spec": "urn:ietf:params:corobate:receipt:1",
  "receipt_version": "1.8",
  "issued_at": "2026-08-08T16:00:00.000Z",
  "decision": {
   "id": "ai_TRIAGE_V4_before",
   "subject": "ai-system:TRIAGE-ASSISTANT-V4",
   "question": "May this AI system be deployed to triage citizen-facing casework?"
  },
  "memory": {
   "state_digest": "sha256:2d93db16d55c8de970115a836b580dcfdc4be9a6747a75d2d04c931322b48f90",
   "ledger_head": "sha256:7529436da173e2905b4859118dac726b0cd5c4c379029c2afc524393c0d06822",
   "coverage_gaps": [
    "ai-system:TRIAGE-ASSISTANT-V4|model_evaluation"
   ]
  },
  "data_horizon": "2026-08-08T16:00:00.000Z",
  "verdict": {
   "value": "WITHHELD"
  },
  "regulatory": {
   "spec": "corobate:regulatory:2",
   "resolved": true,
   "applied": [
    {
     "instrument_id": "nist-ai-rmf-1-0",
     "version": 1,
     "authority": "National Institute of Standards and Technology",
     "instrument": "AI Risk Management Framework 1.0",
     "edition": "1.0",
     "citation": "MEASURE-2.3, MEASURE-2.7, MANAGE-2.2 [VERIFY]",
     "source_digest": "sha256:a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1",
     "entered_by": "actor:human:issm",
     "entered_at": "2026-08-08T16:00:00.000Z"
    },
    {
     "instrument_id": "nist-sp-800-53r5-moderate",
     "version": 5,
     "authority": "National Institute of Standards and Technology",
     "instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
     "edition": "Rev. 5",
     "citation": "CA-2, CA-8, RA-5, SR-6 [VERIFY]",
     "source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353",
     "entered_by": "actor:human:issm",
     "entered_at": "2026-08-08T16:00:00.000Z"
    }
   ],
   "skipped": [],
   "conflicts": [],
   "bindings": [
    {
     "claim": "control_assessment",
     "requirement": "max_age_days",
     "value": 365,
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
      "instrument_id": "nist-sp-800-53r5-moderate",
      "version": 5,
      "edition": "Rev. 5",
      "citation": "CA-2 [VERIFY]",
      "source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "control_assessment",
     "requirement": "min_class",
     "value": "VERIFIED",
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
      "instrument_id": "nist-sp-800-53r5-moderate",
      "version": 5,
      "edition": "Rev. 5",
      "citation": "CA-2(1) independent assessors [VERIFY]",
      "source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "control_assessment",
     "requirement": "required",
     "value": true,
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
      "instrument_id": "nist-sp-800-53r5-moderate",
      "version": 5,
      "edition": "Rev. 5",
      "citation": "CA-2 [VERIFY]",
      "source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "incident_response_plan_test",
     "requirement": "required",
     "value": true,
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "AI Risk Management Framework 1.0",
      "instrument_id": "nist-ai-rmf-1-0",
      "version": 1,
      "edition": "1.0",
      "citation": "MANAGE-4.1 [VERIFY]",
      "source_digest": "sha256:a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "model_evaluation",
     "requirement": "max_age_days",
     "value": 180,
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "AI Risk Management Framework 1.0",
      "instrument_id": "nist-ai-rmf-1-0",
      "version": 1,
      "edition": "1.0",
      "citation": "MEASURE-2.3 [VERIFY]",
      "source_digest": "sha256:a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "model_evaluation",
     "requirement": "min_class",
     "value": "VERIFIED",
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "AI Risk Management Framework 1.0",
      "instrument_id": "nist-ai-rmf-1-0",
      "version": 1,
      "edition": "1.0",
      "citation": "MEASURE-2.3 independent evaluation [VERIFY]",
      "source_digest": "sha256:a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "model_evaluation",
     "requirement": "required",
     "value": true,
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "AI Risk Management Framework 1.0",
      "instrument_id": "nist-ai-rmf-1-0",
      "version": 1,
      "edition": "1.0",
      "citation": "MEASURE-2.3 [VERIFY]",
      "source_digest": "sha256:a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "penetration_test",
     "requirement": "min_class",
     "value": "VERIFIED",
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
      "instrument_id": "nist-sp-800-53r5-moderate",
      "version": 5,
      "edition": "Rev. 5",
      "citation": "CA-8(1) independent penetration agent [VERIFY]",
      "source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "penetration_test",
     "requirement": "required",
     "value": true,
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
      "instrument_id": "nist-sp-800-53r5-moderate",
      "version": 5,
      "edition": "Rev. 5",
      "citation": "CA-8 [VERIFY]",
      "source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "security_resilience_evaluation",
     "requirement": "required",
     "value": true,
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "AI Risk Management Framework 1.0",
      "instrument_id": "nist-ai-rmf-1-0",
      "version": 1,
      "edition": "1.0",
      "citation": "MEASURE-2.7 [VERIFY]",
      "source_digest": "sha256:a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "vulnerability_scan",
     "requirement": "max_age_days",
     "value": 30,
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
      "instrument_id": "nist-sp-800-53r5-moderate",
      "version": 5,
      "edition": "Rev. 5",
      "citation": "RA-5(a) [VERIFY]",
      "source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "vulnerability_scan",
     "requirement": "required",
     "value": true,
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
      "instrument_id": "nist-sp-800-53r5-moderate",
      "version": 5,
      "edition": "Rev. 5",
      "citation": "RA-5 [VERIFY]",
      "source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    }
   ],
   "defaults": [
    {
     "claim": "control_assessment",
     "requirement": "ai_position",
     "value": "ADMIT",
     "because": "No instrument in force stated a position on AI-authored evidence for \"control_assessment\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
    },
    {
     "claim": "incident_response_plan_test",
     "requirement": "ai_position",
     "value": "ADMIT",
     "because": "No instrument in force stated a position on AI-authored evidence for \"incident_response_plan_test\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
    },
    {
     "claim": "model_evaluation",
     "requirement": "ai_position",
     "value": "ADMIT",
     "because": "No instrument in force stated a position on AI-authored evidence for \"model_evaluation\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
    },
    {
     "claim": "penetration_test",
     "requirement": "ai_position",
     "value": "ADMIT",
     "because": "No instrument in force stated a position on AI-authored evidence for \"penetration_test\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
    },
    {
     "claim": "security_resilience_evaluation",
     "requirement": "ai_position",
     "value": "ADMIT",
     "because": "No instrument in force stated a position on AI-authored evidence for \"security_resilience_evaluation\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
    },
    {
     "claim": "vulnerability_scan",
     "requirement": "ai_position",
     "value": "ADMIT",
     "because": "No instrument in force stated a position on AI-authored evidence for \"vulnerability_scan\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
    }
   ]
  },
  "inputs": [
   {
    "key": "ai-system:TRIAGE-ASSISTANT-V4::vulnerability_scan",
    "provenance": "VERIFIED",
    "source": "nvd-cve:vulnerability_scan",
    "observed_at": "2026-08-04T16:00:00.000Z",
    "critical": true,
    "memory_status": "admitted",
    "memory_actor": "actor:sys:registry:nvd-cve"
   },
   {
    "key": "ai-system:TRIAGE-ASSISTANT-V4::incident_response_plan_test",
    "provenance": "VERIFIED",
    "source": "CERT-3PAO-ATLANTIC:incident_response_plan_test",
    "observed_at": "2026-06-24T16:00:00.000Z",
    "critical": true,
    "memory_status": "admitted",
    "memory_actor": "actor:org:CERT-3PAO-ATLANTIC"
   },
   {
    "key": "ai-system:TRIAGE-ASSISTANT-V4::security_resilience_evaluation",
    "provenance": "VERIFIED",
    "source": "LAB-NVLAP-0412:security_resilience_evaluation",
    "observed_at": "2026-07-09T16:00:00.000Z",
    "critical": true,
    "memory_status": "admitted",
    "memory_actor": "actor:org:LAB-NVLAP-0412"
   },
   {
    "key": "ai-system:TRIAGE-ASSISTANT-V4::penetration_test",
    "provenance": "VERIFIED",
    "source": "LAB-NVLAP-0412:penetration_test",
    "observed_at": "2026-06-09T16:00:00.000Z",
    "critical": true,
    "memory_status": "admitted",
    "memory_actor": "actor:org:LAB-NVLAP-0412"
   },
   {
    "key": "ai-system:TRIAGE-ASSISTANT-V4::control_assessment",
    "provenance": "VERIFIED",
    "source": "CERT-3PAO-ATLANTIC:control_assessment",
    "observed_at": "2026-04-30T16:00:00.000Z",
    "critical": true,
    "memory_status": "admitted",
    "memory_actor": "actor:org:CERT-3PAO-ATLANTIC"
   },
   {
    "key": "ai-system:TRIAGE-ASSISTANT-V4::model_evaluation",
    "provenance": "SELLER-ASSERTED",
    "source": "triage-assistant-v4:model_evaluation",
    "observed_at": "2026-07-30T16:00:00.000Z",
    "critical": false,
    "memory_status": "withheld",
    "memory_actor": "actor:ai:triage-assistant-v4"
   },
   {
    "key": "ai-system:TRIAGE-ASSISTANT-V4::model_evaluation",
    "provenance": "MISSING",
    "source": null,
    "observed_at": "2026-08-08T16:00:00.000Z",
    "critical": true,
    "memory_status": "coverage_gap"
   }
  ],
  "crypto_suite": {
   "spec": "corobate:suite:1",
   "id": "CB-1-ES256-SHA256",
   "receipt_digest": "sha256",
   "chain_digest": "sha256",
   "content_digest": "sha256",
   "envelope_signature": "ES256",
   "signature_curve": "P-256",
   "canonicalisation": "attest-canon/2",
   "quantum_resistant": false
  }
 }
}

ISSM / control owner

The information system security manager and the control owners who hold the package.

The fullest internal view: every input, its class, its age, its score, the exposure, and every publication in force.

VerdictWITHHELD
Confidence0%
bound by model_evaluation
Exposure$1,400,000
ReleaseWITHHELD_NO_EVIDENCE
Risk acceptedNONE

Every input the gate saw

ClaimRequiredEvidence classWhoAgeScoreOutcome
vulnerability_scanyesVERIFIEDactor:sys:registry:nvd-cve4d95%admitted
incident_response_plan_testyesVERIFIEDactor:org:CERT-3PAO-ATLANTIC45d95%admitted
security_resilience_evaluationyesVERIFIEDactor:org:LAB-NVLAP-041230d95%admitted
penetration_testyesVERIFIEDactor:org:LAB-NVLAP-041260d95%admitted
control_assessmentyesVERIFIEDactor:org:CERT-3PAO-ATLANTIC100d95%admitted
model_evaluationnoSELLER-ASSERTEDactor:ai:triage-assistant-v49d50%withheld
model_evaluationyesMISSING2026-08-080%coverage gap

Instruments in force

National Institute of Standards and Technology
AI Risk Management Framework 1.0
MEASURE-2.3, MEASURE-2.7, MANAGE-2.2 [VERIFY] · edition 1.0
document sha256:a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1
entered by actor:human:issm
National Institute of Standards and Technology
SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)
CA-2, CA-8, RA-5, SR-6 [VERIFY] · edition Rev. 5
document sha256:5353535353535353535353535353535353535353535353535353535353535353
entered by actor:human:issm

Why

  • Coverage gap: no admissible memory for required claim(s) ai-system:TRIAGE-ASSISTANT-V4|model_evaluation.
  • Confidence 0.00% is bound by "ai-system:TRIAGE-ASSISTANT-V4|model_evaluation".
  • 1 memory was withheld from the context block: ai-system:TRIAGE-ASSISTANT-V4|model_evaluation (below class floor: rule requires at least VERIFIED, held SELLER-ASSERTED — inadmissible at any exposure).
  • Thresholds for $1,400,000 exposure: approve 90%, caution 70%.
The scoped copy itself — partial — something outside this role’s remit was removed
FAITHFUL digest sha256:4572cb29ae4eb49c43beda0b02708048b6b23c4a8fbbddf1f8f21978982a9d55 matches the commitment sealed in the receipt.
{
 "spec": "corobate:role-view:2",
 "role": "COMPLIANCE",
 "purpose": "The operator’s own compliance function. The fullest internal view: every gap, every instrument in force, the waivability of each requirement and who accepted what.",
 "is_a_receipt": false,
 "warning": "This is a SCOPED COPY of a sealed decision, not the decision record itself. It will not verify as a receipt and must not be presented as one. To confirm it is faithful, recompute its `view` digest under the same canonicalisation that produces receipt_hash and compare it with the entry for this role in the source receipt’s `views` block.",
 "derived_from": {
  "receipt_hash": "sha256:6cfa106851e42c578947d59d107ffb474e39c813bc52723eb7102a95dc5a5e81",
  "entry_hash": "sha256:2955bbd1e87ad0cde1c0780e46dbe791796688fe9d626f467577319c4d1158ca",
  "issued_at": "2026-08-08T16:00:00.000Z"
 },
 "view_digest": "sha256:4572cb29ae4eb49c43beda0b02708048b6b23c4a8fbbddf1f8f21978982a9d55",
 "withheld": {
  "anything_withheld": true,
  "note": "Facts outside this role’s remit were removed. That something was removed is stated so a partial record is never mistaken for a complete one. How much, and what, is not stated — a count is an inference about the part you are not entitled to see."
 },
 "view": {
  "spec": "urn:ietf:params:corobate:receipt:1",
  "receipt_version": "1.8",
  "issued_at": "2026-08-08T16:00:00.000Z",
  "decision": {
   "id": "ai_TRIAGE_V4_before",
   "domain": "supply-chain",
   "subject": "ai-system:TRIAGE-ASSISTANT-V4",
   "question": "May this AI system be deployed to triage citizen-facing casework?"
  },
  "memory": {
   "state_digest": "sha256:2d93db16d55c8de970115a836b580dcfdc4be9a6747a75d2d04c931322b48f90",
   "ledger_head": "sha256:7529436da173e2905b4859118dac726b0cd5c4c379029c2afc524393c0d06822",
   "coverage_gaps": [
    "ai-system:TRIAGE-ASSISTANT-V4|model_evaluation"
   ],
   "exposure": {
    "usd": 1400000,
    "declared_by": "actor:human:ao-authorizing-official",
    "ledger_seq": 6
   },
   "policy_digest": "sha256:a6b69b7d20f7fb04d522364af1d92992058b04a5835fcec9d1c9f2261c7ef636"
  },
  "data_horizon": "2026-08-08T16:00:00.000Z",
  "verdict": {
   "value": "WITHHELD",
   "threshold_approve": 0.9,
   "threshold_caution": 0.7,
   "rule": "confidence>=threshold"
  },
  "confidence": {
   "value": 0,
   "method": "min-over-critical-inputs",
   "bound_by": "ai-system:TRIAGE-ASSISTANT-V4::model_evaluation"
  },
  "release": {
   "required": false,
   "required_by_tier": false,
   "escalated_by_acceptance": false,
   "risk_accepted": false,
   "state": "WITHHELD_NO_EVIDENCE",
   "code": "QUORUM_EVIDENCE_WITHHELD",
   "reason": "the evidence did not clear the threshold for this exposure, so there is nothing to release. Signatures do not substitute for evidence, and this state is deliberately distinct from WITHHELD_PENDING_SIGNATURES: a reader must be able to tell \"the evidence is not there\" from \"the evidence is there and 0 of 2 people have signed\".",
   "tier_floor_cents": 1000000000,
   "exposure_usd_cents": 140000000,
   "required_m": 2,
   "declared_n": 3,
   "floor_m": 2,
   "distinct_signers": 0,
   "superseded": 0,
   "collapsed": 0,
   "release_digest": "sha256:49e46dc99310dfb4f669746425dfb108ff1f2d3e71c03f35b99c9f14211809df",
   "governance_digest": "sha256:8b0a45a27fcce9c1c243c764e855e67c6fe6dfd7f02a563bd90809b419731905",
   "governance_signed": true,
   "counted_voices": [],
   "signatures": [],
   "ledger_seq": null
  },
  "acceptance": {
   "state": "NONE",
   "code": "ACCEPTANCE_NONE",
   "reason": "no risk acceptance was presented for this decision. This is the ordinary case: a refusal is a refusal unless a named person has priced it.",
   "permitted_basis": null,
   "presented": 0,
   "superseded": 0,
   "expired": 0,
   "gaps_not_covered": 0,
   "coverage_gaps_in_force": [
    "ai-system:TRIAGE-ASSISTANT-V4|model_evaluation"
   ],
   "evidentiary_digest": "sha256:49e46dc99310dfb4f669746425dfb108ff1f2d3e71c03f35b99c9f14211809df",
   "margin_floor_bp": 100,
   "authority_ceiling_cents": {
    "SUPERVISOR": 1000000,
    "MANAGER": 25000000,
    "DIRECTOR": 500000000,
    "OFFICER": 5000000000
   },
   "acceptances": [],
   "escalated": false,
   "live": false,
   "ledger_seq": null
  },
  "regulatory": {
   "spec": "corobate:regulatory:2",
   "resolved": true,
   "applied": [
    {
     "instrument_id": "nist-ai-rmf-1-0",
     "version": 1,
     "authority": "National Institute of Standards and Technology",
     "instrument": "AI Risk Management Framework 1.0",
     "edition": "1.0",
     "citation": "MEASURE-2.3, MEASURE-2.7, MANAGE-2.2 [VERIFY]",
     "source_digest": "sha256:a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1",
     "entered_by": "actor:human:issm",
     "entered_at": "2026-08-08T16:00:00.000Z"
    },
    {
     "instrument_id": "nist-sp-800-53r5-moderate",
     "version": 5,
     "authority": "National Institute of Standards and Technology",
     "instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
     "edition": "Rev. 5",
     "citation": "CA-2, CA-8, RA-5, SR-6 [VERIFY]",
     "source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353",
     "entered_by": "actor:human:issm",
     "entered_at": "2026-08-08T16:00:00.000Z"
    }
   ],
   "skipped": [],
   "conflicts": [],
   "bindings": [
    {
     "claim": "control_assessment",
     "requirement": "max_age_days",
     "value": 365,
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
      "instrument_id": "nist-sp-800-53r5-moderate",
      "version": 5,
      "edition": "Rev. 5",
      "citation": "CA-2 [VERIFY]",
      "source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "control_assessment",
     "requirement": "min_class",
     "value": "VERIFIED",
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
      "instrument_id": "nist-sp-800-53r5-moderate",
      "version": 5,
      "edition": "Rev. 5",
      "citation": "CA-2(1) independent assessors [VERIFY]",
      "source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "control_assessment",
     "requirement": "required",
     "value": true,
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
      "instrument_id": "nist-sp-800-53r5-moderate",
      "version": 5,
      "edition": "Rev. 5",
      "citation": "CA-2 [VERIFY]",
      "source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "incident_response_plan_test",
     "requirement": "required",
     "value": true,
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "AI Risk Management Framework 1.0",
      "instrument_id": "nist-ai-rmf-1-0",
      "version": 1,
      "edition": "1.0",
      "citation": "MANAGE-4.1 [VERIFY]",
      "source_digest": "sha256:a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "model_evaluation",
     "requirement": "max_age_days",
     "value": 180,
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "AI Risk Management Framework 1.0",
      "instrument_id": "nist-ai-rmf-1-0",
      "version": 1,
      "edition": "1.0",
      "citation": "MEASURE-2.3 [VERIFY]",
      "source_digest": "sha256:a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "model_evaluation",
     "requirement": "min_class",
     "value": "VERIFIED",
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "AI Risk Management Framework 1.0",
      "instrument_id": "nist-ai-rmf-1-0",
      "version": 1,
      "edition": "1.0",
      "citation": "MEASURE-2.3 independent evaluation [VERIFY]",
      "source_digest": "sha256:a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "model_evaluation",
     "requirement": "required",
     "value": true,
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "AI Risk Management Framework 1.0",
      "instrument_id": "nist-ai-rmf-1-0",
      "version": 1,
      "edition": "1.0",
      "citation": "MEASURE-2.3 [VERIFY]",
      "source_digest": "sha256:a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "penetration_test",
     "requirement": "min_class",
     "value": "VERIFIED",
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
      "instrument_id": "nist-sp-800-53r5-moderate",
      "version": 5,
      "edition": "Rev. 5",
      "citation": "CA-8(1) independent penetration agent [VERIFY]",
      "source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "penetration_test",
     "requirement": "required",
     "value": true,
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
      "instrument_id": "nist-sp-800-53r5-moderate",
      "version": 5,
      "edition": "Rev. 5",
      "citation": "CA-8 [VERIFY]",
      "source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "security_resilience_evaluation",
     "requirement": "required",
     "value": true,
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "AI Risk Management Framework 1.0",
      "instrument_id": "nist-ai-rmf-1-0",
      "version": 1,
      "edition": "1.0",
      "citation": "MEASURE-2.7 [VERIFY]",
      "source_digest": "sha256:a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "vulnerability_scan",
     "requirement": "max_age_days",
     "value": 30,
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
      "instrument_id": "nist-sp-800-53r5-moderate",
      "version": 5,
      "edition": "Rev. 5",
      "citation": "RA-5(a) [VERIFY]",
      "source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "vulnerability_scan",
     "requirement": "required",
     "value": true,
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
      "instrument_id": "nist-sp-800-53r5-moderate",
      "version": 5,
      "edition": "Rev. 5",
      "citation": "RA-5 [VERIFY]",
      "source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    }
   ],
   "defaults": [
    {
     "claim": "control_assessment",
     "requirement": "ai_position",
     "value": "ADMIT",
     "because": "No instrument in force stated a position on AI-authored evidence for \"control_assessment\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
    },
    {
     "claim": "incident_response_plan_test",
     "requirement": "ai_position",
     "value": "ADMIT",
     "because": "No instrument in force stated a position on AI-authored evidence for \"incident_response_plan_test\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
    },
    {
     "claim": "model_evaluation",
     "requirement": "ai_position",
     "value": "ADMIT",
     "because": "No instrument in force stated a position on AI-authored evidence for \"model_evaluation\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
    },
    {
     "claim": "penetration_test",
     "requirement": "ai_position",
     "value": "ADMIT",
     "because": "No instrument in force stated a position on AI-authored evidence for \"penetration_test\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
    },
    {
     "claim": "security_resilience_evaluation",
     "requirement": "ai_position",
     "value": "ADMIT",
     "because": "No instrument in force stated a position on AI-authored evidence for \"security_resilience_evaluation\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
    },
    {
     "claim": "vulnerability_scan",
     "requirement": "ai_position",
     "value": "ADMIT",
     "because": "No instrument in force stated a position on AI-authored evidence for \"vulnerability_scan\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
    }
   ]
  },
  "reasons": [
   "Coverage gap: no admissible memory for required claim(s) ai-system:TRIAGE-ASSISTANT-V4|model_evaluation.",
   "Confidence 0.00% is bound by \"ai-system:TRIAGE-ASSISTANT-V4|model_evaluation\".",
   "1 memory was withheld from the context block: ai-system:TRIAGE-ASSISTANT-V4|model_evaluation (below class floor: rule requires at least VERIFIED, held SELLER-ASSERTED — inadmissible at any exposure).",
   "Thresholds for $1,400,000 exposure: approve 90%, caution 70%."
  ],
  "inputs": [
   {
    "key": "ai-system:TRIAGE-ASSISTANT-V4::vulnerability_scan",
    "value": "clean-at-scan",
    "provenance": "VERIFIED",
    "source": "nvd-cve:vulnerability_scan",
    "observed_at": "2026-08-04T16:00:00.000Z",
    "reliability": 0.95,
    "critical": true,
    "memory_status": "admitted",
    "memory_kind": "status",
    "memory_actor": "actor:sys:registry:nvd-cve",
    "memory_age_days": 4
   },
   {
    "key": "ai-system:TRIAGE-ASSISTANT-V4::incident_response_plan_test",
    "value": "observed",
    "provenance": "VERIFIED",
    "source": "CERT-3PAO-ATLANTIC:incident_response_plan_test",
    "observed_at": "2026-06-24T16:00:00.000Z",
    "reliability": 0.95,
    "critical": true,
    "memory_status": "admitted",
    "memory_kind": "certificate",
    "memory_actor": "actor:org:CERT-3PAO-ATLANTIC",
    "memory_age_days": 45
   },
   {
    "key": "ai-system:TRIAGE-ASSISTANT-V4::security_resilience_evaluation",
    "value": "assessed",
    "provenance": "VERIFIED",
    "source": "LAB-NVLAP-0412:security_resilience_evaluation",
    "observed_at": "2026-07-09T16:00:00.000Z",
    "reliability": 0.95,
    "critical": true,
    "memory_status": "admitted",
    "memory_kind": "test_report",
    "memory_actor": "actor:org:LAB-NVLAP-0412",
    "memory_age_days": 30
   },
   {
    "key": "ai-system:TRIAGE-ASSISTANT-V4::penetration_test",
    "value": "no-critical",
    "provenance": "VERIFIED",
    "source": "LAB-NVLAP-0412:penetration_test",
    "observed_at": "2026-06-09T16:00:00.000Z",
    "reliability": 0.95,
    "critical": true,
    "memory_status": "admitted",
    "memory_kind": "test_report",
    "memory_actor": "actor:org:LAB-NVLAP-0412",
    "memory_age_days": 60
   },
   {
    "key": "ai-system:TRIAGE-ASSISTANT-V4::control_assessment",
    "value": "satisfied",
    "provenance": "VERIFIED",
    "source": "CERT-3PAO-ATLANTIC:control_assessment",
    "observed_at": "2026-04-30T16:00:00.000Z",
    "reliability": 0.95,
    "critical": true,
    "memory_status": "admitted",
    "memory_kind": "certificate",
    "memory_actor": "actor:org:CERT-3PAO-ATLANTIC",
    "memory_age_days": 100
   },
   {
    "key": "ai-system:TRIAGE-ASSISTANT-V4::model_evaluation",
    "value": null,
    "provenance": "SELLER-ASSERTED",
    "source": "triage-assistant-v4:model_evaluation",
    "observed_at": "2026-07-30T16:00:00.000Z",
    "reliability": 0.5,
    "critical": false,
    "memory_status": "withheld",
    "memory_kind": "test_report",
    "memory_actor": "actor:ai:triage-assistant-v4",
    "memory_age_days": 9
   },
   {
    "key": "ai-system:TRIAGE-ASSISTANT-V4::model_evaluation",
    "value": null,
    "provenance": "MISSING",
    "source": null,
    "observed_at": "2026-08-08T16:00:00.000Z",
    "reliability": 0,
    "critical": true,
    "memory_status": "coverage_gap"
   }
  ],
  "crypto_suite": {
   "spec": "corobate:suite:1",
   "id": "CB-1-ES256-SHA256",
   "receipt_digest": "sha256",
   "chain_digest": "sha256",
   "content_digest": "sha256",
   "envelope_signature": "ES256",
   "signature_curve": "P-256",
   "canonicalisation": "attest-canon/2",
   "quantum_resistant": false
  }
 }
}

Authorising official (signer)

The named official whose signature carries the authorisation decision.

What is at stake, what the evidence supports, what is missing, and the digest they are signing over.

You are being asked to sign

May this AI system be deployed to triage citizen-facing casework?

At stake$1,400,000
Evidence saysWITHHELD
Release stateWITHHELD_NO_EVIDENCE
signing over evidentiary digest sha256:49e46dc99310dfb4f669746425dfb108ff1f2d3e71c03f35b99c9f14211809df

The signature is over the STATE OF THE EVIDENCE. Move one fact behind this decision and the digest moves and the signature stops counting — which is what makes it safe to collect signatures before everyone is in the room.

What is missing

  • model evaluation
The scoped copy itself — partial — something outside this role’s remit was removed
FAITHFUL digest sha256:b2b81493f4d95918b2eee35db343860df5d0a15d2cce12a0af4f5a10d2e63e83 matches the commitment sealed in the receipt.
{
 "spec": "corobate:role-view:2",
 "role": "EXECUTIVE",
 "purpose": "A named signer on the release gate. Sees what is at stake, what the evidence supports, who else has signed and what they are being asked to sign over.",
 "is_a_receipt": false,
 "warning": "This is a SCOPED COPY of a sealed decision, not the decision record itself. It will not verify as a receipt and must not be presented as one. To confirm it is faithful, recompute its `view` digest under the same canonicalisation that produces receipt_hash and compare it with the entry for this role in the source receipt’s `views` block.",
 "derived_from": {
  "receipt_hash": "sha256:6cfa106851e42c578947d59d107ffb474e39c813bc52723eb7102a95dc5a5e81",
  "entry_hash": "sha256:2955bbd1e87ad0cde1c0780e46dbe791796688fe9d626f467577319c4d1158ca",
  "issued_at": "2026-08-08T16:00:00.000Z"
 },
 "view_digest": "sha256:b2b81493f4d95918b2eee35db343860df5d0a15d2cce12a0af4f5a10d2e63e83",
 "withheld": {
  "anything_withheld": true,
  "note": "Facts outside this role’s remit were removed. That something was removed is stated so a partial record is never mistaken for a complete one. How much, and what, is not stated — a count is an inference about the part you are not entitled to see."
 },
 "view": {
  "spec": "urn:ietf:params:corobate:receipt:1",
  "receipt_version": "1.8",
  "issued_at": "2026-08-08T16:00:00.000Z",
  "decision": {
   "id": "ai_TRIAGE_V4_before",
   "domain": "supply-chain",
   "subject": "ai-system:TRIAGE-ASSISTANT-V4",
   "question": "May this AI system be deployed to triage citizen-facing casework?"
  },
  "memory": {
   "state_digest": "sha256:2d93db16d55c8de970115a836b580dcfdc4be9a6747a75d2d04c931322b48f90",
   "ledger_head": "sha256:7529436da173e2905b4859118dac726b0cd5c4c379029c2afc524393c0d06822",
   "coverage_gaps": [
    "ai-system:TRIAGE-ASSISTANT-V4|model_evaluation"
   ],
   "exposure": {
    "usd": 1400000,
    "declared_by": "actor:human:ao-authorizing-official",
    "ledger_seq": 6
   }
  },
  "verdict": {
   "value": "WITHHELD",
   "threshold_approve": 0.9,
   "threshold_caution": 0.7,
   "rule": "confidence>=threshold"
  },
  "confidence": {
   "value": 0,
   "method": "min-over-critical-inputs",
   "bound_by": "ai-system:TRIAGE-ASSISTANT-V4::model_evaluation"
  },
  "release": {
   "required": false,
   "required_by_tier": false,
   "escalated_by_acceptance": false,
   "risk_accepted": false,
   "state": "WITHHELD_NO_EVIDENCE",
   "code": "QUORUM_EVIDENCE_WITHHELD",
   "reason": "the evidence did not clear the threshold for this exposure, so there is nothing to release. Signatures do not substitute for evidence, and this state is deliberately distinct from WITHHELD_PENDING_SIGNATURES: a reader must be able to tell \"the evidence is not there\" from \"the evidence is there and 0 of 2 people have signed\".",
   "tier_floor_cents": 1000000000,
   "exposure_usd_cents": 140000000,
   "required_m": 2,
   "declared_n": 3,
   "floor_m": 2,
   "distinct_signers": 0,
   "superseded": 0,
   "collapsed": 0,
   "release_digest": "sha256:49e46dc99310dfb4f669746425dfb108ff1f2d3e71c03f35b99c9f14211809df",
   "governance_digest": "sha256:8b0a45a27fcce9c1c243c764e855e67c6fe6dfd7f02a563bd90809b419731905",
   "governance_signed": true,
   "counted_voices": [],
   "signatures": [],
   "ledger_seq": null
  },
  "acceptance": {
   "state": "NONE",
   "code": "ACCEPTANCE_NONE",
   "reason": "no risk acceptance was presented for this decision. This is the ordinary case: a refusal is a refusal unless a named person has priced it.",
   "permitted_basis": null,
   "presented": 0,
   "superseded": 0,
   "expired": 0,
   "gaps_not_covered": 0,
   "coverage_gaps_in_force": [
    "ai-system:TRIAGE-ASSISTANT-V4|model_evaluation"
   ],
   "evidentiary_digest": "sha256:49e46dc99310dfb4f669746425dfb108ff1f2d3e71c03f35b99c9f14211809df",
   "margin_floor_bp": 100,
   "authority_ceiling_cents": {
    "SUPERVISOR": 1000000,
    "MANAGER": 25000000,
    "DIRECTOR": 500000000,
    "OFFICER": 5000000000
   },
   "acceptances": [],
   "escalated": false,
   "live": false,
   "ledger_seq": null
  },
  "reasons": [
   "Coverage gap: no admissible memory for required claim(s) ai-system:TRIAGE-ASSISTANT-V4|model_evaluation.",
   "Confidence 0.00% is bound by \"ai-system:TRIAGE-ASSISTANT-V4|model_evaluation\".",
   "1 memory was withheld from the context block: ai-system:TRIAGE-ASSISTANT-V4|model_evaluation (below class floor: rule requires at least VERIFIED, held SELLER-ASSERTED — inadmissible at any exposure).",
   "Thresholds for $1,400,000 exposure: approve 90%, caution 70%."
  ],
  "regulatory": {
   "applied": [
    {
     "instrument_id": "nist-ai-rmf-1-0",
     "version": 1,
     "authority": "National Institute of Standards and Technology",
     "instrument": "AI Risk Management Framework 1.0",
     "edition": "1.0",
     "citation": "MEASURE-2.3, MEASURE-2.7, MANAGE-2.2 [VERIFY]",
     "source_digest": "sha256:a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1",
     "entered_by": "actor:human:issm",
     "entered_at": "2026-08-08T16:00:00.000Z"
    },
    {
     "instrument_id": "nist-sp-800-53r5-moderate",
     "version": 5,
     "authority": "National Institute of Standards and Technology",
     "instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
     "edition": "Rev. 5",
     "citation": "CA-2, CA-8, RA-5, SR-6 [VERIFY]",
     "source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353",
     "entered_by": "actor:human:issm",
     "entered_at": "2026-08-08T16:00:00.000Z"
    }
   ],
   "conflicts": [],
   "defaults": [
    {
     "claim": "control_assessment",
     "requirement": "ai_position",
     "value": "ADMIT",
     "because": "No instrument in force stated a position on AI-authored evidence for \"control_assessment\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
    },
    {
     "claim": "incident_response_plan_test",
     "requirement": "ai_position",
     "value": "ADMIT",
     "because": "No instrument in force stated a position on AI-authored evidence for \"incident_response_plan_test\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
    },
    {
     "claim": "model_evaluation",
     "requirement": "ai_position",
     "value": "ADMIT",
     "because": "No instrument in force stated a position on AI-authored evidence for \"model_evaluation\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
    },
    {
     "claim": "penetration_test",
     "requirement": "ai_position",
     "value": "ADMIT",
     "because": "No instrument in force stated a position on AI-authored evidence for \"penetration_test\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
    },
    {
     "claim": "security_resilience_evaluation",
     "requirement": "ai_position",
     "value": "ADMIT",
     "because": "No instrument in force stated a position on AI-authored evidence for \"security_resilience_evaluation\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
    },
    {
     "claim": "vulnerability_scan",
     "requirement": "ai_position",
     "value": "ADMIT",
     "because": "No instrument in force stated a position on AI-authored evidence for \"vulnerability_scan\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
    }
   ]
  },
  "inputs": [
   {
    "key": "ai-system:TRIAGE-ASSISTANT-V4::vulnerability_scan",
    "provenance": "VERIFIED",
    "reliability": 0.95,
    "critical": true,
    "memory_status": "admitted"
   },
   {
    "key": "ai-system:TRIAGE-ASSISTANT-V4::incident_response_plan_test",
    "provenance": "VERIFIED",
    "reliability": 0.95,
    "critical": true,
    "memory_status": "admitted"
   },
   {
    "key": "ai-system:TRIAGE-ASSISTANT-V4::security_resilience_evaluation",
    "provenance": "VERIFIED",
    "reliability": 0.95,
    "critical": true,
    "memory_status": "admitted"
   },
   {
    "key": "ai-system:TRIAGE-ASSISTANT-V4::penetration_test",
    "provenance": "VERIFIED",
    "reliability": 0.95,
    "critical": true,
    "memory_status": "admitted"
   },
   {
    "key": "ai-system:TRIAGE-ASSISTANT-V4::control_assessment",
    "provenance": "VERIFIED",
    "reliability": 0.95,
    "critical": true,
    "memory_status": "admitted"
   },
   {
    "key": "ai-system:TRIAGE-ASSISTANT-V4::model_evaluation",
    "provenance": "SELLER-ASSERTED",
    "reliability": 0.5,
    "critical": false,
    "memory_status": "withheld"
   },
   {
    "key": "ai-system:TRIAGE-ASSISTANT-V4::model_evaluation",
    "provenance": "MISSING",
    "reliability": 0,
    "critical": true,
    "memory_status": "coverage_gap"
   }
  ]
 }
}

Independent audit / IG

Internal audit, an inspector general, or an external auditor testing the programme.

Everything, plus the verifier’s own findings over the sealed record.

This view withholds nothing. What it adds is the 22 checks the published verifier ran over the sealed record behind every other view of this decision — recomputed at build time, not asserted.

#CheckDetail
1Content reproduces (JCS + SHA-256)PASSmatches sha256:6cfa106851e42c578947d59d107ffb474e39c813bc52723eb7102a95dc5a5e81
2Hash chain links (entry = H(prev||content))PASShead sha256:2955bbd1e87ad0cde1c0780e46dbe791796688fe9d626f467577319c4d1158ca
3Confidence gated by weakest critical inputPASSmin over critical = 0, bound_by ai-system:TRIAGE-ASSISTANT-V4::model_evaluation (MISSING)
3bVerdict follows the threshold rulePASS0 => WITHHELD; recorded WITHHELD
4Point-in-time seal (no input past data_horizon)PASSall inputs <= 2026-08-08T16:00:00.000Z
5Anchor covers the head, and the timestamp token re-readsPASSinternally consistent; NO external anchor was requested — this is not a validated timestamp
6Criteria travel with the receipt and reproducePASSpolicy_body hashes to sha256:a6b69b7d20f7fb04d522364af1d92992058b04a5835fcec9d1c9f2261c7ef636
7Reliability re-derives from recorded evidencePASSall 7 inputs re-derive exactly
8Outcome trials and lineage discounts re-derivePASS6 input(s) re-derive: 0 credited outcome trial(s), 0 lineage-discounted corroboration(s); every reliability is at or under its class ceiling
9Re-ingested receipts respect their weakest-input ceilingPASSno re-ingested receipts: every input rests on a primary observation
10Release quorum re-derivesPASSWITHHELD_NO_EVIDENCE - below the top exposure tier, no multi-party requirement applies
11Risk acceptance re-derivesPASSno risk acceptance: this decision stands or falls on its evidence
12Observer credentials were not revoked as of observation timePASSrevocation list 5 (0 entries, issued 2026-08-06T00:00:00.000Z, next update due 2026-08-13T00:00:00.000Z) reproduces; 5 observer signature(s) judged as of their own instant, none under a key revoked as compromised or retired by then
13The cryptographic suite is named and is one this verifier implementsPASSsealed under CB-1-ES256-SHA256 (ES256 / sha256, attest-canon/2); this verifier implements it; the suite states it is NOT quantum resistant
14Regulatory bindings are attributed and were enforcedPASS12 binding(s) from 2 instrument(s) in force, each attributed to an authority, a citation and a document digest; 6 required claim(s) all reached the gate
15Role-view commitments re-derive, and the customs view carries no moneyPASS6 role-view commitment(s) re-derived from this receipt’s own body by this verifier’s independent projection; the REGULATOR view carries no commercial figure
16AI-authored input was admitted only where an authority allowed itPASS0 claim(s) carry a position on AI-authored evidence set by an authority and 6 carry a recorded default nobody set; 0 exclusion(s) and 0 corroboration-only rule(s) re-derived against this receipt's own admitted inputs; 0 admitted input(s) are AI-authored by their enrolled identity
17State digest recomputes from the ledger aloneUNVERIFIABLENOT APPLICABLE — you supplied no ledger, so the state digest cannot be re-derived from anything. This receipt commits to the corpus the deciding system held at the instant it sealed, and that commitment is checked by recomputing it from the append-only ledger and comparing; with no ledger in hand there is no second artefact to recompute from. The receipt is not at fault and nothing here is missing from it. Obtain the ledger from the issuer and re-run with --ledger <file>, or verifyReceipt(r, {ledger}). Nothing here has failed and nothing here has passed.
18Registry membership re-derives for every key relied onPASSall 3 key(s) relied on re-derive to the entries root registry v3 committed to and the trust root signed
20Geometric support re-derives, and an unevaluated record is not a supported onePASSno authority bound a metric to any claim on this receipt, so no geometric test applied. A claim nobody bound a metric to is not a claim about geometry, and this is a stated absence rather than a silent one
19The cause of every uncovered requirement re-derivesPASSall 1 uncovered requirement(s) re-derive their cause from this receipt's own rows. What notice is ADEQUATE is not decided here: this check establishes what the record says and that the record agrees with itself.
21The sealing party is the one you were told to expectUNVERIFIABLENOT APPLICABLE — you supplied no trust bundle, so nothing here establishes who sealed this. Identities 1 to 20 prove that this document agrees with itself; not one of them asks whose trust root it was sealed under, and a document that agrees with itself about a decision nobody made agrees with itself perfectly. Obtain the issuer's corobate:trust-bundle:1 out of band, confirm its spoken fingerprint with them by voice, and re-run with --trust-bundle <file> --expect-fingerprint <what you heard>. Nothing here has failed and nothing here has passed.
The scoped copy itself — complete for this role
FAITHFUL digest sha256:bf67848128fb2010efa7cb7fe589d33f0f93e58bf4a36c483e781346639299c9 matches the commitment sealed in the receipt.
{
 "spec": "corobate:role-view:2",
 "role": "AUDITOR",
 "purpose": "An external assessor. Sees the complete sealed record: this view withholds nothing and exists so the identity case is a case rather than an exception.",
 "is_a_receipt": false,
 "warning": "This is a SCOPED COPY of a sealed decision, not the decision record itself. It will not verify as a receipt and must not be presented as one. To confirm it is faithful, recompute its `view` digest under the same canonicalisation that produces receipt_hash and compare it with the entry for this role in the source receipt’s `views` block.",
 "derived_from": {
  "receipt_hash": "sha256:6cfa106851e42c578947d59d107ffb474e39c813bc52723eb7102a95dc5a5e81",
  "entry_hash": "sha256:2955bbd1e87ad0cde1c0780e46dbe791796688fe9d626f467577319c4d1158ca",
  "issued_at": "2026-08-08T16:00:00.000Z"
 },
 "view_digest": "sha256:bf67848128fb2010efa7cb7fe589d33f0f93e58bf4a36c483e781346639299c9",
 "withheld": {
  "anything_withheld": false,
  "note": "Nothing outside the seal was removed for this role."
 },
 "view": {
  "spec": "urn:ietf:params:corobate:receipt:1",
  "receipt_version": "1.8",
  "engine": {
   "name": "corobate-memory",
   "version": "1.0.0"
  },
  "decision": {
   "id": "ai_TRIAGE_V4_before",
   "domain": "supply-chain",
   "subject": "ai-system:TRIAGE-ASSISTANT-V4",
   "question": "May this AI system be deployed to triage citizen-facing casework?"
  },
  "issued_at": "2026-08-08T16:00:00.000Z",
  "data_horizon": "2026-08-08T16:00:00.000Z",
  "inputs": [
   {
    "key": "ai-system:TRIAGE-ASSISTANT-V4::vulnerability_scan",
    "value": "clean-at-scan",
    "provenance": "VERIFIED",
    "source": "nvd-cve:vulnerability_scan",
    "observed_at": "2026-08-04T16:00:00.000Z",
    "last_corroborated_at": null,
    "memory_refreshed_by": [],
    "reliability": 0.95,
    "critical": true,
    "memory_id": "mem_4d2b1fc0d322",
    "memory_status": "admitted",
    "memory_kind": "status",
    "memory_actor": "actor:sys:registry:nvd-cve",
    "memory_age_days": 4,
    "memory_track": {
     "n": 1,
     "successes": 1
    },
    "memory_promoted_by": [],
    "memory_content_digest": "sha256:aea4c3860d57b3edd045cd33946015c41ff1aee9cc8a4df49f26d8a5165d4a38",
    "memory_outcomes": {
     "verified": 0,
     "falsified": 0,
     "modified": 0,
     "counted": 0,
     "recorded": 0
    },
    "memory_outcome_attestations": [],
    "memory_observer_lineage": null,
    "memory_corroborations": [],
    "memory_reingest": null,
    "memory_reasons": [
     "sparse track record: 1 independent observation(s); no failure recorded, so the class ceiling stands"
    ],
    "memory_class_floor": null,
    "memory_below_class_floor": false,
    "memory_not_attested": false,
    "memory_below_claim_reliability_floor": false,
    "memory_not_competent_authority": false,
    "memory_out_of_specification": false,
    "memory_ai_authored": false,
    "memory_ai_in_lineage": false,
    "memory_ai_position": "ADMIT",
    "memory_ai_inadmissible": false,
    "memory_geo_inadmissible": false,
    "memory_geo_rung": null,
    "memory_geo_metric": null,
    "memory_geo_required_metric": null,
    "observer_attested": true,
    "observer_auth_code": "VERIFIED",
    "observer_key_id": "k_5873dd9e7169def3",
    "attestation": null,
    "derivation": {
     "provenance": "VERIFIED",
     "ceiling_bp": 9500,
     "track": {
      "n": 1,
      "successes": 1
     },
     "wilson_bp": null,
     "age_days": 4,
     "max_age_days": 14,
     "house_max_age_days": 14,
     "instrument_max_age_days": 30,
     "freshness_cap_bp": 4000,
     "min_track_n": 5,
     "wilson_z_milli": 1960,
     "source_present": true,
     "seller_asserted_cap_bp": 5000,
     "retracted": false,
     "contradicted": false,
     "outcome_trials": 0,
     "outcomes": {
      "verified": 0,
      "falsified": 0,
      "modified": 0,
      "counted": 0,
      "recorded": 0
     },
     "corroborations_counted": 0,
     "corroborations_discounted": 0,
     "reingest_ceiling_bp": null,
     "reingest_depth": null,
     "reingest_weakest_class": null,
     "reingest_source_confidence_bp": null,
     "ai_authored": false,
     "ai_authored_because": null,
     "ai_in_lineage": false,
     "ai_position": "ADMIT"
    },
    "memory_reason_codes": [
     {
      "code": "SPARSE_TRACK_RECORD",
      "observed": 1,
      "limit": 5,
      "binding": false
     }
    ],
    "context_line": "[VERIFIED · r=95.0% · 4d · nvd-cve:vulnerability_scan] ai-system:TRIAGE-ASSISTANT-V4 / vulnerability_scan: clean-at-scan"
   },
   {
    "key": "ai-system:TRIAGE-ASSISTANT-V4::incident_response_plan_test",
    "value": "observed",
    "provenance": "VERIFIED",
    "source": "CERT-3PAO-ATLANTIC:incident_response_plan_test",
    "observed_at": "2026-06-24T16:00:00.000Z",
    "last_corroborated_at": null,
    "memory_refreshed_by": [],
    "reliability": 0.95,
    "critical": true,
    "memory_id": "mem_a54dcc18c5ba",
    "memory_status": "admitted",
    "memory_kind": "certificate",
    "memory_actor": "actor:org:CERT-3PAO-ATLANTIC",
    "memory_age_days": 45,
    "memory_track": {
     "n": 1,
     "successes": 1
    },
    "memory_promoted_by": [],
    "memory_content_digest": "sha256:a73e4d82b06b62aa687c0a5352a36df46dd691e2bfa8b1354c847d24612df001",
    "memory_outcomes": {
     "verified": 0,
     "falsified": 0,
     "modified": 0,
     "counted": 0,
     "recorded": 0
    },
    "memory_outcome_attestations": [],
    "memory_observer_lineage": null,
    "memory_corroborations": [],
    "memory_reingest": null,
    "memory_reasons": [
     "sparse track record: 1 independent observation(s); no failure recorded, so the class ceiling stands"
    ],
    "memory_class_floor": null,
    "memory_below_class_floor": false,
    "memory_not_attested": false,
    "memory_below_claim_reliability_floor": false,
    "memory_not_competent_authority": false,
    "memory_out_of_specification": false,
    "memory_ai_authored": false,
    "memory_ai_in_lineage": false,
    "memory_ai_position": "ADMIT",
    "memory_ai_inadmissible": false,
    "memory_geo_inadmissible": false,
    "memory_geo_rung": null,
    "memory_geo_metric": null,
    "memory_geo_required_metric": null,
    "observer_attested": true,
    "observer_auth_code": "VERIFIED",
    "observer_key_id": "k_307e4bfd710ec9b3",
    "attestation": null,
    "derivation": {
     "provenance": "VERIFIED",
     "ceiling_bp": 9500,
     "track": {
      "n": 1,
      "successes": 1
     },
     "wilson_bp": null,
     "age_days": 45,
     "max_age_days": 365,
     "house_max_age_days": 365,
     "instrument_max_age_days": null,
     "freshness_cap_bp": 4000,
     "min_track_n": 5,
     "wilson_z_milli": 1960,
     "source_present": true,
     "seller_asserted_cap_bp": 5000,
     "retracted": false,
     "contradicted": false,
     "outcome_trials": 0,
     "outcomes": {
      "verified": 0,
      "falsified": 0,
      "modified": 0,
      "counted": 0,
      "recorded": 0
     },
     "corroborations_counted": 0,
     "corroborations_discounted": 0,
     "reingest_ceiling_bp": null,
     "reingest_depth": null,
     "reingest_weakest_class": null,
     "reingest_source_confidence_bp": null,
     "ai_authored": false,
     "ai_authored_because": null,
     "ai_in_lineage": false,
     "ai_position": "ADMIT"
    },
    "memory_reason_codes": [
     {
      "code": "SPARSE_TRACK_RECORD",
      "observed": 1,
      "limit": 5,
      "binding": false
     }
    ],
    "context_line": "[VERIFIED · r=95.0% · 45d · CERT-3PAO-ATLANTIC:incident_response_plan_test] ai-system:TRIAGE-ASSISTANT-V4 / incident_response_plan_test: observed"
   },
   {
    "key": "ai-system:TRIAGE-ASSISTANT-V4::security_resilience_evaluation",
    "value": "assessed",
    "provenance": "VERIFIED",
    "source": "LAB-NVLAP-0412:security_resilience_evaluation",
    "observed_at": "2026-07-09T16:00:00.000Z",
    "last_corroborated_at": null,
    "memory_refreshed_by": [],
    "reliability": 0.95,
    "critical": true,
    "memory_id": "mem_2c29e7fe028c",
    "memory_status": "admitted",
    "memory_kind": "test_report",
    "memory_actor": "actor:org:LAB-NVLAP-0412",
    "memory_age_days": 30,
    "memory_track": {
     "n": 1,
     "successes": 1
    },
    "memory_promoted_by": [],
    "memory_content_digest": "sha256:dcbb60638904f38e17aa80dd1108c75855c10f1992b0793dc56d369582fc515e",
    "memory_outcomes": {
     "verified": 0,
     "falsified": 0,
     "modified": 0,
     "counted": 0,
     "recorded": 0
    },
    "memory_outcome_attestations": [],
    "memory_observer_lineage": null,
    "memory_corroborations": [],
    "memory_reingest": null,
    "memory_reasons": [
     "sparse track record: 1 independent observation(s); no failure recorded, so the class ceiling stands"
    ],
    "memory_class_floor": null,
    "memory_below_class_floor": false,
    "memory_not_attested": false,
    "memory_below_claim_reliability_floor": false,
    "memory_not_competent_authority": false,
    "memory_out_of_specification": false,
    "memory_ai_authored": false,
    "memory_ai_in_lineage": false,
    "memory_ai_position": "ADMIT",
    "memory_ai_inadmissible": false,
    "memory_geo_inadmissible": false,
    "memory_geo_rung": null,
    "memory_geo_metric": null,
    "memory_geo_required_metric": null,
    "observer_attested": true,
    "observer_auth_code": "VERIFIED",
    "observer_key_id": "k_17d23885943ae529",
    "attestation": null,
    "derivation": {
     "provenance": "VERIFIED",
     "ceiling_bp": 9500,
     "track": {
      "n": 1,
      "successes": 1
     },
     "wilson_bp": null,
     "age_days": 30,
     "max_age_days": 180,
     "house_max_age_days": 180,
     "instrument_max_age_days": null,
     "freshness_cap_bp": 4000,
     "min_track_n": 5,
     "wilson_z_milli": 1960,
     "source_present": true,
     "seller_asserted_cap_bp": 5000,
     "retracted": false,
     "contradicted": false,
     "outcome_trials": 0,
     "outcomes": {
      "verified": 0,
      "falsified": 0,
      "modified": 0,
      "counted": 0,
      "recorded": 0
     },
     "corroborations_counted": 0,
     "corroborations_discounted": 0,
     "reingest_ceiling_bp": null,
     "reingest_depth": null,
     "reingest_weakest_class": null,
     "reingest_source_confidence_bp": null,
     "ai_authored": false,
     "ai_authored_because": null,
     "ai_in_lineage": false,
     "ai_position": "ADMIT"
    },
    "memory_reason_codes": [
     {
      "code": "SPARSE_TRACK_RECORD",
      "observed": 1,
      "limit": 5,
      "binding": false
     }
    ],
    "context_line": "[VERIFIED · r=95.0% · 30d · LAB-NVLAP-0412:security_resilience_evaluation] ai-system:TRIAGE-ASSISTANT-V4 / security_resilience_evaluation: assessed"
   },
   {
    "key": "ai-system:TRIAGE-ASSISTANT-V4::penetration_test",
    "value": "no-critical",
    "provenance": "VERIFIED",
    "source": "LAB-NVLAP-0412:penetration_test",
    "observed_at": "2026-06-09T16:00:00.000Z",
    "last_corroborated_at": null,
    "memory_refreshed_by": [],
    "reliability": 0.95,
    "critical": true,
    "memory_id": "mem_a3316d633bfe",
    "memory_status": "admitted",
    "memory_kind": "test_report",
    "memory_actor": "actor:org:LAB-NVLAP-0412",
    "memory_age_days": 60,
    "memory_track": {
     "n": 1,
     "successes": 1
    },
    "memory_promoted_by": [],
    "memory_content_digest": "sha256:db69fb062be9b066b370c668281e12896da2869456a2e6d356a0f14879b27de9",
    "memory_outcomes": {
     "verified": 0,
     "falsified": 0,
     "modified": 0,
     "counted": 0,
     "recorded": 0
    },
    "memory_outcome_attestations": [],
    "memory_observer_lineage": null,
    "memory_corroborations": [],
    "memory_reingest": null,
    "memory_reasons": [
     "sparse track record: 1 independent observation(s); no failure recorded, so the class ceiling stands"
    ],
    "memory_class_floor": "VERIFIED",
    "memory_below_class_floor": false,
    "memory_not_attested": false,
    "memory_below_claim_reliability_floor": false,
    "memory_not_competent_authority": false,
    "memory_out_of_specification": false,
    "memory_ai_authored": false,
    "memory_ai_in_lineage": false,
    "memory_ai_position": "ADMIT",
    "memory_ai_inadmissible": false,
    "memory_geo_inadmissible": false,
    "memory_geo_rung": null,
    "memory_geo_metric": null,
    "memory_geo_required_metric": null,
    "observer_attested": true,
    "observer_auth_code": "VERIFIED",
    "observer_key_id": "k_17d23885943ae529",
    "attestation": null,
    "derivation": {
     "provenance": "VERIFIED",
     "ceiling_bp": 9500,
     "track": {
      "n": 1,
      "successes": 1
     },
     "wilson_bp": null,
     "age_days": 60,
     "max_age_days": 180,
     "house_max_age_days": 180,
     "instrument_max_age_days": null,
     "freshness_cap_bp": 4000,
     "min_track_n": 5,
     "wilson_z_milli": 1960,
     "source_present": true,
     "seller_asserted_cap_bp": 5000,
     "retracted": false,
     "contradicted": false,
     "outcome_trials": 0,
     "outcomes": {
      "verified": 0,
      "falsified": 0,
      "modified": 0,
      "counted": 0,
      "recorded": 0
     },
     "corroborations_counted": 0,
     "corroborations_discounted": 0,
     "reingest_ceiling_bp": null,
     "reingest_depth": null,
     "reingest_weakest_class": null,
     "reingest_source_confidence_bp": null,
     "min_class_floor": "VERIFIED",
     "ai_authored": false,
     "ai_authored_because": null,
     "ai_in_lineage": false,
     "ai_position": "ADMIT"
    },
    "memory_reason_codes": [
     {
      "code": "SPARSE_TRACK_RECORD",
      "observed": 1,
      "limit": 5,
      "binding": false
     }
    ],
    "context_line": "[VERIFIED · r=95.0% · 60d · LAB-NVLAP-0412:penetration_test] ai-system:TRIAGE-ASSISTANT-V4 / penetration_test: no-critical"
   },
   {
    "key": "ai-system:TRIAGE-ASSISTANT-V4::control_assessment",
    "value": "satisfied",
    "provenance": "VERIFIED",
    "source": "CERT-3PAO-ATLANTIC:control_assessment",
    "observed_at": "2026-04-30T16:00:00.000Z",
    "last_corroborated_at": null,
    "memory_refreshed_by": [],
    "reliability": 0.95,
    "critical": true,
    "memory_id": "mem_a153eb336060",
    "memory_status": "admitted",
    "memory_kind": "certificate",
    "memory_actor": "actor:org:CERT-3PAO-ATLANTIC",
    "memory_age_days": 100,
    "memory_track": {
     "n": 1,
     "successes": 1
    },
    "memory_promoted_by": [],
    "memory_content_digest": "sha256:c1aaf46a55b4cdc629a754ac35da1b8ec4dec85c2c78613c7bc93546b63f233c",
    "memory_outcomes": {
     "verified": 0,
     "falsified": 0,
     "modified": 0,
     "counted": 0,
     "recorded": 0
    },
    "memory_outcome_attestations": [],
    "memory_observer_lineage": null,
    "memory_corroborations": [],
    "memory_reingest": null,
    "memory_reasons": [
     "sparse track record: 1 independent observation(s); no failure recorded, so the class ceiling stands"
    ],
    "memory_class_floor": "VERIFIED",
    "memory_below_class_floor": false,
    "memory_not_attested": false,
    "memory_below_claim_reliability_floor": false,
    "memory_not_competent_authority": false,
    "memory_out_of_specification": false,
    "memory_ai_authored": false,
    "memory_ai_in_lineage": false,
    "memory_ai_position": "ADMIT",
    "memory_ai_inadmissible": false,
    "memory_geo_inadmissible": false,
    "memory_geo_rung": null,
    "memory_geo_metric": null,
    "memory_geo_required_metric": null,
    "observer_attested": true,
    "observer_auth_code": "VERIFIED",
    "observer_key_id": "k_307e4bfd710ec9b3",
    "attestation": null,
    "derivation": {
     "provenance": "VERIFIED",
     "ceiling_bp": 9500,
     "track": {
      "n": 1,
      "successes": 1
     },
     "wilson_bp": null,
     "age_days": 100,
     "max_age_days": 365,
     "house_max_age_days": 365,
     "instrument_max_age_days": 365,
     "freshness_cap_bp": 4000,
     "min_track_n": 5,
     "wilson_z_milli": 1960,
     "source_present": true,
     "seller_asserted_cap_bp": 5000,
     "retracted": false,
     "contradicted": false,
     "outcome_trials": 0,
     "outcomes": {
      "verified": 0,
      "falsified": 0,
      "modified": 0,
      "counted": 0,
      "recorded": 0
     },
     "corroborations_counted": 0,
     "corroborations_discounted": 0,
     "reingest_ceiling_bp": null,
     "reingest_depth": null,
     "reingest_weakest_class": null,
     "reingest_source_confidence_bp": null,
     "min_class_floor": "VERIFIED",
     "ai_authored": false,
     "ai_authored_because": null,
     "ai_in_lineage": false,
     "ai_position": "ADMIT"
    },
    "memory_reason_codes": [
     {
      "code": "SPARSE_TRACK_RECORD",
      "observed": 1,
      "limit": 5,
      "binding": false
     }
    ],
    "context_line": "[VERIFIED · r=95.0% · 100d · CERT-3PAO-ATLANTIC:control_assessment] ai-system:TRIAGE-ASSISTANT-V4 / control_assessment: satisfied"
   },
   {
    "key": "ai-system:TRIAGE-ASSISTANT-V4::model_evaluation",
    "value": null,
    "provenance": "SELLER-ASSERTED",
    "source": "triage-assistant-v4:model_evaluation",
    "observed_at": "2026-07-30T16:00:00.000Z",
    "last_corroborated_at": null,
    "memory_refreshed_by": [],
    "reliability": 0.5,
    "critical": false,
    "memory_id": "mem_5de9825e17f5",
    "memory_status": "withheld",
    "memory_kind": "test_report",
    "memory_actor": "actor:ai:triage-assistant-v4",
    "memory_age_days": 9,
    "memory_track": {
     "n": 1,
     "successes": 1
    },
    "memory_promoted_by": [],
    "memory_content_digest": "sha256:224db2c622d9fec54b10ae86e818c3bf4832c6eaf0549b6cf298d50ca55668bc",
    "memory_outcomes": {
     "verified": 0,
     "falsified": 0,
     "modified": 0,
     "counted": 0,
     "recorded": 0
    },
    "memory_outcome_attestations": [],
    "memory_observer_lineage": null,
    "memory_corroborations": [],
    "memory_reingest": null,
    "memory_reasons": [
     "below class floor: rule requires at least VERIFIED, held SELLER-ASSERTED — inadmissible at any exposure",
     "sparse track record: 1 independent observation(s); no failure recorded, so the class ceiling stands"
    ],
    "memory_class_floor": "VERIFIED",
    "memory_below_class_floor": true,
    "memory_not_attested": false,
    "memory_below_claim_reliability_floor": false,
    "memory_not_competent_authority": false,
    "memory_out_of_specification": false,
    "memory_ai_authored": true,
    "memory_ai_in_lineage": false,
    "memory_ai_position": "ADMIT",
    "memory_ai_inadmissible": false,
    "memory_geo_inadmissible": false,
    "memory_geo_rung": null,
    "memory_geo_metric": null,
    "memory_geo_required_metric": null,
    "observer_attested": false,
    "observer_auth_code": "NO_ENVELOPE",
    "observer_key_id": null,
    "attestation": null,
    "derivation": {
     "provenance": "SELLER-ASSERTED",
     "ceiling_bp": 5000,
     "track": {
      "n": 1,
      "successes": 1
     },
     "wilson_bp": null,
     "age_days": 9,
     "max_age_days": 180,
     "house_max_age_days": 180,
     "instrument_max_age_days": 180,
     "freshness_cap_bp": 4000,
     "min_track_n": 5,
     "wilson_z_milli": 1960,
     "source_present": true,
     "seller_asserted_cap_bp": 5000,
     "retracted": false,
     "contradicted": false,
     "outcome_trials": 0,
     "outcomes": {
      "verified": 0,
      "falsified": 0,
      "modified": 0,
      "counted": 0,
      "recorded": 0
     },
     "corroborations_counted": 0,
     "corroborations_discounted": 0,
     "reingest_ceiling_bp": null,
     "reingest_depth": null,
     "reingest_weakest_class": null,
     "reingest_source_confidence_bp": null,
     "min_class_floor": "VERIFIED",
     "ai_authored": true,
     "ai_authored_because": "a model, named as one in its own enrolled identity",
     "ai_in_lineage": false,
     "ai_position": "ADMIT"
    },
    "memory_reason_codes": [
     {
      "code": "BELOW_CLASS_FLOOR",
      "observed": "SELLER-ASSERTED",
      "limit": "VERIFIED",
      "binding": true
     },
     {
      "code": "SPARSE_TRACK_RECORD",
      "observed": 1,
      "limit": 5,
      "binding": false
     }
    ]
   },
   {
    "key": "ai-system:TRIAGE-ASSISTANT-V4::model_evaluation",
    "value": null,
    "provenance": "MISSING",
    "source": null,
    "observed_at": "2026-08-08T16:00:00.000Z",
    "reliability": 0,
    "critical": true,
    "memory_status": "coverage_gap",
    "gap_cause": "EVIDENCE_PRESENTED_FAILED",
    "gap_request": null,
    "gap_origin": "BUSINESS_EVIDENCE",
    "gap_conditions": [
     "below_class_floor"
    ]
   }
  ],
  "serialization": {
   "algorithm": "RFC8785-JCS",
   "hash": "sha256"
  },
  "crypto_suite": {
   "spec": "corobate:suite:1",
   "id": "CB-1-ES256-SHA256",
   "receipt_digest": "sha256",
   "chain_digest": "sha256",
   "content_digest": "sha256",
   "envelope_signature": "ES256",
   "signature_curve": "P-256",
   "canonicalisation": "attest-canon/2",
   "quantum_resistant": false
  },
  "confidence": {
   "value": 0,
   "method": "min-over-critical-inputs",
   "bound_by": "ai-system:TRIAGE-ASSISTANT-V4::model_evaluation"
  },
  "verdict": {
   "value": "WITHHELD",
   "threshold_approve": 0.9,
   "threshold_caution": 0.7,
   "rule": "confidence>=threshold"
  },
  "release": {
   "required": false,
   "required_by_tier": false,
   "escalated_by_acceptance": false,
   "risk_accepted": false,
   "state": "WITHHELD_NO_EVIDENCE",
   "code": "QUORUM_EVIDENCE_WITHHELD",
   "reason": "the evidence did not clear the threshold for this exposure, so there is nothing to release. Signatures do not substitute for evidence, and this state is deliberately distinct from WITHHELD_PENDING_SIGNATURES: a reader must be able to tell \"the evidence is not there\" from \"the evidence is there and 0 of 2 people have signed\".",
   "tier_floor_cents": 1000000000,
   "exposure_usd_cents": 140000000,
   "required_m": 2,
   "declared_n": 3,
   "floor_m": 2,
   "distinct_signers": 0,
   "superseded": 0,
   "collapsed": 0,
   "release_digest": "sha256:49e46dc99310dfb4f669746425dfb108ff1f2d3e71c03f35b99c9f14211809df",
   "governance_digest": "sha256:8b0a45a27fcce9c1c243c764e855e67c6fe6dfd7f02a563bd90809b419731905",
   "governance_signed": true,
   "counted_voices": [],
   "signatures": [],
   "ledger_seq": null
  },
  "acceptance": {
   "state": "NONE",
   "code": "ACCEPTANCE_NONE",
   "reason": "no risk acceptance was presented for this decision. This is the ordinary case: a refusal is a refusal unless a named person has priced it.",
   "permitted_basis": null,
   "presented": 0,
   "superseded": 0,
   "expired": 0,
   "gaps_not_covered": 0,
   "coverage_gaps_in_force": [
    "ai-system:TRIAGE-ASSISTANT-V4|model_evaluation"
   ],
   "evidentiary_digest": "sha256:49e46dc99310dfb4f669746425dfb108ff1f2d3e71c03f35b99c9f14211809df",
   "margin_floor_bp": 100,
   "authority_ceiling_cents": {
    "SUPERVISOR": 1000000,
    "MANAGER": 25000000,
    "DIRECTOR": 500000000,
    "OFFICER": 5000000000
   },
   "acceptances": [],
   "escalated": false,
   "live": false,
   "ledger_seq": null
  },
  "regulatory": {
   "spec": "corobate:regulatory:2",
   "resolved": true,
   "applied": [
    {
     "instrument_id": "nist-ai-rmf-1-0",
     "version": 1,
     "authority": "National Institute of Standards and Technology",
     "instrument": "AI Risk Management Framework 1.0",
     "edition": "1.0",
     "citation": "MEASURE-2.3, MEASURE-2.7, MANAGE-2.2 [VERIFY]",
     "source_digest": "sha256:a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1",
     "entered_by": "actor:human:issm",
     "entered_at": "2026-08-08T16:00:00.000Z"
    },
    {
     "instrument_id": "nist-sp-800-53r5-moderate",
     "version": 5,
     "authority": "National Institute of Standards and Technology",
     "instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
     "edition": "Rev. 5",
     "citation": "CA-2, CA-8, RA-5, SR-6 [VERIFY]",
     "source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353",
     "entered_by": "actor:human:issm",
     "entered_at": "2026-08-08T16:00:00.000Z"
    }
   ],
   "skipped": [],
   "conflicts": [],
   "bindings": [
    {
     "claim": "control_assessment",
     "requirement": "max_age_days",
     "value": 365,
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
      "instrument_id": "nist-sp-800-53r5-moderate",
      "version": 5,
      "edition": "Rev. 5",
      "citation": "CA-2 [VERIFY]",
      "source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "control_assessment",
     "requirement": "min_class",
     "value": "VERIFIED",
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
      "instrument_id": "nist-sp-800-53r5-moderate",
      "version": 5,
      "edition": "Rev. 5",
      "citation": "CA-2(1) independent assessors [VERIFY]",
      "source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "control_assessment",
     "requirement": "required",
     "value": true,
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
      "instrument_id": "nist-sp-800-53r5-moderate",
      "version": 5,
      "edition": "Rev. 5",
      "citation": "CA-2 [VERIFY]",
      "source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "incident_response_plan_test",
     "requirement": "required",
     "value": true,
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "AI Risk Management Framework 1.0",
      "instrument_id": "nist-ai-rmf-1-0",
      "version": 1,
      "edition": "1.0",
      "citation": "MANAGE-4.1 [VERIFY]",
      "source_digest": "sha256:a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "model_evaluation",
     "requirement": "max_age_days",
     "value": 180,
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "AI Risk Management Framework 1.0",
      "instrument_id": "nist-ai-rmf-1-0",
      "version": 1,
      "edition": "1.0",
      "citation": "MEASURE-2.3 [VERIFY]",
      "source_digest": "sha256:a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "model_evaluation",
     "requirement": "min_class",
     "value": "VERIFIED",
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "AI Risk Management Framework 1.0",
      "instrument_id": "nist-ai-rmf-1-0",
      "version": 1,
      "edition": "1.0",
      "citation": "MEASURE-2.3 independent evaluation [VERIFY]",
      "source_digest": "sha256:a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "model_evaluation",
     "requirement": "required",
     "value": true,
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "AI Risk Management Framework 1.0",
      "instrument_id": "nist-ai-rmf-1-0",
      "version": 1,
      "edition": "1.0",
      "citation": "MEASURE-2.3 [VERIFY]",
      "source_digest": "sha256:a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "penetration_test",
     "requirement": "min_class",
     "value": "VERIFIED",
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
      "instrument_id": "nist-sp-800-53r5-moderate",
      "version": 5,
      "edition": "Rev. 5",
      "citation": "CA-8(1) independent penetration agent [VERIFY]",
      "source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "penetration_test",
     "requirement": "required",
     "value": true,
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
      "instrument_id": "nist-sp-800-53r5-moderate",
      "version": 5,
      "edition": "Rev. 5",
      "citation": "CA-8 [VERIFY]",
      "source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "security_resilience_evaluation",
     "requirement": "required",
     "value": true,
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "AI Risk Management Framework 1.0",
      "instrument_id": "nist-ai-rmf-1-0",
      "version": 1,
      "edition": "1.0",
      "citation": "MEASURE-2.7 [VERIFY]",
      "source_digest": "sha256:a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "vulnerability_scan",
     "requirement": "max_age_days",
     "value": 30,
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
      "instrument_id": "nist-sp-800-53r5-moderate",
      "version": 5,
      "edition": "Rev. 5",
      "citation": "RA-5(a) [VERIFY]",
      "source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "vulnerability_scan",
     "requirement": "required",
     "value": true,
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
      "instrument_id": "nist-sp-800-53r5-moderate",
      "version": 5,
      "edition": "Rev. 5",
      "citation": "RA-5 [VERIFY]",
      "source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    }
   ],
   "defaults": [
    {
     "claim": "control_assessment",
     "requirement": "ai_position",
     "value": "ADMIT",
     "because": "No instrument in force stated a position on AI-authored evidence for \"control_assessment\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
    },
    {
     "claim": "incident_response_plan_test",
     "requirement": "ai_position",
     "value": "ADMIT",
     "because": "No instrument in force stated a position on AI-authored evidence for \"incident_response_plan_test\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
    },
    {
     "claim": "model_evaluation",
     "requirement": "ai_position",
     "value": "ADMIT",
     "because": "No instrument in force stated a position on AI-authored evidence for \"model_evaluation\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
    },
    {
     "claim": "penetration_test",
     "requirement": "ai_position",
     "value": "ADMIT",
     "because": "No instrument in force stated a position on AI-authored evidence for \"penetration_test\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
    },
    {
     "claim": "security_resilience_evaluation",
     "requirement": "ai_position",
     "value": "ADMIT",
     "because": "No instrument in force stated a position on AI-authored evidence for \"security_resilience_evaluation\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
    },
    {
     "claim": "vulnerability_scan",
     "requirement": "ai_position",
     "value": "ADMIT",
     "because": "No instrument in force stated a position on AI-authored evidence for \"vulnerability_scan\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
    }
   ]
  },
  "reasons": [
   "Coverage gap: no admissible memory for required claim(s) ai-system:TRIAGE-ASSISTANT-V4|model_evaluation.",
   "Confidence 0.00% is bound by \"ai-system:TRIAGE-ASSISTANT-V4|model_evaluation\".",
   "1 memory was withheld from the context block: ai-system:TRIAGE-ASSISTANT-V4|model_evaluation (below class floor: rule requires at least VERIFIED, held SELLER-ASSERTED — inadmissible at any exposure).",
   "Thresholds for $1,400,000 exposure: approve 90%, caution 70%."
  ],
  "memory": {
   "layer": "capture->store->recall->act",
   "ledger_head": "sha256:7529436da173e2905b4859118dac726b0cd5c4c379029c2afc524393c0d06822",
   "ledger_entries": 8,
   "context_digest": null,
   "context_memory_ids": [],
   "state_digest": "sha256:2d93db16d55c8de970115a836b580dcfdc4be9a6747a75d2d04c931322b48f90",
   "retrieval_method": "idf-lexical",
   "corpus_size": 6,
   "considered": 6,
   "admitted": 5,
   "withheld": 1,
   "not_considered": 0,
   "coverage_gaps": [
    "ai-system:TRIAGE-ASSISTANT-V4|model_evaluation"
   ],
   "exposure": {
    "usd": 1400000,
    "declared_by": "actor:human:ao-authorizing-official",
    "ledger_seq": 6
   },
   "salience_policy": {
    "half_life_days": 90,
    "grace_days": 7,
    "access_boost_bp": 500,
    "access_boost_cap_bp": 2500,
    "relevance_weight_bp": 6000,
    "recency_weight_bp": 3000,
    "usage_weight_bp": 1000,
    "context_cap": 12,
    "method": "idf-lexical",
    "candidate_list_digest": "sha256:9bb0607e470641a267f1d574195d02b2a3a9a800f4aebf8bd9c9cb9cad937907",
    "note": "salience orders retrieval only; it never contributes to reliability"
   },
   "policy_digest": "sha256:a6b69b7d20f7fb04d522364af1d92992058b04a5835fcec9d1c9f2261c7ef636",
   "policy_body": {
    "class_ceiling_bp": {
     "VERIFIED": 9500,
     "MODELED": 8000,
     "SELLER-ASSERTED": 5000,
     "MISSING": 0
    },
    "actor_class_ceiling": [
     [
      "^actor:ai:",
      "MODELED"
     ],
     [
      "^actor:agent:",
      "MODELED"
     ],
     [
      "^actor:human:",
      "SELLER-ASSERTED"
     ],
     [
      "^actor:org:LAB-",
      "VERIFIED"
     ],
     [
      "^actor:org:CERT-",
      "VERIFIED"
     ],
     [
      "^actor:org:",
      "SELLER-ASSERTED"
     ],
     [
      "^actor:sys:registry:",
      "VERIFIED"
     ],
     [
      "^actor:sys:sensor:",
      "VERIFIED"
     ],
     [
      "^actor:sys:",
      "MODELED"
     ]
    ],
    "freshness_cap_bp": 4000,
    "max_age_days": {
     "telemetry": 1,
     "price": 7,
     "status": 14,
     "certificate": 365,
     "test_report": 180,
     "filing": 90,
     "transcript": 120,
     "highlight": 365,
     "voice_note": 120,
     "note": 365,
     "preference": 540,
     "decision": 1825,
     "receipt": 365,
     "default": 90
    },
    "wilson_z_milli": 1960,
    "min_track_n": 5,
    "exposure_tiers_bp": [
     [
      1000000000,
      9500,
      8000
     ],
     [
      100000000,
      9000,
      7000
     ],
     [
      1000000,
      8500,
      6000
     ],
     [
      0,
      8000,
      5000
     ]
    ],
    "max_context_memories": 12,
    "contradiction_resolve_margin": 2,
    "salience": {
     "half_life_days": 90,
     "grace_days": 7,
     "access_boost_bp": 500,
     "access_boost_cap_bp": 2500,
     "relevance_weight_bp": 6000,
     "recency_weight_bp": 3000,
     "usage_weight_bp": 1000
    }
   },
   "observer_auth": {
    "mode": "required",
    "registry_version": 3,
    "registry_digest": "sha256:460aeaafe345f69542a302e6619dff0712af98de6518838ee4c8585e448c3a7d",
    "entries_root": "sha256:5670469f96484a814462814ed74f0f992b5f19e8ad6afced548e4956e4835ba5",
    "memberships": [
     {
      "key_id": "k_17d23885943ae529",
      "index": 1,
      "entry": {
       "actor": "actor:org:LAB-NVLAP-0412",
       "class": "VERIFIED",
       "kind": "org",
       "key_id": "k_17d23885943ae529",
       "jwk": {
        "kty": "EC",
        "crv": "P-256",
        "x": "3TTw47-PkYfo3ZaKTq_qtHghnGvninAVj25kyOwONno",
        "y": "16PMaR8ofeF5IcZk6ZLml8gDs8uE1s1sBLdciH5e4vg"
       },
       "valid_from": "2025-01-01T00:00:00.000Z",
       "valid_to": "2027-06-01T00:00:00.000Z"
      },
      "path": [
       {
        "side": "left",
        "sibling": "sha256:500f2ba5949d5256ae0f563530b0b270db41ce99d2d7c4b4b60e4bd558ca353d"
       },
       {
        "side": "right",
        "sibling": "sha256:a0b47ea437bf4f1042a1dd50a5a3f411f9a17971812fc6bafccd434eb7d78ccc"
       },
       {
        "side": "right",
        "sibling": "sha256:d3c2347eb675e865fc17ef0204cacda7b02e8784a811fdd1c8a015d1865e6dfb"
       },
       {
        "side": "right",
        "sibling": "sha256:7071adf5e21a94147d31f42f1028b4867b6562e5b78726259c2515b03b213e52"
       }
      ]
     },
     {
      "key_id": "k_307e4bfd710ec9b3",
      "index": 0,
      "entry": {
       "actor": "actor:org:CERT-3PAO-ATLANTIC",
       "class": "VERIFIED",
       "kind": "org",
       "key_id": "k_307e4bfd710ec9b3",
       "jwk": {
        "kty": "EC",
        "crv": "P-256",
        "x": "MGtV26TezLMPjiD3SecQtnje6eLqYyx4qkKzzAkbiY4",
        "y": "SMMdLYnn-FpKbb2sJQ8EAZnzvozNm-cGO0VbUUpniPY"
       },
       "valid_from": "2025-01-01T00:00:00.000Z",
       "valid_to": "2027-06-01T00:00:00.000Z"
      },
      "path": [
       {
        "side": "right",
        "sibling": "sha256:4148869fc259d2c5fc19fe5831065b165a9acf81812e123162035acfdecade1d"
       },
       {
        "side": "right",
        "sibling": "sha256:a0b47ea437bf4f1042a1dd50a5a3f411f9a17971812fc6bafccd434eb7d78ccc"
       },
       {
        "side": "right",
        "sibling": "sha256:d3c2347eb675e865fc17ef0204cacda7b02e8784a811fdd1c8a015d1865e6dfb"
       },
       {
        "side": "right",
        "sibling": "sha256:7071adf5e21a94147d31f42f1028b4867b6562e5b78726259c2515b03b213e52"
       }
      ]
     },
     {
      "key_id": "k_5873dd9e7169def3",
      "index": 2,
      "entry": {
       "actor": "actor:sys:registry:nvd-cve",
       "class": "VERIFIED",
       "kind": "system",
       "key_id": "k_5873dd9e7169def3",
       "jwk": {
        "kty": "EC",
        "crv": "P-256",
        "x": "O9OY6oMuJg0df_INePO19_3b11VaSyMwIPdxoqvV2ak",
        "y": "k7Orm5pxDxMdTF-H2S4h6ixRywzk1WxvquOQeqxLFx0"
       },
       "valid_from": "2025-01-01T00:00:00.000Z",
       "valid_to": "2027-06-01T00:00:00.000Z"
      },
      "path": [
       {
        "side": "right",
        "sibling": "sha256:e1fe36fe7c8e4695327c25d6d722630b6249c93293bfdc5894c58aaf961ab6f8"
       },
       {
        "side": "left",
        "sibling": "sha256:e8b9cba101f13538b909a2e686e9e6e9a8d77212036ed567eaebc205a443e83f"
       },
       {
        "side": "right",
        "sibling": "sha256:d3c2347eb675e865fc17ef0204cacda7b02e8784a811fdd1c8a015d1865e6dfb"
       },
       {
        "side": "right",
        "sibling": "sha256:7071adf5e21a94147d31f42f1028b4867b6562e5b78726259c2515b03b213e52"
       }
      ]
     }
    ],
    "memberships_unproven": [],
    "revocation": {
     "source": "SIGNED_LIST",
     "digest": "sha256:12f73b1fbf27d38cf137b86a1ce13bbcd98161123a6aa7d79b107db8189966b9",
     "sequence": 5,
     "registry_version": 3,
     "issued_at": "2026-08-06T00:00:00.000Z",
     "next_update_due": "2026-08-13T00:00:00.000Z",
     "entry_count": 0,
     "body": {
      "sequence": 5,
      "registry_version": 3,
      "issuer": {
       "name": "NIST-regulated enterprise demonstration trust root",
       "key_id": "k_3793b8e35f8acac1"
      },
      "issued_at": "2026-08-06T00:00:00.000Z",
      "next_update_due": "2026-08-13T00:00:00.000Z",
      "entries": [],
      "spec": "corobate:revocation-list:1"
     }
    }
   },
   "governance": {
    "digest": "sha256:8b0a45a27fcce9c1c243c764e855e67c6fe6dfd7f02a563bd90809b419731905",
    "signed": true,
    "actor_trust": "FLOOR_TO_SELLER_ASSERTED",
    "outcome_trial_weight": 1,
    "max_reingest_depth": 3,
    "release_quorum_m": 2,
    "release_quorum_n": 3,
    "risk_acceptance_margin_bp": 500,
    "risk_acceptance_max_days": 30,
    "risk_acceptance_authority_cents": {
     "SUPERVISOR": 1000000,
     "MANAGER": 25000000,
     "DIRECTOR": 500000000,
     "OFFICER": 5000000000
    },
    "template_author_roles": [
     "MANAGER",
     "DIRECTOR",
     "OFFICER"
    ]
   },
   "observers_attested": 5,
   "outcomes": {
    "attestations_counted": 0,
    "attestations_recorded": 0,
    "records_with_outcomes": 0
   },
   "lineage": {
    "corroborations_counted": 0,
    "corroborations_discounted": 0,
    "records_with_discounted_corroborations": 0
   },
   "reingest": {
    "records": 0,
    "max_depth": 0,
    "weakest_class": null,
    "chain_weakest_bp": 10000,
    "chain": []
   },
   "template": null
  }
 }
}

One document arrived: an external red team's evaluation. It reports a LOWER score than the system reported about itself, and it is the one that satisfies the requirement — because the requirement was never about the number.

Subject
ai-system:TRIAGE-ASSISTANT-V4
Question
May this AI system be deployed to triage citizen-facing casework?
Exposure
$1,400,000
Instruments
National Institute of Standards and Technology · National Institute of Standards and Technology
Outcome
APPROVE — the action may proceed
Receipt
sha256:c344f0bbd85452f2a504d682b85270eccef70039d8abc41090c18d33e17b94d1
The gate variables this decision ran under — a dial per question, read back off the sealed receipt
control assessmentrequired
necessity
requiredNational Institute of Standards and Technology — CA-2 [VERIFY]
staleness
365 daysNational Institute of Standards and Technology — CA-2 [VERIFY]
reputation class
verifiedNational Institute of Standards and Technology — CA-2(1) independent assessors [VERIFY]
reputation record
No reliability floor beyond the exposure tier's own threshold, which still binds.
completion
No satisfaction window was set. The requirement is due now: there is no period in which it may be outstanding, and nothing proceeds without it.
ai provenance
admitNo instrument in force stated a position on AI-authored evidence for "control_assessment". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway.
incident response plan testrequired
necessity
requiredNational Institute of Standards and Technology — MANAGE-4.1 [VERIFY]
staleness
90 daysNo instrument set an age limit for this claim, so the deploying organisation's own freshness policy binds at 90 days. It is not unlimited.
reputation class
No class floor was set, so the seller's own assertion is admissible for this claim up to the ceiling that class carries. That is a setting, not an absence.
reputation record
No reliability floor beyond the exposure tier's own threshold, which still binds.
completion
No satisfaction window was set. The requirement is due now: there is no period in which it may be outstanding, and nothing proceeds without it.
ai provenance
admitNo instrument in force stated a position on AI-authored evidence for "incident_response_plan_test". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway.
model evaluationrequired
necessity
requiredNational Institute of Standards and Technology — MEASURE-2.3 [VERIFY]
staleness
180 daysNational Institute of Standards and Technology — MEASURE-2.3 [VERIFY]
reputation class
verifiedNational Institute of Standards and Technology — MEASURE-2.3 independent evaluation [VERIFY]
reputation record
No reliability floor beyond the exposure tier's own threshold, which still binds.
completion
No satisfaction window was set. The requirement is due now: there is no period in which it may be outstanding, and nothing proceeds without it.
ai provenance
admitNo instrument in force stated a position on AI-authored evidence for "model_evaluation". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway.
penetration testrequired
necessity
requiredNational Institute of Standards and Technology — CA-8 [VERIFY]
staleness
90 daysNo instrument set an age limit for this claim, so the deploying organisation's own freshness policy binds at 90 days. It is not unlimited.
reputation class
verifiedNational Institute of Standards and Technology — CA-8(1) independent penetration agent [VERIFY]
reputation record
No reliability floor beyond the exposure tier's own threshold, which still binds.
completion
No satisfaction window was set. The requirement is due now: there is no period in which it may be outstanding, and nothing proceeds without it.
ai provenance
admitNo instrument in force stated a position on AI-authored evidence for "penetration_test". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway.
security resilience evaluationrequired
necessity
requiredNational Institute of Standards and Technology — MEASURE-2.7 [VERIFY]
staleness
90 daysNo instrument set an age limit for this claim, so the deploying organisation's own freshness policy binds at 90 days. It is not unlimited.
reputation class
No class floor was set, so the seller's own assertion is admissible for this claim up to the ceiling that class carries. That is a setting, not an absence.
reputation record
No reliability floor beyond the exposure tier's own threshold, which still binds.
completion
No satisfaction window was set. The requirement is due now: there is no period in which it may be outstanding, and nothing proceeds without it.
ai provenance
admitNo instrument in force stated a position on AI-authored evidence for "security_resilience_evaluation". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway.
vulnerability scanrequired
necessity
requiredNational Institute of Standards and Technology — RA-5 [VERIFY]
staleness
30 daysNational Institute of Standards and Technology — RA-5(a) [VERIFY]
reputation class
No class floor was set, so the seller's own assertion is admissible for this claim up to the ceiling that class carries. That is a setting, not an absence.
reputation record
No reliability floor beyond the exposure tier's own threshold, which still binds.
completion
No satisfaction window was set. The requirement is due now: there is no period in which it may be outstanding, and nothing proceeds without it.
ai provenance
admitNo instrument in force stated a position on AI-authored evidence for "vulnerability_scan". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway.

Every bar above was re-derived from the regulatory bindings inside this receipt’s hashed body, not from the configuration that produced it. A bar in grey is a setting no instrument made — the deploying organisation’s own default, which still binds and is not an absence. A bar position renders an ordinal on a declared ladder: it is a way to draw a control and to compare two settings on the same axis, and it is not a measurement. The value printed beside each bar is the authoritative one.

Whoever must act now

The engineer with the deployment in their hands, the release manager, the person who must publish or hold.

One instruction and the reason in words. No score, no money, no signatures.

PROCEED
ai-system:TRIAGE-ASSISTANT-V4
Everything required is on file and current.

Seven or eight fields, and not one of them is a number somebody can argue with. This person is not being asked to re-judge the evidence; somebody already did, and it is on the record.

The scoped copy itself — partial — something outside this role’s remit was removed
FAITHFUL digest sha256:51ee16a5792728e4497078fe19c6628a0c8e8cc7f1d568beed94cda17400d528 matches the commitment sealed in the receipt.
{
 "spec": "corobate:role-view:2",
 "role": "OPERATOR",
 "purpose": "Whoever must act on this decision now — release the goods, fund the draw, dispatch the agent, ship the title. Sees one instruction and the reason in plain words, and nothing that could be argued about while somebody waits.",
 "is_a_receipt": false,
 "warning": "This is a SCOPED COPY of a sealed decision, not the decision record itself. It will not verify as a receipt and must not be presented as one. To confirm it is faithful, recompute its `view` digest under the same canonicalisation that produces receipt_hash and compare it with the entry for this role in the source receipt’s `views` block.",
 "derived_from": {
  "receipt_hash": "sha256:c344f0bbd85452f2a504d682b85270eccef70039d8abc41090c18d33e17b94d1",
  "entry_hash": "sha256:b55a572b8c628ac13f33499905dac7c6bd9f4cfa33c14f5b40eb5f789ad4f04f",
  "issued_at": "2026-08-08T16:00:00.000Z"
 },
 "view_digest": "sha256:51ee16a5792728e4497078fe19c6628a0c8e8cc7f1d568beed94cda17400d528",
 "withheld": {
  "anything_withheld": true,
  "note": "Facts outside this role’s remit were removed. That something was removed is stated so a partial record is never mistaken for a complete one. How much, and what, is not stated — a count is an inference about the part you are not entitled to see."
 },
 "view": {
  "spec": "urn:ietf:params:corobate:receipt:1",
  "receipt_version": "1.8",
  "issued_at": "2026-08-08T16:00:00.000Z",
  "decision": {
   "id": "ai_TRIAGE_V4_after",
   "subject": "ai-system:TRIAGE-ASSISTANT-V4"
  },
  "memory": {
   "state_digest": "sha256:d8c970114e57738a62465be9287d7045cd8966caeb801154d420321a11451dcc",
   "ledger_head": "sha256:b883e583bf7eac8664664c008b4556f5e62ef70a681669c550a6d84ccad602fc",
   "coverage_gaps": []
  },
  "verdict": {
   "value": "APPROVE"
  },
  "release": {
   "state": "NOT_REQUIRED"
  }
 }
}

Provider / assessed party

The cloud service provider, the release team, or the party operating the AI system — whoever is being assessed.

Sees which controls were required of them and by which publication and control identifier. Does not see the authorising official’s exposure figure or how any shortfall was priced.

What is outstanding on your file

Nothing. Every required item is present and current.

ClaimRequiredEvidence classWhoAgeOutcome
vulnerability_scanyesVERIFIED2026-08-04admitted
incident_response_plan_testyesVERIFIED2026-06-24admitted
model_evaluationyesVERIFIED2026-07-19admitted
security_resilience_evaluationyesVERIFIED2026-07-09admitted
penetration_testyesVERIFIED2026-06-09admitted
control_assessmentyesVERIFIED2026-04-30admitted
model_self_reportnoSELLER-ASSERTED2026-07-30withheld

The clause is here because it turns an argument into an errand. What is not here: what the bank had at stake, and whether anyone priced the shortfall.

The scoped copy itself — partial — something outside this role’s remit was removed
FAITHFUL digest sha256:8baf1b2ef73d519ae44f14cbe6d59a5c7c77b9bb8e911f5f3850de5bdad6b41f matches the commitment sealed in the receipt.
{
 "spec": "corobate:role-view:2",
 "role": "SUPPLIER",
 "purpose": "The party whose evidence was judged. Sees every claim the decision required, which fell short, and the clause that required it — and nothing about what the buyer had at stake or how the buyer priced any shortfall. NOTE, because an earlier draft of this sentence was untrue: this projection carries the WHOLE inputs array, so where several parties supplied evidence for one decision, each of them sees all of it. Per-party scoping cannot be expressed by a commitment scheme with one digest per role, and claiming it anyway would be the kind of promise this file exists to stop making.",
 "is_a_receipt": false,
 "warning": "This is a SCOPED COPY of a sealed decision, not the decision record itself. It will not verify as a receipt and must not be presented as one. To confirm it is faithful, recompute its `view` digest under the same canonicalisation that produces receipt_hash and compare it with the entry for this role in the source receipt’s `views` block.",
 "derived_from": {
  "receipt_hash": "sha256:c344f0bbd85452f2a504d682b85270eccef70039d8abc41090c18d33e17b94d1",
  "entry_hash": "sha256:b55a572b8c628ac13f33499905dac7c6bd9f4cfa33c14f5b40eb5f789ad4f04f",
  "issued_at": "2026-08-08T16:00:00.000Z"
 },
 "view_digest": "sha256:8baf1b2ef73d519ae44f14cbe6d59a5c7c77b9bb8e911f5f3850de5bdad6b41f",
 "withheld": {
  "anything_withheld": true,
  "note": "Facts outside this role’s remit were removed. That something was removed is stated so a partial record is never mistaken for a complete one. How much, and what, is not stated — a count is an inference about the part you are not entitled to see."
 },
 "view": {
  "spec": "urn:ietf:params:corobate:receipt:1",
  "receipt_version": "1.8",
  "issued_at": "2026-08-08T16:00:00.000Z",
  "decision": {
   "id": "ai_TRIAGE_V4_after",
   "subject": "ai-system:TRIAGE-ASSISTANT-V4",
   "question": "May this AI system be deployed to triage citizen-facing casework?"
  },
  "memory": {
   "state_digest": "sha256:d8c970114e57738a62465be9287d7045cd8966caeb801154d420321a11451dcc",
   "ledger_head": "sha256:b883e583bf7eac8664664c008b4556f5e62ef70a681669c550a6d84ccad602fc",
   "coverage_gaps": []
  },
  "verdict": {
   "value": "APPROVE"
  },
  "inputs": [
   {
    "key": "ai-system:TRIAGE-ASSISTANT-V4::vulnerability_scan",
    "provenance": "VERIFIED",
    "observed_at": "2026-08-04T16:00:00.000Z",
    "memory_status": "admitted",
    "critical": true
   },
   {
    "key": "ai-system:TRIAGE-ASSISTANT-V4::incident_response_plan_test",
    "provenance": "VERIFIED",
    "observed_at": "2026-06-24T16:00:00.000Z",
    "memory_status": "admitted",
    "critical": true
   },
   {
    "key": "ai-system:TRIAGE-ASSISTANT-V4::model_evaluation",
    "provenance": "VERIFIED",
    "observed_at": "2026-07-19T16:00:00.000Z",
    "memory_status": "admitted",
    "critical": true
   },
   {
    "key": "ai-system:TRIAGE-ASSISTANT-V4::security_resilience_evaluation",
    "provenance": "VERIFIED",
    "observed_at": "2026-07-09T16:00:00.000Z",
    "memory_status": "admitted",
    "critical": true
   },
   {
    "key": "ai-system:TRIAGE-ASSISTANT-V4::penetration_test",
    "provenance": "VERIFIED",
    "observed_at": "2026-06-09T16:00:00.000Z",
    "memory_status": "admitted",
    "critical": true
   },
   {
    "key": "ai-system:TRIAGE-ASSISTANT-V4::control_assessment",
    "provenance": "VERIFIED",
    "observed_at": "2026-04-30T16:00:00.000Z",
    "memory_status": "admitted",
    "critical": true
   },
   {
    "key": "ai-system:TRIAGE-ASSISTANT-V4::model_self_report",
    "provenance": "SELLER-ASSERTED",
    "observed_at": "2026-07-30T16:00:00.000Z",
    "memory_status": "withheld",
    "critical": false
   }
  ],
  "regulatory": {
   "bindings": [
    {
     "claim": "control_assessment",
     "requirement": "max_age_days",
     "value": 365,
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
      "instrument_id": "nist-sp-800-53r5-moderate",
      "version": 5,
      "edition": "Rev. 5",
      "citation": "CA-2 [VERIFY]",
      "source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "control_assessment",
     "requirement": "min_class",
     "value": "VERIFIED",
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
      "instrument_id": "nist-sp-800-53r5-moderate",
      "version": 5,
      "edition": "Rev. 5",
      "citation": "CA-2(1) independent assessors [VERIFY]",
      "source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "control_assessment",
     "requirement": "required",
     "value": true,
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
      "instrument_id": "nist-sp-800-53r5-moderate",
      "version": 5,
      "edition": "Rev. 5",
      "citation": "CA-2 [VERIFY]",
      "source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "incident_response_plan_test",
     "requirement": "required",
     "value": true,
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "AI Risk Management Framework 1.0",
      "instrument_id": "nist-ai-rmf-1-0",
      "version": 1,
      "edition": "1.0",
      "citation": "MANAGE-4.1 [VERIFY]",
      "source_digest": "sha256:a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "model_evaluation",
     "requirement": "max_age_days",
     "value": 180,
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "AI Risk Management Framework 1.0",
      "instrument_id": "nist-ai-rmf-1-0",
      "version": 1,
      "edition": "1.0",
      "citation": "MEASURE-2.3 [VERIFY]",
      "source_digest": "sha256:a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "model_evaluation",
     "requirement": "min_class",
     "value": "VERIFIED",
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "AI Risk Management Framework 1.0",
      "instrument_id": "nist-ai-rmf-1-0",
      "version": 1,
      "edition": "1.0",
      "citation": "MEASURE-2.3 independent evaluation [VERIFY]",
      "source_digest": "sha256:a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "model_evaluation",
     "requirement": "required",
     "value": true,
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "AI Risk Management Framework 1.0",
      "instrument_id": "nist-ai-rmf-1-0",
      "version": 1,
      "edition": "1.0",
      "citation": "MEASURE-2.3 [VERIFY]",
      "source_digest": "sha256:a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "penetration_test",
     "requirement": "min_class",
     "value": "VERIFIED",
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
      "instrument_id": "nist-sp-800-53r5-moderate",
      "version": 5,
      "edition": "Rev. 5",
      "citation": "CA-8(1) independent penetration agent [VERIFY]",
      "source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "penetration_test",
     "requirement": "required",
     "value": true,
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
      "instrument_id": "nist-sp-800-53r5-moderate",
      "version": 5,
      "edition": "Rev. 5",
      "citation": "CA-8 [VERIFY]",
      "source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "security_resilience_evaluation",
     "requirement": "required",
     "value": true,
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "AI Risk Management Framework 1.0",
      "instrument_id": "nist-ai-rmf-1-0",
      "version": 1,
      "edition": "1.0",
      "citation": "MEASURE-2.7 [VERIFY]",
      "source_digest": "sha256:a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "vulnerability_scan",
     "requirement": "max_age_days",
     "value": 30,
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
      "instrument_id": "nist-sp-800-53r5-moderate",
      "version": 5,
      "edition": "Rev. 5",
      "citation": "RA-5(a) [VERIFY]",
      "source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "vulnerability_scan",
     "requirement": "required",
     "value": true,
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
      "instrument_id": "nist-sp-800-53r5-moderate",
      "version": 5,
      "edition": "Rev. 5",
      "citation": "RA-5 [VERIFY]",
      "source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    }
   ],
   "applied": [
    {
     "instrument_id": "nist-ai-rmf-1-0",
     "version": 1,
     "authority": "National Institute of Standards and Technology",
     "instrument": "AI Risk Management Framework 1.0",
     "edition": "1.0",
     "citation": "MEASURE-2.3, MEASURE-2.7, MANAGE-2.2 [VERIFY]",
     "source_digest": "sha256:a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1",
     "entered_by": "actor:human:issm",
     "entered_at": "2026-08-08T16:00:00.000Z"
    },
    {
     "instrument_id": "nist-sp-800-53r5-moderate",
     "version": 5,
     "authority": "National Institute of Standards and Technology",
     "instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
     "edition": "Rev. 5",
     "citation": "CA-2, CA-8, RA-5, SR-6 [VERIFY]",
     "source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353",
     "entered_by": "actor:human:issm",
     "entered_at": "2026-08-08T16:00:00.000Z"
    }
   ],
   "defaults": [
    {
     "claim": "control_assessment",
     "requirement": "ai_position",
     "value": "ADMIT",
     "because": "No instrument in force stated a position on AI-authored evidence for \"control_assessment\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
    },
    {
     "claim": "incident_response_plan_test",
     "requirement": "ai_position",
     "value": "ADMIT",
     "because": "No instrument in force stated a position on AI-authored evidence for \"incident_response_plan_test\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
    },
    {
     "claim": "model_evaluation",
     "requirement": "ai_position",
     "value": "ADMIT",
     "because": "No instrument in force stated a position on AI-authored evidence for \"model_evaluation\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
    },
    {
     "claim": "penetration_test",
     "requirement": "ai_position",
     "value": "ADMIT",
     "because": "No instrument in force stated a position on AI-authored evidence for \"penetration_test\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
    },
    {
     "claim": "security_resilience_evaluation",
     "requirement": "ai_position",
     "value": "ADMIT",
     "because": "No instrument in force stated a position on AI-authored evidence for \"security_resilience_evaluation\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
    },
    {
     "claim": "vulnerability_scan",
     "requirement": "ai_position",
     "value": "ADMIT",
     "because": "No instrument in force stated a position on AI-authored evidence for \"vulnerability_scan\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
    }
   ]
  }
 }
}

Assessor / authorising official

A third-party assessment organisation, an agency assessor, or an inspector general reviewing the package. Same position as a customs officer: a public mandate over the record.

The control record in full — each publication by control identifier, edition and document digest, and every required claim with who supplied it and when. No exposure figure, no risk pricing, no confidence score.

National Institute of Standards and Technology
AI Risk Management Framework 1.0
MEASURE-2.3, MEASURE-2.7, MANAGE-2.2 [VERIFY] · edition 1.0
document sha256:a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1
entered by actor:human:issm
National Institute of Standards and Technology
SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)
CA-2, CA-8, RA-5, SR-6 [VERIFY] · edition Rev. 5
document sha256:5353535353535353535353535353535353535353535353535353535353535353
entered by actor:human:issm

What each authority bound

ClaimRequirementLevelBound by
control_assessmentmax age days365National Institute of Standards and Technology
CA-2 [VERIFY] · SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)
control_assessmentmin classVERIFIEDNational Institute of Standards and Technology
CA-2(1) independent assessors [VERIFY] · SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)
control_assessmentrequiredtrueNational Institute of Standards and Technology
CA-2 [VERIFY] · SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)
incident_response_plan_testrequiredtrueNational Institute of Standards and Technology
MANAGE-4.1 [VERIFY] · AI Risk Management Framework 1.0
model_evaluationmax age days180National Institute of Standards and Technology
MEASURE-2.3 [VERIFY] · AI Risk Management Framework 1.0
model_evaluationmin classVERIFIEDNational Institute of Standards and Technology
MEASURE-2.3 independent evaluation [VERIFY] · AI Risk Management Framework 1.0
model_evaluationrequiredtrueNational Institute of Standards and Technology
MEASURE-2.3 [VERIFY] · AI Risk Management Framework 1.0
penetration_testmin classVERIFIEDNational Institute of Standards and Technology
CA-8(1) independent penetration agent [VERIFY] · SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)
penetration_testrequiredtrueNational Institute of Standards and Technology
CA-8 [VERIFY] · SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)
security_resilience_evaluationrequiredtrueNational Institute of Standards and Technology
MEASURE-2.7 [VERIFY] · AI Risk Management Framework 1.0
vulnerability_scanmax age days30National Institute of Standards and Technology
RA-5(a) [VERIFY] · SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)
vulnerability_scanrequiredtrueNational Institute of Standards and Technology
RA-5 [VERIFY] · SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)

Every required claim, and what was actually held

ClaimRequiredEvidence classWhoAgeOutcome
vulnerability_scanyesVERIFIEDactor:sys:registry:nvd-cve2026-08-04admitted
incident_response_plan_testyesVERIFIEDactor:org:CERT-3PAO-ATLANTIC2026-06-24admitted
model_evaluationyesVERIFIEDactor:org:LAB-REDTEAM-EVAL2026-07-19admitted
security_resilience_evaluationyesVERIFIEDactor:org:LAB-NVLAP-04122026-07-09admitted
penetration_testyesVERIFIEDactor:org:LAB-NVLAP-04122026-06-09admitted
control_assessmentyesVERIFIEDactor:org:CERT-3PAO-ATLANTIC2026-04-30admitted
model_self_reportnoSELLER-ASSERTEDactor:ai:triage-assistant-v42026-07-30withheld
Absent from this copy, deliberatelyNo exposure figure, no risk pricing, no confidence score, no release quorum. The examiner’s claim is on the record of what was required and what was held — answered here completely, down to the digest of the document each requirement was configured from. The institution’s commercial position is a different question and this document does not answer it. The published verifier checks that on the content of the copy, not on the intentions of whoever produced it.
The scoped copy itself — partial — something outside this role’s remit was removed
FAITHFUL digest sha256:32298fafe3fdc4b6bf28b177afb15207c2fc0a59d3db8f8599d92bdd8ccce5ca matches the commitment sealed in the receipt.
{
 "spec": "corobate:role-view:2",
 "role": "REGULATOR",
 "purpose": "An official holding a public mandate over this record — a customs officer, a bank examiner, a market conduct supervisor. Sees the regulatory record in full: their own instrument named, every required claim and whether it was met, by whom, how old. No commercial figure of any kind.",
 "is_a_receipt": false,
 "warning": "This is a SCOPED COPY of a sealed decision, not the decision record itself. It will not verify as a receipt and must not be presented as one. To confirm it is faithful, recompute its `view` digest under the same canonicalisation that produces receipt_hash and compare it with the entry for this role in the source receipt’s `views` block.",
 "derived_from": {
  "receipt_hash": "sha256:c344f0bbd85452f2a504d682b85270eccef70039d8abc41090c18d33e17b94d1",
  "entry_hash": "sha256:b55a572b8c628ac13f33499905dac7c6bd9f4cfa33c14f5b40eb5f789ad4f04f",
  "issued_at": "2026-08-08T16:00:00.000Z"
 },
 "view_digest": "sha256:32298fafe3fdc4b6bf28b177afb15207c2fc0a59d3db8f8599d92bdd8ccce5ca",
 "withheld": {
  "anything_withheld": true,
  "note": "Facts outside this role’s remit were removed. That something was removed is stated so a partial record is never mistaken for a complete one. How much, and what, is not stated — a count is an inference about the part you are not entitled to see."
 },
 "view": {
  "spec": "urn:ietf:params:corobate:receipt:1",
  "receipt_version": "1.8",
  "issued_at": "2026-08-08T16:00:00.000Z",
  "decision": {
   "id": "ai_TRIAGE_V4_after",
   "subject": "ai-system:TRIAGE-ASSISTANT-V4",
   "question": "May this AI system be deployed to triage citizen-facing casework?"
  },
  "memory": {
   "state_digest": "sha256:d8c970114e57738a62465be9287d7045cd8966caeb801154d420321a11451dcc",
   "ledger_head": "sha256:b883e583bf7eac8664664c008b4556f5e62ef70a681669c550a6d84ccad602fc",
   "coverage_gaps": []
  },
  "data_horizon": "2026-08-08T16:00:00.000Z",
  "verdict": {
   "value": "APPROVE"
  },
  "regulatory": {
   "spec": "corobate:regulatory:2",
   "resolved": true,
   "applied": [
    {
     "instrument_id": "nist-ai-rmf-1-0",
     "version": 1,
     "authority": "National Institute of Standards and Technology",
     "instrument": "AI Risk Management Framework 1.0",
     "edition": "1.0",
     "citation": "MEASURE-2.3, MEASURE-2.7, MANAGE-2.2 [VERIFY]",
     "source_digest": "sha256:a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1",
     "entered_by": "actor:human:issm",
     "entered_at": "2026-08-08T16:00:00.000Z"
    },
    {
     "instrument_id": "nist-sp-800-53r5-moderate",
     "version": 5,
     "authority": "National Institute of Standards and Technology",
     "instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
     "edition": "Rev. 5",
     "citation": "CA-2, CA-8, RA-5, SR-6 [VERIFY]",
     "source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353",
     "entered_by": "actor:human:issm",
     "entered_at": "2026-08-08T16:00:00.000Z"
    }
   ],
   "skipped": [],
   "conflicts": [],
   "bindings": [
    {
     "claim": "control_assessment",
     "requirement": "max_age_days",
     "value": 365,
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
      "instrument_id": "nist-sp-800-53r5-moderate",
      "version": 5,
      "edition": "Rev. 5",
      "citation": "CA-2 [VERIFY]",
      "source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "control_assessment",
     "requirement": "min_class",
     "value": "VERIFIED",
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
      "instrument_id": "nist-sp-800-53r5-moderate",
      "version": 5,
      "edition": "Rev. 5",
      "citation": "CA-2(1) independent assessors [VERIFY]",
      "source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "control_assessment",
     "requirement": "required",
     "value": true,
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
      "instrument_id": "nist-sp-800-53r5-moderate",
      "version": 5,
      "edition": "Rev. 5",
      "citation": "CA-2 [VERIFY]",
      "source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "incident_response_plan_test",
     "requirement": "required",
     "value": true,
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "AI Risk Management Framework 1.0",
      "instrument_id": "nist-ai-rmf-1-0",
      "version": 1,
      "edition": "1.0",
      "citation": "MANAGE-4.1 [VERIFY]",
      "source_digest": "sha256:a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "model_evaluation",
     "requirement": "max_age_days",
     "value": 180,
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "AI Risk Management Framework 1.0",
      "instrument_id": "nist-ai-rmf-1-0",
      "version": 1,
      "edition": "1.0",
      "citation": "MEASURE-2.3 [VERIFY]",
      "source_digest": "sha256:a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "model_evaluation",
     "requirement": "min_class",
     "value": "VERIFIED",
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "AI Risk Management Framework 1.0",
      "instrument_id": "nist-ai-rmf-1-0",
      "version": 1,
      "edition": "1.0",
      "citation": "MEASURE-2.3 independent evaluation [VERIFY]",
      "source_digest": "sha256:a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "model_evaluation",
     "requirement": "required",
     "value": true,
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "AI Risk Management Framework 1.0",
      "instrument_id": "nist-ai-rmf-1-0",
      "version": 1,
      "edition": "1.0",
      "citation": "MEASURE-2.3 [VERIFY]",
      "source_digest": "sha256:a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "penetration_test",
     "requirement": "min_class",
     "value": "VERIFIED",
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
      "instrument_id": "nist-sp-800-53r5-moderate",
      "version": 5,
      "edition": "Rev. 5",
      "citation": "CA-8(1) independent penetration agent [VERIFY]",
      "source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "penetration_test",
     "requirement": "required",
     "value": true,
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
      "instrument_id": "nist-sp-800-53r5-moderate",
      "version": 5,
      "edition": "Rev. 5",
      "citation": "CA-8 [VERIFY]",
      "source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "security_resilience_evaluation",
     "requirement": "required",
     "value": true,
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "AI Risk Management Framework 1.0",
      "instrument_id": "nist-ai-rmf-1-0",
      "version": 1,
      "edition": "1.0",
      "citation": "MEASURE-2.7 [VERIFY]",
      "source_digest": "sha256:a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "vulnerability_scan",
     "requirement": "max_age_days",
     "value": 30,
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
      "instrument_id": "nist-sp-800-53r5-moderate",
      "version": 5,
      "edition": "Rev. 5",
      "citation": "RA-5(a) [VERIFY]",
      "source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "vulnerability_scan",
     "requirement": "required",
     "value": true,
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
      "instrument_id": "nist-sp-800-53r5-moderate",
      "version": 5,
      "edition": "Rev. 5",
      "citation": "RA-5 [VERIFY]",
      "source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    }
   ],
   "defaults": [
    {
     "claim": "control_assessment",
     "requirement": "ai_position",
     "value": "ADMIT",
     "because": "No instrument in force stated a position on AI-authored evidence for \"control_assessment\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
    },
    {
     "claim": "incident_response_plan_test",
     "requirement": "ai_position",
     "value": "ADMIT",
     "because": "No instrument in force stated a position on AI-authored evidence for \"incident_response_plan_test\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
    },
    {
     "claim": "model_evaluation",
     "requirement": "ai_position",
     "value": "ADMIT",
     "because": "No instrument in force stated a position on AI-authored evidence for \"model_evaluation\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
    },
    {
     "claim": "penetration_test",
     "requirement": "ai_position",
     "value": "ADMIT",
     "because": "No instrument in force stated a position on AI-authored evidence for \"penetration_test\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
    },
    {
     "claim": "security_resilience_evaluation",
     "requirement": "ai_position",
     "value": "ADMIT",
     "because": "No instrument in force stated a position on AI-authored evidence for \"security_resilience_evaluation\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
    },
    {
     "claim": "vulnerability_scan",
     "requirement": "ai_position",
     "value": "ADMIT",
     "because": "No instrument in force stated a position on AI-authored evidence for \"vulnerability_scan\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
    }
   ]
  },
  "inputs": [
   {
    "key": "ai-system:TRIAGE-ASSISTANT-V4::vulnerability_scan",
    "provenance": "VERIFIED",
    "source": "nvd-cve:vulnerability_scan",
    "observed_at": "2026-08-04T16:00:00.000Z",
    "critical": true,
    "memory_status": "admitted",
    "memory_actor": "actor:sys:registry:nvd-cve"
   },
   {
    "key": "ai-system:TRIAGE-ASSISTANT-V4::incident_response_plan_test",
    "provenance": "VERIFIED",
    "source": "CERT-3PAO-ATLANTIC:incident_response_plan_test",
    "observed_at": "2026-06-24T16:00:00.000Z",
    "critical": true,
    "memory_status": "admitted",
    "memory_actor": "actor:org:CERT-3PAO-ATLANTIC"
   },
   {
    "key": "ai-system:TRIAGE-ASSISTANT-V4::model_evaluation",
    "provenance": "VERIFIED",
    "source": "LAB-REDTEAM-EVAL:model_evaluation",
    "observed_at": "2026-07-19T16:00:00.000Z",
    "critical": true,
    "memory_status": "admitted",
    "memory_actor": "actor:org:LAB-REDTEAM-EVAL"
   },
   {
    "key": "ai-system:TRIAGE-ASSISTANT-V4::security_resilience_evaluation",
    "provenance": "VERIFIED",
    "source": "LAB-NVLAP-0412:security_resilience_evaluation",
    "observed_at": "2026-07-09T16:00:00.000Z",
    "critical": true,
    "memory_status": "admitted",
    "memory_actor": "actor:org:LAB-NVLAP-0412"
   },
   {
    "key": "ai-system:TRIAGE-ASSISTANT-V4::penetration_test",
    "provenance": "VERIFIED",
    "source": "LAB-NVLAP-0412:penetration_test",
    "observed_at": "2026-06-09T16:00:00.000Z",
    "critical": true,
    "memory_status": "admitted",
    "memory_actor": "actor:org:LAB-NVLAP-0412"
   },
   {
    "key": "ai-system:TRIAGE-ASSISTANT-V4::control_assessment",
    "provenance": "VERIFIED",
    "source": "CERT-3PAO-ATLANTIC:control_assessment",
    "observed_at": "2026-04-30T16:00:00.000Z",
    "critical": true,
    "memory_status": "admitted",
    "memory_actor": "actor:org:CERT-3PAO-ATLANTIC"
   },
   {
    "key": "ai-system:TRIAGE-ASSISTANT-V4::model_self_report",
    "provenance": "SELLER-ASSERTED",
    "source": "triage-assistant-v4:model_self_report",
    "observed_at": "2026-07-30T16:00:00.000Z",
    "critical": false,
    "memory_status": "withheld",
    "memory_actor": "actor:ai:triage-assistant-v4"
   }
  ],
  "crypto_suite": {
   "spec": "corobate:suite:1",
   "id": "CB-1-ES256-SHA256",
   "receipt_digest": "sha256",
   "chain_digest": "sha256",
   "content_digest": "sha256",
   "envelope_signature": "ES256",
   "signature_curve": "P-256",
   "canonicalisation": "attest-canon/2",
   "quantum_resistant": false
  }
 }
}

ISSM / control owner

The information system security manager and the control owners who hold the package.

The fullest internal view: every input, its class, its age, its score, the exposure, and every publication in force.

VerdictAPPROVE
Confidence95%
bound by vulnerability_scan
Exposure$1,400,000
ReleaseNOT_REQUIRED
Risk acceptedNONE

Every input the gate saw

ClaimRequiredEvidence classWhoAgeScoreOutcome
vulnerability_scanyesVERIFIEDactor:sys:registry:nvd-cve4d95%admitted
incident_response_plan_testyesVERIFIEDactor:org:CERT-3PAO-ATLANTIC45d95%admitted
model_evaluationyesVERIFIEDactor:org:LAB-REDTEAM-EVAL20d95%admitted
security_resilience_evaluationyesVERIFIEDactor:org:LAB-NVLAP-041230d95%admitted
penetration_testyesVERIFIEDactor:org:LAB-NVLAP-041260d95%admitted
control_assessmentyesVERIFIEDactor:org:CERT-3PAO-ATLANTIC100d95%admitted
model_self_reportnoSELLER-ASSERTEDactor:ai:triage-assistant-v49d50%withheld

Instruments in force

National Institute of Standards and Technology
AI Risk Management Framework 1.0
MEASURE-2.3, MEASURE-2.7, MANAGE-2.2 [VERIFY] · edition 1.0
document sha256:a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1
entered by actor:human:issm
National Institute of Standards and Technology
SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)
CA-2, CA-8, RA-5, SR-6 [VERIFY] · edition Rev. 5
document sha256:5353535353535353535353535353535353535353535353535353535353535353
entered by actor:human:issm

Why

  • Confidence 95.00% is bound by "ai-system:TRIAGE-ASSISTANT-V4|vulnerability_scan".
  • 1 memory was withheld from the context block: ai-system:TRIAGE-ASSISTANT-V4|model_self_report (sparse track record: 1 independent observation(s); no failure recorded, so the class ceiling stands).
  • Thresholds for $1,400,000 exposure: approve 90%, caution 70%.
The scoped copy itself — partial — something outside this role’s remit was removed
FAITHFUL digest sha256:4f2aacb1ebf1da5dd26a81387f4ca2e5cedbc2276ba43c1c37fe3d2d4165ef3b matches the commitment sealed in the receipt.
{
 "spec": "corobate:role-view:2",
 "role": "COMPLIANCE",
 "purpose": "The operator’s own compliance function. The fullest internal view: every gap, every instrument in force, the waivability of each requirement and who accepted what.",
 "is_a_receipt": false,
 "warning": "This is a SCOPED COPY of a sealed decision, not the decision record itself. It will not verify as a receipt and must not be presented as one. To confirm it is faithful, recompute its `view` digest under the same canonicalisation that produces receipt_hash and compare it with the entry for this role in the source receipt’s `views` block.",
 "derived_from": {
  "receipt_hash": "sha256:c344f0bbd85452f2a504d682b85270eccef70039d8abc41090c18d33e17b94d1",
  "entry_hash": "sha256:b55a572b8c628ac13f33499905dac7c6bd9f4cfa33c14f5b40eb5f789ad4f04f",
  "issued_at": "2026-08-08T16:00:00.000Z"
 },
 "view_digest": "sha256:4f2aacb1ebf1da5dd26a81387f4ca2e5cedbc2276ba43c1c37fe3d2d4165ef3b",
 "withheld": {
  "anything_withheld": true,
  "note": "Facts outside this role’s remit were removed. That something was removed is stated so a partial record is never mistaken for a complete one. How much, and what, is not stated — a count is an inference about the part you are not entitled to see."
 },
 "view": {
  "spec": "urn:ietf:params:corobate:receipt:1",
  "receipt_version": "1.8",
  "issued_at": "2026-08-08T16:00:00.000Z",
  "decision": {
   "id": "ai_TRIAGE_V4_after",
   "domain": "supply-chain",
   "subject": "ai-system:TRIAGE-ASSISTANT-V4",
   "question": "May this AI system be deployed to triage citizen-facing casework?"
  },
  "memory": {
   "state_digest": "sha256:d8c970114e57738a62465be9287d7045cd8966caeb801154d420321a11451dcc",
   "ledger_head": "sha256:b883e583bf7eac8664664c008b4556f5e62ef70a681669c550a6d84ccad602fc",
   "coverage_gaps": [],
   "exposure": {
    "usd": 1400000,
    "declared_by": "actor:human:ao-authorizing-official",
    "ledger_seq": 7
   },
   "policy_digest": "sha256:a6b69b7d20f7fb04d522364af1d92992058b04a5835fcec9d1c9f2261c7ef636"
  },
  "data_horizon": "2026-08-08T16:00:00.000Z",
  "verdict": {
   "value": "APPROVE",
   "threshold_approve": 0.9,
   "threshold_caution": 0.7,
   "rule": "confidence>=threshold"
  },
  "confidence": {
   "value": 0.95,
   "method": "min-over-critical-inputs",
   "bound_by": "ai-system:TRIAGE-ASSISTANT-V4::vulnerability_scan"
  },
  "release": {
   "required": false,
   "required_by_tier": false,
   "escalated_by_acceptance": false,
   "risk_accepted": false,
   "state": "NOT_REQUIRED",
   "code": "QUORUM_NOT_REQUIRED",
   "reason": "this decision is below the top exposure tier (floor $10,000,000) and no risk acceptance escalated into this gate, so no multi-party release requirement applies.",
   "tier_floor_cents": 1000000000,
   "exposure_usd_cents": 140000000,
   "required_m": 2,
   "declared_n": 3,
   "floor_m": 2,
   "distinct_signers": 0,
   "superseded": 0,
   "collapsed": 0,
   "release_digest": "sha256:4ad3faa1a749da2c56339fa29e711571515a647ee4c4d9a29d41aa2251bff28a",
   "governance_digest": "sha256:8b0a45a27fcce9c1c243c764e855e67c6fe6dfd7f02a563bd90809b419731905",
   "governance_signed": true,
   "counted_voices": [],
   "signatures": [],
   "ledger_seq": null
  },
  "acceptance": {
   "state": "NONE",
   "code": "ACCEPTANCE_NONE",
   "reason": "no risk acceptance was presented for this decision. This is the ordinary case: a refusal is a refusal unless a named person has priced it.",
   "permitted_basis": null,
   "presented": 0,
   "superseded": 0,
   "expired": 0,
   "gaps_not_covered": 0,
   "coverage_gaps_in_force": [],
   "evidentiary_digest": "sha256:4ad3faa1a749da2c56339fa29e711571515a647ee4c4d9a29d41aa2251bff28a",
   "margin_floor_bp": 100,
   "authority_ceiling_cents": {
    "SUPERVISOR": 1000000,
    "MANAGER": 25000000,
    "DIRECTOR": 500000000,
    "OFFICER": 5000000000
   },
   "acceptances": [],
   "escalated": false,
   "live": false,
   "ledger_seq": null
  },
  "regulatory": {
   "spec": "corobate:regulatory:2",
   "resolved": true,
   "applied": [
    {
     "instrument_id": "nist-ai-rmf-1-0",
     "version": 1,
     "authority": "National Institute of Standards and Technology",
     "instrument": "AI Risk Management Framework 1.0",
     "edition": "1.0",
     "citation": "MEASURE-2.3, MEASURE-2.7, MANAGE-2.2 [VERIFY]",
     "source_digest": "sha256:a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1",
     "entered_by": "actor:human:issm",
     "entered_at": "2026-08-08T16:00:00.000Z"
    },
    {
     "instrument_id": "nist-sp-800-53r5-moderate",
     "version": 5,
     "authority": "National Institute of Standards and Technology",
     "instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
     "edition": "Rev. 5",
     "citation": "CA-2, CA-8, RA-5, SR-6 [VERIFY]",
     "source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353",
     "entered_by": "actor:human:issm",
     "entered_at": "2026-08-08T16:00:00.000Z"
    }
   ],
   "skipped": [],
   "conflicts": [],
   "bindings": [
    {
     "claim": "control_assessment",
     "requirement": "max_age_days",
     "value": 365,
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
      "instrument_id": "nist-sp-800-53r5-moderate",
      "version": 5,
      "edition": "Rev. 5",
      "citation": "CA-2 [VERIFY]",
      "source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "control_assessment",
     "requirement": "min_class",
     "value": "VERIFIED",
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
      "instrument_id": "nist-sp-800-53r5-moderate",
      "version": 5,
      "edition": "Rev. 5",
      "citation": "CA-2(1) independent assessors [VERIFY]",
      "source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "control_assessment",
     "requirement": "required",
     "value": true,
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
      "instrument_id": "nist-sp-800-53r5-moderate",
      "version": 5,
      "edition": "Rev. 5",
      "citation": "CA-2 [VERIFY]",
      "source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "incident_response_plan_test",
     "requirement": "required",
     "value": true,
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "AI Risk Management Framework 1.0",
      "instrument_id": "nist-ai-rmf-1-0",
      "version": 1,
      "edition": "1.0",
      "citation": "MANAGE-4.1 [VERIFY]",
      "source_digest": "sha256:a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "model_evaluation",
     "requirement": "max_age_days",
     "value": 180,
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "AI Risk Management Framework 1.0",
      "instrument_id": "nist-ai-rmf-1-0",
      "version": 1,
      "edition": "1.0",
      "citation": "MEASURE-2.3 [VERIFY]",
      "source_digest": "sha256:a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "model_evaluation",
     "requirement": "min_class",
     "value": "VERIFIED",
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "AI Risk Management Framework 1.0",
      "instrument_id": "nist-ai-rmf-1-0",
      "version": 1,
      "edition": "1.0",
      "citation": "MEASURE-2.3 independent evaluation [VERIFY]",
      "source_digest": "sha256:a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "model_evaluation",
     "requirement": "required",
     "value": true,
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "AI Risk Management Framework 1.0",
      "instrument_id": "nist-ai-rmf-1-0",
      "version": 1,
      "edition": "1.0",
      "citation": "MEASURE-2.3 [VERIFY]",
      "source_digest": "sha256:a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "penetration_test",
     "requirement": "min_class",
     "value": "VERIFIED",
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
      "instrument_id": "nist-sp-800-53r5-moderate",
      "version": 5,
      "edition": "Rev. 5",
      "citation": "CA-8(1) independent penetration agent [VERIFY]",
      "source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "penetration_test",
     "requirement": "required",
     "value": true,
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
      "instrument_id": "nist-sp-800-53r5-moderate",
      "version": 5,
      "edition": "Rev. 5",
      "citation": "CA-8 [VERIFY]",
      "source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "security_resilience_evaluation",
     "requirement": "required",
     "value": true,
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "AI Risk Management Framework 1.0",
      "instrument_id": "nist-ai-rmf-1-0",
      "version": 1,
      "edition": "1.0",
      "citation": "MEASURE-2.7 [VERIFY]",
      "source_digest": "sha256:a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "vulnerability_scan",
     "requirement": "max_age_days",
     "value": 30,
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
      "instrument_id": "nist-sp-800-53r5-moderate",
      "version": 5,
      "edition": "Rev. 5",
      "citation": "RA-5(a) [VERIFY]",
      "source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "vulnerability_scan",
     "requirement": "required",
     "value": true,
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
      "instrument_id": "nist-sp-800-53r5-moderate",
      "version": 5,
      "edition": "Rev. 5",
      "citation": "RA-5 [VERIFY]",
      "source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    }
   ],
   "defaults": [
    {
     "claim": "control_assessment",
     "requirement": "ai_position",
     "value": "ADMIT",
     "because": "No instrument in force stated a position on AI-authored evidence for \"control_assessment\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
    },
    {
     "claim": "incident_response_plan_test",
     "requirement": "ai_position",
     "value": "ADMIT",
     "because": "No instrument in force stated a position on AI-authored evidence for \"incident_response_plan_test\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
    },
    {
     "claim": "model_evaluation",
     "requirement": "ai_position",
     "value": "ADMIT",
     "because": "No instrument in force stated a position on AI-authored evidence for \"model_evaluation\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
    },
    {
     "claim": "penetration_test",
     "requirement": "ai_position",
     "value": "ADMIT",
     "because": "No instrument in force stated a position on AI-authored evidence for \"penetration_test\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
    },
    {
     "claim": "security_resilience_evaluation",
     "requirement": "ai_position",
     "value": "ADMIT",
     "because": "No instrument in force stated a position on AI-authored evidence for \"security_resilience_evaluation\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
    },
    {
     "claim": "vulnerability_scan",
     "requirement": "ai_position",
     "value": "ADMIT",
     "because": "No instrument in force stated a position on AI-authored evidence for \"vulnerability_scan\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
    }
   ]
  },
  "reasons": [
   "Confidence 95.00% is bound by \"ai-system:TRIAGE-ASSISTANT-V4|vulnerability_scan\".",
   "1 memory was withheld from the context block: ai-system:TRIAGE-ASSISTANT-V4|model_self_report (sparse track record: 1 independent observation(s); no failure recorded, so the class ceiling stands).",
   "Thresholds for $1,400,000 exposure: approve 90%, caution 70%."
  ],
  "inputs": [
   {
    "key": "ai-system:TRIAGE-ASSISTANT-V4::vulnerability_scan",
    "value": "clean-at-scan",
    "provenance": "VERIFIED",
    "source": "nvd-cve:vulnerability_scan",
    "observed_at": "2026-08-04T16:00:00.000Z",
    "reliability": 0.95,
    "critical": true,
    "memory_status": "admitted",
    "memory_kind": "status",
    "memory_actor": "actor:sys:registry:nvd-cve",
    "memory_age_days": 4
   },
   {
    "key": "ai-system:TRIAGE-ASSISTANT-V4::incident_response_plan_test",
    "value": "observed",
    "provenance": "VERIFIED",
    "source": "CERT-3PAO-ATLANTIC:incident_response_plan_test",
    "observed_at": "2026-06-24T16:00:00.000Z",
    "reliability": 0.95,
    "critical": true,
    "memory_status": "admitted",
    "memory_kind": "certificate",
    "memory_actor": "actor:org:CERT-3PAO-ATLANTIC",
    "memory_age_days": 45
   },
   {
    "key": "ai-system:TRIAGE-ASSISTANT-V4::model_evaluation",
    "value": "independent",
    "provenance": "VERIFIED",
    "source": "LAB-REDTEAM-EVAL:model_evaluation",
    "observed_at": "2026-07-19T16:00:00.000Z",
    "reliability": 0.95,
    "critical": true,
    "memory_status": "admitted",
    "memory_kind": "test_report",
    "memory_actor": "actor:org:LAB-REDTEAM-EVAL",
    "memory_age_days": 20
   },
   {
    "key": "ai-system:TRIAGE-ASSISTANT-V4::security_resilience_evaluation",
    "value": "assessed",
    "provenance": "VERIFIED",
    "source": "LAB-NVLAP-0412:security_resilience_evaluation",
    "observed_at": "2026-07-09T16:00:00.000Z",
    "reliability": 0.95,
    "critical": true,
    "memory_status": "admitted",
    "memory_kind": "test_report",
    "memory_actor": "actor:org:LAB-NVLAP-0412",
    "memory_age_days": 30
   },
   {
    "key": "ai-system:TRIAGE-ASSISTANT-V4::penetration_test",
    "value": "no-critical",
    "provenance": "VERIFIED",
    "source": "LAB-NVLAP-0412:penetration_test",
    "observed_at": "2026-06-09T16:00:00.000Z",
    "reliability": 0.95,
    "critical": true,
    "memory_status": "admitted",
    "memory_kind": "test_report",
    "memory_actor": "actor:org:LAB-NVLAP-0412",
    "memory_age_days": 60
   },
   {
    "key": "ai-system:TRIAGE-ASSISTANT-V4::control_assessment",
    "value": "satisfied",
    "provenance": "VERIFIED",
    "source": "CERT-3PAO-ATLANTIC:control_assessment",
    "observed_at": "2026-04-30T16:00:00.000Z",
    "reliability": 0.95,
    "critical": true,
    "memory_status": "admitted",
    "memory_kind": "certificate",
    "memory_actor": "actor:org:CERT-3PAO-ATLANTIC",
    "memory_age_days": 100
   },
   {
    "key": "ai-system:TRIAGE-ASSISTANT-V4::model_self_report",
    "value": null,
    "provenance": "SELLER-ASSERTED",
    "source": "triage-assistant-v4:model_self_report",
    "observed_at": "2026-07-30T16:00:00.000Z",
    "reliability": 0.5,
    "critical": false,
    "memory_status": "withheld",
    "memory_kind": "test_report",
    "memory_actor": "actor:ai:triage-assistant-v4",
    "memory_age_days": 9
   }
  ],
  "crypto_suite": {
   "spec": "corobate:suite:1",
   "id": "CB-1-ES256-SHA256",
   "receipt_digest": "sha256",
   "chain_digest": "sha256",
   "content_digest": "sha256",
   "envelope_signature": "ES256",
   "signature_curve": "P-256",
   "canonicalisation": "attest-canon/2",
   "quantum_resistant": false
  }
 }
}

Authorising official (signer)

The named official whose signature carries the authorisation decision.

What is at stake, what the evidence supports, what is missing, and the digest they are signing over.

You are being asked to sign

May this AI system be deployed to triage citizen-facing casework?

At stake$1,400,000
Evidence saysAPPROVE
Release stateNOT_REQUIRED
signing over evidentiary digest sha256:4ad3faa1a749da2c56339fa29e711571515a647ee4c4d9a29d41aa2251bff28a

The signature is over the STATE OF THE EVIDENCE. Move one fact behind this decision and the digest moves and the signature stops counting — which is what makes it safe to collect signatures before everyone is in the room.

What is missing

  • Nothing required is missing.
The scoped copy itself — partial — something outside this role’s remit was removed
FAITHFUL digest sha256:5a5e12d1f5206d731efed4c4973894c3632f1e773c2d7e939bbe76823b76156c matches the commitment sealed in the receipt.
{
 "spec": "corobate:role-view:2",
 "role": "EXECUTIVE",
 "purpose": "A named signer on the release gate. Sees what is at stake, what the evidence supports, who else has signed and what they are being asked to sign over.",
 "is_a_receipt": false,
 "warning": "This is a SCOPED COPY of a sealed decision, not the decision record itself. It will not verify as a receipt and must not be presented as one. To confirm it is faithful, recompute its `view` digest under the same canonicalisation that produces receipt_hash and compare it with the entry for this role in the source receipt’s `views` block.",
 "derived_from": {
  "receipt_hash": "sha256:c344f0bbd85452f2a504d682b85270eccef70039d8abc41090c18d33e17b94d1",
  "entry_hash": "sha256:b55a572b8c628ac13f33499905dac7c6bd9f4cfa33c14f5b40eb5f789ad4f04f",
  "issued_at": "2026-08-08T16:00:00.000Z"
 },
 "view_digest": "sha256:5a5e12d1f5206d731efed4c4973894c3632f1e773c2d7e939bbe76823b76156c",
 "withheld": {
  "anything_withheld": true,
  "note": "Facts outside this role’s remit were removed. That something was removed is stated so a partial record is never mistaken for a complete one. How much, and what, is not stated — a count is an inference about the part you are not entitled to see."
 },
 "view": {
  "spec": "urn:ietf:params:corobate:receipt:1",
  "receipt_version": "1.8",
  "issued_at": "2026-08-08T16:00:00.000Z",
  "decision": {
   "id": "ai_TRIAGE_V4_after",
   "domain": "supply-chain",
   "subject": "ai-system:TRIAGE-ASSISTANT-V4",
   "question": "May this AI system be deployed to triage citizen-facing casework?"
  },
  "memory": {
   "state_digest": "sha256:d8c970114e57738a62465be9287d7045cd8966caeb801154d420321a11451dcc",
   "ledger_head": "sha256:b883e583bf7eac8664664c008b4556f5e62ef70a681669c550a6d84ccad602fc",
   "coverage_gaps": [],
   "exposure": {
    "usd": 1400000,
    "declared_by": "actor:human:ao-authorizing-official",
    "ledger_seq": 7
   }
  },
  "verdict": {
   "value": "APPROVE",
   "threshold_approve": 0.9,
   "threshold_caution": 0.7,
   "rule": "confidence>=threshold"
  },
  "confidence": {
   "value": 0.95,
   "method": "min-over-critical-inputs",
   "bound_by": "ai-system:TRIAGE-ASSISTANT-V4::vulnerability_scan"
  },
  "release": {
   "required": false,
   "required_by_tier": false,
   "escalated_by_acceptance": false,
   "risk_accepted": false,
   "state": "NOT_REQUIRED",
   "code": "QUORUM_NOT_REQUIRED",
   "reason": "this decision is below the top exposure tier (floor $10,000,000) and no risk acceptance escalated into this gate, so no multi-party release requirement applies.",
   "tier_floor_cents": 1000000000,
   "exposure_usd_cents": 140000000,
   "required_m": 2,
   "declared_n": 3,
   "floor_m": 2,
   "distinct_signers": 0,
   "superseded": 0,
   "collapsed": 0,
   "release_digest": "sha256:4ad3faa1a749da2c56339fa29e711571515a647ee4c4d9a29d41aa2251bff28a",
   "governance_digest": "sha256:8b0a45a27fcce9c1c243c764e855e67c6fe6dfd7f02a563bd90809b419731905",
   "governance_signed": true,
   "counted_voices": [],
   "signatures": [],
   "ledger_seq": null
  },
  "acceptance": {
   "state": "NONE",
   "code": "ACCEPTANCE_NONE",
   "reason": "no risk acceptance was presented for this decision. This is the ordinary case: a refusal is a refusal unless a named person has priced it.",
   "permitted_basis": null,
   "presented": 0,
   "superseded": 0,
   "expired": 0,
   "gaps_not_covered": 0,
   "coverage_gaps_in_force": [],
   "evidentiary_digest": "sha256:4ad3faa1a749da2c56339fa29e711571515a647ee4c4d9a29d41aa2251bff28a",
   "margin_floor_bp": 100,
   "authority_ceiling_cents": {
    "SUPERVISOR": 1000000,
    "MANAGER": 25000000,
    "DIRECTOR": 500000000,
    "OFFICER": 5000000000
   },
   "acceptances": [],
   "escalated": false,
   "live": false,
   "ledger_seq": null
  },
  "reasons": [
   "Confidence 95.00% is bound by \"ai-system:TRIAGE-ASSISTANT-V4|vulnerability_scan\".",
   "1 memory was withheld from the context block: ai-system:TRIAGE-ASSISTANT-V4|model_self_report (sparse track record: 1 independent observation(s); no failure recorded, so the class ceiling stands).",
   "Thresholds for $1,400,000 exposure: approve 90%, caution 70%."
  ],
  "regulatory": {
   "applied": [
    {
     "instrument_id": "nist-ai-rmf-1-0",
     "version": 1,
     "authority": "National Institute of Standards and Technology",
     "instrument": "AI Risk Management Framework 1.0",
     "edition": "1.0",
     "citation": "MEASURE-2.3, MEASURE-2.7, MANAGE-2.2 [VERIFY]",
     "source_digest": "sha256:a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1",
     "entered_by": "actor:human:issm",
     "entered_at": "2026-08-08T16:00:00.000Z"
    },
    {
     "instrument_id": "nist-sp-800-53r5-moderate",
     "version": 5,
     "authority": "National Institute of Standards and Technology",
     "instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
     "edition": "Rev. 5",
     "citation": "CA-2, CA-8, RA-5, SR-6 [VERIFY]",
     "source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353",
     "entered_by": "actor:human:issm",
     "entered_at": "2026-08-08T16:00:00.000Z"
    }
   ],
   "conflicts": [],
   "defaults": [
    {
     "claim": "control_assessment",
     "requirement": "ai_position",
     "value": "ADMIT",
     "because": "No instrument in force stated a position on AI-authored evidence for \"control_assessment\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
    },
    {
     "claim": "incident_response_plan_test",
     "requirement": "ai_position",
     "value": "ADMIT",
     "because": "No instrument in force stated a position on AI-authored evidence for \"incident_response_plan_test\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
    },
    {
     "claim": "model_evaluation",
     "requirement": "ai_position",
     "value": "ADMIT",
     "because": "No instrument in force stated a position on AI-authored evidence for \"model_evaluation\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
    },
    {
     "claim": "penetration_test",
     "requirement": "ai_position",
     "value": "ADMIT",
     "because": "No instrument in force stated a position on AI-authored evidence for \"penetration_test\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
    },
    {
     "claim": "security_resilience_evaluation",
     "requirement": "ai_position",
     "value": "ADMIT",
     "because": "No instrument in force stated a position on AI-authored evidence for \"security_resilience_evaluation\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
    },
    {
     "claim": "vulnerability_scan",
     "requirement": "ai_position",
     "value": "ADMIT",
     "because": "No instrument in force stated a position on AI-authored evidence for \"vulnerability_scan\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
    }
   ]
  },
  "inputs": [
   {
    "key": "ai-system:TRIAGE-ASSISTANT-V4::vulnerability_scan",
    "provenance": "VERIFIED",
    "reliability": 0.95,
    "critical": true,
    "memory_status": "admitted"
   },
   {
    "key": "ai-system:TRIAGE-ASSISTANT-V4::incident_response_plan_test",
    "provenance": "VERIFIED",
    "reliability": 0.95,
    "critical": true,
    "memory_status": "admitted"
   },
   {
    "key": "ai-system:TRIAGE-ASSISTANT-V4::model_evaluation",
    "provenance": "VERIFIED",
    "reliability": 0.95,
    "critical": true,
    "memory_status": "admitted"
   },
   {
    "key": "ai-system:TRIAGE-ASSISTANT-V4::security_resilience_evaluation",
    "provenance": "VERIFIED",
    "reliability": 0.95,
    "critical": true,
    "memory_status": "admitted"
   },
   {
    "key": "ai-system:TRIAGE-ASSISTANT-V4::penetration_test",
    "provenance": "VERIFIED",
    "reliability": 0.95,
    "critical": true,
    "memory_status": "admitted"
   },
   {
    "key": "ai-system:TRIAGE-ASSISTANT-V4::control_assessment",
    "provenance": "VERIFIED",
    "reliability": 0.95,
    "critical": true,
    "memory_status": "admitted"
   },
   {
    "key": "ai-system:TRIAGE-ASSISTANT-V4::model_self_report",
    "provenance": "SELLER-ASSERTED",
    "reliability": 0.5,
    "critical": false,
    "memory_status": "withheld"
   }
  ]
 }
}

Independent audit / IG

Internal audit, an inspector general, or an external auditor testing the programme.

Everything, plus the verifier’s own findings over the sealed record.

This view withholds nothing. What it adds is the 22 checks the published verifier ran over the sealed record behind every other view of this decision — recomputed at build time, not asserted.

#CheckDetail
1Content reproduces (JCS + SHA-256)PASSmatches sha256:c344f0bbd85452f2a504d682b85270eccef70039d8abc41090c18d33e17b94d1
2Hash chain links (entry = H(prev||content))PASShead sha256:b55a572b8c628ac13f33499905dac7c6bd9f4cfa33c14f5b40eb5f789ad4f04f
3Confidence gated by weakest critical inputPASSmin over critical = 0.95, bound_by ai-system:TRIAGE-ASSISTANT-V4::vulnerability_scan (VERIFIED)
3bVerdict follows the threshold rulePASS0.95 => APPROVE; recorded APPROVE
4Point-in-time seal (no input past data_horizon)PASSall inputs <= 2026-08-08T16:00:00.000Z
5Anchor covers the head, and the timestamp token re-readsPASSinternally consistent; NO external anchor was requested — this is not a validated timestamp
6Criteria travel with the receipt and reproducePASSpolicy_body hashes to sha256:a6b69b7d20f7fb04d522364af1d92992058b04a5835fcec9d1c9f2261c7ef636
7Reliability re-derives from recorded evidencePASSall 7 inputs re-derive exactly
8Outcome trials and lineage discounts re-derivePASS7 input(s) re-derive: 0 credited outcome trial(s), 0 lineage-discounted corroboration(s); every reliability is at or under its class ceiling
9Re-ingested receipts respect their weakest-input ceilingPASSno re-ingested receipts: every input rests on a primary observation
10Release quorum re-derivesPASSNOT_REQUIRED - below the top exposure tier, no multi-party requirement applies
11Risk acceptance re-derivesPASSno risk acceptance: this decision stands or falls on its evidence
12Observer credentials were not revoked as of observation timePASSrevocation list 5 (0 entries, issued 2026-08-06T00:00:00.000Z, next update due 2026-08-13T00:00:00.000Z) reproduces; 6 observer signature(s) judged as of their own instant, none under a key revoked as compromised or retired by then
13The cryptographic suite is named and is one this verifier implementsPASSsealed under CB-1-ES256-SHA256 (ES256 / sha256, attest-canon/2); this verifier implements it; the suite states it is NOT quantum resistant
14Regulatory bindings are attributed and were enforcedPASS12 binding(s) from 2 instrument(s) in force, each attributed to an authority, a citation and a document digest; 6 required claim(s) all reached the gate
15Role-view commitments re-derive, and the customs view carries no moneyPASS6 role-view commitment(s) re-derived from this receipt’s own body by this verifier’s independent projection; the REGULATOR view carries no commercial figure
16AI-authored input was admitted only where an authority allowed itPASS0 claim(s) carry a position on AI-authored evidence set by an authority and 6 carry a recorded default nobody set; 0 exclusion(s) and 0 corroboration-only rule(s) re-derived against this receipt's own admitted inputs; 0 admitted input(s) are AI-authored by their enrolled identity
17State digest recomputes from the ledger aloneUNVERIFIABLENOT APPLICABLE — you supplied no ledger, so the state digest cannot be re-derived from anything. This receipt commits to the corpus the deciding system held at the instant it sealed, and that commitment is checked by recomputing it from the append-only ledger and comparing; with no ledger in hand there is no second artefact to recompute from. The receipt is not at fault and nothing here is missing from it. Obtain the ledger from the issuer and re-run with --ledger <file>, or verifyReceipt(r, {ledger}). Nothing here has failed and nothing here has passed.
18Registry membership re-derives for every key relied onPASSall 4 key(s) relied on re-derive to the entries root registry v3 committed to and the trust root signed
20Geometric support re-derives, and an unevaluated record is not a supported onePASSno authority bound a metric to any claim on this receipt, so no geometric test applied. A claim nobody bound a metric to is not a claim about geometry, and this is a stated absence rather than a silent one
19The cause of every uncovered requirement re-derivesPASSevery required claim on this receipt is covered, so this check ran and had nothing to explain
21The sealing party is the one you were told to expectUNVERIFIABLENOT APPLICABLE — you supplied no trust bundle, so nothing here establishes who sealed this. Identities 1 to 20 prove that this document agrees with itself; not one of them asks whose trust root it was sealed under, and a document that agrees with itself about a decision nobody made agrees with itself perfectly. Obtain the issuer's corobate:trust-bundle:1 out of band, confirm its spoken fingerprint with them by voice, and re-run with --trust-bundle <file> --expect-fingerprint <what you heard>. Nothing here has failed and nothing here has passed.
The scoped copy itself — complete for this role
FAITHFUL digest sha256:f755a71573eb528e6058341aafab143fa3afc9ec3aefa3c220c08c292ccf9795 matches the commitment sealed in the receipt.
{
 "spec": "corobate:role-view:2",
 "role": "AUDITOR",
 "purpose": "An external assessor. Sees the complete sealed record: this view withholds nothing and exists so the identity case is a case rather than an exception.",
 "is_a_receipt": false,
 "warning": "This is a SCOPED COPY of a sealed decision, not the decision record itself. It will not verify as a receipt and must not be presented as one. To confirm it is faithful, recompute its `view` digest under the same canonicalisation that produces receipt_hash and compare it with the entry for this role in the source receipt’s `views` block.",
 "derived_from": {
  "receipt_hash": "sha256:c344f0bbd85452f2a504d682b85270eccef70039d8abc41090c18d33e17b94d1",
  "entry_hash": "sha256:b55a572b8c628ac13f33499905dac7c6bd9f4cfa33c14f5b40eb5f789ad4f04f",
  "issued_at": "2026-08-08T16:00:00.000Z"
 },
 "view_digest": "sha256:f755a71573eb528e6058341aafab143fa3afc9ec3aefa3c220c08c292ccf9795",
 "withheld": {
  "anything_withheld": false,
  "note": "Nothing outside the seal was removed for this role."
 },
 "view": {
  "spec": "urn:ietf:params:corobate:receipt:1",
  "receipt_version": "1.8",
  "engine": {
   "name": "corobate-memory",
   "version": "1.0.0"
  },
  "decision": {
   "id": "ai_TRIAGE_V4_after",
   "domain": "supply-chain",
   "subject": "ai-system:TRIAGE-ASSISTANT-V4",
   "question": "May this AI system be deployed to triage citizen-facing casework?"
  },
  "issued_at": "2026-08-08T16:00:00.000Z",
  "data_horizon": "2026-08-08T16:00:00.000Z",
  "inputs": [
   {
    "key": "ai-system:TRIAGE-ASSISTANT-V4::vulnerability_scan",
    "value": "clean-at-scan",
    "provenance": "VERIFIED",
    "source": "nvd-cve:vulnerability_scan",
    "observed_at": "2026-08-04T16:00:00.000Z",
    "last_corroborated_at": null,
    "memory_refreshed_by": [],
    "reliability": 0.95,
    "critical": true,
    "memory_id": "mem_4d2b1fc0d322",
    "memory_status": "admitted",
    "memory_kind": "status",
    "memory_actor": "actor:sys:registry:nvd-cve",
    "memory_age_days": 4,
    "memory_track": {
     "n": 1,
     "successes": 1
    },
    "memory_promoted_by": [],
    "memory_content_digest": "sha256:aea4c3860d57b3edd045cd33946015c41ff1aee9cc8a4df49f26d8a5165d4a38",
    "memory_outcomes": {
     "verified": 0,
     "falsified": 0,
     "modified": 0,
     "counted": 0,
     "recorded": 0
    },
    "memory_outcome_attestations": [],
    "memory_observer_lineage": null,
    "memory_corroborations": [],
    "memory_reingest": null,
    "memory_reasons": [
     "sparse track record: 1 independent observation(s); no failure recorded, so the class ceiling stands"
    ],
    "memory_class_floor": null,
    "memory_below_class_floor": false,
    "memory_not_attested": false,
    "memory_below_claim_reliability_floor": false,
    "memory_not_competent_authority": false,
    "memory_out_of_specification": false,
    "memory_ai_authored": false,
    "memory_ai_in_lineage": false,
    "memory_ai_position": "ADMIT",
    "memory_ai_inadmissible": false,
    "memory_geo_inadmissible": false,
    "memory_geo_rung": null,
    "memory_geo_metric": null,
    "memory_geo_required_metric": null,
    "observer_attested": true,
    "observer_auth_code": "VERIFIED",
    "observer_key_id": "k_5873dd9e7169def3",
    "attestation": null,
    "derivation": {
     "provenance": "VERIFIED",
     "ceiling_bp": 9500,
     "track": {
      "n": 1,
      "successes": 1
     },
     "wilson_bp": null,
     "age_days": 4,
     "max_age_days": 14,
     "house_max_age_days": 14,
     "instrument_max_age_days": 30,
     "freshness_cap_bp": 4000,
     "min_track_n": 5,
     "wilson_z_milli": 1960,
     "source_present": true,
     "seller_asserted_cap_bp": 5000,
     "retracted": false,
     "contradicted": false,
     "outcome_trials": 0,
     "outcomes": {
      "verified": 0,
      "falsified": 0,
      "modified": 0,
      "counted": 0,
      "recorded": 0
     },
     "corroborations_counted": 0,
     "corroborations_discounted": 0,
     "reingest_ceiling_bp": null,
     "reingest_depth": null,
     "reingest_weakest_class": null,
     "reingest_source_confidence_bp": null,
     "ai_authored": false,
     "ai_authored_because": null,
     "ai_in_lineage": false,
     "ai_position": "ADMIT"
    },
    "memory_reason_codes": [
     {
      "code": "SPARSE_TRACK_RECORD",
      "observed": 1,
      "limit": 5,
      "binding": false
     }
    ],
    "context_line": "[VERIFIED · r=95.0% · 4d · nvd-cve:vulnerability_scan] ai-system:TRIAGE-ASSISTANT-V4 / vulnerability_scan: clean-at-scan"
   },
   {
    "key": "ai-system:TRIAGE-ASSISTANT-V4::incident_response_plan_test",
    "value": "observed",
    "provenance": "VERIFIED",
    "source": "CERT-3PAO-ATLANTIC:incident_response_plan_test",
    "observed_at": "2026-06-24T16:00:00.000Z",
    "last_corroborated_at": null,
    "memory_refreshed_by": [],
    "reliability": 0.95,
    "critical": true,
    "memory_id": "mem_a54dcc18c5ba",
    "memory_status": "admitted",
    "memory_kind": "certificate",
    "memory_actor": "actor:org:CERT-3PAO-ATLANTIC",
    "memory_age_days": 45,
    "memory_track": {
     "n": 1,
     "successes": 1
    },
    "memory_promoted_by": [],
    "memory_content_digest": "sha256:a73e4d82b06b62aa687c0a5352a36df46dd691e2bfa8b1354c847d24612df001",
    "memory_outcomes": {
     "verified": 0,
     "falsified": 0,
     "modified": 0,
     "counted": 0,
     "recorded": 0
    },
    "memory_outcome_attestations": [],
    "memory_observer_lineage": null,
    "memory_corroborations": [],
    "memory_reingest": null,
    "memory_reasons": [
     "sparse track record: 1 independent observation(s); no failure recorded, so the class ceiling stands"
    ],
    "memory_class_floor": null,
    "memory_below_class_floor": false,
    "memory_not_attested": false,
    "memory_below_claim_reliability_floor": false,
    "memory_not_competent_authority": false,
    "memory_out_of_specification": false,
    "memory_ai_authored": false,
    "memory_ai_in_lineage": false,
    "memory_ai_position": "ADMIT",
    "memory_ai_inadmissible": false,
    "memory_geo_inadmissible": false,
    "memory_geo_rung": null,
    "memory_geo_metric": null,
    "memory_geo_required_metric": null,
    "observer_attested": true,
    "observer_auth_code": "VERIFIED",
    "observer_key_id": "k_307e4bfd710ec9b3",
    "attestation": null,
    "derivation": {
     "provenance": "VERIFIED",
     "ceiling_bp": 9500,
     "track": {
      "n": 1,
      "successes": 1
     },
     "wilson_bp": null,
     "age_days": 45,
     "max_age_days": 365,
     "house_max_age_days": 365,
     "instrument_max_age_days": null,
     "freshness_cap_bp": 4000,
     "min_track_n": 5,
     "wilson_z_milli": 1960,
     "source_present": true,
     "seller_asserted_cap_bp": 5000,
     "retracted": false,
     "contradicted": false,
     "outcome_trials": 0,
     "outcomes": {
      "verified": 0,
      "falsified": 0,
      "modified": 0,
      "counted": 0,
      "recorded": 0
     },
     "corroborations_counted": 0,
     "corroborations_discounted": 0,
     "reingest_ceiling_bp": null,
     "reingest_depth": null,
     "reingest_weakest_class": null,
     "reingest_source_confidence_bp": null,
     "ai_authored": false,
     "ai_authored_because": null,
     "ai_in_lineage": false,
     "ai_position": "ADMIT"
    },
    "memory_reason_codes": [
     {
      "code": "SPARSE_TRACK_RECORD",
      "observed": 1,
      "limit": 5,
      "binding": false
     }
    ],
    "context_line": "[VERIFIED · r=95.0% · 45d · CERT-3PAO-ATLANTIC:incident_response_plan_test] ai-system:TRIAGE-ASSISTANT-V4 / incident_response_plan_test: observed"
   },
   {
    "key": "ai-system:TRIAGE-ASSISTANT-V4::model_evaluation",
    "value": "independent",
    "provenance": "VERIFIED",
    "source": "LAB-REDTEAM-EVAL:model_evaluation",
    "observed_at": "2026-07-19T16:00:00.000Z",
    "last_corroborated_at": null,
    "memory_refreshed_by": [],
    "reliability": 0.95,
    "critical": true,
    "memory_id": "mem_7dfaefd014b0",
    "memory_status": "admitted",
    "memory_kind": "test_report",
    "memory_actor": "actor:org:LAB-REDTEAM-EVAL",
    "memory_age_days": 20,
    "memory_track": {
     "n": 1,
     "successes": 1
    },
    "memory_promoted_by": [],
    "memory_content_digest": "sha256:a7ca29dc11f86a762fc3c3783a0d758796ee0cae8bbd4ae7cb996b3c0a5f45a4",
    "memory_outcomes": {
     "verified": 0,
     "falsified": 0,
     "modified": 0,
     "counted": 0,
     "recorded": 0
    },
    "memory_outcome_attestations": [],
    "memory_observer_lineage": null,
    "memory_corroborations": [],
    "memory_reingest": null,
    "memory_reasons": [
     "sparse track record: 1 independent observation(s); no failure recorded, so the class ceiling stands"
    ],
    "memory_class_floor": "VERIFIED",
    "memory_below_class_floor": false,
    "memory_not_attested": false,
    "memory_below_claim_reliability_floor": false,
    "memory_not_competent_authority": false,
    "memory_out_of_specification": false,
    "memory_ai_authored": false,
    "memory_ai_in_lineage": false,
    "memory_ai_position": "ADMIT",
    "memory_ai_inadmissible": false,
    "memory_geo_inadmissible": false,
    "memory_geo_rung": null,
    "memory_geo_metric": null,
    "memory_geo_required_metric": null,
    "observer_attested": true,
    "observer_auth_code": "VERIFIED",
    "observer_key_id": "k_db83368c3527dcb1",
    "attestation": null,
    "derivation": {
     "provenance": "VERIFIED",
     "ceiling_bp": 9500,
     "track": {
      "n": 1,
      "successes": 1
     },
     "wilson_bp": null,
     "age_days": 20,
     "max_age_days": 180,
     "house_max_age_days": 180,
     "instrument_max_age_days": 180,
     "freshness_cap_bp": 4000,
     "min_track_n": 5,
     "wilson_z_milli": 1960,
     "source_present": true,
     "seller_asserted_cap_bp": 5000,
     "retracted": false,
     "contradicted": false,
     "outcome_trials": 0,
     "outcomes": {
      "verified": 0,
      "falsified": 0,
      "modified": 0,
      "counted": 0,
      "recorded": 0
     },
     "corroborations_counted": 0,
     "corroborations_discounted": 0,
     "reingest_ceiling_bp": null,
     "reingest_depth": null,
     "reingest_weakest_class": null,
     "reingest_source_confidence_bp": null,
     "min_class_floor": "VERIFIED",
     "ai_authored": false,
     "ai_authored_because": null,
     "ai_in_lineage": false,
     "ai_position": "ADMIT"
    },
    "memory_reason_codes": [
     {
      "code": "SPARSE_TRACK_RECORD",
      "observed": 1,
      "limit": 5,
      "binding": false
     }
    ],
    "context_line": "[VERIFIED · r=95.0% · 20d · LAB-REDTEAM-EVAL:model_evaluation] ai-system:TRIAGE-ASSISTANT-V4 / model_evaluation: independent"
   },
   {
    "key": "ai-system:TRIAGE-ASSISTANT-V4::security_resilience_evaluation",
    "value": "assessed",
    "provenance": "VERIFIED",
    "source": "LAB-NVLAP-0412:security_resilience_evaluation",
    "observed_at": "2026-07-09T16:00:00.000Z",
    "last_corroborated_at": null,
    "memory_refreshed_by": [],
    "reliability": 0.95,
    "critical": true,
    "memory_id": "mem_2c29e7fe028c",
    "memory_status": "admitted",
    "memory_kind": "test_report",
    "memory_actor": "actor:org:LAB-NVLAP-0412",
    "memory_age_days": 30,
    "memory_track": {
     "n": 1,
     "successes": 1
    },
    "memory_promoted_by": [],
    "memory_content_digest": "sha256:dcbb60638904f38e17aa80dd1108c75855c10f1992b0793dc56d369582fc515e",
    "memory_outcomes": {
     "verified": 0,
     "falsified": 0,
     "modified": 0,
     "counted": 0,
     "recorded": 0
    },
    "memory_outcome_attestations": [],
    "memory_observer_lineage": null,
    "memory_corroborations": [],
    "memory_reingest": null,
    "memory_reasons": [
     "sparse track record: 1 independent observation(s); no failure recorded, so the class ceiling stands"
    ],
    "memory_class_floor": null,
    "memory_below_class_floor": false,
    "memory_not_attested": false,
    "memory_below_claim_reliability_floor": false,
    "memory_not_competent_authority": false,
    "memory_out_of_specification": false,
    "memory_ai_authored": false,
    "memory_ai_in_lineage": false,
    "memory_ai_position": "ADMIT",
    "memory_ai_inadmissible": false,
    "memory_geo_inadmissible": false,
    "memory_geo_rung": null,
    "memory_geo_metric": null,
    "memory_geo_required_metric": null,
    "observer_attested": true,
    "observer_auth_code": "VERIFIED",
    "observer_key_id": "k_17d23885943ae529",
    "attestation": null,
    "derivation": {
     "provenance": "VERIFIED",
     "ceiling_bp": 9500,
     "track": {
      "n": 1,
      "successes": 1
     },
     "wilson_bp": null,
     "age_days": 30,
     "max_age_days": 180,
     "house_max_age_days": 180,
     "instrument_max_age_days": null,
     "freshness_cap_bp": 4000,
     "min_track_n": 5,
     "wilson_z_milli": 1960,
     "source_present": true,
     "seller_asserted_cap_bp": 5000,
     "retracted": false,
     "contradicted": false,
     "outcome_trials": 0,
     "outcomes": {
      "verified": 0,
      "falsified": 0,
      "modified": 0,
      "counted": 0,
      "recorded": 0
     },
     "corroborations_counted": 0,
     "corroborations_discounted": 0,
     "reingest_ceiling_bp": null,
     "reingest_depth": null,
     "reingest_weakest_class": null,
     "reingest_source_confidence_bp": null,
     "ai_authored": false,
     "ai_authored_because": null,
     "ai_in_lineage": false,
     "ai_position": "ADMIT"
    },
    "memory_reason_codes": [
     {
      "code": "SPARSE_TRACK_RECORD",
      "observed": 1,
      "limit": 5,
      "binding": false
     }
    ],
    "context_line": "[VERIFIED · r=95.0% · 30d · LAB-NVLAP-0412:security_resilience_evaluation] ai-system:TRIAGE-ASSISTANT-V4 / security_resilience_evaluation: assessed"
   },
   {
    "key": "ai-system:TRIAGE-ASSISTANT-V4::penetration_test",
    "value": "no-critical",
    "provenance": "VERIFIED",
    "source": "LAB-NVLAP-0412:penetration_test",
    "observed_at": "2026-06-09T16:00:00.000Z",
    "last_corroborated_at": null,
    "memory_refreshed_by": [],
    "reliability": 0.95,
    "critical": true,
    "memory_id": "mem_a3316d633bfe",
    "memory_status": "admitted",
    "memory_kind": "test_report",
    "memory_actor": "actor:org:LAB-NVLAP-0412",
    "memory_age_days": 60,
    "memory_track": {
     "n": 1,
     "successes": 1
    },
    "memory_promoted_by": [],
    "memory_content_digest": "sha256:db69fb062be9b066b370c668281e12896da2869456a2e6d356a0f14879b27de9",
    "memory_outcomes": {
     "verified": 0,
     "falsified": 0,
     "modified": 0,
     "counted": 0,
     "recorded": 0
    },
    "memory_outcome_attestations": [],
    "memory_observer_lineage": null,
    "memory_corroborations": [],
    "memory_reingest": null,
    "memory_reasons": [
     "sparse track record: 1 independent observation(s); no failure recorded, so the class ceiling stands"
    ],
    "memory_class_floor": "VERIFIED",
    "memory_below_class_floor": false,
    "memory_not_attested": false,
    "memory_below_claim_reliability_floor": false,
    "memory_not_competent_authority": false,
    "memory_out_of_specification": false,
    "memory_ai_authored": false,
    "memory_ai_in_lineage": false,
    "memory_ai_position": "ADMIT",
    "memory_ai_inadmissible": false,
    "memory_geo_inadmissible": false,
    "memory_geo_rung": null,
    "memory_geo_metric": null,
    "memory_geo_required_metric": null,
    "observer_attested": true,
    "observer_auth_code": "VERIFIED",
    "observer_key_id": "k_17d23885943ae529",
    "attestation": null,
    "derivation": {
     "provenance": "VERIFIED",
     "ceiling_bp": 9500,
     "track": {
      "n": 1,
      "successes": 1
     },
     "wilson_bp": null,
     "age_days": 60,
     "max_age_days": 180,
     "house_max_age_days": 180,
     "instrument_max_age_days": null,
     "freshness_cap_bp": 4000,
     "min_track_n": 5,
     "wilson_z_milli": 1960,
     "source_present": true,
     "seller_asserted_cap_bp": 5000,
     "retracted": false,
     "contradicted": false,
     "outcome_trials": 0,
     "outcomes": {
      "verified": 0,
      "falsified": 0,
      "modified": 0,
      "counted": 0,
      "recorded": 0
     },
     "corroborations_counted": 0,
     "corroborations_discounted": 0,
     "reingest_ceiling_bp": null,
     "reingest_depth": null,
     "reingest_weakest_class": null,
     "reingest_source_confidence_bp": null,
     "min_class_floor": "VERIFIED",
     "ai_authored": false,
     "ai_authored_because": null,
     "ai_in_lineage": false,
     "ai_position": "ADMIT"
    },
    "memory_reason_codes": [
     {
      "code": "SPARSE_TRACK_RECORD",
      "observed": 1,
      "limit": 5,
      "binding": false
     }
    ],
    "context_line": "[VERIFIED · r=95.0% · 60d · LAB-NVLAP-0412:penetration_test] ai-system:TRIAGE-ASSISTANT-V4 / penetration_test: no-critical"
   },
   {
    "key": "ai-system:TRIAGE-ASSISTANT-V4::control_assessment",
    "value": "satisfied",
    "provenance": "VERIFIED",
    "source": "CERT-3PAO-ATLANTIC:control_assessment",
    "observed_at": "2026-04-30T16:00:00.000Z",
    "last_corroborated_at": null,
    "memory_refreshed_by": [],
    "reliability": 0.95,
    "critical": true,
    "memory_id": "mem_a153eb336060",
    "memory_status": "admitted",
    "memory_kind": "certificate",
    "memory_actor": "actor:org:CERT-3PAO-ATLANTIC",
    "memory_age_days": 100,
    "memory_track": {
     "n": 1,
     "successes": 1
    },
    "memory_promoted_by": [],
    "memory_content_digest": "sha256:c1aaf46a55b4cdc629a754ac35da1b8ec4dec85c2c78613c7bc93546b63f233c",
    "memory_outcomes": {
     "verified": 0,
     "falsified": 0,
     "modified": 0,
     "counted": 0,
     "recorded": 0
    },
    "memory_outcome_attestations": [],
    "memory_observer_lineage": null,
    "memory_corroborations": [],
    "memory_reingest": null,
    "memory_reasons": [
     "sparse track record: 1 independent observation(s); no failure recorded, so the class ceiling stands"
    ],
    "memory_class_floor": "VERIFIED",
    "memory_below_class_floor": false,
    "memory_not_attested": false,
    "memory_below_claim_reliability_floor": false,
    "memory_not_competent_authority": false,
    "memory_out_of_specification": false,
    "memory_ai_authored": false,
    "memory_ai_in_lineage": false,
    "memory_ai_position": "ADMIT",
    "memory_ai_inadmissible": false,
    "memory_geo_inadmissible": false,
    "memory_geo_rung": null,
    "memory_geo_metric": null,
    "memory_geo_required_metric": null,
    "observer_attested": true,
    "observer_auth_code": "VERIFIED",
    "observer_key_id": "k_307e4bfd710ec9b3",
    "attestation": null,
    "derivation": {
     "provenance": "VERIFIED",
     "ceiling_bp": 9500,
     "track": {
      "n": 1,
      "successes": 1
     },
     "wilson_bp": null,
     "age_days": 100,
     "max_age_days": 365,
     "house_max_age_days": 365,
     "instrument_max_age_days": 365,
     "freshness_cap_bp": 4000,
     "min_track_n": 5,
     "wilson_z_milli": 1960,
     "source_present": true,
     "seller_asserted_cap_bp": 5000,
     "retracted": false,
     "contradicted": false,
     "outcome_trials": 0,
     "outcomes": {
      "verified": 0,
      "falsified": 0,
      "modified": 0,
      "counted": 0,
      "recorded": 0
     },
     "corroborations_counted": 0,
     "corroborations_discounted": 0,
     "reingest_ceiling_bp": null,
     "reingest_depth": null,
     "reingest_weakest_class": null,
     "reingest_source_confidence_bp": null,
     "min_class_floor": "VERIFIED",
     "ai_authored": false,
     "ai_authored_because": null,
     "ai_in_lineage": false,
     "ai_position": "ADMIT"
    },
    "memory_reason_codes": [
     {
      "code": "SPARSE_TRACK_RECORD",
      "observed": 1,
      "limit": 5,
      "binding": false
     }
    ],
    "context_line": "[VERIFIED · r=95.0% · 100d · CERT-3PAO-ATLANTIC:control_assessment] ai-system:TRIAGE-ASSISTANT-V4 / control_assessment: satisfied"
   },
   {
    "key": "ai-system:TRIAGE-ASSISTANT-V4::model_self_report",
    "value": null,
    "provenance": "SELLER-ASSERTED",
    "source": "triage-assistant-v4:model_self_report",
    "observed_at": "2026-07-30T16:00:00.000Z",
    "last_corroborated_at": null,
    "memory_refreshed_by": [],
    "reliability": 0.5,
    "critical": false,
    "memory_id": "mem_0412e050668a",
    "memory_status": "withheld",
    "memory_kind": "test_report",
    "memory_actor": "actor:ai:triage-assistant-v4",
    "memory_age_days": 9,
    "memory_track": {
     "n": 1,
     "successes": 1
    },
    "memory_promoted_by": [],
    "memory_content_digest": "sha256:d0df12a8884400dacf5a33d710fcc546d8d522ded0cf8d1e272b04b956a33c1c",
    "memory_outcomes": {
     "verified": 0,
     "falsified": 0,
     "modified": 0,
     "counted": 0,
     "recorded": 0
    },
    "memory_outcome_attestations": [],
    "memory_observer_lineage": null,
    "memory_corroborations": [],
    "memory_reingest": null,
    "memory_reasons": [
     "sparse track record: 1 independent observation(s); no failure recorded, so the class ceiling stands"
    ],
    "memory_class_floor": null,
    "memory_below_class_floor": false,
    "memory_not_attested": false,
    "memory_below_claim_reliability_floor": false,
    "memory_not_competent_authority": false,
    "memory_out_of_specification": false,
    "memory_ai_authored": true,
    "memory_ai_in_lineage": false,
    "memory_ai_position": null,
    "memory_ai_inadmissible": false,
    "memory_geo_inadmissible": false,
    "memory_geo_rung": null,
    "memory_geo_metric": null,
    "memory_geo_required_metric": null,
    "observer_attested": false,
    "observer_auth_code": "NO_ENVELOPE",
    "observer_key_id": null,
    "attestation": null,
    "derivation": {
     "provenance": "SELLER-ASSERTED",
     "ceiling_bp": 5000,
     "track": {
      "n": 1,
      "successes": 1
     },
     "wilson_bp": null,
     "age_days": 9,
     "max_age_days": 180,
     "house_max_age_days": 180,
     "instrument_max_age_days": null,
     "freshness_cap_bp": 4000,
     "min_track_n": 5,
     "wilson_z_milli": 1960,
     "source_present": true,
     "seller_asserted_cap_bp": 5000,
     "retracted": false,
     "contradicted": false,
     "outcome_trials": 0,
     "outcomes": {
      "verified": 0,
      "falsified": 0,
      "modified": 0,
      "counted": 0,
      "recorded": 0
     },
     "corroborations_counted": 0,
     "corroborations_discounted": 0,
     "reingest_ceiling_bp": null,
     "reingest_depth": null,
     "reingest_weakest_class": null,
     "reingest_source_confidence_bp": null,
     "ai_authored": true,
     "ai_authored_because": "a model, named as one in its own enrolled identity",
     "ai_in_lineage": false,
     "ai_position": null
    },
    "memory_reason_codes": [
     {
      "code": "SPARSE_TRACK_RECORD",
      "observed": 1,
      "limit": 5,
      "binding": false
     }
    ]
   }
  ],
  "serialization": {
   "algorithm": "RFC8785-JCS",
   "hash": "sha256"
  },
  "crypto_suite": {
   "spec": "corobate:suite:1",
   "id": "CB-1-ES256-SHA256",
   "receipt_digest": "sha256",
   "chain_digest": "sha256",
   "content_digest": "sha256",
   "envelope_signature": "ES256",
   "signature_curve": "P-256",
   "canonicalisation": "attest-canon/2",
   "quantum_resistant": false
  },
  "confidence": {
   "value": 0.95,
   "method": "min-over-critical-inputs",
   "bound_by": "ai-system:TRIAGE-ASSISTANT-V4::vulnerability_scan"
  },
  "verdict": {
   "value": "APPROVE",
   "threshold_approve": 0.9,
   "threshold_caution": 0.7,
   "rule": "confidence>=threshold"
  },
  "release": {
   "required": false,
   "required_by_tier": false,
   "escalated_by_acceptance": false,
   "risk_accepted": false,
   "state": "NOT_REQUIRED",
   "code": "QUORUM_NOT_REQUIRED",
   "reason": "this decision is below the top exposure tier (floor $10,000,000) and no risk acceptance escalated into this gate, so no multi-party release requirement applies.",
   "tier_floor_cents": 1000000000,
   "exposure_usd_cents": 140000000,
   "required_m": 2,
   "declared_n": 3,
   "floor_m": 2,
   "distinct_signers": 0,
   "superseded": 0,
   "collapsed": 0,
   "release_digest": "sha256:4ad3faa1a749da2c56339fa29e711571515a647ee4c4d9a29d41aa2251bff28a",
   "governance_digest": "sha256:8b0a45a27fcce9c1c243c764e855e67c6fe6dfd7f02a563bd90809b419731905",
   "governance_signed": true,
   "counted_voices": [],
   "signatures": [],
   "ledger_seq": null
  },
  "acceptance": {
   "state": "NONE",
   "code": "ACCEPTANCE_NONE",
   "reason": "no risk acceptance was presented for this decision. This is the ordinary case: a refusal is a refusal unless a named person has priced it.",
   "permitted_basis": null,
   "presented": 0,
   "superseded": 0,
   "expired": 0,
   "gaps_not_covered": 0,
   "coverage_gaps_in_force": [],
   "evidentiary_digest": "sha256:4ad3faa1a749da2c56339fa29e711571515a647ee4c4d9a29d41aa2251bff28a",
   "margin_floor_bp": 100,
   "authority_ceiling_cents": {
    "SUPERVISOR": 1000000,
    "MANAGER": 25000000,
    "DIRECTOR": 500000000,
    "OFFICER": 5000000000
   },
   "acceptances": [],
   "escalated": false,
   "live": false,
   "ledger_seq": null
  },
  "regulatory": {
   "spec": "corobate:regulatory:2",
   "resolved": true,
   "applied": [
    {
     "instrument_id": "nist-ai-rmf-1-0",
     "version": 1,
     "authority": "National Institute of Standards and Technology",
     "instrument": "AI Risk Management Framework 1.0",
     "edition": "1.0",
     "citation": "MEASURE-2.3, MEASURE-2.7, MANAGE-2.2 [VERIFY]",
     "source_digest": "sha256:a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1",
     "entered_by": "actor:human:issm",
     "entered_at": "2026-08-08T16:00:00.000Z"
    },
    {
     "instrument_id": "nist-sp-800-53r5-moderate",
     "version": 5,
     "authority": "National Institute of Standards and Technology",
     "instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
     "edition": "Rev. 5",
     "citation": "CA-2, CA-8, RA-5, SR-6 [VERIFY]",
     "source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353",
     "entered_by": "actor:human:issm",
     "entered_at": "2026-08-08T16:00:00.000Z"
    }
   ],
   "skipped": [],
   "conflicts": [],
   "bindings": [
    {
     "claim": "control_assessment",
     "requirement": "max_age_days",
     "value": 365,
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
      "instrument_id": "nist-sp-800-53r5-moderate",
      "version": 5,
      "edition": "Rev. 5",
      "citation": "CA-2 [VERIFY]",
      "source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "control_assessment",
     "requirement": "min_class",
     "value": "VERIFIED",
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
      "instrument_id": "nist-sp-800-53r5-moderate",
      "version": 5,
      "edition": "Rev. 5",
      "citation": "CA-2(1) independent assessors [VERIFY]",
      "source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "control_assessment",
     "requirement": "required",
     "value": true,
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
      "instrument_id": "nist-sp-800-53r5-moderate",
      "version": 5,
      "edition": "Rev. 5",
      "citation": "CA-2 [VERIFY]",
      "source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "incident_response_plan_test",
     "requirement": "required",
     "value": true,
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "AI Risk Management Framework 1.0",
      "instrument_id": "nist-ai-rmf-1-0",
      "version": 1,
      "edition": "1.0",
      "citation": "MANAGE-4.1 [VERIFY]",
      "source_digest": "sha256:a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "model_evaluation",
     "requirement": "max_age_days",
     "value": 180,
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "AI Risk Management Framework 1.0",
      "instrument_id": "nist-ai-rmf-1-0",
      "version": 1,
      "edition": "1.0",
      "citation": "MEASURE-2.3 [VERIFY]",
      "source_digest": "sha256:a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "model_evaluation",
     "requirement": "min_class",
     "value": "VERIFIED",
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "AI Risk Management Framework 1.0",
      "instrument_id": "nist-ai-rmf-1-0",
      "version": 1,
      "edition": "1.0",
      "citation": "MEASURE-2.3 independent evaluation [VERIFY]",
      "source_digest": "sha256:a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "model_evaluation",
     "requirement": "required",
     "value": true,
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "AI Risk Management Framework 1.0",
      "instrument_id": "nist-ai-rmf-1-0",
      "version": 1,
      "edition": "1.0",
      "citation": "MEASURE-2.3 [VERIFY]",
      "source_digest": "sha256:a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "penetration_test",
     "requirement": "min_class",
     "value": "VERIFIED",
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
      "instrument_id": "nist-sp-800-53r5-moderate",
      "version": 5,
      "edition": "Rev. 5",
      "citation": "CA-8(1) independent penetration agent [VERIFY]",
      "source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "penetration_test",
     "requirement": "required",
     "value": true,
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
      "instrument_id": "nist-sp-800-53r5-moderate",
      "version": 5,
      "edition": "Rev. 5",
      "citation": "CA-8 [VERIFY]",
      "source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "security_resilience_evaluation",
     "requirement": "required",
     "value": true,
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "AI Risk Management Framework 1.0",
      "instrument_id": "nist-ai-rmf-1-0",
      "version": 1,
      "edition": "1.0",
      "citation": "MEASURE-2.7 [VERIFY]",
      "source_digest": "sha256:a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "vulnerability_scan",
     "requirement": "max_age_days",
     "value": 30,
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
      "instrument_id": "nist-sp-800-53r5-moderate",
      "version": 5,
      "edition": "Rev. 5",
      "citation": "RA-5(a) [VERIFY]",
      "source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "vulnerability_scan",
     "requirement": "required",
     "value": true,
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
      "instrument_id": "nist-sp-800-53r5-moderate",
      "version": 5,
      "edition": "Rev. 5",
      "citation": "RA-5 [VERIFY]",
      "source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    }
   ],
   "defaults": [
    {
     "claim": "control_assessment",
     "requirement": "ai_position",
     "value": "ADMIT",
     "because": "No instrument in force stated a position on AI-authored evidence for \"control_assessment\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
    },
    {
     "claim": "incident_response_plan_test",
     "requirement": "ai_position",
     "value": "ADMIT",
     "because": "No instrument in force stated a position on AI-authored evidence for \"incident_response_plan_test\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
    },
    {
     "claim": "model_evaluation",
     "requirement": "ai_position",
     "value": "ADMIT",
     "because": "No instrument in force stated a position on AI-authored evidence for \"model_evaluation\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
    },
    {
     "claim": "penetration_test",
     "requirement": "ai_position",
     "value": "ADMIT",
     "because": "No instrument in force stated a position on AI-authored evidence for \"penetration_test\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
    },
    {
     "claim": "security_resilience_evaluation",
     "requirement": "ai_position",
     "value": "ADMIT",
     "because": "No instrument in force stated a position on AI-authored evidence for \"security_resilience_evaluation\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
    },
    {
     "claim": "vulnerability_scan",
     "requirement": "ai_position",
     "value": "ADMIT",
     "because": "No instrument in force stated a position on AI-authored evidence for \"vulnerability_scan\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
    }
   ]
  },
  "reasons": [
   "Confidence 95.00% is bound by \"ai-system:TRIAGE-ASSISTANT-V4|vulnerability_scan\".",
   "1 memory was withheld from the context block: ai-system:TRIAGE-ASSISTANT-V4|model_self_report (sparse track record: 1 independent observation(s); no failure recorded, so the class ceiling stands).",
   "Thresholds for $1,400,000 exposure: approve 90%, caution 70%."
  ],
  "memory": {
   "layer": "capture->store->recall->act",
   "ledger_head": "sha256:b883e583bf7eac8664664c008b4556f5e62ef70a681669c550a6d84ccad602fc",
   "ledger_entries": 9,
   "context_digest": "sha256:370424ce7a83527f262a9382eaada142e12978740525dbc7a71302faabc196b5",
   "context_memory_ids": [
    "mem_2c29e7fe028c",
    "mem_4d2b1fc0d322",
    "mem_7dfaefd014b0",
    "mem_a153eb336060",
    "mem_a3316d633bfe",
    "mem_a54dcc18c5ba"
   ],
   "state_digest": "sha256:d8c970114e57738a62465be9287d7045cd8966caeb801154d420321a11451dcc",
   "retrieval_method": "idf-lexical",
   "corpus_size": 7,
   "considered": 7,
   "admitted": 6,
   "withheld": 1,
   "not_considered": 0,
   "coverage_gaps": [],
   "exposure": {
    "usd": 1400000,
    "declared_by": "actor:human:ao-authorizing-official",
    "ledger_seq": 7
   },
   "salience_policy": {
    "half_life_days": 90,
    "grace_days": 7,
    "access_boost_bp": 500,
    "access_boost_cap_bp": 2500,
    "relevance_weight_bp": 6000,
    "recency_weight_bp": 3000,
    "usage_weight_bp": 1000,
    "context_cap": 12,
    "method": "idf-lexical",
    "candidate_list_digest": "sha256:eccb7e3ba1bd02c228774ef6908a72059c0e1ea29475f3d42946329f3a52cebe",
    "note": "salience orders retrieval only; it never contributes to reliability"
   },
   "policy_digest": "sha256:a6b69b7d20f7fb04d522364af1d92992058b04a5835fcec9d1c9f2261c7ef636",
   "policy_body": {
    "class_ceiling_bp": {
     "VERIFIED": 9500,
     "MODELED": 8000,
     "SELLER-ASSERTED": 5000,
     "MISSING": 0
    },
    "actor_class_ceiling": [
     [
      "^actor:ai:",
      "MODELED"
     ],
     [
      "^actor:agent:",
      "MODELED"
     ],
     [
      "^actor:human:",
      "SELLER-ASSERTED"
     ],
     [
      "^actor:org:LAB-",
      "VERIFIED"
     ],
     [
      "^actor:org:CERT-",
      "VERIFIED"
     ],
     [
      "^actor:org:",
      "SELLER-ASSERTED"
     ],
     [
      "^actor:sys:registry:",
      "VERIFIED"
     ],
     [
      "^actor:sys:sensor:",
      "VERIFIED"
     ],
     [
      "^actor:sys:",
      "MODELED"
     ]
    ],
    "freshness_cap_bp": 4000,
    "max_age_days": {
     "telemetry": 1,
     "price": 7,
     "status": 14,
     "certificate": 365,
     "test_report": 180,
     "filing": 90,
     "transcript": 120,
     "highlight": 365,
     "voice_note": 120,
     "note": 365,
     "preference": 540,
     "decision": 1825,
     "receipt": 365,
     "default": 90
    },
    "wilson_z_milli": 1960,
    "min_track_n": 5,
    "exposure_tiers_bp": [
     [
      1000000000,
      9500,
      8000
     ],
     [
      100000000,
      9000,
      7000
     ],
     [
      1000000,
      8500,
      6000
     ],
     [
      0,
      8000,
      5000
     ]
    ],
    "max_context_memories": 12,
    "contradiction_resolve_margin": 2,
    "salience": {
     "half_life_days": 90,
     "grace_days": 7,
     "access_boost_bp": 500,
     "access_boost_cap_bp": 2500,
     "relevance_weight_bp": 6000,
     "recency_weight_bp": 3000,
     "usage_weight_bp": 1000
    }
   },
   "observer_auth": {
    "mode": "required",
    "registry_version": 3,
    "registry_digest": "sha256:460aeaafe345f69542a302e6619dff0712af98de6518838ee4c8585e448c3a7d",
    "entries_root": "sha256:5670469f96484a814462814ed74f0f992b5f19e8ad6afced548e4956e4835ba5",
    "memberships": [
     {
      "key_id": "k_17d23885943ae529",
      "index": 1,
      "entry": {
       "actor": "actor:org:LAB-NVLAP-0412",
       "class": "VERIFIED",
       "kind": "org",
       "key_id": "k_17d23885943ae529",
       "jwk": {
        "kty": "EC",
        "crv": "P-256",
        "x": "3TTw47-PkYfo3ZaKTq_qtHghnGvninAVj25kyOwONno",
        "y": "16PMaR8ofeF5IcZk6ZLml8gDs8uE1s1sBLdciH5e4vg"
       },
       "valid_from": "2025-01-01T00:00:00.000Z",
       "valid_to": "2027-06-01T00:00:00.000Z"
      },
      "path": [
       {
        "side": "left",
        "sibling": "sha256:500f2ba5949d5256ae0f563530b0b270db41ce99d2d7c4b4b60e4bd558ca353d"
       },
       {
        "side": "right",
        "sibling": "sha256:a0b47ea437bf4f1042a1dd50a5a3f411f9a17971812fc6bafccd434eb7d78ccc"
       },
       {
        "side": "right",
        "sibling": "sha256:d3c2347eb675e865fc17ef0204cacda7b02e8784a811fdd1c8a015d1865e6dfb"
       },
       {
        "side": "right",
        "sibling": "sha256:7071adf5e21a94147d31f42f1028b4867b6562e5b78726259c2515b03b213e52"
       }
      ]
     },
     {
      "key_id": "k_307e4bfd710ec9b3",
      "index": 0,
      "entry": {
       "actor": "actor:org:CERT-3PAO-ATLANTIC",
       "class": "VERIFIED",
       "kind": "org",
       "key_id": "k_307e4bfd710ec9b3",
       "jwk": {
        "kty": "EC",
        "crv": "P-256",
        "x": "MGtV26TezLMPjiD3SecQtnje6eLqYyx4qkKzzAkbiY4",
        "y": "SMMdLYnn-FpKbb2sJQ8EAZnzvozNm-cGO0VbUUpniPY"
       },
       "valid_from": "2025-01-01T00:00:00.000Z",
       "valid_to": "2027-06-01T00:00:00.000Z"
      },
      "path": [
       {
        "side": "right",
        "sibling": "sha256:4148869fc259d2c5fc19fe5831065b165a9acf81812e123162035acfdecade1d"
       },
       {
        "side": "right",
        "sibling": "sha256:a0b47ea437bf4f1042a1dd50a5a3f411f9a17971812fc6bafccd434eb7d78ccc"
       },
       {
        "side": "right",
        "sibling": "sha256:d3c2347eb675e865fc17ef0204cacda7b02e8784a811fdd1c8a015d1865e6dfb"
       },
       {
        "side": "right",
        "sibling": "sha256:7071adf5e21a94147d31f42f1028b4867b6562e5b78726259c2515b03b213e52"
       }
      ]
     },
     {
      "key_id": "k_5873dd9e7169def3",
      "index": 2,
      "entry": {
       "actor": "actor:sys:registry:nvd-cve",
       "class": "VERIFIED",
       "kind": "system",
       "key_id": "k_5873dd9e7169def3",
       "jwk": {
        "kty": "EC",
        "crv": "P-256",
        "x": "O9OY6oMuJg0df_INePO19_3b11VaSyMwIPdxoqvV2ak",
        "y": "k7Orm5pxDxMdTF-H2S4h6ixRywzk1WxvquOQeqxLFx0"
       },
       "valid_from": "2025-01-01T00:00:00.000Z",
       "valid_to": "2027-06-01T00:00:00.000Z"
      },
      "path": [
       {
        "side": "right",
        "sibling": "sha256:e1fe36fe7c8e4695327c25d6d722630b6249c93293bfdc5894c58aaf961ab6f8"
       },
       {
        "side": "left",
        "sibling": "sha256:e8b9cba101f13538b909a2e686e9e6e9a8d77212036ed567eaebc205a443e83f"
       },
       {
        "side": "right",
        "sibling": "sha256:d3c2347eb675e865fc17ef0204cacda7b02e8784a811fdd1c8a015d1865e6dfb"
       },
       {
        "side": "right",
        "sibling": "sha256:7071adf5e21a94147d31f42f1028b4867b6562e5b78726259c2515b03b213e52"
       }
      ]
     },
     {
      "key_id": "k_db83368c3527dcb1",
      "index": 4,
      "entry": {
       "actor": "actor:org:LAB-REDTEAM-EVAL",
       "class": "VERIFIED",
       "kind": "org",
       "key_id": "k_db83368c3527dcb1",
       "jwk": {
        "kty": "EC",
        "crv": "P-256",
        "x": "1102q4E19agLvSGA6yK4u2zhpxY-jaQOP4wQ6NNh9Cg",
        "y": "XiDaanPqOwwYAYYIuZugw76jb_AiL13q7HKUphl1bog"
       },
       "valid_from": "2025-01-01T00:00:00.000Z",
       "valid_to": "2027-06-01T00:00:00.000Z"
      },
      "path": [
       {
        "side": "right",
        "sibling": "sha256:38e595fa3d2f2ead066b77b76ce900a756b59361a08b6a7bb044c626be3f062f"
       },
       {
        "side": "right",
        "sibling": "sha256:e579ab792dab36997cea2010753062ba6df4702a94d39085c307e749243ab70a"
       },
       {
        "side": "left",
        "sibling": "sha256:d3f1d60ec9478d2b69455e5ba8168897966d18429bd3b7d36105841cc2ae1776"
       },
       {
        "side": "right",
        "sibling": "sha256:7071adf5e21a94147d31f42f1028b4867b6562e5b78726259c2515b03b213e52"
       }
      ]
     }
    ],
    "memberships_unproven": [],
    "revocation": {
     "source": "SIGNED_LIST",
     "digest": "sha256:12f73b1fbf27d38cf137b86a1ce13bbcd98161123a6aa7d79b107db8189966b9",
     "sequence": 5,
     "registry_version": 3,
     "issued_at": "2026-08-06T00:00:00.000Z",
     "next_update_due": "2026-08-13T00:00:00.000Z",
     "entry_count": 0,
     "body": {
      "sequence": 5,
      "registry_version": 3,
      "issuer": {
       "name": "NIST-regulated enterprise demonstration trust root",
       "key_id": "k_3793b8e35f8acac1"
      },
      "issued_at": "2026-08-06T00:00:00.000Z",
      "next_update_due": "2026-08-13T00:00:00.000Z",
      "entries": [],
      "spec": "corobate:revocation-list:1"
     }
    }
   },
   "governance": {
    "digest": "sha256:8b0a45a27fcce9c1c243c764e855e67c6fe6dfd7f02a563bd90809b419731905",
    "signed": true,
    "actor_trust": "FLOOR_TO_SELLER_ASSERTED",
    "outcome_trial_weight": 1,
    "max_reingest_depth": 3,
    "release_quorum_m": 2,
    "release_quorum_n": 3,
    "risk_acceptance_margin_bp": 500,
    "risk_acceptance_max_days": 30,
    "risk_acceptance_authority_cents": {
     "SUPERVISOR": 1000000,
     "MANAGER": 25000000,
     "DIRECTOR": 500000000,
     "OFFICER": 5000000000
    },
    "template_author_roles": [
     "MANAGER",
     "DIRECTOR",
     "OFFICER"
    ]
   },
   "observers_attested": 6,
   "outcomes": {
    "attestations_counted": 0,
    "attestations_recorded": 0,
    "records_with_outcomes": 0
   },
   "lineage": {
    "corroborations_counted": 0,
    "corroborations_discounted": 0,
    "records_with_discounted_corroborations": 0
   },
   "reingest": {
    "records": 0,
    "max_depth": 0,
    "weakest_class": null,
    "chain_weakest_bp": 10000,
    "chain": []
   },
   "template": null
  }
 }
}

The enterprise standard ADMITS machine-generated evidence for this control. The assistant’s disposition of 412 scanner findings carries it — and carries it at MODELED, because admitting model output does not promote it. The verdict is CAUTION rather than APPROVE for exactly that reason: the position decides ADMISSIBILITY, the class table still decides how far the evidence reaches.

Subject
ai-system:TRIAGE-ASSISTANT-V4
Question
May this quarter's vulnerability triage be accepted as the record of review?
Exposure
$250,000
Instruments
Office of the Chief Information Security Officer · National Institute of Standards and Technology
Outcome
CAUTION — the action may proceed
Receipt
sha256:e6038d8525d391ca3b49b3b8135e9b479595df9200a54c9f68c7cbb286b87a34
The gate variables this decision ran under — a dial per question, read back off the sealed receipt
control assessmentrequired
necessity
requiredNational Institute of Standards and Technology — CA-2 [VERIFY]
staleness
365 daysNational Institute of Standards and Technology — CA-2 [VERIFY]
reputation class
verifiedNational Institute of Standards and Technology — CA-2(1) independent assessors [VERIFY]
reputation record
No reliability floor beyond the exposure tier's own threshold, which still binds.
completion
No satisfaction window was set. The requirement is due now: there is no period in which it may be outstanding, and nothing proceeds without it.
ai provenance
admitNo instrument in force stated a position on AI-authored evidence for "control_assessment". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway.
penetration testrequired
necessity
requiredNational Institute of Standards and Technology — CA-8 [VERIFY]
staleness
90 daysNo instrument set an age limit for this claim, so the deploying organisation's own freshness policy binds at 90 days. It is not unlimited.
reputation class
verifiedNational Institute of Standards and Technology — CA-8(1) independent penetration agent [VERIFY]
reputation record
No reliability floor beyond the exposure tier's own threshold, which still binds.
completion
No satisfaction window was set. The requirement is due now: there is no period in which it may be outstanding, and nothing proceeds without it.
ai provenance
admitNo instrument in force stated a position on AI-authored evidence for "penetration_test". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway.
vulnerability scanrequired
necessity
requiredNational Institute of Standards and Technology — RA-5 [VERIFY]
staleness
30 daysNational Institute of Standards and Technology — RA-5(a) [VERIFY]
reputation class
No class floor was set, so the seller's own assertion is admissible for this claim up to the ceiling that class carries. That is a setting, not an absence.
reputation record
No reliability floor beyond the exposure tier's own threshold, which still binds.
completion
No satisfaction window was set. The requirement is due now: there is no period in which it may be outstanding, and nothing proceeds without it.
ai provenance
admitNo instrument in force stated a position on AI-authored evidence for "vulnerability_scan". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway.
vulnerability triage dispositionrequired
necessity
requiredOffice of the Chief Information Security Officer — § 3.1 [VERIFY]
staleness
90 daysNo instrument set an age limit for this claim, so the deploying organisation's own freshness policy binds at 90 days. It is not unlimited.
reputation class
No class floor was set, so the seller's own assertion is admissible for this claim up to the ceiling that class carries. That is a setting, not an absence.
reputation record
No reliability floor beyond the exposure tier's own threshold, which still binds.
completion
No satisfaction window was set. The requirement is due now: there is no period in which it may be outstanding, and nothing proceeds without it.
ai provenance
admitOffice of the Chief Information Security Officer — § 3.4 [VERIFY]

Every bar above was re-derived from the regulatory bindings inside this receipt’s hashed body, not from the configuration that produced it. A bar in grey is a setting no instrument made — the deploying organisation’s own default, which still binds and is not an absence. A bar position renders an ordinal on a declared ladder: it is a way to draw a control and to compare two settings on the same axis, and it is not a measurement. The value printed beside each bar is the authoritative one.

Whoever must act now

The engineer with the deployment in their hands, the release manager, the person who must publish or hold.

One instruction and the reason in words. No score, no money, no signatures.

DO NOT PROCEED
ai-system:TRIAGE-ASSISTANT-V4
Everything required is on file and current.

Seven or eight fields, and not one of them is a number somebody can argue with. This person is not being asked to re-judge the evidence; somebody already did, and it is on the record.

The scoped copy itself — partial — something outside this role’s remit was removed
FAITHFUL digest sha256:1fe235515c5a224af813a3209419b79317940804ca62f64effc7c3b187c641e6 matches the commitment sealed in the receipt.
{
 "spec": "corobate:role-view:2",
 "role": "OPERATOR",
 "purpose": "Whoever must act on this decision now — release the goods, fund the draw, dispatch the agent, ship the title. Sees one instruction and the reason in plain words, and nothing that could be argued about while somebody waits.",
 "is_a_receipt": false,
 "warning": "This is a SCOPED COPY of a sealed decision, not the decision record itself. It will not verify as a receipt and must not be presented as one. To confirm it is faithful, recompute its `view` digest under the same canonicalisation that produces receipt_hash and compare it with the entry for this role in the source receipt’s `views` block.",
 "derived_from": {
  "receipt_hash": "sha256:e6038d8525d391ca3b49b3b8135e9b479595df9200a54c9f68c7cbb286b87a34",
  "entry_hash": "sha256:2c628fa4efbfe5c02c5978f8f777b7877876cc40f378291a8bf847cd5db64977",
  "issued_at": "2026-08-08T16:00:00.000Z"
 },
 "view_digest": "sha256:1fe235515c5a224af813a3209419b79317940804ca62f64effc7c3b187c641e6",
 "withheld": {
  "anything_withheld": true,
  "note": "Facts outside this role’s remit were removed. That something was removed is stated so a partial record is never mistaken for a complete one. How much, and what, is not stated — a count is an inference about the part you are not entitled to see."
 },
 "view": {
  "spec": "urn:ietf:params:corobate:receipt:1",
  "receipt_version": "1.8",
  "issued_at": "2026-08-08T16:00:00.000Z",
  "decision": {
   "id": "ai_TRIAGE_EVIDENCE_ADMIT",
   "subject": "ai-system:TRIAGE-ASSISTANT-V4"
  },
  "memory": {
   "state_digest": "sha256:9357ab4d994dcd108cd3f22257927b155d8e44f669c5c0bb8d3e9bfc6be9e52a",
   "ledger_head": "sha256:d11e8eaa639930292fb398123e6aeefff52b74a09d6448ad6f8e6c8e154ce39f",
   "coverage_gaps": []
  },
  "verdict": {
   "value": "CAUTION"
  },
  "release": {
   "state": "NOT_REQUIRED"
  }
 }
}

Provider / assessed party

The cloud service provider, the release team, or the party operating the AI system — whoever is being assessed.

Sees which controls were required of them and by which publication and control identifier. Does not see the authorising official’s exposure figure or how any shortfall was priced.

What is outstanding on your file

Nothing. Every required item is present and current.

ClaimRequiredEvidence classWhoAgeOutcome
vulnerability_triage_dispositionyesMODELED2026-08-05admitted
vulnerability_scanyesVERIFIED2026-08-04admitted
penetration_testyesVERIFIED2026-06-09admitted
control_assessmentyesVERIFIED2026-04-30admitted

The clause is here because it turns an argument into an errand. What is not here: what the bank had at stake, and whether anyone priced the shortfall.

The scoped copy itself — partial — something outside this role’s remit was removed
FAITHFUL digest sha256:5aac9db26c6938a9d95cac33ff8b8992b210c3b79b803c96941b08fb95ccdc67 matches the commitment sealed in the receipt.
{
 "spec": "corobate:role-view:2",
 "role": "SUPPLIER",
 "purpose": "The party whose evidence was judged. Sees every claim the decision required, which fell short, and the clause that required it — and nothing about what the buyer had at stake or how the buyer priced any shortfall. NOTE, because an earlier draft of this sentence was untrue: this projection carries the WHOLE inputs array, so where several parties supplied evidence for one decision, each of them sees all of it. Per-party scoping cannot be expressed by a commitment scheme with one digest per role, and claiming it anyway would be the kind of promise this file exists to stop making.",
 "is_a_receipt": false,
 "warning": "This is a SCOPED COPY of a sealed decision, not the decision record itself. It will not verify as a receipt and must not be presented as one. To confirm it is faithful, recompute its `view` digest under the same canonicalisation that produces receipt_hash and compare it with the entry for this role in the source receipt’s `views` block.",
 "derived_from": {
  "receipt_hash": "sha256:e6038d8525d391ca3b49b3b8135e9b479595df9200a54c9f68c7cbb286b87a34",
  "entry_hash": "sha256:2c628fa4efbfe5c02c5978f8f777b7877876cc40f378291a8bf847cd5db64977",
  "issued_at": "2026-08-08T16:00:00.000Z"
 },
 "view_digest": "sha256:5aac9db26c6938a9d95cac33ff8b8992b210c3b79b803c96941b08fb95ccdc67",
 "withheld": {
  "anything_withheld": true,
  "note": "Facts outside this role’s remit were removed. That something was removed is stated so a partial record is never mistaken for a complete one. How much, and what, is not stated — a count is an inference about the part you are not entitled to see."
 },
 "view": {
  "spec": "urn:ietf:params:corobate:receipt:1",
  "receipt_version": "1.8",
  "issued_at": "2026-08-08T16:00:00.000Z",
  "decision": {
   "id": "ai_TRIAGE_EVIDENCE_ADMIT",
   "subject": "ai-system:TRIAGE-ASSISTANT-V4",
   "question": "May this quarter's vulnerability triage be accepted as the record of review?"
  },
  "memory": {
   "state_digest": "sha256:9357ab4d994dcd108cd3f22257927b155d8e44f669c5c0bb8d3e9bfc6be9e52a",
   "ledger_head": "sha256:d11e8eaa639930292fb398123e6aeefff52b74a09d6448ad6f8e6c8e154ce39f",
   "coverage_gaps": []
  },
  "verdict": {
   "value": "CAUTION"
  },
  "inputs": [
   {
    "key": "ai-system:TRIAGE-ASSISTANT-V4::vulnerability_triage_disposition",
    "provenance": "MODELED",
    "observed_at": "2026-08-05T16:00:00.000Z",
    "memory_status": "admitted",
    "critical": true
   },
   {
    "key": "ai-system:TRIAGE-ASSISTANT-V4::vulnerability_scan",
    "provenance": "VERIFIED",
    "observed_at": "2026-08-04T16:00:00.000Z",
    "memory_status": "admitted",
    "critical": true
   },
   {
    "key": "ai-system:TRIAGE-ASSISTANT-V4::penetration_test",
    "provenance": "VERIFIED",
    "observed_at": "2026-06-09T16:00:00.000Z",
    "memory_status": "admitted",
    "critical": true
   },
   {
    "key": "ai-system:TRIAGE-ASSISTANT-V4::control_assessment",
    "provenance": "VERIFIED",
    "observed_at": "2026-04-30T16:00:00.000Z",
    "memory_status": "admitted",
    "critical": true
   }
  ],
  "regulatory": {
   "bindings": [
    {
     "claim": "control_assessment",
     "requirement": "max_age_days",
     "value": 365,
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
      "instrument_id": "nist-sp-800-53r5-moderate",
      "version": 5,
      "edition": "Rev. 5",
      "citation": "CA-2 [VERIFY]",
      "source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "control_assessment",
     "requirement": "min_class",
     "value": "VERIFIED",
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
      "instrument_id": "nist-sp-800-53r5-moderate",
      "version": 5,
      "edition": "Rev. 5",
      "citation": "CA-2(1) independent assessors [VERIFY]",
      "source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "control_assessment",
     "requirement": "required",
     "value": true,
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
      "instrument_id": "nist-sp-800-53r5-moderate",
      "version": 5,
      "edition": "Rev. 5",
      "citation": "CA-2 [VERIFY]",
      "source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "penetration_test",
     "requirement": "min_class",
     "value": "VERIFIED",
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
      "instrument_id": "nist-sp-800-53r5-moderate",
      "version": 5,
      "edition": "Rev. 5",
      "citation": "CA-8(1) independent penetration agent [VERIFY]",
      "source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "penetration_test",
     "requirement": "required",
     "value": true,
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
      "instrument_id": "nist-sp-800-53r5-moderate",
      "version": 5,
      "edition": "Rev. 5",
      "citation": "CA-8 [VERIFY]",
      "source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "vulnerability_scan",
     "requirement": "max_age_days",
     "value": 30,
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
      "instrument_id": "nist-sp-800-53r5-moderate",
      "version": 5,
      "edition": "Rev. 5",
      "citation": "RA-5(a) [VERIFY]",
      "source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "vulnerability_scan",
     "requirement": "required",
     "value": true,
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
      "instrument_id": "nist-sp-800-53r5-moderate",
      "version": 5,
      "edition": "Rev. 5",
      "citation": "RA-5 [VERIFY]",
      "source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "vulnerability_triage_disposition",
     "requirement": "ai_position",
     "value": "ADMIT",
     "bound_by": {
      "authority": "Office of the Chief Information Security Officer",
      "instrument": "Enterprise standard on machine-generated evidence",
      "instrument_id": "enterprise-ai-evidence-standard",
      "version": 1,
      "edition": "2026-03-01",
      "citation": "§ 3.4 [VERIFY]",
      "source_digest": "sha256:e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "vulnerability_triage_disposition",
     "requirement": "required",
     "value": true,
     "bound_by": {
      "authority": "Office of the Chief Information Security Officer",
      "instrument": "Enterprise standard on machine-generated evidence",
      "instrument_id": "enterprise-ai-evidence-standard",
      "version": 1,
      "edition": "2026-03-01",
      "citation": "§ 3.1 [VERIFY]",
      "source_digest": "sha256:e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    }
   ],
   "applied": [
    {
     "instrument_id": "enterprise-ai-evidence-standard",
     "version": 1,
     "authority": "Office of the Chief Information Security Officer",
     "instrument": "Enterprise standard on machine-generated evidence",
     "edition": "2026-03-01",
     "citation": "§ 3 [VERIFY]",
     "source_digest": "sha256:e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5",
     "entered_by": "actor:human:issm",
     "entered_at": "2026-08-08T16:00:00.000Z"
    },
    {
     "instrument_id": "nist-sp-800-53r5-moderate",
     "version": 5,
     "authority": "National Institute of Standards and Technology",
     "instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
     "edition": "Rev. 5",
     "citation": "CA-2, CA-8, RA-5, SR-6 [VERIFY]",
     "source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353",
     "entered_by": "actor:human:issm",
     "entered_at": "2026-08-08T16:00:00.000Z"
    }
   ],
   "defaults": [
    {
     "claim": "control_assessment",
     "requirement": "ai_position",
     "value": "ADMIT",
     "because": "No instrument in force stated a position on AI-authored evidence for \"control_assessment\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
    },
    {
     "claim": "penetration_test",
     "requirement": "ai_position",
     "value": "ADMIT",
     "because": "No instrument in force stated a position on AI-authored evidence for \"penetration_test\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
    },
    {
     "claim": "vulnerability_scan",
     "requirement": "ai_position",
     "value": "ADMIT",
     "because": "No instrument in force stated a position on AI-authored evidence for \"vulnerability_scan\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
    }
   ]
  }
 }
}

Assessor / authorising official

A third-party assessment organisation, an agency assessor, or an inspector general reviewing the package. Same position as a customs officer: a public mandate over the record.

The control record in full — each publication by control identifier, edition and document digest, and every required claim with who supplied it and when. No exposure figure, no risk pricing, no confidence score.

Office of the Chief Information Security Officer
Enterprise standard on machine-generated evidence
§ 3 [VERIFY] · edition 2026-03-01
document sha256:e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5
entered by actor:human:issm
National Institute of Standards and Technology
SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)
CA-2, CA-8, RA-5, SR-6 [VERIFY] · edition Rev. 5
document sha256:5353535353535353535353535353535353535353535353535353535353535353
entered by actor:human:issm

What each authority bound

ClaimRequirementLevelBound by
control_assessmentmax age days365National Institute of Standards and Technology
CA-2 [VERIFY] · SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)
control_assessmentmin classVERIFIEDNational Institute of Standards and Technology
CA-2(1) independent assessors [VERIFY] · SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)
control_assessmentrequiredtrueNational Institute of Standards and Technology
CA-2 [VERIFY] · SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)
penetration_testmin classVERIFIEDNational Institute of Standards and Technology
CA-8(1) independent penetration agent [VERIFY] · SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)
penetration_testrequiredtrueNational Institute of Standards and Technology
CA-8 [VERIFY] · SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)
vulnerability_scanmax age days30National Institute of Standards and Technology
RA-5(a) [VERIFY] · SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)
vulnerability_scanrequiredtrueNational Institute of Standards and Technology
RA-5 [VERIFY] · SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)
vulnerability_triage_dispositionai positionADMITOffice of the Chief Information Security Officer
§ 3.4 [VERIFY] · Enterprise standard on machine-generated evidence
vulnerability_triage_dispositionrequiredtrueOffice of the Chief Information Security Officer
§ 3.1 [VERIFY] · Enterprise standard on machine-generated evidence

Every required claim, and what was actually held

ClaimRequiredEvidence classWhoAgeOutcome
vulnerability_triage_dispositionyesMODELEDactor:ai:triage-assistant-v42026-08-05admitted
vulnerability_scanyesVERIFIEDactor:sys:registry:nvd-cve2026-08-04admitted
penetration_testyesVERIFIEDactor:org:LAB-NVLAP-04122026-06-09admitted
control_assessmentyesVERIFIEDactor:org:CERT-3PAO-ATLANTIC2026-04-30admitted
Absent from this copy, deliberatelyNo exposure figure, no risk pricing, no confidence score, no release quorum. The examiner’s claim is on the record of what was required and what was held — answered here completely, down to the digest of the document each requirement was configured from. The institution’s commercial position is a different question and this document does not answer it. The published verifier checks that on the content of the copy, not on the intentions of whoever produced it.
The scoped copy itself — partial — something outside this role’s remit was removed
FAITHFUL digest sha256:9a4b8a4d1b9701b338aad746af3048c54cc711b555325c27799cae64707a8873 matches the commitment sealed in the receipt.
{
 "spec": "corobate:role-view:2",
 "role": "REGULATOR",
 "purpose": "An official holding a public mandate over this record — a customs officer, a bank examiner, a market conduct supervisor. Sees the regulatory record in full: their own instrument named, every required claim and whether it was met, by whom, how old. No commercial figure of any kind.",
 "is_a_receipt": false,
 "warning": "This is a SCOPED COPY of a sealed decision, not the decision record itself. It will not verify as a receipt and must not be presented as one. To confirm it is faithful, recompute its `view` digest under the same canonicalisation that produces receipt_hash and compare it with the entry for this role in the source receipt’s `views` block.",
 "derived_from": {
  "receipt_hash": "sha256:e6038d8525d391ca3b49b3b8135e9b479595df9200a54c9f68c7cbb286b87a34",
  "entry_hash": "sha256:2c628fa4efbfe5c02c5978f8f777b7877876cc40f378291a8bf847cd5db64977",
  "issued_at": "2026-08-08T16:00:00.000Z"
 },
 "view_digest": "sha256:9a4b8a4d1b9701b338aad746af3048c54cc711b555325c27799cae64707a8873",
 "withheld": {
  "anything_withheld": true,
  "note": "Facts outside this role’s remit were removed. That something was removed is stated so a partial record is never mistaken for a complete one. How much, and what, is not stated — a count is an inference about the part you are not entitled to see."
 },
 "view": {
  "spec": "urn:ietf:params:corobate:receipt:1",
  "receipt_version": "1.8",
  "issued_at": "2026-08-08T16:00:00.000Z",
  "decision": {
   "id": "ai_TRIAGE_EVIDENCE_ADMIT",
   "subject": "ai-system:TRIAGE-ASSISTANT-V4",
   "question": "May this quarter's vulnerability triage be accepted as the record of review?"
  },
  "memory": {
   "state_digest": "sha256:9357ab4d994dcd108cd3f22257927b155d8e44f669c5c0bb8d3e9bfc6be9e52a",
   "ledger_head": "sha256:d11e8eaa639930292fb398123e6aeefff52b74a09d6448ad6f8e6c8e154ce39f",
   "coverage_gaps": []
  },
  "data_horizon": "2026-08-08T16:00:00.000Z",
  "verdict": {
   "value": "CAUTION"
  },
  "regulatory": {
   "spec": "corobate:regulatory:2",
   "resolved": true,
   "applied": [
    {
     "instrument_id": "enterprise-ai-evidence-standard",
     "version": 1,
     "authority": "Office of the Chief Information Security Officer",
     "instrument": "Enterprise standard on machine-generated evidence",
     "edition": "2026-03-01",
     "citation": "§ 3 [VERIFY]",
     "source_digest": "sha256:e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5",
     "entered_by": "actor:human:issm",
     "entered_at": "2026-08-08T16:00:00.000Z"
    },
    {
     "instrument_id": "nist-sp-800-53r5-moderate",
     "version": 5,
     "authority": "National Institute of Standards and Technology",
     "instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
     "edition": "Rev. 5",
     "citation": "CA-2, CA-8, RA-5, SR-6 [VERIFY]",
     "source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353",
     "entered_by": "actor:human:issm",
     "entered_at": "2026-08-08T16:00:00.000Z"
    }
   ],
   "skipped": [],
   "conflicts": [],
   "bindings": [
    {
     "claim": "control_assessment",
     "requirement": "max_age_days",
     "value": 365,
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
      "instrument_id": "nist-sp-800-53r5-moderate",
      "version": 5,
      "edition": "Rev. 5",
      "citation": "CA-2 [VERIFY]",
      "source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "control_assessment",
     "requirement": "min_class",
     "value": "VERIFIED",
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
      "instrument_id": "nist-sp-800-53r5-moderate",
      "version": 5,
      "edition": "Rev. 5",
      "citation": "CA-2(1) independent assessors [VERIFY]",
      "source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "control_assessment",
     "requirement": "required",
     "value": true,
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
      "instrument_id": "nist-sp-800-53r5-moderate",
      "version": 5,
      "edition": "Rev. 5",
      "citation": "CA-2 [VERIFY]",
      "source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "penetration_test",
     "requirement": "min_class",
     "value": "VERIFIED",
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
      "instrument_id": "nist-sp-800-53r5-moderate",
      "version": 5,
      "edition": "Rev. 5",
      "citation": "CA-8(1) independent penetration agent [VERIFY]",
      "source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "penetration_test",
     "requirement": "required",
     "value": true,
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
      "instrument_id": "nist-sp-800-53r5-moderate",
      "version": 5,
      "edition": "Rev. 5",
      "citation": "CA-8 [VERIFY]",
      "source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "vulnerability_scan",
     "requirement": "max_age_days",
     "value": 30,
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
      "instrument_id": "nist-sp-800-53r5-moderate",
      "version": 5,
      "edition": "Rev. 5",
      "citation": "RA-5(a) [VERIFY]",
      "source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "vulnerability_scan",
     "requirement": "required",
     "value": true,
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
      "instrument_id": "nist-sp-800-53r5-moderate",
      "version": 5,
      "edition": "Rev. 5",
      "citation": "RA-5 [VERIFY]",
      "source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "vulnerability_triage_disposition",
     "requirement": "ai_position",
     "value": "ADMIT",
     "bound_by": {
      "authority": "Office of the Chief Information Security Officer",
      "instrument": "Enterprise standard on machine-generated evidence",
      "instrument_id": "enterprise-ai-evidence-standard",
      "version": 1,
      "edition": "2026-03-01",
      "citation": "§ 3.4 [VERIFY]",
      "source_digest": "sha256:e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "vulnerability_triage_disposition",
     "requirement": "required",
     "value": true,
     "bound_by": {
      "authority": "Office of the Chief Information Security Officer",
      "instrument": "Enterprise standard on machine-generated evidence",
      "instrument_id": "enterprise-ai-evidence-standard",
      "version": 1,
      "edition": "2026-03-01",
      "citation": "§ 3.1 [VERIFY]",
      "source_digest": "sha256:e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    }
   ],
   "defaults": [
    {
     "claim": "control_assessment",
     "requirement": "ai_position",
     "value": "ADMIT",
     "because": "No instrument in force stated a position on AI-authored evidence for \"control_assessment\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
    },
    {
     "claim": "penetration_test",
     "requirement": "ai_position",
     "value": "ADMIT",
     "because": "No instrument in force stated a position on AI-authored evidence for \"penetration_test\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
    },
    {
     "claim": "vulnerability_scan",
     "requirement": "ai_position",
     "value": "ADMIT",
     "because": "No instrument in force stated a position on AI-authored evidence for \"vulnerability_scan\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
    }
   ]
  },
  "inputs": [
   {
    "key": "ai-system:TRIAGE-ASSISTANT-V4::vulnerability_triage_disposition",
    "provenance": "MODELED",
    "source": "triage-assistant-v4:vulnerability_triage_disposition",
    "observed_at": "2026-08-05T16:00:00.000Z",
    "critical": true,
    "memory_status": "admitted",
    "memory_actor": "actor:ai:triage-assistant-v4"
   },
   {
    "key": "ai-system:TRIAGE-ASSISTANT-V4::vulnerability_scan",
    "provenance": "VERIFIED",
    "source": "nvd-cve:vulnerability_scan",
    "observed_at": "2026-08-04T16:00:00.000Z",
    "critical": true,
    "memory_status": "admitted",
    "memory_actor": "actor:sys:registry:nvd-cve"
   },
   {
    "key": "ai-system:TRIAGE-ASSISTANT-V4::penetration_test",
    "provenance": "VERIFIED",
    "source": "LAB-NVLAP-0412:penetration_test",
    "observed_at": "2026-06-09T16:00:00.000Z",
    "critical": true,
    "memory_status": "admitted",
    "memory_actor": "actor:org:LAB-NVLAP-0412"
   },
   {
    "key": "ai-system:TRIAGE-ASSISTANT-V4::control_assessment",
    "provenance": "VERIFIED",
    "source": "CERT-3PAO-ATLANTIC:control_assessment",
    "observed_at": "2026-04-30T16:00:00.000Z",
    "critical": true,
    "memory_status": "admitted",
    "memory_actor": "actor:org:CERT-3PAO-ATLANTIC"
   }
  ],
  "crypto_suite": {
   "spec": "corobate:suite:1",
   "id": "CB-1-ES256-SHA256",
   "receipt_digest": "sha256",
   "chain_digest": "sha256",
   "content_digest": "sha256",
   "envelope_signature": "ES256",
   "signature_curve": "P-256",
   "canonicalisation": "attest-canon/2",
   "quantum_resistant": false
  }
 }
}

ISSM / control owner

The information system security manager and the control owners who hold the package.

The fullest internal view: every input, its class, its age, its score, the exposure, and every publication in force.

VerdictCAUTION
Confidence80%
bound by vulnerability_triage_disposition
Exposure$250,000
ReleaseNOT_REQUIRED
Risk acceptedNONE

Every input the gate saw

ClaimRequiredEvidence classWhoAgeScoreOutcome
vulnerability_triage_dispositionyesMODELEDactor:ai:triage-assistant-v43d80%admitted
vulnerability_scanyesVERIFIEDactor:sys:registry:nvd-cve4d95%admitted
penetration_testyesVERIFIEDactor:org:LAB-NVLAP-041260d95%admitted
control_assessmentyesVERIFIEDactor:org:CERT-3PAO-ATLANTIC100d95%admitted

Instruments in force

Office of the Chief Information Security Officer
Enterprise standard on machine-generated evidence
§ 3 [VERIFY] · edition 2026-03-01
document sha256:e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5
entered by actor:human:issm
National Institute of Standards and Technology
SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)
CA-2, CA-8, RA-5, SR-6 [VERIFY] · edition Rev. 5
document sha256:5353535353535353535353535353535353535353535353535353535353535353
entered by actor:human:issm

Why

  • Confidence 80.00% is bound by "ai-system:TRIAGE-ASSISTANT-V4|vulnerability_triage_disposition".
  • Thresholds for $250,000 exposure: approve 85%, caution 60%.
The scoped copy itself — partial — something outside this role’s remit was removed
FAITHFUL digest sha256:1c6958e7227b3b16a5c1056014c13a84c196169fea5293816b8931f006eab289 matches the commitment sealed in the receipt.
{
 "spec": "corobate:role-view:2",
 "role": "COMPLIANCE",
 "purpose": "The operator’s own compliance function. The fullest internal view: every gap, every instrument in force, the waivability of each requirement and who accepted what.",
 "is_a_receipt": false,
 "warning": "This is a SCOPED COPY of a sealed decision, not the decision record itself. It will not verify as a receipt and must not be presented as one. To confirm it is faithful, recompute its `view` digest under the same canonicalisation that produces receipt_hash and compare it with the entry for this role in the source receipt’s `views` block.",
 "derived_from": {
  "receipt_hash": "sha256:e6038d8525d391ca3b49b3b8135e9b479595df9200a54c9f68c7cbb286b87a34",
  "entry_hash": "sha256:2c628fa4efbfe5c02c5978f8f777b7877876cc40f378291a8bf847cd5db64977",
  "issued_at": "2026-08-08T16:00:00.000Z"
 },
 "view_digest": "sha256:1c6958e7227b3b16a5c1056014c13a84c196169fea5293816b8931f006eab289",
 "withheld": {
  "anything_withheld": true,
  "note": "Facts outside this role’s remit were removed. That something was removed is stated so a partial record is never mistaken for a complete one. How much, and what, is not stated — a count is an inference about the part you are not entitled to see."
 },
 "view": {
  "spec": "urn:ietf:params:corobate:receipt:1",
  "receipt_version": "1.8",
  "issued_at": "2026-08-08T16:00:00.000Z",
  "decision": {
   "id": "ai_TRIAGE_EVIDENCE_ADMIT",
   "domain": "supply-chain",
   "subject": "ai-system:TRIAGE-ASSISTANT-V4",
   "question": "May this quarter's vulnerability triage be accepted as the record of review?"
  },
  "memory": {
   "state_digest": "sha256:9357ab4d994dcd108cd3f22257927b155d8e44f669c5c0bb8d3e9bfc6be9e52a",
   "ledger_head": "sha256:d11e8eaa639930292fb398123e6aeefff52b74a09d6448ad6f8e6c8e154ce39f",
   "coverage_gaps": [],
   "exposure": {
    "usd": 250000,
    "declared_by": "actor:human:issm",
    "ledger_seq": 4
   },
   "policy_digest": "sha256:a6b69b7d20f7fb04d522364af1d92992058b04a5835fcec9d1c9f2261c7ef636"
  },
  "data_horizon": "2026-08-08T16:00:00.000Z",
  "verdict": {
   "value": "CAUTION",
   "threshold_approve": 0.85,
   "threshold_caution": 0.6,
   "rule": "confidence>=threshold"
  },
  "confidence": {
   "value": 0.8,
   "method": "min-over-critical-inputs",
   "bound_by": "ai-system:TRIAGE-ASSISTANT-V4::vulnerability_triage_disposition"
  },
  "release": {
   "required": false,
   "required_by_tier": false,
   "escalated_by_acceptance": false,
   "risk_accepted": false,
   "state": "NOT_REQUIRED",
   "code": "QUORUM_NOT_REQUIRED",
   "reason": "this decision is below the top exposure tier (floor $10,000,000) and no risk acceptance escalated into this gate, so no multi-party release requirement applies.",
   "tier_floor_cents": 1000000000,
   "exposure_usd_cents": 25000000,
   "required_m": 2,
   "declared_n": 3,
   "floor_m": 2,
   "distinct_signers": 0,
   "superseded": 0,
   "collapsed": 0,
   "release_digest": "sha256:3174d524ab5881c0caf1099f0c0265966e5b12c85c71c87fc8f9af138736ff5c",
   "governance_digest": "sha256:8b0a45a27fcce9c1c243c764e855e67c6fe6dfd7f02a563bd90809b419731905",
   "governance_signed": true,
   "counted_voices": [],
   "signatures": [],
   "ledger_seq": null
  },
  "acceptance": {
   "state": "NONE",
   "code": "ACCEPTANCE_NONE",
   "reason": "no risk acceptance was presented for this decision. This is the ordinary case: a refusal is a refusal unless a named person has priced it.",
   "permitted_basis": null,
   "presented": 0,
   "superseded": 0,
   "expired": 0,
   "gaps_not_covered": 0,
   "coverage_gaps_in_force": [],
   "evidentiary_digest": "sha256:3174d524ab5881c0caf1099f0c0265966e5b12c85c71c87fc8f9af138736ff5c",
   "margin_floor_bp": 100,
   "authority_ceiling_cents": {
    "SUPERVISOR": 1000000,
    "MANAGER": 25000000,
    "DIRECTOR": 500000000,
    "OFFICER": 5000000000
   },
   "acceptances": [],
   "escalated": false,
   "live": false,
   "ledger_seq": null
  },
  "regulatory": {
   "spec": "corobate:regulatory:2",
   "resolved": true,
   "applied": [
    {
     "instrument_id": "enterprise-ai-evidence-standard",
     "version": 1,
     "authority": "Office of the Chief Information Security Officer",
     "instrument": "Enterprise standard on machine-generated evidence",
     "edition": "2026-03-01",
     "citation": "§ 3 [VERIFY]",
     "source_digest": "sha256:e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5",
     "entered_by": "actor:human:issm",
     "entered_at": "2026-08-08T16:00:00.000Z"
    },
    {
     "instrument_id": "nist-sp-800-53r5-moderate",
     "version": 5,
     "authority": "National Institute of Standards and Technology",
     "instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
     "edition": "Rev. 5",
     "citation": "CA-2, CA-8, RA-5, SR-6 [VERIFY]",
     "source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353",
     "entered_by": "actor:human:issm",
     "entered_at": "2026-08-08T16:00:00.000Z"
    }
   ],
   "skipped": [],
   "conflicts": [],
   "bindings": [
    {
     "claim": "control_assessment",
     "requirement": "max_age_days",
     "value": 365,
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
      "instrument_id": "nist-sp-800-53r5-moderate",
      "version": 5,
      "edition": "Rev. 5",
      "citation": "CA-2 [VERIFY]",
      "source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "control_assessment",
     "requirement": "min_class",
     "value": "VERIFIED",
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
      "instrument_id": "nist-sp-800-53r5-moderate",
      "version": 5,
      "edition": "Rev. 5",
      "citation": "CA-2(1) independent assessors [VERIFY]",
      "source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "control_assessment",
     "requirement": "required",
     "value": true,
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
      "instrument_id": "nist-sp-800-53r5-moderate",
      "version": 5,
      "edition": "Rev. 5",
      "citation": "CA-2 [VERIFY]",
      "source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "penetration_test",
     "requirement": "min_class",
     "value": "VERIFIED",
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
      "instrument_id": "nist-sp-800-53r5-moderate",
      "version": 5,
      "edition": "Rev. 5",
      "citation": "CA-8(1) independent penetration agent [VERIFY]",
      "source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "penetration_test",
     "requirement": "required",
     "value": true,
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
      "instrument_id": "nist-sp-800-53r5-moderate",
      "version": 5,
      "edition": "Rev. 5",
      "citation": "CA-8 [VERIFY]",
      "source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "vulnerability_scan",
     "requirement": "max_age_days",
     "value": 30,
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
      "instrument_id": "nist-sp-800-53r5-moderate",
      "version": 5,
      "edition": "Rev. 5",
      "citation": "RA-5(a) [VERIFY]",
      "source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "vulnerability_scan",
     "requirement": "required",
     "value": true,
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
      "instrument_id": "nist-sp-800-53r5-moderate",
      "version": 5,
      "edition": "Rev. 5",
      "citation": "RA-5 [VERIFY]",
      "source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "vulnerability_triage_disposition",
     "requirement": "ai_position",
     "value": "ADMIT",
     "bound_by": {
      "authority": "Office of the Chief Information Security Officer",
      "instrument": "Enterprise standard on machine-generated evidence",
      "instrument_id": "enterprise-ai-evidence-standard",
      "version": 1,
      "edition": "2026-03-01",
      "citation": "§ 3.4 [VERIFY]",
      "source_digest": "sha256:e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "vulnerability_triage_disposition",
     "requirement": "required",
     "value": true,
     "bound_by": {
      "authority": "Office of the Chief Information Security Officer",
      "instrument": "Enterprise standard on machine-generated evidence",
      "instrument_id": "enterprise-ai-evidence-standard",
      "version": 1,
      "edition": "2026-03-01",
      "citation": "§ 3.1 [VERIFY]",
      "source_digest": "sha256:e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    }
   ],
   "defaults": [
    {
     "claim": "control_assessment",
     "requirement": "ai_position",
     "value": "ADMIT",
     "because": "No instrument in force stated a position on AI-authored evidence for \"control_assessment\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
    },
    {
     "claim": "penetration_test",
     "requirement": "ai_position",
     "value": "ADMIT",
     "because": "No instrument in force stated a position on AI-authored evidence for \"penetration_test\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
    },
    {
     "claim": "vulnerability_scan",
     "requirement": "ai_position",
     "value": "ADMIT",
     "because": "No instrument in force stated a position on AI-authored evidence for \"vulnerability_scan\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
    }
   ]
  },
  "reasons": [
   "Confidence 80.00% is bound by \"ai-system:TRIAGE-ASSISTANT-V4|vulnerability_triage_disposition\".",
   "Thresholds for $250,000 exposure: approve 85%, caution 60%."
  ],
  "inputs": [
   {
    "key": "ai-system:TRIAGE-ASSISTANT-V4::vulnerability_triage_disposition",
    "value": "412-triaged",
    "provenance": "MODELED",
    "source": "triage-assistant-v4:vulnerability_triage_disposition",
    "observed_at": "2026-08-05T16:00:00.000Z",
    "reliability": 0.8,
    "critical": true,
    "memory_status": "admitted",
    "memory_kind": "status",
    "memory_actor": "actor:ai:triage-assistant-v4",
    "memory_age_days": 3
   },
   {
    "key": "ai-system:TRIAGE-ASSISTANT-V4::vulnerability_scan",
    "value": "clean-at-scan",
    "provenance": "VERIFIED",
    "source": "nvd-cve:vulnerability_scan",
    "observed_at": "2026-08-04T16:00:00.000Z",
    "reliability": 0.95,
    "critical": true,
    "memory_status": "admitted",
    "memory_kind": "status",
    "memory_actor": "actor:sys:registry:nvd-cve",
    "memory_age_days": 4
   },
   {
    "key": "ai-system:TRIAGE-ASSISTANT-V4::penetration_test",
    "value": "no-critical",
    "provenance": "VERIFIED",
    "source": "LAB-NVLAP-0412:penetration_test",
    "observed_at": "2026-06-09T16:00:00.000Z",
    "reliability": 0.95,
    "critical": true,
    "memory_status": "admitted",
    "memory_kind": "test_report",
    "memory_actor": "actor:org:LAB-NVLAP-0412",
    "memory_age_days": 60
   },
   {
    "key": "ai-system:TRIAGE-ASSISTANT-V4::control_assessment",
    "value": "satisfied",
    "provenance": "VERIFIED",
    "source": "CERT-3PAO-ATLANTIC:control_assessment",
    "observed_at": "2026-04-30T16:00:00.000Z",
    "reliability": 0.95,
    "critical": true,
    "memory_status": "admitted",
    "memory_kind": "certificate",
    "memory_actor": "actor:org:CERT-3PAO-ATLANTIC",
    "memory_age_days": 100
   }
  ],
  "crypto_suite": {
   "spec": "corobate:suite:1",
   "id": "CB-1-ES256-SHA256",
   "receipt_digest": "sha256",
   "chain_digest": "sha256",
   "content_digest": "sha256",
   "envelope_signature": "ES256",
   "signature_curve": "P-256",
   "canonicalisation": "attest-canon/2",
   "quantum_resistant": false
  }
 }
}

Authorising official (signer)

The named official whose signature carries the authorisation decision.

What is at stake, what the evidence supports, what is missing, and the digest they are signing over.

You are being asked to sign

May this quarter's vulnerability triage be accepted as the record of review?

At stake$250,000
Evidence saysCAUTION
Release stateNOT_REQUIRED
signing over evidentiary digest sha256:3174d524ab5881c0caf1099f0c0265966e5b12c85c71c87fc8f9af138736ff5c

The signature is over the STATE OF THE EVIDENCE. Move one fact behind this decision and the digest moves and the signature stops counting — which is what makes it safe to collect signatures before everyone is in the room.

What is missing

  • Nothing required is missing.
The scoped copy itself — partial — something outside this role’s remit was removed
FAITHFUL digest sha256:1ebccbd14a774d07a3c0c503c1892adb2f3a95bfe13924e6787f116c6d079329 matches the commitment sealed in the receipt.
{
 "spec": "corobate:role-view:2",
 "role": "EXECUTIVE",
 "purpose": "A named signer on the release gate. Sees what is at stake, what the evidence supports, who else has signed and what they are being asked to sign over.",
 "is_a_receipt": false,
 "warning": "This is a SCOPED COPY of a sealed decision, not the decision record itself. It will not verify as a receipt and must not be presented as one. To confirm it is faithful, recompute its `view` digest under the same canonicalisation that produces receipt_hash and compare it with the entry for this role in the source receipt’s `views` block.",
 "derived_from": {
  "receipt_hash": "sha256:e6038d8525d391ca3b49b3b8135e9b479595df9200a54c9f68c7cbb286b87a34",
  "entry_hash": "sha256:2c628fa4efbfe5c02c5978f8f777b7877876cc40f378291a8bf847cd5db64977",
  "issued_at": "2026-08-08T16:00:00.000Z"
 },
 "view_digest": "sha256:1ebccbd14a774d07a3c0c503c1892adb2f3a95bfe13924e6787f116c6d079329",
 "withheld": {
  "anything_withheld": true,
  "note": "Facts outside this role’s remit were removed. That something was removed is stated so a partial record is never mistaken for a complete one. How much, and what, is not stated — a count is an inference about the part you are not entitled to see."
 },
 "view": {
  "spec": "urn:ietf:params:corobate:receipt:1",
  "receipt_version": "1.8",
  "issued_at": "2026-08-08T16:00:00.000Z",
  "decision": {
   "id": "ai_TRIAGE_EVIDENCE_ADMIT",
   "domain": "supply-chain",
   "subject": "ai-system:TRIAGE-ASSISTANT-V4",
   "question": "May this quarter's vulnerability triage be accepted as the record of review?"
  },
  "memory": {
   "state_digest": "sha256:9357ab4d994dcd108cd3f22257927b155d8e44f669c5c0bb8d3e9bfc6be9e52a",
   "ledger_head": "sha256:d11e8eaa639930292fb398123e6aeefff52b74a09d6448ad6f8e6c8e154ce39f",
   "coverage_gaps": [],
   "exposure": {
    "usd": 250000,
    "declared_by": "actor:human:issm",
    "ledger_seq": 4
   }
  },
  "verdict": {
   "value": "CAUTION",
   "threshold_approve": 0.85,
   "threshold_caution": 0.6,
   "rule": "confidence>=threshold"
  },
  "confidence": {
   "value": 0.8,
   "method": "min-over-critical-inputs",
   "bound_by": "ai-system:TRIAGE-ASSISTANT-V4::vulnerability_triage_disposition"
  },
  "release": {
   "required": false,
   "required_by_tier": false,
   "escalated_by_acceptance": false,
   "risk_accepted": false,
   "state": "NOT_REQUIRED",
   "code": "QUORUM_NOT_REQUIRED",
   "reason": "this decision is below the top exposure tier (floor $10,000,000) and no risk acceptance escalated into this gate, so no multi-party release requirement applies.",
   "tier_floor_cents": 1000000000,
   "exposure_usd_cents": 25000000,
   "required_m": 2,
   "declared_n": 3,
   "floor_m": 2,
   "distinct_signers": 0,
   "superseded": 0,
   "collapsed": 0,
   "release_digest": "sha256:3174d524ab5881c0caf1099f0c0265966e5b12c85c71c87fc8f9af138736ff5c",
   "governance_digest": "sha256:8b0a45a27fcce9c1c243c764e855e67c6fe6dfd7f02a563bd90809b419731905",
   "governance_signed": true,
   "counted_voices": [],
   "signatures": [],
   "ledger_seq": null
  },
  "acceptance": {
   "state": "NONE",
   "code": "ACCEPTANCE_NONE",
   "reason": "no risk acceptance was presented for this decision. This is the ordinary case: a refusal is a refusal unless a named person has priced it.",
   "permitted_basis": null,
   "presented": 0,
   "superseded": 0,
   "expired": 0,
   "gaps_not_covered": 0,
   "coverage_gaps_in_force": [],
   "evidentiary_digest": "sha256:3174d524ab5881c0caf1099f0c0265966e5b12c85c71c87fc8f9af138736ff5c",
   "margin_floor_bp": 100,
   "authority_ceiling_cents": {
    "SUPERVISOR": 1000000,
    "MANAGER": 25000000,
    "DIRECTOR": 500000000,
    "OFFICER": 5000000000
   },
   "acceptances": [],
   "escalated": false,
   "live": false,
   "ledger_seq": null
  },
  "reasons": [
   "Confidence 80.00% is bound by \"ai-system:TRIAGE-ASSISTANT-V4|vulnerability_triage_disposition\".",
   "Thresholds for $250,000 exposure: approve 85%, caution 60%."
  ],
  "regulatory": {
   "applied": [
    {
     "instrument_id": "enterprise-ai-evidence-standard",
     "version": 1,
     "authority": "Office of the Chief Information Security Officer",
     "instrument": "Enterprise standard on machine-generated evidence",
     "edition": "2026-03-01",
     "citation": "§ 3 [VERIFY]",
     "source_digest": "sha256:e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5",
     "entered_by": "actor:human:issm",
     "entered_at": "2026-08-08T16:00:00.000Z"
    },
    {
     "instrument_id": "nist-sp-800-53r5-moderate",
     "version": 5,
     "authority": "National Institute of Standards and Technology",
     "instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
     "edition": "Rev. 5",
     "citation": "CA-2, CA-8, RA-5, SR-6 [VERIFY]",
     "source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353",
     "entered_by": "actor:human:issm",
     "entered_at": "2026-08-08T16:00:00.000Z"
    }
   ],
   "conflicts": [],
   "defaults": [
    {
     "claim": "control_assessment",
     "requirement": "ai_position",
     "value": "ADMIT",
     "because": "No instrument in force stated a position on AI-authored evidence for \"control_assessment\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
    },
    {
     "claim": "penetration_test",
     "requirement": "ai_position",
     "value": "ADMIT",
     "because": "No instrument in force stated a position on AI-authored evidence for \"penetration_test\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
    },
    {
     "claim": "vulnerability_scan",
     "requirement": "ai_position",
     "value": "ADMIT",
     "because": "No instrument in force stated a position on AI-authored evidence for \"vulnerability_scan\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
    }
   ]
  },
  "inputs": [
   {
    "key": "ai-system:TRIAGE-ASSISTANT-V4::vulnerability_triage_disposition",
    "provenance": "MODELED",
    "reliability": 0.8,
    "critical": true,
    "memory_status": "admitted"
   },
   {
    "key": "ai-system:TRIAGE-ASSISTANT-V4::vulnerability_scan",
    "provenance": "VERIFIED",
    "reliability": 0.95,
    "critical": true,
    "memory_status": "admitted"
   },
   {
    "key": "ai-system:TRIAGE-ASSISTANT-V4::penetration_test",
    "provenance": "VERIFIED",
    "reliability": 0.95,
    "critical": true,
    "memory_status": "admitted"
   },
   {
    "key": "ai-system:TRIAGE-ASSISTANT-V4::control_assessment",
    "provenance": "VERIFIED",
    "reliability": 0.95,
    "critical": true,
    "memory_status": "admitted"
   }
  ]
 }
}

Independent audit / IG

Internal audit, an inspector general, or an external auditor testing the programme.

Everything, plus the verifier’s own findings over the sealed record.

This view withholds nothing. What it adds is the 22 checks the published verifier ran over the sealed record behind every other view of this decision — recomputed at build time, not asserted.

#CheckDetail
1Content reproduces (JCS + SHA-256)PASSmatches sha256:e6038d8525d391ca3b49b3b8135e9b479595df9200a54c9f68c7cbb286b87a34
2Hash chain links (entry = H(prev||content))PASShead sha256:2c628fa4efbfe5c02c5978f8f777b7877876cc40f378291a8bf847cd5db64977
3Confidence gated by weakest critical inputPASSmin over critical = 0.8, bound_by ai-system:TRIAGE-ASSISTANT-V4::vulnerability_triage_disposition (MODELED)
3bVerdict follows the threshold rulePASS0.8 => CAUTION; recorded CAUTION
4Point-in-time seal (no input past data_horizon)PASSall inputs <= 2026-08-08T16:00:00.000Z
5Anchor covers the head, and the timestamp token re-readsPASSinternally consistent; NO external anchor was requested — this is not a validated timestamp
6Criteria travel with the receipt and reproducePASSpolicy_body hashes to sha256:a6b69b7d20f7fb04d522364af1d92992058b04a5835fcec9d1c9f2261c7ef636
7Reliability re-derives from recorded evidencePASSall 4 inputs re-derive exactly
8Outcome trials and lineage discounts re-derivePASS4 input(s) re-derive: 0 credited outcome trial(s), 0 lineage-discounted corroboration(s); every reliability is at or under its class ceiling
9Re-ingested receipts respect their weakest-input ceilingPASSno re-ingested receipts: every input rests on a primary observation
10Release quorum re-derivesPASSNOT_REQUIRED - below the top exposure tier, no multi-party requirement applies
11Risk acceptance re-derivesPASSno risk acceptance: this decision stands or falls on its evidence
12Observer credentials were not revoked as of observation timePASSrevocation list 5 (0 entries, issued 2026-08-06T00:00:00.000Z, next update due 2026-08-13T00:00:00.000Z) reproduces; 4 observer signature(s) judged as of their own instant, none under a key revoked as compromised or retired by then
13The cryptographic suite is named and is one this verifier implementsPASSsealed under CB-1-ES256-SHA256 (ES256 / sha256, attest-canon/2); this verifier implements it; the suite states it is NOT quantum resistant
14Regulatory bindings are attributed and were enforcedPASS9 binding(s) from 2 instrument(s) in force, each attributed to an authority, a citation and a document digest; 4 required claim(s) all reached the gate
15Role-view commitments re-derive, and the customs view carries no moneyPASS6 role-view commitment(s) re-derived from this receipt’s own body by this verifier’s independent projection; the REGULATOR view carries no commercial figure
16AI-authored input was admitted only where an authority allowed itPASS1 claim(s) carry a position on AI-authored evidence set by an authority and 3 carry a recorded default nobody set; 0 exclusion(s) and 0 corroboration-only rule(s) re-derived against this receipt's own admitted inputs; 1 admitted input(s) are AI-authored by their enrolled identity (actor:ai:triage-assistant-v4)
17State digest recomputes from the ledger aloneUNVERIFIABLENOT APPLICABLE — you supplied no ledger, so the state digest cannot be re-derived from anything. This receipt commits to the corpus the deciding system held at the instant it sealed, and that commitment is checked by recomputing it from the append-only ledger and comparing; with no ledger in hand there is no second artefact to recompute from. The receipt is not at fault and nothing here is missing from it. Obtain the ledger from the issuer and re-run with --ledger <file>, or verifyReceipt(r, {ledger}). Nothing here has failed and nothing here has passed.
18Registry membership re-derives for every key relied onPASSall 4 key(s) relied on re-derive to the entries root registry v3 committed to and the trust root signed
20Geometric support re-derives, and an unevaluated record is not a supported onePASSno authority bound a metric to any claim on this receipt, so no geometric test applied. A claim nobody bound a metric to is not a claim about geometry, and this is a stated absence rather than a silent one
19The cause of every uncovered requirement re-derivesPASSevery required claim on this receipt is covered, so this check ran and had nothing to explain
21The sealing party is the one you were told to expectUNVERIFIABLENOT APPLICABLE — you supplied no trust bundle, so nothing here establishes who sealed this. Identities 1 to 20 prove that this document agrees with itself; not one of them asks whose trust root it was sealed under, and a document that agrees with itself about a decision nobody made agrees with itself perfectly. Obtain the issuer's corobate:trust-bundle:1 out of band, confirm its spoken fingerprint with them by voice, and re-run with --trust-bundle <file> --expect-fingerprint <what you heard>. Nothing here has failed and nothing here has passed.
The scoped copy itself — complete for this role
FAITHFUL digest sha256:829aa222cd3e07054f6ea39841e34280e3842f9709d8fbfd163da120eaa8ae28 matches the commitment sealed in the receipt.
{
 "spec": "corobate:role-view:2",
 "role": "AUDITOR",
 "purpose": "An external assessor. Sees the complete sealed record: this view withholds nothing and exists so the identity case is a case rather than an exception.",
 "is_a_receipt": false,
 "warning": "This is a SCOPED COPY of a sealed decision, not the decision record itself. It will not verify as a receipt and must not be presented as one. To confirm it is faithful, recompute its `view` digest under the same canonicalisation that produces receipt_hash and compare it with the entry for this role in the source receipt’s `views` block.",
 "derived_from": {
  "receipt_hash": "sha256:e6038d8525d391ca3b49b3b8135e9b479595df9200a54c9f68c7cbb286b87a34",
  "entry_hash": "sha256:2c628fa4efbfe5c02c5978f8f777b7877876cc40f378291a8bf847cd5db64977",
  "issued_at": "2026-08-08T16:00:00.000Z"
 },
 "view_digest": "sha256:829aa222cd3e07054f6ea39841e34280e3842f9709d8fbfd163da120eaa8ae28",
 "withheld": {
  "anything_withheld": false,
  "note": "Nothing outside the seal was removed for this role."
 },
 "view": {
  "spec": "urn:ietf:params:corobate:receipt:1",
  "receipt_version": "1.8",
  "engine": {
   "name": "corobate-memory",
   "version": "1.0.0"
  },
  "decision": {
   "id": "ai_TRIAGE_EVIDENCE_ADMIT",
   "domain": "supply-chain",
   "subject": "ai-system:TRIAGE-ASSISTANT-V4",
   "question": "May this quarter's vulnerability triage be accepted as the record of review?"
  },
  "issued_at": "2026-08-08T16:00:00.000Z",
  "data_horizon": "2026-08-08T16:00:00.000Z",
  "inputs": [
   {
    "key": "ai-system:TRIAGE-ASSISTANT-V4::vulnerability_triage_disposition",
    "value": "412-triaged",
    "provenance": "MODELED",
    "source": "triage-assistant-v4:vulnerability_triage_disposition",
    "observed_at": "2026-08-05T16:00:00.000Z",
    "last_corroborated_at": null,
    "memory_refreshed_by": [],
    "reliability": 0.8,
    "critical": true,
    "memory_id": "mem_0a6980bbce9f",
    "memory_status": "admitted",
    "memory_kind": "status",
    "memory_actor": "actor:ai:triage-assistant-v4",
    "memory_age_days": 3,
    "memory_track": {
     "n": 1,
     "successes": 1
    },
    "memory_promoted_by": [],
    "memory_content_digest": "sha256:612e098189acf7652c237b016c3537b38c17d735452f4f1d519c6bfa0772b2c2",
    "memory_outcomes": {
     "verified": 0,
     "falsified": 0,
     "modified": 0,
     "counted": 0,
     "recorded": 0
    },
    "memory_outcome_attestations": [],
    "memory_observer_lineage": null,
    "memory_corroborations": [],
    "memory_reingest": null,
    "memory_reasons": [
     "sparse track record: 1 independent observation(s); no failure recorded, so the class ceiling stands"
    ],
    "memory_class_floor": null,
    "memory_below_class_floor": false,
    "memory_not_attested": false,
    "memory_below_claim_reliability_floor": false,
    "memory_not_competent_authority": false,
    "memory_out_of_specification": false,
    "memory_ai_authored": true,
    "memory_ai_in_lineage": false,
    "memory_ai_position": "ADMIT",
    "memory_ai_inadmissible": false,
    "memory_geo_inadmissible": false,
    "memory_geo_rung": null,
    "memory_geo_metric": null,
    "memory_geo_required_metric": null,
    "observer_attested": true,
    "observer_auth_code": "VERIFIED",
    "observer_key_id": "k_f71bde46a9680d8d",
    "attestation": null,
    "derivation": {
     "provenance": "MODELED",
     "ceiling_bp": 8000,
     "track": {
      "n": 1,
      "successes": 1
     },
     "wilson_bp": null,
     "age_days": 3,
     "max_age_days": 14,
     "house_max_age_days": 14,
     "instrument_max_age_days": null,
     "freshness_cap_bp": 4000,
     "min_track_n": 5,
     "wilson_z_milli": 1960,
     "source_present": true,
     "seller_asserted_cap_bp": 5000,
     "retracted": false,
     "contradicted": false,
     "outcome_trials": 0,
     "outcomes": {
      "verified": 0,
      "falsified": 0,
      "modified": 0,
      "counted": 0,
      "recorded": 0
     },
     "corroborations_counted": 0,
     "corroborations_discounted": 0,
     "reingest_ceiling_bp": null,
     "reingest_depth": null,
     "reingest_weakest_class": null,
     "reingest_source_confidence_bp": null,
     "ai_authored": true,
     "ai_authored_because": "a model, named as one in its own enrolled identity",
     "ai_in_lineage": false,
     "ai_position": "ADMIT"
    },
    "memory_reason_codes": [
     {
      "code": "SPARSE_TRACK_RECORD",
      "observed": 1,
      "limit": 5,
      "binding": false
     }
    ],
    "context_line": "[MODELED · r=80.0% · 3d · triage-assistant-v4:vulnerability_triage_disposition] ai-system:TRIAGE-ASSISTANT-V4 / vulnerability_triage_disposition: 412-triaged"
   },
   {
    "key": "ai-system:TRIAGE-ASSISTANT-V4::vulnerability_scan",
    "value": "clean-at-scan",
    "provenance": "VERIFIED",
    "source": "nvd-cve:vulnerability_scan",
    "observed_at": "2026-08-04T16:00:00.000Z",
    "last_corroborated_at": null,
    "memory_refreshed_by": [],
    "reliability": 0.95,
    "critical": true,
    "memory_id": "mem_4d2b1fc0d322",
    "memory_status": "admitted",
    "memory_kind": "status",
    "memory_actor": "actor:sys:registry:nvd-cve",
    "memory_age_days": 4,
    "memory_track": {
     "n": 1,
     "successes": 1
    },
    "memory_promoted_by": [],
    "memory_content_digest": "sha256:aea4c3860d57b3edd045cd33946015c41ff1aee9cc8a4df49f26d8a5165d4a38",
    "memory_outcomes": {
     "verified": 0,
     "falsified": 0,
     "modified": 0,
     "counted": 0,
     "recorded": 0
    },
    "memory_outcome_attestations": [],
    "memory_observer_lineage": null,
    "memory_corroborations": [],
    "memory_reingest": null,
    "memory_reasons": [
     "sparse track record: 1 independent observation(s); no failure recorded, so the class ceiling stands"
    ],
    "memory_class_floor": null,
    "memory_below_class_floor": false,
    "memory_not_attested": false,
    "memory_below_claim_reliability_floor": false,
    "memory_not_competent_authority": false,
    "memory_out_of_specification": false,
    "memory_ai_authored": false,
    "memory_ai_in_lineage": false,
    "memory_ai_position": "ADMIT",
    "memory_ai_inadmissible": false,
    "memory_geo_inadmissible": false,
    "memory_geo_rung": null,
    "memory_geo_metric": null,
    "memory_geo_required_metric": null,
    "observer_attested": true,
    "observer_auth_code": "VERIFIED",
    "observer_key_id": "k_5873dd9e7169def3",
    "attestation": null,
    "derivation": {
     "provenance": "VERIFIED",
     "ceiling_bp": 9500,
     "track": {
      "n": 1,
      "successes": 1
     },
     "wilson_bp": null,
     "age_days": 4,
     "max_age_days": 14,
     "house_max_age_days": 14,
     "instrument_max_age_days": 30,
     "freshness_cap_bp": 4000,
     "min_track_n": 5,
     "wilson_z_milli": 1960,
     "source_present": true,
     "seller_asserted_cap_bp": 5000,
     "retracted": false,
     "contradicted": false,
     "outcome_trials": 0,
     "outcomes": {
      "verified": 0,
      "falsified": 0,
      "modified": 0,
      "counted": 0,
      "recorded": 0
     },
     "corroborations_counted": 0,
     "corroborations_discounted": 0,
     "reingest_ceiling_bp": null,
     "reingest_depth": null,
     "reingest_weakest_class": null,
     "reingest_source_confidence_bp": null,
     "ai_authored": false,
     "ai_authored_because": null,
     "ai_in_lineage": false,
     "ai_position": "ADMIT"
    },
    "memory_reason_codes": [
     {
      "code": "SPARSE_TRACK_RECORD",
      "observed": 1,
      "limit": 5,
      "binding": false
     }
    ],
    "context_line": "[VERIFIED · r=95.0% · 4d · nvd-cve:vulnerability_scan] ai-system:TRIAGE-ASSISTANT-V4 / vulnerability_scan: clean-at-scan"
   },
   {
    "key": "ai-system:TRIAGE-ASSISTANT-V4::penetration_test",
    "value": "no-critical",
    "provenance": "VERIFIED",
    "source": "LAB-NVLAP-0412:penetration_test",
    "observed_at": "2026-06-09T16:00:00.000Z",
    "last_corroborated_at": null,
    "memory_refreshed_by": [],
    "reliability": 0.95,
    "critical": true,
    "memory_id": "mem_a3316d633bfe",
    "memory_status": "admitted",
    "memory_kind": "test_report",
    "memory_actor": "actor:org:LAB-NVLAP-0412",
    "memory_age_days": 60,
    "memory_track": {
     "n": 1,
     "successes": 1
    },
    "memory_promoted_by": [],
    "memory_content_digest": "sha256:db69fb062be9b066b370c668281e12896da2869456a2e6d356a0f14879b27de9",
    "memory_outcomes": {
     "verified": 0,
     "falsified": 0,
     "modified": 0,
     "counted": 0,
     "recorded": 0
    },
    "memory_outcome_attestations": [],
    "memory_observer_lineage": null,
    "memory_corroborations": [],
    "memory_reingest": null,
    "memory_reasons": [
     "sparse track record: 1 independent observation(s); no failure recorded, so the class ceiling stands"
    ],
    "memory_class_floor": "VERIFIED",
    "memory_below_class_floor": false,
    "memory_not_attested": false,
    "memory_below_claim_reliability_floor": false,
    "memory_not_competent_authority": false,
    "memory_out_of_specification": false,
    "memory_ai_authored": false,
    "memory_ai_in_lineage": false,
    "memory_ai_position": "ADMIT",
    "memory_ai_inadmissible": false,
    "memory_geo_inadmissible": false,
    "memory_geo_rung": null,
    "memory_geo_metric": null,
    "memory_geo_required_metric": null,
    "observer_attested": true,
    "observer_auth_code": "VERIFIED",
    "observer_key_id": "k_17d23885943ae529",
    "attestation": null,
    "derivation": {
     "provenance": "VERIFIED",
     "ceiling_bp": 9500,
     "track": {
      "n": 1,
      "successes": 1
     },
     "wilson_bp": null,
     "age_days": 60,
     "max_age_days": 180,
     "house_max_age_days": 180,
     "instrument_max_age_days": null,
     "freshness_cap_bp": 4000,
     "min_track_n": 5,
     "wilson_z_milli": 1960,
     "source_present": true,
     "seller_asserted_cap_bp": 5000,
     "retracted": false,
     "contradicted": false,
     "outcome_trials": 0,
     "outcomes": {
      "verified": 0,
      "falsified": 0,
      "modified": 0,
      "counted": 0,
      "recorded": 0
     },
     "corroborations_counted": 0,
     "corroborations_discounted": 0,
     "reingest_ceiling_bp": null,
     "reingest_depth": null,
     "reingest_weakest_class": null,
     "reingest_source_confidence_bp": null,
     "min_class_floor": "VERIFIED",
     "ai_authored": false,
     "ai_authored_because": null,
     "ai_in_lineage": false,
     "ai_position": "ADMIT"
    },
    "memory_reason_codes": [
     {
      "code": "SPARSE_TRACK_RECORD",
      "observed": 1,
      "limit": 5,
      "binding": false
     }
    ],
    "context_line": "[VERIFIED · r=95.0% · 60d · LAB-NVLAP-0412:penetration_test] ai-system:TRIAGE-ASSISTANT-V4 / penetration_test: no-critical"
   },
   {
    "key": "ai-system:TRIAGE-ASSISTANT-V4::control_assessment",
    "value": "satisfied",
    "provenance": "VERIFIED",
    "source": "CERT-3PAO-ATLANTIC:control_assessment",
    "observed_at": "2026-04-30T16:00:00.000Z",
    "last_corroborated_at": null,
    "memory_refreshed_by": [],
    "reliability": 0.95,
    "critical": true,
    "memory_id": "mem_a153eb336060",
    "memory_status": "admitted",
    "memory_kind": "certificate",
    "memory_actor": "actor:org:CERT-3PAO-ATLANTIC",
    "memory_age_days": 100,
    "memory_track": {
     "n": 1,
     "successes": 1
    },
    "memory_promoted_by": [],
    "memory_content_digest": "sha256:c1aaf46a55b4cdc629a754ac35da1b8ec4dec85c2c78613c7bc93546b63f233c",
    "memory_outcomes": {
     "verified": 0,
     "falsified": 0,
     "modified": 0,
     "counted": 0,
     "recorded": 0
    },
    "memory_outcome_attestations": [],
    "memory_observer_lineage": null,
    "memory_corroborations": [],
    "memory_reingest": null,
    "memory_reasons": [
     "sparse track record: 1 independent observation(s); no failure recorded, so the class ceiling stands"
    ],
    "memory_class_floor": "VERIFIED",
    "memory_below_class_floor": false,
    "memory_not_attested": false,
    "memory_below_claim_reliability_floor": false,
    "memory_not_competent_authority": false,
    "memory_out_of_specification": false,
    "memory_ai_authored": false,
    "memory_ai_in_lineage": false,
    "memory_ai_position": "ADMIT",
    "memory_ai_inadmissible": false,
    "memory_geo_inadmissible": false,
    "memory_geo_rung": null,
    "memory_geo_metric": null,
    "memory_geo_required_metric": null,
    "observer_attested": true,
    "observer_auth_code": "VERIFIED",
    "observer_key_id": "k_307e4bfd710ec9b3",
    "attestation": null,
    "derivation": {
     "provenance": "VERIFIED",
     "ceiling_bp": 9500,
     "track": {
      "n": 1,
      "successes": 1
     },
     "wilson_bp": null,
     "age_days": 100,
     "max_age_days": 365,
     "house_max_age_days": 365,
     "instrument_max_age_days": 365,
     "freshness_cap_bp": 4000,
     "min_track_n": 5,
     "wilson_z_milli": 1960,
     "source_present": true,
     "seller_asserted_cap_bp": 5000,
     "retracted": false,
     "contradicted": false,
     "outcome_trials": 0,
     "outcomes": {
      "verified": 0,
      "falsified": 0,
      "modified": 0,
      "counted": 0,
      "recorded": 0
     },
     "corroborations_counted": 0,
     "corroborations_discounted": 0,
     "reingest_ceiling_bp": null,
     "reingest_depth": null,
     "reingest_weakest_class": null,
     "reingest_source_confidence_bp": null,
     "min_class_floor": "VERIFIED",
     "ai_authored": false,
     "ai_authored_because": null,
     "ai_in_lineage": false,
     "ai_position": "ADMIT"
    },
    "memory_reason_codes": [
     {
      "code": "SPARSE_TRACK_RECORD",
      "observed": 1,
      "limit": 5,
      "binding": false
     }
    ],
    "context_line": "[VERIFIED · r=95.0% · 100d · CERT-3PAO-ATLANTIC:control_assessment] ai-system:TRIAGE-ASSISTANT-V4 / control_assessment: satisfied"
   }
  ],
  "serialization": {
   "algorithm": "RFC8785-JCS",
   "hash": "sha256"
  },
  "crypto_suite": {
   "spec": "corobate:suite:1",
   "id": "CB-1-ES256-SHA256",
   "receipt_digest": "sha256",
   "chain_digest": "sha256",
   "content_digest": "sha256",
   "envelope_signature": "ES256",
   "signature_curve": "P-256",
   "canonicalisation": "attest-canon/2",
   "quantum_resistant": false
  },
  "confidence": {
   "value": 0.8,
   "method": "min-over-critical-inputs",
   "bound_by": "ai-system:TRIAGE-ASSISTANT-V4::vulnerability_triage_disposition"
  },
  "verdict": {
   "value": "CAUTION",
   "threshold_approve": 0.85,
   "threshold_caution": 0.6,
   "rule": "confidence>=threshold"
  },
  "release": {
   "required": false,
   "required_by_tier": false,
   "escalated_by_acceptance": false,
   "risk_accepted": false,
   "state": "NOT_REQUIRED",
   "code": "QUORUM_NOT_REQUIRED",
   "reason": "this decision is below the top exposure tier (floor $10,000,000) and no risk acceptance escalated into this gate, so no multi-party release requirement applies.",
   "tier_floor_cents": 1000000000,
   "exposure_usd_cents": 25000000,
   "required_m": 2,
   "declared_n": 3,
   "floor_m": 2,
   "distinct_signers": 0,
   "superseded": 0,
   "collapsed": 0,
   "release_digest": "sha256:3174d524ab5881c0caf1099f0c0265966e5b12c85c71c87fc8f9af138736ff5c",
   "governance_digest": "sha256:8b0a45a27fcce9c1c243c764e855e67c6fe6dfd7f02a563bd90809b419731905",
   "governance_signed": true,
   "counted_voices": [],
   "signatures": [],
   "ledger_seq": null
  },
  "acceptance": {
   "state": "NONE",
   "code": "ACCEPTANCE_NONE",
   "reason": "no risk acceptance was presented for this decision. This is the ordinary case: a refusal is a refusal unless a named person has priced it.",
   "permitted_basis": null,
   "presented": 0,
   "superseded": 0,
   "expired": 0,
   "gaps_not_covered": 0,
   "coverage_gaps_in_force": [],
   "evidentiary_digest": "sha256:3174d524ab5881c0caf1099f0c0265966e5b12c85c71c87fc8f9af138736ff5c",
   "margin_floor_bp": 100,
   "authority_ceiling_cents": {
    "SUPERVISOR": 1000000,
    "MANAGER": 25000000,
    "DIRECTOR": 500000000,
    "OFFICER": 5000000000
   },
   "acceptances": [],
   "escalated": false,
   "live": false,
   "ledger_seq": null
  },
  "regulatory": {
   "spec": "corobate:regulatory:2",
   "resolved": true,
   "applied": [
    {
     "instrument_id": "enterprise-ai-evidence-standard",
     "version": 1,
     "authority": "Office of the Chief Information Security Officer",
     "instrument": "Enterprise standard on machine-generated evidence",
     "edition": "2026-03-01",
     "citation": "§ 3 [VERIFY]",
     "source_digest": "sha256:e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5",
     "entered_by": "actor:human:issm",
     "entered_at": "2026-08-08T16:00:00.000Z"
    },
    {
     "instrument_id": "nist-sp-800-53r5-moderate",
     "version": 5,
     "authority": "National Institute of Standards and Technology",
     "instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
     "edition": "Rev. 5",
     "citation": "CA-2, CA-8, RA-5, SR-6 [VERIFY]",
     "source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353",
     "entered_by": "actor:human:issm",
     "entered_at": "2026-08-08T16:00:00.000Z"
    }
   ],
   "skipped": [],
   "conflicts": [],
   "bindings": [
    {
     "claim": "control_assessment",
     "requirement": "max_age_days",
     "value": 365,
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
      "instrument_id": "nist-sp-800-53r5-moderate",
      "version": 5,
      "edition": "Rev. 5",
      "citation": "CA-2 [VERIFY]",
      "source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "control_assessment",
     "requirement": "min_class",
     "value": "VERIFIED",
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
      "instrument_id": "nist-sp-800-53r5-moderate",
      "version": 5,
      "edition": "Rev. 5",
      "citation": "CA-2(1) independent assessors [VERIFY]",
      "source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "control_assessment",
     "requirement": "required",
     "value": true,
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
      "instrument_id": "nist-sp-800-53r5-moderate",
      "version": 5,
      "edition": "Rev. 5",
      "citation": "CA-2 [VERIFY]",
      "source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "penetration_test",
     "requirement": "min_class",
     "value": "VERIFIED",
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
      "instrument_id": "nist-sp-800-53r5-moderate",
      "version": 5,
      "edition": "Rev. 5",
      "citation": "CA-8(1) independent penetration agent [VERIFY]",
      "source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "penetration_test",
     "requirement": "required",
     "value": true,
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
      "instrument_id": "nist-sp-800-53r5-moderate",
      "version": 5,
      "edition": "Rev. 5",
      "citation": "CA-8 [VERIFY]",
      "source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "vulnerability_scan",
     "requirement": "max_age_days",
     "value": 30,
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
      "instrument_id": "nist-sp-800-53r5-moderate",
      "version": 5,
      "edition": "Rev. 5",
      "citation": "RA-5(a) [VERIFY]",
      "source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "vulnerability_scan",
     "requirement": "required",
     "value": true,
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
      "instrument_id": "nist-sp-800-53r5-moderate",
      "version": 5,
      "edition": "Rev. 5",
      "citation": "RA-5 [VERIFY]",
      "source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "vulnerability_triage_disposition",
     "requirement": "ai_position",
     "value": "ADMIT",
     "bound_by": {
      "authority": "Office of the Chief Information Security Officer",
      "instrument": "Enterprise standard on machine-generated evidence",
      "instrument_id": "enterprise-ai-evidence-standard",
      "version": 1,
      "edition": "2026-03-01",
      "citation": "§ 3.4 [VERIFY]",
      "source_digest": "sha256:e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "vulnerability_triage_disposition",
     "requirement": "required",
     "value": true,
     "bound_by": {
      "authority": "Office of the Chief Information Security Officer",
      "instrument": "Enterprise standard on machine-generated evidence",
      "instrument_id": "enterprise-ai-evidence-standard",
      "version": 1,
      "edition": "2026-03-01",
      "citation": "§ 3.1 [VERIFY]",
      "source_digest": "sha256:e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    }
   ],
   "defaults": [
    {
     "claim": "control_assessment",
     "requirement": "ai_position",
     "value": "ADMIT",
     "because": "No instrument in force stated a position on AI-authored evidence for \"control_assessment\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
    },
    {
     "claim": "penetration_test",
     "requirement": "ai_position",
     "value": "ADMIT",
     "because": "No instrument in force stated a position on AI-authored evidence for \"penetration_test\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
    },
    {
     "claim": "vulnerability_scan",
     "requirement": "ai_position",
     "value": "ADMIT",
     "because": "No instrument in force stated a position on AI-authored evidence for \"vulnerability_scan\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
    }
   ]
  },
  "reasons": [
   "Confidence 80.00% is bound by \"ai-system:TRIAGE-ASSISTANT-V4|vulnerability_triage_disposition\".",
   "Thresholds for $250,000 exposure: approve 85%, caution 60%."
  ],
  "memory": {
   "layer": "capture->store->recall->act",
   "ledger_head": "sha256:d11e8eaa639930292fb398123e6aeefff52b74a09d6448ad6f8e6c8e154ce39f",
   "ledger_entries": 6,
   "context_digest": "sha256:65e002162e15f455ef2fd75329ee96a1849c1c750f0f4fd3d5108a009fe44ab4",
   "context_memory_ids": [
    "mem_0a6980bbce9f",
    "mem_4d2b1fc0d322",
    "mem_a153eb336060",
    "mem_a3316d633bfe"
   ],
   "state_digest": "sha256:9357ab4d994dcd108cd3f22257927b155d8e44f669c5c0bb8d3e9bfc6be9e52a",
   "retrieval_method": "idf-lexical",
   "corpus_size": 4,
   "considered": 4,
   "admitted": 4,
   "withheld": 0,
   "not_considered": 0,
   "coverage_gaps": [],
   "exposure": {
    "usd": 250000,
    "declared_by": "actor:human:issm",
    "ledger_seq": 4
   },
   "salience_policy": {
    "half_life_days": 90,
    "grace_days": 7,
    "access_boost_bp": 500,
    "access_boost_cap_bp": 2500,
    "relevance_weight_bp": 6000,
    "recency_weight_bp": 3000,
    "usage_weight_bp": 1000,
    "context_cap": 12,
    "method": "idf-lexical",
    "candidate_list_digest": "sha256:fa532eca9f6e74d805d7557e2b12f0a9b5ac6a3262e163b632463317b542709f",
    "note": "salience orders retrieval only; it never contributes to reliability"
   },
   "policy_digest": "sha256:a6b69b7d20f7fb04d522364af1d92992058b04a5835fcec9d1c9f2261c7ef636",
   "policy_body": {
    "class_ceiling_bp": {
     "VERIFIED": 9500,
     "MODELED": 8000,
     "SELLER-ASSERTED": 5000,
     "MISSING": 0
    },
    "actor_class_ceiling": [
     [
      "^actor:ai:",
      "MODELED"
     ],
     [
      "^actor:agent:",
      "MODELED"
     ],
     [
      "^actor:human:",
      "SELLER-ASSERTED"
     ],
     [
      "^actor:org:LAB-",
      "VERIFIED"
     ],
     [
      "^actor:org:CERT-",
      "VERIFIED"
     ],
     [
      "^actor:org:",
      "SELLER-ASSERTED"
     ],
     [
      "^actor:sys:registry:",
      "VERIFIED"
     ],
     [
      "^actor:sys:sensor:",
      "VERIFIED"
     ],
     [
      "^actor:sys:",
      "MODELED"
     ]
    ],
    "freshness_cap_bp": 4000,
    "max_age_days": {
     "telemetry": 1,
     "price": 7,
     "status": 14,
     "certificate": 365,
     "test_report": 180,
     "filing": 90,
     "transcript": 120,
     "highlight": 365,
     "voice_note": 120,
     "note": 365,
     "preference": 540,
     "decision": 1825,
     "receipt": 365,
     "default": 90
    },
    "wilson_z_milli": 1960,
    "min_track_n": 5,
    "exposure_tiers_bp": [
     [
      1000000000,
      9500,
      8000
     ],
     [
      100000000,
      9000,
      7000
     ],
     [
      1000000,
      8500,
      6000
     ],
     [
      0,
      8000,
      5000
     ]
    ],
    "max_context_memories": 12,
    "contradiction_resolve_margin": 2,
    "salience": {
     "half_life_days": 90,
     "grace_days": 7,
     "access_boost_bp": 500,
     "access_boost_cap_bp": 2500,
     "relevance_weight_bp": 6000,
     "recency_weight_bp": 3000,
     "usage_weight_bp": 1000
    }
   },
   "observer_auth": {
    "mode": "required",
    "registry_version": 3,
    "registry_digest": "sha256:460aeaafe345f69542a302e6619dff0712af98de6518838ee4c8585e448c3a7d",
    "entries_root": "sha256:5670469f96484a814462814ed74f0f992b5f19e8ad6afced548e4956e4835ba5",
    "memberships": [
     {
      "key_id": "k_17d23885943ae529",
      "index": 1,
      "entry": {
       "actor": "actor:org:LAB-NVLAP-0412",
       "class": "VERIFIED",
       "kind": "org",
       "key_id": "k_17d23885943ae529",
       "jwk": {
        "kty": "EC",
        "crv": "P-256",
        "x": "3TTw47-PkYfo3ZaKTq_qtHghnGvninAVj25kyOwONno",
        "y": "16PMaR8ofeF5IcZk6ZLml8gDs8uE1s1sBLdciH5e4vg"
       },
       "valid_from": "2025-01-01T00:00:00.000Z",
       "valid_to": "2027-06-01T00:00:00.000Z"
      },
      "path": [
       {
        "side": "left",
        "sibling": "sha256:500f2ba5949d5256ae0f563530b0b270db41ce99d2d7c4b4b60e4bd558ca353d"
       },
       {
        "side": "right",
        "sibling": "sha256:a0b47ea437bf4f1042a1dd50a5a3f411f9a17971812fc6bafccd434eb7d78ccc"
       },
       {
        "side": "right",
        "sibling": "sha256:d3c2347eb675e865fc17ef0204cacda7b02e8784a811fdd1c8a015d1865e6dfb"
       },
       {
        "side": "right",
        "sibling": "sha256:7071adf5e21a94147d31f42f1028b4867b6562e5b78726259c2515b03b213e52"
       }
      ]
     },
     {
      "key_id": "k_307e4bfd710ec9b3",
      "index": 0,
      "entry": {
       "actor": "actor:org:CERT-3PAO-ATLANTIC",
       "class": "VERIFIED",
       "kind": "org",
       "key_id": "k_307e4bfd710ec9b3",
       "jwk": {
        "kty": "EC",
        "crv": "P-256",
        "x": "MGtV26TezLMPjiD3SecQtnje6eLqYyx4qkKzzAkbiY4",
        "y": "SMMdLYnn-FpKbb2sJQ8EAZnzvozNm-cGO0VbUUpniPY"
       },
       "valid_from": "2025-01-01T00:00:00.000Z",
       "valid_to": "2027-06-01T00:00:00.000Z"
      },
      "path": [
       {
        "side": "right",
        "sibling": "sha256:4148869fc259d2c5fc19fe5831065b165a9acf81812e123162035acfdecade1d"
       },
       {
        "side": "right",
        "sibling": "sha256:a0b47ea437bf4f1042a1dd50a5a3f411f9a17971812fc6bafccd434eb7d78ccc"
       },
       {
        "side": "right",
        "sibling": "sha256:d3c2347eb675e865fc17ef0204cacda7b02e8784a811fdd1c8a015d1865e6dfb"
       },
       {
        "side": "right",
        "sibling": "sha256:7071adf5e21a94147d31f42f1028b4867b6562e5b78726259c2515b03b213e52"
       }
      ]
     },
     {
      "key_id": "k_5873dd9e7169def3",
      "index": 2,
      "entry": {
       "actor": "actor:sys:registry:nvd-cve",
       "class": "VERIFIED",
       "kind": "system",
       "key_id": "k_5873dd9e7169def3",
       "jwk": {
        "kty": "EC",
        "crv": "P-256",
        "x": "O9OY6oMuJg0df_INePO19_3b11VaSyMwIPdxoqvV2ak",
        "y": "k7Orm5pxDxMdTF-H2S4h6ixRywzk1WxvquOQeqxLFx0"
       },
       "valid_from": "2025-01-01T00:00:00.000Z",
       "valid_to": "2027-06-01T00:00:00.000Z"
      },
      "path": [
       {
        "side": "right",
        "sibling": "sha256:e1fe36fe7c8e4695327c25d6d722630b6249c93293bfdc5894c58aaf961ab6f8"
       },
       {
        "side": "left",
        "sibling": "sha256:e8b9cba101f13538b909a2e686e9e6e9a8d77212036ed567eaebc205a443e83f"
       },
       {
        "side": "right",
        "sibling": "sha256:d3c2347eb675e865fc17ef0204cacda7b02e8784a811fdd1c8a015d1865e6dfb"
       },
       {
        "side": "right",
        "sibling": "sha256:7071adf5e21a94147d31f42f1028b4867b6562e5b78726259c2515b03b213e52"
       }
      ]
     },
     {
      "key_id": "k_f71bde46a9680d8d",
      "index": 7,
      "entry": {
       "actor": "actor:ai:triage-assistant-v4",
       "class": "MODELED",
       "kind": "system",
       "key_id": "k_f71bde46a9680d8d",
       "jwk": {
        "kty": "EC",
        "crv": "P-256",
        "x": "AmVfK7ltK7mprIKSXcj-PNTw4f8zq2gcbRG-qEiFmbU",
        "y": "W7sar2SHGJ_jUsBSxoasMr7l1If81Qu5BdYfvlK8Who"
       },
       "valid_from": "2025-01-01T00:00:00.000Z",
       "valid_to": "2027-06-01T00:00:00.000Z"
      },
      "path": [
       {
        "side": "left",
        "sibling": "sha256:3e8eae859976a6f7d64543a05e28b4c8fc52b8500c65decc7e124af145fac567"
       },
       {
        "side": "left",
        "sibling": "sha256:6d20941c438f3924c50e6573d0712466ec6b91655705d2603ea89981e4c50ffc"
       },
       {
        "side": "left",
        "sibling": "sha256:d3f1d60ec9478d2b69455e5ba8168897966d18429bd3b7d36105841cc2ae1776"
       },
       {
        "side": "right",
        "sibling": "sha256:7071adf5e21a94147d31f42f1028b4867b6562e5b78726259c2515b03b213e52"
       }
      ]
     }
    ],
    "memberships_unproven": [],
    "revocation": {
     "source": "SIGNED_LIST",
     "digest": "sha256:12f73b1fbf27d38cf137b86a1ce13bbcd98161123a6aa7d79b107db8189966b9",
     "sequence": 5,
     "registry_version": 3,
     "issued_at": "2026-08-06T00:00:00.000Z",
     "next_update_due": "2026-08-13T00:00:00.000Z",
     "entry_count": 0,
     "body": {
      "sequence": 5,
      "registry_version": 3,
      "issuer": {
       "name": "NIST-regulated enterprise demonstration trust root",
       "key_id": "k_3793b8e35f8acac1"
      },
      "issued_at": "2026-08-06T00:00:00.000Z",
      "next_update_due": "2026-08-13T00:00:00.000Z",
      "entries": [],
      "spec": "corobate:revocation-list:1"
     }
    }
   },
   "governance": {
    "digest": "sha256:8b0a45a27fcce9c1c243c764e855e67c6fe6dfd7f02a563bd90809b419731905",
    "signed": true,
    "actor_trust": "FLOOR_TO_SELLER_ASSERTED",
    "outcome_trial_weight": 1,
    "max_reingest_depth": 3,
    "release_quorum_m": 2,
    "release_quorum_n": 3,
    "risk_acceptance_margin_bp": 500,
    "risk_acceptance_max_days": 30,
    "risk_acceptance_authority_cents": {
     "SUPERVISOR": 1000000,
     "MANAGER": 25000000,
     "DIRECTOR": 500000000,
     "OFFICER": 5000000000
    },
    "template_author_roles": [
     "MANAGER",
     "DIRECTOR",
     "OFFICER"
    ]
   },
   "observers_attested": 4,
   "outcomes": {
    "attestations_counted": 0,
    "attestations_recorded": 0,
    "records_with_outcomes": 0
   },
   "lineage": {
    "corroborations_counted": 0,
    "corroborations_discounted": 0,
    "records_with_discounted_corroborations": 0
   },
   "reingest": {
    "records": 0,
    "max_depth": 0,
    "weakest_class": null,
    "chain_weakest_bp": 10000,
    "chain": []
   },
   "template": null
  }
 }
}

The same 412 findings, the same assistant, the same exposure. The enterprise standard now says a model may AGREE with this control and may not be the whole of it — the rung most real programmes actually want, and the one a two-position switch cannot express. Nobody else looked, so the control is uncovered. Note what did NOT happen: the score did not drop. The evidence became inadmissible, which is a different fact and has a different remedy — an analyst reviews the queue, rather than the assistant running again.

Subject
ai-system:TRIAGE-ASSISTANT-V4
Question
May this quarter's vulnerability triage be accepted as the record of review?
Exposure
$250,000
Instruments
Office of the Chief Information Security Officer · National Institute of Standards and Technology
Outcome
WITHHELD — the action is not permitted; outstanding: vulnerability triage disposition
Receipt
sha256:02be618b5d00cceb6f837bb29494c14973458076fd7998398a8daea7165ae8b4
The gate variables this decision ran under — a dial per question, read back off the sealed receipt
control assessmentrequired
necessity
requiredNational Institute of Standards and Technology — CA-2 [VERIFY]
staleness
365 daysNational Institute of Standards and Technology — CA-2 [VERIFY]
reputation class
verifiedNational Institute of Standards and Technology — CA-2(1) independent assessors [VERIFY]
reputation record
No reliability floor beyond the exposure tier's own threshold, which still binds.
completion
No satisfaction window was set. The requirement is due now: there is no period in which it may be outstanding, and nothing proceeds without it.
ai provenance
admitNo instrument in force stated a position on AI-authored evidence for "control_assessment". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway.
penetration testrequired
necessity
requiredNational Institute of Standards and Technology — CA-8 [VERIFY]
staleness
90 daysNo instrument set an age limit for this claim, so the deploying organisation's own freshness policy binds at 90 days. It is not unlimited.
reputation class
verifiedNational Institute of Standards and Technology — CA-8(1) independent penetration agent [VERIFY]
reputation record
No reliability floor beyond the exposure tier's own threshold, which still binds.
completion
No satisfaction window was set. The requirement is due now: there is no period in which it may be outstanding, and nothing proceeds without it.
ai provenance
admitNo instrument in force stated a position on AI-authored evidence for "penetration_test". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway.
vulnerability scanrequired
necessity
requiredNational Institute of Standards and Technology — RA-5 [VERIFY]
staleness
30 daysNational Institute of Standards and Technology — RA-5(a) [VERIFY]
reputation class
No class floor was set, so the seller's own assertion is admissible for this claim up to the ceiling that class carries. That is a setting, not an absence.
reputation record
No reliability floor beyond the exposure tier's own threshold, which still binds.
completion
No satisfaction window was set. The requirement is due now: there is no period in which it may be outstanding, and nothing proceeds without it.
ai provenance
admitNo instrument in force stated a position on AI-authored evidence for "vulnerability_scan". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway.
vulnerability triage dispositionrequired
necessity
requiredOffice of the Chief Information Security Officer — § 3.1 [VERIFY]
staleness
90 daysNo instrument set an age limit for this claim, so the deploying organisation's own freshness policy binds at 90 days. It is not unlimited.
reputation class
No class floor was set, so the seller's own assertion is admissible for this claim up to the ceiling that class carries. That is a setting, not an absence.
reputation record
No reliability floor beyond the exposure tier's own threshold, which still binds.
completion
No satisfaction window was set. The requirement is due now: there is no period in which it may be outstanding, and nothing proceeds without it.
ai provenance
corroboration onlyOffice of the Chief Information Security Officer — § 3.4 [VERIFY]

Every bar above was re-derived from the regulatory bindings inside this receipt’s hashed body, not from the configuration that produced it. A bar in grey is a setting no instrument made — the deploying organisation’s own default, which still binds and is not an absence. A bar position renders an ordinal on a declared ladder: it is a way to draw a control and to compare two settings on the same axis, and it is not a measurement. The value printed beside each bar is the authoritative one.

Whoever must act now

The engineer with the deployment in their hands, the release manager, the person who must publish or hold.

One instruction and the reason in words. No score, no money, no signatures.

DO NOT PROCEED
ai-system:TRIAGE-ASSISTANT-V4
Missing or out of date: vulnerability triage disposition

Seven or eight fields, and not one of them is a number somebody can argue with. This person is not being asked to re-judge the evidence; somebody already did, and it is on the record.

The scoped copy itself — partial — something outside this role’s remit was removed
FAITHFUL digest sha256:350e78c681bb8d15440796459a02f5120657797bd3114114277d42a44b6b6b0d matches the commitment sealed in the receipt.
{
 "spec": "corobate:role-view:2",
 "role": "OPERATOR",
 "purpose": "Whoever must act on this decision now — release the goods, fund the draw, dispatch the agent, ship the title. Sees one instruction and the reason in plain words, and nothing that could be argued about while somebody waits.",
 "is_a_receipt": false,
 "warning": "This is a SCOPED COPY of a sealed decision, not the decision record itself. It will not verify as a receipt and must not be presented as one. To confirm it is faithful, recompute its `view` digest under the same canonicalisation that produces receipt_hash and compare it with the entry for this role in the source receipt’s `views` block.",
 "derived_from": {
  "receipt_hash": "sha256:02be618b5d00cceb6f837bb29494c14973458076fd7998398a8daea7165ae8b4",
  "entry_hash": "sha256:6b9124406ee627da802b075c8ef55df54ffc8320e20937b2d1f1038d286feefb",
  "issued_at": "2026-08-08T16:00:00.000Z"
 },
 "view_digest": "sha256:350e78c681bb8d15440796459a02f5120657797bd3114114277d42a44b6b6b0d",
 "withheld": {
  "anything_withheld": true,
  "note": "Facts outside this role’s remit were removed. That something was removed is stated so a partial record is never mistaken for a complete one. How much, and what, is not stated — a count is an inference about the part you are not entitled to see."
 },
 "view": {
  "spec": "urn:ietf:params:corobate:receipt:1",
  "receipt_version": "1.8",
  "issued_at": "2026-08-08T16:00:00.000Z",
  "decision": {
   "id": "ai_TRIAGE_EVIDENCE_CORROBORATION_ONLY",
   "subject": "ai-system:TRIAGE-ASSISTANT-V4"
  },
  "memory": {
   "state_digest": "sha256:9357ab4d994dcd108cd3f22257927b155d8e44f669c5c0bb8d3e9bfc6be9e52a",
   "ledger_head": "sha256:b037093616312675fb7422882b44889dba9f936590214cd993c2e391b7f121c9",
   "coverage_gaps": [
    "ai-system:TRIAGE-ASSISTANT-V4|vulnerability_triage_disposition"
   ]
  },
  "verdict": {
   "value": "WITHHELD"
  },
  "release": {
   "state": "WITHHELD_NO_EVIDENCE"
  }
 }
}

Provider / assessed party

The cloud service provider, the release team, or the party operating the AI system — whoever is being assessed.

Sees which controls were required of them and by which publication and control identifier. Does not see the authorising official’s exposure figure or how any shortfall was priced.

What is outstanding on your file

  • vulnerability triage disposition — required by Office of the Chief Information Security Officer, § 3.1 [VERIFY]
ClaimRequiredEvidence classWhoAgeOutcome
vulnerability_scanyesVERIFIED2026-08-04admitted
penetration_testyesVERIFIED2026-06-09admitted
control_assessmentyesVERIFIED2026-04-30admitted
vulnerability_triage_dispositionnoMODELED2026-08-05withheld
vulnerability_triage_dispositionyesMISSING2026-08-08coverage gap

The clause is here because it turns an argument into an errand. What is not here: what the bank had at stake, and whether anyone priced the shortfall.

The scoped copy itself — partial — something outside this role’s remit was removed
FAITHFUL digest sha256:9ec178449e48f0edb2b08816fb258433837d59a524b070ed72dd9f3c9128c50f matches the commitment sealed in the receipt.
{
 "spec": "corobate:role-view:2",
 "role": "SUPPLIER",
 "purpose": "The party whose evidence was judged. Sees every claim the decision required, which fell short, and the clause that required it — and nothing about what the buyer had at stake or how the buyer priced any shortfall. NOTE, because an earlier draft of this sentence was untrue: this projection carries the WHOLE inputs array, so where several parties supplied evidence for one decision, each of them sees all of it. Per-party scoping cannot be expressed by a commitment scheme with one digest per role, and claiming it anyway would be the kind of promise this file exists to stop making.",
 "is_a_receipt": false,
 "warning": "This is a SCOPED COPY of a sealed decision, not the decision record itself. It will not verify as a receipt and must not be presented as one. To confirm it is faithful, recompute its `view` digest under the same canonicalisation that produces receipt_hash and compare it with the entry for this role in the source receipt’s `views` block.",
 "derived_from": {
  "receipt_hash": "sha256:02be618b5d00cceb6f837bb29494c14973458076fd7998398a8daea7165ae8b4",
  "entry_hash": "sha256:6b9124406ee627da802b075c8ef55df54ffc8320e20937b2d1f1038d286feefb",
  "issued_at": "2026-08-08T16:00:00.000Z"
 },
 "view_digest": "sha256:9ec178449e48f0edb2b08816fb258433837d59a524b070ed72dd9f3c9128c50f",
 "withheld": {
  "anything_withheld": true,
  "note": "Facts outside this role’s remit were removed. That something was removed is stated so a partial record is never mistaken for a complete one. How much, and what, is not stated — a count is an inference about the part you are not entitled to see."
 },
 "view": {
  "spec": "urn:ietf:params:corobate:receipt:1",
  "receipt_version": "1.8",
  "issued_at": "2026-08-08T16:00:00.000Z",
  "decision": {
   "id": "ai_TRIAGE_EVIDENCE_CORROBORATION_ONLY",
   "subject": "ai-system:TRIAGE-ASSISTANT-V4",
   "question": "May this quarter's vulnerability triage be accepted as the record of review?"
  },
  "memory": {
   "state_digest": "sha256:9357ab4d994dcd108cd3f22257927b155d8e44f669c5c0bb8d3e9bfc6be9e52a",
   "ledger_head": "sha256:b037093616312675fb7422882b44889dba9f936590214cd993c2e391b7f121c9",
   "coverage_gaps": [
    "ai-system:TRIAGE-ASSISTANT-V4|vulnerability_triage_disposition"
   ]
  },
  "verdict": {
   "value": "WITHHELD"
  },
  "inputs": [
   {
    "key": "ai-system:TRIAGE-ASSISTANT-V4::vulnerability_scan",
    "provenance": "VERIFIED",
    "observed_at": "2026-08-04T16:00:00.000Z",
    "memory_status": "admitted",
    "critical": true
   },
   {
    "key": "ai-system:TRIAGE-ASSISTANT-V4::penetration_test",
    "provenance": "VERIFIED",
    "observed_at": "2026-06-09T16:00:00.000Z",
    "memory_status": "admitted",
    "critical": true
   },
   {
    "key": "ai-system:TRIAGE-ASSISTANT-V4::control_assessment",
    "provenance": "VERIFIED",
    "observed_at": "2026-04-30T16:00:00.000Z",
    "memory_status": "admitted",
    "critical": true
   },
   {
    "key": "ai-system:TRIAGE-ASSISTANT-V4::vulnerability_triage_disposition",
    "provenance": "MODELED",
    "observed_at": "2026-08-05T16:00:00.000Z",
    "memory_status": "withheld",
    "critical": false
   },
   {
    "key": "ai-system:TRIAGE-ASSISTANT-V4::vulnerability_triage_disposition",
    "provenance": "MISSING",
    "observed_at": "2026-08-08T16:00:00.000Z",
    "memory_status": "coverage_gap",
    "critical": true
   }
  ],
  "regulatory": {
   "bindings": [
    {
     "claim": "control_assessment",
     "requirement": "max_age_days",
     "value": 365,
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
      "instrument_id": "nist-sp-800-53r5-moderate",
      "version": 5,
      "edition": "Rev. 5",
      "citation": "CA-2 [VERIFY]",
      "source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "control_assessment",
     "requirement": "min_class",
     "value": "VERIFIED",
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
      "instrument_id": "nist-sp-800-53r5-moderate",
      "version": 5,
      "edition": "Rev. 5",
      "citation": "CA-2(1) independent assessors [VERIFY]",
      "source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "control_assessment",
     "requirement": "required",
     "value": true,
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
      "instrument_id": "nist-sp-800-53r5-moderate",
      "version": 5,
      "edition": "Rev. 5",
      "citation": "CA-2 [VERIFY]",
      "source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "penetration_test",
     "requirement": "min_class",
     "value": "VERIFIED",
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
      "instrument_id": "nist-sp-800-53r5-moderate",
      "version": 5,
      "edition": "Rev. 5",
      "citation": "CA-8(1) independent penetration agent [VERIFY]",
      "source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "penetration_test",
     "requirement": "required",
     "value": true,
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
      "instrument_id": "nist-sp-800-53r5-moderate",
      "version": 5,
      "edition": "Rev. 5",
      "citation": "CA-8 [VERIFY]",
      "source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "vulnerability_scan",
     "requirement": "max_age_days",
     "value": 30,
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
      "instrument_id": "nist-sp-800-53r5-moderate",
      "version": 5,
      "edition": "Rev. 5",
      "citation": "RA-5(a) [VERIFY]",
      "source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "vulnerability_scan",
     "requirement": "required",
     "value": true,
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
      "instrument_id": "nist-sp-800-53r5-moderate",
      "version": 5,
      "edition": "Rev. 5",
      "citation": "RA-5 [VERIFY]",
      "source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "vulnerability_triage_disposition",
     "requirement": "ai_position",
     "value": "CORROBORATION_ONLY",
     "bound_by": {
      "authority": "Office of the Chief Information Security Officer",
      "instrument": "Enterprise standard on machine-generated evidence",
      "instrument_id": "enterprise-ai-evidence-standard",
      "version": 1,
      "edition": "2026-03-01",
      "citation": "§ 3.4 [VERIFY]",
      "source_digest": "sha256:e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "vulnerability_triage_disposition",
     "requirement": "required",
     "value": true,
     "bound_by": {
      "authority": "Office of the Chief Information Security Officer",
      "instrument": "Enterprise standard on machine-generated evidence",
      "instrument_id": "enterprise-ai-evidence-standard",
      "version": 1,
      "edition": "2026-03-01",
      "citation": "§ 3.1 [VERIFY]",
      "source_digest": "sha256:e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    }
   ],
   "applied": [
    {
     "instrument_id": "enterprise-ai-evidence-standard",
     "version": 1,
     "authority": "Office of the Chief Information Security Officer",
     "instrument": "Enterprise standard on machine-generated evidence",
     "edition": "2026-03-01",
     "citation": "§ 3 [VERIFY]",
     "source_digest": "sha256:e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5",
     "entered_by": "actor:human:issm",
     "entered_at": "2026-08-08T16:00:00.000Z"
    },
    {
     "instrument_id": "nist-sp-800-53r5-moderate",
     "version": 5,
     "authority": "National Institute of Standards and Technology",
     "instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
     "edition": "Rev. 5",
     "citation": "CA-2, CA-8, RA-5, SR-6 [VERIFY]",
     "source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353",
     "entered_by": "actor:human:issm",
     "entered_at": "2026-08-08T16:00:00.000Z"
    }
   ],
   "defaults": [
    {
     "claim": "control_assessment",
     "requirement": "ai_position",
     "value": "ADMIT",
     "because": "No instrument in force stated a position on AI-authored evidence for \"control_assessment\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
    },
    {
     "claim": "penetration_test",
     "requirement": "ai_position",
     "value": "ADMIT",
     "because": "No instrument in force stated a position on AI-authored evidence for \"penetration_test\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
    },
    {
     "claim": "vulnerability_scan",
     "requirement": "ai_position",
     "value": "ADMIT",
     "because": "No instrument in force stated a position on AI-authored evidence for \"vulnerability_scan\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
    }
   ]
  }
 }
}

Assessor / authorising official

A third-party assessment organisation, an agency assessor, or an inspector general reviewing the package. Same position as a customs officer: a public mandate over the record.

The control record in full — each publication by control identifier, edition and document digest, and every required claim with who supplied it and when. No exposure figure, no risk pricing, no confidence score.

Office of the Chief Information Security Officer
Enterprise standard on machine-generated evidence
§ 3 [VERIFY] · edition 2026-03-01
document sha256:e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5
entered by actor:human:issm
National Institute of Standards and Technology
SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)
CA-2, CA-8, RA-5, SR-6 [VERIFY] · edition Rev. 5
document sha256:5353535353535353535353535353535353535353535353535353535353535353
entered by actor:human:issm

What each authority bound

ClaimRequirementLevelBound by
control_assessmentmax age days365National Institute of Standards and Technology
CA-2 [VERIFY] · SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)
control_assessmentmin classVERIFIEDNational Institute of Standards and Technology
CA-2(1) independent assessors [VERIFY] · SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)
control_assessmentrequiredtrueNational Institute of Standards and Technology
CA-2 [VERIFY] · SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)
penetration_testmin classVERIFIEDNational Institute of Standards and Technology
CA-8(1) independent penetration agent [VERIFY] · SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)
penetration_testrequiredtrueNational Institute of Standards and Technology
CA-8 [VERIFY] · SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)
vulnerability_scanmax age days30National Institute of Standards and Technology
RA-5(a) [VERIFY] · SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)
vulnerability_scanrequiredtrueNational Institute of Standards and Technology
RA-5 [VERIFY] · SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)
vulnerability_triage_dispositionai positionCORROBORATION_ONLYOffice of the Chief Information Security Officer
§ 3.4 [VERIFY] · Enterprise standard on machine-generated evidence
vulnerability_triage_dispositionrequiredtrueOffice of the Chief Information Security Officer
§ 3.1 [VERIFY] · Enterprise standard on machine-generated evidence

Every required claim, and what was actually held

ClaimRequiredEvidence classWhoAgeOutcome
vulnerability_scanyesVERIFIEDactor:sys:registry:nvd-cve2026-08-04admitted
penetration_testyesVERIFIEDactor:org:LAB-NVLAP-04122026-06-09admitted
control_assessmentyesVERIFIEDactor:org:CERT-3PAO-ATLANTIC2026-04-30admitted
vulnerability_triage_dispositionnoMODELEDactor:ai:triage-assistant-v42026-08-05withheld
vulnerability_triage_dispositionyesMISSING2026-08-08coverage gap
Absent from this copy, deliberatelyNo exposure figure, no risk pricing, no confidence score, no release quorum. The examiner’s claim is on the record of what was required and what was held — answered here completely, down to the digest of the document each requirement was configured from. The institution’s commercial position is a different question and this document does not answer it. The published verifier checks that on the content of the copy, not on the intentions of whoever produced it.
The scoped copy itself — partial — something outside this role’s remit was removed
FAITHFUL digest sha256:27db26202a1449fdac2ae53eee7a5ad96646ddb9854a1c539aa5b0f5cf6c3919 matches the commitment sealed in the receipt.
{
 "spec": "corobate:role-view:2",
 "role": "REGULATOR",
 "purpose": "An official holding a public mandate over this record — a customs officer, a bank examiner, a market conduct supervisor. Sees the regulatory record in full: their own instrument named, every required claim and whether it was met, by whom, how old. No commercial figure of any kind.",
 "is_a_receipt": false,
 "warning": "This is a SCOPED COPY of a sealed decision, not the decision record itself. It will not verify as a receipt and must not be presented as one. To confirm it is faithful, recompute its `view` digest under the same canonicalisation that produces receipt_hash and compare it with the entry for this role in the source receipt’s `views` block.",
 "derived_from": {
  "receipt_hash": "sha256:02be618b5d00cceb6f837bb29494c14973458076fd7998398a8daea7165ae8b4",
  "entry_hash": "sha256:6b9124406ee627da802b075c8ef55df54ffc8320e20937b2d1f1038d286feefb",
  "issued_at": "2026-08-08T16:00:00.000Z"
 },
 "view_digest": "sha256:27db26202a1449fdac2ae53eee7a5ad96646ddb9854a1c539aa5b0f5cf6c3919",
 "withheld": {
  "anything_withheld": true,
  "note": "Facts outside this role’s remit were removed. That something was removed is stated so a partial record is never mistaken for a complete one. How much, and what, is not stated — a count is an inference about the part you are not entitled to see."
 },
 "view": {
  "spec": "urn:ietf:params:corobate:receipt:1",
  "receipt_version": "1.8",
  "issued_at": "2026-08-08T16:00:00.000Z",
  "decision": {
   "id": "ai_TRIAGE_EVIDENCE_CORROBORATION_ONLY",
   "subject": "ai-system:TRIAGE-ASSISTANT-V4",
   "question": "May this quarter's vulnerability triage be accepted as the record of review?"
  },
  "memory": {
   "state_digest": "sha256:9357ab4d994dcd108cd3f22257927b155d8e44f669c5c0bb8d3e9bfc6be9e52a",
   "ledger_head": "sha256:b037093616312675fb7422882b44889dba9f936590214cd993c2e391b7f121c9",
   "coverage_gaps": [
    "ai-system:TRIAGE-ASSISTANT-V4|vulnerability_triage_disposition"
   ]
  },
  "data_horizon": "2026-08-08T16:00:00.000Z",
  "verdict": {
   "value": "WITHHELD"
  },
  "regulatory": {
   "spec": "corobate:regulatory:2",
   "resolved": true,
   "applied": [
    {
     "instrument_id": "enterprise-ai-evidence-standard",
     "version": 1,
     "authority": "Office of the Chief Information Security Officer",
     "instrument": "Enterprise standard on machine-generated evidence",
     "edition": "2026-03-01",
     "citation": "§ 3 [VERIFY]",
     "source_digest": "sha256:e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5",
     "entered_by": "actor:human:issm",
     "entered_at": "2026-08-08T16:00:00.000Z"
    },
    {
     "instrument_id": "nist-sp-800-53r5-moderate",
     "version": 5,
     "authority": "National Institute of Standards and Technology",
     "instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
     "edition": "Rev. 5",
     "citation": "CA-2, CA-8, RA-5, SR-6 [VERIFY]",
     "source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353",
     "entered_by": "actor:human:issm",
     "entered_at": "2026-08-08T16:00:00.000Z"
    }
   ],
   "skipped": [],
   "conflicts": [],
   "bindings": [
    {
     "claim": "control_assessment",
     "requirement": "max_age_days",
     "value": 365,
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
      "instrument_id": "nist-sp-800-53r5-moderate",
      "version": 5,
      "edition": "Rev. 5",
      "citation": "CA-2 [VERIFY]",
      "source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "control_assessment",
     "requirement": "min_class",
     "value": "VERIFIED",
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
      "instrument_id": "nist-sp-800-53r5-moderate",
      "version": 5,
      "edition": "Rev. 5",
      "citation": "CA-2(1) independent assessors [VERIFY]",
      "source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "control_assessment",
     "requirement": "required",
     "value": true,
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
      "instrument_id": "nist-sp-800-53r5-moderate",
      "version": 5,
      "edition": "Rev. 5",
      "citation": "CA-2 [VERIFY]",
      "source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "penetration_test",
     "requirement": "min_class",
     "value": "VERIFIED",
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
      "instrument_id": "nist-sp-800-53r5-moderate",
      "version": 5,
      "edition": "Rev. 5",
      "citation": "CA-8(1) independent penetration agent [VERIFY]",
      "source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "penetration_test",
     "requirement": "required",
     "value": true,
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
      "instrument_id": "nist-sp-800-53r5-moderate",
      "version": 5,
      "edition": "Rev. 5",
      "citation": "CA-8 [VERIFY]",
      "source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "vulnerability_scan",
     "requirement": "max_age_days",
     "value": 30,
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
      "instrument_id": "nist-sp-800-53r5-moderate",
      "version": 5,
      "edition": "Rev. 5",
      "citation": "RA-5(a) [VERIFY]",
      "source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "vulnerability_scan",
     "requirement": "required",
     "value": true,
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
      "instrument_id": "nist-sp-800-53r5-moderate",
      "version": 5,
      "edition": "Rev. 5",
      "citation": "RA-5 [VERIFY]",
      "source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "vulnerability_triage_disposition",
     "requirement": "ai_position",
     "value": "CORROBORATION_ONLY",
     "bound_by": {
      "authority": "Office of the Chief Information Security Officer",
      "instrument": "Enterprise standard on machine-generated evidence",
      "instrument_id": "enterprise-ai-evidence-standard",
      "version": 1,
      "edition": "2026-03-01",
      "citation": "§ 3.4 [VERIFY]",
      "source_digest": "sha256:e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "vulnerability_triage_disposition",
     "requirement": "required",
     "value": true,
     "bound_by": {
      "authority": "Office of the Chief Information Security Officer",
      "instrument": "Enterprise standard on machine-generated evidence",
      "instrument_id": "enterprise-ai-evidence-standard",
      "version": 1,
      "edition": "2026-03-01",
      "citation": "§ 3.1 [VERIFY]",
      "source_digest": "sha256:e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    }
   ],
   "defaults": [
    {
     "claim": "control_assessment",
     "requirement": "ai_position",
     "value": "ADMIT",
     "because": "No instrument in force stated a position on AI-authored evidence for \"control_assessment\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
    },
    {
     "claim": "penetration_test",
     "requirement": "ai_position",
     "value": "ADMIT",
     "because": "No instrument in force stated a position on AI-authored evidence for \"penetration_test\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
    },
    {
     "claim": "vulnerability_scan",
     "requirement": "ai_position",
     "value": "ADMIT",
     "because": "No instrument in force stated a position on AI-authored evidence for \"vulnerability_scan\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
    }
   ]
  },
  "inputs": [
   {
    "key": "ai-system:TRIAGE-ASSISTANT-V4::vulnerability_scan",
    "provenance": "VERIFIED",
    "source": "nvd-cve:vulnerability_scan",
    "observed_at": "2026-08-04T16:00:00.000Z",
    "critical": true,
    "memory_status": "admitted",
    "memory_actor": "actor:sys:registry:nvd-cve"
   },
   {
    "key": "ai-system:TRIAGE-ASSISTANT-V4::penetration_test",
    "provenance": "VERIFIED",
    "source": "LAB-NVLAP-0412:penetration_test",
    "observed_at": "2026-06-09T16:00:00.000Z",
    "critical": true,
    "memory_status": "admitted",
    "memory_actor": "actor:org:LAB-NVLAP-0412"
   },
   {
    "key": "ai-system:TRIAGE-ASSISTANT-V4::control_assessment",
    "provenance": "VERIFIED",
    "source": "CERT-3PAO-ATLANTIC:control_assessment",
    "observed_at": "2026-04-30T16:00:00.000Z",
    "critical": true,
    "memory_status": "admitted",
    "memory_actor": "actor:org:CERT-3PAO-ATLANTIC"
   },
   {
    "key": "ai-system:TRIAGE-ASSISTANT-V4::vulnerability_triage_disposition",
    "provenance": "MODELED",
    "source": "triage-assistant-v4:vulnerability_triage_disposition",
    "observed_at": "2026-08-05T16:00:00.000Z",
    "critical": false,
    "memory_status": "withheld",
    "memory_actor": "actor:ai:triage-assistant-v4"
   },
   {
    "key": "ai-system:TRIAGE-ASSISTANT-V4::vulnerability_triage_disposition",
    "provenance": "MISSING",
    "source": null,
    "observed_at": "2026-08-08T16:00:00.000Z",
    "critical": true,
    "memory_status": "coverage_gap"
   }
  ],
  "crypto_suite": {
   "spec": "corobate:suite:1",
   "id": "CB-1-ES256-SHA256",
   "receipt_digest": "sha256",
   "chain_digest": "sha256",
   "content_digest": "sha256",
   "envelope_signature": "ES256",
   "signature_curve": "P-256",
   "canonicalisation": "attest-canon/2",
   "quantum_resistant": false
  }
 }
}

ISSM / control owner

The information system security manager and the control owners who hold the package.

The fullest internal view: every input, its class, its age, its score, the exposure, and every publication in force.

VerdictWITHHELD
Confidence0%
bound by vulnerability_triage_disposition
Exposure$250,000
ReleaseWITHHELD_NO_EVIDENCE
Risk acceptedNONE

Every input the gate saw

ClaimRequiredEvidence classWhoAgeScoreOutcome
vulnerability_scanyesVERIFIEDactor:sys:registry:nvd-cve4d95%admitted
penetration_testyesVERIFIEDactor:org:LAB-NVLAP-041260d95%admitted
control_assessmentyesVERIFIEDactor:org:CERT-3PAO-ATLANTIC100d95%admitted
vulnerability_triage_dispositionnoMODELEDactor:ai:triage-assistant-v43d80%withheld
vulnerability_triage_dispositionyesMISSING2026-08-080%coverage gap

Instruments in force

Office of the Chief Information Security Officer
Enterprise standard on machine-generated evidence
§ 3 [VERIFY] · edition 2026-03-01
document sha256:e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5
entered by actor:human:issm
National Institute of Standards and Technology
SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)
CA-2, CA-8, RA-5, SR-6 [VERIFY] · edition Rev. 5
document sha256:5353535353535353535353535353535353535353535353535353535353535353
entered by actor:human:issm

Why

  • Coverage gap: no admissible memory for required claim(s) ai-system:TRIAGE-ASSISTANT-V4|vulnerability_triage_disposition.
  • Confidence 0.00% is bound by "ai-system:TRIAGE-ASSISTANT-V4|vulnerability_triage_disposition".
  • 1 memory was withheld from the context block: ai-system:TRIAGE-ASSISTANT-V4|vulnerability_triage_disposition (AI-authored and standing alone: the authority binding this claim admits model output as corroboration but not as the whole of it, and nothing else that survived on this decision — no separate admissible record and no counted corroboration from a party that is not itself a model — carries "ai-system:TRIAGE-ASSISTANT-V4|vulnerability_triage_disposition". A model agreeing with nothing is not corroboration, and a model agreeing with a record this decision has itself refused is agreeing with nothing.).
  • Thresholds for $250,000 exposure: approve 85%, caution 60%.
The scoped copy itself — partial — something outside this role’s remit was removed
FAITHFUL digest sha256:2add4b14ddb2392c2c4d09321c6ced764a745b025d71efa72f63735d23bca1f1 matches the commitment sealed in the receipt.
{
 "spec": "corobate:role-view:2",
 "role": "COMPLIANCE",
 "purpose": "The operator’s own compliance function. The fullest internal view: every gap, every instrument in force, the waivability of each requirement and who accepted what.",
 "is_a_receipt": false,
 "warning": "This is a SCOPED COPY of a sealed decision, not the decision record itself. It will not verify as a receipt and must not be presented as one. To confirm it is faithful, recompute its `view` digest under the same canonicalisation that produces receipt_hash and compare it with the entry for this role in the source receipt’s `views` block.",
 "derived_from": {
  "receipt_hash": "sha256:02be618b5d00cceb6f837bb29494c14973458076fd7998398a8daea7165ae8b4",
  "entry_hash": "sha256:6b9124406ee627da802b075c8ef55df54ffc8320e20937b2d1f1038d286feefb",
  "issued_at": "2026-08-08T16:00:00.000Z"
 },
 "view_digest": "sha256:2add4b14ddb2392c2c4d09321c6ced764a745b025d71efa72f63735d23bca1f1",
 "withheld": {
  "anything_withheld": true,
  "note": "Facts outside this role’s remit were removed. That something was removed is stated so a partial record is never mistaken for a complete one. How much, and what, is not stated — a count is an inference about the part you are not entitled to see."
 },
 "view": {
  "spec": "urn:ietf:params:corobate:receipt:1",
  "receipt_version": "1.8",
  "issued_at": "2026-08-08T16:00:00.000Z",
  "decision": {
   "id": "ai_TRIAGE_EVIDENCE_CORROBORATION_ONLY",
   "domain": "supply-chain",
   "subject": "ai-system:TRIAGE-ASSISTANT-V4",
   "question": "May this quarter's vulnerability triage be accepted as the record of review?"
  },
  "memory": {
   "state_digest": "sha256:9357ab4d994dcd108cd3f22257927b155d8e44f669c5c0bb8d3e9bfc6be9e52a",
   "ledger_head": "sha256:b037093616312675fb7422882b44889dba9f936590214cd993c2e391b7f121c9",
   "coverage_gaps": [
    "ai-system:TRIAGE-ASSISTANT-V4|vulnerability_triage_disposition"
   ],
   "exposure": {
    "usd": 250000,
    "declared_by": "actor:human:issm",
    "ledger_seq": 4
   },
   "policy_digest": "sha256:a6b69b7d20f7fb04d522364af1d92992058b04a5835fcec9d1c9f2261c7ef636"
  },
  "data_horizon": "2026-08-08T16:00:00.000Z",
  "verdict": {
   "value": "WITHHELD",
   "threshold_approve": 0.85,
   "threshold_caution": 0.6,
   "rule": "confidence>=threshold"
  },
  "confidence": {
   "value": 0,
   "method": "min-over-critical-inputs",
   "bound_by": "ai-system:TRIAGE-ASSISTANT-V4::vulnerability_triage_disposition"
  },
  "release": {
   "required": false,
   "required_by_tier": false,
   "escalated_by_acceptance": false,
   "risk_accepted": false,
   "state": "WITHHELD_NO_EVIDENCE",
   "code": "QUORUM_EVIDENCE_WITHHELD",
   "reason": "the evidence did not clear the threshold for this exposure, so there is nothing to release. Signatures do not substitute for evidence, and this state is deliberately distinct from WITHHELD_PENDING_SIGNATURES: a reader must be able to tell \"the evidence is not there\" from \"the evidence is there and 0 of 2 people have signed\".",
   "tier_floor_cents": 1000000000,
   "exposure_usd_cents": 25000000,
   "required_m": 2,
   "declared_n": 3,
   "floor_m": 2,
   "distinct_signers": 0,
   "superseded": 0,
   "collapsed": 0,
   "release_digest": "sha256:2e954dcf94eabc7d1a96c41ff856217c64f65ad722b43bccaaf61e5de35dbe1d",
   "governance_digest": "sha256:8b0a45a27fcce9c1c243c764e855e67c6fe6dfd7f02a563bd90809b419731905",
   "governance_signed": true,
   "counted_voices": [],
   "signatures": [],
   "ledger_seq": null
  },
  "acceptance": {
   "state": "NONE",
   "code": "ACCEPTANCE_NONE",
   "reason": "no risk acceptance was presented for this decision. This is the ordinary case: a refusal is a refusal unless a named person has priced it.",
   "permitted_basis": null,
   "presented": 0,
   "superseded": 0,
   "expired": 0,
   "gaps_not_covered": 0,
   "coverage_gaps_in_force": [
    "ai-system:TRIAGE-ASSISTANT-V4|vulnerability_triage_disposition"
   ],
   "evidentiary_digest": "sha256:2e954dcf94eabc7d1a96c41ff856217c64f65ad722b43bccaaf61e5de35dbe1d",
   "margin_floor_bp": 100,
   "authority_ceiling_cents": {
    "SUPERVISOR": 1000000,
    "MANAGER": 25000000,
    "DIRECTOR": 500000000,
    "OFFICER": 5000000000
   },
   "acceptances": [],
   "escalated": false,
   "live": false,
   "ledger_seq": null
  },
  "regulatory": {
   "spec": "corobate:regulatory:2",
   "resolved": true,
   "applied": [
    {
     "instrument_id": "enterprise-ai-evidence-standard",
     "version": 1,
     "authority": "Office of the Chief Information Security Officer",
     "instrument": "Enterprise standard on machine-generated evidence",
     "edition": "2026-03-01",
     "citation": "§ 3 [VERIFY]",
     "source_digest": "sha256:e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5",
     "entered_by": "actor:human:issm",
     "entered_at": "2026-08-08T16:00:00.000Z"
    },
    {
     "instrument_id": "nist-sp-800-53r5-moderate",
     "version": 5,
     "authority": "National Institute of Standards and Technology",
     "instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
     "edition": "Rev. 5",
     "citation": "CA-2, CA-8, RA-5, SR-6 [VERIFY]",
     "source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353",
     "entered_by": "actor:human:issm",
     "entered_at": "2026-08-08T16:00:00.000Z"
    }
   ],
   "skipped": [],
   "conflicts": [],
   "bindings": [
    {
     "claim": "control_assessment",
     "requirement": "max_age_days",
     "value": 365,
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
      "instrument_id": "nist-sp-800-53r5-moderate",
      "version": 5,
      "edition": "Rev. 5",
      "citation": "CA-2 [VERIFY]",
      "source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "control_assessment",
     "requirement": "min_class",
     "value": "VERIFIED",
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
      "instrument_id": "nist-sp-800-53r5-moderate",
      "version": 5,
      "edition": "Rev. 5",
      "citation": "CA-2(1) independent assessors [VERIFY]",
      "source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "control_assessment",
     "requirement": "required",
     "value": true,
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
      "instrument_id": "nist-sp-800-53r5-moderate",
      "version": 5,
      "edition": "Rev. 5",
      "citation": "CA-2 [VERIFY]",
      "source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "penetration_test",
     "requirement": "min_class",
     "value": "VERIFIED",
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
      "instrument_id": "nist-sp-800-53r5-moderate",
      "version": 5,
      "edition": "Rev. 5",
      "citation": "CA-8(1) independent penetration agent [VERIFY]",
      "source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "penetration_test",
     "requirement": "required",
     "value": true,
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
      "instrument_id": "nist-sp-800-53r5-moderate",
      "version": 5,
      "edition": "Rev. 5",
      "citation": "CA-8 [VERIFY]",
      "source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "vulnerability_scan",
     "requirement": "max_age_days",
     "value": 30,
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
      "instrument_id": "nist-sp-800-53r5-moderate",
      "version": 5,
      "edition": "Rev. 5",
      "citation": "RA-5(a) [VERIFY]",
      "source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "vulnerability_scan",
     "requirement": "required",
     "value": true,
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
      "instrument_id": "nist-sp-800-53r5-moderate",
      "version": 5,
      "edition": "Rev. 5",
      "citation": "RA-5 [VERIFY]",
      "source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "vulnerability_triage_disposition",
     "requirement": "ai_position",
     "value": "CORROBORATION_ONLY",
     "bound_by": {
      "authority": "Office of the Chief Information Security Officer",
      "instrument": "Enterprise standard on machine-generated evidence",
      "instrument_id": "enterprise-ai-evidence-standard",
      "version": 1,
      "edition": "2026-03-01",
      "citation": "§ 3.4 [VERIFY]",
      "source_digest": "sha256:e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "vulnerability_triage_disposition",
     "requirement": "required",
     "value": true,
     "bound_by": {
      "authority": "Office of the Chief Information Security Officer",
      "instrument": "Enterprise standard on machine-generated evidence",
      "instrument_id": "enterprise-ai-evidence-standard",
      "version": 1,
      "edition": "2026-03-01",
      "citation": "§ 3.1 [VERIFY]",
      "source_digest": "sha256:e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    }
   ],
   "defaults": [
    {
     "claim": "control_assessment",
     "requirement": "ai_position",
     "value": "ADMIT",
     "because": "No instrument in force stated a position on AI-authored evidence for \"control_assessment\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
    },
    {
     "claim": "penetration_test",
     "requirement": "ai_position",
     "value": "ADMIT",
     "because": "No instrument in force stated a position on AI-authored evidence for \"penetration_test\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
    },
    {
     "claim": "vulnerability_scan",
     "requirement": "ai_position",
     "value": "ADMIT",
     "because": "No instrument in force stated a position on AI-authored evidence for \"vulnerability_scan\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
    }
   ]
  },
  "reasons": [
   "Coverage gap: no admissible memory for required claim(s) ai-system:TRIAGE-ASSISTANT-V4|vulnerability_triage_disposition.",
   "Confidence 0.00% is bound by \"ai-system:TRIAGE-ASSISTANT-V4|vulnerability_triage_disposition\".",
   "1 memory was withheld from the context block: ai-system:TRIAGE-ASSISTANT-V4|vulnerability_triage_disposition (AI-authored and standing alone: the authority binding this claim admits model output as corroboration but not as the whole of it, and nothing else that survived on this decision — no separate admissible record and no counted corroboration from a party that is not itself a model — carries \"ai-system:TRIAGE-ASSISTANT-V4|vulnerability_triage_disposition\". A model agreeing with nothing is not corroboration, and a model agreeing with a record this decision has itself refused is agreeing with nothing.).",
   "Thresholds for $250,000 exposure: approve 85%, caution 60%."
  ],
  "inputs": [
   {
    "key": "ai-system:TRIAGE-ASSISTANT-V4::vulnerability_scan",
    "value": "clean-at-scan",
    "provenance": "VERIFIED",
    "source": "nvd-cve:vulnerability_scan",
    "observed_at": "2026-08-04T16:00:00.000Z",
    "reliability": 0.95,
    "critical": true,
    "memory_status": "admitted",
    "memory_kind": "status",
    "memory_actor": "actor:sys:registry:nvd-cve",
    "memory_age_days": 4
   },
   {
    "key": "ai-system:TRIAGE-ASSISTANT-V4::penetration_test",
    "value": "no-critical",
    "provenance": "VERIFIED",
    "source": "LAB-NVLAP-0412:penetration_test",
    "observed_at": "2026-06-09T16:00:00.000Z",
    "reliability": 0.95,
    "critical": true,
    "memory_status": "admitted",
    "memory_kind": "test_report",
    "memory_actor": "actor:org:LAB-NVLAP-0412",
    "memory_age_days": 60
   },
   {
    "key": "ai-system:TRIAGE-ASSISTANT-V4::control_assessment",
    "value": "satisfied",
    "provenance": "VERIFIED",
    "source": "CERT-3PAO-ATLANTIC:control_assessment",
    "observed_at": "2026-04-30T16:00:00.000Z",
    "reliability": 0.95,
    "critical": true,
    "memory_status": "admitted",
    "memory_kind": "certificate",
    "memory_actor": "actor:org:CERT-3PAO-ATLANTIC",
    "memory_age_days": 100
   },
   {
    "key": "ai-system:TRIAGE-ASSISTANT-V4::vulnerability_triage_disposition",
    "value": null,
    "provenance": "MODELED",
    "source": "triage-assistant-v4:vulnerability_triage_disposition",
    "observed_at": "2026-08-05T16:00:00.000Z",
    "reliability": 0.8,
    "critical": false,
    "memory_status": "withheld",
    "memory_kind": "status",
    "memory_actor": "actor:ai:triage-assistant-v4",
    "memory_age_days": 3
   },
   {
    "key": "ai-system:TRIAGE-ASSISTANT-V4::vulnerability_triage_disposition",
    "value": null,
    "provenance": "MISSING",
    "source": null,
    "observed_at": "2026-08-08T16:00:00.000Z",
    "reliability": 0,
    "critical": true,
    "memory_status": "coverage_gap"
   }
  ],
  "crypto_suite": {
   "spec": "corobate:suite:1",
   "id": "CB-1-ES256-SHA256",
   "receipt_digest": "sha256",
   "chain_digest": "sha256",
   "content_digest": "sha256",
   "envelope_signature": "ES256",
   "signature_curve": "P-256",
   "canonicalisation": "attest-canon/2",
   "quantum_resistant": false
  }
 }
}

Authorising official (signer)

The named official whose signature carries the authorisation decision.

What is at stake, what the evidence supports, what is missing, and the digest they are signing over.

You are being asked to sign

May this quarter's vulnerability triage be accepted as the record of review?

At stake$250,000
Evidence saysWITHHELD
Release stateWITHHELD_NO_EVIDENCE
signing over evidentiary digest sha256:2e954dcf94eabc7d1a96c41ff856217c64f65ad722b43bccaaf61e5de35dbe1d

The signature is over the STATE OF THE EVIDENCE. Move one fact behind this decision and the digest moves and the signature stops counting — which is what makes it safe to collect signatures before everyone is in the room.

What is missing

  • vulnerability triage disposition
The scoped copy itself — partial — something outside this role’s remit was removed
FAITHFUL digest sha256:85e61bf3fe99a19483e9bbbcf158e87bb0c8720fb95b1bf73a2c039ee733096a matches the commitment sealed in the receipt.
{
 "spec": "corobate:role-view:2",
 "role": "EXECUTIVE",
 "purpose": "A named signer on the release gate. Sees what is at stake, what the evidence supports, who else has signed and what they are being asked to sign over.",
 "is_a_receipt": false,
 "warning": "This is a SCOPED COPY of a sealed decision, not the decision record itself. It will not verify as a receipt and must not be presented as one. To confirm it is faithful, recompute its `view` digest under the same canonicalisation that produces receipt_hash and compare it with the entry for this role in the source receipt’s `views` block.",
 "derived_from": {
  "receipt_hash": "sha256:02be618b5d00cceb6f837bb29494c14973458076fd7998398a8daea7165ae8b4",
  "entry_hash": "sha256:6b9124406ee627da802b075c8ef55df54ffc8320e20937b2d1f1038d286feefb",
  "issued_at": "2026-08-08T16:00:00.000Z"
 },
 "view_digest": "sha256:85e61bf3fe99a19483e9bbbcf158e87bb0c8720fb95b1bf73a2c039ee733096a",
 "withheld": {
  "anything_withheld": true,
  "note": "Facts outside this role’s remit were removed. That something was removed is stated so a partial record is never mistaken for a complete one. How much, and what, is not stated — a count is an inference about the part you are not entitled to see."
 },
 "view": {
  "spec": "urn:ietf:params:corobate:receipt:1",
  "receipt_version": "1.8",
  "issued_at": "2026-08-08T16:00:00.000Z",
  "decision": {
   "id": "ai_TRIAGE_EVIDENCE_CORROBORATION_ONLY",
   "domain": "supply-chain",
   "subject": "ai-system:TRIAGE-ASSISTANT-V4",
   "question": "May this quarter's vulnerability triage be accepted as the record of review?"
  },
  "memory": {
   "state_digest": "sha256:9357ab4d994dcd108cd3f22257927b155d8e44f669c5c0bb8d3e9bfc6be9e52a",
   "ledger_head": "sha256:b037093616312675fb7422882b44889dba9f936590214cd993c2e391b7f121c9",
   "coverage_gaps": [
    "ai-system:TRIAGE-ASSISTANT-V4|vulnerability_triage_disposition"
   ],
   "exposure": {
    "usd": 250000,
    "declared_by": "actor:human:issm",
    "ledger_seq": 4
   }
  },
  "verdict": {
   "value": "WITHHELD",
   "threshold_approve": 0.85,
   "threshold_caution": 0.6,
   "rule": "confidence>=threshold"
  },
  "confidence": {
   "value": 0,
   "method": "min-over-critical-inputs",
   "bound_by": "ai-system:TRIAGE-ASSISTANT-V4::vulnerability_triage_disposition"
  },
  "release": {
   "required": false,
   "required_by_tier": false,
   "escalated_by_acceptance": false,
   "risk_accepted": false,
   "state": "WITHHELD_NO_EVIDENCE",
   "code": "QUORUM_EVIDENCE_WITHHELD",
   "reason": "the evidence did not clear the threshold for this exposure, so there is nothing to release. Signatures do not substitute for evidence, and this state is deliberately distinct from WITHHELD_PENDING_SIGNATURES: a reader must be able to tell \"the evidence is not there\" from \"the evidence is there and 0 of 2 people have signed\".",
   "tier_floor_cents": 1000000000,
   "exposure_usd_cents": 25000000,
   "required_m": 2,
   "declared_n": 3,
   "floor_m": 2,
   "distinct_signers": 0,
   "superseded": 0,
   "collapsed": 0,
   "release_digest": "sha256:2e954dcf94eabc7d1a96c41ff856217c64f65ad722b43bccaaf61e5de35dbe1d",
   "governance_digest": "sha256:8b0a45a27fcce9c1c243c764e855e67c6fe6dfd7f02a563bd90809b419731905",
   "governance_signed": true,
   "counted_voices": [],
   "signatures": [],
   "ledger_seq": null
  },
  "acceptance": {
   "state": "NONE",
   "code": "ACCEPTANCE_NONE",
   "reason": "no risk acceptance was presented for this decision. This is the ordinary case: a refusal is a refusal unless a named person has priced it.",
   "permitted_basis": null,
   "presented": 0,
   "superseded": 0,
   "expired": 0,
   "gaps_not_covered": 0,
   "coverage_gaps_in_force": [
    "ai-system:TRIAGE-ASSISTANT-V4|vulnerability_triage_disposition"
   ],
   "evidentiary_digest": "sha256:2e954dcf94eabc7d1a96c41ff856217c64f65ad722b43bccaaf61e5de35dbe1d",
   "margin_floor_bp": 100,
   "authority_ceiling_cents": {
    "SUPERVISOR": 1000000,
    "MANAGER": 25000000,
    "DIRECTOR": 500000000,
    "OFFICER": 5000000000
   },
   "acceptances": [],
   "escalated": false,
   "live": false,
   "ledger_seq": null
  },
  "reasons": [
   "Coverage gap: no admissible memory for required claim(s) ai-system:TRIAGE-ASSISTANT-V4|vulnerability_triage_disposition.",
   "Confidence 0.00% is bound by \"ai-system:TRIAGE-ASSISTANT-V4|vulnerability_triage_disposition\".",
   "1 memory was withheld from the context block: ai-system:TRIAGE-ASSISTANT-V4|vulnerability_triage_disposition (AI-authored and standing alone: the authority binding this claim admits model output as corroboration but not as the whole of it, and nothing else that survived on this decision — no separate admissible record and no counted corroboration from a party that is not itself a model — carries \"ai-system:TRIAGE-ASSISTANT-V4|vulnerability_triage_disposition\". A model agreeing with nothing is not corroboration, and a model agreeing with a record this decision has itself refused is agreeing with nothing.).",
   "Thresholds for $250,000 exposure: approve 85%, caution 60%."
  ],
  "regulatory": {
   "applied": [
    {
     "instrument_id": "enterprise-ai-evidence-standard",
     "version": 1,
     "authority": "Office of the Chief Information Security Officer",
     "instrument": "Enterprise standard on machine-generated evidence",
     "edition": "2026-03-01",
     "citation": "§ 3 [VERIFY]",
     "source_digest": "sha256:e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5",
     "entered_by": "actor:human:issm",
     "entered_at": "2026-08-08T16:00:00.000Z"
    },
    {
     "instrument_id": "nist-sp-800-53r5-moderate",
     "version": 5,
     "authority": "National Institute of Standards and Technology",
     "instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
     "edition": "Rev. 5",
     "citation": "CA-2, CA-8, RA-5, SR-6 [VERIFY]",
     "source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353",
     "entered_by": "actor:human:issm",
     "entered_at": "2026-08-08T16:00:00.000Z"
    }
   ],
   "conflicts": [],
   "defaults": [
    {
     "claim": "control_assessment",
     "requirement": "ai_position",
     "value": "ADMIT",
     "because": "No instrument in force stated a position on AI-authored evidence for \"control_assessment\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
    },
    {
     "claim": "penetration_test",
     "requirement": "ai_position",
     "value": "ADMIT",
     "because": "No instrument in force stated a position on AI-authored evidence for \"penetration_test\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
    },
    {
     "claim": "vulnerability_scan",
     "requirement": "ai_position",
     "value": "ADMIT",
     "because": "No instrument in force stated a position on AI-authored evidence for \"vulnerability_scan\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
    }
   ]
  },
  "inputs": [
   {
    "key": "ai-system:TRIAGE-ASSISTANT-V4::vulnerability_scan",
    "provenance": "VERIFIED",
    "reliability": 0.95,
    "critical": true,
    "memory_status": "admitted"
   },
   {
    "key": "ai-system:TRIAGE-ASSISTANT-V4::penetration_test",
    "provenance": "VERIFIED",
    "reliability": 0.95,
    "critical": true,
    "memory_status": "admitted"
   },
   {
    "key": "ai-system:TRIAGE-ASSISTANT-V4::control_assessment",
    "provenance": "VERIFIED",
    "reliability": 0.95,
    "critical": true,
    "memory_status": "admitted"
   },
   {
    "key": "ai-system:TRIAGE-ASSISTANT-V4::vulnerability_triage_disposition",
    "provenance": "MODELED",
    "reliability": 0.8,
    "critical": false,
    "memory_status": "withheld"
   },
   {
    "key": "ai-system:TRIAGE-ASSISTANT-V4::vulnerability_triage_disposition",
    "provenance": "MISSING",
    "reliability": 0,
    "critical": true,
    "memory_status": "coverage_gap"
   }
  ]
 }
}

Independent audit / IG

Internal audit, an inspector general, or an external auditor testing the programme.

Everything, plus the verifier’s own findings over the sealed record.

This view withholds nothing. What it adds is the 22 checks the published verifier ran over the sealed record behind every other view of this decision — recomputed at build time, not asserted.

#CheckDetail
1Content reproduces (JCS + SHA-256)PASSmatches sha256:02be618b5d00cceb6f837bb29494c14973458076fd7998398a8daea7165ae8b4
2Hash chain links (entry = H(prev||content))PASShead sha256:6b9124406ee627da802b075c8ef55df54ffc8320e20937b2d1f1038d286feefb
3Confidence gated by weakest critical inputPASSmin over critical = 0, bound_by ai-system:TRIAGE-ASSISTANT-V4::vulnerability_triage_disposition (MISSING)
3bVerdict follows the threshold rulePASS0 => WITHHELD; recorded WITHHELD
4Point-in-time seal (no input past data_horizon)PASSall inputs <= 2026-08-08T16:00:00.000Z
5Anchor covers the head, and the timestamp token re-readsPASSinternally consistent; NO external anchor was requested — this is not a validated timestamp
6Criteria travel with the receipt and reproducePASSpolicy_body hashes to sha256:a6b69b7d20f7fb04d522364af1d92992058b04a5835fcec9d1c9f2261c7ef636
7Reliability re-derives from recorded evidencePASSall 5 inputs re-derive exactly
8Outcome trials and lineage discounts re-derivePASS4 input(s) re-derive: 0 credited outcome trial(s), 0 lineage-discounted corroboration(s); every reliability is at or under its class ceiling
9Re-ingested receipts respect their weakest-input ceilingPASSno re-ingested receipts: every input rests on a primary observation
10Release quorum re-derivesPASSWITHHELD_NO_EVIDENCE - below the top exposure tier, no multi-party requirement applies
11Risk acceptance re-derivesPASSno risk acceptance: this decision stands or falls on its evidence
12Observer credentials were not revoked as of observation timePASSrevocation list 5 (0 entries, issued 2026-08-06T00:00:00.000Z, next update due 2026-08-13T00:00:00.000Z) reproduces; 4 observer signature(s) judged as of their own instant, none under a key revoked as compromised or retired by then
13The cryptographic suite is named and is one this verifier implementsPASSsealed under CB-1-ES256-SHA256 (ES256 / sha256, attest-canon/2); this verifier implements it; the suite states it is NOT quantum resistant
14Regulatory bindings are attributed and were enforcedPASS9 binding(s) from 2 instrument(s) in force, each attributed to an authority, a citation and a document digest; 4 required claim(s) all reached the gate
15Role-view commitments re-derive, and the customs view carries no moneyPASS6 role-view commitment(s) re-derived from this receipt’s own body by this verifier’s independent projection; the REGULATOR view carries no commercial figure
16AI-authored input was admitted only where an authority allowed itPASS1 claim(s) carry a position on AI-authored evidence set by an authority and 3 carry a recorded default nobody set; 0 exclusion(s) and 0 corroboration-only rule(s) re-derived against this receipt's own admitted inputs; 0 admitted input(s) are AI-authored by their enrolled identity
17State digest recomputes from the ledger aloneUNVERIFIABLENOT APPLICABLE — you supplied no ledger, so the state digest cannot be re-derived from anything. This receipt commits to the corpus the deciding system held at the instant it sealed, and that commitment is checked by recomputing it from the append-only ledger and comparing; with no ledger in hand there is no second artefact to recompute from. The receipt is not at fault and nothing here is missing from it. Obtain the ledger from the issuer and re-run with --ledger <file>, or verifyReceipt(r, {ledger}). Nothing here has failed and nothing here has passed.
18Registry membership re-derives for every key relied onPASSall 4 key(s) relied on re-derive to the entries root registry v3 committed to and the trust root signed
20Geometric support re-derives, and an unevaluated record is not a supported onePASSno authority bound a metric to any claim on this receipt, so no geometric test applied. A claim nobody bound a metric to is not a claim about geometry, and this is a stated absence rather than a silent one
19The cause of every uncovered requirement re-derivesPASSall 1 uncovered requirement(s) re-derive their cause from this receipt's own rows. What notice is ADEQUATE is not decided here: this check establishes what the record says and that the record agrees with itself.
21The sealing party is the one you were told to expectUNVERIFIABLENOT APPLICABLE — you supplied no trust bundle, so nothing here establishes who sealed this. Identities 1 to 20 prove that this document agrees with itself; not one of them asks whose trust root it was sealed under, and a document that agrees with itself about a decision nobody made agrees with itself perfectly. Obtain the issuer's corobate:trust-bundle:1 out of band, confirm its spoken fingerprint with them by voice, and re-run with --trust-bundle <file> --expect-fingerprint <what you heard>. Nothing here has failed and nothing here has passed.
The scoped copy itself — complete for this role
FAITHFUL digest sha256:2e0e9d01c728e141bdde2dd5deffaedcecfc0aae1ac876ff7167bc0588ab10c9 matches the commitment sealed in the receipt.
{
 "spec": "corobate:role-view:2",
 "role": "AUDITOR",
 "purpose": "An external assessor. Sees the complete sealed record: this view withholds nothing and exists so the identity case is a case rather than an exception.",
 "is_a_receipt": false,
 "warning": "This is a SCOPED COPY of a sealed decision, not the decision record itself. It will not verify as a receipt and must not be presented as one. To confirm it is faithful, recompute its `view` digest under the same canonicalisation that produces receipt_hash and compare it with the entry for this role in the source receipt’s `views` block.",
 "derived_from": {
  "receipt_hash": "sha256:02be618b5d00cceb6f837bb29494c14973458076fd7998398a8daea7165ae8b4",
  "entry_hash": "sha256:6b9124406ee627da802b075c8ef55df54ffc8320e20937b2d1f1038d286feefb",
  "issued_at": "2026-08-08T16:00:00.000Z"
 },
 "view_digest": "sha256:2e0e9d01c728e141bdde2dd5deffaedcecfc0aae1ac876ff7167bc0588ab10c9",
 "withheld": {
  "anything_withheld": false,
  "note": "Nothing outside the seal was removed for this role."
 },
 "view": {
  "spec": "urn:ietf:params:corobate:receipt:1",
  "receipt_version": "1.8",
  "engine": {
   "name": "corobate-memory",
   "version": "1.0.0"
  },
  "decision": {
   "id": "ai_TRIAGE_EVIDENCE_CORROBORATION_ONLY",
   "domain": "supply-chain",
   "subject": "ai-system:TRIAGE-ASSISTANT-V4",
   "question": "May this quarter's vulnerability triage be accepted as the record of review?"
  },
  "issued_at": "2026-08-08T16:00:00.000Z",
  "data_horizon": "2026-08-08T16:00:00.000Z",
  "inputs": [
   {
    "key": "ai-system:TRIAGE-ASSISTANT-V4::vulnerability_scan",
    "value": "clean-at-scan",
    "provenance": "VERIFIED",
    "source": "nvd-cve:vulnerability_scan",
    "observed_at": "2026-08-04T16:00:00.000Z",
    "last_corroborated_at": null,
    "memory_refreshed_by": [],
    "reliability": 0.95,
    "critical": true,
    "memory_id": "mem_4d2b1fc0d322",
    "memory_status": "admitted",
    "memory_kind": "status",
    "memory_actor": "actor:sys:registry:nvd-cve",
    "memory_age_days": 4,
    "memory_track": {
     "n": 1,
     "successes": 1
    },
    "memory_promoted_by": [],
    "memory_content_digest": "sha256:aea4c3860d57b3edd045cd33946015c41ff1aee9cc8a4df49f26d8a5165d4a38",
    "memory_outcomes": {
     "verified": 0,
     "falsified": 0,
     "modified": 0,
     "counted": 0,
     "recorded": 0
    },
    "memory_outcome_attestations": [],
    "memory_observer_lineage": null,
    "memory_corroborations": [],
    "memory_reingest": null,
    "memory_reasons": [
     "sparse track record: 1 independent observation(s); no failure recorded, so the class ceiling stands"
    ],
    "memory_class_floor": null,
    "memory_below_class_floor": false,
    "memory_not_attested": false,
    "memory_below_claim_reliability_floor": false,
    "memory_not_competent_authority": false,
    "memory_out_of_specification": false,
    "memory_ai_authored": false,
    "memory_ai_in_lineage": false,
    "memory_ai_position": "ADMIT",
    "memory_ai_inadmissible": false,
    "memory_geo_inadmissible": false,
    "memory_geo_rung": null,
    "memory_geo_metric": null,
    "memory_geo_required_metric": null,
    "observer_attested": true,
    "observer_auth_code": "VERIFIED",
    "observer_key_id": "k_5873dd9e7169def3",
    "attestation": null,
    "derivation": {
     "provenance": "VERIFIED",
     "ceiling_bp": 9500,
     "track": {
      "n": 1,
      "successes": 1
     },
     "wilson_bp": null,
     "age_days": 4,
     "max_age_days": 14,
     "house_max_age_days": 14,
     "instrument_max_age_days": 30,
     "freshness_cap_bp": 4000,
     "min_track_n": 5,
     "wilson_z_milli": 1960,
     "source_present": true,
     "seller_asserted_cap_bp": 5000,
     "retracted": false,
     "contradicted": false,
     "outcome_trials": 0,
     "outcomes": {
      "verified": 0,
      "falsified": 0,
      "modified": 0,
      "counted": 0,
      "recorded": 0
     },
     "corroborations_counted": 0,
     "corroborations_discounted": 0,
     "reingest_ceiling_bp": null,
     "reingest_depth": null,
     "reingest_weakest_class": null,
     "reingest_source_confidence_bp": null,
     "ai_authored": false,
     "ai_authored_because": null,
     "ai_in_lineage": false,
     "ai_position": "ADMIT"
    },
    "memory_reason_codes": [
     {
      "code": "SPARSE_TRACK_RECORD",
      "observed": 1,
      "limit": 5,
      "binding": false
     }
    ],
    "context_line": "[VERIFIED · r=95.0% · 4d · nvd-cve:vulnerability_scan] ai-system:TRIAGE-ASSISTANT-V4 / vulnerability_scan: clean-at-scan"
   },
   {
    "key": "ai-system:TRIAGE-ASSISTANT-V4::penetration_test",
    "value": "no-critical",
    "provenance": "VERIFIED",
    "source": "LAB-NVLAP-0412:penetration_test",
    "observed_at": "2026-06-09T16:00:00.000Z",
    "last_corroborated_at": null,
    "memory_refreshed_by": [],
    "reliability": 0.95,
    "critical": true,
    "memory_id": "mem_a3316d633bfe",
    "memory_status": "admitted",
    "memory_kind": "test_report",
    "memory_actor": "actor:org:LAB-NVLAP-0412",
    "memory_age_days": 60,
    "memory_track": {
     "n": 1,
     "successes": 1
    },
    "memory_promoted_by": [],
    "memory_content_digest": "sha256:db69fb062be9b066b370c668281e12896da2869456a2e6d356a0f14879b27de9",
    "memory_outcomes": {
     "verified": 0,
     "falsified": 0,
     "modified": 0,
     "counted": 0,
     "recorded": 0
    },
    "memory_outcome_attestations": [],
    "memory_observer_lineage": null,
    "memory_corroborations": [],
    "memory_reingest": null,
    "memory_reasons": [
     "sparse track record: 1 independent observation(s); no failure recorded, so the class ceiling stands"
    ],
    "memory_class_floor": "VERIFIED",
    "memory_below_class_floor": false,
    "memory_not_attested": false,
    "memory_below_claim_reliability_floor": false,
    "memory_not_competent_authority": false,
    "memory_out_of_specification": false,
    "memory_ai_authored": false,
    "memory_ai_in_lineage": false,
    "memory_ai_position": "ADMIT",
    "memory_ai_inadmissible": false,
    "memory_geo_inadmissible": false,
    "memory_geo_rung": null,
    "memory_geo_metric": null,
    "memory_geo_required_metric": null,
    "observer_attested": true,
    "observer_auth_code": "VERIFIED",
    "observer_key_id": "k_17d23885943ae529",
    "attestation": null,
    "derivation": {
     "provenance": "VERIFIED",
     "ceiling_bp": 9500,
     "track": {
      "n": 1,
      "successes": 1
     },
     "wilson_bp": null,
     "age_days": 60,
     "max_age_days": 180,
     "house_max_age_days": 180,
     "instrument_max_age_days": null,
     "freshness_cap_bp": 4000,
     "min_track_n": 5,
     "wilson_z_milli": 1960,
     "source_present": true,
     "seller_asserted_cap_bp": 5000,
     "retracted": false,
     "contradicted": false,
     "outcome_trials": 0,
     "outcomes": {
      "verified": 0,
      "falsified": 0,
      "modified": 0,
      "counted": 0,
      "recorded": 0
     },
     "corroborations_counted": 0,
     "corroborations_discounted": 0,
     "reingest_ceiling_bp": null,
     "reingest_depth": null,
     "reingest_weakest_class": null,
     "reingest_source_confidence_bp": null,
     "min_class_floor": "VERIFIED",
     "ai_authored": false,
     "ai_authored_because": null,
     "ai_in_lineage": false,
     "ai_position": "ADMIT"
    },
    "memory_reason_codes": [
     {
      "code": "SPARSE_TRACK_RECORD",
      "observed": 1,
      "limit": 5,
      "binding": false
     }
    ],
    "context_line": "[VERIFIED · r=95.0% · 60d · LAB-NVLAP-0412:penetration_test] ai-system:TRIAGE-ASSISTANT-V4 / penetration_test: no-critical"
   },
   {
    "key": "ai-system:TRIAGE-ASSISTANT-V4::control_assessment",
    "value": "satisfied",
    "provenance": "VERIFIED",
    "source": "CERT-3PAO-ATLANTIC:control_assessment",
    "observed_at": "2026-04-30T16:00:00.000Z",
    "last_corroborated_at": null,
    "memory_refreshed_by": [],
    "reliability": 0.95,
    "critical": true,
    "memory_id": "mem_a153eb336060",
    "memory_status": "admitted",
    "memory_kind": "certificate",
    "memory_actor": "actor:org:CERT-3PAO-ATLANTIC",
    "memory_age_days": 100,
    "memory_track": {
     "n": 1,
     "successes": 1
    },
    "memory_promoted_by": [],
    "memory_content_digest": "sha256:c1aaf46a55b4cdc629a754ac35da1b8ec4dec85c2c78613c7bc93546b63f233c",
    "memory_outcomes": {
     "verified": 0,
     "falsified": 0,
     "modified": 0,
     "counted": 0,
     "recorded": 0
    },
    "memory_outcome_attestations": [],
    "memory_observer_lineage": null,
    "memory_corroborations": [],
    "memory_reingest": null,
    "memory_reasons": [
     "sparse track record: 1 independent observation(s); no failure recorded, so the class ceiling stands"
    ],
    "memory_class_floor": "VERIFIED",
    "memory_below_class_floor": false,
    "memory_not_attested": false,
    "memory_below_claim_reliability_floor": false,
    "memory_not_competent_authority": false,
    "memory_out_of_specification": false,
    "memory_ai_authored": false,
    "memory_ai_in_lineage": false,
    "memory_ai_position": "ADMIT",
    "memory_ai_inadmissible": false,
    "memory_geo_inadmissible": false,
    "memory_geo_rung": null,
    "memory_geo_metric": null,
    "memory_geo_required_metric": null,
    "observer_attested": true,
    "observer_auth_code": "VERIFIED",
    "observer_key_id": "k_307e4bfd710ec9b3",
    "attestation": null,
    "derivation": {
     "provenance": "VERIFIED",
     "ceiling_bp": 9500,
     "track": {
      "n": 1,
      "successes": 1
     },
     "wilson_bp": null,
     "age_days": 100,
     "max_age_days": 365,
     "house_max_age_days": 365,
     "instrument_max_age_days": 365,
     "freshness_cap_bp": 4000,
     "min_track_n": 5,
     "wilson_z_milli": 1960,
     "source_present": true,
     "seller_asserted_cap_bp": 5000,
     "retracted": false,
     "contradicted": false,
     "outcome_trials": 0,
     "outcomes": {
      "verified": 0,
      "falsified": 0,
      "modified": 0,
      "counted": 0,
      "recorded": 0
     },
     "corroborations_counted": 0,
     "corroborations_discounted": 0,
     "reingest_ceiling_bp": null,
     "reingest_depth": null,
     "reingest_weakest_class": null,
     "reingest_source_confidence_bp": null,
     "min_class_floor": "VERIFIED",
     "ai_authored": false,
     "ai_authored_because": null,
     "ai_in_lineage": false,
     "ai_position": "ADMIT"
    },
    "memory_reason_codes": [
     {
      "code": "SPARSE_TRACK_RECORD",
      "observed": 1,
      "limit": 5,
      "binding": false
     }
    ],
    "context_line": "[VERIFIED · r=95.0% · 100d · CERT-3PAO-ATLANTIC:control_assessment] ai-system:TRIAGE-ASSISTANT-V4 / control_assessment: satisfied"
   },
   {
    "key": "ai-system:TRIAGE-ASSISTANT-V4::vulnerability_triage_disposition",
    "value": null,
    "provenance": "MODELED",
    "source": "triage-assistant-v4:vulnerability_triage_disposition",
    "observed_at": "2026-08-05T16:00:00.000Z",
    "last_corroborated_at": null,
    "memory_refreshed_by": [],
    "reliability": 0.8,
    "critical": false,
    "memory_id": "mem_0a6980bbce9f",
    "memory_status": "withheld",
    "memory_kind": "status",
    "memory_actor": "actor:ai:triage-assistant-v4",
    "memory_age_days": 3,
    "memory_track": {
     "n": 1,
     "successes": 1
    },
    "memory_promoted_by": [],
    "memory_content_digest": "sha256:612e098189acf7652c237b016c3537b38c17d735452f4f1d519c6bfa0772b2c2",
    "memory_outcomes": {
     "verified": 0,
     "falsified": 0,
     "modified": 0,
     "counted": 0,
     "recorded": 0
    },
    "memory_outcome_attestations": [],
    "memory_observer_lineage": null,
    "memory_corroborations": [],
    "memory_reingest": null,
    "memory_reasons": [
     "AI-authored and standing alone: the authority binding this claim admits model output as corroboration but not as the whole of it, and nothing else that survived on this decision — no separate admissible record and no counted corroboration from a party that is not itself a model — carries \"ai-system:TRIAGE-ASSISTANT-V4|vulnerability_triage_disposition\". A model agreeing with nothing is not corroboration, and a model agreeing with a record this decision has itself refused is agreeing with nothing.",
     "sparse track record: 1 independent observation(s); no failure recorded, so the class ceiling stands"
    ],
    "memory_class_floor": null,
    "memory_below_class_floor": false,
    "memory_not_attested": false,
    "memory_below_claim_reliability_floor": false,
    "memory_not_competent_authority": false,
    "memory_out_of_specification": false,
    "memory_ai_authored": true,
    "memory_ai_in_lineage": false,
    "memory_ai_position": "CORROBORATION_ONLY",
    "memory_ai_inadmissible": true,
    "memory_geo_inadmissible": false,
    "memory_geo_rung": null,
    "memory_geo_metric": null,
    "memory_geo_required_metric": null,
    "observer_attested": true,
    "observer_auth_code": "VERIFIED",
    "observer_key_id": "k_f71bde46a9680d8d",
    "attestation": null,
    "derivation": {
     "provenance": "MODELED",
     "ceiling_bp": 8000,
     "track": {
      "n": 1,
      "successes": 1
     },
     "wilson_bp": null,
     "age_days": 3,
     "max_age_days": 14,
     "house_max_age_days": 14,
     "instrument_max_age_days": null,
     "freshness_cap_bp": 4000,
     "min_track_n": 5,
     "wilson_z_milli": 1960,
     "source_present": true,
     "seller_asserted_cap_bp": 5000,
     "retracted": false,
     "contradicted": false,
     "outcome_trials": 0,
     "outcomes": {
      "verified": 0,
      "falsified": 0,
      "modified": 0,
      "counted": 0,
      "recorded": 0
     },
     "corroborations_counted": 0,
     "corroborations_discounted": 0,
     "reingest_ceiling_bp": null,
     "reingest_depth": null,
     "reingest_weakest_class": null,
     "reingest_source_confidence_bp": null,
     "ai_authored": true,
     "ai_authored_because": "a model, named as one in its own enrolled identity",
     "ai_in_lineage": false,
     "ai_position": "CORROBORATION_ONLY",
     "ai_sole_basis": true
    },
    "memory_reason_codes": [
     {
      "code": "AI_SOLE_BASIS",
      "observed": "actor:ai:triage-assistant-v4",
      "limit": "CORROBORATION_ONLY",
      "binding": true
     },
     {
      "code": "SPARSE_TRACK_RECORD",
      "observed": 1,
      "limit": 5,
      "binding": false
     }
    ]
   },
   {
    "key": "ai-system:TRIAGE-ASSISTANT-V4::vulnerability_triage_disposition",
    "value": null,
    "provenance": "MISSING",
    "source": null,
    "observed_at": "2026-08-08T16:00:00.000Z",
    "reliability": 0,
    "critical": true,
    "memory_status": "coverage_gap",
    "gap_cause": "EVIDENCE_PRESENTED_FAILED",
    "gap_request": null,
    "gap_origin": "BUSINESS_EVIDENCE",
    "gap_conditions": [
     "ai_inadmissible"
    ]
   }
  ],
  "serialization": {
   "algorithm": "RFC8785-JCS",
   "hash": "sha256"
  },
  "crypto_suite": {
   "spec": "corobate:suite:1",
   "id": "CB-1-ES256-SHA256",
   "receipt_digest": "sha256",
   "chain_digest": "sha256",
   "content_digest": "sha256",
   "envelope_signature": "ES256",
   "signature_curve": "P-256",
   "canonicalisation": "attest-canon/2",
   "quantum_resistant": false
  },
  "confidence": {
   "value": 0,
   "method": "min-over-critical-inputs",
   "bound_by": "ai-system:TRIAGE-ASSISTANT-V4::vulnerability_triage_disposition"
  },
  "verdict": {
   "value": "WITHHELD",
   "threshold_approve": 0.85,
   "threshold_caution": 0.6,
   "rule": "confidence>=threshold"
  },
  "release": {
   "required": false,
   "required_by_tier": false,
   "escalated_by_acceptance": false,
   "risk_accepted": false,
   "state": "WITHHELD_NO_EVIDENCE",
   "code": "QUORUM_EVIDENCE_WITHHELD",
   "reason": "the evidence did not clear the threshold for this exposure, so there is nothing to release. Signatures do not substitute for evidence, and this state is deliberately distinct from WITHHELD_PENDING_SIGNATURES: a reader must be able to tell \"the evidence is not there\" from \"the evidence is there and 0 of 2 people have signed\".",
   "tier_floor_cents": 1000000000,
   "exposure_usd_cents": 25000000,
   "required_m": 2,
   "declared_n": 3,
   "floor_m": 2,
   "distinct_signers": 0,
   "superseded": 0,
   "collapsed": 0,
   "release_digest": "sha256:2e954dcf94eabc7d1a96c41ff856217c64f65ad722b43bccaaf61e5de35dbe1d",
   "governance_digest": "sha256:8b0a45a27fcce9c1c243c764e855e67c6fe6dfd7f02a563bd90809b419731905",
   "governance_signed": true,
   "counted_voices": [],
   "signatures": [],
   "ledger_seq": null
  },
  "acceptance": {
   "state": "NONE",
   "code": "ACCEPTANCE_NONE",
   "reason": "no risk acceptance was presented for this decision. This is the ordinary case: a refusal is a refusal unless a named person has priced it.",
   "permitted_basis": null,
   "presented": 0,
   "superseded": 0,
   "expired": 0,
   "gaps_not_covered": 0,
   "coverage_gaps_in_force": [
    "ai-system:TRIAGE-ASSISTANT-V4|vulnerability_triage_disposition"
   ],
   "evidentiary_digest": "sha256:2e954dcf94eabc7d1a96c41ff856217c64f65ad722b43bccaaf61e5de35dbe1d",
   "margin_floor_bp": 100,
   "authority_ceiling_cents": {
    "SUPERVISOR": 1000000,
    "MANAGER": 25000000,
    "DIRECTOR": 500000000,
    "OFFICER": 5000000000
   },
   "acceptances": [],
   "escalated": false,
   "live": false,
   "ledger_seq": null
  },
  "regulatory": {
   "spec": "corobate:regulatory:2",
   "resolved": true,
   "applied": [
    {
     "instrument_id": "enterprise-ai-evidence-standard",
     "version": 1,
     "authority": "Office of the Chief Information Security Officer",
     "instrument": "Enterprise standard on machine-generated evidence",
     "edition": "2026-03-01",
     "citation": "§ 3 [VERIFY]",
     "source_digest": "sha256:e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5",
     "entered_by": "actor:human:issm",
     "entered_at": "2026-08-08T16:00:00.000Z"
    },
    {
     "instrument_id": "nist-sp-800-53r5-moderate",
     "version": 5,
     "authority": "National Institute of Standards and Technology",
     "instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
     "edition": "Rev. 5",
     "citation": "CA-2, CA-8, RA-5, SR-6 [VERIFY]",
     "source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353",
     "entered_by": "actor:human:issm",
     "entered_at": "2026-08-08T16:00:00.000Z"
    }
   ],
   "skipped": [],
   "conflicts": [],
   "bindings": [
    {
     "claim": "control_assessment",
     "requirement": "max_age_days",
     "value": 365,
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
      "instrument_id": "nist-sp-800-53r5-moderate",
      "version": 5,
      "edition": "Rev. 5",
      "citation": "CA-2 [VERIFY]",
      "source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "control_assessment",
     "requirement": "min_class",
     "value": "VERIFIED",
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
      "instrument_id": "nist-sp-800-53r5-moderate",
      "version": 5,
      "edition": "Rev. 5",
      "citation": "CA-2(1) independent assessors [VERIFY]",
      "source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "control_assessment",
     "requirement": "required",
     "value": true,
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
      "instrument_id": "nist-sp-800-53r5-moderate",
      "version": 5,
      "edition": "Rev. 5",
      "citation": "CA-2 [VERIFY]",
      "source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "penetration_test",
     "requirement": "min_class",
     "value": "VERIFIED",
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
      "instrument_id": "nist-sp-800-53r5-moderate",
      "version": 5,
      "edition": "Rev. 5",
      "citation": "CA-8(1) independent penetration agent [VERIFY]",
      "source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "penetration_test",
     "requirement": "required",
     "value": true,
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
      "instrument_id": "nist-sp-800-53r5-moderate",
      "version": 5,
      "edition": "Rev. 5",
      "citation": "CA-8 [VERIFY]",
      "source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "vulnerability_scan",
     "requirement": "max_age_days",
     "value": 30,
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
      "instrument_id": "nist-sp-800-53r5-moderate",
      "version": 5,
      "edition": "Rev. 5",
      "citation": "RA-5(a) [VERIFY]",
      "source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "vulnerability_scan",
     "requirement": "required",
     "value": true,
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
      "instrument_id": "nist-sp-800-53r5-moderate",
      "version": 5,
      "edition": "Rev. 5",
      "citation": "RA-5 [VERIFY]",
      "source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "vulnerability_triage_disposition",
     "requirement": "ai_position",
     "value": "CORROBORATION_ONLY",
     "bound_by": {
      "authority": "Office of the Chief Information Security Officer",
      "instrument": "Enterprise standard on machine-generated evidence",
      "instrument_id": "enterprise-ai-evidence-standard",
      "version": 1,
      "edition": "2026-03-01",
      "citation": "§ 3.4 [VERIFY]",
      "source_digest": "sha256:e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "vulnerability_triage_disposition",
     "requirement": "required",
     "value": true,
     "bound_by": {
      "authority": "Office of the Chief Information Security Officer",
      "instrument": "Enterprise standard on machine-generated evidence",
      "instrument_id": "enterprise-ai-evidence-standard",
      "version": 1,
      "edition": "2026-03-01",
      "citation": "§ 3.1 [VERIFY]",
      "source_digest": "sha256:e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    }
   ],
   "defaults": [
    {
     "claim": "control_assessment",
     "requirement": "ai_position",
     "value": "ADMIT",
     "because": "No instrument in force stated a position on AI-authored evidence for \"control_assessment\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
    },
    {
     "claim": "penetration_test",
     "requirement": "ai_position",
     "value": "ADMIT",
     "because": "No instrument in force stated a position on AI-authored evidence for \"penetration_test\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
    },
    {
     "claim": "vulnerability_scan",
     "requirement": "ai_position",
     "value": "ADMIT",
     "because": "No instrument in force stated a position on AI-authored evidence for \"vulnerability_scan\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
    }
   ]
  },
  "reasons": [
   "Coverage gap: no admissible memory for required claim(s) ai-system:TRIAGE-ASSISTANT-V4|vulnerability_triage_disposition.",
   "Confidence 0.00% is bound by \"ai-system:TRIAGE-ASSISTANT-V4|vulnerability_triage_disposition\".",
   "1 memory was withheld from the context block: ai-system:TRIAGE-ASSISTANT-V4|vulnerability_triage_disposition (AI-authored and standing alone: the authority binding this claim admits model output as corroboration but not as the whole of it, and nothing else that survived on this decision — no separate admissible record and no counted corroboration from a party that is not itself a model — carries \"ai-system:TRIAGE-ASSISTANT-V4|vulnerability_triage_disposition\". A model agreeing with nothing is not corroboration, and a model agreeing with a record this decision has itself refused is agreeing with nothing.).",
   "Thresholds for $250,000 exposure: approve 85%, caution 60%."
  ],
  "memory": {
   "layer": "capture->store->recall->act",
   "ledger_head": "sha256:b037093616312675fb7422882b44889dba9f936590214cd993c2e391b7f121c9",
   "ledger_entries": 6,
   "context_digest": null,
   "context_memory_ids": [],
   "state_digest": "sha256:9357ab4d994dcd108cd3f22257927b155d8e44f669c5c0bb8d3e9bfc6be9e52a",
   "retrieval_method": "idf-lexical",
   "corpus_size": 4,
   "considered": 4,
   "admitted": 3,
   "withheld": 1,
   "not_considered": 0,
   "coverage_gaps": [
    "ai-system:TRIAGE-ASSISTANT-V4|vulnerability_triage_disposition"
   ],
   "exposure": {
    "usd": 250000,
    "declared_by": "actor:human:issm",
    "ledger_seq": 4
   },
   "salience_policy": {
    "half_life_days": 90,
    "grace_days": 7,
    "access_boost_bp": 500,
    "access_boost_cap_bp": 2500,
    "relevance_weight_bp": 6000,
    "recency_weight_bp": 3000,
    "usage_weight_bp": 1000,
    "context_cap": 12,
    "method": "idf-lexical",
    "candidate_list_digest": "sha256:fa532eca9f6e74d805d7557e2b12f0a9b5ac6a3262e163b632463317b542709f",
    "note": "salience orders retrieval only; it never contributes to reliability"
   },
   "policy_digest": "sha256:a6b69b7d20f7fb04d522364af1d92992058b04a5835fcec9d1c9f2261c7ef636",
   "policy_body": {
    "class_ceiling_bp": {
     "VERIFIED": 9500,
     "MODELED": 8000,
     "SELLER-ASSERTED": 5000,
     "MISSING": 0
    },
    "actor_class_ceiling": [
     [
      "^actor:ai:",
      "MODELED"
     ],
     [
      "^actor:agent:",
      "MODELED"
     ],
     [
      "^actor:human:",
      "SELLER-ASSERTED"
     ],
     [
      "^actor:org:LAB-",
      "VERIFIED"
     ],
     [
      "^actor:org:CERT-",
      "VERIFIED"
     ],
     [
      "^actor:org:",
      "SELLER-ASSERTED"
     ],
     [
      "^actor:sys:registry:",
      "VERIFIED"
     ],
     [
      "^actor:sys:sensor:",
      "VERIFIED"
     ],
     [
      "^actor:sys:",
      "MODELED"
     ]
    ],
    "freshness_cap_bp": 4000,
    "max_age_days": {
     "telemetry": 1,
     "price": 7,
     "status": 14,
     "certificate": 365,
     "test_report": 180,
     "filing": 90,
     "transcript": 120,
     "highlight": 365,
     "voice_note": 120,
     "note": 365,
     "preference": 540,
     "decision": 1825,
     "receipt": 365,
     "default": 90
    },
    "wilson_z_milli": 1960,
    "min_track_n": 5,
    "exposure_tiers_bp": [
     [
      1000000000,
      9500,
      8000
     ],
     [
      100000000,
      9000,
      7000
     ],
     [
      1000000,
      8500,
      6000
     ],
     [
      0,
      8000,
      5000
     ]
    ],
    "max_context_memories": 12,
    "contradiction_resolve_margin": 2,
    "salience": {
     "half_life_days": 90,
     "grace_days": 7,
     "access_boost_bp": 500,
     "access_boost_cap_bp": 2500,
     "relevance_weight_bp": 6000,
     "recency_weight_bp": 3000,
     "usage_weight_bp": 1000
    }
   },
   "observer_auth": {
    "mode": "required",
    "registry_version": 3,
    "registry_digest": "sha256:460aeaafe345f69542a302e6619dff0712af98de6518838ee4c8585e448c3a7d",
    "entries_root": "sha256:5670469f96484a814462814ed74f0f992b5f19e8ad6afced548e4956e4835ba5",
    "memberships": [
     {
      "key_id": "k_17d23885943ae529",
      "index": 1,
      "entry": {
       "actor": "actor:org:LAB-NVLAP-0412",
       "class": "VERIFIED",
       "kind": "org",
       "key_id": "k_17d23885943ae529",
       "jwk": {
        "kty": "EC",
        "crv": "P-256",
        "x": "3TTw47-PkYfo3ZaKTq_qtHghnGvninAVj25kyOwONno",
        "y": "16PMaR8ofeF5IcZk6ZLml8gDs8uE1s1sBLdciH5e4vg"
       },
       "valid_from": "2025-01-01T00:00:00.000Z",
       "valid_to": "2027-06-01T00:00:00.000Z"
      },
      "path": [
       {
        "side": "left",
        "sibling": "sha256:500f2ba5949d5256ae0f563530b0b270db41ce99d2d7c4b4b60e4bd558ca353d"
       },
       {
        "side": "right",
        "sibling": "sha256:a0b47ea437bf4f1042a1dd50a5a3f411f9a17971812fc6bafccd434eb7d78ccc"
       },
       {
        "side": "right",
        "sibling": "sha256:d3c2347eb675e865fc17ef0204cacda7b02e8784a811fdd1c8a015d1865e6dfb"
       },
       {
        "side": "right",
        "sibling": "sha256:7071adf5e21a94147d31f42f1028b4867b6562e5b78726259c2515b03b213e52"
       }
      ]
     },
     {
      "key_id": "k_307e4bfd710ec9b3",
      "index": 0,
      "entry": {
       "actor": "actor:org:CERT-3PAO-ATLANTIC",
       "class": "VERIFIED",
       "kind": "org",
       "key_id": "k_307e4bfd710ec9b3",
       "jwk": {
        "kty": "EC",
        "crv": "P-256",
        "x": "MGtV26TezLMPjiD3SecQtnje6eLqYyx4qkKzzAkbiY4",
        "y": "SMMdLYnn-FpKbb2sJQ8EAZnzvozNm-cGO0VbUUpniPY"
       },
       "valid_from": "2025-01-01T00:00:00.000Z",
       "valid_to": "2027-06-01T00:00:00.000Z"
      },
      "path": [
       {
        "side": "right",
        "sibling": "sha256:4148869fc259d2c5fc19fe5831065b165a9acf81812e123162035acfdecade1d"
       },
       {
        "side": "right",
        "sibling": "sha256:a0b47ea437bf4f1042a1dd50a5a3f411f9a17971812fc6bafccd434eb7d78ccc"
       },
       {
        "side": "right",
        "sibling": "sha256:d3c2347eb675e865fc17ef0204cacda7b02e8784a811fdd1c8a015d1865e6dfb"
       },
       {
        "side": "right",
        "sibling": "sha256:7071adf5e21a94147d31f42f1028b4867b6562e5b78726259c2515b03b213e52"
       }
      ]
     },
     {
      "key_id": "k_5873dd9e7169def3",
      "index": 2,
      "entry": {
       "actor": "actor:sys:registry:nvd-cve",
       "class": "VERIFIED",
       "kind": "system",
       "key_id": "k_5873dd9e7169def3",
       "jwk": {
        "kty": "EC",
        "crv": "P-256",
        "x": "O9OY6oMuJg0df_INePO19_3b11VaSyMwIPdxoqvV2ak",
        "y": "k7Orm5pxDxMdTF-H2S4h6ixRywzk1WxvquOQeqxLFx0"
       },
       "valid_from": "2025-01-01T00:00:00.000Z",
       "valid_to": "2027-06-01T00:00:00.000Z"
      },
      "path": [
       {
        "side": "right",
        "sibling": "sha256:e1fe36fe7c8e4695327c25d6d722630b6249c93293bfdc5894c58aaf961ab6f8"
       },
       {
        "side": "left",
        "sibling": "sha256:e8b9cba101f13538b909a2e686e9e6e9a8d77212036ed567eaebc205a443e83f"
       },
       {
        "side": "right",
        "sibling": "sha256:d3c2347eb675e865fc17ef0204cacda7b02e8784a811fdd1c8a015d1865e6dfb"
       },
       {
        "side": "right",
        "sibling": "sha256:7071adf5e21a94147d31f42f1028b4867b6562e5b78726259c2515b03b213e52"
       }
      ]
     },
     {
      "key_id": "k_f71bde46a9680d8d",
      "index": 7,
      "entry": {
       "actor": "actor:ai:triage-assistant-v4",
       "class": "MODELED",
       "kind": "system",
       "key_id": "k_f71bde46a9680d8d",
       "jwk": {
        "kty": "EC",
        "crv": "P-256",
        "x": "AmVfK7ltK7mprIKSXcj-PNTw4f8zq2gcbRG-qEiFmbU",
        "y": "W7sar2SHGJ_jUsBSxoasMr7l1If81Qu5BdYfvlK8Who"
       },
       "valid_from": "2025-01-01T00:00:00.000Z",
       "valid_to": "2027-06-01T00:00:00.000Z"
      },
      "path": [
       {
        "side": "left",
        "sibling": "sha256:3e8eae859976a6f7d64543a05e28b4c8fc52b8500c65decc7e124af145fac567"
       },
       {
        "side": "left",
        "sibling": "sha256:6d20941c438f3924c50e6573d0712466ec6b91655705d2603ea89981e4c50ffc"
       },
       {
        "side": "left",
        "sibling": "sha256:d3f1d60ec9478d2b69455e5ba8168897966d18429bd3b7d36105841cc2ae1776"
       },
       {
        "side": "right",
        "sibling": "sha256:7071adf5e21a94147d31f42f1028b4867b6562e5b78726259c2515b03b213e52"
       }
      ]
     }
    ],
    "memberships_unproven": [],
    "revocation": {
     "source": "SIGNED_LIST",
     "digest": "sha256:12f73b1fbf27d38cf137b86a1ce13bbcd98161123a6aa7d79b107db8189966b9",
     "sequence": 5,
     "registry_version": 3,
     "issued_at": "2026-08-06T00:00:00.000Z",
     "next_update_due": "2026-08-13T00:00:00.000Z",
     "entry_count": 0,
     "body": {
      "sequence": 5,
      "registry_version": 3,
      "issuer": {
       "name": "NIST-regulated enterprise demonstration trust root",
       "key_id": "k_3793b8e35f8acac1"
      },
      "issued_at": "2026-08-06T00:00:00.000Z",
      "next_update_due": "2026-08-13T00:00:00.000Z",
      "entries": [],
      "spec": "corobate:revocation-list:1"
     }
    }
   },
   "governance": {
    "digest": "sha256:8b0a45a27fcce9c1c243c764e855e67c6fe6dfd7f02a563bd90809b419731905",
    "signed": true,
    "actor_trust": "FLOOR_TO_SELLER_ASSERTED",
    "outcome_trial_weight": 1,
    "max_reingest_depth": 3,
    "release_quorum_m": 2,
    "release_quorum_n": 3,
    "risk_acceptance_margin_bp": 500,
    "risk_acceptance_max_days": 30,
    "risk_acceptance_authority_cents": {
     "SUPERVISOR": 1000000,
     "MANAGER": 25000000,
     "DIRECTOR": 500000000,
     "OFFICER": 5000000000
    },
    "template_author_roles": [
     "MANAGER",
     "DIRECTOR",
     "OFFICER"
    ]
   },
   "observers_attested": 3,
   "outcomes": {
    "attestations_counted": 0,
    "attestations_recorded": 0,
    "records_with_outcomes": 0
   },
   "lineage": {
    "corroborations_counted": 0,
    "corroborations_discounted": 0,
    "records_with_discounted_corroborations": 0
   },
   "reingest": {
    "records": 0,
    "max_depth": 0,
    "weakest_class": null,
    "chain_weakest_bp": 10000,
    "chain": []
   },
   "template": null
  }
 }
}

The enterprise tries the honest workaround. A sealed decision that already rested on the assistant is presented for this control by an accredited laboratory. Nothing is forged: the receipt verifies, the presenter is real, the presenter’s own class is VERIFIED. It is refused anyway, because the model is in the lineage and the strictest rung says so. Without this rung an exclusion is defeated by one round trip through a sealed receipt, which is the shape every laundering path in this system takes.

Subject
ai-system:TRIAGE-ASSISTANT-V4
Question
May this quarter's vulnerability triage be accepted as the record of review?
Exposure
$250,000
Instruments
Office of the Chief Information Security Officer · National Institute of Standards and Technology
Outcome
WITHHELD — the action is not permitted; outstanding: vulnerability triage disposition
Receipt
sha256:ee44fd0e4bc167b9c18e62720219425692aaedd851f997bc4c6971c79be02199
The gate variables this decision ran under — a dial per question, read back off the sealed receipt
control assessmentrequired
necessity
requiredNational Institute of Standards and Technology — CA-2 [VERIFY]
staleness
365 daysNational Institute of Standards and Technology — CA-2 [VERIFY]
reputation class
verifiedNational Institute of Standards and Technology — CA-2(1) independent assessors [VERIFY]
reputation record
No reliability floor beyond the exposure tier's own threshold, which still binds.
completion
No satisfaction window was set. The requirement is due now: there is no period in which it may be outstanding, and nothing proceeds without it.
ai provenance
admitNo instrument in force stated a position on AI-authored evidence for "control_assessment". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway.
penetration testrequired
necessity
requiredNational Institute of Standards and Technology — CA-8 [VERIFY]
staleness
90 daysNo instrument set an age limit for this claim, so the deploying organisation's own freshness policy binds at 90 days. It is not unlimited.
reputation class
verifiedNational Institute of Standards and Technology — CA-8(1) independent penetration agent [VERIFY]
reputation record
No reliability floor beyond the exposure tier's own threshold, which still binds.
completion
No satisfaction window was set. The requirement is due now: there is no period in which it may be outstanding, and nothing proceeds without it.
ai provenance
admitNo instrument in force stated a position on AI-authored evidence for "penetration_test". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway.
vulnerability scanrequired
necessity
requiredNational Institute of Standards and Technology — RA-5 [VERIFY]
staleness
30 daysNational Institute of Standards and Technology — RA-5(a) [VERIFY]
reputation class
No class floor was set, so the seller's own assertion is admissible for this claim up to the ceiling that class carries. That is a setting, not an absence.
reputation record
No reliability floor beyond the exposure tier's own threshold, which still binds.
completion
No satisfaction window was set. The requirement is due now: there is no period in which it may be outstanding, and nothing proceeds without it.
ai provenance
admitNo instrument in force stated a position on AI-authored evidence for "vulnerability_scan". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway.
vulnerability triage dispositionrequired
necessity
requiredOffice of the Chief Information Security Officer — § 3.1 [VERIFY]
staleness
90 daysNo instrument set an age limit for this claim, so the deploying organisation's own freshness policy binds at 90 days. It is not unlimited.
reputation class
No class floor was set, so the seller's own assertion is admissible for this claim up to the ceiling that class carries. That is a setting, not an absence.
reputation record
No reliability floor beyond the exposure tier's own threshold, which still binds.
completion
No satisfaction window was set. The requirement is due now: there is no period in which it may be outstanding, and nothing proceeds without it.
ai provenance
exclude tainted lineageOffice of the Chief Information Security Officer — § 3.4 [VERIFY]

Every bar above was re-derived from the regulatory bindings inside this receipt’s hashed body, not from the configuration that produced it. A bar in grey is a setting no instrument made — the deploying organisation’s own default, which still binds and is not an absence. A bar position renders an ordinal on a declared ladder: it is a way to draw a control and to compare two settings on the same axis, and it is not a measurement. The value printed beside each bar is the authoritative one.

Whoever must act now

The engineer with the deployment in their hands, the release manager, the person who must publish or hold.

One instruction and the reason in words. No score, no money, no signatures.

DO NOT PROCEED
ai-system:TRIAGE-ASSISTANT-V4
Missing or out of date: vulnerability triage disposition

Seven or eight fields, and not one of them is a number somebody can argue with. This person is not being asked to re-judge the evidence; somebody already did, and it is on the record.

The scoped copy itself — partial — something outside this role’s remit was removed
FAITHFUL digest sha256:fc675a63c6bfe9c36ae89a9bfe086d74915a0680505ded95d7c5633f2ecbe3d4 matches the commitment sealed in the receipt.
{
 "spec": "corobate:role-view:2",
 "role": "OPERATOR",
 "purpose": "Whoever must act on this decision now — release the goods, fund the draw, dispatch the agent, ship the title. Sees one instruction and the reason in plain words, and nothing that could be argued about while somebody waits.",
 "is_a_receipt": false,
 "warning": "This is a SCOPED COPY of a sealed decision, not the decision record itself. It will not verify as a receipt and must not be presented as one. To confirm it is faithful, recompute its `view` digest under the same canonicalisation that produces receipt_hash and compare it with the entry for this role in the source receipt’s `views` block.",
 "derived_from": {
  "receipt_hash": "sha256:ee44fd0e4bc167b9c18e62720219425692aaedd851f997bc4c6971c79be02199",
  "entry_hash": "sha256:2f26ad85cf44d0df56f007f3b09898161e93903b532e55d46b41823d233e9809",
  "issued_at": "2026-08-08T16:00:00.000Z"
 },
 "view_digest": "sha256:fc675a63c6bfe9c36ae89a9bfe086d74915a0680505ded95d7c5633f2ecbe3d4",
 "withheld": {
  "anything_withheld": true,
  "note": "Facts outside this role’s remit were removed. That something was removed is stated so a partial record is never mistaken for a complete one. How much, and what, is not stated — a count is an inference about the part you are not entitled to see."
 },
 "view": {
  "spec": "urn:ietf:params:corobate:receipt:1",
  "receipt_version": "1.8",
  "issued_at": "2026-08-08T16:00:00.000Z",
  "decision": {
   "id": "ai_TRIAGE_EVIDENCE_EXCLUDE_TAINTED_LINEAGE",
   "subject": "ai-system:TRIAGE-ASSISTANT-V4"
  },
  "memory": {
   "state_digest": "sha256:2c0c2a47680fbf012f29aba9e9ea7a1e4292e0b41243cd158d904090723e6562",
   "ledger_head": "sha256:666ec422cfa0a2aa3a0761bf5d34bc5eeb89079a0a37b9c86caf1f7e41c17603",
   "coverage_gaps": [
    "ai-system:TRIAGE-ASSISTANT-V4|vulnerability_triage_disposition"
   ]
  },
  "verdict": {
   "value": "WITHHELD"
  },
  "release": {
   "state": "WITHHELD_NO_EVIDENCE"
  }
 }
}

Provider / assessed party

The cloud service provider, the release team, or the party operating the AI system — whoever is being assessed.

Sees which controls were required of them and by which publication and control identifier. Does not see the authorising official’s exposure figure or how any shortfall was priced.

What is outstanding on your file

  • vulnerability triage disposition — required by Office of the Chief Information Security Officer, § 3.1 [VERIFY]
ClaimRequiredEvidence classWhoAgeOutcome
vulnerability_scanyesVERIFIED2026-08-04admitted
penetration_testyesVERIFIED2026-06-09admitted
control_assessmentyesVERIFIED2026-04-30admitted
vulnerability_triage_dispositionnoMODELED2026-08-05withheld
vulnerability_triage_dispositionnoMODELED2026-08-08withheld
vulnerability_triage_dispositionyesMISSING2026-08-08coverage gap

The clause is here because it turns an argument into an errand. What is not here: what the bank had at stake, and whether anyone priced the shortfall.

The scoped copy itself — partial — something outside this role’s remit was removed
FAITHFUL digest sha256:012591f154658fa177883bc4f2f569cb1630fa31f2d5f93d2b6eb7ffbc7b56f6 matches the commitment sealed in the receipt.
{
 "spec": "corobate:role-view:2",
 "role": "SUPPLIER",
 "purpose": "The party whose evidence was judged. Sees every claim the decision required, which fell short, and the clause that required it — and nothing about what the buyer had at stake or how the buyer priced any shortfall. NOTE, because an earlier draft of this sentence was untrue: this projection carries the WHOLE inputs array, so where several parties supplied evidence for one decision, each of them sees all of it. Per-party scoping cannot be expressed by a commitment scheme with one digest per role, and claiming it anyway would be the kind of promise this file exists to stop making.",
 "is_a_receipt": false,
 "warning": "This is a SCOPED COPY of a sealed decision, not the decision record itself. It will not verify as a receipt and must not be presented as one. To confirm it is faithful, recompute its `view` digest under the same canonicalisation that produces receipt_hash and compare it with the entry for this role in the source receipt’s `views` block.",
 "derived_from": {
  "receipt_hash": "sha256:ee44fd0e4bc167b9c18e62720219425692aaedd851f997bc4c6971c79be02199",
  "entry_hash": "sha256:2f26ad85cf44d0df56f007f3b09898161e93903b532e55d46b41823d233e9809",
  "issued_at": "2026-08-08T16:00:00.000Z"
 },
 "view_digest": "sha256:012591f154658fa177883bc4f2f569cb1630fa31f2d5f93d2b6eb7ffbc7b56f6",
 "withheld": {
  "anything_withheld": true,
  "note": "Facts outside this role’s remit were removed. That something was removed is stated so a partial record is never mistaken for a complete one. How much, and what, is not stated — a count is an inference about the part you are not entitled to see."
 },
 "view": {
  "spec": "urn:ietf:params:corobate:receipt:1",
  "receipt_version": "1.8",
  "issued_at": "2026-08-08T16:00:00.000Z",
  "decision": {
   "id": "ai_TRIAGE_EVIDENCE_EXCLUDE_TAINTED_LINEAGE",
   "subject": "ai-system:TRIAGE-ASSISTANT-V4",
   "question": "May this quarter's vulnerability triage be accepted as the record of review?"
  },
  "memory": {
   "state_digest": "sha256:2c0c2a47680fbf012f29aba9e9ea7a1e4292e0b41243cd158d904090723e6562",
   "ledger_head": "sha256:666ec422cfa0a2aa3a0761bf5d34bc5eeb89079a0a37b9c86caf1f7e41c17603",
   "coverage_gaps": [
    "ai-system:TRIAGE-ASSISTANT-V4|vulnerability_triage_disposition"
   ]
  },
  "verdict": {
   "value": "WITHHELD"
  },
  "inputs": [
   {
    "key": "ai-system:TRIAGE-ASSISTANT-V4::vulnerability_scan",
    "provenance": "VERIFIED",
    "observed_at": "2026-08-04T16:00:00.000Z",
    "memory_status": "admitted",
    "critical": true
   },
   {
    "key": "ai-system:TRIAGE-ASSISTANT-V4::penetration_test",
    "provenance": "VERIFIED",
    "observed_at": "2026-06-09T16:00:00.000Z",
    "memory_status": "admitted",
    "critical": true
   },
   {
    "key": "ai-system:TRIAGE-ASSISTANT-V4::control_assessment",
    "provenance": "VERIFIED",
    "observed_at": "2026-04-30T16:00:00.000Z",
    "memory_status": "admitted",
    "critical": true
   },
   {
    "key": "ai-system:TRIAGE-ASSISTANT-V4::vulnerability_triage_disposition",
    "provenance": "MODELED",
    "observed_at": "2026-08-05T16:00:00.000Z",
    "memory_status": "withheld",
    "critical": false
   },
   {
    "key": "ai-system:TRIAGE-ASSISTANT-V4::vulnerability_triage_disposition",
    "provenance": "MODELED",
    "observed_at": "2026-08-08T16:00:00.000Z",
    "memory_status": "withheld",
    "critical": false
   },
   {
    "key": "ai-system:TRIAGE-ASSISTANT-V4::vulnerability_triage_disposition",
    "provenance": "MISSING",
    "observed_at": "2026-08-08T16:00:00.000Z",
    "memory_status": "coverage_gap",
    "critical": true
   }
  ],
  "regulatory": {
   "bindings": [
    {
     "claim": "control_assessment",
     "requirement": "max_age_days",
     "value": 365,
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
      "instrument_id": "nist-sp-800-53r5-moderate",
      "version": 5,
      "edition": "Rev. 5",
      "citation": "CA-2 [VERIFY]",
      "source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "control_assessment",
     "requirement": "min_class",
     "value": "VERIFIED",
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
      "instrument_id": "nist-sp-800-53r5-moderate",
      "version": 5,
      "edition": "Rev. 5",
      "citation": "CA-2(1) independent assessors [VERIFY]",
      "source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "control_assessment",
     "requirement": "required",
     "value": true,
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
      "instrument_id": "nist-sp-800-53r5-moderate",
      "version": 5,
      "edition": "Rev. 5",
      "citation": "CA-2 [VERIFY]",
      "source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "penetration_test",
     "requirement": "min_class",
     "value": "VERIFIED",
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
      "instrument_id": "nist-sp-800-53r5-moderate",
      "version": 5,
      "edition": "Rev. 5",
      "citation": "CA-8(1) independent penetration agent [VERIFY]",
      "source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "penetration_test",
     "requirement": "required",
     "value": true,
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
      "instrument_id": "nist-sp-800-53r5-moderate",
      "version": 5,
      "edition": "Rev. 5",
      "citation": "CA-8 [VERIFY]",
      "source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "vulnerability_scan",
     "requirement": "max_age_days",
     "value": 30,
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
      "instrument_id": "nist-sp-800-53r5-moderate",
      "version": 5,
      "edition": "Rev. 5",
      "citation": "RA-5(a) [VERIFY]",
      "source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "vulnerability_scan",
     "requirement": "required",
     "value": true,
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
      "instrument_id": "nist-sp-800-53r5-moderate",
      "version": 5,
      "edition": "Rev. 5",
      "citation": "RA-5 [VERIFY]",
      "source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "vulnerability_triage_disposition",
     "requirement": "ai_position",
     "value": "EXCLUDE_TAINTED_LINEAGE",
     "bound_by": {
      "authority": "Office of the Chief Information Security Officer",
      "instrument": "Enterprise standard on machine-generated evidence",
      "instrument_id": "enterprise-ai-evidence-standard",
      "version": 1,
      "edition": "2026-03-01",
      "citation": "§ 3.4 [VERIFY]",
      "source_digest": "sha256:e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "vulnerability_triage_disposition",
     "requirement": "required",
     "value": true,
     "bound_by": {
      "authority": "Office of the Chief Information Security Officer",
      "instrument": "Enterprise standard on machine-generated evidence",
      "instrument_id": "enterprise-ai-evidence-standard",
      "version": 1,
      "edition": "2026-03-01",
      "citation": "§ 3.1 [VERIFY]",
      "source_digest": "sha256:e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    }
   ],
   "applied": [
    {
     "instrument_id": "enterprise-ai-evidence-standard",
     "version": 1,
     "authority": "Office of the Chief Information Security Officer",
     "instrument": "Enterprise standard on machine-generated evidence",
     "edition": "2026-03-01",
     "citation": "§ 3 [VERIFY]",
     "source_digest": "sha256:e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5",
     "entered_by": "actor:human:issm",
     "entered_at": "2026-08-08T16:00:00.000Z"
    },
    {
     "instrument_id": "nist-sp-800-53r5-moderate",
     "version": 5,
     "authority": "National Institute of Standards and Technology",
     "instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
     "edition": "Rev. 5",
     "citation": "CA-2, CA-8, RA-5, SR-6 [VERIFY]",
     "source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353",
     "entered_by": "actor:human:issm",
     "entered_at": "2026-08-08T16:00:00.000Z"
    }
   ],
   "defaults": [
    {
     "claim": "control_assessment",
     "requirement": "ai_position",
     "value": "ADMIT",
     "because": "No instrument in force stated a position on AI-authored evidence for \"control_assessment\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
    },
    {
     "claim": "penetration_test",
     "requirement": "ai_position",
     "value": "ADMIT",
     "because": "No instrument in force stated a position on AI-authored evidence for \"penetration_test\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
    },
    {
     "claim": "vulnerability_scan",
     "requirement": "ai_position",
     "value": "ADMIT",
     "because": "No instrument in force stated a position on AI-authored evidence for \"vulnerability_scan\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
    }
   ]
  }
 }
}

Assessor / authorising official

A third-party assessment organisation, an agency assessor, or an inspector general reviewing the package. Same position as a customs officer: a public mandate over the record.

The control record in full — each publication by control identifier, edition and document digest, and every required claim with who supplied it and when. No exposure figure, no risk pricing, no confidence score.

Office of the Chief Information Security Officer
Enterprise standard on machine-generated evidence
§ 3 [VERIFY] · edition 2026-03-01
document sha256:e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5
entered by actor:human:issm
National Institute of Standards and Technology
SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)
CA-2, CA-8, RA-5, SR-6 [VERIFY] · edition Rev. 5
document sha256:5353535353535353535353535353535353535353535353535353535353535353
entered by actor:human:issm

What each authority bound

ClaimRequirementLevelBound by
control_assessmentmax age days365National Institute of Standards and Technology
CA-2 [VERIFY] · SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)
control_assessmentmin classVERIFIEDNational Institute of Standards and Technology
CA-2(1) independent assessors [VERIFY] · SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)
control_assessmentrequiredtrueNational Institute of Standards and Technology
CA-2 [VERIFY] · SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)
penetration_testmin classVERIFIEDNational Institute of Standards and Technology
CA-8(1) independent penetration agent [VERIFY] · SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)
penetration_testrequiredtrueNational Institute of Standards and Technology
CA-8 [VERIFY] · SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)
vulnerability_scanmax age days30National Institute of Standards and Technology
RA-5(a) [VERIFY] · SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)
vulnerability_scanrequiredtrueNational Institute of Standards and Technology
RA-5 [VERIFY] · SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)
vulnerability_triage_dispositionai positionEXCLUDE_TAINTED_LINEAGEOffice of the Chief Information Security Officer
§ 3.4 [VERIFY] · Enterprise standard on machine-generated evidence
vulnerability_triage_dispositionrequiredtrueOffice of the Chief Information Security Officer
§ 3.1 [VERIFY] · Enterprise standard on machine-generated evidence

Every required claim, and what was actually held

ClaimRequiredEvidence classWhoAgeOutcome
vulnerability_scanyesVERIFIEDactor:sys:registry:nvd-cve2026-08-04admitted
penetration_testyesVERIFIEDactor:org:LAB-NVLAP-04122026-06-09admitted
control_assessmentyesVERIFIEDactor:org:CERT-3PAO-ATLANTIC2026-04-30admitted
vulnerability_triage_dispositionnoMODELEDactor:ai:triage-assistant-v42026-08-05withheld
vulnerability_triage_dispositionnoMODELEDactor:org:LAB-NVLAP-04122026-08-08withheld
vulnerability_triage_dispositionyesMISSING2026-08-08coverage gap
Absent from this copy, deliberatelyNo exposure figure, no risk pricing, no confidence score, no release quorum. The examiner’s claim is on the record of what was required and what was held — answered here completely, down to the digest of the document each requirement was configured from. The institution’s commercial position is a different question and this document does not answer it. The published verifier checks that on the content of the copy, not on the intentions of whoever produced it.
The scoped copy itself — partial — something outside this role’s remit was removed
FAITHFUL digest sha256:2c9d91944e2efed1f97186874e60c4234c9017a08798259ce25556a904a0da8f matches the commitment sealed in the receipt.
{
 "spec": "corobate:role-view:2",
 "role": "REGULATOR",
 "purpose": "An official holding a public mandate over this record — a customs officer, a bank examiner, a market conduct supervisor. Sees the regulatory record in full: their own instrument named, every required claim and whether it was met, by whom, how old. No commercial figure of any kind.",
 "is_a_receipt": false,
 "warning": "This is a SCOPED COPY of a sealed decision, not the decision record itself. It will not verify as a receipt and must not be presented as one. To confirm it is faithful, recompute its `view` digest under the same canonicalisation that produces receipt_hash and compare it with the entry for this role in the source receipt’s `views` block.",
 "derived_from": {
  "receipt_hash": "sha256:ee44fd0e4bc167b9c18e62720219425692aaedd851f997bc4c6971c79be02199",
  "entry_hash": "sha256:2f26ad85cf44d0df56f007f3b09898161e93903b532e55d46b41823d233e9809",
  "issued_at": "2026-08-08T16:00:00.000Z"
 },
 "view_digest": "sha256:2c9d91944e2efed1f97186874e60c4234c9017a08798259ce25556a904a0da8f",
 "withheld": {
  "anything_withheld": true,
  "note": "Facts outside this role’s remit were removed. That something was removed is stated so a partial record is never mistaken for a complete one. How much, and what, is not stated — a count is an inference about the part you are not entitled to see."
 },
 "view": {
  "spec": "urn:ietf:params:corobate:receipt:1",
  "receipt_version": "1.8",
  "issued_at": "2026-08-08T16:00:00.000Z",
  "decision": {
   "id": "ai_TRIAGE_EVIDENCE_EXCLUDE_TAINTED_LINEAGE",
   "subject": "ai-system:TRIAGE-ASSISTANT-V4",
   "question": "May this quarter's vulnerability triage be accepted as the record of review?"
  },
  "memory": {
   "state_digest": "sha256:2c0c2a47680fbf012f29aba9e9ea7a1e4292e0b41243cd158d904090723e6562",
   "ledger_head": "sha256:666ec422cfa0a2aa3a0761bf5d34bc5eeb89079a0a37b9c86caf1f7e41c17603",
   "coverage_gaps": [
    "ai-system:TRIAGE-ASSISTANT-V4|vulnerability_triage_disposition"
   ]
  },
  "data_horizon": "2026-08-08T16:00:00.000Z",
  "verdict": {
   "value": "WITHHELD"
  },
  "regulatory": {
   "spec": "corobate:regulatory:2",
   "resolved": true,
   "applied": [
    {
     "instrument_id": "enterprise-ai-evidence-standard",
     "version": 1,
     "authority": "Office of the Chief Information Security Officer",
     "instrument": "Enterprise standard on machine-generated evidence",
     "edition": "2026-03-01",
     "citation": "§ 3 [VERIFY]",
     "source_digest": "sha256:e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5",
     "entered_by": "actor:human:issm",
     "entered_at": "2026-08-08T16:00:00.000Z"
    },
    {
     "instrument_id": "nist-sp-800-53r5-moderate",
     "version": 5,
     "authority": "National Institute of Standards and Technology",
     "instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
     "edition": "Rev. 5",
     "citation": "CA-2, CA-8, RA-5, SR-6 [VERIFY]",
     "source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353",
     "entered_by": "actor:human:issm",
     "entered_at": "2026-08-08T16:00:00.000Z"
    }
   ],
   "skipped": [],
   "conflicts": [],
   "bindings": [
    {
     "claim": "control_assessment",
     "requirement": "max_age_days",
     "value": 365,
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
      "instrument_id": "nist-sp-800-53r5-moderate",
      "version": 5,
      "edition": "Rev. 5",
      "citation": "CA-2 [VERIFY]",
      "source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "control_assessment",
     "requirement": "min_class",
     "value": "VERIFIED",
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
      "instrument_id": "nist-sp-800-53r5-moderate",
      "version": 5,
      "edition": "Rev. 5",
      "citation": "CA-2(1) independent assessors [VERIFY]",
      "source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "control_assessment",
     "requirement": "required",
     "value": true,
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
      "instrument_id": "nist-sp-800-53r5-moderate",
      "version": 5,
      "edition": "Rev. 5",
      "citation": "CA-2 [VERIFY]",
      "source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "penetration_test",
     "requirement": "min_class",
     "value": "VERIFIED",
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
      "instrument_id": "nist-sp-800-53r5-moderate",
      "version": 5,
      "edition": "Rev. 5",
      "citation": "CA-8(1) independent penetration agent [VERIFY]",
      "source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "penetration_test",
     "requirement": "required",
     "value": true,
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
      "instrument_id": "nist-sp-800-53r5-moderate",
      "version": 5,
      "edition": "Rev. 5",
      "citation": "CA-8 [VERIFY]",
      "source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "vulnerability_scan",
     "requirement": "max_age_days",
     "value": 30,
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
      "instrument_id": "nist-sp-800-53r5-moderate",
      "version": 5,
      "edition": "Rev. 5",
      "citation": "RA-5(a) [VERIFY]",
      "source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "vulnerability_scan",
     "requirement": "required",
     "value": true,
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
      "instrument_id": "nist-sp-800-53r5-moderate",
      "version": 5,
      "edition": "Rev. 5",
      "citation": "RA-5 [VERIFY]",
      "source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "vulnerability_triage_disposition",
     "requirement": "ai_position",
     "value": "EXCLUDE_TAINTED_LINEAGE",
     "bound_by": {
      "authority": "Office of the Chief Information Security Officer",
      "instrument": "Enterprise standard on machine-generated evidence",
      "instrument_id": "enterprise-ai-evidence-standard",
      "version": 1,
      "edition": "2026-03-01",
      "citation": "§ 3.4 [VERIFY]",
      "source_digest": "sha256:e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "vulnerability_triage_disposition",
     "requirement": "required",
     "value": true,
     "bound_by": {
      "authority": "Office of the Chief Information Security Officer",
      "instrument": "Enterprise standard on machine-generated evidence",
      "instrument_id": "enterprise-ai-evidence-standard",
      "version": 1,
      "edition": "2026-03-01",
      "citation": "§ 3.1 [VERIFY]",
      "source_digest": "sha256:e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    }
   ],
   "defaults": [
    {
     "claim": "control_assessment",
     "requirement": "ai_position",
     "value": "ADMIT",
     "because": "No instrument in force stated a position on AI-authored evidence for \"control_assessment\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
    },
    {
     "claim": "penetration_test",
     "requirement": "ai_position",
     "value": "ADMIT",
     "because": "No instrument in force stated a position on AI-authored evidence for \"penetration_test\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
    },
    {
     "claim": "vulnerability_scan",
     "requirement": "ai_position",
     "value": "ADMIT",
     "because": "No instrument in force stated a position on AI-authored evidence for \"vulnerability_scan\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
    }
   ]
  },
  "inputs": [
   {
    "key": "ai-system:TRIAGE-ASSISTANT-V4::vulnerability_scan",
    "provenance": "VERIFIED",
    "source": "nvd-cve:vulnerability_scan",
    "observed_at": "2026-08-04T16:00:00.000Z",
    "critical": true,
    "memory_status": "admitted",
    "memory_actor": "actor:sys:registry:nvd-cve"
   },
   {
    "key": "ai-system:TRIAGE-ASSISTANT-V4::penetration_test",
    "provenance": "VERIFIED",
    "source": "LAB-NVLAP-0412:penetration_test",
    "observed_at": "2026-06-09T16:00:00.000Z",
    "critical": true,
    "memory_status": "admitted",
    "memory_actor": "actor:org:LAB-NVLAP-0412"
   },
   {
    "key": "ai-system:TRIAGE-ASSISTANT-V4::control_assessment",
    "provenance": "VERIFIED",
    "source": "CERT-3PAO-ATLANTIC:control_assessment",
    "observed_at": "2026-04-30T16:00:00.000Z",
    "critical": true,
    "memory_status": "admitted",
    "memory_actor": "actor:org:CERT-3PAO-ATLANTIC"
   },
   {
    "key": "ai-system:TRIAGE-ASSISTANT-V4::vulnerability_triage_disposition",
    "provenance": "MODELED",
    "source": "triage-assistant-v4:vulnerability_triage_disposition",
    "observed_at": "2026-08-05T16:00:00.000Z",
    "critical": false,
    "memory_status": "withheld",
    "memory_actor": "actor:ai:triage-assistant-v4"
   },
   {
    "key": "ai-system:TRIAGE-ASSISTANT-V4::vulnerability_triage_disposition",
    "provenance": "MODELED",
    "source": "receipt:sha256:d9b9ab69f8c703568004833df6b17024b3fe60322618d2a33283edb39a363bde",
    "observed_at": "2026-08-08T16:00:00.000Z",
    "critical": false,
    "memory_status": "withheld",
    "memory_actor": "actor:org:LAB-NVLAP-0412"
   },
   {
    "key": "ai-system:TRIAGE-ASSISTANT-V4::vulnerability_triage_disposition",
    "provenance": "MISSING",
    "source": null,
    "observed_at": "2026-08-08T16:00:00.000Z",
    "critical": true,
    "memory_status": "coverage_gap"
   }
  ],
  "crypto_suite": {
   "spec": "corobate:suite:1",
   "id": "CB-1-ES256-SHA256",
   "receipt_digest": "sha256",
   "chain_digest": "sha256",
   "content_digest": "sha256",
   "envelope_signature": "ES256",
   "signature_curve": "P-256",
   "canonicalisation": "attest-canon/2",
   "quantum_resistant": false
  }
 }
}

ISSM / control owner

The information system security manager and the control owners who hold the package.

The fullest internal view: every input, its class, its age, its score, the exposure, and every publication in force.

VerdictWITHHELD
Confidence0%
bound by vulnerability_triage_disposition
Exposure$250,000
ReleaseWITHHELD_NO_EVIDENCE
Risk acceptedNONE

Every input the gate saw

ClaimRequiredEvidence classWhoAgeScoreOutcome
vulnerability_scanyesVERIFIEDactor:sys:registry:nvd-cve4d95%admitted
penetration_testyesVERIFIEDactor:org:LAB-NVLAP-041260d95%admitted
control_assessmentyesVERIFIEDactor:org:CERT-3PAO-ATLANTIC100d95%admitted
vulnerability_triage_dispositionnoMODELEDactor:ai:triage-assistant-v43d80%withheld
vulnerability_triage_dispositionnoMODELEDactor:org:LAB-NVLAP-04120d80%withheld
vulnerability_triage_dispositionyesMISSING2026-08-080%coverage gap

Instruments in force

Office of the Chief Information Security Officer
Enterprise standard on machine-generated evidence
§ 3 [VERIFY] · edition 2026-03-01
document sha256:e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5
entered by actor:human:issm
National Institute of Standards and Technology
SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)
CA-2, CA-8, RA-5, SR-6 [VERIFY] · edition Rev. 5
document sha256:5353535353535353535353535353535353535353535353535353535353535353
entered by actor:human:issm

Why

  • Coverage gap: no admissible memory for required claim(s) ai-system:TRIAGE-ASSISTANT-V4|vulnerability_triage_disposition.
  • Confidence 0.00% is bound by "ai-system:TRIAGE-ASSISTANT-V4|vulnerability_triage_disposition".
  • 2 memories were withheld from the context block: ai-system:TRIAGE-ASSISTANT-V4|vulnerability_triage_disposition (AI-authored and excluded: the authority binding this claim does not accept model-authored evidence for it. Observed actor:ai:triage-assistant-v4 — a model, named as one in its own enrolled identity. Inadmissible at any reliability and any exposure. The remedy is to file this model's output under its OWN claim rather than under "ai-system:TRIAGE-ASSISTANT-V4|vulnerability_triage_disposition" — corroborating it does not help, because an identical value merges into this record and a different one contradicts it.); ai-system:TRIAGE-ASSISTANT-V4|vulnerability_triage_disposition (excluded on lineage: this record is a re-ingested receipt that itself rested on AI-authored evidence. The authority binding this claim excludes tainted lineage, which is what stops an exclusion being defeated by one round trip through a sealed receipt.).
  • Thresholds for $250,000 exposure: approve 85%, caution 60%.
The scoped copy itself — partial — something outside this role’s remit was removed
FAITHFUL digest sha256:62c98d9a202a5e5a1ca3772ff13c9f5985304602f80c6da58b5a4f58632d256b matches the commitment sealed in the receipt.
{
 "spec": "corobate:role-view:2",
 "role": "COMPLIANCE",
 "purpose": "The operator’s own compliance function. The fullest internal view: every gap, every instrument in force, the waivability of each requirement and who accepted what.",
 "is_a_receipt": false,
 "warning": "This is a SCOPED COPY of a sealed decision, not the decision record itself. It will not verify as a receipt and must not be presented as one. To confirm it is faithful, recompute its `view` digest under the same canonicalisation that produces receipt_hash and compare it with the entry for this role in the source receipt’s `views` block.",
 "derived_from": {
  "receipt_hash": "sha256:ee44fd0e4bc167b9c18e62720219425692aaedd851f997bc4c6971c79be02199",
  "entry_hash": "sha256:2f26ad85cf44d0df56f007f3b09898161e93903b532e55d46b41823d233e9809",
  "issued_at": "2026-08-08T16:00:00.000Z"
 },
 "view_digest": "sha256:62c98d9a202a5e5a1ca3772ff13c9f5985304602f80c6da58b5a4f58632d256b",
 "withheld": {
  "anything_withheld": true,
  "note": "Facts outside this role’s remit were removed. That something was removed is stated so a partial record is never mistaken for a complete one. How much, and what, is not stated — a count is an inference about the part you are not entitled to see."
 },
 "view": {
  "spec": "urn:ietf:params:corobate:receipt:1",
  "receipt_version": "1.8",
  "issued_at": "2026-08-08T16:00:00.000Z",
  "decision": {
   "id": "ai_TRIAGE_EVIDENCE_EXCLUDE_TAINTED_LINEAGE",
   "domain": "supply-chain",
   "subject": "ai-system:TRIAGE-ASSISTANT-V4",
   "question": "May this quarter's vulnerability triage be accepted as the record of review?"
  },
  "memory": {
   "state_digest": "sha256:2c0c2a47680fbf012f29aba9e9ea7a1e4292e0b41243cd158d904090723e6562",
   "ledger_head": "sha256:666ec422cfa0a2aa3a0761bf5d34bc5eeb89079a0a37b9c86caf1f7e41c17603",
   "coverage_gaps": [
    "ai-system:TRIAGE-ASSISTANT-V4|vulnerability_triage_disposition"
   ],
   "exposure": {
    "usd": 250000,
    "declared_by": "actor:human:issm",
    "ledger_seq": 5
   },
   "policy_digest": "sha256:a6b69b7d20f7fb04d522364af1d92992058b04a5835fcec9d1c9f2261c7ef636"
  },
  "data_horizon": "2026-08-08T16:00:00.000Z",
  "verdict": {
   "value": "WITHHELD",
   "threshold_approve": 0.85,
   "threshold_caution": 0.6,
   "rule": "confidence>=threshold"
  },
  "confidence": {
   "value": 0,
   "method": "min-over-critical-inputs",
   "bound_by": "ai-system:TRIAGE-ASSISTANT-V4::vulnerability_triage_disposition"
  },
  "release": {
   "required": false,
   "required_by_tier": false,
   "escalated_by_acceptance": false,
   "risk_accepted": false,
   "state": "WITHHELD_NO_EVIDENCE",
   "code": "QUORUM_EVIDENCE_WITHHELD",
   "reason": "the evidence did not clear the threshold for this exposure, so there is nothing to release. Signatures do not substitute for evidence, and this state is deliberately distinct from WITHHELD_PENDING_SIGNATURES: a reader must be able to tell \"the evidence is not there\" from \"the evidence is there and 0 of 2 people have signed\".",
   "tier_floor_cents": 1000000000,
   "exposure_usd_cents": 25000000,
   "required_m": 2,
   "declared_n": 3,
   "floor_m": 2,
   "distinct_signers": 0,
   "superseded": 0,
   "collapsed": 0,
   "release_digest": "sha256:a3c837964666f08eab19f6d0645b630ecb8b87ace3c7b95b362ad7a02ed15846",
   "governance_digest": "sha256:8b0a45a27fcce9c1c243c764e855e67c6fe6dfd7f02a563bd90809b419731905",
   "governance_signed": true,
   "counted_voices": [],
   "signatures": [],
   "ledger_seq": null
  },
  "acceptance": {
   "state": "NONE",
   "code": "ACCEPTANCE_NONE",
   "reason": "no risk acceptance was presented for this decision. This is the ordinary case: a refusal is a refusal unless a named person has priced it.",
   "permitted_basis": null,
   "presented": 0,
   "superseded": 0,
   "expired": 0,
   "gaps_not_covered": 0,
   "coverage_gaps_in_force": [
    "ai-system:TRIAGE-ASSISTANT-V4|vulnerability_triage_disposition"
   ],
   "evidentiary_digest": "sha256:a3c837964666f08eab19f6d0645b630ecb8b87ace3c7b95b362ad7a02ed15846",
   "margin_floor_bp": 100,
   "authority_ceiling_cents": {
    "SUPERVISOR": 1000000,
    "MANAGER": 25000000,
    "DIRECTOR": 500000000,
    "OFFICER": 5000000000
   },
   "acceptances": [],
   "escalated": false,
   "live": false,
   "ledger_seq": null
  },
  "regulatory": {
   "spec": "corobate:regulatory:2",
   "resolved": true,
   "applied": [
    {
     "instrument_id": "enterprise-ai-evidence-standard",
     "version": 1,
     "authority": "Office of the Chief Information Security Officer",
     "instrument": "Enterprise standard on machine-generated evidence",
     "edition": "2026-03-01",
     "citation": "§ 3 [VERIFY]",
     "source_digest": "sha256:e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5",
     "entered_by": "actor:human:issm",
     "entered_at": "2026-08-08T16:00:00.000Z"
    },
    {
     "instrument_id": "nist-sp-800-53r5-moderate",
     "version": 5,
     "authority": "National Institute of Standards and Technology",
     "instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
     "edition": "Rev. 5",
     "citation": "CA-2, CA-8, RA-5, SR-6 [VERIFY]",
     "source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353",
     "entered_by": "actor:human:issm",
     "entered_at": "2026-08-08T16:00:00.000Z"
    }
   ],
   "skipped": [],
   "conflicts": [],
   "bindings": [
    {
     "claim": "control_assessment",
     "requirement": "max_age_days",
     "value": 365,
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
      "instrument_id": "nist-sp-800-53r5-moderate",
      "version": 5,
      "edition": "Rev. 5",
      "citation": "CA-2 [VERIFY]",
      "source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "control_assessment",
     "requirement": "min_class",
     "value": "VERIFIED",
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
      "instrument_id": "nist-sp-800-53r5-moderate",
      "version": 5,
      "edition": "Rev. 5",
      "citation": "CA-2(1) independent assessors [VERIFY]",
      "source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "control_assessment",
     "requirement": "required",
     "value": true,
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
      "instrument_id": "nist-sp-800-53r5-moderate",
      "version": 5,
      "edition": "Rev. 5",
      "citation": "CA-2 [VERIFY]",
      "source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "penetration_test",
     "requirement": "min_class",
     "value": "VERIFIED",
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
      "instrument_id": "nist-sp-800-53r5-moderate",
      "version": 5,
      "edition": "Rev. 5",
      "citation": "CA-8(1) independent penetration agent [VERIFY]",
      "source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "penetration_test",
     "requirement": "required",
     "value": true,
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
      "instrument_id": "nist-sp-800-53r5-moderate",
      "version": 5,
      "edition": "Rev. 5",
      "citation": "CA-8 [VERIFY]",
      "source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "vulnerability_scan",
     "requirement": "max_age_days",
     "value": 30,
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
      "instrument_id": "nist-sp-800-53r5-moderate",
      "version": 5,
      "edition": "Rev. 5",
      "citation": "RA-5(a) [VERIFY]",
      "source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "vulnerability_scan",
     "requirement": "required",
     "value": true,
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
      "instrument_id": "nist-sp-800-53r5-moderate",
      "version": 5,
      "edition": "Rev. 5",
      "citation": "RA-5 [VERIFY]",
      "source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "vulnerability_triage_disposition",
     "requirement": "ai_position",
     "value": "EXCLUDE_TAINTED_LINEAGE",
     "bound_by": {
      "authority": "Office of the Chief Information Security Officer",
      "instrument": "Enterprise standard on machine-generated evidence",
      "instrument_id": "enterprise-ai-evidence-standard",
      "version": 1,
      "edition": "2026-03-01",
      "citation": "§ 3.4 [VERIFY]",
      "source_digest": "sha256:e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "vulnerability_triage_disposition",
     "requirement": "required",
     "value": true,
     "bound_by": {
      "authority": "Office of the Chief Information Security Officer",
      "instrument": "Enterprise standard on machine-generated evidence",
      "instrument_id": "enterprise-ai-evidence-standard",
      "version": 1,
      "edition": "2026-03-01",
      "citation": "§ 3.1 [VERIFY]",
      "source_digest": "sha256:e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    }
   ],
   "defaults": [
    {
     "claim": "control_assessment",
     "requirement": "ai_position",
     "value": "ADMIT",
     "because": "No instrument in force stated a position on AI-authored evidence for \"control_assessment\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
    },
    {
     "claim": "penetration_test",
     "requirement": "ai_position",
     "value": "ADMIT",
     "because": "No instrument in force stated a position on AI-authored evidence for \"penetration_test\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
    },
    {
     "claim": "vulnerability_scan",
     "requirement": "ai_position",
     "value": "ADMIT",
     "because": "No instrument in force stated a position on AI-authored evidence for \"vulnerability_scan\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
    }
   ]
  },
  "reasons": [
   "Coverage gap: no admissible memory for required claim(s) ai-system:TRIAGE-ASSISTANT-V4|vulnerability_triage_disposition.",
   "Confidence 0.00% is bound by \"ai-system:TRIAGE-ASSISTANT-V4|vulnerability_triage_disposition\".",
   "2 memories were withheld from the context block: ai-system:TRIAGE-ASSISTANT-V4|vulnerability_triage_disposition (AI-authored and excluded: the authority binding this claim does not accept model-authored evidence for it. Observed actor:ai:triage-assistant-v4 — a model, named as one in its own enrolled identity. Inadmissible at any reliability and any exposure. The remedy is to file this model's output under its OWN claim rather than under \"ai-system:TRIAGE-ASSISTANT-V4|vulnerability_triage_disposition\" — corroborating it does not help, because an identical value merges into this record and a different one contradicts it.); ai-system:TRIAGE-ASSISTANT-V4|vulnerability_triage_disposition (excluded on lineage: this record is a re-ingested receipt that itself rested on AI-authored evidence. The authority binding this claim excludes tainted lineage, which is what stops an exclusion being defeated by one round trip through a sealed receipt.).",
   "Thresholds for $250,000 exposure: approve 85%, caution 60%."
  ],
  "inputs": [
   {
    "key": "ai-system:TRIAGE-ASSISTANT-V4::vulnerability_scan",
    "value": "clean-at-scan",
    "provenance": "VERIFIED",
    "source": "nvd-cve:vulnerability_scan",
    "observed_at": "2026-08-04T16:00:00.000Z",
    "reliability": 0.95,
    "critical": true,
    "memory_status": "admitted",
    "memory_kind": "status",
    "memory_actor": "actor:sys:registry:nvd-cve",
    "memory_age_days": 4
   },
   {
    "key": "ai-system:TRIAGE-ASSISTANT-V4::penetration_test",
    "value": "no-critical",
    "provenance": "VERIFIED",
    "source": "LAB-NVLAP-0412:penetration_test",
    "observed_at": "2026-06-09T16:00:00.000Z",
    "reliability": 0.95,
    "critical": true,
    "memory_status": "admitted",
    "memory_kind": "test_report",
    "memory_actor": "actor:org:LAB-NVLAP-0412",
    "memory_age_days": 60
   },
   {
    "key": "ai-system:TRIAGE-ASSISTANT-V4::control_assessment",
    "value": "satisfied",
    "provenance": "VERIFIED",
    "source": "CERT-3PAO-ATLANTIC:control_assessment",
    "observed_at": "2026-04-30T16:00:00.000Z",
    "reliability": 0.95,
    "critical": true,
    "memory_status": "admitted",
    "memory_kind": "certificate",
    "memory_actor": "actor:org:CERT-3PAO-ATLANTIC",
    "memory_age_days": 100
   },
   {
    "key": "ai-system:TRIAGE-ASSISTANT-V4::vulnerability_triage_disposition",
    "value": null,
    "provenance": "MODELED",
    "source": "triage-assistant-v4:vulnerability_triage_disposition",
    "observed_at": "2026-08-05T16:00:00.000Z",
    "reliability": 0.8,
    "critical": false,
    "memory_status": "withheld",
    "memory_kind": "status",
    "memory_actor": "actor:ai:triage-assistant-v4",
    "memory_age_days": 3
   },
   {
    "key": "ai-system:TRIAGE-ASSISTANT-V4::vulnerability_triage_disposition",
    "value": null,
    "provenance": "MODELED",
    "source": "receipt:sha256:d9b9ab69f8c703568004833df6b17024b3fe60322618d2a33283edb39a363bde",
    "observed_at": "2026-08-08T16:00:00.000Z",
    "reliability": 0.8,
    "critical": false,
    "memory_status": "withheld",
    "memory_kind": "receipt",
    "memory_actor": "actor:org:LAB-NVLAP-0412",
    "memory_age_days": 0
   },
   {
    "key": "ai-system:TRIAGE-ASSISTANT-V4::vulnerability_triage_disposition",
    "value": null,
    "provenance": "MISSING",
    "source": null,
    "observed_at": "2026-08-08T16:00:00.000Z",
    "reliability": 0,
    "critical": true,
    "memory_status": "coverage_gap"
   }
  ],
  "crypto_suite": {
   "spec": "corobate:suite:1",
   "id": "CB-1-ES256-SHA256",
   "receipt_digest": "sha256",
   "chain_digest": "sha256",
   "content_digest": "sha256",
   "envelope_signature": "ES256",
   "signature_curve": "P-256",
   "canonicalisation": "attest-canon/2",
   "quantum_resistant": false
  }
 }
}

Authorising official (signer)

The named official whose signature carries the authorisation decision.

What is at stake, what the evidence supports, what is missing, and the digest they are signing over.

You are being asked to sign

May this quarter's vulnerability triage be accepted as the record of review?

At stake$250,000
Evidence saysWITHHELD
Release stateWITHHELD_NO_EVIDENCE
signing over evidentiary digest sha256:a3c837964666f08eab19f6d0645b630ecb8b87ace3c7b95b362ad7a02ed15846

The signature is over the STATE OF THE EVIDENCE. Move one fact behind this decision and the digest moves and the signature stops counting — which is what makes it safe to collect signatures before everyone is in the room.

What is missing

  • vulnerability triage disposition
The scoped copy itself — partial — something outside this role’s remit was removed
FAITHFUL digest sha256:93683f085f9b601edda076926b5049099229a5b34f246ddadb66d977254c9705 matches the commitment sealed in the receipt.
{
 "spec": "corobate:role-view:2",
 "role": "EXECUTIVE",
 "purpose": "A named signer on the release gate. Sees what is at stake, what the evidence supports, who else has signed and what they are being asked to sign over.",
 "is_a_receipt": false,
 "warning": "This is a SCOPED COPY of a sealed decision, not the decision record itself. It will not verify as a receipt and must not be presented as one. To confirm it is faithful, recompute its `view` digest under the same canonicalisation that produces receipt_hash and compare it with the entry for this role in the source receipt’s `views` block.",
 "derived_from": {
  "receipt_hash": "sha256:ee44fd0e4bc167b9c18e62720219425692aaedd851f997bc4c6971c79be02199",
  "entry_hash": "sha256:2f26ad85cf44d0df56f007f3b09898161e93903b532e55d46b41823d233e9809",
  "issued_at": "2026-08-08T16:00:00.000Z"
 },
 "view_digest": "sha256:93683f085f9b601edda076926b5049099229a5b34f246ddadb66d977254c9705",
 "withheld": {
  "anything_withheld": true,
  "note": "Facts outside this role’s remit were removed. That something was removed is stated so a partial record is never mistaken for a complete one. How much, and what, is not stated — a count is an inference about the part you are not entitled to see."
 },
 "view": {
  "spec": "urn:ietf:params:corobate:receipt:1",
  "receipt_version": "1.8",
  "issued_at": "2026-08-08T16:00:00.000Z",
  "decision": {
   "id": "ai_TRIAGE_EVIDENCE_EXCLUDE_TAINTED_LINEAGE",
   "domain": "supply-chain",
   "subject": "ai-system:TRIAGE-ASSISTANT-V4",
   "question": "May this quarter's vulnerability triage be accepted as the record of review?"
  },
  "memory": {
   "state_digest": "sha256:2c0c2a47680fbf012f29aba9e9ea7a1e4292e0b41243cd158d904090723e6562",
   "ledger_head": "sha256:666ec422cfa0a2aa3a0761bf5d34bc5eeb89079a0a37b9c86caf1f7e41c17603",
   "coverage_gaps": [
    "ai-system:TRIAGE-ASSISTANT-V4|vulnerability_triage_disposition"
   ],
   "exposure": {
    "usd": 250000,
    "declared_by": "actor:human:issm",
    "ledger_seq": 5
   }
  },
  "verdict": {
   "value": "WITHHELD",
   "threshold_approve": 0.85,
   "threshold_caution": 0.6,
   "rule": "confidence>=threshold"
  },
  "confidence": {
   "value": 0,
   "method": "min-over-critical-inputs",
   "bound_by": "ai-system:TRIAGE-ASSISTANT-V4::vulnerability_triage_disposition"
  },
  "release": {
   "required": false,
   "required_by_tier": false,
   "escalated_by_acceptance": false,
   "risk_accepted": false,
   "state": "WITHHELD_NO_EVIDENCE",
   "code": "QUORUM_EVIDENCE_WITHHELD",
   "reason": "the evidence did not clear the threshold for this exposure, so there is nothing to release. Signatures do not substitute for evidence, and this state is deliberately distinct from WITHHELD_PENDING_SIGNATURES: a reader must be able to tell \"the evidence is not there\" from \"the evidence is there and 0 of 2 people have signed\".",
   "tier_floor_cents": 1000000000,
   "exposure_usd_cents": 25000000,
   "required_m": 2,
   "declared_n": 3,
   "floor_m": 2,
   "distinct_signers": 0,
   "superseded": 0,
   "collapsed": 0,
   "release_digest": "sha256:a3c837964666f08eab19f6d0645b630ecb8b87ace3c7b95b362ad7a02ed15846",
   "governance_digest": "sha256:8b0a45a27fcce9c1c243c764e855e67c6fe6dfd7f02a563bd90809b419731905",
   "governance_signed": true,
   "counted_voices": [],
   "signatures": [],
   "ledger_seq": null
  },
  "acceptance": {
   "state": "NONE",
   "code": "ACCEPTANCE_NONE",
   "reason": "no risk acceptance was presented for this decision. This is the ordinary case: a refusal is a refusal unless a named person has priced it.",
   "permitted_basis": null,
   "presented": 0,
   "superseded": 0,
   "expired": 0,
   "gaps_not_covered": 0,
   "coverage_gaps_in_force": [
    "ai-system:TRIAGE-ASSISTANT-V4|vulnerability_triage_disposition"
   ],
   "evidentiary_digest": "sha256:a3c837964666f08eab19f6d0645b630ecb8b87ace3c7b95b362ad7a02ed15846",
   "margin_floor_bp": 100,
   "authority_ceiling_cents": {
    "SUPERVISOR": 1000000,
    "MANAGER": 25000000,
    "DIRECTOR": 500000000,
    "OFFICER": 5000000000
   },
   "acceptances": [],
   "escalated": false,
   "live": false,
   "ledger_seq": null
  },
  "reasons": [
   "Coverage gap: no admissible memory for required claim(s) ai-system:TRIAGE-ASSISTANT-V4|vulnerability_triage_disposition.",
   "Confidence 0.00% is bound by \"ai-system:TRIAGE-ASSISTANT-V4|vulnerability_triage_disposition\".",
   "2 memories were withheld from the context block: ai-system:TRIAGE-ASSISTANT-V4|vulnerability_triage_disposition (AI-authored and excluded: the authority binding this claim does not accept model-authored evidence for it. Observed actor:ai:triage-assistant-v4 — a model, named as one in its own enrolled identity. Inadmissible at any reliability and any exposure. The remedy is to file this model's output under its OWN claim rather than under \"ai-system:TRIAGE-ASSISTANT-V4|vulnerability_triage_disposition\" — corroborating it does not help, because an identical value merges into this record and a different one contradicts it.); ai-system:TRIAGE-ASSISTANT-V4|vulnerability_triage_disposition (excluded on lineage: this record is a re-ingested receipt that itself rested on AI-authored evidence. The authority binding this claim excludes tainted lineage, which is what stops an exclusion being defeated by one round trip through a sealed receipt.).",
   "Thresholds for $250,000 exposure: approve 85%, caution 60%."
  ],
  "regulatory": {
   "applied": [
    {
     "instrument_id": "enterprise-ai-evidence-standard",
     "version": 1,
     "authority": "Office of the Chief Information Security Officer",
     "instrument": "Enterprise standard on machine-generated evidence",
     "edition": "2026-03-01",
     "citation": "§ 3 [VERIFY]",
     "source_digest": "sha256:e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5",
     "entered_by": "actor:human:issm",
     "entered_at": "2026-08-08T16:00:00.000Z"
    },
    {
     "instrument_id": "nist-sp-800-53r5-moderate",
     "version": 5,
     "authority": "National Institute of Standards and Technology",
     "instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
     "edition": "Rev. 5",
     "citation": "CA-2, CA-8, RA-5, SR-6 [VERIFY]",
     "source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353",
     "entered_by": "actor:human:issm",
     "entered_at": "2026-08-08T16:00:00.000Z"
    }
   ],
   "conflicts": [],
   "defaults": [
    {
     "claim": "control_assessment",
     "requirement": "ai_position",
     "value": "ADMIT",
     "because": "No instrument in force stated a position on AI-authored evidence for \"control_assessment\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
    },
    {
     "claim": "penetration_test",
     "requirement": "ai_position",
     "value": "ADMIT",
     "because": "No instrument in force stated a position on AI-authored evidence for \"penetration_test\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
    },
    {
     "claim": "vulnerability_scan",
     "requirement": "ai_position",
     "value": "ADMIT",
     "because": "No instrument in force stated a position on AI-authored evidence for \"vulnerability_scan\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
    }
   ]
  },
  "inputs": [
   {
    "key": "ai-system:TRIAGE-ASSISTANT-V4::vulnerability_scan",
    "provenance": "VERIFIED",
    "reliability": 0.95,
    "critical": true,
    "memory_status": "admitted"
   },
   {
    "key": "ai-system:TRIAGE-ASSISTANT-V4::penetration_test",
    "provenance": "VERIFIED",
    "reliability": 0.95,
    "critical": true,
    "memory_status": "admitted"
   },
   {
    "key": "ai-system:TRIAGE-ASSISTANT-V4::control_assessment",
    "provenance": "VERIFIED",
    "reliability": 0.95,
    "critical": true,
    "memory_status": "admitted"
   },
   {
    "key": "ai-system:TRIAGE-ASSISTANT-V4::vulnerability_triage_disposition",
    "provenance": "MODELED",
    "reliability": 0.8,
    "critical": false,
    "memory_status": "withheld"
   },
   {
    "key": "ai-system:TRIAGE-ASSISTANT-V4::vulnerability_triage_disposition",
    "provenance": "MODELED",
    "reliability": 0.8,
    "critical": false,
    "memory_status": "withheld"
   },
   {
    "key": "ai-system:TRIAGE-ASSISTANT-V4::vulnerability_triage_disposition",
    "provenance": "MISSING",
    "reliability": 0,
    "critical": true,
    "memory_status": "coverage_gap"
   }
  ]
 }
}

Independent audit / IG

Internal audit, an inspector general, or an external auditor testing the programme.

Everything, plus the verifier’s own findings over the sealed record.

This view withholds nothing. What it adds is the 22 checks the published verifier ran over the sealed record behind every other view of this decision — recomputed at build time, not asserted.

#CheckDetail
1Content reproduces (JCS + SHA-256)PASSmatches sha256:ee44fd0e4bc167b9c18e62720219425692aaedd851f997bc4c6971c79be02199
2Hash chain links (entry = H(prev||content))PASShead sha256:2f26ad85cf44d0df56f007f3b09898161e93903b532e55d46b41823d233e9809
3Confidence gated by weakest critical inputPASSmin over critical = 0, bound_by ai-system:TRIAGE-ASSISTANT-V4::vulnerability_triage_disposition (MISSING)
3bVerdict follows the threshold rulePASS0 => WITHHELD; recorded WITHHELD
4Point-in-time seal (no input past data_horizon)PASSall inputs <= 2026-08-08T16:00:00.000Z
5Anchor covers the head, and the timestamp token re-readsPASSinternally consistent; NO external anchor was requested — this is not a validated timestamp
6Criteria travel with the receipt and reproducePASSpolicy_body hashes to sha256:a6b69b7d20f7fb04d522364af1d92992058b04a5835fcec9d1c9f2261c7ef636
7Reliability re-derives from recorded evidencePASSall 6 inputs re-derive exactly
8Outcome trials and lineage discounts re-derivePASS5 input(s) re-derive: 0 credited outcome trial(s), 0 lineage-discounted corroboration(s); every reliability is at or under its class ceiling
9Re-ingested receipts respect their weakest-input ceilingPASSno re-ingested receipt was ADMITTED: every input this decision rests on is a primary observation, and 1 cited receipt(s) were refused
10Release quorum re-derivesPASSWITHHELD_NO_EVIDENCE - below the top exposure tier, no multi-party requirement applies
11Risk acceptance re-derivesPASSno risk acceptance: this decision stands or falls on its evidence
12Observer credentials were not revoked as of observation timePASSrevocation list 5 (0 entries, issued 2026-08-06T00:00:00.000Z, next update due 2026-08-13T00:00:00.000Z) reproduces; 5 observer signature(s) judged as of their own instant, none under a key revoked as compromised or retired by then
13The cryptographic suite is named and is one this verifier implementsPASSsealed under CB-1-ES256-SHA256 (ES256 / sha256, attest-canon/2); this verifier implements it; the suite states it is NOT quantum resistant
14Regulatory bindings are attributed and were enforcedPASS9 binding(s) from 2 instrument(s) in force, each attributed to an authority, a citation and a document digest; 4 required claim(s) all reached the gate
15Role-view commitments re-derive, and the customs view carries no moneyPASS6 role-view commitment(s) re-derived from this receipt’s own body by this verifier’s independent projection; the REGULATOR view carries no commercial figure
16AI-authored input was admitted only where an authority allowed itPASS1 claim(s) carry a position on AI-authored evidence set by an authority and 3 carry a recorded default nobody set; 0 exclusion(s) and 0 corroboration-only rule(s) re-derived against this receipt's own admitted inputs; 0 admitted input(s) are AI-authored by their enrolled identity
17State digest recomputes from the ledger aloneUNVERIFIABLENOT APPLICABLE — you supplied no ledger, so the state digest cannot be re-derived from anything. This receipt commits to the corpus the deciding system held at the instant it sealed, and that commitment is checked by recomputing it from the append-only ledger and comparing; with no ledger in hand there is no second artefact to recompute from. The receipt is not at fault and nothing here is missing from it. Obtain the ledger from the issuer and re-run with --ledger <file>, or verifyReceipt(r, {ledger}). Nothing here has failed and nothing here has passed.
18Registry membership re-derives for every key relied onPASSall 4 key(s) relied on re-derive to the entries root registry v3 committed to and the trust root signed
20Geometric support re-derives, and an unevaluated record is not a supported onePASSno authority bound a metric to any claim on this receipt, so no geometric test applied. A claim nobody bound a metric to is not a claim about geometry, and this is a stated absence rather than a silent one
19The cause of every uncovered requirement re-derivesPASSall 1 uncovered requirement(s) re-derive their cause from this receipt's own rows. What notice is ADEQUATE is not decided here: this check establishes what the record says and that the record agrees with itself.
21The sealing party is the one you were told to expectUNVERIFIABLENOT APPLICABLE — you supplied no trust bundle, so nothing here establishes who sealed this. Identities 1 to 20 prove that this document agrees with itself; not one of them asks whose trust root it was sealed under, and a document that agrees with itself about a decision nobody made agrees with itself perfectly. Obtain the issuer's corobate:trust-bundle:1 out of band, confirm its spoken fingerprint with them by voice, and re-run with --trust-bundle <file> --expect-fingerprint <what you heard>. Nothing here has failed and nothing here has passed.
The scoped copy itself — complete for this role
FAITHFUL digest sha256:c639193ba2a2b100899de6b43ccd708f69f1fdfc8f4e02c369a7dbae8a0afadd matches the commitment sealed in the receipt.
{
 "spec": "corobate:role-view:2",
 "role": "AUDITOR",
 "purpose": "An external assessor. Sees the complete sealed record: this view withholds nothing and exists so the identity case is a case rather than an exception.",
 "is_a_receipt": false,
 "warning": "This is a SCOPED COPY of a sealed decision, not the decision record itself. It will not verify as a receipt and must not be presented as one. To confirm it is faithful, recompute its `view` digest under the same canonicalisation that produces receipt_hash and compare it with the entry for this role in the source receipt’s `views` block.",
 "derived_from": {
  "receipt_hash": "sha256:ee44fd0e4bc167b9c18e62720219425692aaedd851f997bc4c6971c79be02199",
  "entry_hash": "sha256:2f26ad85cf44d0df56f007f3b09898161e93903b532e55d46b41823d233e9809",
  "issued_at": "2026-08-08T16:00:00.000Z"
 },
 "view_digest": "sha256:c639193ba2a2b100899de6b43ccd708f69f1fdfc8f4e02c369a7dbae8a0afadd",
 "withheld": {
  "anything_withheld": false,
  "note": "Nothing outside the seal was removed for this role."
 },
 "view": {
  "spec": "urn:ietf:params:corobate:receipt:1",
  "receipt_version": "1.8",
  "engine": {
   "name": "corobate-memory",
   "version": "1.0.0"
  },
  "decision": {
   "id": "ai_TRIAGE_EVIDENCE_EXCLUDE_TAINTED_LINEAGE",
   "domain": "supply-chain",
   "subject": "ai-system:TRIAGE-ASSISTANT-V4",
   "question": "May this quarter's vulnerability triage be accepted as the record of review?"
  },
  "issued_at": "2026-08-08T16:00:00.000Z",
  "data_horizon": "2026-08-08T16:00:00.000Z",
  "inputs": [
   {
    "key": "ai-system:TRIAGE-ASSISTANT-V4::vulnerability_scan",
    "value": "clean-at-scan",
    "provenance": "VERIFIED",
    "source": "nvd-cve:vulnerability_scan",
    "observed_at": "2026-08-04T16:00:00.000Z",
    "last_corroborated_at": null,
    "memory_refreshed_by": [],
    "reliability": 0.95,
    "critical": true,
    "memory_id": "mem_4d2b1fc0d322",
    "memory_status": "admitted",
    "memory_kind": "status",
    "memory_actor": "actor:sys:registry:nvd-cve",
    "memory_age_days": 4,
    "memory_track": {
     "n": 1,
     "successes": 1
    },
    "memory_promoted_by": [],
    "memory_content_digest": "sha256:aea4c3860d57b3edd045cd33946015c41ff1aee9cc8a4df49f26d8a5165d4a38",
    "memory_outcomes": {
     "verified": 0,
     "falsified": 0,
     "modified": 0,
     "counted": 0,
     "recorded": 0
    },
    "memory_outcome_attestations": [],
    "memory_observer_lineage": null,
    "memory_corroborations": [],
    "memory_reingest": null,
    "memory_reasons": [
     "sparse track record: 1 independent observation(s); no failure recorded, so the class ceiling stands"
    ],
    "memory_class_floor": null,
    "memory_below_class_floor": false,
    "memory_not_attested": false,
    "memory_below_claim_reliability_floor": false,
    "memory_not_competent_authority": false,
    "memory_out_of_specification": false,
    "memory_ai_authored": false,
    "memory_ai_in_lineage": false,
    "memory_ai_position": "ADMIT",
    "memory_ai_inadmissible": false,
    "memory_geo_inadmissible": false,
    "memory_geo_rung": null,
    "memory_geo_metric": null,
    "memory_geo_required_metric": null,
    "observer_attested": true,
    "observer_auth_code": "VERIFIED",
    "observer_key_id": "k_5873dd9e7169def3",
    "attestation": null,
    "derivation": {
     "provenance": "VERIFIED",
     "ceiling_bp": 9500,
     "track": {
      "n": 1,
      "successes": 1
     },
     "wilson_bp": null,
     "age_days": 4,
     "max_age_days": 14,
     "house_max_age_days": 14,
     "instrument_max_age_days": 30,
     "freshness_cap_bp": 4000,
     "min_track_n": 5,
     "wilson_z_milli": 1960,
     "source_present": true,
     "seller_asserted_cap_bp": 5000,
     "retracted": false,
     "contradicted": false,
     "outcome_trials": 0,
     "outcomes": {
      "verified": 0,
      "falsified": 0,
      "modified": 0,
      "counted": 0,
      "recorded": 0
     },
     "corroborations_counted": 0,
     "corroborations_discounted": 0,
     "reingest_ceiling_bp": null,
     "reingest_depth": null,
     "reingest_weakest_class": null,
     "reingest_source_confidence_bp": null,
     "ai_authored": false,
     "ai_authored_because": null,
     "ai_in_lineage": false,
     "ai_position": "ADMIT"
    },
    "memory_reason_codes": [
     {
      "code": "SPARSE_TRACK_RECORD",
      "observed": 1,
      "limit": 5,
      "binding": false
     }
    ],
    "context_line": "[VERIFIED · r=95.0% · 4d · nvd-cve:vulnerability_scan] ai-system:TRIAGE-ASSISTANT-V4 / vulnerability_scan: clean-at-scan"
   },
   {
    "key": "ai-system:TRIAGE-ASSISTANT-V4::penetration_test",
    "value": "no-critical",
    "provenance": "VERIFIED",
    "source": "LAB-NVLAP-0412:penetration_test",
    "observed_at": "2026-06-09T16:00:00.000Z",
    "last_corroborated_at": null,
    "memory_refreshed_by": [],
    "reliability": 0.95,
    "critical": true,
    "memory_id": "mem_a3316d633bfe",
    "memory_status": "admitted",
    "memory_kind": "test_report",
    "memory_actor": "actor:org:LAB-NVLAP-0412",
    "memory_age_days": 60,
    "memory_track": {
     "n": 1,
     "successes": 1
    },
    "memory_promoted_by": [],
    "memory_content_digest": "sha256:db69fb062be9b066b370c668281e12896da2869456a2e6d356a0f14879b27de9",
    "memory_outcomes": {
     "verified": 0,
     "falsified": 0,
     "modified": 0,
     "counted": 0,
     "recorded": 0
    },
    "memory_outcome_attestations": [],
    "memory_observer_lineage": null,
    "memory_corroborations": [],
    "memory_reingest": null,
    "memory_reasons": [
     "sparse track record: 1 independent observation(s); no failure recorded, so the class ceiling stands"
    ],
    "memory_class_floor": "VERIFIED",
    "memory_below_class_floor": false,
    "memory_not_attested": false,
    "memory_below_claim_reliability_floor": false,
    "memory_not_competent_authority": false,
    "memory_out_of_specification": false,
    "memory_ai_authored": false,
    "memory_ai_in_lineage": false,
    "memory_ai_position": "ADMIT",
    "memory_ai_inadmissible": false,
    "memory_geo_inadmissible": false,
    "memory_geo_rung": null,
    "memory_geo_metric": null,
    "memory_geo_required_metric": null,
    "observer_attested": true,
    "observer_auth_code": "VERIFIED",
    "observer_key_id": "k_17d23885943ae529",
    "attestation": null,
    "derivation": {
     "provenance": "VERIFIED",
     "ceiling_bp": 9500,
     "track": {
      "n": 1,
      "successes": 1
     },
     "wilson_bp": null,
     "age_days": 60,
     "max_age_days": 180,
     "house_max_age_days": 180,
     "instrument_max_age_days": null,
     "freshness_cap_bp": 4000,
     "min_track_n": 5,
     "wilson_z_milli": 1960,
     "source_present": true,
     "seller_asserted_cap_bp": 5000,
     "retracted": false,
     "contradicted": false,
     "outcome_trials": 0,
     "outcomes": {
      "verified": 0,
      "falsified": 0,
      "modified": 0,
      "counted": 0,
      "recorded": 0
     },
     "corroborations_counted": 0,
     "corroborations_discounted": 0,
     "reingest_ceiling_bp": null,
     "reingest_depth": null,
     "reingest_weakest_class": null,
     "reingest_source_confidence_bp": null,
     "min_class_floor": "VERIFIED",
     "ai_authored": false,
     "ai_authored_because": null,
     "ai_in_lineage": false,
     "ai_position": "ADMIT"
    },
    "memory_reason_codes": [
     {
      "code": "SPARSE_TRACK_RECORD",
      "observed": 1,
      "limit": 5,
      "binding": false
     }
    ],
    "context_line": "[VERIFIED · r=95.0% · 60d · LAB-NVLAP-0412:penetration_test] ai-system:TRIAGE-ASSISTANT-V4 / penetration_test: no-critical"
   },
   {
    "key": "ai-system:TRIAGE-ASSISTANT-V4::control_assessment",
    "value": "satisfied",
    "provenance": "VERIFIED",
    "source": "CERT-3PAO-ATLANTIC:control_assessment",
    "observed_at": "2026-04-30T16:00:00.000Z",
    "last_corroborated_at": null,
    "memory_refreshed_by": [],
    "reliability": 0.95,
    "critical": true,
    "memory_id": "mem_a153eb336060",
    "memory_status": "admitted",
    "memory_kind": "certificate",
    "memory_actor": "actor:org:CERT-3PAO-ATLANTIC",
    "memory_age_days": 100,
    "memory_track": {
     "n": 1,
     "successes": 1
    },
    "memory_promoted_by": [],
    "memory_content_digest": "sha256:c1aaf46a55b4cdc629a754ac35da1b8ec4dec85c2c78613c7bc93546b63f233c",
    "memory_outcomes": {
     "verified": 0,
     "falsified": 0,
     "modified": 0,
     "counted": 0,
     "recorded": 0
    },
    "memory_outcome_attestations": [],
    "memory_observer_lineage": null,
    "memory_corroborations": [],
    "memory_reingest": null,
    "memory_reasons": [
     "sparse track record: 1 independent observation(s); no failure recorded, so the class ceiling stands"
    ],
    "memory_class_floor": "VERIFIED",
    "memory_below_class_floor": false,
    "memory_not_attested": false,
    "memory_below_claim_reliability_floor": false,
    "memory_not_competent_authority": false,
    "memory_out_of_specification": false,
    "memory_ai_authored": false,
    "memory_ai_in_lineage": false,
    "memory_ai_position": "ADMIT",
    "memory_ai_inadmissible": false,
    "memory_geo_inadmissible": false,
    "memory_geo_rung": null,
    "memory_geo_metric": null,
    "memory_geo_required_metric": null,
    "observer_attested": true,
    "observer_auth_code": "VERIFIED",
    "observer_key_id": "k_307e4bfd710ec9b3",
    "attestation": null,
    "derivation": {
     "provenance": "VERIFIED",
     "ceiling_bp": 9500,
     "track": {
      "n": 1,
      "successes": 1
     },
     "wilson_bp": null,
     "age_days": 100,
     "max_age_days": 365,
     "house_max_age_days": 365,
     "instrument_max_age_days": 365,
     "freshness_cap_bp": 4000,
     "min_track_n": 5,
     "wilson_z_milli": 1960,
     "source_present": true,
     "seller_asserted_cap_bp": 5000,
     "retracted": false,
     "contradicted": false,
     "outcome_trials": 0,
     "outcomes": {
      "verified": 0,
      "falsified": 0,
      "modified": 0,
      "counted": 0,
      "recorded": 0
     },
     "corroborations_counted": 0,
     "corroborations_discounted": 0,
     "reingest_ceiling_bp": null,
     "reingest_depth": null,
     "reingest_weakest_class": null,
     "reingest_source_confidence_bp": null,
     "min_class_floor": "VERIFIED",
     "ai_authored": false,
     "ai_authored_because": null,
     "ai_in_lineage": false,
     "ai_position": "ADMIT"
    },
    "memory_reason_codes": [
     {
      "code": "SPARSE_TRACK_RECORD",
      "observed": 1,
      "limit": 5,
      "binding": false
     }
    ],
    "context_line": "[VERIFIED · r=95.0% · 100d · CERT-3PAO-ATLANTIC:control_assessment] ai-system:TRIAGE-ASSISTANT-V4 / control_assessment: satisfied"
   },
   {
    "key": "ai-system:TRIAGE-ASSISTANT-V4::vulnerability_triage_disposition",
    "value": null,
    "provenance": "MODELED",
    "source": "triage-assistant-v4:vulnerability_triage_disposition",
    "observed_at": "2026-08-05T16:00:00.000Z",
    "last_corroborated_at": null,
    "memory_refreshed_by": [],
    "reliability": 0.8,
    "critical": false,
    "memory_id": "mem_0a6980bbce9f",
    "memory_status": "withheld",
    "memory_kind": "status",
    "memory_actor": "actor:ai:triage-assistant-v4",
    "memory_age_days": 3,
    "memory_track": {
     "n": 1,
     "successes": 1
    },
    "memory_promoted_by": [],
    "memory_content_digest": "sha256:612e098189acf7652c237b016c3537b38c17d735452f4f1d519c6bfa0772b2c2",
    "memory_outcomes": {
     "verified": 0,
     "falsified": 0,
     "modified": 0,
     "counted": 0,
     "recorded": 0
    },
    "memory_outcome_attestations": [],
    "memory_observer_lineage": null,
    "memory_corroborations": [],
    "memory_reingest": null,
    "memory_reasons": [
     "AI-authored and excluded: the authority binding this claim does not accept model-authored evidence for it. Observed actor:ai:triage-assistant-v4 — a model, named as one in its own enrolled identity. Inadmissible at any reliability and any exposure. The remedy is to file this model's output under its OWN claim rather than under \"ai-system:TRIAGE-ASSISTANT-V4|vulnerability_triage_disposition\" — corroborating it does not help, because an identical value merges into this record and a different one contradicts it.",
     "sparse track record: 1 independent observation(s); no failure recorded, so the class ceiling stands"
    ],
    "memory_class_floor": null,
    "memory_below_class_floor": false,
    "memory_not_attested": false,
    "memory_below_claim_reliability_floor": false,
    "memory_not_competent_authority": false,
    "memory_out_of_specification": false,
    "memory_ai_authored": true,
    "memory_ai_in_lineage": false,
    "memory_ai_position": "EXCLUDE_TAINTED_LINEAGE",
    "memory_ai_inadmissible": true,
    "memory_geo_inadmissible": false,
    "memory_geo_rung": null,
    "memory_geo_metric": null,
    "memory_geo_required_metric": null,
    "observer_attested": true,
    "observer_auth_code": "VERIFIED",
    "observer_key_id": "k_f71bde46a9680d8d",
    "attestation": null,
    "derivation": {
     "provenance": "MODELED",
     "ceiling_bp": 8000,
     "track": {
      "n": 1,
      "successes": 1
     },
     "wilson_bp": null,
     "age_days": 3,
     "max_age_days": 14,
     "house_max_age_days": 14,
     "instrument_max_age_days": null,
     "freshness_cap_bp": 4000,
     "min_track_n": 5,
     "wilson_z_milli": 1960,
     "source_present": true,
     "seller_asserted_cap_bp": 5000,
     "retracted": false,
     "contradicted": false,
     "outcome_trials": 0,
     "outcomes": {
      "verified": 0,
      "falsified": 0,
      "modified": 0,
      "counted": 0,
      "recorded": 0
     },
     "corroborations_counted": 0,
     "corroborations_discounted": 0,
     "reingest_ceiling_bp": null,
     "reingest_depth": null,
     "reingest_weakest_class": null,
     "reingest_source_confidence_bp": null,
     "ai_authored": true,
     "ai_authored_because": "a model, named as one in its own enrolled identity",
     "ai_in_lineage": false,
     "ai_position": "EXCLUDE_TAINTED_LINEAGE"
    },
    "memory_reason_codes": [
     {
      "code": "AI_AUTHORED_EXCLUDED",
      "observed": "actor:ai:triage-assistant-v4",
      "limit": "EXCLUDE_TAINTED_LINEAGE",
      "binding": true
     },
     {
      "code": "SPARSE_TRACK_RECORD",
      "observed": 1,
      "limit": 5,
      "binding": false
     }
    ]
   },
   {
    "key": "ai-system:TRIAGE-ASSISTANT-V4::vulnerability_triage_disposition",
    "value": null,
    "provenance": "MODELED",
    "source": "receipt:sha256:d9b9ab69f8c703568004833df6b17024b3fe60322618d2a33283edb39a363bde",
    "observed_at": "2026-08-08T16:00:00.000Z",
    "last_corroborated_at": null,
    "memory_refreshed_by": [],
    "reliability": 0.8,
    "critical": false,
    "memory_id": "mem_d84b950b487d",
    "memory_status": "withheld",
    "memory_kind": "receipt",
    "memory_actor": "actor:org:LAB-NVLAP-0412",
    "memory_age_days": 0,
    "memory_track": {
     "n": 1,
     "successes": 1
    },
    "memory_promoted_by": [],
    "memory_content_digest": "sha256:eb81e6a83d92e0175d5a21e45a29e0cc3dd88c07c53bfe3be082f0665aac8a77",
    "memory_outcomes": {
     "verified": 0,
     "falsified": 0,
     "modified": 0,
     "counted": 0,
     "recorded": 0
    },
    "memory_outcome_attestations": [],
    "memory_observer_lineage": null,
    "memory_corroborations": [],
    "memory_reingest": {
     "source_receipt_hash": "sha256:d9b9ab69f8c703568004833df6b17024b3fe60322618d2a33283edb39a363bde",
     "source_decision_id": "ai_TRIAGE_EARLIER_CYCLE",
     "source_verdict": "CAUTION",
     "source_confidence_bp": 8000,
     "weakest_key": "ai-system:TRIAGE-ASSISTANT-V4::vulnerability_triage_disposition",
     "weakest_class": "MODELED",
     "weakest_bp": 8000,
     "class_ceiling_bp": 8000,
     "inherited_chain_weakest_bp": 10000,
     "ai_in_lineage": true,
     "ai_lineage_actors": [
      "actor:ai:triage-assistant-v4"
     ],
     "ceiling_bp": 8000,
     "depth": 1,
     "max_depth": 3,
     "chain": [
      "sha256:d9b9ab69f8c703568004833df6b17024b3fe60322618d2a33283edb39a363bde"
     ],
     "presenter": "actor:org:LAB-NVLAP-0412",
     "verification_checks": 22,
     "verification_passed": 20
    },
    "memory_reasons": [
     "excluded on lineage: this record is a re-ingested receipt that itself rested on AI-authored evidence. The authority binding this claim excludes tainted lineage, which is what stops an exclusion being defeated by one round trip through a sealed receipt.",
     "sparse track record: 1 independent observation(s); no failure recorded, so the class ceiling stands"
    ],
    "memory_class_floor": null,
    "memory_below_class_floor": false,
    "memory_not_attested": false,
    "memory_below_claim_reliability_floor": false,
    "memory_not_competent_authority": false,
    "memory_out_of_specification": false,
    "memory_ai_authored": false,
    "memory_ai_in_lineage": true,
    "memory_ai_position": "EXCLUDE_TAINTED_LINEAGE",
    "memory_ai_inadmissible": true,
    "memory_geo_inadmissible": false,
    "memory_geo_rung": null,
    "memory_geo_metric": null,
    "memory_geo_required_metric": null,
    "observer_attested": true,
    "observer_auth_code": "VERIFIED",
    "observer_key_id": "k_17d23885943ae529",
    "attestation": null,
    "derivation": {
     "provenance": "MODELED",
     "ceiling_bp": 8000,
     "track": {
      "n": 1,
      "successes": 1
     },
     "wilson_bp": null,
     "age_days": 0,
     "max_age_days": 365,
     "house_max_age_days": 365,
     "instrument_max_age_days": null,
     "freshness_cap_bp": 4000,
     "min_track_n": 5,
     "wilson_z_milli": 1960,
     "source_present": true,
     "seller_asserted_cap_bp": 5000,
     "retracted": false,
     "contradicted": false,
     "outcome_trials": 0,
     "outcomes": {
      "verified": 0,
      "falsified": 0,
      "modified": 0,
      "counted": 0,
      "recorded": 0
     },
     "corroborations_counted": 0,
     "corroborations_discounted": 0,
     "reingest_ceiling_bp": 8000,
     "reingest_depth": 1,
     "reingest_weakest_class": "MODELED",
     "reingest_source_confidence_bp": 8000,
     "ai_authored": false,
     "ai_authored_because": null,
     "ai_in_lineage": true,
     "ai_position": "EXCLUDE_TAINTED_LINEAGE"
    },
    "memory_reason_codes": [
     {
      "code": "AI_LINEAGE_EXCLUDED",
      "observed": "sha256:d9b9ab69f8c703568004833df6b17024b3fe60322618d2a33283edb39a363bde",
      "limit": "EXCLUDE_TAINTED_LINEAGE",
      "binding": true
     },
     {
      "code": "SPARSE_TRACK_RECORD",
      "observed": 1,
      "limit": 5,
      "binding": false
     }
    ]
   },
   {
    "key": "ai-system:TRIAGE-ASSISTANT-V4::vulnerability_triage_disposition",
    "value": null,
    "provenance": "MISSING",
    "source": null,
    "observed_at": "2026-08-08T16:00:00.000Z",
    "reliability": 0,
    "critical": true,
    "memory_status": "coverage_gap",
    "gap_cause": "EVIDENCE_PRESENTED_FAILED",
    "gap_request": null,
    "gap_origin": "BUSINESS_EVIDENCE",
    "gap_conditions": [
     "ai_inadmissible"
    ]
   }
  ],
  "serialization": {
   "algorithm": "RFC8785-JCS",
   "hash": "sha256"
  },
  "crypto_suite": {
   "spec": "corobate:suite:1",
   "id": "CB-1-ES256-SHA256",
   "receipt_digest": "sha256",
   "chain_digest": "sha256",
   "content_digest": "sha256",
   "envelope_signature": "ES256",
   "signature_curve": "P-256",
   "canonicalisation": "attest-canon/2",
   "quantum_resistant": false
  },
  "confidence": {
   "value": 0,
   "method": "min-over-critical-inputs",
   "bound_by": "ai-system:TRIAGE-ASSISTANT-V4::vulnerability_triage_disposition"
  },
  "verdict": {
   "value": "WITHHELD",
   "threshold_approve": 0.85,
   "threshold_caution": 0.6,
   "rule": "confidence>=threshold"
  },
  "release": {
   "required": false,
   "required_by_tier": false,
   "escalated_by_acceptance": false,
   "risk_accepted": false,
   "state": "WITHHELD_NO_EVIDENCE",
   "code": "QUORUM_EVIDENCE_WITHHELD",
   "reason": "the evidence did not clear the threshold for this exposure, so there is nothing to release. Signatures do not substitute for evidence, and this state is deliberately distinct from WITHHELD_PENDING_SIGNATURES: a reader must be able to tell \"the evidence is not there\" from \"the evidence is there and 0 of 2 people have signed\".",
   "tier_floor_cents": 1000000000,
   "exposure_usd_cents": 25000000,
   "required_m": 2,
   "declared_n": 3,
   "floor_m": 2,
   "distinct_signers": 0,
   "superseded": 0,
   "collapsed": 0,
   "release_digest": "sha256:a3c837964666f08eab19f6d0645b630ecb8b87ace3c7b95b362ad7a02ed15846",
   "governance_digest": "sha256:8b0a45a27fcce9c1c243c764e855e67c6fe6dfd7f02a563bd90809b419731905",
   "governance_signed": true,
   "counted_voices": [],
   "signatures": [],
   "ledger_seq": null
  },
  "acceptance": {
   "state": "NONE",
   "code": "ACCEPTANCE_NONE",
   "reason": "no risk acceptance was presented for this decision. This is the ordinary case: a refusal is a refusal unless a named person has priced it.",
   "permitted_basis": null,
   "presented": 0,
   "superseded": 0,
   "expired": 0,
   "gaps_not_covered": 0,
   "coverage_gaps_in_force": [
    "ai-system:TRIAGE-ASSISTANT-V4|vulnerability_triage_disposition"
   ],
   "evidentiary_digest": "sha256:a3c837964666f08eab19f6d0645b630ecb8b87ace3c7b95b362ad7a02ed15846",
   "margin_floor_bp": 100,
   "authority_ceiling_cents": {
    "SUPERVISOR": 1000000,
    "MANAGER": 25000000,
    "DIRECTOR": 500000000,
    "OFFICER": 5000000000
   },
   "acceptances": [],
   "escalated": false,
   "live": false,
   "ledger_seq": null
  },
  "regulatory": {
   "spec": "corobate:regulatory:2",
   "resolved": true,
   "applied": [
    {
     "instrument_id": "enterprise-ai-evidence-standard",
     "version": 1,
     "authority": "Office of the Chief Information Security Officer",
     "instrument": "Enterprise standard on machine-generated evidence",
     "edition": "2026-03-01",
     "citation": "§ 3 [VERIFY]",
     "source_digest": "sha256:e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5",
     "entered_by": "actor:human:issm",
     "entered_at": "2026-08-08T16:00:00.000Z"
    },
    {
     "instrument_id": "nist-sp-800-53r5-moderate",
     "version": 5,
     "authority": "National Institute of Standards and Technology",
     "instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
     "edition": "Rev. 5",
     "citation": "CA-2, CA-8, RA-5, SR-6 [VERIFY]",
     "source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353",
     "entered_by": "actor:human:issm",
     "entered_at": "2026-08-08T16:00:00.000Z"
    }
   ],
   "skipped": [],
   "conflicts": [],
   "bindings": [
    {
     "claim": "control_assessment",
     "requirement": "max_age_days",
     "value": 365,
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
      "instrument_id": "nist-sp-800-53r5-moderate",
      "version": 5,
      "edition": "Rev. 5",
      "citation": "CA-2 [VERIFY]",
      "source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "control_assessment",
     "requirement": "min_class",
     "value": "VERIFIED",
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
      "instrument_id": "nist-sp-800-53r5-moderate",
      "version": 5,
      "edition": "Rev. 5",
      "citation": "CA-2(1) independent assessors [VERIFY]",
      "source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "control_assessment",
     "requirement": "required",
     "value": true,
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
      "instrument_id": "nist-sp-800-53r5-moderate",
      "version": 5,
      "edition": "Rev. 5",
      "citation": "CA-2 [VERIFY]",
      "source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "penetration_test",
     "requirement": "min_class",
     "value": "VERIFIED",
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
      "instrument_id": "nist-sp-800-53r5-moderate",
      "version": 5,
      "edition": "Rev. 5",
      "citation": "CA-8(1) independent penetration agent [VERIFY]",
      "source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "penetration_test",
     "requirement": "required",
     "value": true,
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
      "instrument_id": "nist-sp-800-53r5-moderate",
      "version": 5,
      "edition": "Rev. 5",
      "citation": "CA-8 [VERIFY]",
      "source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "vulnerability_scan",
     "requirement": "max_age_days",
     "value": 30,
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
      "instrument_id": "nist-sp-800-53r5-moderate",
      "version": 5,
      "edition": "Rev. 5",
      "citation": "RA-5(a) [VERIFY]",
      "source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "vulnerability_scan",
     "requirement": "required",
     "value": true,
     "bound_by": {
      "authority": "National Institute of Standards and Technology",
      "instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
      "instrument_id": "nist-sp-800-53r5-moderate",
      "version": 5,
      "edition": "Rev. 5",
      "citation": "RA-5 [VERIFY]",
      "source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "vulnerability_triage_disposition",
     "requirement": "ai_position",
     "value": "EXCLUDE_TAINTED_LINEAGE",
     "bound_by": {
      "authority": "Office of the Chief Information Security Officer",
      "instrument": "Enterprise standard on machine-generated evidence",
      "instrument_id": "enterprise-ai-evidence-standard",
      "version": 1,
      "edition": "2026-03-01",
      "citation": "§ 3.4 [VERIFY]",
      "source_digest": "sha256:e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    },
    {
     "claim": "vulnerability_triage_disposition",
     "requirement": "required",
     "value": true,
     "bound_by": {
      "authority": "Office of the Chief Information Security Officer",
      "instrument": "Enterprise standard on machine-generated evidence",
      "instrument_id": "enterprise-ai-evidence-standard",
      "version": 1,
      "edition": "2026-03-01",
      "citation": "§ 3.1 [VERIFY]",
      "source_digest": "sha256:e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5"
     },
     "also_bound_by": null,
     "weaker_asks": null,
     "downgraded_from": null,
     "downgrade_reason": null
    }
   ],
   "defaults": [
    {
     "claim": "control_assessment",
     "requirement": "ai_position",
     "value": "ADMIT",
     "because": "No instrument in force stated a position on AI-authored evidence for \"control_assessment\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
    },
    {
     "claim": "penetration_test",
     "requirement": "ai_position",
     "value": "ADMIT",
     "because": "No instrument in force stated a position on AI-authored evidence for \"penetration_test\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
    },
    {
     "claim": "vulnerability_scan",
     "requirement": "ai_position",
     "value": "ADMIT",
     "because": "No instrument in force stated a position on AI-authored evidence for \"vulnerability_scan\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
    }
   ]
  },
  "reasons": [
   "Coverage gap: no admissible memory for required claim(s) ai-system:TRIAGE-ASSISTANT-V4|vulnerability_triage_disposition.",
   "Confidence 0.00% is bound by \"ai-system:TRIAGE-ASSISTANT-V4|vulnerability_triage_disposition\".",
   "2 memories were withheld from the context block: ai-system:TRIAGE-ASSISTANT-V4|vulnerability_triage_disposition (AI-authored and excluded: the authority binding this claim does not accept model-authored evidence for it. Observed actor:ai:triage-assistant-v4 — a model, named as one in its own enrolled identity. Inadmissible at any reliability and any exposure. The remedy is to file this model's output under its OWN claim rather than under \"ai-system:TRIAGE-ASSISTANT-V4|vulnerability_triage_disposition\" — corroborating it does not help, because an identical value merges into this record and a different one contradicts it.); ai-system:TRIAGE-ASSISTANT-V4|vulnerability_triage_disposition (excluded on lineage: this record is a re-ingested receipt that itself rested on AI-authored evidence. The authority binding this claim excludes tainted lineage, which is what stops an exclusion being defeated by one round trip through a sealed receipt.).",
   "Thresholds for $250,000 exposure: approve 85%, caution 60%."
  ],
  "memory": {
   "layer": "capture->store->recall->act",
   "ledger_head": "sha256:666ec422cfa0a2aa3a0761bf5d34bc5eeb89079a0a37b9c86caf1f7e41c17603",
   "ledger_entries": 7,
   "context_digest": null,
   "context_memory_ids": [],
   "state_digest": "sha256:2c0c2a47680fbf012f29aba9e9ea7a1e4292e0b41243cd158d904090723e6562",
   "retrieval_method": "idf-lexical",
   "corpus_size": 5,
   "considered": 5,
   "admitted": 3,
   "withheld": 2,
   "not_considered": 0,
   "coverage_gaps": [
    "ai-system:TRIAGE-ASSISTANT-V4|vulnerability_triage_disposition"
   ],
   "exposure": {
    "usd": 250000,
    "declared_by": "actor:human:issm",
    "ledger_seq": 5
   },
   "salience_policy": {
    "half_life_days": 90,
    "grace_days": 7,
    "access_boost_bp": 500,
    "access_boost_cap_bp": 2500,
    "relevance_weight_bp": 6000,
    "recency_weight_bp": 3000,
    "usage_weight_bp": 1000,
    "context_cap": 12,
    "method": "idf-lexical",
    "candidate_list_digest": "sha256:8cd020e2ef86b9b3f5baad9171f55e6c93333bc9a97de3b19cc74a59e54d74ff",
    "note": "salience orders retrieval only; it never contributes to reliability"
   },
   "policy_digest": "sha256:a6b69b7d20f7fb04d522364af1d92992058b04a5835fcec9d1c9f2261c7ef636",
   "policy_body": {
    "class_ceiling_bp": {
     "VERIFIED": 9500,
     "MODELED": 8000,
     "SELLER-ASSERTED": 5000,
     "MISSING": 0
    },
    "actor_class_ceiling": [
     [
      "^actor:ai:",
      "MODELED"
     ],
     [
      "^actor:agent:",
      "MODELED"
     ],
     [
      "^actor:human:",
      "SELLER-ASSERTED"
     ],
     [
      "^actor:org:LAB-",
      "VERIFIED"
     ],
     [
      "^actor:org:CERT-",
      "VERIFIED"
     ],
     [
      "^actor:org:",
      "SELLER-ASSERTED"
     ],
     [
      "^actor:sys:registry:",
      "VERIFIED"
     ],
     [
      "^actor:sys:sensor:",
      "VERIFIED"
     ],
     [
      "^actor:sys:",
      "MODELED"
     ]
    ],
    "freshness_cap_bp": 4000,
    "max_age_days": {
     "telemetry": 1,
     "price": 7,
     "status": 14,
     "certificate": 365,
     "test_report": 180,
     "filing": 90,
     "transcript": 120,
     "highlight": 365,
     "voice_note": 120,
     "note": 365,
     "preference": 540,
     "decision": 1825,
     "receipt": 365,
     "default": 90
    },
    "wilson_z_milli": 1960,
    "min_track_n": 5,
    "exposure_tiers_bp": [
     [
      1000000000,
      9500,
      8000
     ],
     [
      100000000,
      9000,
      7000
     ],
     [
      1000000,
      8500,
      6000
     ],
     [
      0,
      8000,
      5000
     ]
    ],
    "max_context_memories": 12,
    "contradiction_resolve_margin": 2,
    "salience": {
     "half_life_days": 90,
     "grace_days": 7,
     "access_boost_bp": 500,
     "access_boost_cap_bp": 2500,
     "relevance_weight_bp": 6000,
     "recency_weight_bp": 3000,
     "usage_weight_bp": 1000
    }
   },
   "observer_auth": {
    "mode": "required",
    "registry_version": 3,
    "registry_digest": "sha256:460aeaafe345f69542a302e6619dff0712af98de6518838ee4c8585e448c3a7d",
    "entries_root": "sha256:5670469f96484a814462814ed74f0f992b5f19e8ad6afced548e4956e4835ba5",
    "memberships": [
     {
      "key_id": "k_17d23885943ae529",
      "index": 1,
      "entry": {
       "actor": "actor:org:LAB-NVLAP-0412",
       "class": "VERIFIED",
       "kind": "org",
       "key_id": "k_17d23885943ae529",
       "jwk": {
        "kty": "EC",
        "crv": "P-256",
        "x": "3TTw47-PkYfo3ZaKTq_qtHghnGvninAVj25kyOwONno",
        "y": "16PMaR8ofeF5IcZk6ZLml8gDs8uE1s1sBLdciH5e4vg"
       },
       "valid_from": "2025-01-01T00:00:00.000Z",
       "valid_to": "2027-06-01T00:00:00.000Z"
      },
      "path": [
       {
        "side": "left",
        "sibling": "sha256:500f2ba5949d5256ae0f563530b0b270db41ce99d2d7c4b4b60e4bd558ca353d"
       },
       {
        "side": "right",
        "sibling": "sha256:a0b47ea437bf4f1042a1dd50a5a3f411f9a17971812fc6bafccd434eb7d78ccc"
       },
       {
        "side": "right",
        "sibling": "sha256:d3c2347eb675e865fc17ef0204cacda7b02e8784a811fdd1c8a015d1865e6dfb"
       },
       {
        "side": "right",
        "sibling": "sha256:7071adf5e21a94147d31f42f1028b4867b6562e5b78726259c2515b03b213e52"
       }
      ]
     },
     {
      "key_id": "k_307e4bfd710ec9b3",
      "index": 0,
      "entry": {
       "actor": "actor:org:CERT-3PAO-ATLANTIC",
       "class": "VERIFIED",
       "kind": "org",
       "key_id": "k_307e4bfd710ec9b3",
       "jwk": {
        "kty": "EC",
        "crv": "P-256",
        "x": "MGtV26TezLMPjiD3SecQtnje6eLqYyx4qkKzzAkbiY4",
        "y": "SMMdLYnn-FpKbb2sJQ8EAZnzvozNm-cGO0VbUUpniPY"
       },
       "valid_from": "2025-01-01T00:00:00.000Z",
       "valid_to": "2027-06-01T00:00:00.000Z"
      },
      "path": [
       {
        "side": "right",
        "sibling": "sha256:4148869fc259d2c5fc19fe5831065b165a9acf81812e123162035acfdecade1d"
       },
       {
        "side": "right",
        "sibling": "sha256:a0b47ea437bf4f1042a1dd50a5a3f411f9a17971812fc6bafccd434eb7d78ccc"
       },
       {
        "side": "right",
        "sibling": "sha256:d3c2347eb675e865fc17ef0204cacda7b02e8784a811fdd1c8a015d1865e6dfb"
       },
       {
        "side": "right",
        "sibling": "sha256:7071adf5e21a94147d31f42f1028b4867b6562e5b78726259c2515b03b213e52"
       }
      ]
     },
     {
      "key_id": "k_5873dd9e7169def3",
      "index": 2,
      "entry": {
       "actor": "actor:sys:registry:nvd-cve",
       "class": "VERIFIED",
       "kind": "system",
       "key_id": "k_5873dd9e7169def3",
       "jwk": {
        "kty": "EC",
        "crv": "P-256",
        "x": "O9OY6oMuJg0df_INePO19_3b11VaSyMwIPdxoqvV2ak",
        "y": "k7Orm5pxDxMdTF-H2S4h6ixRywzk1WxvquOQeqxLFx0"
       },
       "valid_from": "2025-01-01T00:00:00.000Z",
       "valid_to": "2027-06-01T00:00:00.000Z"
      },
      "path": [
       {
        "side": "right",
        "sibling": "sha256:e1fe36fe7c8e4695327c25d6d722630b6249c93293bfdc5894c58aaf961ab6f8"
       },
       {
        "side": "left",
        "sibling": "sha256:e8b9cba101f13538b909a2e686e9e6e9a8d77212036ed567eaebc205a443e83f"
       },
       {
        "side": "right",
        "sibling": "sha256:d3c2347eb675e865fc17ef0204cacda7b02e8784a811fdd1c8a015d1865e6dfb"
       },
       {
        "side": "right",
        "sibling": "sha256:7071adf5e21a94147d31f42f1028b4867b6562e5b78726259c2515b03b213e52"
       }
      ]
     },
     {
      "key_id": "k_f71bde46a9680d8d",
      "index": 7,
      "entry": {
       "actor": "actor:ai:triage-assistant-v4",
       "class": "MODELED",
       "kind": "system",
       "key_id": "k_f71bde46a9680d8d",
       "jwk": {
        "kty": "EC",
        "crv": "P-256",
        "x": "AmVfK7ltK7mprIKSXcj-PNTw4f8zq2gcbRG-qEiFmbU",
        "y": "W7sar2SHGJ_jUsBSxoasMr7l1If81Qu5BdYfvlK8Who"
       },
       "valid_from": "2025-01-01T00:00:00.000Z",
       "valid_to": "2027-06-01T00:00:00.000Z"
      },
      "path": [
       {
        "side": "left",
        "sibling": "sha256:3e8eae859976a6f7d64543a05e28b4c8fc52b8500c65decc7e124af145fac567"
       },
       {
        "side": "left",
        "sibling": "sha256:6d20941c438f3924c50e6573d0712466ec6b91655705d2603ea89981e4c50ffc"
       },
       {
        "side": "left",
        "sibling": "sha256:d3f1d60ec9478d2b69455e5ba8168897966d18429bd3b7d36105841cc2ae1776"
       },
       {
        "side": "right",
        "sibling": "sha256:7071adf5e21a94147d31f42f1028b4867b6562e5b78726259c2515b03b213e52"
       }
      ]
     }
    ],
    "memberships_unproven": [],
    "revocation": {
     "source": "SIGNED_LIST",
     "digest": "sha256:12f73b1fbf27d38cf137b86a1ce13bbcd98161123a6aa7d79b107db8189966b9",
     "sequence": 5,
     "registry_version": 3,
     "issued_at": "2026-08-06T00:00:00.000Z",
     "next_update_due": "2026-08-13T00:00:00.000Z",
     "entry_count": 0,
     "body": {
      "sequence": 5,
      "registry_version": 3,
      "issuer": {
       "name": "NIST-regulated enterprise demonstration trust root",
       "key_id": "k_3793b8e35f8acac1"
      },
      "issued_at": "2026-08-06T00:00:00.000Z",
      "next_update_due": "2026-08-13T00:00:00.000Z",
      "entries": [],
      "spec": "corobate:revocation-list:1"
     }
    }
   },
   "governance": {
    "digest": "sha256:8b0a45a27fcce9c1c243c764e855e67c6fe6dfd7f02a563bd90809b419731905",
    "signed": true,
    "actor_trust": "FLOOR_TO_SELLER_ASSERTED",
    "outcome_trial_weight": 1,
    "max_reingest_depth": 3,
    "release_quorum_m": 2,
    "release_quorum_n": 3,
    "risk_acceptance_margin_bp": 500,
    "risk_acceptance_max_days": 30,
    "risk_acceptance_authority_cents": {
     "SUPERVISOR": 1000000,
     "MANAGER": 25000000,
     "DIRECTOR": 500000000,
     "OFFICER": 5000000000
    },
    "template_author_roles": [
     "MANAGER",
     "DIRECTOR",
     "OFFICER"
    ]
   },
   "observers_attested": 3,
   "outcomes": {
    "attestations_counted": 0,
    "attestations_recorded": 0,
    "records_with_outcomes": 0
   },
   "lineage": {
    "corroborations_counted": 0,
    "corroborations_discounted": 0,
    "records_with_discounted_corroborations": 0
   },
   "reingest": {
    "records": 0,
    "max_depth": 0,
    "weakest_class": null,
    "chain_weakest_bp": 10000,
    "chain": []
   },
   "template": null
  }
 }
}

What a control programme gets out of this

Every refusal on this page names the publication, the control identifier, the edition and the digest of the document it was read from. An assessor reading the regulator view finds their own catalogue cited back to them rather than a vendor's summary of it, and can re-derive every figure from the receipt with the published verifier, which imports nothing from the engine that produced it.

The AI position travels the same way. It is not a configuration flag inside a product — it is a rule in a signed instrument, attributed to an authority and a clause, sealed into the receipt's hashed body, drawn as a dial that is re-derived from that body rather than from the system that applied it, and re-checked by the published verifier as its own named identity. A recorded position that nothing enforces is the exact defect this estate found in its own never-waivable rule on 8 August 2026, and the remedy was not a better comment.

Generated by node 03-source/make-ally-data.js --write and node 16-site/build-ally.js. The build refuses to write a page if any receipt fails to verify, if any scoped copy fails its commitment check, or if the examiner's copy contains a commercial figure.

NIST publications are guidance and catalogues, not statutes, and encoding them as instruments is a READING. Every control identifier below is flagged [VERIFY] and needs a security officer's confirmation; the source digests are placeholders for documents this build never fetched. The structure is the claim; the readings are not. Party names are invented and no real assessor, provider or system is described.

Instruments were modelled from: NIST SP 800-53 Rev. 5 · NIST SP 800-161 Rev. 1 · NIST SP 800-218 (SSDF) v1.1 · NIST AI Risk Management Framework 1.0. Party names other than the publishing bodies are invented; no real vendor, dealer, assessor or vehicle is described here.
This page makes no network request and stores nothing in your browser.
Patent pending — U.S. Patent Application No. 19/747,068.

Everything on this site

Terms · Privacy · Licence · partners@corobate.com · Corobate LLC, North Carolina, USA