Corobate inside a NIST-regulated enterprise
A federal-facing enterprise is a hard case for a provenance gate for a specific reason: it is simultaneously the party being assessed and the party doing the assessing. NIST controls are written as obligations on an organisation — "the organization employs", "the organization documents" — and the naive encoding turns each one into a checkbox an employee ticks. That produces exactly the compliance theatre the catalogues exist to prevent: a self-attested control is a seller assertion about oneself, and a programme built entirely of them has no independent evidence in it anywhere.
The seven decisions below are chosen to expose that rather than hide it. Each one is real: the engine ran, a receipt was sealed, and the six scoped copies were derived and checked against the digest the receipt committed to before this page was written. The instruments are NIST publications, encoded by control identifier, edition and document digest.
Machine-generated evidence: the option to admit it, or refuse it
Every organisation running models inside a control programme is now answering a question no catalogue answers for them: may a model's own output carry a control? The three tabs at the end are the same system, the same 412 scanner findings and the same exposure, differing only in where the enterprise stands on that question.
It is a separate axis from provenance class, and the separation is the whole point. The class table already caps anything signed as a model at MODELED — but MODELED is a bucket holding two very different things: an unclassified telemetry feed, and a language model's account of work it did itself. An officer who tries to express "no model output behind this control" as a class floor of VERIFIED writes an AI policy that also silently bans thermometers. So the position is stated on its own axis, by an authority, with a citation, and it composes with every other instrument in force by the same rule everything else does: the strictest wins, and the authority that asked for less is recorded rather than dropped.
The strong evidence here is independent by construction: a third-party assessment organisation, an accredited laboratory, and a public vulnerability registry. The one weak item is the provider's own statement about its own subservice organisations — which is exactly the item a control questionnaire would have recorded as a tick.
- Subject
- system:CLOUDVANE-GOV-REGION-3
- Question
- May this cloud service be brought inside the authorisation boundary?
- Exposure
- $2,200,000
- Instruments
- National Institute of Standards and Technology · National Institute of Standards and Technology
- Outcome
- WITHHELD — the action is not permitted; outstanding: supplier assessment
- Receipt
- sha256:cc116c0bdb3d3f998c71834f6a365315765375dd99ed77c20c2a9ed4e007625e
The gate variables this decision ran under — a dial per question, read back off the sealed receipt
component provenancerequired
control assessmentrequired
penetration testrequired
supplier assessmentrequired
vulnerability scanrequired
Every bar above was re-derived from the regulatory bindings inside this receipt’s hashed body, not from the configuration that produced it. A bar in grey is a setting no instrument made — the deploying organisation’s own default, which still binds and is not an absence. A bar position renders an ordinal on a declared ladder: it is a way to draw a control and to compare two settings on the same axis, and it is not a measurement. The value printed beside each bar is the authoritative one.
Whoever must act now
The engineer with the deployment in their hands, the release manager, the person who must publish or hold.
One instruction and the reason in words. No score, no money, no signatures.
Seven or eight fields, and not one of them is a number somebody can argue with. This person is not being asked to re-judge the evidence; somebody already did, and it is on the record.
The scoped copy itself — partial — something outside this role’s remit was removed
{
"spec": "corobate:role-view:2",
"role": "OPERATOR",
"purpose": "Whoever must act on this decision now — release the goods, fund the draw, dispatch the agent, ship the title. Sees one instruction and the reason in plain words, and nothing that could be argued about while somebody waits.",
"is_a_receipt": false,
"warning": "This is a SCOPED COPY of a sealed decision, not the decision record itself. It will not verify as a receipt and must not be presented as one. To confirm it is faithful, recompute its `view` digest under the same canonicalisation that produces receipt_hash and compare it with the entry for this role in the source receipt’s `views` block.",
"derived_from": {
"receipt_hash": "sha256:cc116c0bdb3d3f998c71834f6a365315765375dd99ed77c20c2a9ed4e007625e",
"entry_hash": "sha256:d60b7a4f6b95aa315ea2d3ca369db1f2c20a5eea0fd5b641c3e36f23f6e23cff",
"issued_at": "2026-08-08T16:00:00.000Z"
},
"view_digest": "sha256:df8b6522881a6c186dbd5d96ae5616fc7204824773c1d8b2c2c1677f935c5152",
"withheld": {
"anything_withheld": true,
"note": "Facts outside this role’s remit were removed. That something was removed is stated so a partial record is never mistaken for a complete one. How much, and what, is not stated — a count is an inference about the part you are not entitled to see."
},
"view": {
"spec": "urn:ietf:params:corobate:receipt:1",
"receipt_version": "1.8",
"issued_at": "2026-08-08T16:00:00.000Z",
"decision": {
"id": "ato_CLOUDVANE_R3",
"subject": "system:CLOUDVANE-GOV-REGION-3"
},
"memory": {
"state_digest": "sha256:01827de72fd2a97521310c759fdc925c1c51ca2f43949aa72b79b19221e6ff88",
"ledger_head": "sha256:5bbeec39ca2744b408818488f7595e4b119e254325fd84642a3c66c636794c9c",
"coverage_gaps": [
"system:CLOUDVANE-GOV-REGION-3|supplier_assessment"
]
},
"verdict": {
"value": "WITHHELD"
},
"release": {
"state": "WITHHELD_NO_EVIDENCE"
}
}
}Provider / assessed party
The cloud service provider, the release team, or the party operating the AI system — whoever is being assessed.
Sees which controls were required of them and by which publication and control identifier. Does not see the authorising official’s exposure figure or how any shortfall was priced.
What is outstanding on your file
- supplier assessment — required by National Institute of Standards and Technology, SR-6 [VERIFY]
| Claim | Required | Evidence class | Who | Age | Outcome |
|---|---|---|---|---|---|
| vulnerability_scan | yes | VERIFIED | — | 2026-08-02 | admitted |
| component_provenance | yes | VERIFIED | — | 2026-05-10 | admitted |
| penetration_test | yes | VERIFIED | — | 2026-03-11 | admitted |
| control_assessment | yes | VERIFIED | — | 2026-04-10 | admitted |
| supplier_assessment | no | SELLER-ASSERTED | — | 2026-06-29 | withheld |
| supplier_assessment | yes | MISSING | — | 2026-08-08 | coverage gap |
The clause is here because it turns an argument into an errand. What is not here: what the bank had at stake, and whether anyone priced the shortfall.
The scoped copy itself — partial — something outside this role’s remit was removed
{
"spec": "corobate:role-view:2",
"role": "SUPPLIER",
"purpose": "The party whose evidence was judged. Sees every claim the decision required, which fell short, and the clause that required it — and nothing about what the buyer had at stake or how the buyer priced any shortfall. NOTE, because an earlier draft of this sentence was untrue: this projection carries the WHOLE inputs array, so where several parties supplied evidence for one decision, each of them sees all of it. Per-party scoping cannot be expressed by a commitment scheme with one digest per role, and claiming it anyway would be the kind of promise this file exists to stop making.",
"is_a_receipt": false,
"warning": "This is a SCOPED COPY of a sealed decision, not the decision record itself. It will not verify as a receipt and must not be presented as one. To confirm it is faithful, recompute its `view` digest under the same canonicalisation that produces receipt_hash and compare it with the entry for this role in the source receipt’s `views` block.",
"derived_from": {
"receipt_hash": "sha256:cc116c0bdb3d3f998c71834f6a365315765375dd99ed77c20c2a9ed4e007625e",
"entry_hash": "sha256:d60b7a4f6b95aa315ea2d3ca369db1f2c20a5eea0fd5b641c3e36f23f6e23cff",
"issued_at": "2026-08-08T16:00:00.000Z"
},
"view_digest": "sha256:fb3ec1004ea6e7f7012833cd6236f14ead6c7a07897c8d7629f5b248ca77a6fb",
"withheld": {
"anything_withheld": true,
"note": "Facts outside this role’s remit were removed. That something was removed is stated so a partial record is never mistaken for a complete one. How much, and what, is not stated — a count is an inference about the part you are not entitled to see."
},
"view": {
"spec": "urn:ietf:params:corobate:receipt:1",
"receipt_version": "1.8",
"issued_at": "2026-08-08T16:00:00.000Z",
"decision": {
"id": "ato_CLOUDVANE_R3",
"subject": "system:CLOUDVANE-GOV-REGION-3",
"question": "May this cloud service be brought inside the authorisation boundary?"
},
"memory": {
"state_digest": "sha256:01827de72fd2a97521310c759fdc925c1c51ca2f43949aa72b79b19221e6ff88",
"ledger_head": "sha256:5bbeec39ca2744b408818488f7595e4b119e254325fd84642a3c66c636794c9c",
"coverage_gaps": [
"system:CLOUDVANE-GOV-REGION-3|supplier_assessment"
]
},
"verdict": {
"value": "WITHHELD"
},
"inputs": [
{
"key": "system:CLOUDVANE-GOV-REGION-3::vulnerability_scan",
"provenance": "VERIFIED",
"observed_at": "2026-08-02T16:00:00.000Z",
"memory_status": "admitted",
"critical": true
},
{
"key": "system:CLOUDVANE-GOV-REGION-3::component_provenance",
"provenance": "VERIFIED",
"observed_at": "2026-05-10T16:00:00.000Z",
"memory_status": "admitted",
"critical": true
},
{
"key": "system:CLOUDVANE-GOV-REGION-3::penetration_test",
"provenance": "VERIFIED",
"observed_at": "2026-03-11T16:00:00.000Z",
"memory_status": "admitted",
"critical": true
},
{
"key": "system:CLOUDVANE-GOV-REGION-3::control_assessment",
"provenance": "VERIFIED",
"observed_at": "2026-04-10T16:00:00.000Z",
"memory_status": "admitted",
"critical": true
},
{
"key": "system:CLOUDVANE-GOV-REGION-3::supplier_assessment",
"provenance": "SELLER-ASSERTED",
"observed_at": "2026-06-29T16:00:00.000Z",
"memory_status": "withheld",
"critical": false
},
{
"key": "system:CLOUDVANE-GOV-REGION-3::supplier_assessment",
"provenance": "MISSING",
"observed_at": "2026-08-08T16:00:00.000Z",
"memory_status": "coverage_gap",
"critical": true
}
],
"regulatory": {
"bindings": [
{
"claim": "component_provenance",
"requirement": "min_class",
"value": "SELLER-ASSERTED",
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-161 Rev. 1 — C-SCRM Practices for Systems and Organizations",
"instrument_id": "nist-sp-800-161r1-cscrm",
"version": 1,
"edition": "Rev. 1",
"citation": "SR-4 [VERIFY]",
"source_digest": "sha256:6161616161616161616161616161616161616161616161616161616161616161"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "component_provenance",
"requirement": "required",
"value": true,
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-161 Rev. 1 — C-SCRM Practices for Systems and Organizations",
"instrument_id": "nist-sp-800-161r1-cscrm",
"version": 1,
"edition": "Rev. 1",
"citation": "SR-4 provenance [VERIFY]",
"source_digest": "sha256:6161616161616161616161616161616161616161616161616161616161616161"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "control_assessment",
"requirement": "max_age_days",
"value": 365,
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
"instrument_id": "nist-sp-800-53r5-moderate",
"version": 5,
"edition": "Rev. 5",
"citation": "CA-2 [VERIFY]",
"source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "control_assessment",
"requirement": "min_class",
"value": "VERIFIED",
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
"instrument_id": "nist-sp-800-53r5-moderate",
"version": 5,
"edition": "Rev. 5",
"citation": "CA-2(1) independent assessors [VERIFY]",
"source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "control_assessment",
"requirement": "required",
"value": true,
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
"instrument_id": "nist-sp-800-53r5-moderate",
"version": 5,
"edition": "Rev. 5",
"citation": "CA-2 [VERIFY]",
"source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "penetration_test",
"requirement": "min_class",
"value": "VERIFIED",
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
"instrument_id": "nist-sp-800-53r5-moderate",
"version": 5,
"edition": "Rev. 5",
"citation": "CA-8(1) independent penetration agent [VERIFY]",
"source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "penetration_test",
"requirement": "required",
"value": true,
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
"instrument_id": "nist-sp-800-53r5-moderate",
"version": 5,
"edition": "Rev. 5",
"citation": "CA-8 [VERIFY]",
"source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "supplier_assessment",
"requirement": "required",
"value": true,
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-161 Rev. 1 — C-SCRM Practices for Systems and Organizations",
"instrument_id": "nist-sp-800-161r1-cscrm",
"version": 1,
"edition": "Rev. 1",
"citation": "SR-6 [VERIFY]",
"source_digest": "sha256:6161616161616161616161616161616161616161616161616161616161616161"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "vulnerability_scan",
"requirement": "max_age_days",
"value": 30,
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
"instrument_id": "nist-sp-800-53r5-moderate",
"version": 5,
"edition": "Rev. 5",
"citation": "RA-5(a) [VERIFY]",
"source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "vulnerability_scan",
"requirement": "required",
"value": true,
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
"instrument_id": "nist-sp-800-53r5-moderate",
"version": 5,
"edition": "Rev. 5",
"citation": "RA-5 [VERIFY]",
"source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
}
],
"applied": [
{
"instrument_id": "nist-sp-800-53r5-moderate",
"version": 5,
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
"edition": "Rev. 5",
"citation": "CA-2, CA-8, RA-5, SR-6 [VERIFY]",
"source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353",
"entered_by": "actor:human:issm",
"entered_at": "2026-08-08T16:00:00.000Z"
},
{
"instrument_id": "nist-sp-800-161r1-cscrm",
"version": 1,
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-161 Rev. 1 — C-SCRM Practices for Systems and Organizations",
"edition": "Rev. 1",
"citation": "SR-3, SR-4, SR-11 [VERIFY]",
"source_digest": "sha256:6161616161616161616161616161616161616161616161616161616161616161",
"entered_by": "actor:human:issm",
"entered_at": "2026-08-08T16:00:00.000Z"
}
],
"defaults": [
{
"claim": "component_provenance",
"requirement": "ai_position",
"value": "ADMIT",
"because": "No instrument in force stated a position on AI-authored evidence for \"component_provenance\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
},
{
"claim": "control_assessment",
"requirement": "ai_position",
"value": "ADMIT",
"because": "No instrument in force stated a position on AI-authored evidence for \"control_assessment\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
},
{
"claim": "penetration_test",
"requirement": "ai_position",
"value": "ADMIT",
"because": "No instrument in force stated a position on AI-authored evidence for \"penetration_test\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
},
{
"claim": "supplier_assessment",
"requirement": "ai_position",
"value": "ADMIT",
"because": "No instrument in force stated a position on AI-authored evidence for \"supplier_assessment\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
},
{
"claim": "vulnerability_scan",
"requirement": "ai_position",
"value": "ADMIT",
"because": "No instrument in force stated a position on AI-authored evidence for \"vulnerability_scan\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
}
]
}
}
}Assessor / authorising official
A third-party assessment organisation, an agency assessor, or an inspector general reviewing the package. Same position as a customs officer: a public mandate over the record.
The control record in full — each publication by control identifier, edition and document digest, and every required claim with who supplied it and when. No exposure figure, no risk pricing, no confidence score.
What each authority bound
| Claim | Requirement | Level | Bound by |
|---|---|---|---|
| component_provenance | min class | SELLER-ASSERTED | National Institute of Standards and Technology SR-4 [VERIFY] · SP 800-161 Rev. 1 — C-SCRM Practices for Systems and Organizations |
| component_provenance | required | true | National Institute of Standards and Technology SR-4 provenance [VERIFY] · SP 800-161 Rev. 1 — C-SCRM Practices for Systems and Organizations |
| control_assessment | max age days | 365 | National Institute of Standards and Technology CA-2 [VERIFY] · SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline) |
| control_assessment | min class | VERIFIED | National Institute of Standards and Technology CA-2(1) independent assessors [VERIFY] · SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline) |
| control_assessment | required | true | National Institute of Standards and Technology CA-2 [VERIFY] · SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline) |
| penetration_test | min class | VERIFIED | National Institute of Standards and Technology CA-8(1) independent penetration agent [VERIFY] · SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline) |
| penetration_test | required | true | National Institute of Standards and Technology CA-8 [VERIFY] · SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline) |
| supplier_assessment | required | true | National Institute of Standards and Technology SR-6 [VERIFY] · SP 800-161 Rev. 1 — C-SCRM Practices for Systems and Organizations |
| vulnerability_scan | max age days | 30 | National Institute of Standards and Technology RA-5(a) [VERIFY] · SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline) |
| vulnerability_scan | required | true | National Institute of Standards and Technology RA-5 [VERIFY] · SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline) |
Every required claim, and what was actually held
| Claim | Required | Evidence class | Who | Age | Outcome |
|---|---|---|---|---|---|
| vulnerability_scan | yes | VERIFIED | actor:sys:registry:nvd-cve | 2026-08-02 | admitted |
| component_provenance | yes | VERIFIED | actor:sys:registry:contract-repository | 2026-05-10 | admitted |
| penetration_test | yes | VERIFIED | actor:org:LAB-NVLAP-0412 | 2026-03-11 | admitted |
| control_assessment | yes | VERIFIED | actor:org:CERT-3PAO-ATLANTIC | 2026-04-10 | admitted |
| supplier_assessment | no | SELLER-ASSERTED | actor:org:CLOUDVANE-GOV | 2026-06-29 | withheld |
| supplier_assessment | yes | MISSING | — | 2026-08-08 | coverage gap |
The scoped copy itself — partial — something outside this role’s remit was removed
{
"spec": "corobate:role-view:2",
"role": "REGULATOR",
"purpose": "An official holding a public mandate over this record — a customs officer, a bank examiner, a market conduct supervisor. Sees the regulatory record in full: their own instrument named, every required claim and whether it was met, by whom, how old. No commercial figure of any kind.",
"is_a_receipt": false,
"warning": "This is a SCOPED COPY of a sealed decision, not the decision record itself. It will not verify as a receipt and must not be presented as one. To confirm it is faithful, recompute its `view` digest under the same canonicalisation that produces receipt_hash and compare it with the entry for this role in the source receipt’s `views` block.",
"derived_from": {
"receipt_hash": "sha256:cc116c0bdb3d3f998c71834f6a365315765375dd99ed77c20c2a9ed4e007625e",
"entry_hash": "sha256:d60b7a4f6b95aa315ea2d3ca369db1f2c20a5eea0fd5b641c3e36f23f6e23cff",
"issued_at": "2026-08-08T16:00:00.000Z"
},
"view_digest": "sha256:e102db692451fc9dbd6a121ecc0bde60e54740537e0b652fe25ac735c5636f85",
"withheld": {
"anything_withheld": true,
"note": "Facts outside this role’s remit were removed. That something was removed is stated so a partial record is never mistaken for a complete one. How much, and what, is not stated — a count is an inference about the part you are not entitled to see."
},
"view": {
"spec": "urn:ietf:params:corobate:receipt:1",
"receipt_version": "1.8",
"issued_at": "2026-08-08T16:00:00.000Z",
"decision": {
"id": "ato_CLOUDVANE_R3",
"subject": "system:CLOUDVANE-GOV-REGION-3",
"question": "May this cloud service be brought inside the authorisation boundary?"
},
"memory": {
"state_digest": "sha256:01827de72fd2a97521310c759fdc925c1c51ca2f43949aa72b79b19221e6ff88",
"ledger_head": "sha256:5bbeec39ca2744b408818488f7595e4b119e254325fd84642a3c66c636794c9c",
"coverage_gaps": [
"system:CLOUDVANE-GOV-REGION-3|supplier_assessment"
]
},
"data_horizon": "2026-08-08T16:00:00.000Z",
"verdict": {
"value": "WITHHELD"
},
"regulatory": {
"spec": "corobate:regulatory:2",
"resolved": true,
"applied": [
{
"instrument_id": "nist-sp-800-53r5-moderate",
"version": 5,
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
"edition": "Rev. 5",
"citation": "CA-2, CA-8, RA-5, SR-6 [VERIFY]",
"source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353",
"entered_by": "actor:human:issm",
"entered_at": "2026-08-08T16:00:00.000Z"
},
{
"instrument_id": "nist-sp-800-161r1-cscrm",
"version": 1,
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-161 Rev. 1 — C-SCRM Practices for Systems and Organizations",
"edition": "Rev. 1",
"citation": "SR-3, SR-4, SR-11 [VERIFY]",
"source_digest": "sha256:6161616161616161616161616161616161616161616161616161616161616161",
"entered_by": "actor:human:issm",
"entered_at": "2026-08-08T16:00:00.000Z"
}
],
"skipped": [],
"conflicts": [],
"bindings": [
{
"claim": "component_provenance",
"requirement": "min_class",
"value": "SELLER-ASSERTED",
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-161 Rev. 1 — C-SCRM Practices for Systems and Organizations",
"instrument_id": "nist-sp-800-161r1-cscrm",
"version": 1,
"edition": "Rev. 1",
"citation": "SR-4 [VERIFY]",
"source_digest": "sha256:6161616161616161616161616161616161616161616161616161616161616161"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "component_provenance",
"requirement": "required",
"value": true,
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-161 Rev. 1 — C-SCRM Practices for Systems and Organizations",
"instrument_id": "nist-sp-800-161r1-cscrm",
"version": 1,
"edition": "Rev. 1",
"citation": "SR-4 provenance [VERIFY]",
"source_digest": "sha256:6161616161616161616161616161616161616161616161616161616161616161"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "control_assessment",
"requirement": "max_age_days",
"value": 365,
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
"instrument_id": "nist-sp-800-53r5-moderate",
"version": 5,
"edition": "Rev. 5",
"citation": "CA-2 [VERIFY]",
"source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "control_assessment",
"requirement": "min_class",
"value": "VERIFIED",
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
"instrument_id": "nist-sp-800-53r5-moderate",
"version": 5,
"edition": "Rev. 5",
"citation": "CA-2(1) independent assessors [VERIFY]",
"source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "control_assessment",
"requirement": "required",
"value": true,
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
"instrument_id": "nist-sp-800-53r5-moderate",
"version": 5,
"edition": "Rev. 5",
"citation": "CA-2 [VERIFY]",
"source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "penetration_test",
"requirement": "min_class",
"value": "VERIFIED",
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
"instrument_id": "nist-sp-800-53r5-moderate",
"version": 5,
"edition": "Rev. 5",
"citation": "CA-8(1) independent penetration agent [VERIFY]",
"source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "penetration_test",
"requirement": "required",
"value": true,
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
"instrument_id": "nist-sp-800-53r5-moderate",
"version": 5,
"edition": "Rev. 5",
"citation": "CA-8 [VERIFY]",
"source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "supplier_assessment",
"requirement": "required",
"value": true,
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-161 Rev. 1 — C-SCRM Practices for Systems and Organizations",
"instrument_id": "nist-sp-800-161r1-cscrm",
"version": 1,
"edition": "Rev. 1",
"citation": "SR-6 [VERIFY]",
"source_digest": "sha256:6161616161616161616161616161616161616161616161616161616161616161"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "vulnerability_scan",
"requirement": "max_age_days",
"value": 30,
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
"instrument_id": "nist-sp-800-53r5-moderate",
"version": 5,
"edition": "Rev. 5",
"citation": "RA-5(a) [VERIFY]",
"source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "vulnerability_scan",
"requirement": "required",
"value": true,
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
"instrument_id": "nist-sp-800-53r5-moderate",
"version": 5,
"edition": "Rev. 5",
"citation": "RA-5 [VERIFY]",
"source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
}
],
"defaults": [
{
"claim": "component_provenance",
"requirement": "ai_position",
"value": "ADMIT",
"because": "No instrument in force stated a position on AI-authored evidence for \"component_provenance\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
},
{
"claim": "control_assessment",
"requirement": "ai_position",
"value": "ADMIT",
"because": "No instrument in force stated a position on AI-authored evidence for \"control_assessment\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
},
{
"claim": "penetration_test",
"requirement": "ai_position",
"value": "ADMIT",
"because": "No instrument in force stated a position on AI-authored evidence for \"penetration_test\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
},
{
"claim": "supplier_assessment",
"requirement": "ai_position",
"value": "ADMIT",
"because": "No instrument in force stated a position on AI-authored evidence for \"supplier_assessment\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
},
{
"claim": "vulnerability_scan",
"requirement": "ai_position",
"value": "ADMIT",
"because": "No instrument in force stated a position on AI-authored evidence for \"vulnerability_scan\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
}
]
},
"inputs": [
{
"key": "system:CLOUDVANE-GOV-REGION-3::vulnerability_scan",
"provenance": "VERIFIED",
"source": "nvd-cve:vulnerability_scan",
"observed_at": "2026-08-02T16:00:00.000Z",
"critical": true,
"memory_status": "admitted",
"memory_actor": "actor:sys:registry:nvd-cve"
},
{
"key": "system:CLOUDVANE-GOV-REGION-3::component_provenance",
"provenance": "VERIFIED",
"source": "contract-repository:component_provenance",
"observed_at": "2026-05-10T16:00:00.000Z",
"critical": true,
"memory_status": "admitted",
"memory_actor": "actor:sys:registry:contract-repository"
},
{
"key": "system:CLOUDVANE-GOV-REGION-3::penetration_test",
"provenance": "VERIFIED",
"source": "LAB-NVLAP-0412:penetration_test",
"observed_at": "2026-03-11T16:00:00.000Z",
"critical": true,
"memory_status": "admitted",
"memory_actor": "actor:org:LAB-NVLAP-0412"
},
{
"key": "system:CLOUDVANE-GOV-REGION-3::control_assessment",
"provenance": "VERIFIED",
"source": "CERT-3PAO-ATLANTIC:control_assessment",
"observed_at": "2026-04-10T16:00:00.000Z",
"critical": true,
"memory_status": "admitted",
"memory_actor": "actor:org:CERT-3PAO-ATLANTIC"
},
{
"key": "system:CLOUDVANE-GOV-REGION-3::supplier_assessment",
"provenance": "SELLER-ASSERTED",
"source": "CLOUDVANE-GOV:supplier_assessment",
"observed_at": "2026-06-29T16:00:00.000Z",
"critical": false,
"memory_status": "withheld",
"memory_actor": "actor:org:CLOUDVANE-GOV"
},
{
"key": "system:CLOUDVANE-GOV-REGION-3::supplier_assessment",
"provenance": "MISSING",
"source": null,
"observed_at": "2026-08-08T16:00:00.000Z",
"critical": true,
"memory_status": "coverage_gap"
}
],
"crypto_suite": {
"spec": "corobate:suite:1",
"id": "CB-1-ES256-SHA256",
"receipt_digest": "sha256",
"chain_digest": "sha256",
"content_digest": "sha256",
"envelope_signature": "ES256",
"signature_curve": "P-256",
"canonicalisation": "attest-canon/2",
"quantum_resistant": false
}
}
}ISSM / control owner
The information system security manager and the control owners who hold the package.
The fullest internal view: every input, its class, its age, its score, the exposure, and every publication in force.
Every input the gate saw
| Claim | Required | Evidence class | Who | Age | Score | Outcome |
|---|---|---|---|---|---|---|
| vulnerability_scan | yes | VERIFIED | actor:sys:registry:nvd-cve | 6d | 95% | admitted |
| component_provenance | yes | VERIFIED | actor:sys:registry:contract-repository | 90d | 95% | admitted |
| penetration_test | yes | VERIFIED | actor:org:LAB-NVLAP-0412 | 150d | 95% | admitted |
| control_assessment | yes | VERIFIED | actor:org:CERT-3PAO-ATLANTIC | 120d | 95% | admitted |
| supplier_assessment | no | SELLER-ASSERTED | actor:org:CLOUDVANE-GOV | 40d | 40% | withheld |
| supplier_assessment | yes | MISSING | — | 2026-08-08 | 0% | coverage gap |
Instruments in force
Why
- Coverage gap: no admissible memory for required claim(s) system:CLOUDVANE-GOV-REGION-3|supplier_assessment.
- Confidence 0.00% is bound by "system:CLOUDVANE-GOV-REGION-3|supplier_assessment".
- 1 memory was withheld from the context block: system:CLOUDVANE-GOV-REGION-3|supplier_assessment (sparse track record: 1 independent observation(s); no failure recorded, so the class ceiling stands).
- Thresholds for $2,200,000 exposure: approve 90%, caution 70%.
The scoped copy itself — partial — something outside this role’s remit was removed
{
"spec": "corobate:role-view:2",
"role": "COMPLIANCE",
"purpose": "The operator’s own compliance function. The fullest internal view: every gap, every instrument in force, the waivability of each requirement and who accepted what.",
"is_a_receipt": false,
"warning": "This is a SCOPED COPY of a sealed decision, not the decision record itself. It will not verify as a receipt and must not be presented as one. To confirm it is faithful, recompute its `view` digest under the same canonicalisation that produces receipt_hash and compare it with the entry for this role in the source receipt’s `views` block.",
"derived_from": {
"receipt_hash": "sha256:cc116c0bdb3d3f998c71834f6a365315765375dd99ed77c20c2a9ed4e007625e",
"entry_hash": "sha256:d60b7a4f6b95aa315ea2d3ca369db1f2c20a5eea0fd5b641c3e36f23f6e23cff",
"issued_at": "2026-08-08T16:00:00.000Z"
},
"view_digest": "sha256:a89d4b30651ea80c88f153e1b4d7c6126ff521b6659ee0f6f07e8117f4a182f1",
"withheld": {
"anything_withheld": true,
"note": "Facts outside this role’s remit were removed. That something was removed is stated so a partial record is never mistaken for a complete one. How much, and what, is not stated — a count is an inference about the part you are not entitled to see."
},
"view": {
"spec": "urn:ietf:params:corobate:receipt:1",
"receipt_version": "1.8",
"issued_at": "2026-08-08T16:00:00.000Z",
"decision": {
"id": "ato_CLOUDVANE_R3",
"domain": "supply-chain",
"subject": "system:CLOUDVANE-GOV-REGION-3",
"question": "May this cloud service be brought inside the authorisation boundary?"
},
"memory": {
"state_digest": "sha256:01827de72fd2a97521310c759fdc925c1c51ca2f43949aa72b79b19221e6ff88",
"ledger_head": "sha256:5bbeec39ca2744b408818488f7595e4b119e254325fd84642a3c66c636794c9c",
"coverage_gaps": [
"system:CLOUDVANE-GOV-REGION-3|supplier_assessment"
],
"exposure": {
"usd": 2200000,
"declared_by": "actor:human:ao-authorizing-official",
"ledger_seq": 5
},
"policy_digest": "sha256:a6b69b7d20f7fb04d522364af1d92992058b04a5835fcec9d1c9f2261c7ef636"
},
"data_horizon": "2026-08-08T16:00:00.000Z",
"verdict": {
"value": "WITHHELD",
"threshold_approve": 0.9,
"threshold_caution": 0.7,
"rule": "confidence>=threshold"
},
"confidence": {
"value": 0,
"method": "min-over-critical-inputs",
"bound_by": "system:CLOUDVANE-GOV-REGION-3::supplier_assessment"
},
"release": {
"required": false,
"required_by_tier": false,
"escalated_by_acceptance": false,
"risk_accepted": false,
"state": "WITHHELD_NO_EVIDENCE",
"code": "QUORUM_EVIDENCE_WITHHELD",
"reason": "the evidence did not clear the threshold for this exposure, so there is nothing to release. Signatures do not substitute for evidence, and this state is deliberately distinct from WITHHELD_PENDING_SIGNATURES: a reader must be able to tell \"the evidence is not there\" from \"the evidence is there and 0 of 2 people have signed\".",
"tier_floor_cents": 1000000000,
"exposure_usd_cents": 220000000,
"required_m": 2,
"declared_n": 3,
"floor_m": 2,
"distinct_signers": 0,
"superseded": 0,
"collapsed": 0,
"release_digest": "sha256:8ef23045c8d8714e4d68ec83739091959dcb5765515b96c8c66ebbf99a4558ec",
"governance_digest": "sha256:8b0a45a27fcce9c1c243c764e855e67c6fe6dfd7f02a563bd90809b419731905",
"governance_signed": true,
"counted_voices": [],
"signatures": [],
"ledger_seq": null
},
"acceptance": {
"state": "NONE",
"code": "ACCEPTANCE_NONE",
"reason": "no risk acceptance was presented for this decision. This is the ordinary case: a refusal is a refusal unless a named person has priced it.",
"permitted_basis": null,
"presented": 0,
"superseded": 0,
"expired": 0,
"gaps_not_covered": 0,
"coverage_gaps_in_force": [
"system:CLOUDVANE-GOV-REGION-3|supplier_assessment"
],
"evidentiary_digest": "sha256:8ef23045c8d8714e4d68ec83739091959dcb5765515b96c8c66ebbf99a4558ec",
"margin_floor_bp": 100,
"authority_ceiling_cents": {
"SUPERVISOR": 1000000,
"MANAGER": 25000000,
"DIRECTOR": 500000000,
"OFFICER": 5000000000
},
"acceptances": [],
"escalated": false,
"live": false,
"ledger_seq": null
},
"regulatory": {
"spec": "corobate:regulatory:2",
"resolved": true,
"applied": [
{
"instrument_id": "nist-sp-800-53r5-moderate",
"version": 5,
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
"edition": "Rev. 5",
"citation": "CA-2, CA-8, RA-5, SR-6 [VERIFY]",
"source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353",
"entered_by": "actor:human:issm",
"entered_at": "2026-08-08T16:00:00.000Z"
},
{
"instrument_id": "nist-sp-800-161r1-cscrm",
"version": 1,
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-161 Rev. 1 — C-SCRM Practices for Systems and Organizations",
"edition": "Rev. 1",
"citation": "SR-3, SR-4, SR-11 [VERIFY]",
"source_digest": "sha256:6161616161616161616161616161616161616161616161616161616161616161",
"entered_by": "actor:human:issm",
"entered_at": "2026-08-08T16:00:00.000Z"
}
],
"skipped": [],
"conflicts": [],
"bindings": [
{
"claim": "component_provenance",
"requirement": "min_class",
"value": "SELLER-ASSERTED",
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-161 Rev. 1 — C-SCRM Practices for Systems and Organizations",
"instrument_id": "nist-sp-800-161r1-cscrm",
"version": 1,
"edition": "Rev. 1",
"citation": "SR-4 [VERIFY]",
"source_digest": "sha256:6161616161616161616161616161616161616161616161616161616161616161"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "component_provenance",
"requirement": "required",
"value": true,
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-161 Rev. 1 — C-SCRM Practices for Systems and Organizations",
"instrument_id": "nist-sp-800-161r1-cscrm",
"version": 1,
"edition": "Rev. 1",
"citation": "SR-4 provenance [VERIFY]",
"source_digest": "sha256:6161616161616161616161616161616161616161616161616161616161616161"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "control_assessment",
"requirement": "max_age_days",
"value": 365,
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
"instrument_id": "nist-sp-800-53r5-moderate",
"version": 5,
"edition": "Rev. 5",
"citation": "CA-2 [VERIFY]",
"source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "control_assessment",
"requirement": "min_class",
"value": "VERIFIED",
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
"instrument_id": "nist-sp-800-53r5-moderate",
"version": 5,
"edition": "Rev. 5",
"citation": "CA-2(1) independent assessors [VERIFY]",
"source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "control_assessment",
"requirement": "required",
"value": true,
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
"instrument_id": "nist-sp-800-53r5-moderate",
"version": 5,
"edition": "Rev. 5",
"citation": "CA-2 [VERIFY]",
"source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "penetration_test",
"requirement": "min_class",
"value": "VERIFIED",
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
"instrument_id": "nist-sp-800-53r5-moderate",
"version": 5,
"edition": "Rev. 5",
"citation": "CA-8(1) independent penetration agent [VERIFY]",
"source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "penetration_test",
"requirement": "required",
"value": true,
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
"instrument_id": "nist-sp-800-53r5-moderate",
"version": 5,
"edition": "Rev. 5",
"citation": "CA-8 [VERIFY]",
"source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "supplier_assessment",
"requirement": "required",
"value": true,
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-161 Rev. 1 — C-SCRM Practices for Systems and Organizations",
"instrument_id": "nist-sp-800-161r1-cscrm",
"version": 1,
"edition": "Rev. 1",
"citation": "SR-6 [VERIFY]",
"source_digest": "sha256:6161616161616161616161616161616161616161616161616161616161616161"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "vulnerability_scan",
"requirement": "max_age_days",
"value": 30,
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
"instrument_id": "nist-sp-800-53r5-moderate",
"version": 5,
"edition": "Rev. 5",
"citation": "RA-5(a) [VERIFY]",
"source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "vulnerability_scan",
"requirement": "required",
"value": true,
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
"instrument_id": "nist-sp-800-53r5-moderate",
"version": 5,
"edition": "Rev. 5",
"citation": "RA-5 [VERIFY]",
"source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
}
],
"defaults": [
{
"claim": "component_provenance",
"requirement": "ai_position",
"value": "ADMIT",
"because": "No instrument in force stated a position on AI-authored evidence for \"component_provenance\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
},
{
"claim": "control_assessment",
"requirement": "ai_position",
"value": "ADMIT",
"because": "No instrument in force stated a position on AI-authored evidence for \"control_assessment\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
},
{
"claim": "penetration_test",
"requirement": "ai_position",
"value": "ADMIT",
"because": "No instrument in force stated a position on AI-authored evidence for \"penetration_test\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
},
{
"claim": "supplier_assessment",
"requirement": "ai_position",
"value": "ADMIT",
"because": "No instrument in force stated a position on AI-authored evidence for \"supplier_assessment\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
},
{
"claim": "vulnerability_scan",
"requirement": "ai_position",
"value": "ADMIT",
"because": "No instrument in force stated a position on AI-authored evidence for \"vulnerability_scan\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
}
]
},
"reasons": [
"Coverage gap: no admissible memory for required claim(s) system:CLOUDVANE-GOV-REGION-3|supplier_assessment.",
"Confidence 0.00% is bound by \"system:CLOUDVANE-GOV-REGION-3|supplier_assessment\".",
"1 memory was withheld from the context block: system:CLOUDVANE-GOV-REGION-3|supplier_assessment (sparse track record: 1 independent observation(s); no failure recorded, so the class ceiling stands).",
"Thresholds for $2,200,000 exposure: approve 90%, caution 70%."
],
"inputs": [
{
"key": "system:CLOUDVANE-GOV-REGION-3::vulnerability_scan",
"value": "clean-at-scan",
"provenance": "VERIFIED",
"source": "nvd-cve:vulnerability_scan",
"observed_at": "2026-08-02T16:00:00.000Z",
"reliability": 0.95,
"critical": true,
"memory_status": "admitted",
"memory_kind": "status",
"memory_actor": "actor:sys:registry:nvd-cve",
"memory_age_days": 6
},
{
"key": "system:CLOUDVANE-GOV-REGION-3::component_provenance",
"value": "schedule",
"provenance": "VERIFIED",
"source": "contract-repository:component_provenance",
"observed_at": "2026-05-10T16:00:00.000Z",
"reliability": 0.95,
"critical": true,
"memory_status": "admitted",
"memory_kind": "certificate",
"memory_actor": "actor:sys:registry:contract-repository",
"memory_age_days": 90
},
{
"key": "system:CLOUDVANE-GOV-REGION-3::penetration_test",
"value": "no-critical",
"provenance": "VERIFIED",
"source": "LAB-NVLAP-0412:penetration_test",
"observed_at": "2026-03-11T16:00:00.000Z",
"reliability": 0.95,
"critical": true,
"memory_status": "admitted",
"memory_kind": "test_report",
"memory_actor": "actor:org:LAB-NVLAP-0412",
"memory_age_days": 150
},
{
"key": "system:CLOUDVANE-GOV-REGION-3::control_assessment",
"value": "satisfied-with-poams",
"provenance": "VERIFIED",
"source": "CERT-3PAO-ATLANTIC:control_assessment",
"observed_at": "2026-04-10T16:00:00.000Z",
"reliability": 0.95,
"critical": true,
"memory_status": "admitted",
"memory_kind": "certificate",
"memory_actor": "actor:org:CERT-3PAO-ATLANTIC",
"memory_age_days": 120
},
{
"key": "system:CLOUDVANE-GOV-REGION-3::supplier_assessment",
"value": null,
"provenance": "SELLER-ASSERTED",
"source": "CLOUDVANE-GOV:supplier_assessment",
"observed_at": "2026-06-29T16:00:00.000Z",
"reliability": 0.4,
"critical": false,
"memory_status": "withheld",
"memory_kind": "status",
"memory_actor": "actor:org:CLOUDVANE-GOV",
"memory_age_days": 40
},
{
"key": "system:CLOUDVANE-GOV-REGION-3::supplier_assessment",
"value": null,
"provenance": "MISSING",
"source": null,
"observed_at": "2026-08-08T16:00:00.000Z",
"reliability": 0,
"critical": true,
"memory_status": "coverage_gap"
}
],
"crypto_suite": {
"spec": "corobate:suite:1",
"id": "CB-1-ES256-SHA256",
"receipt_digest": "sha256",
"chain_digest": "sha256",
"content_digest": "sha256",
"envelope_signature": "ES256",
"signature_curve": "P-256",
"canonicalisation": "attest-canon/2",
"quantum_resistant": false
}
}
}Authorising official (signer)
The named official whose signature carries the authorisation decision.
What is at stake, what the evidence supports, what is missing, and the digest they are signing over.
You are being asked to sign
May this cloud service be brought inside the authorisation boundary?
The signature is over the STATE OF THE EVIDENCE. Move one fact behind this decision and the digest moves and the signature stops counting — which is what makes it safe to collect signatures before everyone is in the room.
What is missing
- supplier assessment
The scoped copy itself — partial — something outside this role’s remit was removed
{
"spec": "corobate:role-view:2",
"role": "EXECUTIVE",
"purpose": "A named signer on the release gate. Sees what is at stake, what the evidence supports, who else has signed and what they are being asked to sign over.",
"is_a_receipt": false,
"warning": "This is a SCOPED COPY of a sealed decision, not the decision record itself. It will not verify as a receipt and must not be presented as one. To confirm it is faithful, recompute its `view` digest under the same canonicalisation that produces receipt_hash and compare it with the entry for this role in the source receipt’s `views` block.",
"derived_from": {
"receipt_hash": "sha256:cc116c0bdb3d3f998c71834f6a365315765375dd99ed77c20c2a9ed4e007625e",
"entry_hash": "sha256:d60b7a4f6b95aa315ea2d3ca369db1f2c20a5eea0fd5b641c3e36f23f6e23cff",
"issued_at": "2026-08-08T16:00:00.000Z"
},
"view_digest": "sha256:0cf465714d0c4787762ad88079ddd218dbc696be4ca734ca4b713c0b5ac783c7",
"withheld": {
"anything_withheld": true,
"note": "Facts outside this role’s remit were removed. That something was removed is stated so a partial record is never mistaken for a complete one. How much, and what, is not stated — a count is an inference about the part you are not entitled to see."
},
"view": {
"spec": "urn:ietf:params:corobate:receipt:1",
"receipt_version": "1.8",
"issued_at": "2026-08-08T16:00:00.000Z",
"decision": {
"id": "ato_CLOUDVANE_R3",
"domain": "supply-chain",
"subject": "system:CLOUDVANE-GOV-REGION-3",
"question": "May this cloud service be brought inside the authorisation boundary?"
},
"memory": {
"state_digest": "sha256:01827de72fd2a97521310c759fdc925c1c51ca2f43949aa72b79b19221e6ff88",
"ledger_head": "sha256:5bbeec39ca2744b408818488f7595e4b119e254325fd84642a3c66c636794c9c",
"coverage_gaps": [
"system:CLOUDVANE-GOV-REGION-3|supplier_assessment"
],
"exposure": {
"usd": 2200000,
"declared_by": "actor:human:ao-authorizing-official",
"ledger_seq": 5
}
},
"verdict": {
"value": "WITHHELD",
"threshold_approve": 0.9,
"threshold_caution": 0.7,
"rule": "confidence>=threshold"
},
"confidence": {
"value": 0,
"method": "min-over-critical-inputs",
"bound_by": "system:CLOUDVANE-GOV-REGION-3::supplier_assessment"
},
"release": {
"required": false,
"required_by_tier": false,
"escalated_by_acceptance": false,
"risk_accepted": false,
"state": "WITHHELD_NO_EVIDENCE",
"code": "QUORUM_EVIDENCE_WITHHELD",
"reason": "the evidence did not clear the threshold for this exposure, so there is nothing to release. Signatures do not substitute for evidence, and this state is deliberately distinct from WITHHELD_PENDING_SIGNATURES: a reader must be able to tell \"the evidence is not there\" from \"the evidence is there and 0 of 2 people have signed\".",
"tier_floor_cents": 1000000000,
"exposure_usd_cents": 220000000,
"required_m": 2,
"declared_n": 3,
"floor_m": 2,
"distinct_signers": 0,
"superseded": 0,
"collapsed": 0,
"release_digest": "sha256:8ef23045c8d8714e4d68ec83739091959dcb5765515b96c8c66ebbf99a4558ec",
"governance_digest": "sha256:8b0a45a27fcce9c1c243c764e855e67c6fe6dfd7f02a563bd90809b419731905",
"governance_signed": true,
"counted_voices": [],
"signatures": [],
"ledger_seq": null
},
"acceptance": {
"state": "NONE",
"code": "ACCEPTANCE_NONE",
"reason": "no risk acceptance was presented for this decision. This is the ordinary case: a refusal is a refusal unless a named person has priced it.",
"permitted_basis": null,
"presented": 0,
"superseded": 0,
"expired": 0,
"gaps_not_covered": 0,
"coverage_gaps_in_force": [
"system:CLOUDVANE-GOV-REGION-3|supplier_assessment"
],
"evidentiary_digest": "sha256:8ef23045c8d8714e4d68ec83739091959dcb5765515b96c8c66ebbf99a4558ec",
"margin_floor_bp": 100,
"authority_ceiling_cents": {
"SUPERVISOR": 1000000,
"MANAGER": 25000000,
"DIRECTOR": 500000000,
"OFFICER": 5000000000
},
"acceptances": [],
"escalated": false,
"live": false,
"ledger_seq": null
},
"reasons": [
"Coverage gap: no admissible memory for required claim(s) system:CLOUDVANE-GOV-REGION-3|supplier_assessment.",
"Confidence 0.00% is bound by \"system:CLOUDVANE-GOV-REGION-3|supplier_assessment\".",
"1 memory was withheld from the context block: system:CLOUDVANE-GOV-REGION-3|supplier_assessment (sparse track record: 1 independent observation(s); no failure recorded, so the class ceiling stands).",
"Thresholds for $2,200,000 exposure: approve 90%, caution 70%."
],
"regulatory": {
"applied": [
{
"instrument_id": "nist-sp-800-53r5-moderate",
"version": 5,
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
"edition": "Rev. 5",
"citation": "CA-2, CA-8, RA-5, SR-6 [VERIFY]",
"source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353",
"entered_by": "actor:human:issm",
"entered_at": "2026-08-08T16:00:00.000Z"
},
{
"instrument_id": "nist-sp-800-161r1-cscrm",
"version": 1,
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-161 Rev. 1 — C-SCRM Practices for Systems and Organizations",
"edition": "Rev. 1",
"citation": "SR-3, SR-4, SR-11 [VERIFY]",
"source_digest": "sha256:6161616161616161616161616161616161616161616161616161616161616161",
"entered_by": "actor:human:issm",
"entered_at": "2026-08-08T16:00:00.000Z"
}
],
"conflicts": [],
"defaults": [
{
"claim": "component_provenance",
"requirement": "ai_position",
"value": "ADMIT",
"because": "No instrument in force stated a position on AI-authored evidence for \"component_provenance\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
},
{
"claim": "control_assessment",
"requirement": "ai_position",
"value": "ADMIT",
"because": "No instrument in force stated a position on AI-authored evidence for \"control_assessment\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
},
{
"claim": "penetration_test",
"requirement": "ai_position",
"value": "ADMIT",
"because": "No instrument in force stated a position on AI-authored evidence for \"penetration_test\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
},
{
"claim": "supplier_assessment",
"requirement": "ai_position",
"value": "ADMIT",
"because": "No instrument in force stated a position on AI-authored evidence for \"supplier_assessment\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
},
{
"claim": "vulnerability_scan",
"requirement": "ai_position",
"value": "ADMIT",
"because": "No instrument in force stated a position on AI-authored evidence for \"vulnerability_scan\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
}
]
},
"inputs": [
{
"key": "system:CLOUDVANE-GOV-REGION-3::vulnerability_scan",
"provenance": "VERIFIED",
"reliability": 0.95,
"critical": true,
"memory_status": "admitted"
},
{
"key": "system:CLOUDVANE-GOV-REGION-3::component_provenance",
"provenance": "VERIFIED",
"reliability": 0.95,
"critical": true,
"memory_status": "admitted"
},
{
"key": "system:CLOUDVANE-GOV-REGION-3::penetration_test",
"provenance": "VERIFIED",
"reliability": 0.95,
"critical": true,
"memory_status": "admitted"
},
{
"key": "system:CLOUDVANE-GOV-REGION-3::control_assessment",
"provenance": "VERIFIED",
"reliability": 0.95,
"critical": true,
"memory_status": "admitted"
},
{
"key": "system:CLOUDVANE-GOV-REGION-3::supplier_assessment",
"provenance": "SELLER-ASSERTED",
"reliability": 0.4,
"critical": false,
"memory_status": "withheld"
},
{
"key": "system:CLOUDVANE-GOV-REGION-3::supplier_assessment",
"provenance": "MISSING",
"reliability": 0,
"critical": true,
"memory_status": "coverage_gap"
}
]
}
}Independent audit / IG
Internal audit, an inspector general, or an external auditor testing the programme.
Everything, plus the verifier’s own findings over the sealed record.
This view withholds nothing. What it adds is the 22 checks the published verifier ran over the sealed record behind every other view of this decision — recomputed at build time, not asserted.
| # | Check | Detail | |
|---|---|---|---|
| 1 | Content reproduces (JCS + SHA-256) | PASS | matches sha256:cc116c0bdb3d3f998c71834f6a365315765375dd99ed77c20c2a9ed4e007625e |
| 2 | Hash chain links (entry = H(prev||content)) | PASS | head sha256:d60b7a4f6b95aa315ea2d3ca369db1f2c20a5eea0fd5b641c3e36f23f6e23cff |
| 3 | Confidence gated by weakest critical input | PASS | min over critical = 0, bound_by system:CLOUDVANE-GOV-REGION-3::supplier_assessment (MISSING) |
| 3b | Verdict follows the threshold rule | PASS | 0 => WITHHELD; recorded WITHHELD |
| 4 | Point-in-time seal (no input past data_horizon) | PASS | all inputs <= 2026-08-08T16:00:00.000Z |
| 5 | Anchor covers the head, and the timestamp token re-reads | PASS | internally consistent; NO external anchor was requested — this is not a validated timestamp |
| 6 | Criteria travel with the receipt and reproduce | PASS | policy_body hashes to sha256:a6b69b7d20f7fb04d522364af1d92992058b04a5835fcec9d1c9f2261c7ef636 |
| 7 | Reliability re-derives from recorded evidence | PASS | all 6 inputs re-derive exactly |
| 8 | Outcome trials and lineage discounts re-derive | PASS | 5 input(s) re-derive: 0 credited outcome trial(s), 0 lineage-discounted corroboration(s); every reliability is at or under its class ceiling |
| 9 | Re-ingested receipts respect their weakest-input ceiling | PASS | no re-ingested receipts: every input rests on a primary observation |
| 10 | Release quorum re-derives | PASS | WITHHELD_NO_EVIDENCE - below the top exposure tier, no multi-party requirement applies |
| 11 | Risk acceptance re-derives | PASS | no risk acceptance: this decision stands or falls on its evidence |
| 12 | Observer credentials were not revoked as of observation time | PASS | revocation list 5 (0 entries, issued 2026-08-06T00:00:00.000Z, next update due 2026-08-13T00:00:00.000Z) reproduces; 4 observer signature(s) judged as of their own instant, none under a key revoked as compromised or retired by then |
| 13 | The cryptographic suite is named and is one this verifier implements | PASS | sealed under CB-1-ES256-SHA256 (ES256 / sha256, attest-canon/2); this verifier implements it; the suite states it is NOT quantum resistant |
| 14 | Regulatory bindings are attributed and were enforced | PASS | 10 binding(s) from 2 instrument(s) in force, each attributed to an authority, a citation and a document digest; 5 required claim(s) all reached the gate |
| 15 | Role-view commitments re-derive, and the customs view carries no money | PASS | 6 role-view commitment(s) re-derived from this receipt’s own body by this verifier’s independent projection; the REGULATOR view carries no commercial figure |
| 16 | AI-authored input was admitted only where an authority allowed it | PASS | 0 claim(s) carry a position on AI-authored evidence set by an authority and 5 carry a recorded default nobody set; 0 exclusion(s) and 0 corroboration-only rule(s) re-derived against this receipt's own admitted inputs; 0 admitted input(s) are AI-authored by their enrolled identity |
| 17 | State digest recomputes from the ledger alone | UNVERIFIABLE | NOT APPLICABLE — you supplied no ledger, so the state digest cannot be re-derived from anything. This receipt commits to the corpus the deciding system held at the instant it sealed, and that commitment is checked by recomputing it from the append-only ledger and comparing; with no ledger in hand there is no second artefact to recompute from. The receipt is not at fault and nothing here is missing from it. Obtain the ledger from the issuer and re-run with --ledger <file>, or verifyReceipt(r, {ledger}). Nothing here has failed and nothing here has passed. |
| 18 | Registry membership re-derives for every key relied on | PASS | all 4 key(s) relied on re-derive to the entries root registry v3 committed to and the trust root signed |
| 20 | Geometric support re-derives, and an unevaluated record is not a supported one | PASS | no authority bound a metric to any claim on this receipt, so no geometric test applied. A claim nobody bound a metric to is not a claim about geometry, and this is a stated absence rather than a silent one |
| 19 | The cause of every uncovered requirement re-derives | PASS | all 1 uncovered requirement(s) re-derive their cause from this receipt's own rows. What notice is ADEQUATE is not decided here: this check establishes what the record says and that the record agrees with itself. |
| 21 | The sealing party is the one you were told to expect | UNVERIFIABLE | NOT APPLICABLE — you supplied no trust bundle, so nothing here establishes who sealed this. Identities 1 to 20 prove that this document agrees with itself; not one of them asks whose trust root it was sealed under, and a document that agrees with itself about a decision nobody made agrees with itself perfectly. Obtain the issuer's corobate:trust-bundle:1 out of band, confirm its spoken fingerprint with them by voice, and re-run with --trust-bundle <file> --expect-fingerprint <what you heard>. Nothing here has failed and nothing here has passed. |
The scoped copy itself — complete for this role
{
"spec": "corobate:role-view:2",
"role": "AUDITOR",
"purpose": "An external assessor. Sees the complete sealed record: this view withholds nothing and exists so the identity case is a case rather than an exception.",
"is_a_receipt": false,
"warning": "This is a SCOPED COPY of a sealed decision, not the decision record itself. It will not verify as a receipt and must not be presented as one. To confirm it is faithful, recompute its `view` digest under the same canonicalisation that produces receipt_hash and compare it with the entry for this role in the source receipt’s `views` block.",
"derived_from": {
"receipt_hash": "sha256:cc116c0bdb3d3f998c71834f6a365315765375dd99ed77c20c2a9ed4e007625e",
"entry_hash": "sha256:d60b7a4f6b95aa315ea2d3ca369db1f2c20a5eea0fd5b641c3e36f23f6e23cff",
"issued_at": "2026-08-08T16:00:00.000Z"
},
"view_digest": "sha256:d350145dbd32a6ab5a4433eb3725702c7aa4ec780bf40041798b3d7233f20643",
"withheld": {
"anything_withheld": false,
"note": "Nothing outside the seal was removed for this role."
},
"view": {
"spec": "urn:ietf:params:corobate:receipt:1",
"receipt_version": "1.8",
"engine": {
"name": "corobate-memory",
"version": "1.0.0"
},
"decision": {
"id": "ato_CLOUDVANE_R3",
"domain": "supply-chain",
"subject": "system:CLOUDVANE-GOV-REGION-3",
"question": "May this cloud service be brought inside the authorisation boundary?"
},
"issued_at": "2026-08-08T16:00:00.000Z",
"data_horizon": "2026-08-08T16:00:00.000Z",
"inputs": [
{
"key": "system:CLOUDVANE-GOV-REGION-3::vulnerability_scan",
"value": "clean-at-scan",
"provenance": "VERIFIED",
"source": "nvd-cve:vulnerability_scan",
"observed_at": "2026-08-02T16:00:00.000Z",
"last_corroborated_at": null,
"memory_refreshed_by": [],
"reliability": 0.95,
"critical": true,
"memory_id": "mem_6d2e9d3452ab",
"memory_status": "admitted",
"memory_kind": "status",
"memory_actor": "actor:sys:registry:nvd-cve",
"memory_age_days": 6,
"memory_track": {
"n": 1,
"successes": 1
},
"memory_promoted_by": [],
"memory_content_digest": "sha256:5b21c1afb32830893109c15819f205ccf5bf45d924ae231a0e80f2d4d5750c56",
"memory_outcomes": {
"verified": 0,
"falsified": 0,
"modified": 0,
"counted": 0,
"recorded": 0
},
"memory_outcome_attestations": [],
"memory_observer_lineage": null,
"memory_corroborations": [],
"memory_reingest": null,
"memory_reasons": [
"sparse track record: 1 independent observation(s); no failure recorded, so the class ceiling stands"
],
"memory_class_floor": null,
"memory_below_class_floor": false,
"memory_not_attested": false,
"memory_below_claim_reliability_floor": false,
"memory_not_competent_authority": false,
"memory_out_of_specification": false,
"memory_ai_authored": false,
"memory_ai_in_lineage": false,
"memory_ai_position": "ADMIT",
"memory_ai_inadmissible": false,
"memory_geo_inadmissible": false,
"memory_geo_rung": null,
"memory_geo_metric": null,
"memory_geo_required_metric": null,
"observer_attested": true,
"observer_auth_code": "VERIFIED",
"observer_key_id": "k_5873dd9e7169def3",
"attestation": null,
"derivation": {
"provenance": "VERIFIED",
"ceiling_bp": 9500,
"track": {
"n": 1,
"successes": 1
},
"wilson_bp": null,
"age_days": 6,
"max_age_days": 14,
"house_max_age_days": 14,
"instrument_max_age_days": 30,
"freshness_cap_bp": 4000,
"min_track_n": 5,
"wilson_z_milli": 1960,
"source_present": true,
"seller_asserted_cap_bp": 5000,
"retracted": false,
"contradicted": false,
"outcome_trials": 0,
"outcomes": {
"verified": 0,
"falsified": 0,
"modified": 0,
"counted": 0,
"recorded": 0
},
"corroborations_counted": 0,
"corroborations_discounted": 0,
"reingest_ceiling_bp": null,
"reingest_depth": null,
"reingest_weakest_class": null,
"reingest_source_confidence_bp": null,
"ai_authored": false,
"ai_authored_because": null,
"ai_in_lineage": false,
"ai_position": "ADMIT"
},
"memory_reason_codes": [
{
"code": "SPARSE_TRACK_RECORD",
"observed": 1,
"limit": 5,
"binding": false
}
],
"context_line": "[VERIFIED · r=95.0% · 6d · nvd-cve:vulnerability_scan] system:CLOUDVANE-GOV-REGION-3 / vulnerability_scan: clean-at-scan"
},
{
"key": "system:CLOUDVANE-GOV-REGION-3::component_provenance",
"value": "schedule",
"provenance": "VERIFIED",
"source": "contract-repository:component_provenance",
"observed_at": "2026-05-10T16:00:00.000Z",
"last_corroborated_at": null,
"memory_refreshed_by": [],
"reliability": 0.95,
"critical": true,
"memory_id": "mem_e29e9c84fa74",
"memory_status": "admitted",
"memory_kind": "certificate",
"memory_actor": "actor:sys:registry:contract-repository",
"memory_age_days": 90,
"memory_track": {
"n": 1,
"successes": 1
},
"memory_promoted_by": [],
"memory_content_digest": "sha256:5a5215268a700967ccc165c44f865e2dc842606621ac09382cefe34705724a21",
"memory_outcomes": {
"verified": 0,
"falsified": 0,
"modified": 0,
"counted": 0,
"recorded": 0
},
"memory_outcome_attestations": [],
"memory_observer_lineage": null,
"memory_corroborations": [],
"memory_reingest": null,
"memory_reasons": [
"sparse track record: 1 independent observation(s); no failure recorded, so the class ceiling stands"
],
"memory_class_floor": "SELLER-ASSERTED",
"memory_below_class_floor": false,
"memory_not_attested": false,
"memory_below_claim_reliability_floor": false,
"memory_not_competent_authority": false,
"memory_out_of_specification": false,
"memory_ai_authored": false,
"memory_ai_in_lineage": false,
"memory_ai_position": "ADMIT",
"memory_ai_inadmissible": false,
"memory_geo_inadmissible": false,
"memory_geo_rung": null,
"memory_geo_metric": null,
"memory_geo_required_metric": null,
"observer_attested": true,
"observer_auth_code": "VERIFIED",
"observer_key_id": "k_1fa747666eaebac1",
"attestation": null,
"derivation": {
"provenance": "VERIFIED",
"ceiling_bp": 9500,
"track": {
"n": 1,
"successes": 1
},
"wilson_bp": null,
"age_days": 90,
"max_age_days": 365,
"house_max_age_days": 365,
"instrument_max_age_days": null,
"freshness_cap_bp": 4000,
"min_track_n": 5,
"wilson_z_milli": 1960,
"source_present": true,
"seller_asserted_cap_bp": 5000,
"retracted": false,
"contradicted": false,
"outcome_trials": 0,
"outcomes": {
"verified": 0,
"falsified": 0,
"modified": 0,
"counted": 0,
"recorded": 0
},
"corroborations_counted": 0,
"corroborations_discounted": 0,
"reingest_ceiling_bp": null,
"reingest_depth": null,
"reingest_weakest_class": null,
"reingest_source_confidence_bp": null,
"min_class_floor": "SELLER-ASSERTED",
"ai_authored": false,
"ai_authored_because": null,
"ai_in_lineage": false,
"ai_position": "ADMIT"
},
"memory_reason_codes": [
{
"code": "SPARSE_TRACK_RECORD",
"observed": 1,
"limit": 5,
"binding": false
}
],
"context_line": "[VERIFIED · r=95.0% · 90d · contract-repository:component_provenance] system:CLOUDVANE-GOV-REGION-3 / component_provenance: schedule"
},
{
"key": "system:CLOUDVANE-GOV-REGION-3::penetration_test",
"value": "no-critical",
"provenance": "VERIFIED",
"source": "LAB-NVLAP-0412:penetration_test",
"observed_at": "2026-03-11T16:00:00.000Z",
"last_corroborated_at": null,
"memory_refreshed_by": [],
"reliability": 0.95,
"critical": true,
"memory_id": "mem_90a2f98fe191",
"memory_status": "admitted",
"memory_kind": "test_report",
"memory_actor": "actor:org:LAB-NVLAP-0412",
"memory_age_days": 150,
"memory_track": {
"n": 1,
"successes": 1
},
"memory_promoted_by": [],
"memory_content_digest": "sha256:b311aa9e0ab8603002bba31e48e377d009a9cfbba410090796cfcacffcc3ec25",
"memory_outcomes": {
"verified": 0,
"falsified": 0,
"modified": 0,
"counted": 0,
"recorded": 0
},
"memory_outcome_attestations": [],
"memory_observer_lineage": null,
"memory_corroborations": [],
"memory_reingest": null,
"memory_reasons": [
"sparse track record: 1 independent observation(s); no failure recorded, so the class ceiling stands"
],
"memory_class_floor": "VERIFIED",
"memory_below_class_floor": false,
"memory_not_attested": false,
"memory_below_claim_reliability_floor": false,
"memory_not_competent_authority": false,
"memory_out_of_specification": false,
"memory_ai_authored": false,
"memory_ai_in_lineage": false,
"memory_ai_position": "ADMIT",
"memory_ai_inadmissible": false,
"memory_geo_inadmissible": false,
"memory_geo_rung": null,
"memory_geo_metric": null,
"memory_geo_required_metric": null,
"observer_attested": true,
"observer_auth_code": "VERIFIED",
"observer_key_id": "k_17d23885943ae529",
"attestation": null,
"derivation": {
"provenance": "VERIFIED",
"ceiling_bp": 9500,
"track": {
"n": 1,
"successes": 1
},
"wilson_bp": null,
"age_days": 150,
"max_age_days": 180,
"house_max_age_days": 180,
"instrument_max_age_days": null,
"freshness_cap_bp": 4000,
"min_track_n": 5,
"wilson_z_milli": 1960,
"source_present": true,
"seller_asserted_cap_bp": 5000,
"retracted": false,
"contradicted": false,
"outcome_trials": 0,
"outcomes": {
"verified": 0,
"falsified": 0,
"modified": 0,
"counted": 0,
"recorded": 0
},
"corroborations_counted": 0,
"corroborations_discounted": 0,
"reingest_ceiling_bp": null,
"reingest_depth": null,
"reingest_weakest_class": null,
"reingest_source_confidence_bp": null,
"min_class_floor": "VERIFIED",
"ai_authored": false,
"ai_authored_because": null,
"ai_in_lineage": false,
"ai_position": "ADMIT"
},
"memory_reason_codes": [
{
"code": "SPARSE_TRACK_RECORD",
"observed": 1,
"limit": 5,
"binding": false
}
],
"context_line": "[VERIFIED · r=95.0% · 150d · LAB-NVLAP-0412:penetration_test] system:CLOUDVANE-GOV-REGION-3 / penetration_test: no-critical"
},
{
"key": "system:CLOUDVANE-GOV-REGION-3::control_assessment",
"value": "satisfied-with-poams",
"provenance": "VERIFIED",
"source": "CERT-3PAO-ATLANTIC:control_assessment",
"observed_at": "2026-04-10T16:00:00.000Z",
"last_corroborated_at": null,
"memory_refreshed_by": [],
"reliability": 0.95,
"critical": true,
"memory_id": "mem_ecad7667d650",
"memory_status": "admitted",
"memory_kind": "certificate",
"memory_actor": "actor:org:CERT-3PAO-ATLANTIC",
"memory_age_days": 120,
"memory_track": {
"n": 1,
"successes": 1
},
"memory_promoted_by": [],
"memory_content_digest": "sha256:4876ae25906e54c009f92eed417815877d7ff5deabc9bff96f51cb05c1ced026",
"memory_outcomes": {
"verified": 0,
"falsified": 0,
"modified": 0,
"counted": 0,
"recorded": 0
},
"memory_outcome_attestations": [],
"memory_observer_lineage": null,
"memory_corroborations": [],
"memory_reingest": null,
"memory_reasons": [
"sparse track record: 1 independent observation(s); no failure recorded, so the class ceiling stands"
],
"memory_class_floor": "VERIFIED",
"memory_below_class_floor": false,
"memory_not_attested": false,
"memory_below_claim_reliability_floor": false,
"memory_not_competent_authority": false,
"memory_out_of_specification": false,
"memory_ai_authored": false,
"memory_ai_in_lineage": false,
"memory_ai_position": "ADMIT",
"memory_ai_inadmissible": false,
"memory_geo_inadmissible": false,
"memory_geo_rung": null,
"memory_geo_metric": null,
"memory_geo_required_metric": null,
"observer_attested": true,
"observer_auth_code": "VERIFIED",
"observer_key_id": "k_307e4bfd710ec9b3",
"attestation": null,
"derivation": {
"provenance": "VERIFIED",
"ceiling_bp": 9500,
"track": {
"n": 1,
"successes": 1
},
"wilson_bp": null,
"age_days": 120,
"max_age_days": 365,
"house_max_age_days": 365,
"instrument_max_age_days": 365,
"freshness_cap_bp": 4000,
"min_track_n": 5,
"wilson_z_milli": 1960,
"source_present": true,
"seller_asserted_cap_bp": 5000,
"retracted": false,
"contradicted": false,
"outcome_trials": 0,
"outcomes": {
"verified": 0,
"falsified": 0,
"modified": 0,
"counted": 0,
"recorded": 0
},
"corroborations_counted": 0,
"corroborations_discounted": 0,
"reingest_ceiling_bp": null,
"reingest_depth": null,
"reingest_weakest_class": null,
"reingest_source_confidence_bp": null,
"min_class_floor": "VERIFIED",
"ai_authored": false,
"ai_authored_because": null,
"ai_in_lineage": false,
"ai_position": "ADMIT"
},
"memory_reason_codes": [
{
"code": "SPARSE_TRACK_RECORD",
"observed": 1,
"limit": 5,
"binding": false
}
],
"context_line": "[VERIFIED · r=95.0% · 120d · CERT-3PAO-ATLANTIC:control_assessment] system:CLOUDVANE-GOV-REGION-3 / control_assessment: satisfied-with-poams"
},
{
"key": "system:CLOUDVANE-GOV-REGION-3::supplier_assessment",
"value": null,
"provenance": "SELLER-ASSERTED",
"source": "CLOUDVANE-GOV:supplier_assessment",
"observed_at": "2026-06-29T16:00:00.000Z",
"last_corroborated_at": null,
"memory_refreshed_by": [],
"reliability": 0.4,
"critical": false,
"memory_id": "mem_d33e14759cf8",
"memory_status": "withheld",
"memory_kind": "status",
"memory_actor": "actor:org:CLOUDVANE-GOV",
"memory_age_days": 40,
"memory_track": {
"n": 1,
"successes": 1
},
"memory_promoted_by": [],
"memory_content_digest": "sha256:bde7cbac63dcfd998e3e446beb25e8e93acf950045317f20eaf8d3e3204fc090",
"memory_outcomes": {
"verified": 0,
"falsified": 0,
"modified": 0,
"counted": 0,
"recorded": 0
},
"memory_outcome_attestations": [],
"memory_observer_lineage": null,
"memory_corroborations": [],
"memory_reingest": null,
"memory_reasons": [
"sparse track record: 1 independent observation(s); no failure recorded, so the class ceiling stands",
"stale field: observed 40d ago, limit 14d for kind \"status\"; reliability capped at 40%"
],
"memory_class_floor": null,
"memory_below_class_floor": false,
"memory_not_attested": false,
"memory_below_claim_reliability_floor": false,
"memory_not_competent_authority": false,
"memory_out_of_specification": false,
"memory_ai_authored": false,
"memory_ai_in_lineage": false,
"memory_ai_position": "ADMIT",
"memory_ai_inadmissible": false,
"memory_geo_inadmissible": false,
"memory_geo_rung": null,
"memory_geo_metric": null,
"memory_geo_required_metric": null,
"observer_attested": false,
"observer_auth_code": "NO_ENVELOPE",
"observer_key_id": null,
"attestation": null,
"derivation": {
"provenance": "SELLER-ASSERTED",
"ceiling_bp": 5000,
"track": {
"n": 1,
"successes": 1
},
"wilson_bp": null,
"age_days": 40,
"max_age_days": 14,
"house_max_age_days": 14,
"instrument_max_age_days": null,
"freshness_cap_bp": 4000,
"min_track_n": 5,
"wilson_z_milli": 1960,
"source_present": true,
"seller_asserted_cap_bp": 5000,
"retracted": false,
"contradicted": false,
"outcome_trials": 0,
"outcomes": {
"verified": 0,
"falsified": 0,
"modified": 0,
"counted": 0,
"recorded": 0
},
"corroborations_counted": 0,
"corroborations_discounted": 0,
"reingest_ceiling_bp": null,
"reingest_depth": null,
"reingest_weakest_class": null,
"reingest_source_confidence_bp": null,
"ai_authored": false,
"ai_authored_because": null,
"ai_in_lineage": false,
"ai_position": "ADMIT"
},
"memory_reason_codes": [
{
"code": "SPARSE_TRACK_RECORD",
"observed": 1,
"limit": 5,
"binding": false
},
{
"code": "STALE_FIELD",
"observed": 40,
"limit": 14,
"cap_bp": 4000,
"resulting_bp": 4000,
"binding": true
}
]
},
{
"key": "system:CLOUDVANE-GOV-REGION-3::supplier_assessment",
"value": null,
"provenance": "MISSING",
"source": null,
"observed_at": "2026-08-08T16:00:00.000Z",
"reliability": 0,
"critical": true,
"memory_status": "coverage_gap",
"gap_cause": "EVIDENCE_PRESENTED_FAILED",
"gap_request": null,
"gap_origin": "BUSINESS_EVIDENCE",
"gap_conditions": []
}
],
"serialization": {
"algorithm": "RFC8785-JCS",
"hash": "sha256"
},
"crypto_suite": {
"spec": "corobate:suite:1",
"id": "CB-1-ES256-SHA256",
"receipt_digest": "sha256",
"chain_digest": "sha256",
"content_digest": "sha256",
"envelope_signature": "ES256",
"signature_curve": "P-256",
"canonicalisation": "attest-canon/2",
"quantum_resistant": false
},
"confidence": {
"value": 0,
"method": "min-over-critical-inputs",
"bound_by": "system:CLOUDVANE-GOV-REGION-3::supplier_assessment"
},
"verdict": {
"value": "WITHHELD",
"threshold_approve": 0.9,
"threshold_caution": 0.7,
"rule": "confidence>=threshold"
},
"release": {
"required": false,
"required_by_tier": false,
"escalated_by_acceptance": false,
"risk_accepted": false,
"state": "WITHHELD_NO_EVIDENCE",
"code": "QUORUM_EVIDENCE_WITHHELD",
"reason": "the evidence did not clear the threshold for this exposure, so there is nothing to release. Signatures do not substitute for evidence, and this state is deliberately distinct from WITHHELD_PENDING_SIGNATURES: a reader must be able to tell \"the evidence is not there\" from \"the evidence is there and 0 of 2 people have signed\".",
"tier_floor_cents": 1000000000,
"exposure_usd_cents": 220000000,
"required_m": 2,
"declared_n": 3,
"floor_m": 2,
"distinct_signers": 0,
"superseded": 0,
"collapsed": 0,
"release_digest": "sha256:8ef23045c8d8714e4d68ec83739091959dcb5765515b96c8c66ebbf99a4558ec",
"governance_digest": "sha256:8b0a45a27fcce9c1c243c764e855e67c6fe6dfd7f02a563bd90809b419731905",
"governance_signed": true,
"counted_voices": [],
"signatures": [],
"ledger_seq": null
},
"acceptance": {
"state": "NONE",
"code": "ACCEPTANCE_NONE",
"reason": "no risk acceptance was presented for this decision. This is the ordinary case: a refusal is a refusal unless a named person has priced it.",
"permitted_basis": null,
"presented": 0,
"superseded": 0,
"expired": 0,
"gaps_not_covered": 0,
"coverage_gaps_in_force": [
"system:CLOUDVANE-GOV-REGION-3|supplier_assessment"
],
"evidentiary_digest": "sha256:8ef23045c8d8714e4d68ec83739091959dcb5765515b96c8c66ebbf99a4558ec",
"margin_floor_bp": 100,
"authority_ceiling_cents": {
"SUPERVISOR": 1000000,
"MANAGER": 25000000,
"DIRECTOR": 500000000,
"OFFICER": 5000000000
},
"acceptances": [],
"escalated": false,
"live": false,
"ledger_seq": null
},
"regulatory": {
"spec": "corobate:regulatory:2",
"resolved": true,
"applied": [
{
"instrument_id": "nist-sp-800-53r5-moderate",
"version": 5,
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
"edition": "Rev. 5",
"citation": "CA-2, CA-8, RA-5, SR-6 [VERIFY]",
"source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353",
"entered_by": "actor:human:issm",
"entered_at": "2026-08-08T16:00:00.000Z"
},
{
"instrument_id": "nist-sp-800-161r1-cscrm",
"version": 1,
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-161 Rev. 1 — C-SCRM Practices for Systems and Organizations",
"edition": "Rev. 1",
"citation": "SR-3, SR-4, SR-11 [VERIFY]",
"source_digest": "sha256:6161616161616161616161616161616161616161616161616161616161616161",
"entered_by": "actor:human:issm",
"entered_at": "2026-08-08T16:00:00.000Z"
}
],
"skipped": [],
"conflicts": [],
"bindings": [
{
"claim": "component_provenance",
"requirement": "min_class",
"value": "SELLER-ASSERTED",
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-161 Rev. 1 — C-SCRM Practices for Systems and Organizations",
"instrument_id": "nist-sp-800-161r1-cscrm",
"version": 1,
"edition": "Rev. 1",
"citation": "SR-4 [VERIFY]",
"source_digest": "sha256:6161616161616161616161616161616161616161616161616161616161616161"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "component_provenance",
"requirement": "required",
"value": true,
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-161 Rev. 1 — C-SCRM Practices for Systems and Organizations",
"instrument_id": "nist-sp-800-161r1-cscrm",
"version": 1,
"edition": "Rev. 1",
"citation": "SR-4 provenance [VERIFY]",
"source_digest": "sha256:6161616161616161616161616161616161616161616161616161616161616161"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "control_assessment",
"requirement": "max_age_days",
"value": 365,
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
"instrument_id": "nist-sp-800-53r5-moderate",
"version": 5,
"edition": "Rev. 5",
"citation": "CA-2 [VERIFY]",
"source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "control_assessment",
"requirement": "min_class",
"value": "VERIFIED",
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
"instrument_id": "nist-sp-800-53r5-moderate",
"version": 5,
"edition": "Rev. 5",
"citation": "CA-2(1) independent assessors [VERIFY]",
"source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "control_assessment",
"requirement": "required",
"value": true,
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
"instrument_id": "nist-sp-800-53r5-moderate",
"version": 5,
"edition": "Rev. 5",
"citation": "CA-2 [VERIFY]",
"source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "penetration_test",
"requirement": "min_class",
"value": "VERIFIED",
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
"instrument_id": "nist-sp-800-53r5-moderate",
"version": 5,
"edition": "Rev. 5",
"citation": "CA-8(1) independent penetration agent [VERIFY]",
"source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "penetration_test",
"requirement": "required",
"value": true,
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
"instrument_id": "nist-sp-800-53r5-moderate",
"version": 5,
"edition": "Rev. 5",
"citation": "CA-8 [VERIFY]",
"source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "supplier_assessment",
"requirement": "required",
"value": true,
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-161 Rev. 1 — C-SCRM Practices for Systems and Organizations",
"instrument_id": "nist-sp-800-161r1-cscrm",
"version": 1,
"edition": "Rev. 1",
"citation": "SR-6 [VERIFY]",
"source_digest": "sha256:6161616161616161616161616161616161616161616161616161616161616161"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "vulnerability_scan",
"requirement": "max_age_days",
"value": 30,
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
"instrument_id": "nist-sp-800-53r5-moderate",
"version": 5,
"edition": "Rev. 5",
"citation": "RA-5(a) [VERIFY]",
"source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "vulnerability_scan",
"requirement": "required",
"value": true,
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
"instrument_id": "nist-sp-800-53r5-moderate",
"version": 5,
"edition": "Rev. 5",
"citation": "RA-5 [VERIFY]",
"source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
}
],
"defaults": [
{
"claim": "component_provenance",
"requirement": "ai_position",
"value": "ADMIT",
"because": "No instrument in force stated a position on AI-authored evidence for \"component_provenance\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
},
{
"claim": "control_assessment",
"requirement": "ai_position",
"value": "ADMIT",
"because": "No instrument in force stated a position on AI-authored evidence for \"control_assessment\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
},
{
"claim": "penetration_test",
"requirement": "ai_position",
"value": "ADMIT",
"because": "No instrument in force stated a position on AI-authored evidence for \"penetration_test\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
},
{
"claim": "supplier_assessment",
"requirement": "ai_position",
"value": "ADMIT",
"because": "No instrument in force stated a position on AI-authored evidence for \"supplier_assessment\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
},
{
"claim": "vulnerability_scan",
"requirement": "ai_position",
"value": "ADMIT",
"because": "No instrument in force stated a position on AI-authored evidence for \"vulnerability_scan\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
}
]
},
"reasons": [
"Coverage gap: no admissible memory for required claim(s) system:CLOUDVANE-GOV-REGION-3|supplier_assessment.",
"Confidence 0.00% is bound by \"system:CLOUDVANE-GOV-REGION-3|supplier_assessment\".",
"1 memory was withheld from the context block: system:CLOUDVANE-GOV-REGION-3|supplier_assessment (sparse track record: 1 independent observation(s); no failure recorded, so the class ceiling stands).",
"Thresholds for $2,200,000 exposure: approve 90%, caution 70%."
],
"memory": {
"layer": "capture->store->recall->act",
"ledger_head": "sha256:5bbeec39ca2744b408818488f7595e4b119e254325fd84642a3c66c636794c9c",
"ledger_entries": 7,
"context_digest": null,
"context_memory_ids": [],
"state_digest": "sha256:01827de72fd2a97521310c759fdc925c1c51ca2f43949aa72b79b19221e6ff88",
"retrieval_method": "idf-lexical",
"corpus_size": 5,
"considered": 5,
"admitted": 4,
"withheld": 1,
"not_considered": 0,
"coverage_gaps": [
"system:CLOUDVANE-GOV-REGION-3|supplier_assessment"
],
"exposure": {
"usd": 2200000,
"declared_by": "actor:human:ao-authorizing-official",
"ledger_seq": 5
},
"salience_policy": {
"half_life_days": 90,
"grace_days": 7,
"access_boost_bp": 500,
"access_boost_cap_bp": 2500,
"relevance_weight_bp": 6000,
"recency_weight_bp": 3000,
"usage_weight_bp": 1000,
"context_cap": 12,
"method": "idf-lexical",
"candidate_list_digest": "sha256:a0a517898454c11e39c80e688bd1f37bd556d635f7242d58d4a695ae3443279d",
"note": "salience orders retrieval only; it never contributes to reliability"
},
"policy_digest": "sha256:a6b69b7d20f7fb04d522364af1d92992058b04a5835fcec9d1c9f2261c7ef636",
"policy_body": {
"class_ceiling_bp": {
"VERIFIED": 9500,
"MODELED": 8000,
"SELLER-ASSERTED": 5000,
"MISSING": 0
},
"actor_class_ceiling": [
[
"^actor:ai:",
"MODELED"
],
[
"^actor:agent:",
"MODELED"
],
[
"^actor:human:",
"SELLER-ASSERTED"
],
[
"^actor:org:LAB-",
"VERIFIED"
],
[
"^actor:org:CERT-",
"VERIFIED"
],
[
"^actor:org:",
"SELLER-ASSERTED"
],
[
"^actor:sys:registry:",
"VERIFIED"
],
[
"^actor:sys:sensor:",
"VERIFIED"
],
[
"^actor:sys:",
"MODELED"
]
],
"freshness_cap_bp": 4000,
"max_age_days": {
"telemetry": 1,
"price": 7,
"status": 14,
"certificate": 365,
"test_report": 180,
"filing": 90,
"transcript": 120,
"highlight": 365,
"voice_note": 120,
"note": 365,
"preference": 540,
"decision": 1825,
"receipt": 365,
"default": 90
},
"wilson_z_milli": 1960,
"min_track_n": 5,
"exposure_tiers_bp": [
[
1000000000,
9500,
8000
],
[
100000000,
9000,
7000
],
[
1000000,
8500,
6000
],
[
0,
8000,
5000
]
],
"max_context_memories": 12,
"contradiction_resolve_margin": 2,
"salience": {
"half_life_days": 90,
"grace_days": 7,
"access_boost_bp": 500,
"access_boost_cap_bp": 2500,
"relevance_weight_bp": 6000,
"recency_weight_bp": 3000,
"usage_weight_bp": 1000
}
},
"observer_auth": {
"mode": "required",
"registry_version": 3,
"registry_digest": "sha256:460aeaafe345f69542a302e6619dff0712af98de6518838ee4c8585e448c3a7d",
"entries_root": "sha256:5670469f96484a814462814ed74f0f992b5f19e8ad6afced548e4956e4835ba5",
"memberships": [
{
"key_id": "k_17d23885943ae529",
"index": 1,
"entry": {
"actor": "actor:org:LAB-NVLAP-0412",
"class": "VERIFIED",
"kind": "org",
"key_id": "k_17d23885943ae529",
"jwk": {
"kty": "EC",
"crv": "P-256",
"x": "3TTw47-PkYfo3ZaKTq_qtHghnGvninAVj25kyOwONno",
"y": "16PMaR8ofeF5IcZk6ZLml8gDs8uE1s1sBLdciH5e4vg"
},
"valid_from": "2025-01-01T00:00:00.000Z",
"valid_to": "2027-06-01T00:00:00.000Z"
},
"path": [
{
"side": "left",
"sibling": "sha256:500f2ba5949d5256ae0f563530b0b270db41ce99d2d7c4b4b60e4bd558ca353d"
},
{
"side": "right",
"sibling": "sha256:a0b47ea437bf4f1042a1dd50a5a3f411f9a17971812fc6bafccd434eb7d78ccc"
},
{
"side": "right",
"sibling": "sha256:d3c2347eb675e865fc17ef0204cacda7b02e8784a811fdd1c8a015d1865e6dfb"
},
{
"side": "right",
"sibling": "sha256:7071adf5e21a94147d31f42f1028b4867b6562e5b78726259c2515b03b213e52"
}
]
},
{
"key_id": "k_1fa747666eaebac1",
"index": 3,
"entry": {
"actor": "actor:sys:registry:contract-repository",
"class": "VERIFIED",
"kind": "system",
"key_id": "k_1fa747666eaebac1",
"jwk": {
"kty": "EC",
"crv": "P-256",
"x": "41rFxJFoXZce5-6xjOTknC2gQCVb0skbk4cmn1olvNQ",
"y": "4hEvB6nrEDYLOe5NUMev83ShXuBe_KwoDZiYjFAAN1c"
},
"valid_from": "2025-01-01T00:00:00.000Z",
"valid_to": "2027-06-01T00:00:00.000Z"
},
"path": [
{
"side": "left",
"sibling": "sha256:e2e716026353b5cc8c43a2af49ee6dc31d111d1ec3f275262d0c4601ae124c27"
},
{
"side": "left",
"sibling": "sha256:e8b9cba101f13538b909a2e686e9e6e9a8d77212036ed567eaebc205a443e83f"
},
{
"side": "right",
"sibling": "sha256:d3c2347eb675e865fc17ef0204cacda7b02e8784a811fdd1c8a015d1865e6dfb"
},
{
"side": "right",
"sibling": "sha256:7071adf5e21a94147d31f42f1028b4867b6562e5b78726259c2515b03b213e52"
}
]
},
{
"key_id": "k_307e4bfd710ec9b3",
"index": 0,
"entry": {
"actor": "actor:org:CERT-3PAO-ATLANTIC",
"class": "VERIFIED",
"kind": "org",
"key_id": "k_307e4bfd710ec9b3",
"jwk": {
"kty": "EC",
"crv": "P-256",
"x": "MGtV26TezLMPjiD3SecQtnje6eLqYyx4qkKzzAkbiY4",
"y": "SMMdLYnn-FpKbb2sJQ8EAZnzvozNm-cGO0VbUUpniPY"
},
"valid_from": "2025-01-01T00:00:00.000Z",
"valid_to": "2027-06-01T00:00:00.000Z"
},
"path": [
{
"side": "right",
"sibling": "sha256:4148869fc259d2c5fc19fe5831065b165a9acf81812e123162035acfdecade1d"
},
{
"side": "right",
"sibling": "sha256:a0b47ea437bf4f1042a1dd50a5a3f411f9a17971812fc6bafccd434eb7d78ccc"
},
{
"side": "right",
"sibling": "sha256:d3c2347eb675e865fc17ef0204cacda7b02e8784a811fdd1c8a015d1865e6dfb"
},
{
"side": "right",
"sibling": "sha256:7071adf5e21a94147d31f42f1028b4867b6562e5b78726259c2515b03b213e52"
}
]
},
{
"key_id": "k_5873dd9e7169def3",
"index": 2,
"entry": {
"actor": "actor:sys:registry:nvd-cve",
"class": "VERIFIED",
"kind": "system",
"key_id": "k_5873dd9e7169def3",
"jwk": {
"kty": "EC",
"crv": "P-256",
"x": "O9OY6oMuJg0df_INePO19_3b11VaSyMwIPdxoqvV2ak",
"y": "k7Orm5pxDxMdTF-H2S4h6ixRywzk1WxvquOQeqxLFx0"
},
"valid_from": "2025-01-01T00:00:00.000Z",
"valid_to": "2027-06-01T00:00:00.000Z"
},
"path": [
{
"side": "right",
"sibling": "sha256:e1fe36fe7c8e4695327c25d6d722630b6249c93293bfdc5894c58aaf961ab6f8"
},
{
"side": "left",
"sibling": "sha256:e8b9cba101f13538b909a2e686e9e6e9a8d77212036ed567eaebc205a443e83f"
},
{
"side": "right",
"sibling": "sha256:d3c2347eb675e865fc17ef0204cacda7b02e8784a811fdd1c8a015d1865e6dfb"
},
{
"side": "right",
"sibling": "sha256:7071adf5e21a94147d31f42f1028b4867b6562e5b78726259c2515b03b213e52"
}
]
}
],
"memberships_unproven": [],
"revocation": {
"source": "SIGNED_LIST",
"digest": "sha256:12f73b1fbf27d38cf137b86a1ce13bbcd98161123a6aa7d79b107db8189966b9",
"sequence": 5,
"registry_version": 3,
"issued_at": "2026-08-06T00:00:00.000Z",
"next_update_due": "2026-08-13T00:00:00.000Z",
"entry_count": 0,
"body": {
"sequence": 5,
"registry_version": 3,
"issuer": {
"name": "NIST-regulated enterprise demonstration trust root",
"key_id": "k_3793b8e35f8acac1"
},
"issued_at": "2026-08-06T00:00:00.000Z",
"next_update_due": "2026-08-13T00:00:00.000Z",
"entries": [],
"spec": "corobate:revocation-list:1"
}
}
},
"governance": {
"digest": "sha256:8b0a45a27fcce9c1c243c764e855e67c6fe6dfd7f02a563bd90809b419731905",
"signed": true,
"actor_trust": "FLOOR_TO_SELLER_ASSERTED",
"outcome_trial_weight": 1,
"max_reingest_depth": 3,
"release_quorum_m": 2,
"release_quorum_n": 3,
"risk_acceptance_margin_bp": 500,
"risk_acceptance_max_days": 30,
"risk_acceptance_authority_cents": {
"SUPERVISOR": 1000000,
"MANAGER": 25000000,
"DIRECTOR": 500000000,
"OFFICER": 5000000000
},
"template_author_roles": [
"MANAGER",
"DIRECTOR",
"OFFICER"
]
},
"observers_attested": 4,
"outcomes": {
"attestations_counted": 0,
"attestations_recorded": 0,
"records_with_outcomes": 0
},
"lineage": {
"corroborations_counted": 0,
"corroborations_discounted": 0,
"records_with_discounted_corroborations": 0
},
"reingest": {
"records": 0,
"max_depth": 0,
"weakest_class": null,
"chain_weakest_bp": 10000,
"chain": []
},
"template": null
}
}
}Two NIST publications require component provenance and they require it at different strengths. The bill of materials is genuine, produced by the build, and it is still the producer describing its own product — so at this exposure it does not carry the requirement on its own.
- Subject
- release:PLATFORM-CORE-2026.8.0
- Question
- May this release be published to the government-facing environment?
- Exposure
- $640,000
- Instruments
- National Institute of Standards and Technology · National Institute of Standards and Technology
- Outcome
- WITHHELD — the action is not permitted; outstanding: code review, component provenance
- Receipt
- sha256:90a20c5dcda8ab70e32d7b08521e24e2f271d03ac079f47c2a047dfd3ed9cb4c
- Fourth party
- 68 components ingested from a CycloneDX 1.5 bill of materials · sha256:e4daced4f23c89e…
The gate variables this decision ran under — a dial per question, read back off the sealed receipt
code reviewrequired
component provenancerequired
release integrity mechanismrequired never waivable
supplier assessmentrequired
Every bar above was re-derived from the regulatory bindings inside this receipt’s hashed body, not from the configuration that produced it. A bar in grey is a setting no instrument made — the deploying organisation’s own default, which still binds and is not an absence. A bar position renders an ordinal on a declared ladder: it is a way to draw a control and to compare two settings on the same axis, and it is not a measurement. The value printed beside each bar is the authoritative one.
Whoever must act now
The engineer with the deployment in their hands, the release manager, the person who must publish or hold.
One instruction and the reason in words. No score, no money, no signatures.
Seven or eight fields, and not one of them is a number somebody can argue with. This person is not being asked to re-judge the evidence; somebody already did, and it is on the record.
The scoped copy itself — partial — something outside this role’s remit was removed
{
"spec": "corobate:role-view:2",
"role": "OPERATOR",
"purpose": "Whoever must act on this decision now — release the goods, fund the draw, dispatch the agent, ship the title. Sees one instruction and the reason in plain words, and nothing that could be argued about while somebody waits.",
"is_a_receipt": false,
"warning": "This is a SCOPED COPY of a sealed decision, not the decision record itself. It will not verify as a receipt and must not be presented as one. To confirm it is faithful, recompute its `view` digest under the same canonicalisation that produces receipt_hash and compare it with the entry for this role in the source receipt’s `views` block.",
"derived_from": {
"receipt_hash": "sha256:90a20c5dcda8ab70e32d7b08521e24e2f271d03ac079f47c2a047dfd3ed9cb4c",
"entry_hash": "sha256:62842a7dbe06d36b693bfd2f62a3c8123aede49a1a9092bc52a75f26ff260df5",
"issued_at": "2026-08-08T16:00:00.000Z"
},
"view_digest": "sha256:d06346a284746171de8dc76beb511144a8edd0f0e33aa231cd18f9e1be8c85eb",
"withheld": {
"anything_withheld": true,
"note": "Facts outside this role’s remit were removed. That something was removed is stated so a partial record is never mistaken for a complete one. How much, and what, is not stated — a count is an inference about the part you are not entitled to see."
},
"view": {
"spec": "urn:ietf:params:corobate:receipt:1",
"receipt_version": "1.8",
"issued_at": "2026-08-08T16:00:00.000Z",
"decision": {
"id": "rel_PLATFORM_2026_8_0",
"subject": "release:PLATFORM-CORE-2026.8.0"
},
"memory": {
"state_digest": "sha256:b69314201d2e10631d7179b82717dd6079b7dc7408b3ee37281eb56729ce59f2",
"ledger_head": "sha256:fdadc9eed6746ad514ec9f681a2910b2fa04006a84e45cb24a08e5bdcd9e97b3",
"coverage_gaps": [
"release:PLATFORM-CORE-2026.8.0|code_review",
"release:PLATFORM-CORE-2026.8.0|component_provenance"
]
},
"verdict": {
"value": "WITHHELD"
},
"release": {
"state": "WITHHELD_NO_EVIDENCE"
}
}
}Provider / assessed party
The cloud service provider, the release team, or the party operating the AI system — whoever is being assessed.
Sees which controls were required of them and by which publication and control identifier. Does not see the authorising official’s exposure figure or how any shortfall was priced.
What is outstanding on your file
- code review — required by National Institute of Standards and Technology, PW.7 [VERIFY]
- component provenance — required by National Institute of Standards and Technology, PS.3.2 [VERIFY]
| Claim | Required | Evidence class | Who | Age | Outcome |
|---|---|---|---|---|---|
| release_integrity_mechanism | yes | VERIFIED | — | 2026-05-30 | admitted |
| supplier_assessment | yes | VERIFIED | — | 2026-01-20 | admitted |
| code_review | no | SELLER-ASSERTED | — | 2026-08-06 | withheld |
| component_provenance | no | SELLER-ASSERTED | — | 2026-08-07 | withheld |
| code_review | yes | MISSING | — | 2026-08-08 | coverage gap |
| component_provenance | yes | MISSING | — | 2026-08-08 | coverage gap |
The clause is here because it turns an argument into an errand. What is not here: what the bank had at stake, and whether anyone priced the shortfall.
The scoped copy itself — partial — something outside this role’s remit was removed
{
"spec": "corobate:role-view:2",
"role": "SUPPLIER",
"purpose": "The party whose evidence was judged. Sees every claim the decision required, which fell short, and the clause that required it — and nothing about what the buyer had at stake or how the buyer priced any shortfall. NOTE, because an earlier draft of this sentence was untrue: this projection carries the WHOLE inputs array, so where several parties supplied evidence for one decision, each of them sees all of it. Per-party scoping cannot be expressed by a commitment scheme with one digest per role, and claiming it anyway would be the kind of promise this file exists to stop making.",
"is_a_receipt": false,
"warning": "This is a SCOPED COPY of a sealed decision, not the decision record itself. It will not verify as a receipt and must not be presented as one. To confirm it is faithful, recompute its `view` digest under the same canonicalisation that produces receipt_hash and compare it with the entry for this role in the source receipt’s `views` block.",
"derived_from": {
"receipt_hash": "sha256:90a20c5dcda8ab70e32d7b08521e24e2f271d03ac079f47c2a047dfd3ed9cb4c",
"entry_hash": "sha256:62842a7dbe06d36b693bfd2f62a3c8123aede49a1a9092bc52a75f26ff260df5",
"issued_at": "2026-08-08T16:00:00.000Z"
},
"view_digest": "sha256:0535e361c75eb51ca23b8063e86fda7be235ab66839af88fc2bc1920588ed492",
"withheld": {
"anything_withheld": true,
"note": "Facts outside this role’s remit were removed. That something was removed is stated so a partial record is never mistaken for a complete one. How much, and what, is not stated — a count is an inference about the part you are not entitled to see."
},
"view": {
"spec": "urn:ietf:params:corobate:receipt:1",
"receipt_version": "1.8",
"issued_at": "2026-08-08T16:00:00.000Z",
"decision": {
"id": "rel_PLATFORM_2026_8_0",
"subject": "release:PLATFORM-CORE-2026.8.0",
"question": "May this release be published to the government-facing environment?"
},
"memory": {
"state_digest": "sha256:b69314201d2e10631d7179b82717dd6079b7dc7408b3ee37281eb56729ce59f2",
"ledger_head": "sha256:fdadc9eed6746ad514ec9f681a2910b2fa04006a84e45cb24a08e5bdcd9e97b3",
"coverage_gaps": [
"release:PLATFORM-CORE-2026.8.0|code_review",
"release:PLATFORM-CORE-2026.8.0|component_provenance"
]
},
"verdict": {
"value": "WITHHELD"
},
"inputs": [
{
"key": "release:PLATFORM-CORE-2026.8.0::release_integrity_mechanism",
"provenance": "VERIFIED",
"observed_at": "2026-05-30T16:00:00.000Z",
"memory_status": "admitted",
"critical": true
},
{
"key": "release:PLATFORM-CORE-2026.8.0::supplier_assessment",
"provenance": "VERIFIED",
"observed_at": "2026-01-20T16:00:00.000Z",
"memory_status": "admitted",
"critical": true
},
{
"key": "release:PLATFORM-CORE-2026.8.0::code_review",
"provenance": "SELLER-ASSERTED",
"observed_at": "2026-08-06T16:00:00.000Z",
"memory_status": "withheld",
"critical": false
},
{
"key": "release:PLATFORM-CORE-2026.8.0::component_provenance",
"provenance": "SELLER-ASSERTED",
"observed_at": "2026-08-07T16:00:00.000Z",
"memory_status": "withheld",
"critical": false
},
{
"key": "release:PLATFORM-CORE-2026.8.0::code_review",
"provenance": "MISSING",
"observed_at": "2026-08-08T16:00:00.000Z",
"memory_status": "coverage_gap",
"critical": true
},
{
"key": "release:PLATFORM-CORE-2026.8.0::component_provenance",
"provenance": "MISSING",
"observed_at": "2026-08-08T16:00:00.000Z",
"memory_status": "coverage_gap",
"critical": true
}
],
"regulatory": {
"bindings": [
{
"claim": "code_review",
"requirement": "required",
"value": true,
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-218 — Secure Software Development Framework v1.1",
"instrument_id": "nist-sp-800-218-ssdf",
"version": 1,
"edition": "1.1",
"citation": "PW.7 [VERIFY]",
"source_digest": "sha256:1818181818181818181818181818181818181818181818181818181818181818"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "component_provenance",
"requirement": "min_class",
"value": "SELLER-ASSERTED",
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-161 Rev. 1 — C-SCRM Practices for Systems and Organizations",
"instrument_id": "nist-sp-800-161r1-cscrm",
"version": 1,
"edition": "Rev. 1",
"citation": "SR-4 [VERIFY]",
"source_digest": "sha256:6161616161616161616161616161616161616161616161616161616161616161"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "component_provenance",
"requirement": "required",
"value": true,
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-218 — Secure Software Development Framework v1.1",
"instrument_id": "nist-sp-800-218-ssdf",
"version": 1,
"edition": "1.1",
"citation": "PS.3.2 [VERIFY]",
"source_digest": "sha256:1818181818181818181818181818181818181818181818181818181818181818"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "release_integrity_mechanism",
"requirement": "min_class",
"value": "VERIFIED",
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-218 — Secure Software Development Framework v1.1",
"instrument_id": "nist-sp-800-218-ssdf",
"version": 1,
"edition": "1.1",
"citation": "PS.2 [VERIFY]",
"source_digest": "sha256:1818181818181818181818181818181818181818181818181818181818181818"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "release_integrity_mechanism",
"requirement": "never_waivable",
"value": true,
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-218 — Secure Software Development Framework v1.1",
"instrument_id": "nist-sp-800-218-ssdf",
"version": 1,
"edition": "1.1",
"citation": "PS.2 [VERIFY]",
"source_digest": "sha256:1818181818181818181818181818181818181818181818181818181818181818"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "release_integrity_mechanism",
"requirement": "required",
"value": true,
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-218 — Secure Software Development Framework v1.1",
"instrument_id": "nist-sp-800-218-ssdf",
"version": 1,
"edition": "1.1",
"citation": "PS.2 [VERIFY]",
"source_digest": "sha256:1818181818181818181818181818181818181818181818181818181818181818"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "supplier_assessment",
"requirement": "required",
"value": true,
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-161 Rev. 1 — C-SCRM Practices for Systems and Organizations",
"instrument_id": "nist-sp-800-161r1-cscrm",
"version": 1,
"edition": "Rev. 1",
"citation": "SR-6 [VERIFY]",
"source_digest": "sha256:6161616161616161616161616161616161616161616161616161616161616161"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
}
],
"applied": [
{
"instrument_id": "nist-sp-800-218-ssdf",
"version": 1,
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-218 — Secure Software Development Framework v1.1",
"edition": "1.1",
"citation": "PS.3.2, PS.2, PW.7 [VERIFY]",
"source_digest": "sha256:1818181818181818181818181818181818181818181818181818181818181818",
"entered_by": "actor:human:issm",
"entered_at": "2026-08-08T16:00:00.000Z"
},
{
"instrument_id": "nist-sp-800-161r1-cscrm",
"version": 1,
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-161 Rev. 1 — C-SCRM Practices for Systems and Organizations",
"edition": "Rev. 1",
"citation": "SR-3, SR-4, SR-11 [VERIFY]",
"source_digest": "sha256:6161616161616161616161616161616161616161616161616161616161616161",
"entered_by": "actor:human:issm",
"entered_at": "2026-08-08T16:00:00.000Z"
}
],
"defaults": [
{
"claim": "code_review",
"requirement": "ai_position",
"value": "ADMIT",
"because": "No instrument in force stated a position on AI-authored evidence for \"code_review\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
},
{
"claim": "component_provenance",
"requirement": "ai_position",
"value": "ADMIT",
"because": "No instrument in force stated a position on AI-authored evidence for \"component_provenance\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
},
{
"claim": "release_integrity_mechanism",
"requirement": "ai_position",
"value": "ADMIT",
"because": "No instrument in force stated a position on AI-authored evidence for \"release_integrity_mechanism\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
},
{
"claim": "supplier_assessment",
"requirement": "ai_position",
"value": "ADMIT",
"because": "No instrument in force stated a position on AI-authored evidence for \"supplier_assessment\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
}
]
}
}
}Assessor / authorising official
A third-party assessment organisation, an agency assessor, or an inspector general reviewing the package. Same position as a customs officer: a public mandate over the record.
The control record in full — each publication by control identifier, edition and document digest, and every required claim with who supplied it and when. No exposure figure, no risk pricing, no confidence score.
What each authority bound
| Claim | Requirement | Level | Bound by |
|---|---|---|---|
| code_review | required | true | National Institute of Standards and Technology PW.7 [VERIFY] · SP 800-218 — Secure Software Development Framework v1.1 |
| component_provenance | min class | SELLER-ASSERTED | National Institute of Standards and Technology SR-4 [VERIFY] · SP 800-161 Rev. 1 — C-SCRM Practices for Systems and Organizations |
| component_provenance | required | true | National Institute of Standards and Technology PS.3.2 [VERIFY] · SP 800-218 — Secure Software Development Framework v1.1 |
| release_integrity_mechanism | min class | VERIFIED | National Institute of Standards and Technology PS.2 [VERIFY] · SP 800-218 — Secure Software Development Framework v1.1 |
| release_integrity_mechanism | never waivable | true | National Institute of Standards and Technology PS.2 [VERIFY] · SP 800-218 — Secure Software Development Framework v1.1 |
| release_integrity_mechanism | required | true | National Institute of Standards and Technology PS.2 [VERIFY] · SP 800-218 — Secure Software Development Framework v1.1 |
| supplier_assessment | required | true | National Institute of Standards and Technology SR-6 [VERIFY] · SP 800-161 Rev. 1 — C-SCRM Practices for Systems and Organizations |
Every required claim, and what was actually held
| Claim | Required | Evidence class | Who | Age | Outcome |
|---|---|---|---|---|---|
| release_integrity_mechanism | yes | VERIFIED | actor:org:LAB-NVLAP-0412 | 2026-05-30 | admitted |
| supplier_assessment | yes | VERIFIED | actor:org:CERT-3PAO-ATLANTIC | 2026-01-20 | admitted |
| code_review | no | SELLER-ASSERTED | actor:org:INTERNAL-PLATFORM-ENG | 2026-08-06 | withheld |
| component_provenance | no | SELLER-ASSERTED | actor:org:INTERNAL-PLATFORM-ENG | 2026-08-07 | withheld |
| code_review | yes | MISSING | — | 2026-08-08 | coverage gap |
| component_provenance | yes | MISSING | — | 2026-08-08 | coverage gap |
The scoped copy itself — partial — something outside this role’s remit was removed
{
"spec": "corobate:role-view:2",
"role": "REGULATOR",
"purpose": "An official holding a public mandate over this record — a customs officer, a bank examiner, a market conduct supervisor. Sees the regulatory record in full: their own instrument named, every required claim and whether it was met, by whom, how old. No commercial figure of any kind.",
"is_a_receipt": false,
"warning": "This is a SCOPED COPY of a sealed decision, not the decision record itself. It will not verify as a receipt and must not be presented as one. To confirm it is faithful, recompute its `view` digest under the same canonicalisation that produces receipt_hash and compare it with the entry for this role in the source receipt’s `views` block.",
"derived_from": {
"receipt_hash": "sha256:90a20c5dcda8ab70e32d7b08521e24e2f271d03ac079f47c2a047dfd3ed9cb4c",
"entry_hash": "sha256:62842a7dbe06d36b693bfd2f62a3c8123aede49a1a9092bc52a75f26ff260df5",
"issued_at": "2026-08-08T16:00:00.000Z"
},
"view_digest": "sha256:20e00f18ba29e2adbe6ae05018470dba5bd4a2da12380cf4261809524035cd94",
"withheld": {
"anything_withheld": true,
"note": "Facts outside this role’s remit were removed. That something was removed is stated so a partial record is never mistaken for a complete one. How much, and what, is not stated — a count is an inference about the part you are not entitled to see."
},
"view": {
"spec": "urn:ietf:params:corobate:receipt:1",
"receipt_version": "1.8",
"issued_at": "2026-08-08T16:00:00.000Z",
"decision": {
"id": "rel_PLATFORM_2026_8_0",
"subject": "release:PLATFORM-CORE-2026.8.0",
"question": "May this release be published to the government-facing environment?"
},
"memory": {
"state_digest": "sha256:b69314201d2e10631d7179b82717dd6079b7dc7408b3ee37281eb56729ce59f2",
"ledger_head": "sha256:fdadc9eed6746ad514ec9f681a2910b2fa04006a84e45cb24a08e5bdcd9e97b3",
"coverage_gaps": [
"release:PLATFORM-CORE-2026.8.0|code_review",
"release:PLATFORM-CORE-2026.8.0|component_provenance"
]
},
"data_horizon": "2026-08-08T16:00:00.000Z",
"verdict": {
"value": "WITHHELD"
},
"regulatory": {
"spec": "corobate:regulatory:2",
"resolved": true,
"applied": [
{
"instrument_id": "nist-sp-800-218-ssdf",
"version": 1,
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-218 — Secure Software Development Framework v1.1",
"edition": "1.1",
"citation": "PS.3.2, PS.2, PW.7 [VERIFY]",
"source_digest": "sha256:1818181818181818181818181818181818181818181818181818181818181818",
"entered_by": "actor:human:issm",
"entered_at": "2026-08-08T16:00:00.000Z"
},
{
"instrument_id": "nist-sp-800-161r1-cscrm",
"version": 1,
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-161 Rev. 1 — C-SCRM Practices for Systems and Organizations",
"edition": "Rev. 1",
"citation": "SR-3, SR-4, SR-11 [VERIFY]",
"source_digest": "sha256:6161616161616161616161616161616161616161616161616161616161616161",
"entered_by": "actor:human:issm",
"entered_at": "2026-08-08T16:00:00.000Z"
}
],
"skipped": [],
"conflicts": [],
"bindings": [
{
"claim": "code_review",
"requirement": "required",
"value": true,
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-218 — Secure Software Development Framework v1.1",
"instrument_id": "nist-sp-800-218-ssdf",
"version": 1,
"edition": "1.1",
"citation": "PW.7 [VERIFY]",
"source_digest": "sha256:1818181818181818181818181818181818181818181818181818181818181818"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "component_provenance",
"requirement": "min_class",
"value": "SELLER-ASSERTED",
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-161 Rev. 1 — C-SCRM Practices for Systems and Organizations",
"instrument_id": "nist-sp-800-161r1-cscrm",
"version": 1,
"edition": "Rev. 1",
"citation": "SR-4 [VERIFY]",
"source_digest": "sha256:6161616161616161616161616161616161616161616161616161616161616161"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "component_provenance",
"requirement": "required",
"value": true,
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-218 — Secure Software Development Framework v1.1",
"instrument_id": "nist-sp-800-218-ssdf",
"version": 1,
"edition": "1.1",
"citation": "PS.3.2 [VERIFY]",
"source_digest": "sha256:1818181818181818181818181818181818181818181818181818181818181818"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "release_integrity_mechanism",
"requirement": "min_class",
"value": "VERIFIED",
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-218 — Secure Software Development Framework v1.1",
"instrument_id": "nist-sp-800-218-ssdf",
"version": 1,
"edition": "1.1",
"citation": "PS.2 [VERIFY]",
"source_digest": "sha256:1818181818181818181818181818181818181818181818181818181818181818"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "release_integrity_mechanism",
"requirement": "never_waivable",
"value": true,
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-218 — Secure Software Development Framework v1.1",
"instrument_id": "nist-sp-800-218-ssdf",
"version": 1,
"edition": "1.1",
"citation": "PS.2 [VERIFY]",
"source_digest": "sha256:1818181818181818181818181818181818181818181818181818181818181818"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "release_integrity_mechanism",
"requirement": "required",
"value": true,
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-218 — Secure Software Development Framework v1.1",
"instrument_id": "nist-sp-800-218-ssdf",
"version": 1,
"edition": "1.1",
"citation": "PS.2 [VERIFY]",
"source_digest": "sha256:1818181818181818181818181818181818181818181818181818181818181818"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "supplier_assessment",
"requirement": "required",
"value": true,
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-161 Rev. 1 — C-SCRM Practices for Systems and Organizations",
"instrument_id": "nist-sp-800-161r1-cscrm",
"version": 1,
"edition": "Rev. 1",
"citation": "SR-6 [VERIFY]",
"source_digest": "sha256:6161616161616161616161616161616161616161616161616161616161616161"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
}
],
"defaults": [
{
"claim": "code_review",
"requirement": "ai_position",
"value": "ADMIT",
"because": "No instrument in force stated a position on AI-authored evidence for \"code_review\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
},
{
"claim": "component_provenance",
"requirement": "ai_position",
"value": "ADMIT",
"because": "No instrument in force stated a position on AI-authored evidence for \"component_provenance\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
},
{
"claim": "release_integrity_mechanism",
"requirement": "ai_position",
"value": "ADMIT",
"because": "No instrument in force stated a position on AI-authored evidence for \"release_integrity_mechanism\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
},
{
"claim": "supplier_assessment",
"requirement": "ai_position",
"value": "ADMIT",
"because": "No instrument in force stated a position on AI-authored evidence for \"supplier_assessment\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
}
]
},
"inputs": [
{
"key": "release:PLATFORM-CORE-2026.8.0::release_integrity_mechanism",
"provenance": "VERIFIED",
"source": "LAB-NVLAP-0412:release_integrity_mechanism",
"observed_at": "2026-05-30T16:00:00.000Z",
"critical": true,
"memory_status": "admitted",
"memory_actor": "actor:org:LAB-NVLAP-0412"
},
{
"key": "release:PLATFORM-CORE-2026.8.0::supplier_assessment",
"provenance": "VERIFIED",
"source": "CERT-3PAO-ATLANTIC:supplier_assessment",
"observed_at": "2026-01-20T16:00:00.000Z",
"critical": true,
"memory_status": "admitted",
"memory_actor": "actor:org:CERT-3PAO-ATLANTIC"
},
{
"key": "release:PLATFORM-CORE-2026.8.0::code_review",
"provenance": "SELLER-ASSERTED",
"source": "INTERNAL-PLATFORM-ENG:code_review",
"observed_at": "2026-08-06T16:00:00.000Z",
"critical": false,
"memory_status": "withheld",
"memory_actor": "actor:org:INTERNAL-PLATFORM-ENG"
},
{
"key": "release:PLATFORM-CORE-2026.8.0::component_provenance",
"provenance": "SELLER-ASSERTED",
"source": "INTERNAL-PLATFORM-ENG:component_provenance",
"observed_at": "2026-08-07T16:00:00.000Z",
"critical": false,
"memory_status": "withheld",
"memory_actor": "actor:org:INTERNAL-PLATFORM-ENG"
},
{
"key": "release:PLATFORM-CORE-2026.8.0::code_review",
"provenance": "MISSING",
"source": null,
"observed_at": "2026-08-08T16:00:00.000Z",
"critical": true,
"memory_status": "coverage_gap"
},
{
"key": "release:PLATFORM-CORE-2026.8.0::component_provenance",
"provenance": "MISSING",
"source": null,
"observed_at": "2026-08-08T16:00:00.000Z",
"critical": true,
"memory_status": "coverage_gap"
}
],
"crypto_suite": {
"spec": "corobate:suite:1",
"id": "CB-1-ES256-SHA256",
"receipt_digest": "sha256",
"chain_digest": "sha256",
"content_digest": "sha256",
"envelope_signature": "ES256",
"signature_curve": "P-256",
"canonicalisation": "attest-canon/2",
"quantum_resistant": false
}
}
}ISSM / control owner
The information system security manager and the control owners who hold the package.
The fullest internal view: every input, its class, its age, its score, the exposure, and every publication in force.
Every input the gate saw
| Claim | Required | Evidence class | Who | Age | Score | Outcome |
|---|---|---|---|---|---|---|
| release_integrity_mechanism | yes | VERIFIED | actor:org:LAB-NVLAP-0412 | 70d | 95% | admitted |
| supplier_assessment | yes | VERIFIED | actor:org:CERT-3PAO-ATLANTIC | 200d | 95% | admitted |
| code_review | no | SELLER-ASSERTED | actor:org:INTERNAL-PLATFORM-ENG | 2d | 50% | withheld |
| component_provenance | no | SELLER-ASSERTED | actor:org:INTERNAL-PLATFORM-ENG | 1d | 50% | withheld |
| code_review | yes | MISSING | — | 2026-08-08 | 0% | coverage gap |
| component_provenance | yes | MISSING | — | 2026-08-08 | 0% | coverage gap |
Instruments in force
Why
- Coverage gap: no admissible memory for required claim(s) release:PLATFORM-CORE-2026.8.0|code_review, release:PLATFORM-CORE-2026.8.0|component_provenance.
- Confidence 0.00% is bound by "release:PLATFORM-CORE-2026.8.0|code_review".
- 2 memories were withheld from the context block: release:PLATFORM-CORE-2026.8.0|code_review (sparse track record: 1 independent observation(s); no failure recorded, so the class ceiling stands); release:PLATFORM-CORE-2026.8.0|component_provenance (sparse track record: 1 independent observation(s); no failure recorded, so the class ceiling stands).
- Thresholds for $640,000 exposure: approve 85%, caution 60%.
The scoped copy itself — partial — something outside this role’s remit was removed
{
"spec": "corobate:role-view:2",
"role": "COMPLIANCE",
"purpose": "The operator’s own compliance function. The fullest internal view: every gap, every instrument in force, the waivability of each requirement and who accepted what.",
"is_a_receipt": false,
"warning": "This is a SCOPED COPY of a sealed decision, not the decision record itself. It will not verify as a receipt and must not be presented as one. To confirm it is faithful, recompute its `view` digest under the same canonicalisation that produces receipt_hash and compare it with the entry for this role in the source receipt’s `views` block.",
"derived_from": {
"receipt_hash": "sha256:90a20c5dcda8ab70e32d7b08521e24e2f271d03ac079f47c2a047dfd3ed9cb4c",
"entry_hash": "sha256:62842a7dbe06d36b693bfd2f62a3c8123aede49a1a9092bc52a75f26ff260df5",
"issued_at": "2026-08-08T16:00:00.000Z"
},
"view_digest": "sha256:7995bc6450131c6fc43f7b94490b44e0f6267dea9c4eafb830c5ab7aff52a688",
"withheld": {
"anything_withheld": true,
"note": "Facts outside this role’s remit were removed. That something was removed is stated so a partial record is never mistaken for a complete one. How much, and what, is not stated — a count is an inference about the part you are not entitled to see."
},
"view": {
"spec": "urn:ietf:params:corobate:receipt:1",
"receipt_version": "1.8",
"issued_at": "2026-08-08T16:00:00.000Z",
"decision": {
"id": "rel_PLATFORM_2026_8_0",
"domain": "supply-chain",
"subject": "release:PLATFORM-CORE-2026.8.0",
"question": "May this release be published to the government-facing environment?"
},
"memory": {
"state_digest": "sha256:b69314201d2e10631d7179b82717dd6079b7dc7408b3ee37281eb56729ce59f2",
"ledger_head": "sha256:fdadc9eed6746ad514ec9f681a2910b2fa04006a84e45cb24a08e5bdcd9e97b3",
"coverage_gaps": [
"release:PLATFORM-CORE-2026.8.0|code_review",
"release:PLATFORM-CORE-2026.8.0|component_provenance"
],
"exposure": {
"usd": 640000,
"declared_by": "actor:human:issm",
"ledger_seq": 4
},
"policy_digest": "sha256:a6b69b7d20f7fb04d522364af1d92992058b04a5835fcec9d1c9f2261c7ef636"
},
"data_horizon": "2026-08-08T16:00:00.000Z",
"verdict": {
"value": "WITHHELD",
"threshold_approve": 0.85,
"threshold_caution": 0.6,
"rule": "confidence>=threshold"
},
"confidence": {
"value": 0,
"method": "min-over-critical-inputs",
"bound_by": "release:PLATFORM-CORE-2026.8.0::code_review"
},
"release": {
"required": false,
"required_by_tier": false,
"escalated_by_acceptance": false,
"risk_accepted": false,
"state": "WITHHELD_NO_EVIDENCE",
"code": "QUORUM_EVIDENCE_WITHHELD",
"reason": "the evidence did not clear the threshold for this exposure, so there is nothing to release. Signatures do not substitute for evidence, and this state is deliberately distinct from WITHHELD_PENDING_SIGNATURES: a reader must be able to tell \"the evidence is not there\" from \"the evidence is there and 0 of 2 people have signed\".",
"tier_floor_cents": 1000000000,
"exposure_usd_cents": 64000000,
"required_m": 2,
"declared_n": 3,
"floor_m": 2,
"distinct_signers": 0,
"superseded": 0,
"collapsed": 0,
"release_digest": "sha256:dab60630adae29904fb52f9577e707f91834a0c7d6e315e4382ceebcc01b11d7",
"governance_digest": "sha256:8b0a45a27fcce9c1c243c764e855e67c6fe6dfd7f02a563bd90809b419731905",
"governance_signed": true,
"counted_voices": [],
"signatures": [],
"ledger_seq": null
},
"acceptance": {
"state": "NONE",
"code": "ACCEPTANCE_NONE",
"reason": "no risk acceptance was presented for this decision. This is the ordinary case: a refusal is a refusal unless a named person has priced it.",
"permitted_basis": null,
"presented": 0,
"superseded": 0,
"expired": 0,
"gaps_not_covered": 0,
"coverage_gaps_in_force": [
"release:PLATFORM-CORE-2026.8.0|code_review",
"release:PLATFORM-CORE-2026.8.0|component_provenance"
],
"evidentiary_digest": "sha256:dab60630adae29904fb52f9577e707f91834a0c7d6e315e4382ceebcc01b11d7",
"margin_floor_bp": 100,
"authority_ceiling_cents": {
"SUPERVISOR": 1000000,
"MANAGER": 25000000,
"DIRECTOR": 500000000,
"OFFICER": 5000000000
},
"acceptances": [],
"escalated": false,
"live": false,
"ledger_seq": null
},
"regulatory": {
"spec": "corobate:regulatory:2",
"resolved": true,
"applied": [
{
"instrument_id": "nist-sp-800-218-ssdf",
"version": 1,
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-218 — Secure Software Development Framework v1.1",
"edition": "1.1",
"citation": "PS.3.2, PS.2, PW.7 [VERIFY]",
"source_digest": "sha256:1818181818181818181818181818181818181818181818181818181818181818",
"entered_by": "actor:human:issm",
"entered_at": "2026-08-08T16:00:00.000Z"
},
{
"instrument_id": "nist-sp-800-161r1-cscrm",
"version": 1,
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-161 Rev. 1 — C-SCRM Practices for Systems and Organizations",
"edition": "Rev. 1",
"citation": "SR-3, SR-4, SR-11 [VERIFY]",
"source_digest": "sha256:6161616161616161616161616161616161616161616161616161616161616161",
"entered_by": "actor:human:issm",
"entered_at": "2026-08-08T16:00:00.000Z"
}
],
"skipped": [],
"conflicts": [],
"bindings": [
{
"claim": "code_review",
"requirement": "required",
"value": true,
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-218 — Secure Software Development Framework v1.1",
"instrument_id": "nist-sp-800-218-ssdf",
"version": 1,
"edition": "1.1",
"citation": "PW.7 [VERIFY]",
"source_digest": "sha256:1818181818181818181818181818181818181818181818181818181818181818"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "component_provenance",
"requirement": "min_class",
"value": "SELLER-ASSERTED",
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-161 Rev. 1 — C-SCRM Practices for Systems and Organizations",
"instrument_id": "nist-sp-800-161r1-cscrm",
"version": 1,
"edition": "Rev. 1",
"citation": "SR-4 [VERIFY]",
"source_digest": "sha256:6161616161616161616161616161616161616161616161616161616161616161"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "component_provenance",
"requirement": "required",
"value": true,
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-218 — Secure Software Development Framework v1.1",
"instrument_id": "nist-sp-800-218-ssdf",
"version": 1,
"edition": "1.1",
"citation": "PS.3.2 [VERIFY]",
"source_digest": "sha256:1818181818181818181818181818181818181818181818181818181818181818"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "release_integrity_mechanism",
"requirement": "min_class",
"value": "VERIFIED",
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-218 — Secure Software Development Framework v1.1",
"instrument_id": "nist-sp-800-218-ssdf",
"version": 1,
"edition": "1.1",
"citation": "PS.2 [VERIFY]",
"source_digest": "sha256:1818181818181818181818181818181818181818181818181818181818181818"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "release_integrity_mechanism",
"requirement": "never_waivable",
"value": true,
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-218 — Secure Software Development Framework v1.1",
"instrument_id": "nist-sp-800-218-ssdf",
"version": 1,
"edition": "1.1",
"citation": "PS.2 [VERIFY]",
"source_digest": "sha256:1818181818181818181818181818181818181818181818181818181818181818"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "release_integrity_mechanism",
"requirement": "required",
"value": true,
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-218 — Secure Software Development Framework v1.1",
"instrument_id": "nist-sp-800-218-ssdf",
"version": 1,
"edition": "1.1",
"citation": "PS.2 [VERIFY]",
"source_digest": "sha256:1818181818181818181818181818181818181818181818181818181818181818"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "supplier_assessment",
"requirement": "required",
"value": true,
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-161 Rev. 1 — C-SCRM Practices for Systems and Organizations",
"instrument_id": "nist-sp-800-161r1-cscrm",
"version": 1,
"edition": "Rev. 1",
"citation": "SR-6 [VERIFY]",
"source_digest": "sha256:6161616161616161616161616161616161616161616161616161616161616161"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
}
],
"defaults": [
{
"claim": "code_review",
"requirement": "ai_position",
"value": "ADMIT",
"because": "No instrument in force stated a position on AI-authored evidence for \"code_review\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
},
{
"claim": "component_provenance",
"requirement": "ai_position",
"value": "ADMIT",
"because": "No instrument in force stated a position on AI-authored evidence for \"component_provenance\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
},
{
"claim": "release_integrity_mechanism",
"requirement": "ai_position",
"value": "ADMIT",
"because": "No instrument in force stated a position on AI-authored evidence for \"release_integrity_mechanism\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
},
{
"claim": "supplier_assessment",
"requirement": "ai_position",
"value": "ADMIT",
"because": "No instrument in force stated a position on AI-authored evidence for \"supplier_assessment\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
}
]
},
"reasons": [
"Coverage gap: no admissible memory for required claim(s) release:PLATFORM-CORE-2026.8.0|code_review, release:PLATFORM-CORE-2026.8.0|component_provenance.",
"Confidence 0.00% is bound by \"release:PLATFORM-CORE-2026.8.0|code_review\".",
"2 memories were withheld from the context block: release:PLATFORM-CORE-2026.8.0|code_review (sparse track record: 1 independent observation(s); no failure recorded, so the class ceiling stands); release:PLATFORM-CORE-2026.8.0|component_provenance (sparse track record: 1 independent observation(s); no failure recorded, so the class ceiling stands).",
"Thresholds for $640,000 exposure: approve 85%, caution 60%."
],
"inputs": [
{
"key": "release:PLATFORM-CORE-2026.8.0::release_integrity_mechanism",
"value": "assessed",
"provenance": "VERIFIED",
"source": "LAB-NVLAP-0412:release_integrity_mechanism",
"observed_at": "2026-05-30T16:00:00.000Z",
"reliability": 0.95,
"critical": true,
"memory_status": "admitted",
"memory_kind": "certificate",
"memory_actor": "actor:org:LAB-NVLAP-0412",
"memory_age_days": 70
},
{
"key": "release:PLATFORM-CORE-2026.8.0::supplier_assessment",
"value": "assessed",
"provenance": "VERIFIED",
"source": "CERT-3PAO-ATLANTIC:supplier_assessment",
"observed_at": "2026-01-20T16:00:00.000Z",
"reliability": 0.95,
"critical": true,
"memory_status": "admitted",
"memory_kind": "certificate",
"memory_actor": "actor:org:CERT-3PAO-ATLANTIC",
"memory_age_days": 200
},
{
"key": "release:PLATFORM-CORE-2026.8.0::code_review",
"value": null,
"provenance": "SELLER-ASSERTED",
"source": "INTERNAL-PLATFORM-ENG:code_review",
"observed_at": "2026-08-06T16:00:00.000Z",
"reliability": 0.5,
"critical": false,
"memory_status": "withheld",
"memory_kind": "status",
"memory_actor": "actor:org:INTERNAL-PLATFORM-ENG",
"memory_age_days": 2
},
{
"key": "release:PLATFORM-CORE-2026.8.0::component_provenance",
"value": null,
"provenance": "SELLER-ASSERTED",
"source": "INTERNAL-PLATFORM-ENG:component_provenance",
"observed_at": "2026-08-07T16:00:00.000Z",
"reliability": 0.5,
"critical": false,
"memory_status": "withheld",
"memory_kind": "test_report",
"memory_actor": "actor:org:INTERNAL-PLATFORM-ENG",
"memory_age_days": 1
},
{
"key": "release:PLATFORM-CORE-2026.8.0::code_review",
"value": null,
"provenance": "MISSING",
"source": null,
"observed_at": "2026-08-08T16:00:00.000Z",
"reliability": 0,
"critical": true,
"memory_status": "coverage_gap"
},
{
"key": "release:PLATFORM-CORE-2026.8.0::component_provenance",
"value": null,
"provenance": "MISSING",
"source": null,
"observed_at": "2026-08-08T16:00:00.000Z",
"reliability": 0,
"critical": true,
"memory_status": "coverage_gap"
}
],
"crypto_suite": {
"spec": "corobate:suite:1",
"id": "CB-1-ES256-SHA256",
"receipt_digest": "sha256",
"chain_digest": "sha256",
"content_digest": "sha256",
"envelope_signature": "ES256",
"signature_curve": "P-256",
"canonicalisation": "attest-canon/2",
"quantum_resistant": false
}
}
}Authorising official (signer)
The named official whose signature carries the authorisation decision.
What is at stake, what the evidence supports, what is missing, and the digest they are signing over.
You are being asked to sign
May this release be published to the government-facing environment?
The signature is over the STATE OF THE EVIDENCE. Move one fact behind this decision and the digest moves and the signature stops counting — which is what makes it safe to collect signatures before everyone is in the room.
What is missing
- code review
- component provenance
The scoped copy itself — partial — something outside this role’s remit was removed
{
"spec": "corobate:role-view:2",
"role": "EXECUTIVE",
"purpose": "A named signer on the release gate. Sees what is at stake, what the evidence supports, who else has signed and what they are being asked to sign over.",
"is_a_receipt": false,
"warning": "This is a SCOPED COPY of a sealed decision, not the decision record itself. It will not verify as a receipt and must not be presented as one. To confirm it is faithful, recompute its `view` digest under the same canonicalisation that produces receipt_hash and compare it with the entry for this role in the source receipt’s `views` block.",
"derived_from": {
"receipt_hash": "sha256:90a20c5dcda8ab70e32d7b08521e24e2f271d03ac079f47c2a047dfd3ed9cb4c",
"entry_hash": "sha256:62842a7dbe06d36b693bfd2f62a3c8123aede49a1a9092bc52a75f26ff260df5",
"issued_at": "2026-08-08T16:00:00.000Z"
},
"view_digest": "sha256:2cb0c1c6e97925924b71cdca6e8cb1c513682ab78fc48f6a5a84be91b3c5b833",
"withheld": {
"anything_withheld": true,
"note": "Facts outside this role’s remit were removed. That something was removed is stated so a partial record is never mistaken for a complete one. How much, and what, is not stated — a count is an inference about the part you are not entitled to see."
},
"view": {
"spec": "urn:ietf:params:corobate:receipt:1",
"receipt_version": "1.8",
"issued_at": "2026-08-08T16:00:00.000Z",
"decision": {
"id": "rel_PLATFORM_2026_8_0",
"domain": "supply-chain",
"subject": "release:PLATFORM-CORE-2026.8.0",
"question": "May this release be published to the government-facing environment?"
},
"memory": {
"state_digest": "sha256:b69314201d2e10631d7179b82717dd6079b7dc7408b3ee37281eb56729ce59f2",
"ledger_head": "sha256:fdadc9eed6746ad514ec9f681a2910b2fa04006a84e45cb24a08e5bdcd9e97b3",
"coverage_gaps": [
"release:PLATFORM-CORE-2026.8.0|code_review",
"release:PLATFORM-CORE-2026.8.0|component_provenance"
],
"exposure": {
"usd": 640000,
"declared_by": "actor:human:issm",
"ledger_seq": 4
}
},
"verdict": {
"value": "WITHHELD",
"threshold_approve": 0.85,
"threshold_caution": 0.6,
"rule": "confidence>=threshold"
},
"confidence": {
"value": 0,
"method": "min-over-critical-inputs",
"bound_by": "release:PLATFORM-CORE-2026.8.0::code_review"
},
"release": {
"required": false,
"required_by_tier": false,
"escalated_by_acceptance": false,
"risk_accepted": false,
"state": "WITHHELD_NO_EVIDENCE",
"code": "QUORUM_EVIDENCE_WITHHELD",
"reason": "the evidence did not clear the threshold for this exposure, so there is nothing to release. Signatures do not substitute for evidence, and this state is deliberately distinct from WITHHELD_PENDING_SIGNATURES: a reader must be able to tell \"the evidence is not there\" from \"the evidence is there and 0 of 2 people have signed\".",
"tier_floor_cents": 1000000000,
"exposure_usd_cents": 64000000,
"required_m": 2,
"declared_n": 3,
"floor_m": 2,
"distinct_signers": 0,
"superseded": 0,
"collapsed": 0,
"release_digest": "sha256:dab60630adae29904fb52f9577e707f91834a0c7d6e315e4382ceebcc01b11d7",
"governance_digest": "sha256:8b0a45a27fcce9c1c243c764e855e67c6fe6dfd7f02a563bd90809b419731905",
"governance_signed": true,
"counted_voices": [],
"signatures": [],
"ledger_seq": null
},
"acceptance": {
"state": "NONE",
"code": "ACCEPTANCE_NONE",
"reason": "no risk acceptance was presented for this decision. This is the ordinary case: a refusal is a refusal unless a named person has priced it.",
"permitted_basis": null,
"presented": 0,
"superseded": 0,
"expired": 0,
"gaps_not_covered": 0,
"coverage_gaps_in_force": [
"release:PLATFORM-CORE-2026.8.0|code_review",
"release:PLATFORM-CORE-2026.8.0|component_provenance"
],
"evidentiary_digest": "sha256:dab60630adae29904fb52f9577e707f91834a0c7d6e315e4382ceebcc01b11d7",
"margin_floor_bp": 100,
"authority_ceiling_cents": {
"SUPERVISOR": 1000000,
"MANAGER": 25000000,
"DIRECTOR": 500000000,
"OFFICER": 5000000000
},
"acceptances": [],
"escalated": false,
"live": false,
"ledger_seq": null
},
"reasons": [
"Coverage gap: no admissible memory for required claim(s) release:PLATFORM-CORE-2026.8.0|code_review, release:PLATFORM-CORE-2026.8.0|component_provenance.",
"Confidence 0.00% is bound by \"release:PLATFORM-CORE-2026.8.0|code_review\".",
"2 memories were withheld from the context block: release:PLATFORM-CORE-2026.8.0|code_review (sparse track record: 1 independent observation(s); no failure recorded, so the class ceiling stands); release:PLATFORM-CORE-2026.8.0|component_provenance (sparse track record: 1 independent observation(s); no failure recorded, so the class ceiling stands).",
"Thresholds for $640,000 exposure: approve 85%, caution 60%."
],
"regulatory": {
"applied": [
{
"instrument_id": "nist-sp-800-218-ssdf",
"version": 1,
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-218 — Secure Software Development Framework v1.1",
"edition": "1.1",
"citation": "PS.3.2, PS.2, PW.7 [VERIFY]",
"source_digest": "sha256:1818181818181818181818181818181818181818181818181818181818181818",
"entered_by": "actor:human:issm",
"entered_at": "2026-08-08T16:00:00.000Z"
},
{
"instrument_id": "nist-sp-800-161r1-cscrm",
"version": 1,
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-161 Rev. 1 — C-SCRM Practices for Systems and Organizations",
"edition": "Rev. 1",
"citation": "SR-3, SR-4, SR-11 [VERIFY]",
"source_digest": "sha256:6161616161616161616161616161616161616161616161616161616161616161",
"entered_by": "actor:human:issm",
"entered_at": "2026-08-08T16:00:00.000Z"
}
],
"conflicts": [],
"defaults": [
{
"claim": "code_review",
"requirement": "ai_position",
"value": "ADMIT",
"because": "No instrument in force stated a position on AI-authored evidence for \"code_review\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
},
{
"claim": "component_provenance",
"requirement": "ai_position",
"value": "ADMIT",
"because": "No instrument in force stated a position on AI-authored evidence for \"component_provenance\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
},
{
"claim": "release_integrity_mechanism",
"requirement": "ai_position",
"value": "ADMIT",
"because": "No instrument in force stated a position on AI-authored evidence for \"release_integrity_mechanism\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
},
{
"claim": "supplier_assessment",
"requirement": "ai_position",
"value": "ADMIT",
"because": "No instrument in force stated a position on AI-authored evidence for \"supplier_assessment\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
}
]
},
"inputs": [
{
"key": "release:PLATFORM-CORE-2026.8.0::release_integrity_mechanism",
"provenance": "VERIFIED",
"reliability": 0.95,
"critical": true,
"memory_status": "admitted"
},
{
"key": "release:PLATFORM-CORE-2026.8.0::supplier_assessment",
"provenance": "VERIFIED",
"reliability": 0.95,
"critical": true,
"memory_status": "admitted"
},
{
"key": "release:PLATFORM-CORE-2026.8.0::code_review",
"provenance": "SELLER-ASSERTED",
"reliability": 0.5,
"critical": false,
"memory_status": "withheld"
},
{
"key": "release:PLATFORM-CORE-2026.8.0::component_provenance",
"provenance": "SELLER-ASSERTED",
"reliability": 0.5,
"critical": false,
"memory_status": "withheld"
},
{
"key": "release:PLATFORM-CORE-2026.8.0::code_review",
"provenance": "MISSING",
"reliability": 0,
"critical": true,
"memory_status": "coverage_gap"
},
{
"key": "release:PLATFORM-CORE-2026.8.0::component_provenance",
"provenance": "MISSING",
"reliability": 0,
"critical": true,
"memory_status": "coverage_gap"
}
]
}
}Independent audit / IG
Internal audit, an inspector general, or an external auditor testing the programme.
Everything, plus the verifier’s own findings over the sealed record.
This view withholds nothing. What it adds is the 22 checks the published verifier ran over the sealed record behind every other view of this decision — recomputed at build time, not asserted.
| # | Check | Detail | |
|---|---|---|---|
| 1 | Content reproduces (JCS + SHA-256) | PASS | matches sha256:90a20c5dcda8ab70e32d7b08521e24e2f271d03ac079f47c2a047dfd3ed9cb4c |
| 2 | Hash chain links (entry = H(prev||content)) | PASS | head sha256:62842a7dbe06d36b693bfd2f62a3c8123aede49a1a9092bc52a75f26ff260df5 |
| 3 | Confidence gated by weakest critical input | PASS | min over critical = 0, bound_by release:PLATFORM-CORE-2026.8.0::code_review (MISSING) |
| 3b | Verdict follows the threshold rule | PASS | 0 => WITHHELD; recorded WITHHELD |
| 4 | Point-in-time seal (no input past data_horizon) | PASS | all inputs <= 2026-08-08T16:00:00.000Z |
| 5 | Anchor covers the head, and the timestamp token re-reads | PASS | internally consistent; NO external anchor was requested — this is not a validated timestamp |
| 6 | Criteria travel with the receipt and reproduce | PASS | policy_body hashes to sha256:a6b69b7d20f7fb04d522364af1d92992058b04a5835fcec9d1c9f2261c7ef636 |
| 7 | Reliability re-derives from recorded evidence | PASS | all 6 inputs re-derive exactly |
| 8 | Outcome trials and lineage discounts re-derive | PASS | 4 input(s) re-derive: 0 credited outcome trial(s), 0 lineage-discounted corroboration(s); every reliability is at or under its class ceiling |
| 9 | Re-ingested receipts respect their weakest-input ceiling | PASS | no re-ingested receipts: every input rests on a primary observation |
| 10 | Release quorum re-derives | PASS | WITHHELD_NO_EVIDENCE - below the top exposure tier, no multi-party requirement applies |
| 11 | Risk acceptance re-derives | PASS | no risk acceptance: this decision stands or falls on its evidence |
| 12 | Observer credentials were not revoked as of observation time | PASS | revocation list 5 (0 entries, issued 2026-08-06T00:00:00.000Z, next update due 2026-08-13T00:00:00.000Z) reproduces; 2 observer signature(s) judged as of their own instant, none under a key revoked as compromised or retired by then |
| 13 | The cryptographic suite is named and is one this verifier implements | PASS | sealed under CB-1-ES256-SHA256 (ES256 / sha256, attest-canon/2); this verifier implements it; the suite states it is NOT quantum resistant |
| 14 | Regulatory bindings are attributed and were enforced | PASS | 7 binding(s) from 2 instrument(s) in force, each attributed to an authority, a citation and a document digest; 4 required claim(s) all reached the gate |
| 15 | Role-view commitments re-derive, and the customs view carries no money | PASS | 6 role-view commitment(s) re-derived from this receipt’s own body by this verifier’s independent projection; the REGULATOR view carries no commercial figure |
| 16 | AI-authored input was admitted only where an authority allowed it | PASS | 0 claim(s) carry a position on AI-authored evidence set by an authority and 4 carry a recorded default nobody set; 0 exclusion(s) and 0 corroboration-only rule(s) re-derived against this receipt's own admitted inputs; 0 admitted input(s) are AI-authored by their enrolled identity |
| 17 | State digest recomputes from the ledger alone | UNVERIFIABLE | NOT APPLICABLE — you supplied no ledger, so the state digest cannot be re-derived from anything. This receipt commits to the corpus the deciding system held at the instant it sealed, and that commitment is checked by recomputing it from the append-only ledger and comparing; with no ledger in hand there is no second artefact to recompute from. The receipt is not at fault and nothing here is missing from it. Obtain the ledger from the issuer and re-run with --ledger <file>, or verifyReceipt(r, {ledger}). Nothing here has failed and nothing here has passed. |
| 18 | Registry membership re-derives for every key relied on | PASS | all 2 key(s) relied on re-derive to the entries root registry v3 committed to and the trust root signed |
| 20 | Geometric support re-derives, and an unevaluated record is not a supported one | PASS | no authority bound a metric to any claim on this receipt, so no geometric test applied. A claim nobody bound a metric to is not a claim about geometry, and this is a stated absence rather than a silent one |
| 19 | The cause of every uncovered requirement re-derives | PASS | all 2 uncovered requirement(s) re-derive their cause from this receipt's own rows. What notice is ADEQUATE is not decided here: this check establishes what the record says and that the record agrees with itself. |
| 21 | The sealing party is the one you were told to expect | UNVERIFIABLE | NOT APPLICABLE — you supplied no trust bundle, so nothing here establishes who sealed this. Identities 1 to 20 prove that this document agrees with itself; not one of them asks whose trust root it was sealed under, and a document that agrees with itself about a decision nobody made agrees with itself perfectly. Obtain the issuer's corobate:trust-bundle:1 out of band, confirm its spoken fingerprint with them by voice, and re-run with --trust-bundle <file> --expect-fingerprint <what you heard>. Nothing here has failed and nothing here has passed. |
The scoped copy itself — complete for this role
{
"spec": "corobate:role-view:2",
"role": "AUDITOR",
"purpose": "An external assessor. Sees the complete sealed record: this view withholds nothing and exists so the identity case is a case rather than an exception.",
"is_a_receipt": false,
"warning": "This is a SCOPED COPY of a sealed decision, not the decision record itself. It will not verify as a receipt and must not be presented as one. To confirm it is faithful, recompute its `view` digest under the same canonicalisation that produces receipt_hash and compare it with the entry for this role in the source receipt’s `views` block.",
"derived_from": {
"receipt_hash": "sha256:90a20c5dcda8ab70e32d7b08521e24e2f271d03ac079f47c2a047dfd3ed9cb4c",
"entry_hash": "sha256:62842a7dbe06d36b693bfd2f62a3c8123aede49a1a9092bc52a75f26ff260df5",
"issued_at": "2026-08-08T16:00:00.000Z"
},
"view_digest": "sha256:656bcf3729e45b526de2bb0e61590b5a1cf2d464f51a5a52a0ad444f59178cf0",
"withheld": {
"anything_withheld": false,
"note": "Nothing outside the seal was removed for this role."
},
"view": {
"spec": "urn:ietf:params:corobate:receipt:1",
"receipt_version": "1.8",
"engine": {
"name": "corobate-memory",
"version": "1.0.0"
},
"decision": {
"id": "rel_PLATFORM_2026_8_0",
"domain": "supply-chain",
"subject": "release:PLATFORM-CORE-2026.8.0",
"question": "May this release be published to the government-facing environment?"
},
"issued_at": "2026-08-08T16:00:00.000Z",
"data_horizon": "2026-08-08T16:00:00.000Z",
"inputs": [
{
"key": "release:PLATFORM-CORE-2026.8.0::release_integrity_mechanism",
"value": "assessed",
"provenance": "VERIFIED",
"source": "LAB-NVLAP-0412:release_integrity_mechanism",
"observed_at": "2026-05-30T16:00:00.000Z",
"last_corroborated_at": null,
"memory_refreshed_by": [],
"reliability": 0.95,
"critical": true,
"memory_id": "mem_9ab88c5965f8",
"memory_status": "admitted",
"memory_kind": "certificate",
"memory_actor": "actor:org:LAB-NVLAP-0412",
"memory_age_days": 70,
"memory_track": {
"n": 1,
"successes": 1
},
"memory_promoted_by": [],
"memory_content_digest": "sha256:271e63573c09d9e0c5d40662165956bcc8a6b4bf65e11baf3f8029a293a9effe",
"memory_outcomes": {
"verified": 0,
"falsified": 0,
"modified": 0,
"counted": 0,
"recorded": 0
},
"memory_outcome_attestations": [],
"memory_observer_lineage": null,
"memory_corroborations": [],
"memory_reingest": null,
"memory_reasons": [
"sparse track record: 1 independent observation(s); no failure recorded, so the class ceiling stands"
],
"memory_class_floor": "VERIFIED",
"memory_below_class_floor": false,
"memory_not_attested": false,
"memory_below_claim_reliability_floor": false,
"memory_not_competent_authority": false,
"memory_out_of_specification": false,
"memory_ai_authored": false,
"memory_ai_in_lineage": false,
"memory_ai_position": "ADMIT",
"memory_ai_inadmissible": false,
"memory_geo_inadmissible": false,
"memory_geo_rung": null,
"memory_geo_metric": null,
"memory_geo_required_metric": null,
"observer_attested": true,
"observer_auth_code": "VERIFIED",
"observer_key_id": "k_17d23885943ae529",
"attestation": null,
"derivation": {
"provenance": "VERIFIED",
"ceiling_bp": 9500,
"track": {
"n": 1,
"successes": 1
},
"wilson_bp": null,
"age_days": 70,
"max_age_days": 365,
"house_max_age_days": 365,
"instrument_max_age_days": null,
"freshness_cap_bp": 4000,
"min_track_n": 5,
"wilson_z_milli": 1960,
"source_present": true,
"seller_asserted_cap_bp": 5000,
"retracted": false,
"contradicted": false,
"outcome_trials": 0,
"outcomes": {
"verified": 0,
"falsified": 0,
"modified": 0,
"counted": 0,
"recorded": 0
},
"corroborations_counted": 0,
"corroborations_discounted": 0,
"reingest_ceiling_bp": null,
"reingest_depth": null,
"reingest_weakest_class": null,
"reingest_source_confidence_bp": null,
"min_class_floor": "VERIFIED",
"ai_authored": false,
"ai_authored_because": null,
"ai_in_lineage": false,
"ai_position": "ADMIT"
},
"memory_reason_codes": [
{
"code": "SPARSE_TRACK_RECORD",
"observed": 1,
"limit": 5,
"binding": false
}
],
"context_line": "[VERIFIED · r=95.0% · 70d · LAB-NVLAP-0412:release_integrity_mechanism] release:PLATFORM-CORE-2026.8.0 / release_integrity_mechanism: assessed"
},
{
"key": "release:PLATFORM-CORE-2026.8.0::supplier_assessment",
"value": "assessed",
"provenance": "VERIFIED",
"source": "CERT-3PAO-ATLANTIC:supplier_assessment",
"observed_at": "2026-01-20T16:00:00.000Z",
"last_corroborated_at": null,
"memory_refreshed_by": [],
"reliability": 0.95,
"critical": true,
"memory_id": "mem_849b47b67301",
"memory_status": "admitted",
"memory_kind": "certificate",
"memory_actor": "actor:org:CERT-3PAO-ATLANTIC",
"memory_age_days": 200,
"memory_track": {
"n": 1,
"successes": 1
},
"memory_promoted_by": [],
"memory_content_digest": "sha256:f62959286a450d4bc998869a2fc8db63d444dc498c9af3fa109595b74e7d0983",
"memory_outcomes": {
"verified": 0,
"falsified": 0,
"modified": 0,
"counted": 0,
"recorded": 0
},
"memory_outcome_attestations": [],
"memory_observer_lineage": null,
"memory_corroborations": [],
"memory_reingest": null,
"memory_reasons": [
"sparse track record: 1 independent observation(s); no failure recorded, so the class ceiling stands"
],
"memory_class_floor": null,
"memory_below_class_floor": false,
"memory_not_attested": false,
"memory_below_claim_reliability_floor": false,
"memory_not_competent_authority": false,
"memory_out_of_specification": false,
"memory_ai_authored": false,
"memory_ai_in_lineage": false,
"memory_ai_position": "ADMIT",
"memory_ai_inadmissible": false,
"memory_geo_inadmissible": false,
"memory_geo_rung": null,
"memory_geo_metric": null,
"memory_geo_required_metric": null,
"observer_attested": true,
"observer_auth_code": "VERIFIED",
"observer_key_id": "k_307e4bfd710ec9b3",
"attestation": null,
"derivation": {
"provenance": "VERIFIED",
"ceiling_bp": 9500,
"track": {
"n": 1,
"successes": 1
},
"wilson_bp": null,
"age_days": 200,
"max_age_days": 365,
"house_max_age_days": 365,
"instrument_max_age_days": null,
"freshness_cap_bp": 4000,
"min_track_n": 5,
"wilson_z_milli": 1960,
"source_present": true,
"seller_asserted_cap_bp": 5000,
"retracted": false,
"contradicted": false,
"outcome_trials": 0,
"outcomes": {
"verified": 0,
"falsified": 0,
"modified": 0,
"counted": 0,
"recorded": 0
},
"corroborations_counted": 0,
"corroborations_discounted": 0,
"reingest_ceiling_bp": null,
"reingest_depth": null,
"reingest_weakest_class": null,
"reingest_source_confidence_bp": null,
"ai_authored": false,
"ai_authored_because": null,
"ai_in_lineage": false,
"ai_position": "ADMIT"
},
"memory_reason_codes": [
{
"code": "SPARSE_TRACK_RECORD",
"observed": 1,
"limit": 5,
"binding": false
}
],
"context_line": "[VERIFIED · r=95.0% · 200d · CERT-3PAO-ATLANTIC:supplier_assessment] release:PLATFORM-CORE-2026.8.0 / supplier_assessment: assessed"
},
{
"key": "release:PLATFORM-CORE-2026.8.0::code_review",
"value": null,
"provenance": "SELLER-ASSERTED",
"source": "INTERNAL-PLATFORM-ENG:code_review",
"observed_at": "2026-08-06T16:00:00.000Z",
"last_corroborated_at": null,
"memory_refreshed_by": [],
"reliability": 0.5,
"critical": false,
"memory_id": "mem_c68678e73e95",
"memory_status": "withheld",
"memory_kind": "status",
"memory_actor": "actor:org:INTERNAL-PLATFORM-ENG",
"memory_age_days": 2,
"memory_track": {
"n": 1,
"successes": 1
},
"memory_promoted_by": [],
"memory_content_digest": "sha256:e0e5ab071d9b9c8dfaa4e76d8c3ce2dfa5ad4fa4674d24c68b4d1c962705926d",
"memory_outcomes": {
"verified": 0,
"falsified": 0,
"modified": 0,
"counted": 0,
"recorded": 0
},
"memory_outcome_attestations": [],
"memory_observer_lineage": null,
"memory_corroborations": [],
"memory_reingest": null,
"memory_reasons": [
"sparse track record: 1 independent observation(s); no failure recorded, so the class ceiling stands"
],
"memory_class_floor": null,
"memory_below_class_floor": false,
"memory_not_attested": false,
"memory_below_claim_reliability_floor": false,
"memory_not_competent_authority": false,
"memory_out_of_specification": false,
"memory_ai_authored": false,
"memory_ai_in_lineage": false,
"memory_ai_position": "ADMIT",
"memory_ai_inadmissible": false,
"memory_geo_inadmissible": false,
"memory_geo_rung": null,
"memory_geo_metric": null,
"memory_geo_required_metric": null,
"observer_attested": false,
"observer_auth_code": "NO_ENVELOPE",
"observer_key_id": null,
"attestation": null,
"derivation": {
"provenance": "SELLER-ASSERTED",
"ceiling_bp": 5000,
"track": {
"n": 1,
"successes": 1
},
"wilson_bp": null,
"age_days": 2,
"max_age_days": 14,
"house_max_age_days": 14,
"instrument_max_age_days": null,
"freshness_cap_bp": 4000,
"min_track_n": 5,
"wilson_z_milli": 1960,
"source_present": true,
"seller_asserted_cap_bp": 5000,
"retracted": false,
"contradicted": false,
"outcome_trials": 0,
"outcomes": {
"verified": 0,
"falsified": 0,
"modified": 0,
"counted": 0,
"recorded": 0
},
"corroborations_counted": 0,
"corroborations_discounted": 0,
"reingest_ceiling_bp": null,
"reingest_depth": null,
"reingest_weakest_class": null,
"reingest_source_confidence_bp": null,
"ai_authored": false,
"ai_authored_because": null,
"ai_in_lineage": false,
"ai_position": "ADMIT"
},
"memory_reason_codes": [
{
"code": "SPARSE_TRACK_RECORD",
"observed": 1,
"limit": 5,
"binding": false
}
]
},
{
"key": "release:PLATFORM-CORE-2026.8.0::component_provenance",
"value": null,
"provenance": "SELLER-ASSERTED",
"source": "INTERNAL-PLATFORM-ENG:component_provenance",
"observed_at": "2026-08-07T16:00:00.000Z",
"last_corroborated_at": null,
"memory_refreshed_by": [],
"reliability": 0.5,
"critical": false,
"memory_id": "mem_bd32f4c2a701",
"memory_status": "withheld",
"memory_kind": "test_report",
"memory_actor": "actor:org:INTERNAL-PLATFORM-ENG",
"memory_age_days": 1,
"memory_track": {
"n": 1,
"successes": 1
},
"memory_promoted_by": [],
"memory_content_digest": "sha256:e9200f9f7a7149856d85d9b6b00a4492b79fa414610af4d974963bb291396246",
"memory_outcomes": {
"verified": 0,
"falsified": 0,
"modified": 0,
"counted": 0,
"recorded": 0
},
"memory_outcome_attestations": [],
"memory_observer_lineage": null,
"memory_corroborations": [],
"memory_reingest": null,
"memory_reasons": [
"sparse track record: 1 independent observation(s); no failure recorded, so the class ceiling stands"
],
"memory_class_floor": "SELLER-ASSERTED",
"memory_below_class_floor": false,
"memory_not_attested": false,
"memory_below_claim_reliability_floor": false,
"memory_not_competent_authority": false,
"memory_out_of_specification": false,
"memory_ai_authored": false,
"memory_ai_in_lineage": false,
"memory_ai_position": "ADMIT",
"memory_ai_inadmissible": false,
"memory_geo_inadmissible": false,
"memory_geo_rung": null,
"memory_geo_metric": null,
"memory_geo_required_metric": null,
"observer_attested": false,
"observer_auth_code": "NO_ENVELOPE",
"observer_key_id": null,
"attestation": null,
"derivation": {
"provenance": "SELLER-ASSERTED",
"ceiling_bp": 5000,
"track": {
"n": 1,
"successes": 1
},
"wilson_bp": null,
"age_days": 1,
"max_age_days": 180,
"house_max_age_days": 180,
"instrument_max_age_days": null,
"freshness_cap_bp": 4000,
"min_track_n": 5,
"wilson_z_milli": 1960,
"source_present": true,
"seller_asserted_cap_bp": 5000,
"retracted": false,
"contradicted": false,
"outcome_trials": 0,
"outcomes": {
"verified": 0,
"falsified": 0,
"modified": 0,
"counted": 0,
"recorded": 0
},
"corroborations_counted": 0,
"corroborations_discounted": 0,
"reingest_ceiling_bp": null,
"reingest_depth": null,
"reingest_weakest_class": null,
"reingest_source_confidence_bp": null,
"min_class_floor": "SELLER-ASSERTED",
"ai_authored": false,
"ai_authored_because": null,
"ai_in_lineage": false,
"ai_position": "ADMIT"
},
"memory_reason_codes": [
{
"code": "SPARSE_TRACK_RECORD",
"observed": 1,
"limit": 5,
"binding": false
}
]
},
{
"key": "release:PLATFORM-CORE-2026.8.0::code_review",
"value": null,
"provenance": "MISSING",
"source": null,
"observed_at": "2026-08-08T16:00:00.000Z",
"reliability": 0,
"critical": true,
"memory_status": "coverage_gap",
"gap_cause": "EVIDENCE_PRESENTED_FAILED",
"gap_request": null,
"gap_origin": "BUSINESS_EVIDENCE",
"gap_conditions": []
},
{
"key": "release:PLATFORM-CORE-2026.8.0::component_provenance",
"value": null,
"provenance": "MISSING",
"source": null,
"observed_at": "2026-08-08T16:00:00.000Z",
"reliability": 0,
"critical": true,
"memory_status": "coverage_gap",
"gap_cause": "EVIDENCE_PRESENTED_FAILED",
"gap_request": null,
"gap_origin": "BUSINESS_EVIDENCE",
"gap_conditions": []
}
],
"serialization": {
"algorithm": "RFC8785-JCS",
"hash": "sha256"
},
"crypto_suite": {
"spec": "corobate:suite:1",
"id": "CB-1-ES256-SHA256",
"receipt_digest": "sha256",
"chain_digest": "sha256",
"content_digest": "sha256",
"envelope_signature": "ES256",
"signature_curve": "P-256",
"canonicalisation": "attest-canon/2",
"quantum_resistant": false
},
"confidence": {
"value": 0,
"method": "min-over-critical-inputs",
"bound_by": "release:PLATFORM-CORE-2026.8.0::code_review"
},
"verdict": {
"value": "WITHHELD",
"threshold_approve": 0.85,
"threshold_caution": 0.6,
"rule": "confidence>=threshold"
},
"release": {
"required": false,
"required_by_tier": false,
"escalated_by_acceptance": false,
"risk_accepted": false,
"state": "WITHHELD_NO_EVIDENCE",
"code": "QUORUM_EVIDENCE_WITHHELD",
"reason": "the evidence did not clear the threshold for this exposure, so there is nothing to release. Signatures do not substitute for evidence, and this state is deliberately distinct from WITHHELD_PENDING_SIGNATURES: a reader must be able to tell \"the evidence is not there\" from \"the evidence is there and 0 of 2 people have signed\".",
"tier_floor_cents": 1000000000,
"exposure_usd_cents": 64000000,
"required_m": 2,
"declared_n": 3,
"floor_m": 2,
"distinct_signers": 0,
"superseded": 0,
"collapsed": 0,
"release_digest": "sha256:dab60630adae29904fb52f9577e707f91834a0c7d6e315e4382ceebcc01b11d7",
"governance_digest": "sha256:8b0a45a27fcce9c1c243c764e855e67c6fe6dfd7f02a563bd90809b419731905",
"governance_signed": true,
"counted_voices": [],
"signatures": [],
"ledger_seq": null
},
"acceptance": {
"state": "NONE",
"code": "ACCEPTANCE_NONE",
"reason": "no risk acceptance was presented for this decision. This is the ordinary case: a refusal is a refusal unless a named person has priced it.",
"permitted_basis": null,
"presented": 0,
"superseded": 0,
"expired": 0,
"gaps_not_covered": 0,
"coverage_gaps_in_force": [
"release:PLATFORM-CORE-2026.8.0|code_review",
"release:PLATFORM-CORE-2026.8.0|component_provenance"
],
"evidentiary_digest": "sha256:dab60630adae29904fb52f9577e707f91834a0c7d6e315e4382ceebcc01b11d7",
"margin_floor_bp": 100,
"authority_ceiling_cents": {
"SUPERVISOR": 1000000,
"MANAGER": 25000000,
"DIRECTOR": 500000000,
"OFFICER": 5000000000
},
"acceptances": [],
"escalated": false,
"live": false,
"ledger_seq": null
},
"regulatory": {
"spec": "corobate:regulatory:2",
"resolved": true,
"applied": [
{
"instrument_id": "nist-sp-800-218-ssdf",
"version": 1,
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-218 — Secure Software Development Framework v1.1",
"edition": "1.1",
"citation": "PS.3.2, PS.2, PW.7 [VERIFY]",
"source_digest": "sha256:1818181818181818181818181818181818181818181818181818181818181818",
"entered_by": "actor:human:issm",
"entered_at": "2026-08-08T16:00:00.000Z"
},
{
"instrument_id": "nist-sp-800-161r1-cscrm",
"version": 1,
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-161 Rev. 1 — C-SCRM Practices for Systems and Organizations",
"edition": "Rev. 1",
"citation": "SR-3, SR-4, SR-11 [VERIFY]",
"source_digest": "sha256:6161616161616161616161616161616161616161616161616161616161616161",
"entered_by": "actor:human:issm",
"entered_at": "2026-08-08T16:00:00.000Z"
}
],
"skipped": [],
"conflicts": [],
"bindings": [
{
"claim": "code_review",
"requirement": "required",
"value": true,
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-218 — Secure Software Development Framework v1.1",
"instrument_id": "nist-sp-800-218-ssdf",
"version": 1,
"edition": "1.1",
"citation": "PW.7 [VERIFY]",
"source_digest": "sha256:1818181818181818181818181818181818181818181818181818181818181818"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "component_provenance",
"requirement": "min_class",
"value": "SELLER-ASSERTED",
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-161 Rev. 1 — C-SCRM Practices for Systems and Organizations",
"instrument_id": "nist-sp-800-161r1-cscrm",
"version": 1,
"edition": "Rev. 1",
"citation": "SR-4 [VERIFY]",
"source_digest": "sha256:6161616161616161616161616161616161616161616161616161616161616161"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "component_provenance",
"requirement": "required",
"value": true,
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-218 — Secure Software Development Framework v1.1",
"instrument_id": "nist-sp-800-218-ssdf",
"version": 1,
"edition": "1.1",
"citation": "PS.3.2 [VERIFY]",
"source_digest": "sha256:1818181818181818181818181818181818181818181818181818181818181818"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "release_integrity_mechanism",
"requirement": "min_class",
"value": "VERIFIED",
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-218 — Secure Software Development Framework v1.1",
"instrument_id": "nist-sp-800-218-ssdf",
"version": 1,
"edition": "1.1",
"citation": "PS.2 [VERIFY]",
"source_digest": "sha256:1818181818181818181818181818181818181818181818181818181818181818"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "release_integrity_mechanism",
"requirement": "never_waivable",
"value": true,
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-218 — Secure Software Development Framework v1.1",
"instrument_id": "nist-sp-800-218-ssdf",
"version": 1,
"edition": "1.1",
"citation": "PS.2 [VERIFY]",
"source_digest": "sha256:1818181818181818181818181818181818181818181818181818181818181818"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "release_integrity_mechanism",
"requirement": "required",
"value": true,
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-218 — Secure Software Development Framework v1.1",
"instrument_id": "nist-sp-800-218-ssdf",
"version": 1,
"edition": "1.1",
"citation": "PS.2 [VERIFY]",
"source_digest": "sha256:1818181818181818181818181818181818181818181818181818181818181818"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "supplier_assessment",
"requirement": "required",
"value": true,
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-161 Rev. 1 — C-SCRM Practices for Systems and Organizations",
"instrument_id": "nist-sp-800-161r1-cscrm",
"version": 1,
"edition": "Rev. 1",
"citation": "SR-6 [VERIFY]",
"source_digest": "sha256:6161616161616161616161616161616161616161616161616161616161616161"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
}
],
"defaults": [
{
"claim": "code_review",
"requirement": "ai_position",
"value": "ADMIT",
"because": "No instrument in force stated a position on AI-authored evidence for \"code_review\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
},
{
"claim": "component_provenance",
"requirement": "ai_position",
"value": "ADMIT",
"because": "No instrument in force stated a position on AI-authored evidence for \"component_provenance\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
},
{
"claim": "release_integrity_mechanism",
"requirement": "ai_position",
"value": "ADMIT",
"because": "No instrument in force stated a position on AI-authored evidence for \"release_integrity_mechanism\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
},
{
"claim": "supplier_assessment",
"requirement": "ai_position",
"value": "ADMIT",
"because": "No instrument in force stated a position on AI-authored evidence for \"supplier_assessment\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
}
]
},
"reasons": [
"Coverage gap: no admissible memory for required claim(s) release:PLATFORM-CORE-2026.8.0|code_review, release:PLATFORM-CORE-2026.8.0|component_provenance.",
"Confidence 0.00% is bound by \"release:PLATFORM-CORE-2026.8.0|code_review\".",
"2 memories were withheld from the context block: release:PLATFORM-CORE-2026.8.0|code_review (sparse track record: 1 independent observation(s); no failure recorded, so the class ceiling stands); release:PLATFORM-CORE-2026.8.0|component_provenance (sparse track record: 1 independent observation(s); no failure recorded, so the class ceiling stands).",
"Thresholds for $640,000 exposure: approve 85%, caution 60%."
],
"memory": {
"layer": "capture->store->recall->act",
"ledger_head": "sha256:fdadc9eed6746ad514ec9f681a2910b2fa04006a84e45cb24a08e5bdcd9e97b3",
"ledger_entries": 6,
"context_digest": null,
"context_memory_ids": [],
"state_digest": "sha256:b69314201d2e10631d7179b82717dd6079b7dc7408b3ee37281eb56729ce59f2",
"retrieval_method": "idf-lexical",
"corpus_size": 4,
"considered": 4,
"admitted": 2,
"withheld": 2,
"not_considered": 0,
"coverage_gaps": [
"release:PLATFORM-CORE-2026.8.0|code_review",
"release:PLATFORM-CORE-2026.8.0|component_provenance"
],
"exposure": {
"usd": 640000,
"declared_by": "actor:human:issm",
"ledger_seq": 4
},
"salience_policy": {
"half_life_days": 90,
"grace_days": 7,
"access_boost_bp": 500,
"access_boost_cap_bp": 2500,
"relevance_weight_bp": 6000,
"recency_weight_bp": 3000,
"usage_weight_bp": 1000,
"context_cap": 12,
"method": "idf-lexical",
"candidate_list_digest": "sha256:d92593a9b72082ce2d91610f9d21bce314f3b5f4d35c034d0d89f2beefc552d7",
"note": "salience orders retrieval only; it never contributes to reliability"
},
"policy_digest": "sha256:a6b69b7d20f7fb04d522364af1d92992058b04a5835fcec9d1c9f2261c7ef636",
"policy_body": {
"class_ceiling_bp": {
"VERIFIED": 9500,
"MODELED": 8000,
"SELLER-ASSERTED": 5000,
"MISSING": 0
},
"actor_class_ceiling": [
[
"^actor:ai:",
"MODELED"
],
[
"^actor:agent:",
"MODELED"
],
[
"^actor:human:",
"SELLER-ASSERTED"
],
[
"^actor:org:LAB-",
"VERIFIED"
],
[
"^actor:org:CERT-",
"VERIFIED"
],
[
"^actor:org:",
"SELLER-ASSERTED"
],
[
"^actor:sys:registry:",
"VERIFIED"
],
[
"^actor:sys:sensor:",
"VERIFIED"
],
[
"^actor:sys:",
"MODELED"
]
],
"freshness_cap_bp": 4000,
"max_age_days": {
"telemetry": 1,
"price": 7,
"status": 14,
"certificate": 365,
"test_report": 180,
"filing": 90,
"transcript": 120,
"highlight": 365,
"voice_note": 120,
"note": 365,
"preference": 540,
"decision": 1825,
"receipt": 365,
"default": 90
},
"wilson_z_milli": 1960,
"min_track_n": 5,
"exposure_tiers_bp": [
[
1000000000,
9500,
8000
],
[
100000000,
9000,
7000
],
[
1000000,
8500,
6000
],
[
0,
8000,
5000
]
],
"max_context_memories": 12,
"contradiction_resolve_margin": 2,
"salience": {
"half_life_days": 90,
"grace_days": 7,
"access_boost_bp": 500,
"access_boost_cap_bp": 2500,
"relevance_weight_bp": 6000,
"recency_weight_bp": 3000,
"usage_weight_bp": 1000
}
},
"observer_auth": {
"mode": "required",
"registry_version": 3,
"registry_digest": "sha256:460aeaafe345f69542a302e6619dff0712af98de6518838ee4c8585e448c3a7d",
"entries_root": "sha256:5670469f96484a814462814ed74f0f992b5f19e8ad6afced548e4956e4835ba5",
"memberships": [
{
"key_id": "k_17d23885943ae529",
"index": 1,
"entry": {
"actor": "actor:org:LAB-NVLAP-0412",
"class": "VERIFIED",
"kind": "org",
"key_id": "k_17d23885943ae529",
"jwk": {
"kty": "EC",
"crv": "P-256",
"x": "3TTw47-PkYfo3ZaKTq_qtHghnGvninAVj25kyOwONno",
"y": "16PMaR8ofeF5IcZk6ZLml8gDs8uE1s1sBLdciH5e4vg"
},
"valid_from": "2025-01-01T00:00:00.000Z",
"valid_to": "2027-06-01T00:00:00.000Z"
},
"path": [
{
"side": "left",
"sibling": "sha256:500f2ba5949d5256ae0f563530b0b270db41ce99d2d7c4b4b60e4bd558ca353d"
},
{
"side": "right",
"sibling": "sha256:a0b47ea437bf4f1042a1dd50a5a3f411f9a17971812fc6bafccd434eb7d78ccc"
},
{
"side": "right",
"sibling": "sha256:d3c2347eb675e865fc17ef0204cacda7b02e8784a811fdd1c8a015d1865e6dfb"
},
{
"side": "right",
"sibling": "sha256:7071adf5e21a94147d31f42f1028b4867b6562e5b78726259c2515b03b213e52"
}
]
},
{
"key_id": "k_307e4bfd710ec9b3",
"index": 0,
"entry": {
"actor": "actor:org:CERT-3PAO-ATLANTIC",
"class": "VERIFIED",
"kind": "org",
"key_id": "k_307e4bfd710ec9b3",
"jwk": {
"kty": "EC",
"crv": "P-256",
"x": "MGtV26TezLMPjiD3SecQtnje6eLqYyx4qkKzzAkbiY4",
"y": "SMMdLYnn-FpKbb2sJQ8EAZnzvozNm-cGO0VbUUpniPY"
},
"valid_from": "2025-01-01T00:00:00.000Z",
"valid_to": "2027-06-01T00:00:00.000Z"
},
"path": [
{
"side": "right",
"sibling": "sha256:4148869fc259d2c5fc19fe5831065b165a9acf81812e123162035acfdecade1d"
},
{
"side": "right",
"sibling": "sha256:a0b47ea437bf4f1042a1dd50a5a3f411f9a17971812fc6bafccd434eb7d78ccc"
},
{
"side": "right",
"sibling": "sha256:d3c2347eb675e865fc17ef0204cacda7b02e8784a811fdd1c8a015d1865e6dfb"
},
{
"side": "right",
"sibling": "sha256:7071adf5e21a94147d31f42f1028b4867b6562e5b78726259c2515b03b213e52"
}
]
}
],
"memberships_unproven": [],
"revocation": {
"source": "SIGNED_LIST",
"digest": "sha256:12f73b1fbf27d38cf137b86a1ce13bbcd98161123a6aa7d79b107db8189966b9",
"sequence": 5,
"registry_version": 3,
"issued_at": "2026-08-06T00:00:00.000Z",
"next_update_due": "2026-08-13T00:00:00.000Z",
"entry_count": 0,
"body": {
"sequence": 5,
"registry_version": 3,
"issuer": {
"name": "NIST-regulated enterprise demonstration trust root",
"key_id": "k_3793b8e35f8acac1"
},
"issued_at": "2026-08-06T00:00:00.000Z",
"next_update_due": "2026-08-13T00:00:00.000Z",
"entries": [],
"spec": "corobate:revocation-list:1"
}
}
},
"governance": {
"digest": "sha256:8b0a45a27fcce9c1c243c764e855e67c6fe6dfd7f02a563bd90809b419731905",
"signed": true,
"actor_trust": "FLOOR_TO_SELLER_ASSERTED",
"outcome_trial_weight": 1,
"max_reingest_depth": 3,
"release_quorum_m": 2,
"release_quorum_n": 3,
"risk_acceptance_margin_bp": 500,
"risk_acceptance_max_days": 30,
"risk_acceptance_authority_cents": {
"SUPERVISOR": 1000000,
"MANAGER": 25000000,
"DIRECTOR": 500000000,
"OFFICER": 5000000000
},
"template_author_roles": [
"MANAGER",
"DIRECTOR",
"OFFICER"
]
},
"observers_attested": 2,
"outcomes": {
"attestations_counted": 0,
"attestations_recorded": 0,
"records_with_outcomes": 0
},
"lineage": {
"corroborations_counted": 0,
"corroborations_discounted": 0,
"records_with_discounted_corroborations": 0
},
"reingest": {
"records": 0,
"max_depth": 0,
"weakest_class": null,
"chain_weakest_bp": 10000,
"chain": []
},
"template": null
}
}
}Every control here is met except one, and the one is the control the organisation most wants to claim. A model's evaluation of itself is a modelled assertion and the policy table will not read it higher, whatever the reported score.
- Subject
- ai-system:TRIAGE-ASSISTANT-V4
- Question
- May this AI system be deployed to triage citizen-facing casework?
- Exposure
- $1,400,000
- Instruments
- National Institute of Standards and Technology · National Institute of Standards and Technology
- Outcome
- WITHHELD — the action is not permitted; outstanding: model evaluation
- Receipt
- sha256:6cfa106851e42c578947d59d107ffb474e39c813bc52723eb7102a95dc5a5e81
The gate variables this decision ran under — a dial per question, read back off the sealed receipt
control assessmentrequired
incident response plan testrequired
model evaluationrequired
penetration testrequired
security resilience evaluationrequired
vulnerability scanrequired
Every bar above was re-derived from the regulatory bindings inside this receipt’s hashed body, not from the configuration that produced it. A bar in grey is a setting no instrument made — the deploying organisation’s own default, which still binds and is not an absence. A bar position renders an ordinal on a declared ladder: it is a way to draw a control and to compare two settings on the same axis, and it is not a measurement. The value printed beside each bar is the authoritative one.
Whoever must act now
The engineer with the deployment in their hands, the release manager, the person who must publish or hold.
One instruction and the reason in words. No score, no money, no signatures.
Seven or eight fields, and not one of them is a number somebody can argue with. This person is not being asked to re-judge the evidence; somebody already did, and it is on the record.
The scoped copy itself — partial — something outside this role’s remit was removed
{
"spec": "corobate:role-view:2",
"role": "OPERATOR",
"purpose": "Whoever must act on this decision now — release the goods, fund the draw, dispatch the agent, ship the title. Sees one instruction and the reason in plain words, and nothing that could be argued about while somebody waits.",
"is_a_receipt": false,
"warning": "This is a SCOPED COPY of a sealed decision, not the decision record itself. It will not verify as a receipt and must not be presented as one. To confirm it is faithful, recompute its `view` digest under the same canonicalisation that produces receipt_hash and compare it with the entry for this role in the source receipt’s `views` block.",
"derived_from": {
"receipt_hash": "sha256:6cfa106851e42c578947d59d107ffb474e39c813bc52723eb7102a95dc5a5e81",
"entry_hash": "sha256:2955bbd1e87ad0cde1c0780e46dbe791796688fe9d626f467577319c4d1158ca",
"issued_at": "2026-08-08T16:00:00.000Z"
},
"view_digest": "sha256:a55ee71351234dcdcf42d90a2a316a5b4fb4f94f4fddc1d9017af6c4d3360bba",
"withheld": {
"anything_withheld": true,
"note": "Facts outside this role’s remit were removed. That something was removed is stated so a partial record is never mistaken for a complete one. How much, and what, is not stated — a count is an inference about the part you are not entitled to see."
},
"view": {
"spec": "urn:ietf:params:corobate:receipt:1",
"receipt_version": "1.8",
"issued_at": "2026-08-08T16:00:00.000Z",
"decision": {
"id": "ai_TRIAGE_V4_before",
"subject": "ai-system:TRIAGE-ASSISTANT-V4"
},
"memory": {
"state_digest": "sha256:2d93db16d55c8de970115a836b580dcfdc4be9a6747a75d2d04c931322b48f90",
"ledger_head": "sha256:7529436da173e2905b4859118dac726b0cd5c4c379029c2afc524393c0d06822",
"coverage_gaps": [
"ai-system:TRIAGE-ASSISTANT-V4|model_evaluation"
]
},
"verdict": {
"value": "WITHHELD"
},
"release": {
"state": "WITHHELD_NO_EVIDENCE"
}
}
}Provider / assessed party
The cloud service provider, the release team, or the party operating the AI system — whoever is being assessed.
Sees which controls were required of them and by which publication and control identifier. Does not see the authorising official’s exposure figure or how any shortfall was priced.
What is outstanding on your file
- model evaluation — required by National Institute of Standards and Technology, MEASURE-2.3 [VERIFY]
| Claim | Required | Evidence class | Who | Age | Outcome |
|---|---|---|---|---|---|
| vulnerability_scan | yes | VERIFIED | — | 2026-08-04 | admitted |
| incident_response_plan_test | yes | VERIFIED | — | 2026-06-24 | admitted |
| security_resilience_evaluation | yes | VERIFIED | — | 2026-07-09 | admitted |
| penetration_test | yes | VERIFIED | — | 2026-06-09 | admitted |
| control_assessment | yes | VERIFIED | — | 2026-04-30 | admitted |
| model_evaluation | no | SELLER-ASSERTED | — | 2026-07-30 | withheld |
| model_evaluation | yes | MISSING | — | 2026-08-08 | coverage gap |
The clause is here because it turns an argument into an errand. What is not here: what the bank had at stake, and whether anyone priced the shortfall.
The scoped copy itself — partial — something outside this role’s remit was removed
{
"spec": "corobate:role-view:2",
"role": "SUPPLIER",
"purpose": "The party whose evidence was judged. Sees every claim the decision required, which fell short, and the clause that required it — and nothing about what the buyer had at stake or how the buyer priced any shortfall. NOTE, because an earlier draft of this sentence was untrue: this projection carries the WHOLE inputs array, so where several parties supplied evidence for one decision, each of them sees all of it. Per-party scoping cannot be expressed by a commitment scheme with one digest per role, and claiming it anyway would be the kind of promise this file exists to stop making.",
"is_a_receipt": false,
"warning": "This is a SCOPED COPY of a sealed decision, not the decision record itself. It will not verify as a receipt and must not be presented as one. To confirm it is faithful, recompute its `view` digest under the same canonicalisation that produces receipt_hash and compare it with the entry for this role in the source receipt’s `views` block.",
"derived_from": {
"receipt_hash": "sha256:6cfa106851e42c578947d59d107ffb474e39c813bc52723eb7102a95dc5a5e81",
"entry_hash": "sha256:2955bbd1e87ad0cde1c0780e46dbe791796688fe9d626f467577319c4d1158ca",
"issued_at": "2026-08-08T16:00:00.000Z"
},
"view_digest": "sha256:52c328d680bca2ee092e2ee7075cfc8db037a9e77f8cbec6dcf6e12dcc12dee6",
"withheld": {
"anything_withheld": true,
"note": "Facts outside this role’s remit were removed. That something was removed is stated so a partial record is never mistaken for a complete one. How much, and what, is not stated — a count is an inference about the part you are not entitled to see."
},
"view": {
"spec": "urn:ietf:params:corobate:receipt:1",
"receipt_version": "1.8",
"issued_at": "2026-08-08T16:00:00.000Z",
"decision": {
"id": "ai_TRIAGE_V4_before",
"subject": "ai-system:TRIAGE-ASSISTANT-V4",
"question": "May this AI system be deployed to triage citizen-facing casework?"
},
"memory": {
"state_digest": "sha256:2d93db16d55c8de970115a836b580dcfdc4be9a6747a75d2d04c931322b48f90",
"ledger_head": "sha256:7529436da173e2905b4859118dac726b0cd5c4c379029c2afc524393c0d06822",
"coverage_gaps": [
"ai-system:TRIAGE-ASSISTANT-V4|model_evaluation"
]
},
"verdict": {
"value": "WITHHELD"
},
"inputs": [
{
"key": "ai-system:TRIAGE-ASSISTANT-V4::vulnerability_scan",
"provenance": "VERIFIED",
"observed_at": "2026-08-04T16:00:00.000Z",
"memory_status": "admitted",
"critical": true
},
{
"key": "ai-system:TRIAGE-ASSISTANT-V4::incident_response_plan_test",
"provenance": "VERIFIED",
"observed_at": "2026-06-24T16:00:00.000Z",
"memory_status": "admitted",
"critical": true
},
{
"key": "ai-system:TRIAGE-ASSISTANT-V4::security_resilience_evaluation",
"provenance": "VERIFIED",
"observed_at": "2026-07-09T16:00:00.000Z",
"memory_status": "admitted",
"critical": true
},
{
"key": "ai-system:TRIAGE-ASSISTANT-V4::penetration_test",
"provenance": "VERIFIED",
"observed_at": "2026-06-09T16:00:00.000Z",
"memory_status": "admitted",
"critical": true
},
{
"key": "ai-system:TRIAGE-ASSISTANT-V4::control_assessment",
"provenance": "VERIFIED",
"observed_at": "2026-04-30T16:00:00.000Z",
"memory_status": "admitted",
"critical": true
},
{
"key": "ai-system:TRIAGE-ASSISTANT-V4::model_evaluation",
"provenance": "SELLER-ASSERTED",
"observed_at": "2026-07-30T16:00:00.000Z",
"memory_status": "withheld",
"critical": false
},
{
"key": "ai-system:TRIAGE-ASSISTANT-V4::model_evaluation",
"provenance": "MISSING",
"observed_at": "2026-08-08T16:00:00.000Z",
"memory_status": "coverage_gap",
"critical": true
}
],
"regulatory": {
"bindings": [
{
"claim": "control_assessment",
"requirement": "max_age_days",
"value": 365,
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
"instrument_id": "nist-sp-800-53r5-moderate",
"version": 5,
"edition": "Rev. 5",
"citation": "CA-2 [VERIFY]",
"source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "control_assessment",
"requirement": "min_class",
"value": "VERIFIED",
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
"instrument_id": "nist-sp-800-53r5-moderate",
"version": 5,
"edition": "Rev. 5",
"citation": "CA-2(1) independent assessors [VERIFY]",
"source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "control_assessment",
"requirement": "required",
"value": true,
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
"instrument_id": "nist-sp-800-53r5-moderate",
"version": 5,
"edition": "Rev. 5",
"citation": "CA-2 [VERIFY]",
"source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "incident_response_plan_test",
"requirement": "required",
"value": true,
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "AI Risk Management Framework 1.0",
"instrument_id": "nist-ai-rmf-1-0",
"version": 1,
"edition": "1.0",
"citation": "MANAGE-4.1 [VERIFY]",
"source_digest": "sha256:a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "model_evaluation",
"requirement": "max_age_days",
"value": 180,
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "AI Risk Management Framework 1.0",
"instrument_id": "nist-ai-rmf-1-0",
"version": 1,
"edition": "1.0",
"citation": "MEASURE-2.3 [VERIFY]",
"source_digest": "sha256:a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "model_evaluation",
"requirement": "min_class",
"value": "VERIFIED",
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "AI Risk Management Framework 1.0",
"instrument_id": "nist-ai-rmf-1-0",
"version": 1,
"edition": "1.0",
"citation": "MEASURE-2.3 independent evaluation [VERIFY]",
"source_digest": "sha256:a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "model_evaluation",
"requirement": "required",
"value": true,
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "AI Risk Management Framework 1.0",
"instrument_id": "nist-ai-rmf-1-0",
"version": 1,
"edition": "1.0",
"citation": "MEASURE-2.3 [VERIFY]",
"source_digest": "sha256:a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "penetration_test",
"requirement": "min_class",
"value": "VERIFIED",
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
"instrument_id": "nist-sp-800-53r5-moderate",
"version": 5,
"edition": "Rev. 5",
"citation": "CA-8(1) independent penetration agent [VERIFY]",
"source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "penetration_test",
"requirement": "required",
"value": true,
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
"instrument_id": "nist-sp-800-53r5-moderate",
"version": 5,
"edition": "Rev. 5",
"citation": "CA-8 [VERIFY]",
"source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "security_resilience_evaluation",
"requirement": "required",
"value": true,
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "AI Risk Management Framework 1.0",
"instrument_id": "nist-ai-rmf-1-0",
"version": 1,
"edition": "1.0",
"citation": "MEASURE-2.7 [VERIFY]",
"source_digest": "sha256:a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "vulnerability_scan",
"requirement": "max_age_days",
"value": 30,
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
"instrument_id": "nist-sp-800-53r5-moderate",
"version": 5,
"edition": "Rev. 5",
"citation": "RA-5(a) [VERIFY]",
"source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "vulnerability_scan",
"requirement": "required",
"value": true,
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
"instrument_id": "nist-sp-800-53r5-moderate",
"version": 5,
"edition": "Rev. 5",
"citation": "RA-5 [VERIFY]",
"source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
}
],
"applied": [
{
"instrument_id": "nist-ai-rmf-1-0",
"version": 1,
"authority": "National Institute of Standards and Technology",
"instrument": "AI Risk Management Framework 1.0",
"edition": "1.0",
"citation": "MEASURE-2.3, MEASURE-2.7, MANAGE-2.2 [VERIFY]",
"source_digest": "sha256:a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1",
"entered_by": "actor:human:issm",
"entered_at": "2026-08-08T16:00:00.000Z"
},
{
"instrument_id": "nist-sp-800-53r5-moderate",
"version": 5,
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
"edition": "Rev. 5",
"citation": "CA-2, CA-8, RA-5, SR-6 [VERIFY]",
"source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353",
"entered_by": "actor:human:issm",
"entered_at": "2026-08-08T16:00:00.000Z"
}
],
"defaults": [
{
"claim": "control_assessment",
"requirement": "ai_position",
"value": "ADMIT",
"because": "No instrument in force stated a position on AI-authored evidence for \"control_assessment\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
},
{
"claim": "incident_response_plan_test",
"requirement": "ai_position",
"value": "ADMIT",
"because": "No instrument in force stated a position on AI-authored evidence for \"incident_response_plan_test\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
},
{
"claim": "model_evaluation",
"requirement": "ai_position",
"value": "ADMIT",
"because": "No instrument in force stated a position on AI-authored evidence for \"model_evaluation\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
},
{
"claim": "penetration_test",
"requirement": "ai_position",
"value": "ADMIT",
"because": "No instrument in force stated a position on AI-authored evidence for \"penetration_test\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
},
{
"claim": "security_resilience_evaluation",
"requirement": "ai_position",
"value": "ADMIT",
"because": "No instrument in force stated a position on AI-authored evidence for \"security_resilience_evaluation\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
},
{
"claim": "vulnerability_scan",
"requirement": "ai_position",
"value": "ADMIT",
"because": "No instrument in force stated a position on AI-authored evidence for \"vulnerability_scan\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
}
]
}
}
}Assessor / authorising official
A third-party assessment organisation, an agency assessor, or an inspector general reviewing the package. Same position as a customs officer: a public mandate over the record.
The control record in full — each publication by control identifier, edition and document digest, and every required claim with who supplied it and when. No exposure figure, no risk pricing, no confidence score.
What each authority bound
| Claim | Requirement | Level | Bound by |
|---|---|---|---|
| control_assessment | max age days | 365 | National Institute of Standards and Technology CA-2 [VERIFY] · SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline) |
| control_assessment | min class | VERIFIED | National Institute of Standards and Technology CA-2(1) independent assessors [VERIFY] · SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline) |
| control_assessment | required | true | National Institute of Standards and Technology CA-2 [VERIFY] · SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline) |
| incident_response_plan_test | required | true | National Institute of Standards and Technology MANAGE-4.1 [VERIFY] · AI Risk Management Framework 1.0 |
| model_evaluation | max age days | 180 | National Institute of Standards and Technology MEASURE-2.3 [VERIFY] · AI Risk Management Framework 1.0 |
| model_evaluation | min class | VERIFIED | National Institute of Standards and Technology MEASURE-2.3 independent evaluation [VERIFY] · AI Risk Management Framework 1.0 |
| model_evaluation | required | true | National Institute of Standards and Technology MEASURE-2.3 [VERIFY] · AI Risk Management Framework 1.0 |
| penetration_test | min class | VERIFIED | National Institute of Standards and Technology CA-8(1) independent penetration agent [VERIFY] · SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline) |
| penetration_test | required | true | National Institute of Standards and Technology CA-8 [VERIFY] · SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline) |
| security_resilience_evaluation | required | true | National Institute of Standards and Technology MEASURE-2.7 [VERIFY] · AI Risk Management Framework 1.0 |
| vulnerability_scan | max age days | 30 | National Institute of Standards and Technology RA-5(a) [VERIFY] · SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline) |
| vulnerability_scan | required | true | National Institute of Standards and Technology RA-5 [VERIFY] · SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline) |
Every required claim, and what was actually held
| Claim | Required | Evidence class | Who | Age | Outcome |
|---|---|---|---|---|---|
| vulnerability_scan | yes | VERIFIED | actor:sys:registry:nvd-cve | 2026-08-04 | admitted |
| incident_response_plan_test | yes | VERIFIED | actor:org:CERT-3PAO-ATLANTIC | 2026-06-24 | admitted |
| security_resilience_evaluation | yes | VERIFIED | actor:org:LAB-NVLAP-0412 | 2026-07-09 | admitted |
| penetration_test | yes | VERIFIED | actor:org:LAB-NVLAP-0412 | 2026-06-09 | admitted |
| control_assessment | yes | VERIFIED | actor:org:CERT-3PAO-ATLANTIC | 2026-04-30 | admitted |
| model_evaluation | no | SELLER-ASSERTED | actor:ai:triage-assistant-v4 | 2026-07-30 | withheld |
| model_evaluation | yes | MISSING | — | 2026-08-08 | coverage gap |
The scoped copy itself — partial — something outside this role’s remit was removed
{
"spec": "corobate:role-view:2",
"role": "REGULATOR",
"purpose": "An official holding a public mandate over this record — a customs officer, a bank examiner, a market conduct supervisor. Sees the regulatory record in full: their own instrument named, every required claim and whether it was met, by whom, how old. No commercial figure of any kind.",
"is_a_receipt": false,
"warning": "This is a SCOPED COPY of a sealed decision, not the decision record itself. It will not verify as a receipt and must not be presented as one. To confirm it is faithful, recompute its `view` digest under the same canonicalisation that produces receipt_hash and compare it with the entry for this role in the source receipt’s `views` block.",
"derived_from": {
"receipt_hash": "sha256:6cfa106851e42c578947d59d107ffb474e39c813bc52723eb7102a95dc5a5e81",
"entry_hash": "sha256:2955bbd1e87ad0cde1c0780e46dbe791796688fe9d626f467577319c4d1158ca",
"issued_at": "2026-08-08T16:00:00.000Z"
},
"view_digest": "sha256:d30bc8c891dbcff157241a0529b9c212ecdf2739b6af22a057b1aab77f437d40",
"withheld": {
"anything_withheld": true,
"note": "Facts outside this role’s remit were removed. That something was removed is stated so a partial record is never mistaken for a complete one. How much, and what, is not stated — a count is an inference about the part you are not entitled to see."
},
"view": {
"spec": "urn:ietf:params:corobate:receipt:1",
"receipt_version": "1.8",
"issued_at": "2026-08-08T16:00:00.000Z",
"decision": {
"id": "ai_TRIAGE_V4_before",
"subject": "ai-system:TRIAGE-ASSISTANT-V4",
"question": "May this AI system be deployed to triage citizen-facing casework?"
},
"memory": {
"state_digest": "sha256:2d93db16d55c8de970115a836b580dcfdc4be9a6747a75d2d04c931322b48f90",
"ledger_head": "sha256:7529436da173e2905b4859118dac726b0cd5c4c379029c2afc524393c0d06822",
"coverage_gaps": [
"ai-system:TRIAGE-ASSISTANT-V4|model_evaluation"
]
},
"data_horizon": "2026-08-08T16:00:00.000Z",
"verdict": {
"value": "WITHHELD"
},
"regulatory": {
"spec": "corobate:regulatory:2",
"resolved": true,
"applied": [
{
"instrument_id": "nist-ai-rmf-1-0",
"version": 1,
"authority": "National Institute of Standards and Technology",
"instrument": "AI Risk Management Framework 1.0",
"edition": "1.0",
"citation": "MEASURE-2.3, MEASURE-2.7, MANAGE-2.2 [VERIFY]",
"source_digest": "sha256:a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1",
"entered_by": "actor:human:issm",
"entered_at": "2026-08-08T16:00:00.000Z"
},
{
"instrument_id": "nist-sp-800-53r5-moderate",
"version": 5,
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
"edition": "Rev. 5",
"citation": "CA-2, CA-8, RA-5, SR-6 [VERIFY]",
"source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353",
"entered_by": "actor:human:issm",
"entered_at": "2026-08-08T16:00:00.000Z"
}
],
"skipped": [],
"conflicts": [],
"bindings": [
{
"claim": "control_assessment",
"requirement": "max_age_days",
"value": 365,
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
"instrument_id": "nist-sp-800-53r5-moderate",
"version": 5,
"edition": "Rev. 5",
"citation": "CA-2 [VERIFY]",
"source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "control_assessment",
"requirement": "min_class",
"value": "VERIFIED",
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
"instrument_id": "nist-sp-800-53r5-moderate",
"version": 5,
"edition": "Rev. 5",
"citation": "CA-2(1) independent assessors [VERIFY]",
"source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "control_assessment",
"requirement": "required",
"value": true,
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
"instrument_id": "nist-sp-800-53r5-moderate",
"version": 5,
"edition": "Rev. 5",
"citation": "CA-2 [VERIFY]",
"source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "incident_response_plan_test",
"requirement": "required",
"value": true,
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "AI Risk Management Framework 1.0",
"instrument_id": "nist-ai-rmf-1-0",
"version": 1,
"edition": "1.0",
"citation": "MANAGE-4.1 [VERIFY]",
"source_digest": "sha256:a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "model_evaluation",
"requirement": "max_age_days",
"value": 180,
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "AI Risk Management Framework 1.0",
"instrument_id": "nist-ai-rmf-1-0",
"version": 1,
"edition": "1.0",
"citation": "MEASURE-2.3 [VERIFY]",
"source_digest": "sha256:a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "model_evaluation",
"requirement": "min_class",
"value": "VERIFIED",
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "AI Risk Management Framework 1.0",
"instrument_id": "nist-ai-rmf-1-0",
"version": 1,
"edition": "1.0",
"citation": "MEASURE-2.3 independent evaluation [VERIFY]",
"source_digest": "sha256:a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "model_evaluation",
"requirement": "required",
"value": true,
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "AI Risk Management Framework 1.0",
"instrument_id": "nist-ai-rmf-1-0",
"version": 1,
"edition": "1.0",
"citation": "MEASURE-2.3 [VERIFY]",
"source_digest": "sha256:a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "penetration_test",
"requirement": "min_class",
"value": "VERIFIED",
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
"instrument_id": "nist-sp-800-53r5-moderate",
"version": 5,
"edition": "Rev. 5",
"citation": "CA-8(1) independent penetration agent [VERIFY]",
"source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "penetration_test",
"requirement": "required",
"value": true,
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
"instrument_id": "nist-sp-800-53r5-moderate",
"version": 5,
"edition": "Rev. 5",
"citation": "CA-8 [VERIFY]",
"source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "security_resilience_evaluation",
"requirement": "required",
"value": true,
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "AI Risk Management Framework 1.0",
"instrument_id": "nist-ai-rmf-1-0",
"version": 1,
"edition": "1.0",
"citation": "MEASURE-2.7 [VERIFY]",
"source_digest": "sha256:a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "vulnerability_scan",
"requirement": "max_age_days",
"value": 30,
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
"instrument_id": "nist-sp-800-53r5-moderate",
"version": 5,
"edition": "Rev. 5",
"citation": "RA-5(a) [VERIFY]",
"source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "vulnerability_scan",
"requirement": "required",
"value": true,
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
"instrument_id": "nist-sp-800-53r5-moderate",
"version": 5,
"edition": "Rev. 5",
"citation": "RA-5 [VERIFY]",
"source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
}
],
"defaults": [
{
"claim": "control_assessment",
"requirement": "ai_position",
"value": "ADMIT",
"because": "No instrument in force stated a position on AI-authored evidence for \"control_assessment\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
},
{
"claim": "incident_response_plan_test",
"requirement": "ai_position",
"value": "ADMIT",
"because": "No instrument in force stated a position on AI-authored evidence for \"incident_response_plan_test\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
},
{
"claim": "model_evaluation",
"requirement": "ai_position",
"value": "ADMIT",
"because": "No instrument in force stated a position on AI-authored evidence for \"model_evaluation\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
},
{
"claim": "penetration_test",
"requirement": "ai_position",
"value": "ADMIT",
"because": "No instrument in force stated a position on AI-authored evidence for \"penetration_test\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
},
{
"claim": "security_resilience_evaluation",
"requirement": "ai_position",
"value": "ADMIT",
"because": "No instrument in force stated a position on AI-authored evidence for \"security_resilience_evaluation\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
},
{
"claim": "vulnerability_scan",
"requirement": "ai_position",
"value": "ADMIT",
"because": "No instrument in force stated a position on AI-authored evidence for \"vulnerability_scan\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
}
]
},
"inputs": [
{
"key": "ai-system:TRIAGE-ASSISTANT-V4::vulnerability_scan",
"provenance": "VERIFIED",
"source": "nvd-cve:vulnerability_scan",
"observed_at": "2026-08-04T16:00:00.000Z",
"critical": true,
"memory_status": "admitted",
"memory_actor": "actor:sys:registry:nvd-cve"
},
{
"key": "ai-system:TRIAGE-ASSISTANT-V4::incident_response_plan_test",
"provenance": "VERIFIED",
"source": "CERT-3PAO-ATLANTIC:incident_response_plan_test",
"observed_at": "2026-06-24T16:00:00.000Z",
"critical": true,
"memory_status": "admitted",
"memory_actor": "actor:org:CERT-3PAO-ATLANTIC"
},
{
"key": "ai-system:TRIAGE-ASSISTANT-V4::security_resilience_evaluation",
"provenance": "VERIFIED",
"source": "LAB-NVLAP-0412:security_resilience_evaluation",
"observed_at": "2026-07-09T16:00:00.000Z",
"critical": true,
"memory_status": "admitted",
"memory_actor": "actor:org:LAB-NVLAP-0412"
},
{
"key": "ai-system:TRIAGE-ASSISTANT-V4::penetration_test",
"provenance": "VERIFIED",
"source": "LAB-NVLAP-0412:penetration_test",
"observed_at": "2026-06-09T16:00:00.000Z",
"critical": true,
"memory_status": "admitted",
"memory_actor": "actor:org:LAB-NVLAP-0412"
},
{
"key": "ai-system:TRIAGE-ASSISTANT-V4::control_assessment",
"provenance": "VERIFIED",
"source": "CERT-3PAO-ATLANTIC:control_assessment",
"observed_at": "2026-04-30T16:00:00.000Z",
"critical": true,
"memory_status": "admitted",
"memory_actor": "actor:org:CERT-3PAO-ATLANTIC"
},
{
"key": "ai-system:TRIAGE-ASSISTANT-V4::model_evaluation",
"provenance": "SELLER-ASSERTED",
"source": "triage-assistant-v4:model_evaluation",
"observed_at": "2026-07-30T16:00:00.000Z",
"critical": false,
"memory_status": "withheld",
"memory_actor": "actor:ai:triage-assistant-v4"
},
{
"key": "ai-system:TRIAGE-ASSISTANT-V4::model_evaluation",
"provenance": "MISSING",
"source": null,
"observed_at": "2026-08-08T16:00:00.000Z",
"critical": true,
"memory_status": "coverage_gap"
}
],
"crypto_suite": {
"spec": "corobate:suite:1",
"id": "CB-1-ES256-SHA256",
"receipt_digest": "sha256",
"chain_digest": "sha256",
"content_digest": "sha256",
"envelope_signature": "ES256",
"signature_curve": "P-256",
"canonicalisation": "attest-canon/2",
"quantum_resistant": false
}
}
}ISSM / control owner
The information system security manager and the control owners who hold the package.
The fullest internal view: every input, its class, its age, its score, the exposure, and every publication in force.
Every input the gate saw
| Claim | Required | Evidence class | Who | Age | Score | Outcome |
|---|---|---|---|---|---|---|
| vulnerability_scan | yes | VERIFIED | actor:sys:registry:nvd-cve | 4d | 95% | admitted |
| incident_response_plan_test | yes | VERIFIED | actor:org:CERT-3PAO-ATLANTIC | 45d | 95% | admitted |
| security_resilience_evaluation | yes | VERIFIED | actor:org:LAB-NVLAP-0412 | 30d | 95% | admitted |
| penetration_test | yes | VERIFIED | actor:org:LAB-NVLAP-0412 | 60d | 95% | admitted |
| control_assessment | yes | VERIFIED | actor:org:CERT-3PAO-ATLANTIC | 100d | 95% | admitted |
| model_evaluation | no | SELLER-ASSERTED | actor:ai:triage-assistant-v4 | 9d | 50% | withheld |
| model_evaluation | yes | MISSING | — | 2026-08-08 | 0% | coverage gap |
Instruments in force
Why
- Coverage gap: no admissible memory for required claim(s) ai-system:TRIAGE-ASSISTANT-V4|model_evaluation.
- Confidence 0.00% is bound by "ai-system:TRIAGE-ASSISTANT-V4|model_evaluation".
- 1 memory was withheld from the context block: ai-system:TRIAGE-ASSISTANT-V4|model_evaluation (below class floor: rule requires at least VERIFIED, held SELLER-ASSERTED — inadmissible at any exposure).
- Thresholds for $1,400,000 exposure: approve 90%, caution 70%.
The scoped copy itself — partial — something outside this role’s remit was removed
{
"spec": "corobate:role-view:2",
"role": "COMPLIANCE",
"purpose": "The operator’s own compliance function. The fullest internal view: every gap, every instrument in force, the waivability of each requirement and who accepted what.",
"is_a_receipt": false,
"warning": "This is a SCOPED COPY of a sealed decision, not the decision record itself. It will not verify as a receipt and must not be presented as one. To confirm it is faithful, recompute its `view` digest under the same canonicalisation that produces receipt_hash and compare it with the entry for this role in the source receipt’s `views` block.",
"derived_from": {
"receipt_hash": "sha256:6cfa106851e42c578947d59d107ffb474e39c813bc52723eb7102a95dc5a5e81",
"entry_hash": "sha256:2955bbd1e87ad0cde1c0780e46dbe791796688fe9d626f467577319c4d1158ca",
"issued_at": "2026-08-08T16:00:00.000Z"
},
"view_digest": "sha256:4572cb29ae4eb49c43beda0b02708048b6b23c4a8fbbddf1f8f21978982a9d55",
"withheld": {
"anything_withheld": true,
"note": "Facts outside this role’s remit were removed. That something was removed is stated so a partial record is never mistaken for a complete one. How much, and what, is not stated — a count is an inference about the part you are not entitled to see."
},
"view": {
"spec": "urn:ietf:params:corobate:receipt:1",
"receipt_version": "1.8",
"issued_at": "2026-08-08T16:00:00.000Z",
"decision": {
"id": "ai_TRIAGE_V4_before",
"domain": "supply-chain",
"subject": "ai-system:TRIAGE-ASSISTANT-V4",
"question": "May this AI system be deployed to triage citizen-facing casework?"
},
"memory": {
"state_digest": "sha256:2d93db16d55c8de970115a836b580dcfdc4be9a6747a75d2d04c931322b48f90",
"ledger_head": "sha256:7529436da173e2905b4859118dac726b0cd5c4c379029c2afc524393c0d06822",
"coverage_gaps": [
"ai-system:TRIAGE-ASSISTANT-V4|model_evaluation"
],
"exposure": {
"usd": 1400000,
"declared_by": "actor:human:ao-authorizing-official",
"ledger_seq": 6
},
"policy_digest": "sha256:a6b69b7d20f7fb04d522364af1d92992058b04a5835fcec9d1c9f2261c7ef636"
},
"data_horizon": "2026-08-08T16:00:00.000Z",
"verdict": {
"value": "WITHHELD",
"threshold_approve": 0.9,
"threshold_caution": 0.7,
"rule": "confidence>=threshold"
},
"confidence": {
"value": 0,
"method": "min-over-critical-inputs",
"bound_by": "ai-system:TRIAGE-ASSISTANT-V4::model_evaluation"
},
"release": {
"required": false,
"required_by_tier": false,
"escalated_by_acceptance": false,
"risk_accepted": false,
"state": "WITHHELD_NO_EVIDENCE",
"code": "QUORUM_EVIDENCE_WITHHELD",
"reason": "the evidence did not clear the threshold for this exposure, so there is nothing to release. Signatures do not substitute for evidence, and this state is deliberately distinct from WITHHELD_PENDING_SIGNATURES: a reader must be able to tell \"the evidence is not there\" from \"the evidence is there and 0 of 2 people have signed\".",
"tier_floor_cents": 1000000000,
"exposure_usd_cents": 140000000,
"required_m": 2,
"declared_n": 3,
"floor_m": 2,
"distinct_signers": 0,
"superseded": 0,
"collapsed": 0,
"release_digest": "sha256:49e46dc99310dfb4f669746425dfb108ff1f2d3e71c03f35b99c9f14211809df",
"governance_digest": "sha256:8b0a45a27fcce9c1c243c764e855e67c6fe6dfd7f02a563bd90809b419731905",
"governance_signed": true,
"counted_voices": [],
"signatures": [],
"ledger_seq": null
},
"acceptance": {
"state": "NONE",
"code": "ACCEPTANCE_NONE",
"reason": "no risk acceptance was presented for this decision. This is the ordinary case: a refusal is a refusal unless a named person has priced it.",
"permitted_basis": null,
"presented": 0,
"superseded": 0,
"expired": 0,
"gaps_not_covered": 0,
"coverage_gaps_in_force": [
"ai-system:TRIAGE-ASSISTANT-V4|model_evaluation"
],
"evidentiary_digest": "sha256:49e46dc99310dfb4f669746425dfb108ff1f2d3e71c03f35b99c9f14211809df",
"margin_floor_bp": 100,
"authority_ceiling_cents": {
"SUPERVISOR": 1000000,
"MANAGER": 25000000,
"DIRECTOR": 500000000,
"OFFICER": 5000000000
},
"acceptances": [],
"escalated": false,
"live": false,
"ledger_seq": null
},
"regulatory": {
"spec": "corobate:regulatory:2",
"resolved": true,
"applied": [
{
"instrument_id": "nist-ai-rmf-1-0",
"version": 1,
"authority": "National Institute of Standards and Technology",
"instrument": "AI Risk Management Framework 1.0",
"edition": "1.0",
"citation": "MEASURE-2.3, MEASURE-2.7, MANAGE-2.2 [VERIFY]",
"source_digest": "sha256:a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1",
"entered_by": "actor:human:issm",
"entered_at": "2026-08-08T16:00:00.000Z"
},
{
"instrument_id": "nist-sp-800-53r5-moderate",
"version": 5,
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
"edition": "Rev. 5",
"citation": "CA-2, CA-8, RA-5, SR-6 [VERIFY]",
"source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353",
"entered_by": "actor:human:issm",
"entered_at": "2026-08-08T16:00:00.000Z"
}
],
"skipped": [],
"conflicts": [],
"bindings": [
{
"claim": "control_assessment",
"requirement": "max_age_days",
"value": 365,
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
"instrument_id": "nist-sp-800-53r5-moderate",
"version": 5,
"edition": "Rev. 5",
"citation": "CA-2 [VERIFY]",
"source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "control_assessment",
"requirement": "min_class",
"value": "VERIFIED",
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
"instrument_id": "nist-sp-800-53r5-moderate",
"version": 5,
"edition": "Rev. 5",
"citation": "CA-2(1) independent assessors [VERIFY]",
"source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "control_assessment",
"requirement": "required",
"value": true,
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
"instrument_id": "nist-sp-800-53r5-moderate",
"version": 5,
"edition": "Rev. 5",
"citation": "CA-2 [VERIFY]",
"source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "incident_response_plan_test",
"requirement": "required",
"value": true,
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "AI Risk Management Framework 1.0",
"instrument_id": "nist-ai-rmf-1-0",
"version": 1,
"edition": "1.0",
"citation": "MANAGE-4.1 [VERIFY]",
"source_digest": "sha256:a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "model_evaluation",
"requirement": "max_age_days",
"value": 180,
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "AI Risk Management Framework 1.0",
"instrument_id": "nist-ai-rmf-1-0",
"version": 1,
"edition": "1.0",
"citation": "MEASURE-2.3 [VERIFY]",
"source_digest": "sha256:a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "model_evaluation",
"requirement": "min_class",
"value": "VERIFIED",
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "AI Risk Management Framework 1.0",
"instrument_id": "nist-ai-rmf-1-0",
"version": 1,
"edition": "1.0",
"citation": "MEASURE-2.3 independent evaluation [VERIFY]",
"source_digest": "sha256:a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "model_evaluation",
"requirement": "required",
"value": true,
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "AI Risk Management Framework 1.0",
"instrument_id": "nist-ai-rmf-1-0",
"version": 1,
"edition": "1.0",
"citation": "MEASURE-2.3 [VERIFY]",
"source_digest": "sha256:a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "penetration_test",
"requirement": "min_class",
"value": "VERIFIED",
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
"instrument_id": "nist-sp-800-53r5-moderate",
"version": 5,
"edition": "Rev. 5",
"citation": "CA-8(1) independent penetration agent [VERIFY]",
"source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "penetration_test",
"requirement": "required",
"value": true,
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
"instrument_id": "nist-sp-800-53r5-moderate",
"version": 5,
"edition": "Rev. 5",
"citation": "CA-8 [VERIFY]",
"source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "security_resilience_evaluation",
"requirement": "required",
"value": true,
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "AI Risk Management Framework 1.0",
"instrument_id": "nist-ai-rmf-1-0",
"version": 1,
"edition": "1.0",
"citation": "MEASURE-2.7 [VERIFY]",
"source_digest": "sha256:a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "vulnerability_scan",
"requirement": "max_age_days",
"value": 30,
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
"instrument_id": "nist-sp-800-53r5-moderate",
"version": 5,
"edition": "Rev. 5",
"citation": "RA-5(a) [VERIFY]",
"source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "vulnerability_scan",
"requirement": "required",
"value": true,
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
"instrument_id": "nist-sp-800-53r5-moderate",
"version": 5,
"edition": "Rev. 5",
"citation": "RA-5 [VERIFY]",
"source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
}
],
"defaults": [
{
"claim": "control_assessment",
"requirement": "ai_position",
"value": "ADMIT",
"because": "No instrument in force stated a position on AI-authored evidence for \"control_assessment\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
},
{
"claim": "incident_response_plan_test",
"requirement": "ai_position",
"value": "ADMIT",
"because": "No instrument in force stated a position on AI-authored evidence for \"incident_response_plan_test\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
},
{
"claim": "model_evaluation",
"requirement": "ai_position",
"value": "ADMIT",
"because": "No instrument in force stated a position on AI-authored evidence for \"model_evaluation\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
},
{
"claim": "penetration_test",
"requirement": "ai_position",
"value": "ADMIT",
"because": "No instrument in force stated a position on AI-authored evidence for \"penetration_test\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
},
{
"claim": "security_resilience_evaluation",
"requirement": "ai_position",
"value": "ADMIT",
"because": "No instrument in force stated a position on AI-authored evidence for \"security_resilience_evaluation\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
},
{
"claim": "vulnerability_scan",
"requirement": "ai_position",
"value": "ADMIT",
"because": "No instrument in force stated a position on AI-authored evidence for \"vulnerability_scan\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
}
]
},
"reasons": [
"Coverage gap: no admissible memory for required claim(s) ai-system:TRIAGE-ASSISTANT-V4|model_evaluation.",
"Confidence 0.00% is bound by \"ai-system:TRIAGE-ASSISTANT-V4|model_evaluation\".",
"1 memory was withheld from the context block: ai-system:TRIAGE-ASSISTANT-V4|model_evaluation (below class floor: rule requires at least VERIFIED, held SELLER-ASSERTED — inadmissible at any exposure).",
"Thresholds for $1,400,000 exposure: approve 90%, caution 70%."
],
"inputs": [
{
"key": "ai-system:TRIAGE-ASSISTANT-V4::vulnerability_scan",
"value": "clean-at-scan",
"provenance": "VERIFIED",
"source": "nvd-cve:vulnerability_scan",
"observed_at": "2026-08-04T16:00:00.000Z",
"reliability": 0.95,
"critical": true,
"memory_status": "admitted",
"memory_kind": "status",
"memory_actor": "actor:sys:registry:nvd-cve",
"memory_age_days": 4
},
{
"key": "ai-system:TRIAGE-ASSISTANT-V4::incident_response_plan_test",
"value": "observed",
"provenance": "VERIFIED",
"source": "CERT-3PAO-ATLANTIC:incident_response_plan_test",
"observed_at": "2026-06-24T16:00:00.000Z",
"reliability": 0.95,
"critical": true,
"memory_status": "admitted",
"memory_kind": "certificate",
"memory_actor": "actor:org:CERT-3PAO-ATLANTIC",
"memory_age_days": 45
},
{
"key": "ai-system:TRIAGE-ASSISTANT-V4::security_resilience_evaluation",
"value": "assessed",
"provenance": "VERIFIED",
"source": "LAB-NVLAP-0412:security_resilience_evaluation",
"observed_at": "2026-07-09T16:00:00.000Z",
"reliability": 0.95,
"critical": true,
"memory_status": "admitted",
"memory_kind": "test_report",
"memory_actor": "actor:org:LAB-NVLAP-0412",
"memory_age_days": 30
},
{
"key": "ai-system:TRIAGE-ASSISTANT-V4::penetration_test",
"value": "no-critical",
"provenance": "VERIFIED",
"source": "LAB-NVLAP-0412:penetration_test",
"observed_at": "2026-06-09T16:00:00.000Z",
"reliability": 0.95,
"critical": true,
"memory_status": "admitted",
"memory_kind": "test_report",
"memory_actor": "actor:org:LAB-NVLAP-0412",
"memory_age_days": 60
},
{
"key": "ai-system:TRIAGE-ASSISTANT-V4::control_assessment",
"value": "satisfied",
"provenance": "VERIFIED",
"source": "CERT-3PAO-ATLANTIC:control_assessment",
"observed_at": "2026-04-30T16:00:00.000Z",
"reliability": 0.95,
"critical": true,
"memory_status": "admitted",
"memory_kind": "certificate",
"memory_actor": "actor:org:CERT-3PAO-ATLANTIC",
"memory_age_days": 100
},
{
"key": "ai-system:TRIAGE-ASSISTANT-V4::model_evaluation",
"value": null,
"provenance": "SELLER-ASSERTED",
"source": "triage-assistant-v4:model_evaluation",
"observed_at": "2026-07-30T16:00:00.000Z",
"reliability": 0.5,
"critical": false,
"memory_status": "withheld",
"memory_kind": "test_report",
"memory_actor": "actor:ai:triage-assistant-v4",
"memory_age_days": 9
},
{
"key": "ai-system:TRIAGE-ASSISTANT-V4::model_evaluation",
"value": null,
"provenance": "MISSING",
"source": null,
"observed_at": "2026-08-08T16:00:00.000Z",
"reliability": 0,
"critical": true,
"memory_status": "coverage_gap"
}
],
"crypto_suite": {
"spec": "corobate:suite:1",
"id": "CB-1-ES256-SHA256",
"receipt_digest": "sha256",
"chain_digest": "sha256",
"content_digest": "sha256",
"envelope_signature": "ES256",
"signature_curve": "P-256",
"canonicalisation": "attest-canon/2",
"quantum_resistant": false
}
}
}Authorising official (signer)
The named official whose signature carries the authorisation decision.
What is at stake, what the evidence supports, what is missing, and the digest they are signing over.
You are being asked to sign
May this AI system be deployed to triage citizen-facing casework?
The signature is over the STATE OF THE EVIDENCE. Move one fact behind this decision and the digest moves and the signature stops counting — which is what makes it safe to collect signatures before everyone is in the room.
What is missing
- model evaluation
The scoped copy itself — partial — something outside this role’s remit was removed
{
"spec": "corobate:role-view:2",
"role": "EXECUTIVE",
"purpose": "A named signer on the release gate. Sees what is at stake, what the evidence supports, who else has signed and what they are being asked to sign over.",
"is_a_receipt": false,
"warning": "This is a SCOPED COPY of a sealed decision, not the decision record itself. It will not verify as a receipt and must not be presented as one. To confirm it is faithful, recompute its `view` digest under the same canonicalisation that produces receipt_hash and compare it with the entry for this role in the source receipt’s `views` block.",
"derived_from": {
"receipt_hash": "sha256:6cfa106851e42c578947d59d107ffb474e39c813bc52723eb7102a95dc5a5e81",
"entry_hash": "sha256:2955bbd1e87ad0cde1c0780e46dbe791796688fe9d626f467577319c4d1158ca",
"issued_at": "2026-08-08T16:00:00.000Z"
},
"view_digest": "sha256:b2b81493f4d95918b2eee35db343860df5d0a15d2cce12a0af4f5a10d2e63e83",
"withheld": {
"anything_withheld": true,
"note": "Facts outside this role’s remit were removed. That something was removed is stated so a partial record is never mistaken for a complete one. How much, and what, is not stated — a count is an inference about the part you are not entitled to see."
},
"view": {
"spec": "urn:ietf:params:corobate:receipt:1",
"receipt_version": "1.8",
"issued_at": "2026-08-08T16:00:00.000Z",
"decision": {
"id": "ai_TRIAGE_V4_before",
"domain": "supply-chain",
"subject": "ai-system:TRIAGE-ASSISTANT-V4",
"question": "May this AI system be deployed to triage citizen-facing casework?"
},
"memory": {
"state_digest": "sha256:2d93db16d55c8de970115a836b580dcfdc4be9a6747a75d2d04c931322b48f90",
"ledger_head": "sha256:7529436da173e2905b4859118dac726b0cd5c4c379029c2afc524393c0d06822",
"coverage_gaps": [
"ai-system:TRIAGE-ASSISTANT-V4|model_evaluation"
],
"exposure": {
"usd": 1400000,
"declared_by": "actor:human:ao-authorizing-official",
"ledger_seq": 6
}
},
"verdict": {
"value": "WITHHELD",
"threshold_approve": 0.9,
"threshold_caution": 0.7,
"rule": "confidence>=threshold"
},
"confidence": {
"value": 0,
"method": "min-over-critical-inputs",
"bound_by": "ai-system:TRIAGE-ASSISTANT-V4::model_evaluation"
},
"release": {
"required": false,
"required_by_tier": false,
"escalated_by_acceptance": false,
"risk_accepted": false,
"state": "WITHHELD_NO_EVIDENCE",
"code": "QUORUM_EVIDENCE_WITHHELD",
"reason": "the evidence did not clear the threshold for this exposure, so there is nothing to release. Signatures do not substitute for evidence, and this state is deliberately distinct from WITHHELD_PENDING_SIGNATURES: a reader must be able to tell \"the evidence is not there\" from \"the evidence is there and 0 of 2 people have signed\".",
"tier_floor_cents": 1000000000,
"exposure_usd_cents": 140000000,
"required_m": 2,
"declared_n": 3,
"floor_m": 2,
"distinct_signers": 0,
"superseded": 0,
"collapsed": 0,
"release_digest": "sha256:49e46dc99310dfb4f669746425dfb108ff1f2d3e71c03f35b99c9f14211809df",
"governance_digest": "sha256:8b0a45a27fcce9c1c243c764e855e67c6fe6dfd7f02a563bd90809b419731905",
"governance_signed": true,
"counted_voices": [],
"signatures": [],
"ledger_seq": null
},
"acceptance": {
"state": "NONE",
"code": "ACCEPTANCE_NONE",
"reason": "no risk acceptance was presented for this decision. This is the ordinary case: a refusal is a refusal unless a named person has priced it.",
"permitted_basis": null,
"presented": 0,
"superseded": 0,
"expired": 0,
"gaps_not_covered": 0,
"coverage_gaps_in_force": [
"ai-system:TRIAGE-ASSISTANT-V4|model_evaluation"
],
"evidentiary_digest": "sha256:49e46dc99310dfb4f669746425dfb108ff1f2d3e71c03f35b99c9f14211809df",
"margin_floor_bp": 100,
"authority_ceiling_cents": {
"SUPERVISOR": 1000000,
"MANAGER": 25000000,
"DIRECTOR": 500000000,
"OFFICER": 5000000000
},
"acceptances": [],
"escalated": false,
"live": false,
"ledger_seq": null
},
"reasons": [
"Coverage gap: no admissible memory for required claim(s) ai-system:TRIAGE-ASSISTANT-V4|model_evaluation.",
"Confidence 0.00% is bound by \"ai-system:TRIAGE-ASSISTANT-V4|model_evaluation\".",
"1 memory was withheld from the context block: ai-system:TRIAGE-ASSISTANT-V4|model_evaluation (below class floor: rule requires at least VERIFIED, held SELLER-ASSERTED — inadmissible at any exposure).",
"Thresholds for $1,400,000 exposure: approve 90%, caution 70%."
],
"regulatory": {
"applied": [
{
"instrument_id": "nist-ai-rmf-1-0",
"version": 1,
"authority": "National Institute of Standards and Technology",
"instrument": "AI Risk Management Framework 1.0",
"edition": "1.0",
"citation": "MEASURE-2.3, MEASURE-2.7, MANAGE-2.2 [VERIFY]",
"source_digest": "sha256:a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1",
"entered_by": "actor:human:issm",
"entered_at": "2026-08-08T16:00:00.000Z"
},
{
"instrument_id": "nist-sp-800-53r5-moderate",
"version": 5,
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
"edition": "Rev. 5",
"citation": "CA-2, CA-8, RA-5, SR-6 [VERIFY]",
"source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353",
"entered_by": "actor:human:issm",
"entered_at": "2026-08-08T16:00:00.000Z"
}
],
"conflicts": [],
"defaults": [
{
"claim": "control_assessment",
"requirement": "ai_position",
"value": "ADMIT",
"because": "No instrument in force stated a position on AI-authored evidence for \"control_assessment\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
},
{
"claim": "incident_response_plan_test",
"requirement": "ai_position",
"value": "ADMIT",
"because": "No instrument in force stated a position on AI-authored evidence for \"incident_response_plan_test\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
},
{
"claim": "model_evaluation",
"requirement": "ai_position",
"value": "ADMIT",
"because": "No instrument in force stated a position on AI-authored evidence for \"model_evaluation\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
},
{
"claim": "penetration_test",
"requirement": "ai_position",
"value": "ADMIT",
"because": "No instrument in force stated a position on AI-authored evidence for \"penetration_test\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
},
{
"claim": "security_resilience_evaluation",
"requirement": "ai_position",
"value": "ADMIT",
"because": "No instrument in force stated a position on AI-authored evidence for \"security_resilience_evaluation\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
},
{
"claim": "vulnerability_scan",
"requirement": "ai_position",
"value": "ADMIT",
"because": "No instrument in force stated a position on AI-authored evidence for \"vulnerability_scan\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
}
]
},
"inputs": [
{
"key": "ai-system:TRIAGE-ASSISTANT-V4::vulnerability_scan",
"provenance": "VERIFIED",
"reliability": 0.95,
"critical": true,
"memory_status": "admitted"
},
{
"key": "ai-system:TRIAGE-ASSISTANT-V4::incident_response_plan_test",
"provenance": "VERIFIED",
"reliability": 0.95,
"critical": true,
"memory_status": "admitted"
},
{
"key": "ai-system:TRIAGE-ASSISTANT-V4::security_resilience_evaluation",
"provenance": "VERIFIED",
"reliability": 0.95,
"critical": true,
"memory_status": "admitted"
},
{
"key": "ai-system:TRIAGE-ASSISTANT-V4::penetration_test",
"provenance": "VERIFIED",
"reliability": 0.95,
"critical": true,
"memory_status": "admitted"
},
{
"key": "ai-system:TRIAGE-ASSISTANT-V4::control_assessment",
"provenance": "VERIFIED",
"reliability": 0.95,
"critical": true,
"memory_status": "admitted"
},
{
"key": "ai-system:TRIAGE-ASSISTANT-V4::model_evaluation",
"provenance": "SELLER-ASSERTED",
"reliability": 0.5,
"critical": false,
"memory_status": "withheld"
},
{
"key": "ai-system:TRIAGE-ASSISTANT-V4::model_evaluation",
"provenance": "MISSING",
"reliability": 0,
"critical": true,
"memory_status": "coverage_gap"
}
]
}
}Independent audit / IG
Internal audit, an inspector general, or an external auditor testing the programme.
Everything, plus the verifier’s own findings over the sealed record.
This view withholds nothing. What it adds is the 22 checks the published verifier ran over the sealed record behind every other view of this decision — recomputed at build time, not asserted.
| # | Check | Detail | |
|---|---|---|---|
| 1 | Content reproduces (JCS + SHA-256) | PASS | matches sha256:6cfa106851e42c578947d59d107ffb474e39c813bc52723eb7102a95dc5a5e81 |
| 2 | Hash chain links (entry = H(prev||content)) | PASS | head sha256:2955bbd1e87ad0cde1c0780e46dbe791796688fe9d626f467577319c4d1158ca |
| 3 | Confidence gated by weakest critical input | PASS | min over critical = 0, bound_by ai-system:TRIAGE-ASSISTANT-V4::model_evaluation (MISSING) |
| 3b | Verdict follows the threshold rule | PASS | 0 => WITHHELD; recorded WITHHELD |
| 4 | Point-in-time seal (no input past data_horizon) | PASS | all inputs <= 2026-08-08T16:00:00.000Z |
| 5 | Anchor covers the head, and the timestamp token re-reads | PASS | internally consistent; NO external anchor was requested — this is not a validated timestamp |
| 6 | Criteria travel with the receipt and reproduce | PASS | policy_body hashes to sha256:a6b69b7d20f7fb04d522364af1d92992058b04a5835fcec9d1c9f2261c7ef636 |
| 7 | Reliability re-derives from recorded evidence | PASS | all 7 inputs re-derive exactly |
| 8 | Outcome trials and lineage discounts re-derive | PASS | 6 input(s) re-derive: 0 credited outcome trial(s), 0 lineage-discounted corroboration(s); every reliability is at or under its class ceiling |
| 9 | Re-ingested receipts respect their weakest-input ceiling | PASS | no re-ingested receipts: every input rests on a primary observation |
| 10 | Release quorum re-derives | PASS | WITHHELD_NO_EVIDENCE - below the top exposure tier, no multi-party requirement applies |
| 11 | Risk acceptance re-derives | PASS | no risk acceptance: this decision stands or falls on its evidence |
| 12 | Observer credentials were not revoked as of observation time | PASS | revocation list 5 (0 entries, issued 2026-08-06T00:00:00.000Z, next update due 2026-08-13T00:00:00.000Z) reproduces; 5 observer signature(s) judged as of their own instant, none under a key revoked as compromised or retired by then |
| 13 | The cryptographic suite is named and is one this verifier implements | PASS | sealed under CB-1-ES256-SHA256 (ES256 / sha256, attest-canon/2); this verifier implements it; the suite states it is NOT quantum resistant |
| 14 | Regulatory bindings are attributed and were enforced | PASS | 12 binding(s) from 2 instrument(s) in force, each attributed to an authority, a citation and a document digest; 6 required claim(s) all reached the gate |
| 15 | Role-view commitments re-derive, and the customs view carries no money | PASS | 6 role-view commitment(s) re-derived from this receipt’s own body by this verifier’s independent projection; the REGULATOR view carries no commercial figure |
| 16 | AI-authored input was admitted only where an authority allowed it | PASS | 0 claim(s) carry a position on AI-authored evidence set by an authority and 6 carry a recorded default nobody set; 0 exclusion(s) and 0 corroboration-only rule(s) re-derived against this receipt's own admitted inputs; 0 admitted input(s) are AI-authored by their enrolled identity |
| 17 | State digest recomputes from the ledger alone | UNVERIFIABLE | NOT APPLICABLE — you supplied no ledger, so the state digest cannot be re-derived from anything. This receipt commits to the corpus the deciding system held at the instant it sealed, and that commitment is checked by recomputing it from the append-only ledger and comparing; with no ledger in hand there is no second artefact to recompute from. The receipt is not at fault and nothing here is missing from it. Obtain the ledger from the issuer and re-run with --ledger <file>, or verifyReceipt(r, {ledger}). Nothing here has failed and nothing here has passed. |
| 18 | Registry membership re-derives for every key relied on | PASS | all 3 key(s) relied on re-derive to the entries root registry v3 committed to and the trust root signed |
| 20 | Geometric support re-derives, and an unevaluated record is not a supported one | PASS | no authority bound a metric to any claim on this receipt, so no geometric test applied. A claim nobody bound a metric to is not a claim about geometry, and this is a stated absence rather than a silent one |
| 19 | The cause of every uncovered requirement re-derives | PASS | all 1 uncovered requirement(s) re-derive their cause from this receipt's own rows. What notice is ADEQUATE is not decided here: this check establishes what the record says and that the record agrees with itself. |
| 21 | The sealing party is the one you were told to expect | UNVERIFIABLE | NOT APPLICABLE — you supplied no trust bundle, so nothing here establishes who sealed this. Identities 1 to 20 prove that this document agrees with itself; not one of them asks whose trust root it was sealed under, and a document that agrees with itself about a decision nobody made agrees with itself perfectly. Obtain the issuer's corobate:trust-bundle:1 out of band, confirm its spoken fingerprint with them by voice, and re-run with --trust-bundle <file> --expect-fingerprint <what you heard>. Nothing here has failed and nothing here has passed. |
The scoped copy itself — complete for this role
{
"spec": "corobate:role-view:2",
"role": "AUDITOR",
"purpose": "An external assessor. Sees the complete sealed record: this view withholds nothing and exists so the identity case is a case rather than an exception.",
"is_a_receipt": false,
"warning": "This is a SCOPED COPY of a sealed decision, not the decision record itself. It will not verify as a receipt and must not be presented as one. To confirm it is faithful, recompute its `view` digest under the same canonicalisation that produces receipt_hash and compare it with the entry for this role in the source receipt’s `views` block.",
"derived_from": {
"receipt_hash": "sha256:6cfa106851e42c578947d59d107ffb474e39c813bc52723eb7102a95dc5a5e81",
"entry_hash": "sha256:2955bbd1e87ad0cde1c0780e46dbe791796688fe9d626f467577319c4d1158ca",
"issued_at": "2026-08-08T16:00:00.000Z"
},
"view_digest": "sha256:bf67848128fb2010efa7cb7fe589d33f0f93e58bf4a36c483e781346639299c9",
"withheld": {
"anything_withheld": false,
"note": "Nothing outside the seal was removed for this role."
},
"view": {
"spec": "urn:ietf:params:corobate:receipt:1",
"receipt_version": "1.8",
"engine": {
"name": "corobate-memory",
"version": "1.0.0"
},
"decision": {
"id": "ai_TRIAGE_V4_before",
"domain": "supply-chain",
"subject": "ai-system:TRIAGE-ASSISTANT-V4",
"question": "May this AI system be deployed to triage citizen-facing casework?"
},
"issued_at": "2026-08-08T16:00:00.000Z",
"data_horizon": "2026-08-08T16:00:00.000Z",
"inputs": [
{
"key": "ai-system:TRIAGE-ASSISTANT-V4::vulnerability_scan",
"value": "clean-at-scan",
"provenance": "VERIFIED",
"source": "nvd-cve:vulnerability_scan",
"observed_at": "2026-08-04T16:00:00.000Z",
"last_corroborated_at": null,
"memory_refreshed_by": [],
"reliability": 0.95,
"critical": true,
"memory_id": "mem_4d2b1fc0d322",
"memory_status": "admitted",
"memory_kind": "status",
"memory_actor": "actor:sys:registry:nvd-cve",
"memory_age_days": 4,
"memory_track": {
"n": 1,
"successes": 1
},
"memory_promoted_by": [],
"memory_content_digest": "sha256:aea4c3860d57b3edd045cd33946015c41ff1aee9cc8a4df49f26d8a5165d4a38",
"memory_outcomes": {
"verified": 0,
"falsified": 0,
"modified": 0,
"counted": 0,
"recorded": 0
},
"memory_outcome_attestations": [],
"memory_observer_lineage": null,
"memory_corroborations": [],
"memory_reingest": null,
"memory_reasons": [
"sparse track record: 1 independent observation(s); no failure recorded, so the class ceiling stands"
],
"memory_class_floor": null,
"memory_below_class_floor": false,
"memory_not_attested": false,
"memory_below_claim_reliability_floor": false,
"memory_not_competent_authority": false,
"memory_out_of_specification": false,
"memory_ai_authored": false,
"memory_ai_in_lineage": false,
"memory_ai_position": "ADMIT",
"memory_ai_inadmissible": false,
"memory_geo_inadmissible": false,
"memory_geo_rung": null,
"memory_geo_metric": null,
"memory_geo_required_metric": null,
"observer_attested": true,
"observer_auth_code": "VERIFIED",
"observer_key_id": "k_5873dd9e7169def3",
"attestation": null,
"derivation": {
"provenance": "VERIFIED",
"ceiling_bp": 9500,
"track": {
"n": 1,
"successes": 1
},
"wilson_bp": null,
"age_days": 4,
"max_age_days": 14,
"house_max_age_days": 14,
"instrument_max_age_days": 30,
"freshness_cap_bp": 4000,
"min_track_n": 5,
"wilson_z_milli": 1960,
"source_present": true,
"seller_asserted_cap_bp": 5000,
"retracted": false,
"contradicted": false,
"outcome_trials": 0,
"outcomes": {
"verified": 0,
"falsified": 0,
"modified": 0,
"counted": 0,
"recorded": 0
},
"corroborations_counted": 0,
"corroborations_discounted": 0,
"reingest_ceiling_bp": null,
"reingest_depth": null,
"reingest_weakest_class": null,
"reingest_source_confidence_bp": null,
"ai_authored": false,
"ai_authored_because": null,
"ai_in_lineage": false,
"ai_position": "ADMIT"
},
"memory_reason_codes": [
{
"code": "SPARSE_TRACK_RECORD",
"observed": 1,
"limit": 5,
"binding": false
}
],
"context_line": "[VERIFIED · r=95.0% · 4d · nvd-cve:vulnerability_scan] ai-system:TRIAGE-ASSISTANT-V4 / vulnerability_scan: clean-at-scan"
},
{
"key": "ai-system:TRIAGE-ASSISTANT-V4::incident_response_plan_test",
"value": "observed",
"provenance": "VERIFIED",
"source": "CERT-3PAO-ATLANTIC:incident_response_plan_test",
"observed_at": "2026-06-24T16:00:00.000Z",
"last_corroborated_at": null,
"memory_refreshed_by": [],
"reliability": 0.95,
"critical": true,
"memory_id": "mem_a54dcc18c5ba",
"memory_status": "admitted",
"memory_kind": "certificate",
"memory_actor": "actor:org:CERT-3PAO-ATLANTIC",
"memory_age_days": 45,
"memory_track": {
"n": 1,
"successes": 1
},
"memory_promoted_by": [],
"memory_content_digest": "sha256:a73e4d82b06b62aa687c0a5352a36df46dd691e2bfa8b1354c847d24612df001",
"memory_outcomes": {
"verified": 0,
"falsified": 0,
"modified": 0,
"counted": 0,
"recorded": 0
},
"memory_outcome_attestations": [],
"memory_observer_lineage": null,
"memory_corroborations": [],
"memory_reingest": null,
"memory_reasons": [
"sparse track record: 1 independent observation(s); no failure recorded, so the class ceiling stands"
],
"memory_class_floor": null,
"memory_below_class_floor": false,
"memory_not_attested": false,
"memory_below_claim_reliability_floor": false,
"memory_not_competent_authority": false,
"memory_out_of_specification": false,
"memory_ai_authored": false,
"memory_ai_in_lineage": false,
"memory_ai_position": "ADMIT",
"memory_ai_inadmissible": false,
"memory_geo_inadmissible": false,
"memory_geo_rung": null,
"memory_geo_metric": null,
"memory_geo_required_metric": null,
"observer_attested": true,
"observer_auth_code": "VERIFIED",
"observer_key_id": "k_307e4bfd710ec9b3",
"attestation": null,
"derivation": {
"provenance": "VERIFIED",
"ceiling_bp": 9500,
"track": {
"n": 1,
"successes": 1
},
"wilson_bp": null,
"age_days": 45,
"max_age_days": 365,
"house_max_age_days": 365,
"instrument_max_age_days": null,
"freshness_cap_bp": 4000,
"min_track_n": 5,
"wilson_z_milli": 1960,
"source_present": true,
"seller_asserted_cap_bp": 5000,
"retracted": false,
"contradicted": false,
"outcome_trials": 0,
"outcomes": {
"verified": 0,
"falsified": 0,
"modified": 0,
"counted": 0,
"recorded": 0
},
"corroborations_counted": 0,
"corroborations_discounted": 0,
"reingest_ceiling_bp": null,
"reingest_depth": null,
"reingest_weakest_class": null,
"reingest_source_confidence_bp": null,
"ai_authored": false,
"ai_authored_because": null,
"ai_in_lineage": false,
"ai_position": "ADMIT"
},
"memory_reason_codes": [
{
"code": "SPARSE_TRACK_RECORD",
"observed": 1,
"limit": 5,
"binding": false
}
],
"context_line": "[VERIFIED · r=95.0% · 45d · CERT-3PAO-ATLANTIC:incident_response_plan_test] ai-system:TRIAGE-ASSISTANT-V4 / incident_response_plan_test: observed"
},
{
"key": "ai-system:TRIAGE-ASSISTANT-V4::security_resilience_evaluation",
"value": "assessed",
"provenance": "VERIFIED",
"source": "LAB-NVLAP-0412:security_resilience_evaluation",
"observed_at": "2026-07-09T16:00:00.000Z",
"last_corroborated_at": null,
"memory_refreshed_by": [],
"reliability": 0.95,
"critical": true,
"memory_id": "mem_2c29e7fe028c",
"memory_status": "admitted",
"memory_kind": "test_report",
"memory_actor": "actor:org:LAB-NVLAP-0412",
"memory_age_days": 30,
"memory_track": {
"n": 1,
"successes": 1
},
"memory_promoted_by": [],
"memory_content_digest": "sha256:dcbb60638904f38e17aa80dd1108c75855c10f1992b0793dc56d369582fc515e",
"memory_outcomes": {
"verified": 0,
"falsified": 0,
"modified": 0,
"counted": 0,
"recorded": 0
},
"memory_outcome_attestations": [],
"memory_observer_lineage": null,
"memory_corroborations": [],
"memory_reingest": null,
"memory_reasons": [
"sparse track record: 1 independent observation(s); no failure recorded, so the class ceiling stands"
],
"memory_class_floor": null,
"memory_below_class_floor": false,
"memory_not_attested": false,
"memory_below_claim_reliability_floor": false,
"memory_not_competent_authority": false,
"memory_out_of_specification": false,
"memory_ai_authored": false,
"memory_ai_in_lineage": false,
"memory_ai_position": "ADMIT",
"memory_ai_inadmissible": false,
"memory_geo_inadmissible": false,
"memory_geo_rung": null,
"memory_geo_metric": null,
"memory_geo_required_metric": null,
"observer_attested": true,
"observer_auth_code": "VERIFIED",
"observer_key_id": "k_17d23885943ae529",
"attestation": null,
"derivation": {
"provenance": "VERIFIED",
"ceiling_bp": 9500,
"track": {
"n": 1,
"successes": 1
},
"wilson_bp": null,
"age_days": 30,
"max_age_days": 180,
"house_max_age_days": 180,
"instrument_max_age_days": null,
"freshness_cap_bp": 4000,
"min_track_n": 5,
"wilson_z_milli": 1960,
"source_present": true,
"seller_asserted_cap_bp": 5000,
"retracted": false,
"contradicted": false,
"outcome_trials": 0,
"outcomes": {
"verified": 0,
"falsified": 0,
"modified": 0,
"counted": 0,
"recorded": 0
},
"corroborations_counted": 0,
"corroborations_discounted": 0,
"reingest_ceiling_bp": null,
"reingest_depth": null,
"reingest_weakest_class": null,
"reingest_source_confidence_bp": null,
"ai_authored": false,
"ai_authored_because": null,
"ai_in_lineage": false,
"ai_position": "ADMIT"
},
"memory_reason_codes": [
{
"code": "SPARSE_TRACK_RECORD",
"observed": 1,
"limit": 5,
"binding": false
}
],
"context_line": "[VERIFIED · r=95.0% · 30d · LAB-NVLAP-0412:security_resilience_evaluation] ai-system:TRIAGE-ASSISTANT-V4 / security_resilience_evaluation: assessed"
},
{
"key": "ai-system:TRIAGE-ASSISTANT-V4::penetration_test",
"value": "no-critical",
"provenance": "VERIFIED",
"source": "LAB-NVLAP-0412:penetration_test",
"observed_at": "2026-06-09T16:00:00.000Z",
"last_corroborated_at": null,
"memory_refreshed_by": [],
"reliability": 0.95,
"critical": true,
"memory_id": "mem_a3316d633bfe",
"memory_status": "admitted",
"memory_kind": "test_report",
"memory_actor": "actor:org:LAB-NVLAP-0412",
"memory_age_days": 60,
"memory_track": {
"n": 1,
"successes": 1
},
"memory_promoted_by": [],
"memory_content_digest": "sha256:db69fb062be9b066b370c668281e12896da2869456a2e6d356a0f14879b27de9",
"memory_outcomes": {
"verified": 0,
"falsified": 0,
"modified": 0,
"counted": 0,
"recorded": 0
},
"memory_outcome_attestations": [],
"memory_observer_lineage": null,
"memory_corroborations": [],
"memory_reingest": null,
"memory_reasons": [
"sparse track record: 1 independent observation(s); no failure recorded, so the class ceiling stands"
],
"memory_class_floor": "VERIFIED",
"memory_below_class_floor": false,
"memory_not_attested": false,
"memory_below_claim_reliability_floor": false,
"memory_not_competent_authority": false,
"memory_out_of_specification": false,
"memory_ai_authored": false,
"memory_ai_in_lineage": false,
"memory_ai_position": "ADMIT",
"memory_ai_inadmissible": false,
"memory_geo_inadmissible": false,
"memory_geo_rung": null,
"memory_geo_metric": null,
"memory_geo_required_metric": null,
"observer_attested": true,
"observer_auth_code": "VERIFIED",
"observer_key_id": "k_17d23885943ae529",
"attestation": null,
"derivation": {
"provenance": "VERIFIED",
"ceiling_bp": 9500,
"track": {
"n": 1,
"successes": 1
},
"wilson_bp": null,
"age_days": 60,
"max_age_days": 180,
"house_max_age_days": 180,
"instrument_max_age_days": null,
"freshness_cap_bp": 4000,
"min_track_n": 5,
"wilson_z_milli": 1960,
"source_present": true,
"seller_asserted_cap_bp": 5000,
"retracted": false,
"contradicted": false,
"outcome_trials": 0,
"outcomes": {
"verified": 0,
"falsified": 0,
"modified": 0,
"counted": 0,
"recorded": 0
},
"corroborations_counted": 0,
"corroborations_discounted": 0,
"reingest_ceiling_bp": null,
"reingest_depth": null,
"reingest_weakest_class": null,
"reingest_source_confidence_bp": null,
"min_class_floor": "VERIFIED",
"ai_authored": false,
"ai_authored_because": null,
"ai_in_lineage": false,
"ai_position": "ADMIT"
},
"memory_reason_codes": [
{
"code": "SPARSE_TRACK_RECORD",
"observed": 1,
"limit": 5,
"binding": false
}
],
"context_line": "[VERIFIED · r=95.0% · 60d · LAB-NVLAP-0412:penetration_test] ai-system:TRIAGE-ASSISTANT-V4 / penetration_test: no-critical"
},
{
"key": "ai-system:TRIAGE-ASSISTANT-V4::control_assessment",
"value": "satisfied",
"provenance": "VERIFIED",
"source": "CERT-3PAO-ATLANTIC:control_assessment",
"observed_at": "2026-04-30T16:00:00.000Z",
"last_corroborated_at": null,
"memory_refreshed_by": [],
"reliability": 0.95,
"critical": true,
"memory_id": "mem_a153eb336060",
"memory_status": "admitted",
"memory_kind": "certificate",
"memory_actor": "actor:org:CERT-3PAO-ATLANTIC",
"memory_age_days": 100,
"memory_track": {
"n": 1,
"successes": 1
},
"memory_promoted_by": [],
"memory_content_digest": "sha256:c1aaf46a55b4cdc629a754ac35da1b8ec4dec85c2c78613c7bc93546b63f233c",
"memory_outcomes": {
"verified": 0,
"falsified": 0,
"modified": 0,
"counted": 0,
"recorded": 0
},
"memory_outcome_attestations": [],
"memory_observer_lineage": null,
"memory_corroborations": [],
"memory_reingest": null,
"memory_reasons": [
"sparse track record: 1 independent observation(s); no failure recorded, so the class ceiling stands"
],
"memory_class_floor": "VERIFIED",
"memory_below_class_floor": false,
"memory_not_attested": false,
"memory_below_claim_reliability_floor": false,
"memory_not_competent_authority": false,
"memory_out_of_specification": false,
"memory_ai_authored": false,
"memory_ai_in_lineage": false,
"memory_ai_position": "ADMIT",
"memory_ai_inadmissible": false,
"memory_geo_inadmissible": false,
"memory_geo_rung": null,
"memory_geo_metric": null,
"memory_geo_required_metric": null,
"observer_attested": true,
"observer_auth_code": "VERIFIED",
"observer_key_id": "k_307e4bfd710ec9b3",
"attestation": null,
"derivation": {
"provenance": "VERIFIED",
"ceiling_bp": 9500,
"track": {
"n": 1,
"successes": 1
},
"wilson_bp": null,
"age_days": 100,
"max_age_days": 365,
"house_max_age_days": 365,
"instrument_max_age_days": 365,
"freshness_cap_bp": 4000,
"min_track_n": 5,
"wilson_z_milli": 1960,
"source_present": true,
"seller_asserted_cap_bp": 5000,
"retracted": false,
"contradicted": false,
"outcome_trials": 0,
"outcomes": {
"verified": 0,
"falsified": 0,
"modified": 0,
"counted": 0,
"recorded": 0
},
"corroborations_counted": 0,
"corroborations_discounted": 0,
"reingest_ceiling_bp": null,
"reingest_depth": null,
"reingest_weakest_class": null,
"reingest_source_confidence_bp": null,
"min_class_floor": "VERIFIED",
"ai_authored": false,
"ai_authored_because": null,
"ai_in_lineage": false,
"ai_position": "ADMIT"
},
"memory_reason_codes": [
{
"code": "SPARSE_TRACK_RECORD",
"observed": 1,
"limit": 5,
"binding": false
}
],
"context_line": "[VERIFIED · r=95.0% · 100d · CERT-3PAO-ATLANTIC:control_assessment] ai-system:TRIAGE-ASSISTANT-V4 / control_assessment: satisfied"
},
{
"key": "ai-system:TRIAGE-ASSISTANT-V4::model_evaluation",
"value": null,
"provenance": "SELLER-ASSERTED",
"source": "triage-assistant-v4:model_evaluation",
"observed_at": "2026-07-30T16:00:00.000Z",
"last_corroborated_at": null,
"memory_refreshed_by": [],
"reliability": 0.5,
"critical": false,
"memory_id": "mem_5de9825e17f5",
"memory_status": "withheld",
"memory_kind": "test_report",
"memory_actor": "actor:ai:triage-assistant-v4",
"memory_age_days": 9,
"memory_track": {
"n": 1,
"successes": 1
},
"memory_promoted_by": [],
"memory_content_digest": "sha256:224db2c622d9fec54b10ae86e818c3bf4832c6eaf0549b6cf298d50ca55668bc",
"memory_outcomes": {
"verified": 0,
"falsified": 0,
"modified": 0,
"counted": 0,
"recorded": 0
},
"memory_outcome_attestations": [],
"memory_observer_lineage": null,
"memory_corroborations": [],
"memory_reingest": null,
"memory_reasons": [
"below class floor: rule requires at least VERIFIED, held SELLER-ASSERTED — inadmissible at any exposure",
"sparse track record: 1 independent observation(s); no failure recorded, so the class ceiling stands"
],
"memory_class_floor": "VERIFIED",
"memory_below_class_floor": true,
"memory_not_attested": false,
"memory_below_claim_reliability_floor": false,
"memory_not_competent_authority": false,
"memory_out_of_specification": false,
"memory_ai_authored": true,
"memory_ai_in_lineage": false,
"memory_ai_position": "ADMIT",
"memory_ai_inadmissible": false,
"memory_geo_inadmissible": false,
"memory_geo_rung": null,
"memory_geo_metric": null,
"memory_geo_required_metric": null,
"observer_attested": false,
"observer_auth_code": "NO_ENVELOPE",
"observer_key_id": null,
"attestation": null,
"derivation": {
"provenance": "SELLER-ASSERTED",
"ceiling_bp": 5000,
"track": {
"n": 1,
"successes": 1
},
"wilson_bp": null,
"age_days": 9,
"max_age_days": 180,
"house_max_age_days": 180,
"instrument_max_age_days": 180,
"freshness_cap_bp": 4000,
"min_track_n": 5,
"wilson_z_milli": 1960,
"source_present": true,
"seller_asserted_cap_bp": 5000,
"retracted": false,
"contradicted": false,
"outcome_trials": 0,
"outcomes": {
"verified": 0,
"falsified": 0,
"modified": 0,
"counted": 0,
"recorded": 0
},
"corroborations_counted": 0,
"corroborations_discounted": 0,
"reingest_ceiling_bp": null,
"reingest_depth": null,
"reingest_weakest_class": null,
"reingest_source_confidence_bp": null,
"min_class_floor": "VERIFIED",
"ai_authored": true,
"ai_authored_because": "a model, named as one in its own enrolled identity",
"ai_in_lineage": false,
"ai_position": "ADMIT"
},
"memory_reason_codes": [
{
"code": "BELOW_CLASS_FLOOR",
"observed": "SELLER-ASSERTED",
"limit": "VERIFIED",
"binding": true
},
{
"code": "SPARSE_TRACK_RECORD",
"observed": 1,
"limit": 5,
"binding": false
}
]
},
{
"key": "ai-system:TRIAGE-ASSISTANT-V4::model_evaluation",
"value": null,
"provenance": "MISSING",
"source": null,
"observed_at": "2026-08-08T16:00:00.000Z",
"reliability": 0,
"critical": true,
"memory_status": "coverage_gap",
"gap_cause": "EVIDENCE_PRESENTED_FAILED",
"gap_request": null,
"gap_origin": "BUSINESS_EVIDENCE",
"gap_conditions": [
"below_class_floor"
]
}
],
"serialization": {
"algorithm": "RFC8785-JCS",
"hash": "sha256"
},
"crypto_suite": {
"spec": "corobate:suite:1",
"id": "CB-1-ES256-SHA256",
"receipt_digest": "sha256",
"chain_digest": "sha256",
"content_digest": "sha256",
"envelope_signature": "ES256",
"signature_curve": "P-256",
"canonicalisation": "attest-canon/2",
"quantum_resistant": false
},
"confidence": {
"value": 0,
"method": "min-over-critical-inputs",
"bound_by": "ai-system:TRIAGE-ASSISTANT-V4::model_evaluation"
},
"verdict": {
"value": "WITHHELD",
"threshold_approve": 0.9,
"threshold_caution": 0.7,
"rule": "confidence>=threshold"
},
"release": {
"required": false,
"required_by_tier": false,
"escalated_by_acceptance": false,
"risk_accepted": false,
"state": "WITHHELD_NO_EVIDENCE",
"code": "QUORUM_EVIDENCE_WITHHELD",
"reason": "the evidence did not clear the threshold for this exposure, so there is nothing to release. Signatures do not substitute for evidence, and this state is deliberately distinct from WITHHELD_PENDING_SIGNATURES: a reader must be able to tell \"the evidence is not there\" from \"the evidence is there and 0 of 2 people have signed\".",
"tier_floor_cents": 1000000000,
"exposure_usd_cents": 140000000,
"required_m": 2,
"declared_n": 3,
"floor_m": 2,
"distinct_signers": 0,
"superseded": 0,
"collapsed": 0,
"release_digest": "sha256:49e46dc99310dfb4f669746425dfb108ff1f2d3e71c03f35b99c9f14211809df",
"governance_digest": "sha256:8b0a45a27fcce9c1c243c764e855e67c6fe6dfd7f02a563bd90809b419731905",
"governance_signed": true,
"counted_voices": [],
"signatures": [],
"ledger_seq": null
},
"acceptance": {
"state": "NONE",
"code": "ACCEPTANCE_NONE",
"reason": "no risk acceptance was presented for this decision. This is the ordinary case: a refusal is a refusal unless a named person has priced it.",
"permitted_basis": null,
"presented": 0,
"superseded": 0,
"expired": 0,
"gaps_not_covered": 0,
"coverage_gaps_in_force": [
"ai-system:TRIAGE-ASSISTANT-V4|model_evaluation"
],
"evidentiary_digest": "sha256:49e46dc99310dfb4f669746425dfb108ff1f2d3e71c03f35b99c9f14211809df",
"margin_floor_bp": 100,
"authority_ceiling_cents": {
"SUPERVISOR": 1000000,
"MANAGER": 25000000,
"DIRECTOR": 500000000,
"OFFICER": 5000000000
},
"acceptances": [],
"escalated": false,
"live": false,
"ledger_seq": null
},
"regulatory": {
"spec": "corobate:regulatory:2",
"resolved": true,
"applied": [
{
"instrument_id": "nist-ai-rmf-1-0",
"version": 1,
"authority": "National Institute of Standards and Technology",
"instrument": "AI Risk Management Framework 1.0",
"edition": "1.0",
"citation": "MEASURE-2.3, MEASURE-2.7, MANAGE-2.2 [VERIFY]",
"source_digest": "sha256:a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1",
"entered_by": "actor:human:issm",
"entered_at": "2026-08-08T16:00:00.000Z"
},
{
"instrument_id": "nist-sp-800-53r5-moderate",
"version": 5,
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
"edition": "Rev. 5",
"citation": "CA-2, CA-8, RA-5, SR-6 [VERIFY]",
"source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353",
"entered_by": "actor:human:issm",
"entered_at": "2026-08-08T16:00:00.000Z"
}
],
"skipped": [],
"conflicts": [],
"bindings": [
{
"claim": "control_assessment",
"requirement": "max_age_days",
"value": 365,
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
"instrument_id": "nist-sp-800-53r5-moderate",
"version": 5,
"edition": "Rev. 5",
"citation": "CA-2 [VERIFY]",
"source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "control_assessment",
"requirement": "min_class",
"value": "VERIFIED",
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
"instrument_id": "nist-sp-800-53r5-moderate",
"version": 5,
"edition": "Rev. 5",
"citation": "CA-2(1) independent assessors [VERIFY]",
"source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "control_assessment",
"requirement": "required",
"value": true,
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
"instrument_id": "nist-sp-800-53r5-moderate",
"version": 5,
"edition": "Rev. 5",
"citation": "CA-2 [VERIFY]",
"source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "incident_response_plan_test",
"requirement": "required",
"value": true,
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "AI Risk Management Framework 1.0",
"instrument_id": "nist-ai-rmf-1-0",
"version": 1,
"edition": "1.0",
"citation": "MANAGE-4.1 [VERIFY]",
"source_digest": "sha256:a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "model_evaluation",
"requirement": "max_age_days",
"value": 180,
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "AI Risk Management Framework 1.0",
"instrument_id": "nist-ai-rmf-1-0",
"version": 1,
"edition": "1.0",
"citation": "MEASURE-2.3 [VERIFY]",
"source_digest": "sha256:a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "model_evaluation",
"requirement": "min_class",
"value": "VERIFIED",
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "AI Risk Management Framework 1.0",
"instrument_id": "nist-ai-rmf-1-0",
"version": 1,
"edition": "1.0",
"citation": "MEASURE-2.3 independent evaluation [VERIFY]",
"source_digest": "sha256:a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "model_evaluation",
"requirement": "required",
"value": true,
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "AI Risk Management Framework 1.0",
"instrument_id": "nist-ai-rmf-1-0",
"version": 1,
"edition": "1.0",
"citation": "MEASURE-2.3 [VERIFY]",
"source_digest": "sha256:a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "penetration_test",
"requirement": "min_class",
"value": "VERIFIED",
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
"instrument_id": "nist-sp-800-53r5-moderate",
"version": 5,
"edition": "Rev. 5",
"citation": "CA-8(1) independent penetration agent [VERIFY]",
"source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "penetration_test",
"requirement": "required",
"value": true,
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
"instrument_id": "nist-sp-800-53r5-moderate",
"version": 5,
"edition": "Rev. 5",
"citation": "CA-8 [VERIFY]",
"source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "security_resilience_evaluation",
"requirement": "required",
"value": true,
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "AI Risk Management Framework 1.0",
"instrument_id": "nist-ai-rmf-1-0",
"version": 1,
"edition": "1.0",
"citation": "MEASURE-2.7 [VERIFY]",
"source_digest": "sha256:a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "vulnerability_scan",
"requirement": "max_age_days",
"value": 30,
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
"instrument_id": "nist-sp-800-53r5-moderate",
"version": 5,
"edition": "Rev. 5",
"citation": "RA-5(a) [VERIFY]",
"source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "vulnerability_scan",
"requirement": "required",
"value": true,
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
"instrument_id": "nist-sp-800-53r5-moderate",
"version": 5,
"edition": "Rev. 5",
"citation": "RA-5 [VERIFY]",
"source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
}
],
"defaults": [
{
"claim": "control_assessment",
"requirement": "ai_position",
"value": "ADMIT",
"because": "No instrument in force stated a position on AI-authored evidence for \"control_assessment\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
},
{
"claim": "incident_response_plan_test",
"requirement": "ai_position",
"value": "ADMIT",
"because": "No instrument in force stated a position on AI-authored evidence for \"incident_response_plan_test\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
},
{
"claim": "model_evaluation",
"requirement": "ai_position",
"value": "ADMIT",
"because": "No instrument in force stated a position on AI-authored evidence for \"model_evaluation\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
},
{
"claim": "penetration_test",
"requirement": "ai_position",
"value": "ADMIT",
"because": "No instrument in force stated a position on AI-authored evidence for \"penetration_test\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
},
{
"claim": "security_resilience_evaluation",
"requirement": "ai_position",
"value": "ADMIT",
"because": "No instrument in force stated a position on AI-authored evidence for \"security_resilience_evaluation\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
},
{
"claim": "vulnerability_scan",
"requirement": "ai_position",
"value": "ADMIT",
"because": "No instrument in force stated a position on AI-authored evidence for \"vulnerability_scan\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
}
]
},
"reasons": [
"Coverage gap: no admissible memory for required claim(s) ai-system:TRIAGE-ASSISTANT-V4|model_evaluation.",
"Confidence 0.00% is bound by \"ai-system:TRIAGE-ASSISTANT-V4|model_evaluation\".",
"1 memory was withheld from the context block: ai-system:TRIAGE-ASSISTANT-V4|model_evaluation (below class floor: rule requires at least VERIFIED, held SELLER-ASSERTED — inadmissible at any exposure).",
"Thresholds for $1,400,000 exposure: approve 90%, caution 70%."
],
"memory": {
"layer": "capture->store->recall->act",
"ledger_head": "sha256:7529436da173e2905b4859118dac726b0cd5c4c379029c2afc524393c0d06822",
"ledger_entries": 8,
"context_digest": null,
"context_memory_ids": [],
"state_digest": "sha256:2d93db16d55c8de970115a836b580dcfdc4be9a6747a75d2d04c931322b48f90",
"retrieval_method": "idf-lexical",
"corpus_size": 6,
"considered": 6,
"admitted": 5,
"withheld": 1,
"not_considered": 0,
"coverage_gaps": [
"ai-system:TRIAGE-ASSISTANT-V4|model_evaluation"
],
"exposure": {
"usd": 1400000,
"declared_by": "actor:human:ao-authorizing-official",
"ledger_seq": 6
},
"salience_policy": {
"half_life_days": 90,
"grace_days": 7,
"access_boost_bp": 500,
"access_boost_cap_bp": 2500,
"relevance_weight_bp": 6000,
"recency_weight_bp": 3000,
"usage_weight_bp": 1000,
"context_cap": 12,
"method": "idf-lexical",
"candidate_list_digest": "sha256:9bb0607e470641a267f1d574195d02b2a3a9a800f4aebf8bd9c9cb9cad937907",
"note": "salience orders retrieval only; it never contributes to reliability"
},
"policy_digest": "sha256:a6b69b7d20f7fb04d522364af1d92992058b04a5835fcec9d1c9f2261c7ef636",
"policy_body": {
"class_ceiling_bp": {
"VERIFIED": 9500,
"MODELED": 8000,
"SELLER-ASSERTED": 5000,
"MISSING": 0
},
"actor_class_ceiling": [
[
"^actor:ai:",
"MODELED"
],
[
"^actor:agent:",
"MODELED"
],
[
"^actor:human:",
"SELLER-ASSERTED"
],
[
"^actor:org:LAB-",
"VERIFIED"
],
[
"^actor:org:CERT-",
"VERIFIED"
],
[
"^actor:org:",
"SELLER-ASSERTED"
],
[
"^actor:sys:registry:",
"VERIFIED"
],
[
"^actor:sys:sensor:",
"VERIFIED"
],
[
"^actor:sys:",
"MODELED"
]
],
"freshness_cap_bp": 4000,
"max_age_days": {
"telemetry": 1,
"price": 7,
"status": 14,
"certificate": 365,
"test_report": 180,
"filing": 90,
"transcript": 120,
"highlight": 365,
"voice_note": 120,
"note": 365,
"preference": 540,
"decision": 1825,
"receipt": 365,
"default": 90
},
"wilson_z_milli": 1960,
"min_track_n": 5,
"exposure_tiers_bp": [
[
1000000000,
9500,
8000
],
[
100000000,
9000,
7000
],
[
1000000,
8500,
6000
],
[
0,
8000,
5000
]
],
"max_context_memories": 12,
"contradiction_resolve_margin": 2,
"salience": {
"half_life_days": 90,
"grace_days": 7,
"access_boost_bp": 500,
"access_boost_cap_bp": 2500,
"relevance_weight_bp": 6000,
"recency_weight_bp": 3000,
"usage_weight_bp": 1000
}
},
"observer_auth": {
"mode": "required",
"registry_version": 3,
"registry_digest": "sha256:460aeaafe345f69542a302e6619dff0712af98de6518838ee4c8585e448c3a7d",
"entries_root": "sha256:5670469f96484a814462814ed74f0f992b5f19e8ad6afced548e4956e4835ba5",
"memberships": [
{
"key_id": "k_17d23885943ae529",
"index": 1,
"entry": {
"actor": "actor:org:LAB-NVLAP-0412",
"class": "VERIFIED",
"kind": "org",
"key_id": "k_17d23885943ae529",
"jwk": {
"kty": "EC",
"crv": "P-256",
"x": "3TTw47-PkYfo3ZaKTq_qtHghnGvninAVj25kyOwONno",
"y": "16PMaR8ofeF5IcZk6ZLml8gDs8uE1s1sBLdciH5e4vg"
},
"valid_from": "2025-01-01T00:00:00.000Z",
"valid_to": "2027-06-01T00:00:00.000Z"
},
"path": [
{
"side": "left",
"sibling": "sha256:500f2ba5949d5256ae0f563530b0b270db41ce99d2d7c4b4b60e4bd558ca353d"
},
{
"side": "right",
"sibling": "sha256:a0b47ea437bf4f1042a1dd50a5a3f411f9a17971812fc6bafccd434eb7d78ccc"
},
{
"side": "right",
"sibling": "sha256:d3c2347eb675e865fc17ef0204cacda7b02e8784a811fdd1c8a015d1865e6dfb"
},
{
"side": "right",
"sibling": "sha256:7071adf5e21a94147d31f42f1028b4867b6562e5b78726259c2515b03b213e52"
}
]
},
{
"key_id": "k_307e4bfd710ec9b3",
"index": 0,
"entry": {
"actor": "actor:org:CERT-3PAO-ATLANTIC",
"class": "VERIFIED",
"kind": "org",
"key_id": "k_307e4bfd710ec9b3",
"jwk": {
"kty": "EC",
"crv": "P-256",
"x": "MGtV26TezLMPjiD3SecQtnje6eLqYyx4qkKzzAkbiY4",
"y": "SMMdLYnn-FpKbb2sJQ8EAZnzvozNm-cGO0VbUUpniPY"
},
"valid_from": "2025-01-01T00:00:00.000Z",
"valid_to": "2027-06-01T00:00:00.000Z"
},
"path": [
{
"side": "right",
"sibling": "sha256:4148869fc259d2c5fc19fe5831065b165a9acf81812e123162035acfdecade1d"
},
{
"side": "right",
"sibling": "sha256:a0b47ea437bf4f1042a1dd50a5a3f411f9a17971812fc6bafccd434eb7d78ccc"
},
{
"side": "right",
"sibling": "sha256:d3c2347eb675e865fc17ef0204cacda7b02e8784a811fdd1c8a015d1865e6dfb"
},
{
"side": "right",
"sibling": "sha256:7071adf5e21a94147d31f42f1028b4867b6562e5b78726259c2515b03b213e52"
}
]
},
{
"key_id": "k_5873dd9e7169def3",
"index": 2,
"entry": {
"actor": "actor:sys:registry:nvd-cve",
"class": "VERIFIED",
"kind": "system",
"key_id": "k_5873dd9e7169def3",
"jwk": {
"kty": "EC",
"crv": "P-256",
"x": "O9OY6oMuJg0df_INePO19_3b11VaSyMwIPdxoqvV2ak",
"y": "k7Orm5pxDxMdTF-H2S4h6ixRywzk1WxvquOQeqxLFx0"
},
"valid_from": "2025-01-01T00:00:00.000Z",
"valid_to": "2027-06-01T00:00:00.000Z"
},
"path": [
{
"side": "right",
"sibling": "sha256:e1fe36fe7c8e4695327c25d6d722630b6249c93293bfdc5894c58aaf961ab6f8"
},
{
"side": "left",
"sibling": "sha256:e8b9cba101f13538b909a2e686e9e6e9a8d77212036ed567eaebc205a443e83f"
},
{
"side": "right",
"sibling": "sha256:d3c2347eb675e865fc17ef0204cacda7b02e8784a811fdd1c8a015d1865e6dfb"
},
{
"side": "right",
"sibling": "sha256:7071adf5e21a94147d31f42f1028b4867b6562e5b78726259c2515b03b213e52"
}
]
}
],
"memberships_unproven": [],
"revocation": {
"source": "SIGNED_LIST",
"digest": "sha256:12f73b1fbf27d38cf137b86a1ce13bbcd98161123a6aa7d79b107db8189966b9",
"sequence": 5,
"registry_version": 3,
"issued_at": "2026-08-06T00:00:00.000Z",
"next_update_due": "2026-08-13T00:00:00.000Z",
"entry_count": 0,
"body": {
"sequence": 5,
"registry_version": 3,
"issuer": {
"name": "NIST-regulated enterprise demonstration trust root",
"key_id": "k_3793b8e35f8acac1"
},
"issued_at": "2026-08-06T00:00:00.000Z",
"next_update_due": "2026-08-13T00:00:00.000Z",
"entries": [],
"spec": "corobate:revocation-list:1"
}
}
},
"governance": {
"digest": "sha256:8b0a45a27fcce9c1c243c764e855e67c6fe6dfd7f02a563bd90809b419731905",
"signed": true,
"actor_trust": "FLOOR_TO_SELLER_ASSERTED",
"outcome_trial_weight": 1,
"max_reingest_depth": 3,
"release_quorum_m": 2,
"release_quorum_n": 3,
"risk_acceptance_margin_bp": 500,
"risk_acceptance_max_days": 30,
"risk_acceptance_authority_cents": {
"SUPERVISOR": 1000000,
"MANAGER": 25000000,
"DIRECTOR": 500000000,
"OFFICER": 5000000000
},
"template_author_roles": [
"MANAGER",
"DIRECTOR",
"OFFICER"
]
},
"observers_attested": 5,
"outcomes": {
"attestations_counted": 0,
"attestations_recorded": 0,
"records_with_outcomes": 0
},
"lineage": {
"corroborations_counted": 0,
"corroborations_discounted": 0,
"records_with_discounted_corroborations": 0
},
"reingest": {
"records": 0,
"max_depth": 0,
"weakest_class": null,
"chain_weakest_bp": 10000,
"chain": []
},
"template": null
}
}
}One document arrived: an external red team's evaluation. It reports a LOWER score than the system reported about itself, and it is the one that satisfies the requirement — because the requirement was never about the number.
- Subject
- ai-system:TRIAGE-ASSISTANT-V4
- Question
- May this AI system be deployed to triage citizen-facing casework?
- Exposure
- $1,400,000
- Instruments
- National Institute of Standards and Technology · National Institute of Standards and Technology
- Outcome
- APPROVE — the action may proceed
- Receipt
- sha256:c344f0bbd85452f2a504d682b85270eccef70039d8abc41090c18d33e17b94d1
The gate variables this decision ran under — a dial per question, read back off the sealed receipt
control assessmentrequired
incident response plan testrequired
model evaluationrequired
penetration testrequired
security resilience evaluationrequired
vulnerability scanrequired
Every bar above was re-derived from the regulatory bindings inside this receipt’s hashed body, not from the configuration that produced it. A bar in grey is a setting no instrument made — the deploying organisation’s own default, which still binds and is not an absence. A bar position renders an ordinal on a declared ladder: it is a way to draw a control and to compare two settings on the same axis, and it is not a measurement. The value printed beside each bar is the authoritative one.
Whoever must act now
The engineer with the deployment in their hands, the release manager, the person who must publish or hold.
One instruction and the reason in words. No score, no money, no signatures.
Seven or eight fields, and not one of them is a number somebody can argue with. This person is not being asked to re-judge the evidence; somebody already did, and it is on the record.
The scoped copy itself — partial — something outside this role’s remit was removed
{
"spec": "corobate:role-view:2",
"role": "OPERATOR",
"purpose": "Whoever must act on this decision now — release the goods, fund the draw, dispatch the agent, ship the title. Sees one instruction and the reason in plain words, and nothing that could be argued about while somebody waits.",
"is_a_receipt": false,
"warning": "This is a SCOPED COPY of a sealed decision, not the decision record itself. It will not verify as a receipt and must not be presented as one. To confirm it is faithful, recompute its `view` digest under the same canonicalisation that produces receipt_hash and compare it with the entry for this role in the source receipt’s `views` block.",
"derived_from": {
"receipt_hash": "sha256:c344f0bbd85452f2a504d682b85270eccef70039d8abc41090c18d33e17b94d1",
"entry_hash": "sha256:b55a572b8c628ac13f33499905dac7c6bd9f4cfa33c14f5b40eb5f789ad4f04f",
"issued_at": "2026-08-08T16:00:00.000Z"
},
"view_digest": "sha256:51ee16a5792728e4497078fe19c6628a0c8e8cc7f1d568beed94cda17400d528",
"withheld": {
"anything_withheld": true,
"note": "Facts outside this role’s remit were removed. That something was removed is stated so a partial record is never mistaken for a complete one. How much, and what, is not stated — a count is an inference about the part you are not entitled to see."
},
"view": {
"spec": "urn:ietf:params:corobate:receipt:1",
"receipt_version": "1.8",
"issued_at": "2026-08-08T16:00:00.000Z",
"decision": {
"id": "ai_TRIAGE_V4_after",
"subject": "ai-system:TRIAGE-ASSISTANT-V4"
},
"memory": {
"state_digest": "sha256:d8c970114e57738a62465be9287d7045cd8966caeb801154d420321a11451dcc",
"ledger_head": "sha256:b883e583bf7eac8664664c008b4556f5e62ef70a681669c550a6d84ccad602fc",
"coverage_gaps": []
},
"verdict": {
"value": "APPROVE"
},
"release": {
"state": "NOT_REQUIRED"
}
}
}Provider / assessed party
The cloud service provider, the release team, or the party operating the AI system — whoever is being assessed.
Sees which controls were required of them and by which publication and control identifier. Does not see the authorising official’s exposure figure or how any shortfall was priced.
What is outstanding on your file
Nothing. Every required item is present and current.
| Claim | Required | Evidence class | Who | Age | Outcome |
|---|---|---|---|---|---|
| vulnerability_scan | yes | VERIFIED | — | 2026-08-04 | admitted |
| incident_response_plan_test | yes | VERIFIED | — | 2026-06-24 | admitted |
| model_evaluation | yes | VERIFIED | — | 2026-07-19 | admitted |
| security_resilience_evaluation | yes | VERIFIED | — | 2026-07-09 | admitted |
| penetration_test | yes | VERIFIED | — | 2026-06-09 | admitted |
| control_assessment | yes | VERIFIED | — | 2026-04-30 | admitted |
| model_self_report | no | SELLER-ASSERTED | — | 2026-07-30 | withheld |
The clause is here because it turns an argument into an errand. What is not here: what the bank had at stake, and whether anyone priced the shortfall.
The scoped copy itself — partial — something outside this role’s remit was removed
{
"spec": "corobate:role-view:2",
"role": "SUPPLIER",
"purpose": "The party whose evidence was judged. Sees every claim the decision required, which fell short, and the clause that required it — and nothing about what the buyer had at stake or how the buyer priced any shortfall. NOTE, because an earlier draft of this sentence was untrue: this projection carries the WHOLE inputs array, so where several parties supplied evidence for one decision, each of them sees all of it. Per-party scoping cannot be expressed by a commitment scheme with one digest per role, and claiming it anyway would be the kind of promise this file exists to stop making.",
"is_a_receipt": false,
"warning": "This is a SCOPED COPY of a sealed decision, not the decision record itself. It will not verify as a receipt and must not be presented as one. To confirm it is faithful, recompute its `view` digest under the same canonicalisation that produces receipt_hash and compare it with the entry for this role in the source receipt’s `views` block.",
"derived_from": {
"receipt_hash": "sha256:c344f0bbd85452f2a504d682b85270eccef70039d8abc41090c18d33e17b94d1",
"entry_hash": "sha256:b55a572b8c628ac13f33499905dac7c6bd9f4cfa33c14f5b40eb5f789ad4f04f",
"issued_at": "2026-08-08T16:00:00.000Z"
},
"view_digest": "sha256:8baf1b2ef73d519ae44f14cbe6d59a5c7c77b9bb8e911f5f3850de5bdad6b41f",
"withheld": {
"anything_withheld": true,
"note": "Facts outside this role’s remit were removed. That something was removed is stated so a partial record is never mistaken for a complete one. How much, and what, is not stated — a count is an inference about the part you are not entitled to see."
},
"view": {
"spec": "urn:ietf:params:corobate:receipt:1",
"receipt_version": "1.8",
"issued_at": "2026-08-08T16:00:00.000Z",
"decision": {
"id": "ai_TRIAGE_V4_after",
"subject": "ai-system:TRIAGE-ASSISTANT-V4",
"question": "May this AI system be deployed to triage citizen-facing casework?"
},
"memory": {
"state_digest": "sha256:d8c970114e57738a62465be9287d7045cd8966caeb801154d420321a11451dcc",
"ledger_head": "sha256:b883e583bf7eac8664664c008b4556f5e62ef70a681669c550a6d84ccad602fc",
"coverage_gaps": []
},
"verdict": {
"value": "APPROVE"
},
"inputs": [
{
"key": "ai-system:TRIAGE-ASSISTANT-V4::vulnerability_scan",
"provenance": "VERIFIED",
"observed_at": "2026-08-04T16:00:00.000Z",
"memory_status": "admitted",
"critical": true
},
{
"key": "ai-system:TRIAGE-ASSISTANT-V4::incident_response_plan_test",
"provenance": "VERIFIED",
"observed_at": "2026-06-24T16:00:00.000Z",
"memory_status": "admitted",
"critical": true
},
{
"key": "ai-system:TRIAGE-ASSISTANT-V4::model_evaluation",
"provenance": "VERIFIED",
"observed_at": "2026-07-19T16:00:00.000Z",
"memory_status": "admitted",
"critical": true
},
{
"key": "ai-system:TRIAGE-ASSISTANT-V4::security_resilience_evaluation",
"provenance": "VERIFIED",
"observed_at": "2026-07-09T16:00:00.000Z",
"memory_status": "admitted",
"critical": true
},
{
"key": "ai-system:TRIAGE-ASSISTANT-V4::penetration_test",
"provenance": "VERIFIED",
"observed_at": "2026-06-09T16:00:00.000Z",
"memory_status": "admitted",
"critical": true
},
{
"key": "ai-system:TRIAGE-ASSISTANT-V4::control_assessment",
"provenance": "VERIFIED",
"observed_at": "2026-04-30T16:00:00.000Z",
"memory_status": "admitted",
"critical": true
},
{
"key": "ai-system:TRIAGE-ASSISTANT-V4::model_self_report",
"provenance": "SELLER-ASSERTED",
"observed_at": "2026-07-30T16:00:00.000Z",
"memory_status": "withheld",
"critical": false
}
],
"regulatory": {
"bindings": [
{
"claim": "control_assessment",
"requirement": "max_age_days",
"value": 365,
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
"instrument_id": "nist-sp-800-53r5-moderate",
"version": 5,
"edition": "Rev. 5",
"citation": "CA-2 [VERIFY]",
"source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "control_assessment",
"requirement": "min_class",
"value": "VERIFIED",
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
"instrument_id": "nist-sp-800-53r5-moderate",
"version": 5,
"edition": "Rev. 5",
"citation": "CA-2(1) independent assessors [VERIFY]",
"source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "control_assessment",
"requirement": "required",
"value": true,
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
"instrument_id": "nist-sp-800-53r5-moderate",
"version": 5,
"edition": "Rev. 5",
"citation": "CA-2 [VERIFY]",
"source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "incident_response_plan_test",
"requirement": "required",
"value": true,
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "AI Risk Management Framework 1.0",
"instrument_id": "nist-ai-rmf-1-0",
"version": 1,
"edition": "1.0",
"citation": "MANAGE-4.1 [VERIFY]",
"source_digest": "sha256:a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "model_evaluation",
"requirement": "max_age_days",
"value": 180,
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "AI Risk Management Framework 1.0",
"instrument_id": "nist-ai-rmf-1-0",
"version": 1,
"edition": "1.0",
"citation": "MEASURE-2.3 [VERIFY]",
"source_digest": "sha256:a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "model_evaluation",
"requirement": "min_class",
"value": "VERIFIED",
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "AI Risk Management Framework 1.0",
"instrument_id": "nist-ai-rmf-1-0",
"version": 1,
"edition": "1.0",
"citation": "MEASURE-2.3 independent evaluation [VERIFY]",
"source_digest": "sha256:a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "model_evaluation",
"requirement": "required",
"value": true,
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "AI Risk Management Framework 1.0",
"instrument_id": "nist-ai-rmf-1-0",
"version": 1,
"edition": "1.0",
"citation": "MEASURE-2.3 [VERIFY]",
"source_digest": "sha256:a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "penetration_test",
"requirement": "min_class",
"value": "VERIFIED",
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
"instrument_id": "nist-sp-800-53r5-moderate",
"version": 5,
"edition": "Rev. 5",
"citation": "CA-8(1) independent penetration agent [VERIFY]",
"source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "penetration_test",
"requirement": "required",
"value": true,
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
"instrument_id": "nist-sp-800-53r5-moderate",
"version": 5,
"edition": "Rev. 5",
"citation": "CA-8 [VERIFY]",
"source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "security_resilience_evaluation",
"requirement": "required",
"value": true,
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "AI Risk Management Framework 1.0",
"instrument_id": "nist-ai-rmf-1-0",
"version": 1,
"edition": "1.0",
"citation": "MEASURE-2.7 [VERIFY]",
"source_digest": "sha256:a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "vulnerability_scan",
"requirement": "max_age_days",
"value": 30,
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
"instrument_id": "nist-sp-800-53r5-moderate",
"version": 5,
"edition": "Rev. 5",
"citation": "RA-5(a) [VERIFY]",
"source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "vulnerability_scan",
"requirement": "required",
"value": true,
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
"instrument_id": "nist-sp-800-53r5-moderate",
"version": 5,
"edition": "Rev. 5",
"citation": "RA-5 [VERIFY]",
"source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
}
],
"applied": [
{
"instrument_id": "nist-ai-rmf-1-0",
"version": 1,
"authority": "National Institute of Standards and Technology",
"instrument": "AI Risk Management Framework 1.0",
"edition": "1.0",
"citation": "MEASURE-2.3, MEASURE-2.7, MANAGE-2.2 [VERIFY]",
"source_digest": "sha256:a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1",
"entered_by": "actor:human:issm",
"entered_at": "2026-08-08T16:00:00.000Z"
},
{
"instrument_id": "nist-sp-800-53r5-moderate",
"version": 5,
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
"edition": "Rev. 5",
"citation": "CA-2, CA-8, RA-5, SR-6 [VERIFY]",
"source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353",
"entered_by": "actor:human:issm",
"entered_at": "2026-08-08T16:00:00.000Z"
}
],
"defaults": [
{
"claim": "control_assessment",
"requirement": "ai_position",
"value": "ADMIT",
"because": "No instrument in force stated a position on AI-authored evidence for \"control_assessment\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
},
{
"claim": "incident_response_plan_test",
"requirement": "ai_position",
"value": "ADMIT",
"because": "No instrument in force stated a position on AI-authored evidence for \"incident_response_plan_test\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
},
{
"claim": "model_evaluation",
"requirement": "ai_position",
"value": "ADMIT",
"because": "No instrument in force stated a position on AI-authored evidence for \"model_evaluation\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
},
{
"claim": "penetration_test",
"requirement": "ai_position",
"value": "ADMIT",
"because": "No instrument in force stated a position on AI-authored evidence for \"penetration_test\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
},
{
"claim": "security_resilience_evaluation",
"requirement": "ai_position",
"value": "ADMIT",
"because": "No instrument in force stated a position on AI-authored evidence for \"security_resilience_evaluation\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
},
{
"claim": "vulnerability_scan",
"requirement": "ai_position",
"value": "ADMIT",
"because": "No instrument in force stated a position on AI-authored evidence for \"vulnerability_scan\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
}
]
}
}
}Assessor / authorising official
A third-party assessment organisation, an agency assessor, or an inspector general reviewing the package. Same position as a customs officer: a public mandate over the record.
The control record in full — each publication by control identifier, edition and document digest, and every required claim with who supplied it and when. No exposure figure, no risk pricing, no confidence score.
What each authority bound
| Claim | Requirement | Level | Bound by |
|---|---|---|---|
| control_assessment | max age days | 365 | National Institute of Standards and Technology CA-2 [VERIFY] · SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline) |
| control_assessment | min class | VERIFIED | National Institute of Standards and Technology CA-2(1) independent assessors [VERIFY] · SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline) |
| control_assessment | required | true | National Institute of Standards and Technology CA-2 [VERIFY] · SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline) |
| incident_response_plan_test | required | true | National Institute of Standards and Technology MANAGE-4.1 [VERIFY] · AI Risk Management Framework 1.0 |
| model_evaluation | max age days | 180 | National Institute of Standards and Technology MEASURE-2.3 [VERIFY] · AI Risk Management Framework 1.0 |
| model_evaluation | min class | VERIFIED | National Institute of Standards and Technology MEASURE-2.3 independent evaluation [VERIFY] · AI Risk Management Framework 1.0 |
| model_evaluation | required | true | National Institute of Standards and Technology MEASURE-2.3 [VERIFY] · AI Risk Management Framework 1.0 |
| penetration_test | min class | VERIFIED | National Institute of Standards and Technology CA-8(1) independent penetration agent [VERIFY] · SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline) |
| penetration_test | required | true | National Institute of Standards and Technology CA-8 [VERIFY] · SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline) |
| security_resilience_evaluation | required | true | National Institute of Standards and Technology MEASURE-2.7 [VERIFY] · AI Risk Management Framework 1.0 |
| vulnerability_scan | max age days | 30 | National Institute of Standards and Technology RA-5(a) [VERIFY] · SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline) |
| vulnerability_scan | required | true | National Institute of Standards and Technology RA-5 [VERIFY] · SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline) |
Every required claim, and what was actually held
| Claim | Required | Evidence class | Who | Age | Outcome |
|---|---|---|---|---|---|
| vulnerability_scan | yes | VERIFIED | actor:sys:registry:nvd-cve | 2026-08-04 | admitted |
| incident_response_plan_test | yes | VERIFIED | actor:org:CERT-3PAO-ATLANTIC | 2026-06-24 | admitted |
| model_evaluation | yes | VERIFIED | actor:org:LAB-REDTEAM-EVAL | 2026-07-19 | admitted |
| security_resilience_evaluation | yes | VERIFIED | actor:org:LAB-NVLAP-0412 | 2026-07-09 | admitted |
| penetration_test | yes | VERIFIED | actor:org:LAB-NVLAP-0412 | 2026-06-09 | admitted |
| control_assessment | yes | VERIFIED | actor:org:CERT-3PAO-ATLANTIC | 2026-04-30 | admitted |
| model_self_report | no | SELLER-ASSERTED | actor:ai:triage-assistant-v4 | 2026-07-30 | withheld |
The scoped copy itself — partial — something outside this role’s remit was removed
{
"spec": "corobate:role-view:2",
"role": "REGULATOR",
"purpose": "An official holding a public mandate over this record — a customs officer, a bank examiner, a market conduct supervisor. Sees the regulatory record in full: their own instrument named, every required claim and whether it was met, by whom, how old. No commercial figure of any kind.",
"is_a_receipt": false,
"warning": "This is a SCOPED COPY of a sealed decision, not the decision record itself. It will not verify as a receipt and must not be presented as one. To confirm it is faithful, recompute its `view` digest under the same canonicalisation that produces receipt_hash and compare it with the entry for this role in the source receipt’s `views` block.",
"derived_from": {
"receipt_hash": "sha256:c344f0bbd85452f2a504d682b85270eccef70039d8abc41090c18d33e17b94d1",
"entry_hash": "sha256:b55a572b8c628ac13f33499905dac7c6bd9f4cfa33c14f5b40eb5f789ad4f04f",
"issued_at": "2026-08-08T16:00:00.000Z"
},
"view_digest": "sha256:32298fafe3fdc4b6bf28b177afb15207c2fc0a59d3db8f8599d92bdd8ccce5ca",
"withheld": {
"anything_withheld": true,
"note": "Facts outside this role’s remit were removed. That something was removed is stated so a partial record is never mistaken for a complete one. How much, and what, is not stated — a count is an inference about the part you are not entitled to see."
},
"view": {
"spec": "urn:ietf:params:corobate:receipt:1",
"receipt_version": "1.8",
"issued_at": "2026-08-08T16:00:00.000Z",
"decision": {
"id": "ai_TRIAGE_V4_after",
"subject": "ai-system:TRIAGE-ASSISTANT-V4",
"question": "May this AI system be deployed to triage citizen-facing casework?"
},
"memory": {
"state_digest": "sha256:d8c970114e57738a62465be9287d7045cd8966caeb801154d420321a11451dcc",
"ledger_head": "sha256:b883e583bf7eac8664664c008b4556f5e62ef70a681669c550a6d84ccad602fc",
"coverage_gaps": []
},
"data_horizon": "2026-08-08T16:00:00.000Z",
"verdict": {
"value": "APPROVE"
},
"regulatory": {
"spec": "corobate:regulatory:2",
"resolved": true,
"applied": [
{
"instrument_id": "nist-ai-rmf-1-0",
"version": 1,
"authority": "National Institute of Standards and Technology",
"instrument": "AI Risk Management Framework 1.0",
"edition": "1.0",
"citation": "MEASURE-2.3, MEASURE-2.7, MANAGE-2.2 [VERIFY]",
"source_digest": "sha256:a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1",
"entered_by": "actor:human:issm",
"entered_at": "2026-08-08T16:00:00.000Z"
},
{
"instrument_id": "nist-sp-800-53r5-moderate",
"version": 5,
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
"edition": "Rev. 5",
"citation": "CA-2, CA-8, RA-5, SR-6 [VERIFY]",
"source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353",
"entered_by": "actor:human:issm",
"entered_at": "2026-08-08T16:00:00.000Z"
}
],
"skipped": [],
"conflicts": [],
"bindings": [
{
"claim": "control_assessment",
"requirement": "max_age_days",
"value": 365,
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
"instrument_id": "nist-sp-800-53r5-moderate",
"version": 5,
"edition": "Rev. 5",
"citation": "CA-2 [VERIFY]",
"source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "control_assessment",
"requirement": "min_class",
"value": "VERIFIED",
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
"instrument_id": "nist-sp-800-53r5-moderate",
"version": 5,
"edition": "Rev. 5",
"citation": "CA-2(1) independent assessors [VERIFY]",
"source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "control_assessment",
"requirement": "required",
"value": true,
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
"instrument_id": "nist-sp-800-53r5-moderate",
"version": 5,
"edition": "Rev. 5",
"citation": "CA-2 [VERIFY]",
"source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "incident_response_plan_test",
"requirement": "required",
"value": true,
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "AI Risk Management Framework 1.0",
"instrument_id": "nist-ai-rmf-1-0",
"version": 1,
"edition": "1.0",
"citation": "MANAGE-4.1 [VERIFY]",
"source_digest": "sha256:a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "model_evaluation",
"requirement": "max_age_days",
"value": 180,
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "AI Risk Management Framework 1.0",
"instrument_id": "nist-ai-rmf-1-0",
"version": 1,
"edition": "1.0",
"citation": "MEASURE-2.3 [VERIFY]",
"source_digest": "sha256:a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "model_evaluation",
"requirement": "min_class",
"value": "VERIFIED",
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "AI Risk Management Framework 1.0",
"instrument_id": "nist-ai-rmf-1-0",
"version": 1,
"edition": "1.0",
"citation": "MEASURE-2.3 independent evaluation [VERIFY]",
"source_digest": "sha256:a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "model_evaluation",
"requirement": "required",
"value": true,
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "AI Risk Management Framework 1.0",
"instrument_id": "nist-ai-rmf-1-0",
"version": 1,
"edition": "1.0",
"citation": "MEASURE-2.3 [VERIFY]",
"source_digest": "sha256:a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "penetration_test",
"requirement": "min_class",
"value": "VERIFIED",
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
"instrument_id": "nist-sp-800-53r5-moderate",
"version": 5,
"edition": "Rev. 5",
"citation": "CA-8(1) independent penetration agent [VERIFY]",
"source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "penetration_test",
"requirement": "required",
"value": true,
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
"instrument_id": "nist-sp-800-53r5-moderate",
"version": 5,
"edition": "Rev. 5",
"citation": "CA-8 [VERIFY]",
"source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "security_resilience_evaluation",
"requirement": "required",
"value": true,
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "AI Risk Management Framework 1.0",
"instrument_id": "nist-ai-rmf-1-0",
"version": 1,
"edition": "1.0",
"citation": "MEASURE-2.7 [VERIFY]",
"source_digest": "sha256:a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "vulnerability_scan",
"requirement": "max_age_days",
"value": 30,
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
"instrument_id": "nist-sp-800-53r5-moderate",
"version": 5,
"edition": "Rev. 5",
"citation": "RA-5(a) [VERIFY]",
"source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "vulnerability_scan",
"requirement": "required",
"value": true,
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
"instrument_id": "nist-sp-800-53r5-moderate",
"version": 5,
"edition": "Rev. 5",
"citation": "RA-5 [VERIFY]",
"source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
}
],
"defaults": [
{
"claim": "control_assessment",
"requirement": "ai_position",
"value": "ADMIT",
"because": "No instrument in force stated a position on AI-authored evidence for \"control_assessment\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
},
{
"claim": "incident_response_plan_test",
"requirement": "ai_position",
"value": "ADMIT",
"because": "No instrument in force stated a position on AI-authored evidence for \"incident_response_plan_test\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
},
{
"claim": "model_evaluation",
"requirement": "ai_position",
"value": "ADMIT",
"because": "No instrument in force stated a position on AI-authored evidence for \"model_evaluation\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
},
{
"claim": "penetration_test",
"requirement": "ai_position",
"value": "ADMIT",
"because": "No instrument in force stated a position on AI-authored evidence for \"penetration_test\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
},
{
"claim": "security_resilience_evaluation",
"requirement": "ai_position",
"value": "ADMIT",
"because": "No instrument in force stated a position on AI-authored evidence for \"security_resilience_evaluation\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
},
{
"claim": "vulnerability_scan",
"requirement": "ai_position",
"value": "ADMIT",
"because": "No instrument in force stated a position on AI-authored evidence for \"vulnerability_scan\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
}
]
},
"inputs": [
{
"key": "ai-system:TRIAGE-ASSISTANT-V4::vulnerability_scan",
"provenance": "VERIFIED",
"source": "nvd-cve:vulnerability_scan",
"observed_at": "2026-08-04T16:00:00.000Z",
"critical": true,
"memory_status": "admitted",
"memory_actor": "actor:sys:registry:nvd-cve"
},
{
"key": "ai-system:TRIAGE-ASSISTANT-V4::incident_response_plan_test",
"provenance": "VERIFIED",
"source": "CERT-3PAO-ATLANTIC:incident_response_plan_test",
"observed_at": "2026-06-24T16:00:00.000Z",
"critical": true,
"memory_status": "admitted",
"memory_actor": "actor:org:CERT-3PAO-ATLANTIC"
},
{
"key": "ai-system:TRIAGE-ASSISTANT-V4::model_evaluation",
"provenance": "VERIFIED",
"source": "LAB-REDTEAM-EVAL:model_evaluation",
"observed_at": "2026-07-19T16:00:00.000Z",
"critical": true,
"memory_status": "admitted",
"memory_actor": "actor:org:LAB-REDTEAM-EVAL"
},
{
"key": "ai-system:TRIAGE-ASSISTANT-V4::security_resilience_evaluation",
"provenance": "VERIFIED",
"source": "LAB-NVLAP-0412:security_resilience_evaluation",
"observed_at": "2026-07-09T16:00:00.000Z",
"critical": true,
"memory_status": "admitted",
"memory_actor": "actor:org:LAB-NVLAP-0412"
},
{
"key": "ai-system:TRIAGE-ASSISTANT-V4::penetration_test",
"provenance": "VERIFIED",
"source": "LAB-NVLAP-0412:penetration_test",
"observed_at": "2026-06-09T16:00:00.000Z",
"critical": true,
"memory_status": "admitted",
"memory_actor": "actor:org:LAB-NVLAP-0412"
},
{
"key": "ai-system:TRIAGE-ASSISTANT-V4::control_assessment",
"provenance": "VERIFIED",
"source": "CERT-3PAO-ATLANTIC:control_assessment",
"observed_at": "2026-04-30T16:00:00.000Z",
"critical": true,
"memory_status": "admitted",
"memory_actor": "actor:org:CERT-3PAO-ATLANTIC"
},
{
"key": "ai-system:TRIAGE-ASSISTANT-V4::model_self_report",
"provenance": "SELLER-ASSERTED",
"source": "triage-assistant-v4:model_self_report",
"observed_at": "2026-07-30T16:00:00.000Z",
"critical": false,
"memory_status": "withheld",
"memory_actor": "actor:ai:triage-assistant-v4"
}
],
"crypto_suite": {
"spec": "corobate:suite:1",
"id": "CB-1-ES256-SHA256",
"receipt_digest": "sha256",
"chain_digest": "sha256",
"content_digest": "sha256",
"envelope_signature": "ES256",
"signature_curve": "P-256",
"canonicalisation": "attest-canon/2",
"quantum_resistant": false
}
}
}ISSM / control owner
The information system security manager and the control owners who hold the package.
The fullest internal view: every input, its class, its age, its score, the exposure, and every publication in force.
Every input the gate saw
| Claim | Required | Evidence class | Who | Age | Score | Outcome |
|---|---|---|---|---|---|---|
| vulnerability_scan | yes | VERIFIED | actor:sys:registry:nvd-cve | 4d | 95% | admitted |
| incident_response_plan_test | yes | VERIFIED | actor:org:CERT-3PAO-ATLANTIC | 45d | 95% | admitted |
| model_evaluation | yes | VERIFIED | actor:org:LAB-REDTEAM-EVAL | 20d | 95% | admitted |
| security_resilience_evaluation | yes | VERIFIED | actor:org:LAB-NVLAP-0412 | 30d | 95% | admitted |
| penetration_test | yes | VERIFIED | actor:org:LAB-NVLAP-0412 | 60d | 95% | admitted |
| control_assessment | yes | VERIFIED | actor:org:CERT-3PAO-ATLANTIC | 100d | 95% | admitted |
| model_self_report | no | SELLER-ASSERTED | actor:ai:triage-assistant-v4 | 9d | 50% | withheld |
Instruments in force
Why
- Confidence 95.00% is bound by "ai-system:TRIAGE-ASSISTANT-V4|vulnerability_scan".
- 1 memory was withheld from the context block: ai-system:TRIAGE-ASSISTANT-V4|model_self_report (sparse track record: 1 independent observation(s); no failure recorded, so the class ceiling stands).
- Thresholds for $1,400,000 exposure: approve 90%, caution 70%.
The scoped copy itself — partial — something outside this role’s remit was removed
{
"spec": "corobate:role-view:2",
"role": "COMPLIANCE",
"purpose": "The operator’s own compliance function. The fullest internal view: every gap, every instrument in force, the waivability of each requirement and who accepted what.",
"is_a_receipt": false,
"warning": "This is a SCOPED COPY of a sealed decision, not the decision record itself. It will not verify as a receipt and must not be presented as one. To confirm it is faithful, recompute its `view` digest under the same canonicalisation that produces receipt_hash and compare it with the entry for this role in the source receipt’s `views` block.",
"derived_from": {
"receipt_hash": "sha256:c344f0bbd85452f2a504d682b85270eccef70039d8abc41090c18d33e17b94d1",
"entry_hash": "sha256:b55a572b8c628ac13f33499905dac7c6bd9f4cfa33c14f5b40eb5f789ad4f04f",
"issued_at": "2026-08-08T16:00:00.000Z"
},
"view_digest": "sha256:4f2aacb1ebf1da5dd26a81387f4ca2e5cedbc2276ba43c1c37fe3d2d4165ef3b",
"withheld": {
"anything_withheld": true,
"note": "Facts outside this role’s remit were removed. That something was removed is stated so a partial record is never mistaken for a complete one. How much, and what, is not stated — a count is an inference about the part you are not entitled to see."
},
"view": {
"spec": "urn:ietf:params:corobate:receipt:1",
"receipt_version": "1.8",
"issued_at": "2026-08-08T16:00:00.000Z",
"decision": {
"id": "ai_TRIAGE_V4_after",
"domain": "supply-chain",
"subject": "ai-system:TRIAGE-ASSISTANT-V4",
"question": "May this AI system be deployed to triage citizen-facing casework?"
},
"memory": {
"state_digest": "sha256:d8c970114e57738a62465be9287d7045cd8966caeb801154d420321a11451dcc",
"ledger_head": "sha256:b883e583bf7eac8664664c008b4556f5e62ef70a681669c550a6d84ccad602fc",
"coverage_gaps": [],
"exposure": {
"usd": 1400000,
"declared_by": "actor:human:ao-authorizing-official",
"ledger_seq": 7
},
"policy_digest": "sha256:a6b69b7d20f7fb04d522364af1d92992058b04a5835fcec9d1c9f2261c7ef636"
},
"data_horizon": "2026-08-08T16:00:00.000Z",
"verdict": {
"value": "APPROVE",
"threshold_approve": 0.9,
"threshold_caution": 0.7,
"rule": "confidence>=threshold"
},
"confidence": {
"value": 0.95,
"method": "min-over-critical-inputs",
"bound_by": "ai-system:TRIAGE-ASSISTANT-V4::vulnerability_scan"
},
"release": {
"required": false,
"required_by_tier": false,
"escalated_by_acceptance": false,
"risk_accepted": false,
"state": "NOT_REQUIRED",
"code": "QUORUM_NOT_REQUIRED",
"reason": "this decision is below the top exposure tier (floor $10,000,000) and no risk acceptance escalated into this gate, so no multi-party release requirement applies.",
"tier_floor_cents": 1000000000,
"exposure_usd_cents": 140000000,
"required_m": 2,
"declared_n": 3,
"floor_m": 2,
"distinct_signers": 0,
"superseded": 0,
"collapsed": 0,
"release_digest": "sha256:4ad3faa1a749da2c56339fa29e711571515a647ee4c4d9a29d41aa2251bff28a",
"governance_digest": "sha256:8b0a45a27fcce9c1c243c764e855e67c6fe6dfd7f02a563bd90809b419731905",
"governance_signed": true,
"counted_voices": [],
"signatures": [],
"ledger_seq": null
},
"acceptance": {
"state": "NONE",
"code": "ACCEPTANCE_NONE",
"reason": "no risk acceptance was presented for this decision. This is the ordinary case: a refusal is a refusal unless a named person has priced it.",
"permitted_basis": null,
"presented": 0,
"superseded": 0,
"expired": 0,
"gaps_not_covered": 0,
"coverage_gaps_in_force": [],
"evidentiary_digest": "sha256:4ad3faa1a749da2c56339fa29e711571515a647ee4c4d9a29d41aa2251bff28a",
"margin_floor_bp": 100,
"authority_ceiling_cents": {
"SUPERVISOR": 1000000,
"MANAGER": 25000000,
"DIRECTOR": 500000000,
"OFFICER": 5000000000
},
"acceptances": [],
"escalated": false,
"live": false,
"ledger_seq": null
},
"regulatory": {
"spec": "corobate:regulatory:2",
"resolved": true,
"applied": [
{
"instrument_id": "nist-ai-rmf-1-0",
"version": 1,
"authority": "National Institute of Standards and Technology",
"instrument": "AI Risk Management Framework 1.0",
"edition": "1.0",
"citation": "MEASURE-2.3, MEASURE-2.7, MANAGE-2.2 [VERIFY]",
"source_digest": "sha256:a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1",
"entered_by": "actor:human:issm",
"entered_at": "2026-08-08T16:00:00.000Z"
},
{
"instrument_id": "nist-sp-800-53r5-moderate",
"version": 5,
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
"edition": "Rev. 5",
"citation": "CA-2, CA-8, RA-5, SR-6 [VERIFY]",
"source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353",
"entered_by": "actor:human:issm",
"entered_at": "2026-08-08T16:00:00.000Z"
}
],
"skipped": [],
"conflicts": [],
"bindings": [
{
"claim": "control_assessment",
"requirement": "max_age_days",
"value": 365,
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
"instrument_id": "nist-sp-800-53r5-moderate",
"version": 5,
"edition": "Rev. 5",
"citation": "CA-2 [VERIFY]",
"source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "control_assessment",
"requirement": "min_class",
"value": "VERIFIED",
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
"instrument_id": "nist-sp-800-53r5-moderate",
"version": 5,
"edition": "Rev. 5",
"citation": "CA-2(1) independent assessors [VERIFY]",
"source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "control_assessment",
"requirement": "required",
"value": true,
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
"instrument_id": "nist-sp-800-53r5-moderate",
"version": 5,
"edition": "Rev. 5",
"citation": "CA-2 [VERIFY]",
"source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "incident_response_plan_test",
"requirement": "required",
"value": true,
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "AI Risk Management Framework 1.0",
"instrument_id": "nist-ai-rmf-1-0",
"version": 1,
"edition": "1.0",
"citation": "MANAGE-4.1 [VERIFY]",
"source_digest": "sha256:a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "model_evaluation",
"requirement": "max_age_days",
"value": 180,
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "AI Risk Management Framework 1.0",
"instrument_id": "nist-ai-rmf-1-0",
"version": 1,
"edition": "1.0",
"citation": "MEASURE-2.3 [VERIFY]",
"source_digest": "sha256:a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "model_evaluation",
"requirement": "min_class",
"value": "VERIFIED",
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "AI Risk Management Framework 1.0",
"instrument_id": "nist-ai-rmf-1-0",
"version": 1,
"edition": "1.0",
"citation": "MEASURE-2.3 independent evaluation [VERIFY]",
"source_digest": "sha256:a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "model_evaluation",
"requirement": "required",
"value": true,
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "AI Risk Management Framework 1.0",
"instrument_id": "nist-ai-rmf-1-0",
"version": 1,
"edition": "1.0",
"citation": "MEASURE-2.3 [VERIFY]",
"source_digest": "sha256:a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "penetration_test",
"requirement": "min_class",
"value": "VERIFIED",
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
"instrument_id": "nist-sp-800-53r5-moderate",
"version": 5,
"edition": "Rev. 5",
"citation": "CA-8(1) independent penetration agent [VERIFY]",
"source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "penetration_test",
"requirement": "required",
"value": true,
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
"instrument_id": "nist-sp-800-53r5-moderate",
"version": 5,
"edition": "Rev. 5",
"citation": "CA-8 [VERIFY]",
"source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "security_resilience_evaluation",
"requirement": "required",
"value": true,
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "AI Risk Management Framework 1.0",
"instrument_id": "nist-ai-rmf-1-0",
"version": 1,
"edition": "1.0",
"citation": "MEASURE-2.7 [VERIFY]",
"source_digest": "sha256:a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "vulnerability_scan",
"requirement": "max_age_days",
"value": 30,
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
"instrument_id": "nist-sp-800-53r5-moderate",
"version": 5,
"edition": "Rev. 5",
"citation": "RA-5(a) [VERIFY]",
"source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "vulnerability_scan",
"requirement": "required",
"value": true,
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
"instrument_id": "nist-sp-800-53r5-moderate",
"version": 5,
"edition": "Rev. 5",
"citation": "RA-5 [VERIFY]",
"source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
}
],
"defaults": [
{
"claim": "control_assessment",
"requirement": "ai_position",
"value": "ADMIT",
"because": "No instrument in force stated a position on AI-authored evidence for \"control_assessment\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
},
{
"claim": "incident_response_plan_test",
"requirement": "ai_position",
"value": "ADMIT",
"because": "No instrument in force stated a position on AI-authored evidence for \"incident_response_plan_test\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
},
{
"claim": "model_evaluation",
"requirement": "ai_position",
"value": "ADMIT",
"because": "No instrument in force stated a position on AI-authored evidence for \"model_evaluation\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
},
{
"claim": "penetration_test",
"requirement": "ai_position",
"value": "ADMIT",
"because": "No instrument in force stated a position on AI-authored evidence for \"penetration_test\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
},
{
"claim": "security_resilience_evaluation",
"requirement": "ai_position",
"value": "ADMIT",
"because": "No instrument in force stated a position on AI-authored evidence for \"security_resilience_evaluation\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
},
{
"claim": "vulnerability_scan",
"requirement": "ai_position",
"value": "ADMIT",
"because": "No instrument in force stated a position on AI-authored evidence for \"vulnerability_scan\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
}
]
},
"reasons": [
"Confidence 95.00% is bound by \"ai-system:TRIAGE-ASSISTANT-V4|vulnerability_scan\".",
"1 memory was withheld from the context block: ai-system:TRIAGE-ASSISTANT-V4|model_self_report (sparse track record: 1 independent observation(s); no failure recorded, so the class ceiling stands).",
"Thresholds for $1,400,000 exposure: approve 90%, caution 70%."
],
"inputs": [
{
"key": "ai-system:TRIAGE-ASSISTANT-V4::vulnerability_scan",
"value": "clean-at-scan",
"provenance": "VERIFIED",
"source": "nvd-cve:vulnerability_scan",
"observed_at": "2026-08-04T16:00:00.000Z",
"reliability": 0.95,
"critical": true,
"memory_status": "admitted",
"memory_kind": "status",
"memory_actor": "actor:sys:registry:nvd-cve",
"memory_age_days": 4
},
{
"key": "ai-system:TRIAGE-ASSISTANT-V4::incident_response_plan_test",
"value": "observed",
"provenance": "VERIFIED",
"source": "CERT-3PAO-ATLANTIC:incident_response_plan_test",
"observed_at": "2026-06-24T16:00:00.000Z",
"reliability": 0.95,
"critical": true,
"memory_status": "admitted",
"memory_kind": "certificate",
"memory_actor": "actor:org:CERT-3PAO-ATLANTIC",
"memory_age_days": 45
},
{
"key": "ai-system:TRIAGE-ASSISTANT-V4::model_evaluation",
"value": "independent",
"provenance": "VERIFIED",
"source": "LAB-REDTEAM-EVAL:model_evaluation",
"observed_at": "2026-07-19T16:00:00.000Z",
"reliability": 0.95,
"critical": true,
"memory_status": "admitted",
"memory_kind": "test_report",
"memory_actor": "actor:org:LAB-REDTEAM-EVAL",
"memory_age_days": 20
},
{
"key": "ai-system:TRIAGE-ASSISTANT-V4::security_resilience_evaluation",
"value": "assessed",
"provenance": "VERIFIED",
"source": "LAB-NVLAP-0412:security_resilience_evaluation",
"observed_at": "2026-07-09T16:00:00.000Z",
"reliability": 0.95,
"critical": true,
"memory_status": "admitted",
"memory_kind": "test_report",
"memory_actor": "actor:org:LAB-NVLAP-0412",
"memory_age_days": 30
},
{
"key": "ai-system:TRIAGE-ASSISTANT-V4::penetration_test",
"value": "no-critical",
"provenance": "VERIFIED",
"source": "LAB-NVLAP-0412:penetration_test",
"observed_at": "2026-06-09T16:00:00.000Z",
"reliability": 0.95,
"critical": true,
"memory_status": "admitted",
"memory_kind": "test_report",
"memory_actor": "actor:org:LAB-NVLAP-0412",
"memory_age_days": 60
},
{
"key": "ai-system:TRIAGE-ASSISTANT-V4::control_assessment",
"value": "satisfied",
"provenance": "VERIFIED",
"source": "CERT-3PAO-ATLANTIC:control_assessment",
"observed_at": "2026-04-30T16:00:00.000Z",
"reliability": 0.95,
"critical": true,
"memory_status": "admitted",
"memory_kind": "certificate",
"memory_actor": "actor:org:CERT-3PAO-ATLANTIC",
"memory_age_days": 100
},
{
"key": "ai-system:TRIAGE-ASSISTANT-V4::model_self_report",
"value": null,
"provenance": "SELLER-ASSERTED",
"source": "triage-assistant-v4:model_self_report",
"observed_at": "2026-07-30T16:00:00.000Z",
"reliability": 0.5,
"critical": false,
"memory_status": "withheld",
"memory_kind": "test_report",
"memory_actor": "actor:ai:triage-assistant-v4",
"memory_age_days": 9
}
],
"crypto_suite": {
"spec": "corobate:suite:1",
"id": "CB-1-ES256-SHA256",
"receipt_digest": "sha256",
"chain_digest": "sha256",
"content_digest": "sha256",
"envelope_signature": "ES256",
"signature_curve": "P-256",
"canonicalisation": "attest-canon/2",
"quantum_resistant": false
}
}
}Authorising official (signer)
The named official whose signature carries the authorisation decision.
What is at stake, what the evidence supports, what is missing, and the digest they are signing over.
You are being asked to sign
May this AI system be deployed to triage citizen-facing casework?
The signature is over the STATE OF THE EVIDENCE. Move one fact behind this decision and the digest moves and the signature stops counting — which is what makes it safe to collect signatures before everyone is in the room.
What is missing
- Nothing required is missing.
The scoped copy itself — partial — something outside this role’s remit was removed
{
"spec": "corobate:role-view:2",
"role": "EXECUTIVE",
"purpose": "A named signer on the release gate. Sees what is at stake, what the evidence supports, who else has signed and what they are being asked to sign over.",
"is_a_receipt": false,
"warning": "This is a SCOPED COPY of a sealed decision, not the decision record itself. It will not verify as a receipt and must not be presented as one. To confirm it is faithful, recompute its `view` digest under the same canonicalisation that produces receipt_hash and compare it with the entry for this role in the source receipt’s `views` block.",
"derived_from": {
"receipt_hash": "sha256:c344f0bbd85452f2a504d682b85270eccef70039d8abc41090c18d33e17b94d1",
"entry_hash": "sha256:b55a572b8c628ac13f33499905dac7c6bd9f4cfa33c14f5b40eb5f789ad4f04f",
"issued_at": "2026-08-08T16:00:00.000Z"
},
"view_digest": "sha256:5a5e12d1f5206d731efed4c4973894c3632f1e773c2d7e939bbe76823b76156c",
"withheld": {
"anything_withheld": true,
"note": "Facts outside this role’s remit were removed. That something was removed is stated so a partial record is never mistaken for a complete one. How much, and what, is not stated — a count is an inference about the part you are not entitled to see."
},
"view": {
"spec": "urn:ietf:params:corobate:receipt:1",
"receipt_version": "1.8",
"issued_at": "2026-08-08T16:00:00.000Z",
"decision": {
"id": "ai_TRIAGE_V4_after",
"domain": "supply-chain",
"subject": "ai-system:TRIAGE-ASSISTANT-V4",
"question": "May this AI system be deployed to triage citizen-facing casework?"
},
"memory": {
"state_digest": "sha256:d8c970114e57738a62465be9287d7045cd8966caeb801154d420321a11451dcc",
"ledger_head": "sha256:b883e583bf7eac8664664c008b4556f5e62ef70a681669c550a6d84ccad602fc",
"coverage_gaps": [],
"exposure": {
"usd": 1400000,
"declared_by": "actor:human:ao-authorizing-official",
"ledger_seq": 7
}
},
"verdict": {
"value": "APPROVE",
"threshold_approve": 0.9,
"threshold_caution": 0.7,
"rule": "confidence>=threshold"
},
"confidence": {
"value": 0.95,
"method": "min-over-critical-inputs",
"bound_by": "ai-system:TRIAGE-ASSISTANT-V4::vulnerability_scan"
},
"release": {
"required": false,
"required_by_tier": false,
"escalated_by_acceptance": false,
"risk_accepted": false,
"state": "NOT_REQUIRED",
"code": "QUORUM_NOT_REQUIRED",
"reason": "this decision is below the top exposure tier (floor $10,000,000) and no risk acceptance escalated into this gate, so no multi-party release requirement applies.",
"tier_floor_cents": 1000000000,
"exposure_usd_cents": 140000000,
"required_m": 2,
"declared_n": 3,
"floor_m": 2,
"distinct_signers": 0,
"superseded": 0,
"collapsed": 0,
"release_digest": "sha256:4ad3faa1a749da2c56339fa29e711571515a647ee4c4d9a29d41aa2251bff28a",
"governance_digest": "sha256:8b0a45a27fcce9c1c243c764e855e67c6fe6dfd7f02a563bd90809b419731905",
"governance_signed": true,
"counted_voices": [],
"signatures": [],
"ledger_seq": null
},
"acceptance": {
"state": "NONE",
"code": "ACCEPTANCE_NONE",
"reason": "no risk acceptance was presented for this decision. This is the ordinary case: a refusal is a refusal unless a named person has priced it.",
"permitted_basis": null,
"presented": 0,
"superseded": 0,
"expired": 0,
"gaps_not_covered": 0,
"coverage_gaps_in_force": [],
"evidentiary_digest": "sha256:4ad3faa1a749da2c56339fa29e711571515a647ee4c4d9a29d41aa2251bff28a",
"margin_floor_bp": 100,
"authority_ceiling_cents": {
"SUPERVISOR": 1000000,
"MANAGER": 25000000,
"DIRECTOR": 500000000,
"OFFICER": 5000000000
},
"acceptances": [],
"escalated": false,
"live": false,
"ledger_seq": null
},
"reasons": [
"Confidence 95.00% is bound by \"ai-system:TRIAGE-ASSISTANT-V4|vulnerability_scan\".",
"1 memory was withheld from the context block: ai-system:TRIAGE-ASSISTANT-V4|model_self_report (sparse track record: 1 independent observation(s); no failure recorded, so the class ceiling stands).",
"Thresholds for $1,400,000 exposure: approve 90%, caution 70%."
],
"regulatory": {
"applied": [
{
"instrument_id": "nist-ai-rmf-1-0",
"version": 1,
"authority": "National Institute of Standards and Technology",
"instrument": "AI Risk Management Framework 1.0",
"edition": "1.0",
"citation": "MEASURE-2.3, MEASURE-2.7, MANAGE-2.2 [VERIFY]",
"source_digest": "sha256:a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1",
"entered_by": "actor:human:issm",
"entered_at": "2026-08-08T16:00:00.000Z"
},
{
"instrument_id": "nist-sp-800-53r5-moderate",
"version": 5,
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
"edition": "Rev. 5",
"citation": "CA-2, CA-8, RA-5, SR-6 [VERIFY]",
"source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353",
"entered_by": "actor:human:issm",
"entered_at": "2026-08-08T16:00:00.000Z"
}
],
"conflicts": [],
"defaults": [
{
"claim": "control_assessment",
"requirement": "ai_position",
"value": "ADMIT",
"because": "No instrument in force stated a position on AI-authored evidence for \"control_assessment\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
},
{
"claim": "incident_response_plan_test",
"requirement": "ai_position",
"value": "ADMIT",
"because": "No instrument in force stated a position on AI-authored evidence for \"incident_response_plan_test\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
},
{
"claim": "model_evaluation",
"requirement": "ai_position",
"value": "ADMIT",
"because": "No instrument in force stated a position on AI-authored evidence for \"model_evaluation\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
},
{
"claim": "penetration_test",
"requirement": "ai_position",
"value": "ADMIT",
"because": "No instrument in force stated a position on AI-authored evidence for \"penetration_test\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
},
{
"claim": "security_resilience_evaluation",
"requirement": "ai_position",
"value": "ADMIT",
"because": "No instrument in force stated a position on AI-authored evidence for \"security_resilience_evaluation\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
},
{
"claim": "vulnerability_scan",
"requirement": "ai_position",
"value": "ADMIT",
"because": "No instrument in force stated a position on AI-authored evidence for \"vulnerability_scan\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
}
]
},
"inputs": [
{
"key": "ai-system:TRIAGE-ASSISTANT-V4::vulnerability_scan",
"provenance": "VERIFIED",
"reliability": 0.95,
"critical": true,
"memory_status": "admitted"
},
{
"key": "ai-system:TRIAGE-ASSISTANT-V4::incident_response_plan_test",
"provenance": "VERIFIED",
"reliability": 0.95,
"critical": true,
"memory_status": "admitted"
},
{
"key": "ai-system:TRIAGE-ASSISTANT-V4::model_evaluation",
"provenance": "VERIFIED",
"reliability": 0.95,
"critical": true,
"memory_status": "admitted"
},
{
"key": "ai-system:TRIAGE-ASSISTANT-V4::security_resilience_evaluation",
"provenance": "VERIFIED",
"reliability": 0.95,
"critical": true,
"memory_status": "admitted"
},
{
"key": "ai-system:TRIAGE-ASSISTANT-V4::penetration_test",
"provenance": "VERIFIED",
"reliability": 0.95,
"critical": true,
"memory_status": "admitted"
},
{
"key": "ai-system:TRIAGE-ASSISTANT-V4::control_assessment",
"provenance": "VERIFIED",
"reliability": 0.95,
"critical": true,
"memory_status": "admitted"
},
{
"key": "ai-system:TRIAGE-ASSISTANT-V4::model_self_report",
"provenance": "SELLER-ASSERTED",
"reliability": 0.5,
"critical": false,
"memory_status": "withheld"
}
]
}
}Independent audit / IG
Internal audit, an inspector general, or an external auditor testing the programme.
Everything, plus the verifier’s own findings over the sealed record.
This view withholds nothing. What it adds is the 22 checks the published verifier ran over the sealed record behind every other view of this decision — recomputed at build time, not asserted.
| # | Check | Detail | |
|---|---|---|---|
| 1 | Content reproduces (JCS + SHA-256) | PASS | matches sha256:c344f0bbd85452f2a504d682b85270eccef70039d8abc41090c18d33e17b94d1 |
| 2 | Hash chain links (entry = H(prev||content)) | PASS | head sha256:b55a572b8c628ac13f33499905dac7c6bd9f4cfa33c14f5b40eb5f789ad4f04f |
| 3 | Confidence gated by weakest critical input | PASS | min over critical = 0.95, bound_by ai-system:TRIAGE-ASSISTANT-V4::vulnerability_scan (VERIFIED) |
| 3b | Verdict follows the threshold rule | PASS | 0.95 => APPROVE; recorded APPROVE |
| 4 | Point-in-time seal (no input past data_horizon) | PASS | all inputs <= 2026-08-08T16:00:00.000Z |
| 5 | Anchor covers the head, and the timestamp token re-reads | PASS | internally consistent; NO external anchor was requested — this is not a validated timestamp |
| 6 | Criteria travel with the receipt and reproduce | PASS | policy_body hashes to sha256:a6b69b7d20f7fb04d522364af1d92992058b04a5835fcec9d1c9f2261c7ef636 |
| 7 | Reliability re-derives from recorded evidence | PASS | all 7 inputs re-derive exactly |
| 8 | Outcome trials and lineage discounts re-derive | PASS | 7 input(s) re-derive: 0 credited outcome trial(s), 0 lineage-discounted corroboration(s); every reliability is at or under its class ceiling |
| 9 | Re-ingested receipts respect their weakest-input ceiling | PASS | no re-ingested receipts: every input rests on a primary observation |
| 10 | Release quorum re-derives | PASS | NOT_REQUIRED - below the top exposure tier, no multi-party requirement applies |
| 11 | Risk acceptance re-derives | PASS | no risk acceptance: this decision stands or falls on its evidence |
| 12 | Observer credentials were not revoked as of observation time | PASS | revocation list 5 (0 entries, issued 2026-08-06T00:00:00.000Z, next update due 2026-08-13T00:00:00.000Z) reproduces; 6 observer signature(s) judged as of their own instant, none under a key revoked as compromised or retired by then |
| 13 | The cryptographic suite is named and is one this verifier implements | PASS | sealed under CB-1-ES256-SHA256 (ES256 / sha256, attest-canon/2); this verifier implements it; the suite states it is NOT quantum resistant |
| 14 | Regulatory bindings are attributed and were enforced | PASS | 12 binding(s) from 2 instrument(s) in force, each attributed to an authority, a citation and a document digest; 6 required claim(s) all reached the gate |
| 15 | Role-view commitments re-derive, and the customs view carries no money | PASS | 6 role-view commitment(s) re-derived from this receipt’s own body by this verifier’s independent projection; the REGULATOR view carries no commercial figure |
| 16 | AI-authored input was admitted only where an authority allowed it | PASS | 0 claim(s) carry a position on AI-authored evidence set by an authority and 6 carry a recorded default nobody set; 0 exclusion(s) and 0 corroboration-only rule(s) re-derived against this receipt's own admitted inputs; 0 admitted input(s) are AI-authored by their enrolled identity |
| 17 | State digest recomputes from the ledger alone | UNVERIFIABLE | NOT APPLICABLE — you supplied no ledger, so the state digest cannot be re-derived from anything. This receipt commits to the corpus the deciding system held at the instant it sealed, and that commitment is checked by recomputing it from the append-only ledger and comparing; with no ledger in hand there is no second artefact to recompute from. The receipt is not at fault and nothing here is missing from it. Obtain the ledger from the issuer and re-run with --ledger <file>, or verifyReceipt(r, {ledger}). Nothing here has failed and nothing here has passed. |
| 18 | Registry membership re-derives for every key relied on | PASS | all 4 key(s) relied on re-derive to the entries root registry v3 committed to and the trust root signed |
| 20 | Geometric support re-derives, and an unevaluated record is not a supported one | PASS | no authority bound a metric to any claim on this receipt, so no geometric test applied. A claim nobody bound a metric to is not a claim about geometry, and this is a stated absence rather than a silent one |
| 19 | The cause of every uncovered requirement re-derives | PASS | every required claim on this receipt is covered, so this check ran and had nothing to explain |
| 21 | The sealing party is the one you were told to expect | UNVERIFIABLE | NOT APPLICABLE — you supplied no trust bundle, so nothing here establishes who sealed this. Identities 1 to 20 prove that this document agrees with itself; not one of them asks whose trust root it was sealed under, and a document that agrees with itself about a decision nobody made agrees with itself perfectly. Obtain the issuer's corobate:trust-bundle:1 out of band, confirm its spoken fingerprint with them by voice, and re-run with --trust-bundle <file> --expect-fingerprint <what you heard>. Nothing here has failed and nothing here has passed. |
The scoped copy itself — complete for this role
{
"spec": "corobate:role-view:2",
"role": "AUDITOR",
"purpose": "An external assessor. Sees the complete sealed record: this view withholds nothing and exists so the identity case is a case rather than an exception.",
"is_a_receipt": false,
"warning": "This is a SCOPED COPY of a sealed decision, not the decision record itself. It will not verify as a receipt and must not be presented as one. To confirm it is faithful, recompute its `view` digest under the same canonicalisation that produces receipt_hash and compare it with the entry for this role in the source receipt’s `views` block.",
"derived_from": {
"receipt_hash": "sha256:c344f0bbd85452f2a504d682b85270eccef70039d8abc41090c18d33e17b94d1",
"entry_hash": "sha256:b55a572b8c628ac13f33499905dac7c6bd9f4cfa33c14f5b40eb5f789ad4f04f",
"issued_at": "2026-08-08T16:00:00.000Z"
},
"view_digest": "sha256:f755a71573eb528e6058341aafab143fa3afc9ec3aefa3c220c08c292ccf9795",
"withheld": {
"anything_withheld": false,
"note": "Nothing outside the seal was removed for this role."
},
"view": {
"spec": "urn:ietf:params:corobate:receipt:1",
"receipt_version": "1.8",
"engine": {
"name": "corobate-memory",
"version": "1.0.0"
},
"decision": {
"id": "ai_TRIAGE_V4_after",
"domain": "supply-chain",
"subject": "ai-system:TRIAGE-ASSISTANT-V4",
"question": "May this AI system be deployed to triage citizen-facing casework?"
},
"issued_at": "2026-08-08T16:00:00.000Z",
"data_horizon": "2026-08-08T16:00:00.000Z",
"inputs": [
{
"key": "ai-system:TRIAGE-ASSISTANT-V4::vulnerability_scan",
"value": "clean-at-scan",
"provenance": "VERIFIED",
"source": "nvd-cve:vulnerability_scan",
"observed_at": "2026-08-04T16:00:00.000Z",
"last_corroborated_at": null,
"memory_refreshed_by": [],
"reliability": 0.95,
"critical": true,
"memory_id": "mem_4d2b1fc0d322",
"memory_status": "admitted",
"memory_kind": "status",
"memory_actor": "actor:sys:registry:nvd-cve",
"memory_age_days": 4,
"memory_track": {
"n": 1,
"successes": 1
},
"memory_promoted_by": [],
"memory_content_digest": "sha256:aea4c3860d57b3edd045cd33946015c41ff1aee9cc8a4df49f26d8a5165d4a38",
"memory_outcomes": {
"verified": 0,
"falsified": 0,
"modified": 0,
"counted": 0,
"recorded": 0
},
"memory_outcome_attestations": [],
"memory_observer_lineage": null,
"memory_corroborations": [],
"memory_reingest": null,
"memory_reasons": [
"sparse track record: 1 independent observation(s); no failure recorded, so the class ceiling stands"
],
"memory_class_floor": null,
"memory_below_class_floor": false,
"memory_not_attested": false,
"memory_below_claim_reliability_floor": false,
"memory_not_competent_authority": false,
"memory_out_of_specification": false,
"memory_ai_authored": false,
"memory_ai_in_lineage": false,
"memory_ai_position": "ADMIT",
"memory_ai_inadmissible": false,
"memory_geo_inadmissible": false,
"memory_geo_rung": null,
"memory_geo_metric": null,
"memory_geo_required_metric": null,
"observer_attested": true,
"observer_auth_code": "VERIFIED",
"observer_key_id": "k_5873dd9e7169def3",
"attestation": null,
"derivation": {
"provenance": "VERIFIED",
"ceiling_bp": 9500,
"track": {
"n": 1,
"successes": 1
},
"wilson_bp": null,
"age_days": 4,
"max_age_days": 14,
"house_max_age_days": 14,
"instrument_max_age_days": 30,
"freshness_cap_bp": 4000,
"min_track_n": 5,
"wilson_z_milli": 1960,
"source_present": true,
"seller_asserted_cap_bp": 5000,
"retracted": false,
"contradicted": false,
"outcome_trials": 0,
"outcomes": {
"verified": 0,
"falsified": 0,
"modified": 0,
"counted": 0,
"recorded": 0
},
"corroborations_counted": 0,
"corroborations_discounted": 0,
"reingest_ceiling_bp": null,
"reingest_depth": null,
"reingest_weakest_class": null,
"reingest_source_confidence_bp": null,
"ai_authored": false,
"ai_authored_because": null,
"ai_in_lineage": false,
"ai_position": "ADMIT"
},
"memory_reason_codes": [
{
"code": "SPARSE_TRACK_RECORD",
"observed": 1,
"limit": 5,
"binding": false
}
],
"context_line": "[VERIFIED · r=95.0% · 4d · nvd-cve:vulnerability_scan] ai-system:TRIAGE-ASSISTANT-V4 / vulnerability_scan: clean-at-scan"
},
{
"key": "ai-system:TRIAGE-ASSISTANT-V4::incident_response_plan_test",
"value": "observed",
"provenance": "VERIFIED",
"source": "CERT-3PAO-ATLANTIC:incident_response_plan_test",
"observed_at": "2026-06-24T16:00:00.000Z",
"last_corroborated_at": null,
"memory_refreshed_by": [],
"reliability": 0.95,
"critical": true,
"memory_id": "mem_a54dcc18c5ba",
"memory_status": "admitted",
"memory_kind": "certificate",
"memory_actor": "actor:org:CERT-3PAO-ATLANTIC",
"memory_age_days": 45,
"memory_track": {
"n": 1,
"successes": 1
},
"memory_promoted_by": [],
"memory_content_digest": "sha256:a73e4d82b06b62aa687c0a5352a36df46dd691e2bfa8b1354c847d24612df001",
"memory_outcomes": {
"verified": 0,
"falsified": 0,
"modified": 0,
"counted": 0,
"recorded": 0
},
"memory_outcome_attestations": [],
"memory_observer_lineage": null,
"memory_corroborations": [],
"memory_reingest": null,
"memory_reasons": [
"sparse track record: 1 independent observation(s); no failure recorded, so the class ceiling stands"
],
"memory_class_floor": null,
"memory_below_class_floor": false,
"memory_not_attested": false,
"memory_below_claim_reliability_floor": false,
"memory_not_competent_authority": false,
"memory_out_of_specification": false,
"memory_ai_authored": false,
"memory_ai_in_lineage": false,
"memory_ai_position": "ADMIT",
"memory_ai_inadmissible": false,
"memory_geo_inadmissible": false,
"memory_geo_rung": null,
"memory_geo_metric": null,
"memory_geo_required_metric": null,
"observer_attested": true,
"observer_auth_code": "VERIFIED",
"observer_key_id": "k_307e4bfd710ec9b3",
"attestation": null,
"derivation": {
"provenance": "VERIFIED",
"ceiling_bp": 9500,
"track": {
"n": 1,
"successes": 1
},
"wilson_bp": null,
"age_days": 45,
"max_age_days": 365,
"house_max_age_days": 365,
"instrument_max_age_days": null,
"freshness_cap_bp": 4000,
"min_track_n": 5,
"wilson_z_milli": 1960,
"source_present": true,
"seller_asserted_cap_bp": 5000,
"retracted": false,
"contradicted": false,
"outcome_trials": 0,
"outcomes": {
"verified": 0,
"falsified": 0,
"modified": 0,
"counted": 0,
"recorded": 0
},
"corroborations_counted": 0,
"corroborations_discounted": 0,
"reingest_ceiling_bp": null,
"reingest_depth": null,
"reingest_weakest_class": null,
"reingest_source_confidence_bp": null,
"ai_authored": false,
"ai_authored_because": null,
"ai_in_lineage": false,
"ai_position": "ADMIT"
},
"memory_reason_codes": [
{
"code": "SPARSE_TRACK_RECORD",
"observed": 1,
"limit": 5,
"binding": false
}
],
"context_line": "[VERIFIED · r=95.0% · 45d · CERT-3PAO-ATLANTIC:incident_response_plan_test] ai-system:TRIAGE-ASSISTANT-V4 / incident_response_plan_test: observed"
},
{
"key": "ai-system:TRIAGE-ASSISTANT-V4::model_evaluation",
"value": "independent",
"provenance": "VERIFIED",
"source": "LAB-REDTEAM-EVAL:model_evaluation",
"observed_at": "2026-07-19T16:00:00.000Z",
"last_corroborated_at": null,
"memory_refreshed_by": [],
"reliability": 0.95,
"critical": true,
"memory_id": "mem_7dfaefd014b0",
"memory_status": "admitted",
"memory_kind": "test_report",
"memory_actor": "actor:org:LAB-REDTEAM-EVAL",
"memory_age_days": 20,
"memory_track": {
"n": 1,
"successes": 1
},
"memory_promoted_by": [],
"memory_content_digest": "sha256:a7ca29dc11f86a762fc3c3783a0d758796ee0cae8bbd4ae7cb996b3c0a5f45a4",
"memory_outcomes": {
"verified": 0,
"falsified": 0,
"modified": 0,
"counted": 0,
"recorded": 0
},
"memory_outcome_attestations": [],
"memory_observer_lineage": null,
"memory_corroborations": [],
"memory_reingest": null,
"memory_reasons": [
"sparse track record: 1 independent observation(s); no failure recorded, so the class ceiling stands"
],
"memory_class_floor": "VERIFIED",
"memory_below_class_floor": false,
"memory_not_attested": false,
"memory_below_claim_reliability_floor": false,
"memory_not_competent_authority": false,
"memory_out_of_specification": false,
"memory_ai_authored": false,
"memory_ai_in_lineage": false,
"memory_ai_position": "ADMIT",
"memory_ai_inadmissible": false,
"memory_geo_inadmissible": false,
"memory_geo_rung": null,
"memory_geo_metric": null,
"memory_geo_required_metric": null,
"observer_attested": true,
"observer_auth_code": "VERIFIED",
"observer_key_id": "k_db83368c3527dcb1",
"attestation": null,
"derivation": {
"provenance": "VERIFIED",
"ceiling_bp": 9500,
"track": {
"n": 1,
"successes": 1
},
"wilson_bp": null,
"age_days": 20,
"max_age_days": 180,
"house_max_age_days": 180,
"instrument_max_age_days": 180,
"freshness_cap_bp": 4000,
"min_track_n": 5,
"wilson_z_milli": 1960,
"source_present": true,
"seller_asserted_cap_bp": 5000,
"retracted": false,
"contradicted": false,
"outcome_trials": 0,
"outcomes": {
"verified": 0,
"falsified": 0,
"modified": 0,
"counted": 0,
"recorded": 0
},
"corroborations_counted": 0,
"corroborations_discounted": 0,
"reingest_ceiling_bp": null,
"reingest_depth": null,
"reingest_weakest_class": null,
"reingest_source_confidence_bp": null,
"min_class_floor": "VERIFIED",
"ai_authored": false,
"ai_authored_because": null,
"ai_in_lineage": false,
"ai_position": "ADMIT"
},
"memory_reason_codes": [
{
"code": "SPARSE_TRACK_RECORD",
"observed": 1,
"limit": 5,
"binding": false
}
],
"context_line": "[VERIFIED · r=95.0% · 20d · LAB-REDTEAM-EVAL:model_evaluation] ai-system:TRIAGE-ASSISTANT-V4 / model_evaluation: independent"
},
{
"key": "ai-system:TRIAGE-ASSISTANT-V4::security_resilience_evaluation",
"value": "assessed",
"provenance": "VERIFIED",
"source": "LAB-NVLAP-0412:security_resilience_evaluation",
"observed_at": "2026-07-09T16:00:00.000Z",
"last_corroborated_at": null,
"memory_refreshed_by": [],
"reliability": 0.95,
"critical": true,
"memory_id": "mem_2c29e7fe028c",
"memory_status": "admitted",
"memory_kind": "test_report",
"memory_actor": "actor:org:LAB-NVLAP-0412",
"memory_age_days": 30,
"memory_track": {
"n": 1,
"successes": 1
},
"memory_promoted_by": [],
"memory_content_digest": "sha256:dcbb60638904f38e17aa80dd1108c75855c10f1992b0793dc56d369582fc515e",
"memory_outcomes": {
"verified": 0,
"falsified": 0,
"modified": 0,
"counted": 0,
"recorded": 0
},
"memory_outcome_attestations": [],
"memory_observer_lineage": null,
"memory_corroborations": [],
"memory_reingest": null,
"memory_reasons": [
"sparse track record: 1 independent observation(s); no failure recorded, so the class ceiling stands"
],
"memory_class_floor": null,
"memory_below_class_floor": false,
"memory_not_attested": false,
"memory_below_claim_reliability_floor": false,
"memory_not_competent_authority": false,
"memory_out_of_specification": false,
"memory_ai_authored": false,
"memory_ai_in_lineage": false,
"memory_ai_position": "ADMIT",
"memory_ai_inadmissible": false,
"memory_geo_inadmissible": false,
"memory_geo_rung": null,
"memory_geo_metric": null,
"memory_geo_required_metric": null,
"observer_attested": true,
"observer_auth_code": "VERIFIED",
"observer_key_id": "k_17d23885943ae529",
"attestation": null,
"derivation": {
"provenance": "VERIFIED",
"ceiling_bp": 9500,
"track": {
"n": 1,
"successes": 1
},
"wilson_bp": null,
"age_days": 30,
"max_age_days": 180,
"house_max_age_days": 180,
"instrument_max_age_days": null,
"freshness_cap_bp": 4000,
"min_track_n": 5,
"wilson_z_milli": 1960,
"source_present": true,
"seller_asserted_cap_bp": 5000,
"retracted": false,
"contradicted": false,
"outcome_trials": 0,
"outcomes": {
"verified": 0,
"falsified": 0,
"modified": 0,
"counted": 0,
"recorded": 0
},
"corroborations_counted": 0,
"corroborations_discounted": 0,
"reingest_ceiling_bp": null,
"reingest_depth": null,
"reingest_weakest_class": null,
"reingest_source_confidence_bp": null,
"ai_authored": false,
"ai_authored_because": null,
"ai_in_lineage": false,
"ai_position": "ADMIT"
},
"memory_reason_codes": [
{
"code": "SPARSE_TRACK_RECORD",
"observed": 1,
"limit": 5,
"binding": false
}
],
"context_line": "[VERIFIED · r=95.0% · 30d · LAB-NVLAP-0412:security_resilience_evaluation] ai-system:TRIAGE-ASSISTANT-V4 / security_resilience_evaluation: assessed"
},
{
"key": "ai-system:TRIAGE-ASSISTANT-V4::penetration_test",
"value": "no-critical",
"provenance": "VERIFIED",
"source": "LAB-NVLAP-0412:penetration_test",
"observed_at": "2026-06-09T16:00:00.000Z",
"last_corroborated_at": null,
"memory_refreshed_by": [],
"reliability": 0.95,
"critical": true,
"memory_id": "mem_a3316d633bfe",
"memory_status": "admitted",
"memory_kind": "test_report",
"memory_actor": "actor:org:LAB-NVLAP-0412",
"memory_age_days": 60,
"memory_track": {
"n": 1,
"successes": 1
},
"memory_promoted_by": [],
"memory_content_digest": "sha256:db69fb062be9b066b370c668281e12896da2869456a2e6d356a0f14879b27de9",
"memory_outcomes": {
"verified": 0,
"falsified": 0,
"modified": 0,
"counted": 0,
"recorded": 0
},
"memory_outcome_attestations": [],
"memory_observer_lineage": null,
"memory_corroborations": [],
"memory_reingest": null,
"memory_reasons": [
"sparse track record: 1 independent observation(s); no failure recorded, so the class ceiling stands"
],
"memory_class_floor": "VERIFIED",
"memory_below_class_floor": false,
"memory_not_attested": false,
"memory_below_claim_reliability_floor": false,
"memory_not_competent_authority": false,
"memory_out_of_specification": false,
"memory_ai_authored": false,
"memory_ai_in_lineage": false,
"memory_ai_position": "ADMIT",
"memory_ai_inadmissible": false,
"memory_geo_inadmissible": false,
"memory_geo_rung": null,
"memory_geo_metric": null,
"memory_geo_required_metric": null,
"observer_attested": true,
"observer_auth_code": "VERIFIED",
"observer_key_id": "k_17d23885943ae529",
"attestation": null,
"derivation": {
"provenance": "VERIFIED",
"ceiling_bp": 9500,
"track": {
"n": 1,
"successes": 1
},
"wilson_bp": null,
"age_days": 60,
"max_age_days": 180,
"house_max_age_days": 180,
"instrument_max_age_days": null,
"freshness_cap_bp": 4000,
"min_track_n": 5,
"wilson_z_milli": 1960,
"source_present": true,
"seller_asserted_cap_bp": 5000,
"retracted": false,
"contradicted": false,
"outcome_trials": 0,
"outcomes": {
"verified": 0,
"falsified": 0,
"modified": 0,
"counted": 0,
"recorded": 0
},
"corroborations_counted": 0,
"corroborations_discounted": 0,
"reingest_ceiling_bp": null,
"reingest_depth": null,
"reingest_weakest_class": null,
"reingest_source_confidence_bp": null,
"min_class_floor": "VERIFIED",
"ai_authored": false,
"ai_authored_because": null,
"ai_in_lineage": false,
"ai_position": "ADMIT"
},
"memory_reason_codes": [
{
"code": "SPARSE_TRACK_RECORD",
"observed": 1,
"limit": 5,
"binding": false
}
],
"context_line": "[VERIFIED · r=95.0% · 60d · LAB-NVLAP-0412:penetration_test] ai-system:TRIAGE-ASSISTANT-V4 / penetration_test: no-critical"
},
{
"key": "ai-system:TRIAGE-ASSISTANT-V4::control_assessment",
"value": "satisfied",
"provenance": "VERIFIED",
"source": "CERT-3PAO-ATLANTIC:control_assessment",
"observed_at": "2026-04-30T16:00:00.000Z",
"last_corroborated_at": null,
"memory_refreshed_by": [],
"reliability": 0.95,
"critical": true,
"memory_id": "mem_a153eb336060",
"memory_status": "admitted",
"memory_kind": "certificate",
"memory_actor": "actor:org:CERT-3PAO-ATLANTIC",
"memory_age_days": 100,
"memory_track": {
"n": 1,
"successes": 1
},
"memory_promoted_by": [],
"memory_content_digest": "sha256:c1aaf46a55b4cdc629a754ac35da1b8ec4dec85c2c78613c7bc93546b63f233c",
"memory_outcomes": {
"verified": 0,
"falsified": 0,
"modified": 0,
"counted": 0,
"recorded": 0
},
"memory_outcome_attestations": [],
"memory_observer_lineage": null,
"memory_corroborations": [],
"memory_reingest": null,
"memory_reasons": [
"sparse track record: 1 independent observation(s); no failure recorded, so the class ceiling stands"
],
"memory_class_floor": "VERIFIED",
"memory_below_class_floor": false,
"memory_not_attested": false,
"memory_below_claim_reliability_floor": false,
"memory_not_competent_authority": false,
"memory_out_of_specification": false,
"memory_ai_authored": false,
"memory_ai_in_lineage": false,
"memory_ai_position": "ADMIT",
"memory_ai_inadmissible": false,
"memory_geo_inadmissible": false,
"memory_geo_rung": null,
"memory_geo_metric": null,
"memory_geo_required_metric": null,
"observer_attested": true,
"observer_auth_code": "VERIFIED",
"observer_key_id": "k_307e4bfd710ec9b3",
"attestation": null,
"derivation": {
"provenance": "VERIFIED",
"ceiling_bp": 9500,
"track": {
"n": 1,
"successes": 1
},
"wilson_bp": null,
"age_days": 100,
"max_age_days": 365,
"house_max_age_days": 365,
"instrument_max_age_days": 365,
"freshness_cap_bp": 4000,
"min_track_n": 5,
"wilson_z_milli": 1960,
"source_present": true,
"seller_asserted_cap_bp": 5000,
"retracted": false,
"contradicted": false,
"outcome_trials": 0,
"outcomes": {
"verified": 0,
"falsified": 0,
"modified": 0,
"counted": 0,
"recorded": 0
},
"corroborations_counted": 0,
"corroborations_discounted": 0,
"reingest_ceiling_bp": null,
"reingest_depth": null,
"reingest_weakest_class": null,
"reingest_source_confidence_bp": null,
"min_class_floor": "VERIFIED",
"ai_authored": false,
"ai_authored_because": null,
"ai_in_lineage": false,
"ai_position": "ADMIT"
},
"memory_reason_codes": [
{
"code": "SPARSE_TRACK_RECORD",
"observed": 1,
"limit": 5,
"binding": false
}
],
"context_line": "[VERIFIED · r=95.0% · 100d · CERT-3PAO-ATLANTIC:control_assessment] ai-system:TRIAGE-ASSISTANT-V4 / control_assessment: satisfied"
},
{
"key": "ai-system:TRIAGE-ASSISTANT-V4::model_self_report",
"value": null,
"provenance": "SELLER-ASSERTED",
"source": "triage-assistant-v4:model_self_report",
"observed_at": "2026-07-30T16:00:00.000Z",
"last_corroborated_at": null,
"memory_refreshed_by": [],
"reliability": 0.5,
"critical": false,
"memory_id": "mem_0412e050668a",
"memory_status": "withheld",
"memory_kind": "test_report",
"memory_actor": "actor:ai:triage-assistant-v4",
"memory_age_days": 9,
"memory_track": {
"n": 1,
"successes": 1
},
"memory_promoted_by": [],
"memory_content_digest": "sha256:d0df12a8884400dacf5a33d710fcc546d8d522ded0cf8d1e272b04b956a33c1c",
"memory_outcomes": {
"verified": 0,
"falsified": 0,
"modified": 0,
"counted": 0,
"recorded": 0
},
"memory_outcome_attestations": [],
"memory_observer_lineage": null,
"memory_corroborations": [],
"memory_reingest": null,
"memory_reasons": [
"sparse track record: 1 independent observation(s); no failure recorded, so the class ceiling stands"
],
"memory_class_floor": null,
"memory_below_class_floor": false,
"memory_not_attested": false,
"memory_below_claim_reliability_floor": false,
"memory_not_competent_authority": false,
"memory_out_of_specification": false,
"memory_ai_authored": true,
"memory_ai_in_lineage": false,
"memory_ai_position": null,
"memory_ai_inadmissible": false,
"memory_geo_inadmissible": false,
"memory_geo_rung": null,
"memory_geo_metric": null,
"memory_geo_required_metric": null,
"observer_attested": false,
"observer_auth_code": "NO_ENVELOPE",
"observer_key_id": null,
"attestation": null,
"derivation": {
"provenance": "SELLER-ASSERTED",
"ceiling_bp": 5000,
"track": {
"n": 1,
"successes": 1
},
"wilson_bp": null,
"age_days": 9,
"max_age_days": 180,
"house_max_age_days": 180,
"instrument_max_age_days": null,
"freshness_cap_bp": 4000,
"min_track_n": 5,
"wilson_z_milli": 1960,
"source_present": true,
"seller_asserted_cap_bp": 5000,
"retracted": false,
"contradicted": false,
"outcome_trials": 0,
"outcomes": {
"verified": 0,
"falsified": 0,
"modified": 0,
"counted": 0,
"recorded": 0
},
"corroborations_counted": 0,
"corroborations_discounted": 0,
"reingest_ceiling_bp": null,
"reingest_depth": null,
"reingest_weakest_class": null,
"reingest_source_confidence_bp": null,
"ai_authored": true,
"ai_authored_because": "a model, named as one in its own enrolled identity",
"ai_in_lineage": false,
"ai_position": null
},
"memory_reason_codes": [
{
"code": "SPARSE_TRACK_RECORD",
"observed": 1,
"limit": 5,
"binding": false
}
]
}
],
"serialization": {
"algorithm": "RFC8785-JCS",
"hash": "sha256"
},
"crypto_suite": {
"spec": "corobate:suite:1",
"id": "CB-1-ES256-SHA256",
"receipt_digest": "sha256",
"chain_digest": "sha256",
"content_digest": "sha256",
"envelope_signature": "ES256",
"signature_curve": "P-256",
"canonicalisation": "attest-canon/2",
"quantum_resistant": false
},
"confidence": {
"value": 0.95,
"method": "min-over-critical-inputs",
"bound_by": "ai-system:TRIAGE-ASSISTANT-V4::vulnerability_scan"
},
"verdict": {
"value": "APPROVE",
"threshold_approve": 0.9,
"threshold_caution": 0.7,
"rule": "confidence>=threshold"
},
"release": {
"required": false,
"required_by_tier": false,
"escalated_by_acceptance": false,
"risk_accepted": false,
"state": "NOT_REQUIRED",
"code": "QUORUM_NOT_REQUIRED",
"reason": "this decision is below the top exposure tier (floor $10,000,000) and no risk acceptance escalated into this gate, so no multi-party release requirement applies.",
"tier_floor_cents": 1000000000,
"exposure_usd_cents": 140000000,
"required_m": 2,
"declared_n": 3,
"floor_m": 2,
"distinct_signers": 0,
"superseded": 0,
"collapsed": 0,
"release_digest": "sha256:4ad3faa1a749da2c56339fa29e711571515a647ee4c4d9a29d41aa2251bff28a",
"governance_digest": "sha256:8b0a45a27fcce9c1c243c764e855e67c6fe6dfd7f02a563bd90809b419731905",
"governance_signed": true,
"counted_voices": [],
"signatures": [],
"ledger_seq": null
},
"acceptance": {
"state": "NONE",
"code": "ACCEPTANCE_NONE",
"reason": "no risk acceptance was presented for this decision. This is the ordinary case: a refusal is a refusal unless a named person has priced it.",
"permitted_basis": null,
"presented": 0,
"superseded": 0,
"expired": 0,
"gaps_not_covered": 0,
"coverage_gaps_in_force": [],
"evidentiary_digest": "sha256:4ad3faa1a749da2c56339fa29e711571515a647ee4c4d9a29d41aa2251bff28a",
"margin_floor_bp": 100,
"authority_ceiling_cents": {
"SUPERVISOR": 1000000,
"MANAGER": 25000000,
"DIRECTOR": 500000000,
"OFFICER": 5000000000
},
"acceptances": [],
"escalated": false,
"live": false,
"ledger_seq": null
},
"regulatory": {
"spec": "corobate:regulatory:2",
"resolved": true,
"applied": [
{
"instrument_id": "nist-ai-rmf-1-0",
"version": 1,
"authority": "National Institute of Standards and Technology",
"instrument": "AI Risk Management Framework 1.0",
"edition": "1.0",
"citation": "MEASURE-2.3, MEASURE-2.7, MANAGE-2.2 [VERIFY]",
"source_digest": "sha256:a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1",
"entered_by": "actor:human:issm",
"entered_at": "2026-08-08T16:00:00.000Z"
},
{
"instrument_id": "nist-sp-800-53r5-moderate",
"version": 5,
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
"edition": "Rev. 5",
"citation": "CA-2, CA-8, RA-5, SR-6 [VERIFY]",
"source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353",
"entered_by": "actor:human:issm",
"entered_at": "2026-08-08T16:00:00.000Z"
}
],
"skipped": [],
"conflicts": [],
"bindings": [
{
"claim": "control_assessment",
"requirement": "max_age_days",
"value": 365,
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
"instrument_id": "nist-sp-800-53r5-moderate",
"version": 5,
"edition": "Rev. 5",
"citation": "CA-2 [VERIFY]",
"source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "control_assessment",
"requirement": "min_class",
"value": "VERIFIED",
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
"instrument_id": "nist-sp-800-53r5-moderate",
"version": 5,
"edition": "Rev. 5",
"citation": "CA-2(1) independent assessors [VERIFY]",
"source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "control_assessment",
"requirement": "required",
"value": true,
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
"instrument_id": "nist-sp-800-53r5-moderate",
"version": 5,
"edition": "Rev. 5",
"citation": "CA-2 [VERIFY]",
"source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "incident_response_plan_test",
"requirement": "required",
"value": true,
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "AI Risk Management Framework 1.0",
"instrument_id": "nist-ai-rmf-1-0",
"version": 1,
"edition": "1.0",
"citation": "MANAGE-4.1 [VERIFY]",
"source_digest": "sha256:a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "model_evaluation",
"requirement": "max_age_days",
"value": 180,
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "AI Risk Management Framework 1.0",
"instrument_id": "nist-ai-rmf-1-0",
"version": 1,
"edition": "1.0",
"citation": "MEASURE-2.3 [VERIFY]",
"source_digest": "sha256:a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "model_evaluation",
"requirement": "min_class",
"value": "VERIFIED",
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "AI Risk Management Framework 1.0",
"instrument_id": "nist-ai-rmf-1-0",
"version": 1,
"edition": "1.0",
"citation": "MEASURE-2.3 independent evaluation [VERIFY]",
"source_digest": "sha256:a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "model_evaluation",
"requirement": "required",
"value": true,
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "AI Risk Management Framework 1.0",
"instrument_id": "nist-ai-rmf-1-0",
"version": 1,
"edition": "1.0",
"citation": "MEASURE-2.3 [VERIFY]",
"source_digest": "sha256:a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "penetration_test",
"requirement": "min_class",
"value": "VERIFIED",
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
"instrument_id": "nist-sp-800-53r5-moderate",
"version": 5,
"edition": "Rev. 5",
"citation": "CA-8(1) independent penetration agent [VERIFY]",
"source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "penetration_test",
"requirement": "required",
"value": true,
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
"instrument_id": "nist-sp-800-53r5-moderate",
"version": 5,
"edition": "Rev. 5",
"citation": "CA-8 [VERIFY]",
"source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "security_resilience_evaluation",
"requirement": "required",
"value": true,
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "AI Risk Management Framework 1.0",
"instrument_id": "nist-ai-rmf-1-0",
"version": 1,
"edition": "1.0",
"citation": "MEASURE-2.7 [VERIFY]",
"source_digest": "sha256:a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "vulnerability_scan",
"requirement": "max_age_days",
"value": 30,
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
"instrument_id": "nist-sp-800-53r5-moderate",
"version": 5,
"edition": "Rev. 5",
"citation": "RA-5(a) [VERIFY]",
"source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "vulnerability_scan",
"requirement": "required",
"value": true,
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
"instrument_id": "nist-sp-800-53r5-moderate",
"version": 5,
"edition": "Rev. 5",
"citation": "RA-5 [VERIFY]",
"source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
}
],
"defaults": [
{
"claim": "control_assessment",
"requirement": "ai_position",
"value": "ADMIT",
"because": "No instrument in force stated a position on AI-authored evidence for \"control_assessment\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
},
{
"claim": "incident_response_plan_test",
"requirement": "ai_position",
"value": "ADMIT",
"because": "No instrument in force stated a position on AI-authored evidence for \"incident_response_plan_test\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
},
{
"claim": "model_evaluation",
"requirement": "ai_position",
"value": "ADMIT",
"because": "No instrument in force stated a position on AI-authored evidence for \"model_evaluation\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
},
{
"claim": "penetration_test",
"requirement": "ai_position",
"value": "ADMIT",
"because": "No instrument in force stated a position on AI-authored evidence for \"penetration_test\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
},
{
"claim": "security_resilience_evaluation",
"requirement": "ai_position",
"value": "ADMIT",
"because": "No instrument in force stated a position on AI-authored evidence for \"security_resilience_evaluation\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
},
{
"claim": "vulnerability_scan",
"requirement": "ai_position",
"value": "ADMIT",
"because": "No instrument in force stated a position on AI-authored evidence for \"vulnerability_scan\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
}
]
},
"reasons": [
"Confidence 95.00% is bound by \"ai-system:TRIAGE-ASSISTANT-V4|vulnerability_scan\".",
"1 memory was withheld from the context block: ai-system:TRIAGE-ASSISTANT-V4|model_self_report (sparse track record: 1 independent observation(s); no failure recorded, so the class ceiling stands).",
"Thresholds for $1,400,000 exposure: approve 90%, caution 70%."
],
"memory": {
"layer": "capture->store->recall->act",
"ledger_head": "sha256:b883e583bf7eac8664664c008b4556f5e62ef70a681669c550a6d84ccad602fc",
"ledger_entries": 9,
"context_digest": "sha256:370424ce7a83527f262a9382eaada142e12978740525dbc7a71302faabc196b5",
"context_memory_ids": [
"mem_2c29e7fe028c",
"mem_4d2b1fc0d322",
"mem_7dfaefd014b0",
"mem_a153eb336060",
"mem_a3316d633bfe",
"mem_a54dcc18c5ba"
],
"state_digest": "sha256:d8c970114e57738a62465be9287d7045cd8966caeb801154d420321a11451dcc",
"retrieval_method": "idf-lexical",
"corpus_size": 7,
"considered": 7,
"admitted": 6,
"withheld": 1,
"not_considered": 0,
"coverage_gaps": [],
"exposure": {
"usd": 1400000,
"declared_by": "actor:human:ao-authorizing-official",
"ledger_seq": 7
},
"salience_policy": {
"half_life_days": 90,
"grace_days": 7,
"access_boost_bp": 500,
"access_boost_cap_bp": 2500,
"relevance_weight_bp": 6000,
"recency_weight_bp": 3000,
"usage_weight_bp": 1000,
"context_cap": 12,
"method": "idf-lexical",
"candidate_list_digest": "sha256:eccb7e3ba1bd02c228774ef6908a72059c0e1ea29475f3d42946329f3a52cebe",
"note": "salience orders retrieval only; it never contributes to reliability"
},
"policy_digest": "sha256:a6b69b7d20f7fb04d522364af1d92992058b04a5835fcec9d1c9f2261c7ef636",
"policy_body": {
"class_ceiling_bp": {
"VERIFIED": 9500,
"MODELED": 8000,
"SELLER-ASSERTED": 5000,
"MISSING": 0
},
"actor_class_ceiling": [
[
"^actor:ai:",
"MODELED"
],
[
"^actor:agent:",
"MODELED"
],
[
"^actor:human:",
"SELLER-ASSERTED"
],
[
"^actor:org:LAB-",
"VERIFIED"
],
[
"^actor:org:CERT-",
"VERIFIED"
],
[
"^actor:org:",
"SELLER-ASSERTED"
],
[
"^actor:sys:registry:",
"VERIFIED"
],
[
"^actor:sys:sensor:",
"VERIFIED"
],
[
"^actor:sys:",
"MODELED"
]
],
"freshness_cap_bp": 4000,
"max_age_days": {
"telemetry": 1,
"price": 7,
"status": 14,
"certificate": 365,
"test_report": 180,
"filing": 90,
"transcript": 120,
"highlight": 365,
"voice_note": 120,
"note": 365,
"preference": 540,
"decision": 1825,
"receipt": 365,
"default": 90
},
"wilson_z_milli": 1960,
"min_track_n": 5,
"exposure_tiers_bp": [
[
1000000000,
9500,
8000
],
[
100000000,
9000,
7000
],
[
1000000,
8500,
6000
],
[
0,
8000,
5000
]
],
"max_context_memories": 12,
"contradiction_resolve_margin": 2,
"salience": {
"half_life_days": 90,
"grace_days": 7,
"access_boost_bp": 500,
"access_boost_cap_bp": 2500,
"relevance_weight_bp": 6000,
"recency_weight_bp": 3000,
"usage_weight_bp": 1000
}
},
"observer_auth": {
"mode": "required",
"registry_version": 3,
"registry_digest": "sha256:460aeaafe345f69542a302e6619dff0712af98de6518838ee4c8585e448c3a7d",
"entries_root": "sha256:5670469f96484a814462814ed74f0f992b5f19e8ad6afced548e4956e4835ba5",
"memberships": [
{
"key_id": "k_17d23885943ae529",
"index": 1,
"entry": {
"actor": "actor:org:LAB-NVLAP-0412",
"class": "VERIFIED",
"kind": "org",
"key_id": "k_17d23885943ae529",
"jwk": {
"kty": "EC",
"crv": "P-256",
"x": "3TTw47-PkYfo3ZaKTq_qtHghnGvninAVj25kyOwONno",
"y": "16PMaR8ofeF5IcZk6ZLml8gDs8uE1s1sBLdciH5e4vg"
},
"valid_from": "2025-01-01T00:00:00.000Z",
"valid_to": "2027-06-01T00:00:00.000Z"
},
"path": [
{
"side": "left",
"sibling": "sha256:500f2ba5949d5256ae0f563530b0b270db41ce99d2d7c4b4b60e4bd558ca353d"
},
{
"side": "right",
"sibling": "sha256:a0b47ea437bf4f1042a1dd50a5a3f411f9a17971812fc6bafccd434eb7d78ccc"
},
{
"side": "right",
"sibling": "sha256:d3c2347eb675e865fc17ef0204cacda7b02e8784a811fdd1c8a015d1865e6dfb"
},
{
"side": "right",
"sibling": "sha256:7071adf5e21a94147d31f42f1028b4867b6562e5b78726259c2515b03b213e52"
}
]
},
{
"key_id": "k_307e4bfd710ec9b3",
"index": 0,
"entry": {
"actor": "actor:org:CERT-3PAO-ATLANTIC",
"class": "VERIFIED",
"kind": "org",
"key_id": "k_307e4bfd710ec9b3",
"jwk": {
"kty": "EC",
"crv": "P-256",
"x": "MGtV26TezLMPjiD3SecQtnje6eLqYyx4qkKzzAkbiY4",
"y": "SMMdLYnn-FpKbb2sJQ8EAZnzvozNm-cGO0VbUUpniPY"
},
"valid_from": "2025-01-01T00:00:00.000Z",
"valid_to": "2027-06-01T00:00:00.000Z"
},
"path": [
{
"side": "right",
"sibling": "sha256:4148869fc259d2c5fc19fe5831065b165a9acf81812e123162035acfdecade1d"
},
{
"side": "right",
"sibling": "sha256:a0b47ea437bf4f1042a1dd50a5a3f411f9a17971812fc6bafccd434eb7d78ccc"
},
{
"side": "right",
"sibling": "sha256:d3c2347eb675e865fc17ef0204cacda7b02e8784a811fdd1c8a015d1865e6dfb"
},
{
"side": "right",
"sibling": "sha256:7071adf5e21a94147d31f42f1028b4867b6562e5b78726259c2515b03b213e52"
}
]
},
{
"key_id": "k_5873dd9e7169def3",
"index": 2,
"entry": {
"actor": "actor:sys:registry:nvd-cve",
"class": "VERIFIED",
"kind": "system",
"key_id": "k_5873dd9e7169def3",
"jwk": {
"kty": "EC",
"crv": "P-256",
"x": "O9OY6oMuJg0df_INePO19_3b11VaSyMwIPdxoqvV2ak",
"y": "k7Orm5pxDxMdTF-H2S4h6ixRywzk1WxvquOQeqxLFx0"
},
"valid_from": "2025-01-01T00:00:00.000Z",
"valid_to": "2027-06-01T00:00:00.000Z"
},
"path": [
{
"side": "right",
"sibling": "sha256:e1fe36fe7c8e4695327c25d6d722630b6249c93293bfdc5894c58aaf961ab6f8"
},
{
"side": "left",
"sibling": "sha256:e8b9cba101f13538b909a2e686e9e6e9a8d77212036ed567eaebc205a443e83f"
},
{
"side": "right",
"sibling": "sha256:d3c2347eb675e865fc17ef0204cacda7b02e8784a811fdd1c8a015d1865e6dfb"
},
{
"side": "right",
"sibling": "sha256:7071adf5e21a94147d31f42f1028b4867b6562e5b78726259c2515b03b213e52"
}
]
},
{
"key_id": "k_db83368c3527dcb1",
"index": 4,
"entry": {
"actor": "actor:org:LAB-REDTEAM-EVAL",
"class": "VERIFIED",
"kind": "org",
"key_id": "k_db83368c3527dcb1",
"jwk": {
"kty": "EC",
"crv": "P-256",
"x": "1102q4E19agLvSGA6yK4u2zhpxY-jaQOP4wQ6NNh9Cg",
"y": "XiDaanPqOwwYAYYIuZugw76jb_AiL13q7HKUphl1bog"
},
"valid_from": "2025-01-01T00:00:00.000Z",
"valid_to": "2027-06-01T00:00:00.000Z"
},
"path": [
{
"side": "right",
"sibling": "sha256:38e595fa3d2f2ead066b77b76ce900a756b59361a08b6a7bb044c626be3f062f"
},
{
"side": "right",
"sibling": "sha256:e579ab792dab36997cea2010753062ba6df4702a94d39085c307e749243ab70a"
},
{
"side": "left",
"sibling": "sha256:d3f1d60ec9478d2b69455e5ba8168897966d18429bd3b7d36105841cc2ae1776"
},
{
"side": "right",
"sibling": "sha256:7071adf5e21a94147d31f42f1028b4867b6562e5b78726259c2515b03b213e52"
}
]
}
],
"memberships_unproven": [],
"revocation": {
"source": "SIGNED_LIST",
"digest": "sha256:12f73b1fbf27d38cf137b86a1ce13bbcd98161123a6aa7d79b107db8189966b9",
"sequence": 5,
"registry_version": 3,
"issued_at": "2026-08-06T00:00:00.000Z",
"next_update_due": "2026-08-13T00:00:00.000Z",
"entry_count": 0,
"body": {
"sequence": 5,
"registry_version": 3,
"issuer": {
"name": "NIST-regulated enterprise demonstration trust root",
"key_id": "k_3793b8e35f8acac1"
},
"issued_at": "2026-08-06T00:00:00.000Z",
"next_update_due": "2026-08-13T00:00:00.000Z",
"entries": [],
"spec": "corobate:revocation-list:1"
}
}
},
"governance": {
"digest": "sha256:8b0a45a27fcce9c1c243c764e855e67c6fe6dfd7f02a563bd90809b419731905",
"signed": true,
"actor_trust": "FLOOR_TO_SELLER_ASSERTED",
"outcome_trial_weight": 1,
"max_reingest_depth": 3,
"release_quorum_m": 2,
"release_quorum_n": 3,
"risk_acceptance_margin_bp": 500,
"risk_acceptance_max_days": 30,
"risk_acceptance_authority_cents": {
"SUPERVISOR": 1000000,
"MANAGER": 25000000,
"DIRECTOR": 500000000,
"OFFICER": 5000000000
},
"template_author_roles": [
"MANAGER",
"DIRECTOR",
"OFFICER"
]
},
"observers_attested": 6,
"outcomes": {
"attestations_counted": 0,
"attestations_recorded": 0,
"records_with_outcomes": 0
},
"lineage": {
"corroborations_counted": 0,
"corroborations_discounted": 0,
"records_with_discounted_corroborations": 0
},
"reingest": {
"records": 0,
"max_depth": 0,
"weakest_class": null,
"chain_weakest_bp": 10000,
"chain": []
},
"template": null
}
}
}The enterprise standard ADMITS machine-generated evidence for this control. The assistant’s disposition of 412 scanner findings carries it — and carries it at MODELED, because admitting model output does not promote it. The verdict is CAUTION rather than APPROVE for exactly that reason: the position decides ADMISSIBILITY, the class table still decides how far the evidence reaches.
- Subject
- ai-system:TRIAGE-ASSISTANT-V4
- Question
- May this quarter's vulnerability triage be accepted as the record of review?
- Exposure
- $250,000
- Instruments
- Office of the Chief Information Security Officer · National Institute of Standards and Technology
- Outcome
- CAUTION — the action may proceed
- Receipt
- sha256:e6038d8525d391ca3b49b3b8135e9b479595df9200a54c9f68c7cbb286b87a34
The gate variables this decision ran under — a dial per question, read back off the sealed receipt
control assessmentrequired
penetration testrequired
vulnerability scanrequired
vulnerability triage dispositionrequired
Every bar above was re-derived from the regulatory bindings inside this receipt’s hashed body, not from the configuration that produced it. A bar in grey is a setting no instrument made — the deploying organisation’s own default, which still binds and is not an absence. A bar position renders an ordinal on a declared ladder: it is a way to draw a control and to compare two settings on the same axis, and it is not a measurement. The value printed beside each bar is the authoritative one.
Whoever must act now
The engineer with the deployment in their hands, the release manager, the person who must publish or hold.
One instruction and the reason in words. No score, no money, no signatures.
Seven or eight fields, and not one of them is a number somebody can argue with. This person is not being asked to re-judge the evidence; somebody already did, and it is on the record.
The scoped copy itself — partial — something outside this role’s remit was removed
{
"spec": "corobate:role-view:2",
"role": "OPERATOR",
"purpose": "Whoever must act on this decision now — release the goods, fund the draw, dispatch the agent, ship the title. Sees one instruction and the reason in plain words, and nothing that could be argued about while somebody waits.",
"is_a_receipt": false,
"warning": "This is a SCOPED COPY of a sealed decision, not the decision record itself. It will not verify as a receipt and must not be presented as one. To confirm it is faithful, recompute its `view` digest under the same canonicalisation that produces receipt_hash and compare it with the entry for this role in the source receipt’s `views` block.",
"derived_from": {
"receipt_hash": "sha256:e6038d8525d391ca3b49b3b8135e9b479595df9200a54c9f68c7cbb286b87a34",
"entry_hash": "sha256:2c628fa4efbfe5c02c5978f8f777b7877876cc40f378291a8bf847cd5db64977",
"issued_at": "2026-08-08T16:00:00.000Z"
},
"view_digest": "sha256:1fe235515c5a224af813a3209419b79317940804ca62f64effc7c3b187c641e6",
"withheld": {
"anything_withheld": true,
"note": "Facts outside this role’s remit were removed. That something was removed is stated so a partial record is never mistaken for a complete one. How much, and what, is not stated — a count is an inference about the part you are not entitled to see."
},
"view": {
"spec": "urn:ietf:params:corobate:receipt:1",
"receipt_version": "1.8",
"issued_at": "2026-08-08T16:00:00.000Z",
"decision": {
"id": "ai_TRIAGE_EVIDENCE_ADMIT",
"subject": "ai-system:TRIAGE-ASSISTANT-V4"
},
"memory": {
"state_digest": "sha256:9357ab4d994dcd108cd3f22257927b155d8e44f669c5c0bb8d3e9bfc6be9e52a",
"ledger_head": "sha256:d11e8eaa639930292fb398123e6aeefff52b74a09d6448ad6f8e6c8e154ce39f",
"coverage_gaps": []
},
"verdict": {
"value": "CAUTION"
},
"release": {
"state": "NOT_REQUIRED"
}
}
}Provider / assessed party
The cloud service provider, the release team, or the party operating the AI system — whoever is being assessed.
Sees which controls were required of them and by which publication and control identifier. Does not see the authorising official’s exposure figure or how any shortfall was priced.
What is outstanding on your file
Nothing. Every required item is present and current.
| Claim | Required | Evidence class | Who | Age | Outcome |
|---|---|---|---|---|---|
| vulnerability_triage_disposition | yes | MODELED | — | 2026-08-05 | admitted |
| vulnerability_scan | yes | VERIFIED | — | 2026-08-04 | admitted |
| penetration_test | yes | VERIFIED | — | 2026-06-09 | admitted |
| control_assessment | yes | VERIFIED | — | 2026-04-30 | admitted |
The clause is here because it turns an argument into an errand. What is not here: what the bank had at stake, and whether anyone priced the shortfall.
The scoped copy itself — partial — something outside this role’s remit was removed
{
"spec": "corobate:role-view:2",
"role": "SUPPLIER",
"purpose": "The party whose evidence was judged. Sees every claim the decision required, which fell short, and the clause that required it — and nothing about what the buyer had at stake or how the buyer priced any shortfall. NOTE, because an earlier draft of this sentence was untrue: this projection carries the WHOLE inputs array, so where several parties supplied evidence for one decision, each of them sees all of it. Per-party scoping cannot be expressed by a commitment scheme with one digest per role, and claiming it anyway would be the kind of promise this file exists to stop making.",
"is_a_receipt": false,
"warning": "This is a SCOPED COPY of a sealed decision, not the decision record itself. It will not verify as a receipt and must not be presented as one. To confirm it is faithful, recompute its `view` digest under the same canonicalisation that produces receipt_hash and compare it with the entry for this role in the source receipt’s `views` block.",
"derived_from": {
"receipt_hash": "sha256:e6038d8525d391ca3b49b3b8135e9b479595df9200a54c9f68c7cbb286b87a34",
"entry_hash": "sha256:2c628fa4efbfe5c02c5978f8f777b7877876cc40f378291a8bf847cd5db64977",
"issued_at": "2026-08-08T16:00:00.000Z"
},
"view_digest": "sha256:5aac9db26c6938a9d95cac33ff8b8992b210c3b79b803c96941b08fb95ccdc67",
"withheld": {
"anything_withheld": true,
"note": "Facts outside this role’s remit were removed. That something was removed is stated so a partial record is never mistaken for a complete one. How much, and what, is not stated — a count is an inference about the part you are not entitled to see."
},
"view": {
"spec": "urn:ietf:params:corobate:receipt:1",
"receipt_version": "1.8",
"issued_at": "2026-08-08T16:00:00.000Z",
"decision": {
"id": "ai_TRIAGE_EVIDENCE_ADMIT",
"subject": "ai-system:TRIAGE-ASSISTANT-V4",
"question": "May this quarter's vulnerability triage be accepted as the record of review?"
},
"memory": {
"state_digest": "sha256:9357ab4d994dcd108cd3f22257927b155d8e44f669c5c0bb8d3e9bfc6be9e52a",
"ledger_head": "sha256:d11e8eaa639930292fb398123e6aeefff52b74a09d6448ad6f8e6c8e154ce39f",
"coverage_gaps": []
},
"verdict": {
"value": "CAUTION"
},
"inputs": [
{
"key": "ai-system:TRIAGE-ASSISTANT-V4::vulnerability_triage_disposition",
"provenance": "MODELED",
"observed_at": "2026-08-05T16:00:00.000Z",
"memory_status": "admitted",
"critical": true
},
{
"key": "ai-system:TRIAGE-ASSISTANT-V4::vulnerability_scan",
"provenance": "VERIFIED",
"observed_at": "2026-08-04T16:00:00.000Z",
"memory_status": "admitted",
"critical": true
},
{
"key": "ai-system:TRIAGE-ASSISTANT-V4::penetration_test",
"provenance": "VERIFIED",
"observed_at": "2026-06-09T16:00:00.000Z",
"memory_status": "admitted",
"critical": true
},
{
"key": "ai-system:TRIAGE-ASSISTANT-V4::control_assessment",
"provenance": "VERIFIED",
"observed_at": "2026-04-30T16:00:00.000Z",
"memory_status": "admitted",
"critical": true
}
],
"regulatory": {
"bindings": [
{
"claim": "control_assessment",
"requirement": "max_age_days",
"value": 365,
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
"instrument_id": "nist-sp-800-53r5-moderate",
"version": 5,
"edition": "Rev. 5",
"citation": "CA-2 [VERIFY]",
"source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "control_assessment",
"requirement": "min_class",
"value": "VERIFIED",
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
"instrument_id": "nist-sp-800-53r5-moderate",
"version": 5,
"edition": "Rev. 5",
"citation": "CA-2(1) independent assessors [VERIFY]",
"source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "control_assessment",
"requirement": "required",
"value": true,
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
"instrument_id": "nist-sp-800-53r5-moderate",
"version": 5,
"edition": "Rev. 5",
"citation": "CA-2 [VERIFY]",
"source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "penetration_test",
"requirement": "min_class",
"value": "VERIFIED",
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
"instrument_id": "nist-sp-800-53r5-moderate",
"version": 5,
"edition": "Rev. 5",
"citation": "CA-8(1) independent penetration agent [VERIFY]",
"source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "penetration_test",
"requirement": "required",
"value": true,
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
"instrument_id": "nist-sp-800-53r5-moderate",
"version": 5,
"edition": "Rev. 5",
"citation": "CA-8 [VERIFY]",
"source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "vulnerability_scan",
"requirement": "max_age_days",
"value": 30,
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
"instrument_id": "nist-sp-800-53r5-moderate",
"version": 5,
"edition": "Rev. 5",
"citation": "RA-5(a) [VERIFY]",
"source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "vulnerability_scan",
"requirement": "required",
"value": true,
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
"instrument_id": "nist-sp-800-53r5-moderate",
"version": 5,
"edition": "Rev. 5",
"citation": "RA-5 [VERIFY]",
"source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "vulnerability_triage_disposition",
"requirement": "ai_position",
"value": "ADMIT",
"bound_by": {
"authority": "Office of the Chief Information Security Officer",
"instrument": "Enterprise standard on machine-generated evidence",
"instrument_id": "enterprise-ai-evidence-standard",
"version": 1,
"edition": "2026-03-01",
"citation": "§ 3.4 [VERIFY]",
"source_digest": "sha256:e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "vulnerability_triage_disposition",
"requirement": "required",
"value": true,
"bound_by": {
"authority": "Office of the Chief Information Security Officer",
"instrument": "Enterprise standard on machine-generated evidence",
"instrument_id": "enterprise-ai-evidence-standard",
"version": 1,
"edition": "2026-03-01",
"citation": "§ 3.1 [VERIFY]",
"source_digest": "sha256:e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
}
],
"applied": [
{
"instrument_id": "enterprise-ai-evidence-standard",
"version": 1,
"authority": "Office of the Chief Information Security Officer",
"instrument": "Enterprise standard on machine-generated evidence",
"edition": "2026-03-01",
"citation": "§ 3 [VERIFY]",
"source_digest": "sha256:e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5",
"entered_by": "actor:human:issm",
"entered_at": "2026-08-08T16:00:00.000Z"
},
{
"instrument_id": "nist-sp-800-53r5-moderate",
"version": 5,
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
"edition": "Rev. 5",
"citation": "CA-2, CA-8, RA-5, SR-6 [VERIFY]",
"source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353",
"entered_by": "actor:human:issm",
"entered_at": "2026-08-08T16:00:00.000Z"
}
],
"defaults": [
{
"claim": "control_assessment",
"requirement": "ai_position",
"value": "ADMIT",
"because": "No instrument in force stated a position on AI-authored evidence for \"control_assessment\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
},
{
"claim": "penetration_test",
"requirement": "ai_position",
"value": "ADMIT",
"because": "No instrument in force stated a position on AI-authored evidence for \"penetration_test\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
},
{
"claim": "vulnerability_scan",
"requirement": "ai_position",
"value": "ADMIT",
"because": "No instrument in force stated a position on AI-authored evidence for \"vulnerability_scan\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
}
]
}
}
}Assessor / authorising official
A third-party assessment organisation, an agency assessor, or an inspector general reviewing the package. Same position as a customs officer: a public mandate over the record.
The control record in full — each publication by control identifier, edition and document digest, and every required claim with who supplied it and when. No exposure figure, no risk pricing, no confidence score.
What each authority bound
| Claim | Requirement | Level | Bound by |
|---|---|---|---|
| control_assessment | max age days | 365 | National Institute of Standards and Technology CA-2 [VERIFY] · SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline) |
| control_assessment | min class | VERIFIED | National Institute of Standards and Technology CA-2(1) independent assessors [VERIFY] · SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline) |
| control_assessment | required | true | National Institute of Standards and Technology CA-2 [VERIFY] · SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline) |
| penetration_test | min class | VERIFIED | National Institute of Standards and Technology CA-8(1) independent penetration agent [VERIFY] · SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline) |
| penetration_test | required | true | National Institute of Standards and Technology CA-8 [VERIFY] · SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline) |
| vulnerability_scan | max age days | 30 | National Institute of Standards and Technology RA-5(a) [VERIFY] · SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline) |
| vulnerability_scan | required | true | National Institute of Standards and Technology RA-5 [VERIFY] · SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline) |
| vulnerability_triage_disposition | ai position | ADMIT | Office of the Chief Information Security Officer § 3.4 [VERIFY] · Enterprise standard on machine-generated evidence |
| vulnerability_triage_disposition | required | true | Office of the Chief Information Security Officer § 3.1 [VERIFY] · Enterprise standard on machine-generated evidence |
Every required claim, and what was actually held
| Claim | Required | Evidence class | Who | Age | Outcome |
|---|---|---|---|---|---|
| vulnerability_triage_disposition | yes | MODELED | actor:ai:triage-assistant-v4 | 2026-08-05 | admitted |
| vulnerability_scan | yes | VERIFIED | actor:sys:registry:nvd-cve | 2026-08-04 | admitted |
| penetration_test | yes | VERIFIED | actor:org:LAB-NVLAP-0412 | 2026-06-09 | admitted |
| control_assessment | yes | VERIFIED | actor:org:CERT-3PAO-ATLANTIC | 2026-04-30 | admitted |
The scoped copy itself — partial — something outside this role’s remit was removed
{
"spec": "corobate:role-view:2",
"role": "REGULATOR",
"purpose": "An official holding a public mandate over this record — a customs officer, a bank examiner, a market conduct supervisor. Sees the regulatory record in full: their own instrument named, every required claim and whether it was met, by whom, how old. No commercial figure of any kind.",
"is_a_receipt": false,
"warning": "This is a SCOPED COPY of a sealed decision, not the decision record itself. It will not verify as a receipt and must not be presented as one. To confirm it is faithful, recompute its `view` digest under the same canonicalisation that produces receipt_hash and compare it with the entry for this role in the source receipt’s `views` block.",
"derived_from": {
"receipt_hash": "sha256:e6038d8525d391ca3b49b3b8135e9b479595df9200a54c9f68c7cbb286b87a34",
"entry_hash": "sha256:2c628fa4efbfe5c02c5978f8f777b7877876cc40f378291a8bf847cd5db64977",
"issued_at": "2026-08-08T16:00:00.000Z"
},
"view_digest": "sha256:9a4b8a4d1b9701b338aad746af3048c54cc711b555325c27799cae64707a8873",
"withheld": {
"anything_withheld": true,
"note": "Facts outside this role’s remit were removed. That something was removed is stated so a partial record is never mistaken for a complete one. How much, and what, is not stated — a count is an inference about the part you are not entitled to see."
},
"view": {
"spec": "urn:ietf:params:corobate:receipt:1",
"receipt_version": "1.8",
"issued_at": "2026-08-08T16:00:00.000Z",
"decision": {
"id": "ai_TRIAGE_EVIDENCE_ADMIT",
"subject": "ai-system:TRIAGE-ASSISTANT-V4",
"question": "May this quarter's vulnerability triage be accepted as the record of review?"
},
"memory": {
"state_digest": "sha256:9357ab4d994dcd108cd3f22257927b155d8e44f669c5c0bb8d3e9bfc6be9e52a",
"ledger_head": "sha256:d11e8eaa639930292fb398123e6aeefff52b74a09d6448ad6f8e6c8e154ce39f",
"coverage_gaps": []
},
"data_horizon": "2026-08-08T16:00:00.000Z",
"verdict": {
"value": "CAUTION"
},
"regulatory": {
"spec": "corobate:regulatory:2",
"resolved": true,
"applied": [
{
"instrument_id": "enterprise-ai-evidence-standard",
"version": 1,
"authority": "Office of the Chief Information Security Officer",
"instrument": "Enterprise standard on machine-generated evidence",
"edition": "2026-03-01",
"citation": "§ 3 [VERIFY]",
"source_digest": "sha256:e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5",
"entered_by": "actor:human:issm",
"entered_at": "2026-08-08T16:00:00.000Z"
},
{
"instrument_id": "nist-sp-800-53r5-moderate",
"version": 5,
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
"edition": "Rev. 5",
"citation": "CA-2, CA-8, RA-5, SR-6 [VERIFY]",
"source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353",
"entered_by": "actor:human:issm",
"entered_at": "2026-08-08T16:00:00.000Z"
}
],
"skipped": [],
"conflicts": [],
"bindings": [
{
"claim": "control_assessment",
"requirement": "max_age_days",
"value": 365,
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
"instrument_id": "nist-sp-800-53r5-moderate",
"version": 5,
"edition": "Rev. 5",
"citation": "CA-2 [VERIFY]",
"source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "control_assessment",
"requirement": "min_class",
"value": "VERIFIED",
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
"instrument_id": "nist-sp-800-53r5-moderate",
"version": 5,
"edition": "Rev. 5",
"citation": "CA-2(1) independent assessors [VERIFY]",
"source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "control_assessment",
"requirement": "required",
"value": true,
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
"instrument_id": "nist-sp-800-53r5-moderate",
"version": 5,
"edition": "Rev. 5",
"citation": "CA-2 [VERIFY]",
"source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "penetration_test",
"requirement": "min_class",
"value": "VERIFIED",
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
"instrument_id": "nist-sp-800-53r5-moderate",
"version": 5,
"edition": "Rev. 5",
"citation": "CA-8(1) independent penetration agent [VERIFY]",
"source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "penetration_test",
"requirement": "required",
"value": true,
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
"instrument_id": "nist-sp-800-53r5-moderate",
"version": 5,
"edition": "Rev. 5",
"citation": "CA-8 [VERIFY]",
"source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "vulnerability_scan",
"requirement": "max_age_days",
"value": 30,
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
"instrument_id": "nist-sp-800-53r5-moderate",
"version": 5,
"edition": "Rev. 5",
"citation": "RA-5(a) [VERIFY]",
"source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "vulnerability_scan",
"requirement": "required",
"value": true,
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
"instrument_id": "nist-sp-800-53r5-moderate",
"version": 5,
"edition": "Rev. 5",
"citation": "RA-5 [VERIFY]",
"source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "vulnerability_triage_disposition",
"requirement": "ai_position",
"value": "ADMIT",
"bound_by": {
"authority": "Office of the Chief Information Security Officer",
"instrument": "Enterprise standard on machine-generated evidence",
"instrument_id": "enterprise-ai-evidence-standard",
"version": 1,
"edition": "2026-03-01",
"citation": "§ 3.4 [VERIFY]",
"source_digest": "sha256:e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "vulnerability_triage_disposition",
"requirement": "required",
"value": true,
"bound_by": {
"authority": "Office of the Chief Information Security Officer",
"instrument": "Enterprise standard on machine-generated evidence",
"instrument_id": "enterprise-ai-evidence-standard",
"version": 1,
"edition": "2026-03-01",
"citation": "§ 3.1 [VERIFY]",
"source_digest": "sha256:e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
}
],
"defaults": [
{
"claim": "control_assessment",
"requirement": "ai_position",
"value": "ADMIT",
"because": "No instrument in force stated a position on AI-authored evidence for \"control_assessment\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
},
{
"claim": "penetration_test",
"requirement": "ai_position",
"value": "ADMIT",
"because": "No instrument in force stated a position on AI-authored evidence for \"penetration_test\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
},
{
"claim": "vulnerability_scan",
"requirement": "ai_position",
"value": "ADMIT",
"because": "No instrument in force stated a position on AI-authored evidence for \"vulnerability_scan\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
}
]
},
"inputs": [
{
"key": "ai-system:TRIAGE-ASSISTANT-V4::vulnerability_triage_disposition",
"provenance": "MODELED",
"source": "triage-assistant-v4:vulnerability_triage_disposition",
"observed_at": "2026-08-05T16:00:00.000Z",
"critical": true,
"memory_status": "admitted",
"memory_actor": "actor:ai:triage-assistant-v4"
},
{
"key": "ai-system:TRIAGE-ASSISTANT-V4::vulnerability_scan",
"provenance": "VERIFIED",
"source": "nvd-cve:vulnerability_scan",
"observed_at": "2026-08-04T16:00:00.000Z",
"critical": true,
"memory_status": "admitted",
"memory_actor": "actor:sys:registry:nvd-cve"
},
{
"key": "ai-system:TRIAGE-ASSISTANT-V4::penetration_test",
"provenance": "VERIFIED",
"source": "LAB-NVLAP-0412:penetration_test",
"observed_at": "2026-06-09T16:00:00.000Z",
"critical": true,
"memory_status": "admitted",
"memory_actor": "actor:org:LAB-NVLAP-0412"
},
{
"key": "ai-system:TRIAGE-ASSISTANT-V4::control_assessment",
"provenance": "VERIFIED",
"source": "CERT-3PAO-ATLANTIC:control_assessment",
"observed_at": "2026-04-30T16:00:00.000Z",
"critical": true,
"memory_status": "admitted",
"memory_actor": "actor:org:CERT-3PAO-ATLANTIC"
}
],
"crypto_suite": {
"spec": "corobate:suite:1",
"id": "CB-1-ES256-SHA256",
"receipt_digest": "sha256",
"chain_digest": "sha256",
"content_digest": "sha256",
"envelope_signature": "ES256",
"signature_curve": "P-256",
"canonicalisation": "attest-canon/2",
"quantum_resistant": false
}
}
}ISSM / control owner
The information system security manager and the control owners who hold the package.
The fullest internal view: every input, its class, its age, its score, the exposure, and every publication in force.
Every input the gate saw
| Claim | Required | Evidence class | Who | Age | Score | Outcome |
|---|---|---|---|---|---|---|
| vulnerability_triage_disposition | yes | MODELED | actor:ai:triage-assistant-v4 | 3d | 80% | admitted |
| vulnerability_scan | yes | VERIFIED | actor:sys:registry:nvd-cve | 4d | 95% | admitted |
| penetration_test | yes | VERIFIED | actor:org:LAB-NVLAP-0412 | 60d | 95% | admitted |
| control_assessment | yes | VERIFIED | actor:org:CERT-3PAO-ATLANTIC | 100d | 95% | admitted |
Instruments in force
Why
- Confidence 80.00% is bound by "ai-system:TRIAGE-ASSISTANT-V4|vulnerability_triage_disposition".
- Thresholds for $250,000 exposure: approve 85%, caution 60%.
The scoped copy itself — partial — something outside this role’s remit was removed
{
"spec": "corobate:role-view:2",
"role": "COMPLIANCE",
"purpose": "The operator’s own compliance function. The fullest internal view: every gap, every instrument in force, the waivability of each requirement and who accepted what.",
"is_a_receipt": false,
"warning": "This is a SCOPED COPY of a sealed decision, not the decision record itself. It will not verify as a receipt and must not be presented as one. To confirm it is faithful, recompute its `view` digest under the same canonicalisation that produces receipt_hash and compare it with the entry for this role in the source receipt’s `views` block.",
"derived_from": {
"receipt_hash": "sha256:e6038d8525d391ca3b49b3b8135e9b479595df9200a54c9f68c7cbb286b87a34",
"entry_hash": "sha256:2c628fa4efbfe5c02c5978f8f777b7877876cc40f378291a8bf847cd5db64977",
"issued_at": "2026-08-08T16:00:00.000Z"
},
"view_digest": "sha256:1c6958e7227b3b16a5c1056014c13a84c196169fea5293816b8931f006eab289",
"withheld": {
"anything_withheld": true,
"note": "Facts outside this role’s remit were removed. That something was removed is stated so a partial record is never mistaken for a complete one. How much, and what, is not stated — a count is an inference about the part you are not entitled to see."
},
"view": {
"spec": "urn:ietf:params:corobate:receipt:1",
"receipt_version": "1.8",
"issued_at": "2026-08-08T16:00:00.000Z",
"decision": {
"id": "ai_TRIAGE_EVIDENCE_ADMIT",
"domain": "supply-chain",
"subject": "ai-system:TRIAGE-ASSISTANT-V4",
"question": "May this quarter's vulnerability triage be accepted as the record of review?"
},
"memory": {
"state_digest": "sha256:9357ab4d994dcd108cd3f22257927b155d8e44f669c5c0bb8d3e9bfc6be9e52a",
"ledger_head": "sha256:d11e8eaa639930292fb398123e6aeefff52b74a09d6448ad6f8e6c8e154ce39f",
"coverage_gaps": [],
"exposure": {
"usd": 250000,
"declared_by": "actor:human:issm",
"ledger_seq": 4
},
"policy_digest": "sha256:a6b69b7d20f7fb04d522364af1d92992058b04a5835fcec9d1c9f2261c7ef636"
},
"data_horizon": "2026-08-08T16:00:00.000Z",
"verdict": {
"value": "CAUTION",
"threshold_approve": 0.85,
"threshold_caution": 0.6,
"rule": "confidence>=threshold"
},
"confidence": {
"value": 0.8,
"method": "min-over-critical-inputs",
"bound_by": "ai-system:TRIAGE-ASSISTANT-V4::vulnerability_triage_disposition"
},
"release": {
"required": false,
"required_by_tier": false,
"escalated_by_acceptance": false,
"risk_accepted": false,
"state": "NOT_REQUIRED",
"code": "QUORUM_NOT_REQUIRED",
"reason": "this decision is below the top exposure tier (floor $10,000,000) and no risk acceptance escalated into this gate, so no multi-party release requirement applies.",
"tier_floor_cents": 1000000000,
"exposure_usd_cents": 25000000,
"required_m": 2,
"declared_n": 3,
"floor_m": 2,
"distinct_signers": 0,
"superseded": 0,
"collapsed": 0,
"release_digest": "sha256:3174d524ab5881c0caf1099f0c0265966e5b12c85c71c87fc8f9af138736ff5c",
"governance_digest": "sha256:8b0a45a27fcce9c1c243c764e855e67c6fe6dfd7f02a563bd90809b419731905",
"governance_signed": true,
"counted_voices": [],
"signatures": [],
"ledger_seq": null
},
"acceptance": {
"state": "NONE",
"code": "ACCEPTANCE_NONE",
"reason": "no risk acceptance was presented for this decision. This is the ordinary case: a refusal is a refusal unless a named person has priced it.",
"permitted_basis": null,
"presented": 0,
"superseded": 0,
"expired": 0,
"gaps_not_covered": 0,
"coverage_gaps_in_force": [],
"evidentiary_digest": "sha256:3174d524ab5881c0caf1099f0c0265966e5b12c85c71c87fc8f9af138736ff5c",
"margin_floor_bp": 100,
"authority_ceiling_cents": {
"SUPERVISOR": 1000000,
"MANAGER": 25000000,
"DIRECTOR": 500000000,
"OFFICER": 5000000000
},
"acceptances": [],
"escalated": false,
"live": false,
"ledger_seq": null
},
"regulatory": {
"spec": "corobate:regulatory:2",
"resolved": true,
"applied": [
{
"instrument_id": "enterprise-ai-evidence-standard",
"version": 1,
"authority": "Office of the Chief Information Security Officer",
"instrument": "Enterprise standard on machine-generated evidence",
"edition": "2026-03-01",
"citation": "§ 3 [VERIFY]",
"source_digest": "sha256:e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5",
"entered_by": "actor:human:issm",
"entered_at": "2026-08-08T16:00:00.000Z"
},
{
"instrument_id": "nist-sp-800-53r5-moderate",
"version": 5,
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
"edition": "Rev. 5",
"citation": "CA-2, CA-8, RA-5, SR-6 [VERIFY]",
"source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353",
"entered_by": "actor:human:issm",
"entered_at": "2026-08-08T16:00:00.000Z"
}
],
"skipped": [],
"conflicts": [],
"bindings": [
{
"claim": "control_assessment",
"requirement": "max_age_days",
"value": 365,
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
"instrument_id": "nist-sp-800-53r5-moderate",
"version": 5,
"edition": "Rev. 5",
"citation": "CA-2 [VERIFY]",
"source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "control_assessment",
"requirement": "min_class",
"value": "VERIFIED",
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
"instrument_id": "nist-sp-800-53r5-moderate",
"version": 5,
"edition": "Rev. 5",
"citation": "CA-2(1) independent assessors [VERIFY]",
"source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "control_assessment",
"requirement": "required",
"value": true,
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
"instrument_id": "nist-sp-800-53r5-moderate",
"version": 5,
"edition": "Rev. 5",
"citation": "CA-2 [VERIFY]",
"source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "penetration_test",
"requirement": "min_class",
"value": "VERIFIED",
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
"instrument_id": "nist-sp-800-53r5-moderate",
"version": 5,
"edition": "Rev. 5",
"citation": "CA-8(1) independent penetration agent [VERIFY]",
"source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "penetration_test",
"requirement": "required",
"value": true,
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
"instrument_id": "nist-sp-800-53r5-moderate",
"version": 5,
"edition": "Rev. 5",
"citation": "CA-8 [VERIFY]",
"source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "vulnerability_scan",
"requirement": "max_age_days",
"value": 30,
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
"instrument_id": "nist-sp-800-53r5-moderate",
"version": 5,
"edition": "Rev. 5",
"citation": "RA-5(a) [VERIFY]",
"source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "vulnerability_scan",
"requirement": "required",
"value": true,
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
"instrument_id": "nist-sp-800-53r5-moderate",
"version": 5,
"edition": "Rev. 5",
"citation": "RA-5 [VERIFY]",
"source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "vulnerability_triage_disposition",
"requirement": "ai_position",
"value": "ADMIT",
"bound_by": {
"authority": "Office of the Chief Information Security Officer",
"instrument": "Enterprise standard on machine-generated evidence",
"instrument_id": "enterprise-ai-evidence-standard",
"version": 1,
"edition": "2026-03-01",
"citation": "§ 3.4 [VERIFY]",
"source_digest": "sha256:e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "vulnerability_triage_disposition",
"requirement": "required",
"value": true,
"bound_by": {
"authority": "Office of the Chief Information Security Officer",
"instrument": "Enterprise standard on machine-generated evidence",
"instrument_id": "enterprise-ai-evidence-standard",
"version": 1,
"edition": "2026-03-01",
"citation": "§ 3.1 [VERIFY]",
"source_digest": "sha256:e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
}
],
"defaults": [
{
"claim": "control_assessment",
"requirement": "ai_position",
"value": "ADMIT",
"because": "No instrument in force stated a position on AI-authored evidence for \"control_assessment\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
},
{
"claim": "penetration_test",
"requirement": "ai_position",
"value": "ADMIT",
"because": "No instrument in force stated a position on AI-authored evidence for \"penetration_test\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
},
{
"claim": "vulnerability_scan",
"requirement": "ai_position",
"value": "ADMIT",
"because": "No instrument in force stated a position on AI-authored evidence for \"vulnerability_scan\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
}
]
},
"reasons": [
"Confidence 80.00% is bound by \"ai-system:TRIAGE-ASSISTANT-V4|vulnerability_triage_disposition\".",
"Thresholds for $250,000 exposure: approve 85%, caution 60%."
],
"inputs": [
{
"key": "ai-system:TRIAGE-ASSISTANT-V4::vulnerability_triage_disposition",
"value": "412-triaged",
"provenance": "MODELED",
"source": "triage-assistant-v4:vulnerability_triage_disposition",
"observed_at": "2026-08-05T16:00:00.000Z",
"reliability": 0.8,
"critical": true,
"memory_status": "admitted",
"memory_kind": "status",
"memory_actor": "actor:ai:triage-assistant-v4",
"memory_age_days": 3
},
{
"key": "ai-system:TRIAGE-ASSISTANT-V4::vulnerability_scan",
"value": "clean-at-scan",
"provenance": "VERIFIED",
"source": "nvd-cve:vulnerability_scan",
"observed_at": "2026-08-04T16:00:00.000Z",
"reliability": 0.95,
"critical": true,
"memory_status": "admitted",
"memory_kind": "status",
"memory_actor": "actor:sys:registry:nvd-cve",
"memory_age_days": 4
},
{
"key": "ai-system:TRIAGE-ASSISTANT-V4::penetration_test",
"value": "no-critical",
"provenance": "VERIFIED",
"source": "LAB-NVLAP-0412:penetration_test",
"observed_at": "2026-06-09T16:00:00.000Z",
"reliability": 0.95,
"critical": true,
"memory_status": "admitted",
"memory_kind": "test_report",
"memory_actor": "actor:org:LAB-NVLAP-0412",
"memory_age_days": 60
},
{
"key": "ai-system:TRIAGE-ASSISTANT-V4::control_assessment",
"value": "satisfied",
"provenance": "VERIFIED",
"source": "CERT-3PAO-ATLANTIC:control_assessment",
"observed_at": "2026-04-30T16:00:00.000Z",
"reliability": 0.95,
"critical": true,
"memory_status": "admitted",
"memory_kind": "certificate",
"memory_actor": "actor:org:CERT-3PAO-ATLANTIC",
"memory_age_days": 100
}
],
"crypto_suite": {
"spec": "corobate:suite:1",
"id": "CB-1-ES256-SHA256",
"receipt_digest": "sha256",
"chain_digest": "sha256",
"content_digest": "sha256",
"envelope_signature": "ES256",
"signature_curve": "P-256",
"canonicalisation": "attest-canon/2",
"quantum_resistant": false
}
}
}Authorising official (signer)
The named official whose signature carries the authorisation decision.
What is at stake, what the evidence supports, what is missing, and the digest they are signing over.
You are being asked to sign
May this quarter's vulnerability triage be accepted as the record of review?
The signature is over the STATE OF THE EVIDENCE. Move one fact behind this decision and the digest moves and the signature stops counting — which is what makes it safe to collect signatures before everyone is in the room.
What is missing
- Nothing required is missing.
The scoped copy itself — partial — something outside this role’s remit was removed
{
"spec": "corobate:role-view:2",
"role": "EXECUTIVE",
"purpose": "A named signer on the release gate. Sees what is at stake, what the evidence supports, who else has signed and what they are being asked to sign over.",
"is_a_receipt": false,
"warning": "This is a SCOPED COPY of a sealed decision, not the decision record itself. It will not verify as a receipt and must not be presented as one. To confirm it is faithful, recompute its `view` digest under the same canonicalisation that produces receipt_hash and compare it with the entry for this role in the source receipt’s `views` block.",
"derived_from": {
"receipt_hash": "sha256:e6038d8525d391ca3b49b3b8135e9b479595df9200a54c9f68c7cbb286b87a34",
"entry_hash": "sha256:2c628fa4efbfe5c02c5978f8f777b7877876cc40f378291a8bf847cd5db64977",
"issued_at": "2026-08-08T16:00:00.000Z"
},
"view_digest": "sha256:1ebccbd14a774d07a3c0c503c1892adb2f3a95bfe13924e6787f116c6d079329",
"withheld": {
"anything_withheld": true,
"note": "Facts outside this role’s remit were removed. That something was removed is stated so a partial record is never mistaken for a complete one. How much, and what, is not stated — a count is an inference about the part you are not entitled to see."
},
"view": {
"spec": "urn:ietf:params:corobate:receipt:1",
"receipt_version": "1.8",
"issued_at": "2026-08-08T16:00:00.000Z",
"decision": {
"id": "ai_TRIAGE_EVIDENCE_ADMIT",
"domain": "supply-chain",
"subject": "ai-system:TRIAGE-ASSISTANT-V4",
"question": "May this quarter's vulnerability triage be accepted as the record of review?"
},
"memory": {
"state_digest": "sha256:9357ab4d994dcd108cd3f22257927b155d8e44f669c5c0bb8d3e9bfc6be9e52a",
"ledger_head": "sha256:d11e8eaa639930292fb398123e6aeefff52b74a09d6448ad6f8e6c8e154ce39f",
"coverage_gaps": [],
"exposure": {
"usd": 250000,
"declared_by": "actor:human:issm",
"ledger_seq": 4
}
},
"verdict": {
"value": "CAUTION",
"threshold_approve": 0.85,
"threshold_caution": 0.6,
"rule": "confidence>=threshold"
},
"confidence": {
"value": 0.8,
"method": "min-over-critical-inputs",
"bound_by": "ai-system:TRIAGE-ASSISTANT-V4::vulnerability_triage_disposition"
},
"release": {
"required": false,
"required_by_tier": false,
"escalated_by_acceptance": false,
"risk_accepted": false,
"state": "NOT_REQUIRED",
"code": "QUORUM_NOT_REQUIRED",
"reason": "this decision is below the top exposure tier (floor $10,000,000) and no risk acceptance escalated into this gate, so no multi-party release requirement applies.",
"tier_floor_cents": 1000000000,
"exposure_usd_cents": 25000000,
"required_m": 2,
"declared_n": 3,
"floor_m": 2,
"distinct_signers": 0,
"superseded": 0,
"collapsed": 0,
"release_digest": "sha256:3174d524ab5881c0caf1099f0c0265966e5b12c85c71c87fc8f9af138736ff5c",
"governance_digest": "sha256:8b0a45a27fcce9c1c243c764e855e67c6fe6dfd7f02a563bd90809b419731905",
"governance_signed": true,
"counted_voices": [],
"signatures": [],
"ledger_seq": null
},
"acceptance": {
"state": "NONE",
"code": "ACCEPTANCE_NONE",
"reason": "no risk acceptance was presented for this decision. This is the ordinary case: a refusal is a refusal unless a named person has priced it.",
"permitted_basis": null,
"presented": 0,
"superseded": 0,
"expired": 0,
"gaps_not_covered": 0,
"coverage_gaps_in_force": [],
"evidentiary_digest": "sha256:3174d524ab5881c0caf1099f0c0265966e5b12c85c71c87fc8f9af138736ff5c",
"margin_floor_bp": 100,
"authority_ceiling_cents": {
"SUPERVISOR": 1000000,
"MANAGER": 25000000,
"DIRECTOR": 500000000,
"OFFICER": 5000000000
},
"acceptances": [],
"escalated": false,
"live": false,
"ledger_seq": null
},
"reasons": [
"Confidence 80.00% is bound by \"ai-system:TRIAGE-ASSISTANT-V4|vulnerability_triage_disposition\".",
"Thresholds for $250,000 exposure: approve 85%, caution 60%."
],
"regulatory": {
"applied": [
{
"instrument_id": "enterprise-ai-evidence-standard",
"version": 1,
"authority": "Office of the Chief Information Security Officer",
"instrument": "Enterprise standard on machine-generated evidence",
"edition": "2026-03-01",
"citation": "§ 3 [VERIFY]",
"source_digest": "sha256:e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5",
"entered_by": "actor:human:issm",
"entered_at": "2026-08-08T16:00:00.000Z"
},
{
"instrument_id": "nist-sp-800-53r5-moderate",
"version": 5,
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
"edition": "Rev. 5",
"citation": "CA-2, CA-8, RA-5, SR-6 [VERIFY]",
"source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353",
"entered_by": "actor:human:issm",
"entered_at": "2026-08-08T16:00:00.000Z"
}
],
"conflicts": [],
"defaults": [
{
"claim": "control_assessment",
"requirement": "ai_position",
"value": "ADMIT",
"because": "No instrument in force stated a position on AI-authored evidence for \"control_assessment\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
},
{
"claim": "penetration_test",
"requirement": "ai_position",
"value": "ADMIT",
"because": "No instrument in force stated a position on AI-authored evidence for \"penetration_test\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
},
{
"claim": "vulnerability_scan",
"requirement": "ai_position",
"value": "ADMIT",
"because": "No instrument in force stated a position on AI-authored evidence for \"vulnerability_scan\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
}
]
},
"inputs": [
{
"key": "ai-system:TRIAGE-ASSISTANT-V4::vulnerability_triage_disposition",
"provenance": "MODELED",
"reliability": 0.8,
"critical": true,
"memory_status": "admitted"
},
{
"key": "ai-system:TRIAGE-ASSISTANT-V4::vulnerability_scan",
"provenance": "VERIFIED",
"reliability": 0.95,
"critical": true,
"memory_status": "admitted"
},
{
"key": "ai-system:TRIAGE-ASSISTANT-V4::penetration_test",
"provenance": "VERIFIED",
"reliability": 0.95,
"critical": true,
"memory_status": "admitted"
},
{
"key": "ai-system:TRIAGE-ASSISTANT-V4::control_assessment",
"provenance": "VERIFIED",
"reliability": 0.95,
"critical": true,
"memory_status": "admitted"
}
]
}
}Independent audit / IG
Internal audit, an inspector general, or an external auditor testing the programme.
Everything, plus the verifier’s own findings over the sealed record.
This view withholds nothing. What it adds is the 22 checks the published verifier ran over the sealed record behind every other view of this decision — recomputed at build time, not asserted.
| # | Check | Detail | |
|---|---|---|---|
| 1 | Content reproduces (JCS + SHA-256) | PASS | matches sha256:e6038d8525d391ca3b49b3b8135e9b479595df9200a54c9f68c7cbb286b87a34 |
| 2 | Hash chain links (entry = H(prev||content)) | PASS | head sha256:2c628fa4efbfe5c02c5978f8f777b7877876cc40f378291a8bf847cd5db64977 |
| 3 | Confidence gated by weakest critical input | PASS | min over critical = 0.8, bound_by ai-system:TRIAGE-ASSISTANT-V4::vulnerability_triage_disposition (MODELED) |
| 3b | Verdict follows the threshold rule | PASS | 0.8 => CAUTION; recorded CAUTION |
| 4 | Point-in-time seal (no input past data_horizon) | PASS | all inputs <= 2026-08-08T16:00:00.000Z |
| 5 | Anchor covers the head, and the timestamp token re-reads | PASS | internally consistent; NO external anchor was requested — this is not a validated timestamp |
| 6 | Criteria travel with the receipt and reproduce | PASS | policy_body hashes to sha256:a6b69b7d20f7fb04d522364af1d92992058b04a5835fcec9d1c9f2261c7ef636 |
| 7 | Reliability re-derives from recorded evidence | PASS | all 4 inputs re-derive exactly |
| 8 | Outcome trials and lineage discounts re-derive | PASS | 4 input(s) re-derive: 0 credited outcome trial(s), 0 lineage-discounted corroboration(s); every reliability is at or under its class ceiling |
| 9 | Re-ingested receipts respect their weakest-input ceiling | PASS | no re-ingested receipts: every input rests on a primary observation |
| 10 | Release quorum re-derives | PASS | NOT_REQUIRED - below the top exposure tier, no multi-party requirement applies |
| 11 | Risk acceptance re-derives | PASS | no risk acceptance: this decision stands or falls on its evidence |
| 12 | Observer credentials were not revoked as of observation time | PASS | revocation list 5 (0 entries, issued 2026-08-06T00:00:00.000Z, next update due 2026-08-13T00:00:00.000Z) reproduces; 4 observer signature(s) judged as of their own instant, none under a key revoked as compromised or retired by then |
| 13 | The cryptographic suite is named and is one this verifier implements | PASS | sealed under CB-1-ES256-SHA256 (ES256 / sha256, attest-canon/2); this verifier implements it; the suite states it is NOT quantum resistant |
| 14 | Regulatory bindings are attributed and were enforced | PASS | 9 binding(s) from 2 instrument(s) in force, each attributed to an authority, a citation and a document digest; 4 required claim(s) all reached the gate |
| 15 | Role-view commitments re-derive, and the customs view carries no money | PASS | 6 role-view commitment(s) re-derived from this receipt’s own body by this verifier’s independent projection; the REGULATOR view carries no commercial figure |
| 16 | AI-authored input was admitted only where an authority allowed it | PASS | 1 claim(s) carry a position on AI-authored evidence set by an authority and 3 carry a recorded default nobody set; 0 exclusion(s) and 0 corroboration-only rule(s) re-derived against this receipt's own admitted inputs; 1 admitted input(s) are AI-authored by their enrolled identity (actor:ai:triage-assistant-v4) |
| 17 | State digest recomputes from the ledger alone | UNVERIFIABLE | NOT APPLICABLE — you supplied no ledger, so the state digest cannot be re-derived from anything. This receipt commits to the corpus the deciding system held at the instant it sealed, and that commitment is checked by recomputing it from the append-only ledger and comparing; with no ledger in hand there is no second artefact to recompute from. The receipt is not at fault and nothing here is missing from it. Obtain the ledger from the issuer and re-run with --ledger <file>, or verifyReceipt(r, {ledger}). Nothing here has failed and nothing here has passed. |
| 18 | Registry membership re-derives for every key relied on | PASS | all 4 key(s) relied on re-derive to the entries root registry v3 committed to and the trust root signed |
| 20 | Geometric support re-derives, and an unevaluated record is not a supported one | PASS | no authority bound a metric to any claim on this receipt, so no geometric test applied. A claim nobody bound a metric to is not a claim about geometry, and this is a stated absence rather than a silent one |
| 19 | The cause of every uncovered requirement re-derives | PASS | every required claim on this receipt is covered, so this check ran and had nothing to explain |
| 21 | The sealing party is the one you were told to expect | UNVERIFIABLE | NOT APPLICABLE — you supplied no trust bundle, so nothing here establishes who sealed this. Identities 1 to 20 prove that this document agrees with itself; not one of them asks whose trust root it was sealed under, and a document that agrees with itself about a decision nobody made agrees with itself perfectly. Obtain the issuer's corobate:trust-bundle:1 out of band, confirm its spoken fingerprint with them by voice, and re-run with --trust-bundle <file> --expect-fingerprint <what you heard>. Nothing here has failed and nothing here has passed. |
The scoped copy itself — complete for this role
{
"spec": "corobate:role-view:2",
"role": "AUDITOR",
"purpose": "An external assessor. Sees the complete sealed record: this view withholds nothing and exists so the identity case is a case rather than an exception.",
"is_a_receipt": false,
"warning": "This is a SCOPED COPY of a sealed decision, not the decision record itself. It will not verify as a receipt and must not be presented as one. To confirm it is faithful, recompute its `view` digest under the same canonicalisation that produces receipt_hash and compare it with the entry for this role in the source receipt’s `views` block.",
"derived_from": {
"receipt_hash": "sha256:e6038d8525d391ca3b49b3b8135e9b479595df9200a54c9f68c7cbb286b87a34",
"entry_hash": "sha256:2c628fa4efbfe5c02c5978f8f777b7877876cc40f378291a8bf847cd5db64977",
"issued_at": "2026-08-08T16:00:00.000Z"
},
"view_digest": "sha256:829aa222cd3e07054f6ea39841e34280e3842f9709d8fbfd163da120eaa8ae28",
"withheld": {
"anything_withheld": false,
"note": "Nothing outside the seal was removed for this role."
},
"view": {
"spec": "urn:ietf:params:corobate:receipt:1",
"receipt_version": "1.8",
"engine": {
"name": "corobate-memory",
"version": "1.0.0"
},
"decision": {
"id": "ai_TRIAGE_EVIDENCE_ADMIT",
"domain": "supply-chain",
"subject": "ai-system:TRIAGE-ASSISTANT-V4",
"question": "May this quarter's vulnerability triage be accepted as the record of review?"
},
"issued_at": "2026-08-08T16:00:00.000Z",
"data_horizon": "2026-08-08T16:00:00.000Z",
"inputs": [
{
"key": "ai-system:TRIAGE-ASSISTANT-V4::vulnerability_triage_disposition",
"value": "412-triaged",
"provenance": "MODELED",
"source": "triage-assistant-v4:vulnerability_triage_disposition",
"observed_at": "2026-08-05T16:00:00.000Z",
"last_corroborated_at": null,
"memory_refreshed_by": [],
"reliability": 0.8,
"critical": true,
"memory_id": "mem_0a6980bbce9f",
"memory_status": "admitted",
"memory_kind": "status",
"memory_actor": "actor:ai:triage-assistant-v4",
"memory_age_days": 3,
"memory_track": {
"n": 1,
"successes": 1
},
"memory_promoted_by": [],
"memory_content_digest": "sha256:612e098189acf7652c237b016c3537b38c17d735452f4f1d519c6bfa0772b2c2",
"memory_outcomes": {
"verified": 0,
"falsified": 0,
"modified": 0,
"counted": 0,
"recorded": 0
},
"memory_outcome_attestations": [],
"memory_observer_lineage": null,
"memory_corroborations": [],
"memory_reingest": null,
"memory_reasons": [
"sparse track record: 1 independent observation(s); no failure recorded, so the class ceiling stands"
],
"memory_class_floor": null,
"memory_below_class_floor": false,
"memory_not_attested": false,
"memory_below_claim_reliability_floor": false,
"memory_not_competent_authority": false,
"memory_out_of_specification": false,
"memory_ai_authored": true,
"memory_ai_in_lineage": false,
"memory_ai_position": "ADMIT",
"memory_ai_inadmissible": false,
"memory_geo_inadmissible": false,
"memory_geo_rung": null,
"memory_geo_metric": null,
"memory_geo_required_metric": null,
"observer_attested": true,
"observer_auth_code": "VERIFIED",
"observer_key_id": "k_f71bde46a9680d8d",
"attestation": null,
"derivation": {
"provenance": "MODELED",
"ceiling_bp": 8000,
"track": {
"n": 1,
"successes": 1
},
"wilson_bp": null,
"age_days": 3,
"max_age_days": 14,
"house_max_age_days": 14,
"instrument_max_age_days": null,
"freshness_cap_bp": 4000,
"min_track_n": 5,
"wilson_z_milli": 1960,
"source_present": true,
"seller_asserted_cap_bp": 5000,
"retracted": false,
"contradicted": false,
"outcome_trials": 0,
"outcomes": {
"verified": 0,
"falsified": 0,
"modified": 0,
"counted": 0,
"recorded": 0
},
"corroborations_counted": 0,
"corroborations_discounted": 0,
"reingest_ceiling_bp": null,
"reingest_depth": null,
"reingest_weakest_class": null,
"reingest_source_confidence_bp": null,
"ai_authored": true,
"ai_authored_because": "a model, named as one in its own enrolled identity",
"ai_in_lineage": false,
"ai_position": "ADMIT"
},
"memory_reason_codes": [
{
"code": "SPARSE_TRACK_RECORD",
"observed": 1,
"limit": 5,
"binding": false
}
],
"context_line": "[MODELED · r=80.0% · 3d · triage-assistant-v4:vulnerability_triage_disposition] ai-system:TRIAGE-ASSISTANT-V4 / vulnerability_triage_disposition: 412-triaged"
},
{
"key": "ai-system:TRIAGE-ASSISTANT-V4::vulnerability_scan",
"value": "clean-at-scan",
"provenance": "VERIFIED",
"source": "nvd-cve:vulnerability_scan",
"observed_at": "2026-08-04T16:00:00.000Z",
"last_corroborated_at": null,
"memory_refreshed_by": [],
"reliability": 0.95,
"critical": true,
"memory_id": "mem_4d2b1fc0d322",
"memory_status": "admitted",
"memory_kind": "status",
"memory_actor": "actor:sys:registry:nvd-cve",
"memory_age_days": 4,
"memory_track": {
"n": 1,
"successes": 1
},
"memory_promoted_by": [],
"memory_content_digest": "sha256:aea4c3860d57b3edd045cd33946015c41ff1aee9cc8a4df49f26d8a5165d4a38",
"memory_outcomes": {
"verified": 0,
"falsified": 0,
"modified": 0,
"counted": 0,
"recorded": 0
},
"memory_outcome_attestations": [],
"memory_observer_lineage": null,
"memory_corroborations": [],
"memory_reingest": null,
"memory_reasons": [
"sparse track record: 1 independent observation(s); no failure recorded, so the class ceiling stands"
],
"memory_class_floor": null,
"memory_below_class_floor": false,
"memory_not_attested": false,
"memory_below_claim_reliability_floor": false,
"memory_not_competent_authority": false,
"memory_out_of_specification": false,
"memory_ai_authored": false,
"memory_ai_in_lineage": false,
"memory_ai_position": "ADMIT",
"memory_ai_inadmissible": false,
"memory_geo_inadmissible": false,
"memory_geo_rung": null,
"memory_geo_metric": null,
"memory_geo_required_metric": null,
"observer_attested": true,
"observer_auth_code": "VERIFIED",
"observer_key_id": "k_5873dd9e7169def3",
"attestation": null,
"derivation": {
"provenance": "VERIFIED",
"ceiling_bp": 9500,
"track": {
"n": 1,
"successes": 1
},
"wilson_bp": null,
"age_days": 4,
"max_age_days": 14,
"house_max_age_days": 14,
"instrument_max_age_days": 30,
"freshness_cap_bp": 4000,
"min_track_n": 5,
"wilson_z_milli": 1960,
"source_present": true,
"seller_asserted_cap_bp": 5000,
"retracted": false,
"contradicted": false,
"outcome_trials": 0,
"outcomes": {
"verified": 0,
"falsified": 0,
"modified": 0,
"counted": 0,
"recorded": 0
},
"corroborations_counted": 0,
"corroborations_discounted": 0,
"reingest_ceiling_bp": null,
"reingest_depth": null,
"reingest_weakest_class": null,
"reingest_source_confidence_bp": null,
"ai_authored": false,
"ai_authored_because": null,
"ai_in_lineage": false,
"ai_position": "ADMIT"
},
"memory_reason_codes": [
{
"code": "SPARSE_TRACK_RECORD",
"observed": 1,
"limit": 5,
"binding": false
}
],
"context_line": "[VERIFIED · r=95.0% · 4d · nvd-cve:vulnerability_scan] ai-system:TRIAGE-ASSISTANT-V4 / vulnerability_scan: clean-at-scan"
},
{
"key": "ai-system:TRIAGE-ASSISTANT-V4::penetration_test",
"value": "no-critical",
"provenance": "VERIFIED",
"source": "LAB-NVLAP-0412:penetration_test",
"observed_at": "2026-06-09T16:00:00.000Z",
"last_corroborated_at": null,
"memory_refreshed_by": [],
"reliability": 0.95,
"critical": true,
"memory_id": "mem_a3316d633bfe",
"memory_status": "admitted",
"memory_kind": "test_report",
"memory_actor": "actor:org:LAB-NVLAP-0412",
"memory_age_days": 60,
"memory_track": {
"n": 1,
"successes": 1
},
"memory_promoted_by": [],
"memory_content_digest": "sha256:db69fb062be9b066b370c668281e12896da2869456a2e6d356a0f14879b27de9",
"memory_outcomes": {
"verified": 0,
"falsified": 0,
"modified": 0,
"counted": 0,
"recorded": 0
},
"memory_outcome_attestations": [],
"memory_observer_lineage": null,
"memory_corroborations": [],
"memory_reingest": null,
"memory_reasons": [
"sparse track record: 1 independent observation(s); no failure recorded, so the class ceiling stands"
],
"memory_class_floor": "VERIFIED",
"memory_below_class_floor": false,
"memory_not_attested": false,
"memory_below_claim_reliability_floor": false,
"memory_not_competent_authority": false,
"memory_out_of_specification": false,
"memory_ai_authored": false,
"memory_ai_in_lineage": false,
"memory_ai_position": "ADMIT",
"memory_ai_inadmissible": false,
"memory_geo_inadmissible": false,
"memory_geo_rung": null,
"memory_geo_metric": null,
"memory_geo_required_metric": null,
"observer_attested": true,
"observer_auth_code": "VERIFIED",
"observer_key_id": "k_17d23885943ae529",
"attestation": null,
"derivation": {
"provenance": "VERIFIED",
"ceiling_bp": 9500,
"track": {
"n": 1,
"successes": 1
},
"wilson_bp": null,
"age_days": 60,
"max_age_days": 180,
"house_max_age_days": 180,
"instrument_max_age_days": null,
"freshness_cap_bp": 4000,
"min_track_n": 5,
"wilson_z_milli": 1960,
"source_present": true,
"seller_asserted_cap_bp": 5000,
"retracted": false,
"contradicted": false,
"outcome_trials": 0,
"outcomes": {
"verified": 0,
"falsified": 0,
"modified": 0,
"counted": 0,
"recorded": 0
},
"corroborations_counted": 0,
"corroborations_discounted": 0,
"reingest_ceiling_bp": null,
"reingest_depth": null,
"reingest_weakest_class": null,
"reingest_source_confidence_bp": null,
"min_class_floor": "VERIFIED",
"ai_authored": false,
"ai_authored_because": null,
"ai_in_lineage": false,
"ai_position": "ADMIT"
},
"memory_reason_codes": [
{
"code": "SPARSE_TRACK_RECORD",
"observed": 1,
"limit": 5,
"binding": false
}
],
"context_line": "[VERIFIED · r=95.0% · 60d · LAB-NVLAP-0412:penetration_test] ai-system:TRIAGE-ASSISTANT-V4 / penetration_test: no-critical"
},
{
"key": "ai-system:TRIAGE-ASSISTANT-V4::control_assessment",
"value": "satisfied",
"provenance": "VERIFIED",
"source": "CERT-3PAO-ATLANTIC:control_assessment",
"observed_at": "2026-04-30T16:00:00.000Z",
"last_corroborated_at": null,
"memory_refreshed_by": [],
"reliability": 0.95,
"critical": true,
"memory_id": "mem_a153eb336060",
"memory_status": "admitted",
"memory_kind": "certificate",
"memory_actor": "actor:org:CERT-3PAO-ATLANTIC",
"memory_age_days": 100,
"memory_track": {
"n": 1,
"successes": 1
},
"memory_promoted_by": [],
"memory_content_digest": "sha256:c1aaf46a55b4cdc629a754ac35da1b8ec4dec85c2c78613c7bc93546b63f233c",
"memory_outcomes": {
"verified": 0,
"falsified": 0,
"modified": 0,
"counted": 0,
"recorded": 0
},
"memory_outcome_attestations": [],
"memory_observer_lineage": null,
"memory_corroborations": [],
"memory_reingest": null,
"memory_reasons": [
"sparse track record: 1 independent observation(s); no failure recorded, so the class ceiling stands"
],
"memory_class_floor": "VERIFIED",
"memory_below_class_floor": false,
"memory_not_attested": false,
"memory_below_claim_reliability_floor": false,
"memory_not_competent_authority": false,
"memory_out_of_specification": false,
"memory_ai_authored": false,
"memory_ai_in_lineage": false,
"memory_ai_position": "ADMIT",
"memory_ai_inadmissible": false,
"memory_geo_inadmissible": false,
"memory_geo_rung": null,
"memory_geo_metric": null,
"memory_geo_required_metric": null,
"observer_attested": true,
"observer_auth_code": "VERIFIED",
"observer_key_id": "k_307e4bfd710ec9b3",
"attestation": null,
"derivation": {
"provenance": "VERIFIED",
"ceiling_bp": 9500,
"track": {
"n": 1,
"successes": 1
},
"wilson_bp": null,
"age_days": 100,
"max_age_days": 365,
"house_max_age_days": 365,
"instrument_max_age_days": 365,
"freshness_cap_bp": 4000,
"min_track_n": 5,
"wilson_z_milli": 1960,
"source_present": true,
"seller_asserted_cap_bp": 5000,
"retracted": false,
"contradicted": false,
"outcome_trials": 0,
"outcomes": {
"verified": 0,
"falsified": 0,
"modified": 0,
"counted": 0,
"recorded": 0
},
"corroborations_counted": 0,
"corroborations_discounted": 0,
"reingest_ceiling_bp": null,
"reingest_depth": null,
"reingest_weakest_class": null,
"reingest_source_confidence_bp": null,
"min_class_floor": "VERIFIED",
"ai_authored": false,
"ai_authored_because": null,
"ai_in_lineage": false,
"ai_position": "ADMIT"
},
"memory_reason_codes": [
{
"code": "SPARSE_TRACK_RECORD",
"observed": 1,
"limit": 5,
"binding": false
}
],
"context_line": "[VERIFIED · r=95.0% · 100d · CERT-3PAO-ATLANTIC:control_assessment] ai-system:TRIAGE-ASSISTANT-V4 / control_assessment: satisfied"
}
],
"serialization": {
"algorithm": "RFC8785-JCS",
"hash": "sha256"
},
"crypto_suite": {
"spec": "corobate:suite:1",
"id": "CB-1-ES256-SHA256",
"receipt_digest": "sha256",
"chain_digest": "sha256",
"content_digest": "sha256",
"envelope_signature": "ES256",
"signature_curve": "P-256",
"canonicalisation": "attest-canon/2",
"quantum_resistant": false
},
"confidence": {
"value": 0.8,
"method": "min-over-critical-inputs",
"bound_by": "ai-system:TRIAGE-ASSISTANT-V4::vulnerability_triage_disposition"
},
"verdict": {
"value": "CAUTION",
"threshold_approve": 0.85,
"threshold_caution": 0.6,
"rule": "confidence>=threshold"
},
"release": {
"required": false,
"required_by_tier": false,
"escalated_by_acceptance": false,
"risk_accepted": false,
"state": "NOT_REQUIRED",
"code": "QUORUM_NOT_REQUIRED",
"reason": "this decision is below the top exposure tier (floor $10,000,000) and no risk acceptance escalated into this gate, so no multi-party release requirement applies.",
"tier_floor_cents": 1000000000,
"exposure_usd_cents": 25000000,
"required_m": 2,
"declared_n": 3,
"floor_m": 2,
"distinct_signers": 0,
"superseded": 0,
"collapsed": 0,
"release_digest": "sha256:3174d524ab5881c0caf1099f0c0265966e5b12c85c71c87fc8f9af138736ff5c",
"governance_digest": "sha256:8b0a45a27fcce9c1c243c764e855e67c6fe6dfd7f02a563bd90809b419731905",
"governance_signed": true,
"counted_voices": [],
"signatures": [],
"ledger_seq": null
},
"acceptance": {
"state": "NONE",
"code": "ACCEPTANCE_NONE",
"reason": "no risk acceptance was presented for this decision. This is the ordinary case: a refusal is a refusal unless a named person has priced it.",
"permitted_basis": null,
"presented": 0,
"superseded": 0,
"expired": 0,
"gaps_not_covered": 0,
"coverage_gaps_in_force": [],
"evidentiary_digest": "sha256:3174d524ab5881c0caf1099f0c0265966e5b12c85c71c87fc8f9af138736ff5c",
"margin_floor_bp": 100,
"authority_ceiling_cents": {
"SUPERVISOR": 1000000,
"MANAGER": 25000000,
"DIRECTOR": 500000000,
"OFFICER": 5000000000
},
"acceptances": [],
"escalated": false,
"live": false,
"ledger_seq": null
},
"regulatory": {
"spec": "corobate:regulatory:2",
"resolved": true,
"applied": [
{
"instrument_id": "enterprise-ai-evidence-standard",
"version": 1,
"authority": "Office of the Chief Information Security Officer",
"instrument": "Enterprise standard on machine-generated evidence",
"edition": "2026-03-01",
"citation": "§ 3 [VERIFY]",
"source_digest": "sha256:e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5",
"entered_by": "actor:human:issm",
"entered_at": "2026-08-08T16:00:00.000Z"
},
{
"instrument_id": "nist-sp-800-53r5-moderate",
"version": 5,
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
"edition": "Rev. 5",
"citation": "CA-2, CA-8, RA-5, SR-6 [VERIFY]",
"source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353",
"entered_by": "actor:human:issm",
"entered_at": "2026-08-08T16:00:00.000Z"
}
],
"skipped": [],
"conflicts": [],
"bindings": [
{
"claim": "control_assessment",
"requirement": "max_age_days",
"value": 365,
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
"instrument_id": "nist-sp-800-53r5-moderate",
"version": 5,
"edition": "Rev. 5",
"citation": "CA-2 [VERIFY]",
"source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "control_assessment",
"requirement": "min_class",
"value": "VERIFIED",
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
"instrument_id": "nist-sp-800-53r5-moderate",
"version": 5,
"edition": "Rev. 5",
"citation": "CA-2(1) independent assessors [VERIFY]",
"source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "control_assessment",
"requirement": "required",
"value": true,
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
"instrument_id": "nist-sp-800-53r5-moderate",
"version": 5,
"edition": "Rev. 5",
"citation": "CA-2 [VERIFY]",
"source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "penetration_test",
"requirement": "min_class",
"value": "VERIFIED",
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
"instrument_id": "nist-sp-800-53r5-moderate",
"version": 5,
"edition": "Rev. 5",
"citation": "CA-8(1) independent penetration agent [VERIFY]",
"source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "penetration_test",
"requirement": "required",
"value": true,
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
"instrument_id": "nist-sp-800-53r5-moderate",
"version": 5,
"edition": "Rev. 5",
"citation": "CA-8 [VERIFY]",
"source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "vulnerability_scan",
"requirement": "max_age_days",
"value": 30,
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
"instrument_id": "nist-sp-800-53r5-moderate",
"version": 5,
"edition": "Rev. 5",
"citation": "RA-5(a) [VERIFY]",
"source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "vulnerability_scan",
"requirement": "required",
"value": true,
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
"instrument_id": "nist-sp-800-53r5-moderate",
"version": 5,
"edition": "Rev. 5",
"citation": "RA-5 [VERIFY]",
"source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "vulnerability_triage_disposition",
"requirement": "ai_position",
"value": "ADMIT",
"bound_by": {
"authority": "Office of the Chief Information Security Officer",
"instrument": "Enterprise standard on machine-generated evidence",
"instrument_id": "enterprise-ai-evidence-standard",
"version": 1,
"edition": "2026-03-01",
"citation": "§ 3.4 [VERIFY]",
"source_digest": "sha256:e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "vulnerability_triage_disposition",
"requirement": "required",
"value": true,
"bound_by": {
"authority": "Office of the Chief Information Security Officer",
"instrument": "Enterprise standard on machine-generated evidence",
"instrument_id": "enterprise-ai-evidence-standard",
"version": 1,
"edition": "2026-03-01",
"citation": "§ 3.1 [VERIFY]",
"source_digest": "sha256:e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
}
],
"defaults": [
{
"claim": "control_assessment",
"requirement": "ai_position",
"value": "ADMIT",
"because": "No instrument in force stated a position on AI-authored evidence for \"control_assessment\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
},
{
"claim": "penetration_test",
"requirement": "ai_position",
"value": "ADMIT",
"because": "No instrument in force stated a position on AI-authored evidence for \"penetration_test\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
},
{
"claim": "vulnerability_scan",
"requirement": "ai_position",
"value": "ADMIT",
"because": "No instrument in force stated a position on AI-authored evidence for \"vulnerability_scan\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
}
]
},
"reasons": [
"Confidence 80.00% is bound by \"ai-system:TRIAGE-ASSISTANT-V4|vulnerability_triage_disposition\".",
"Thresholds for $250,000 exposure: approve 85%, caution 60%."
],
"memory": {
"layer": "capture->store->recall->act",
"ledger_head": "sha256:d11e8eaa639930292fb398123e6aeefff52b74a09d6448ad6f8e6c8e154ce39f",
"ledger_entries": 6,
"context_digest": "sha256:65e002162e15f455ef2fd75329ee96a1849c1c750f0f4fd3d5108a009fe44ab4",
"context_memory_ids": [
"mem_0a6980bbce9f",
"mem_4d2b1fc0d322",
"mem_a153eb336060",
"mem_a3316d633bfe"
],
"state_digest": "sha256:9357ab4d994dcd108cd3f22257927b155d8e44f669c5c0bb8d3e9bfc6be9e52a",
"retrieval_method": "idf-lexical",
"corpus_size": 4,
"considered": 4,
"admitted": 4,
"withheld": 0,
"not_considered": 0,
"coverage_gaps": [],
"exposure": {
"usd": 250000,
"declared_by": "actor:human:issm",
"ledger_seq": 4
},
"salience_policy": {
"half_life_days": 90,
"grace_days": 7,
"access_boost_bp": 500,
"access_boost_cap_bp": 2500,
"relevance_weight_bp": 6000,
"recency_weight_bp": 3000,
"usage_weight_bp": 1000,
"context_cap": 12,
"method": "idf-lexical",
"candidate_list_digest": "sha256:fa532eca9f6e74d805d7557e2b12f0a9b5ac6a3262e163b632463317b542709f",
"note": "salience orders retrieval only; it never contributes to reliability"
},
"policy_digest": "sha256:a6b69b7d20f7fb04d522364af1d92992058b04a5835fcec9d1c9f2261c7ef636",
"policy_body": {
"class_ceiling_bp": {
"VERIFIED": 9500,
"MODELED": 8000,
"SELLER-ASSERTED": 5000,
"MISSING": 0
},
"actor_class_ceiling": [
[
"^actor:ai:",
"MODELED"
],
[
"^actor:agent:",
"MODELED"
],
[
"^actor:human:",
"SELLER-ASSERTED"
],
[
"^actor:org:LAB-",
"VERIFIED"
],
[
"^actor:org:CERT-",
"VERIFIED"
],
[
"^actor:org:",
"SELLER-ASSERTED"
],
[
"^actor:sys:registry:",
"VERIFIED"
],
[
"^actor:sys:sensor:",
"VERIFIED"
],
[
"^actor:sys:",
"MODELED"
]
],
"freshness_cap_bp": 4000,
"max_age_days": {
"telemetry": 1,
"price": 7,
"status": 14,
"certificate": 365,
"test_report": 180,
"filing": 90,
"transcript": 120,
"highlight": 365,
"voice_note": 120,
"note": 365,
"preference": 540,
"decision": 1825,
"receipt": 365,
"default": 90
},
"wilson_z_milli": 1960,
"min_track_n": 5,
"exposure_tiers_bp": [
[
1000000000,
9500,
8000
],
[
100000000,
9000,
7000
],
[
1000000,
8500,
6000
],
[
0,
8000,
5000
]
],
"max_context_memories": 12,
"contradiction_resolve_margin": 2,
"salience": {
"half_life_days": 90,
"grace_days": 7,
"access_boost_bp": 500,
"access_boost_cap_bp": 2500,
"relevance_weight_bp": 6000,
"recency_weight_bp": 3000,
"usage_weight_bp": 1000
}
},
"observer_auth": {
"mode": "required",
"registry_version": 3,
"registry_digest": "sha256:460aeaafe345f69542a302e6619dff0712af98de6518838ee4c8585e448c3a7d",
"entries_root": "sha256:5670469f96484a814462814ed74f0f992b5f19e8ad6afced548e4956e4835ba5",
"memberships": [
{
"key_id": "k_17d23885943ae529",
"index": 1,
"entry": {
"actor": "actor:org:LAB-NVLAP-0412",
"class": "VERIFIED",
"kind": "org",
"key_id": "k_17d23885943ae529",
"jwk": {
"kty": "EC",
"crv": "P-256",
"x": "3TTw47-PkYfo3ZaKTq_qtHghnGvninAVj25kyOwONno",
"y": "16PMaR8ofeF5IcZk6ZLml8gDs8uE1s1sBLdciH5e4vg"
},
"valid_from": "2025-01-01T00:00:00.000Z",
"valid_to": "2027-06-01T00:00:00.000Z"
},
"path": [
{
"side": "left",
"sibling": "sha256:500f2ba5949d5256ae0f563530b0b270db41ce99d2d7c4b4b60e4bd558ca353d"
},
{
"side": "right",
"sibling": "sha256:a0b47ea437bf4f1042a1dd50a5a3f411f9a17971812fc6bafccd434eb7d78ccc"
},
{
"side": "right",
"sibling": "sha256:d3c2347eb675e865fc17ef0204cacda7b02e8784a811fdd1c8a015d1865e6dfb"
},
{
"side": "right",
"sibling": "sha256:7071adf5e21a94147d31f42f1028b4867b6562e5b78726259c2515b03b213e52"
}
]
},
{
"key_id": "k_307e4bfd710ec9b3",
"index": 0,
"entry": {
"actor": "actor:org:CERT-3PAO-ATLANTIC",
"class": "VERIFIED",
"kind": "org",
"key_id": "k_307e4bfd710ec9b3",
"jwk": {
"kty": "EC",
"crv": "P-256",
"x": "MGtV26TezLMPjiD3SecQtnje6eLqYyx4qkKzzAkbiY4",
"y": "SMMdLYnn-FpKbb2sJQ8EAZnzvozNm-cGO0VbUUpniPY"
},
"valid_from": "2025-01-01T00:00:00.000Z",
"valid_to": "2027-06-01T00:00:00.000Z"
},
"path": [
{
"side": "right",
"sibling": "sha256:4148869fc259d2c5fc19fe5831065b165a9acf81812e123162035acfdecade1d"
},
{
"side": "right",
"sibling": "sha256:a0b47ea437bf4f1042a1dd50a5a3f411f9a17971812fc6bafccd434eb7d78ccc"
},
{
"side": "right",
"sibling": "sha256:d3c2347eb675e865fc17ef0204cacda7b02e8784a811fdd1c8a015d1865e6dfb"
},
{
"side": "right",
"sibling": "sha256:7071adf5e21a94147d31f42f1028b4867b6562e5b78726259c2515b03b213e52"
}
]
},
{
"key_id": "k_5873dd9e7169def3",
"index": 2,
"entry": {
"actor": "actor:sys:registry:nvd-cve",
"class": "VERIFIED",
"kind": "system",
"key_id": "k_5873dd9e7169def3",
"jwk": {
"kty": "EC",
"crv": "P-256",
"x": "O9OY6oMuJg0df_INePO19_3b11VaSyMwIPdxoqvV2ak",
"y": "k7Orm5pxDxMdTF-H2S4h6ixRywzk1WxvquOQeqxLFx0"
},
"valid_from": "2025-01-01T00:00:00.000Z",
"valid_to": "2027-06-01T00:00:00.000Z"
},
"path": [
{
"side": "right",
"sibling": "sha256:e1fe36fe7c8e4695327c25d6d722630b6249c93293bfdc5894c58aaf961ab6f8"
},
{
"side": "left",
"sibling": "sha256:e8b9cba101f13538b909a2e686e9e6e9a8d77212036ed567eaebc205a443e83f"
},
{
"side": "right",
"sibling": "sha256:d3c2347eb675e865fc17ef0204cacda7b02e8784a811fdd1c8a015d1865e6dfb"
},
{
"side": "right",
"sibling": "sha256:7071adf5e21a94147d31f42f1028b4867b6562e5b78726259c2515b03b213e52"
}
]
},
{
"key_id": "k_f71bde46a9680d8d",
"index": 7,
"entry": {
"actor": "actor:ai:triage-assistant-v4",
"class": "MODELED",
"kind": "system",
"key_id": "k_f71bde46a9680d8d",
"jwk": {
"kty": "EC",
"crv": "P-256",
"x": "AmVfK7ltK7mprIKSXcj-PNTw4f8zq2gcbRG-qEiFmbU",
"y": "W7sar2SHGJ_jUsBSxoasMr7l1If81Qu5BdYfvlK8Who"
},
"valid_from": "2025-01-01T00:00:00.000Z",
"valid_to": "2027-06-01T00:00:00.000Z"
},
"path": [
{
"side": "left",
"sibling": "sha256:3e8eae859976a6f7d64543a05e28b4c8fc52b8500c65decc7e124af145fac567"
},
{
"side": "left",
"sibling": "sha256:6d20941c438f3924c50e6573d0712466ec6b91655705d2603ea89981e4c50ffc"
},
{
"side": "left",
"sibling": "sha256:d3f1d60ec9478d2b69455e5ba8168897966d18429bd3b7d36105841cc2ae1776"
},
{
"side": "right",
"sibling": "sha256:7071adf5e21a94147d31f42f1028b4867b6562e5b78726259c2515b03b213e52"
}
]
}
],
"memberships_unproven": [],
"revocation": {
"source": "SIGNED_LIST",
"digest": "sha256:12f73b1fbf27d38cf137b86a1ce13bbcd98161123a6aa7d79b107db8189966b9",
"sequence": 5,
"registry_version": 3,
"issued_at": "2026-08-06T00:00:00.000Z",
"next_update_due": "2026-08-13T00:00:00.000Z",
"entry_count": 0,
"body": {
"sequence": 5,
"registry_version": 3,
"issuer": {
"name": "NIST-regulated enterprise demonstration trust root",
"key_id": "k_3793b8e35f8acac1"
},
"issued_at": "2026-08-06T00:00:00.000Z",
"next_update_due": "2026-08-13T00:00:00.000Z",
"entries": [],
"spec": "corobate:revocation-list:1"
}
}
},
"governance": {
"digest": "sha256:8b0a45a27fcce9c1c243c764e855e67c6fe6dfd7f02a563bd90809b419731905",
"signed": true,
"actor_trust": "FLOOR_TO_SELLER_ASSERTED",
"outcome_trial_weight": 1,
"max_reingest_depth": 3,
"release_quorum_m": 2,
"release_quorum_n": 3,
"risk_acceptance_margin_bp": 500,
"risk_acceptance_max_days": 30,
"risk_acceptance_authority_cents": {
"SUPERVISOR": 1000000,
"MANAGER": 25000000,
"DIRECTOR": 500000000,
"OFFICER": 5000000000
},
"template_author_roles": [
"MANAGER",
"DIRECTOR",
"OFFICER"
]
},
"observers_attested": 4,
"outcomes": {
"attestations_counted": 0,
"attestations_recorded": 0,
"records_with_outcomes": 0
},
"lineage": {
"corroborations_counted": 0,
"corroborations_discounted": 0,
"records_with_discounted_corroborations": 0
},
"reingest": {
"records": 0,
"max_depth": 0,
"weakest_class": null,
"chain_weakest_bp": 10000,
"chain": []
},
"template": null
}
}
}The same 412 findings, the same assistant, the same exposure. The enterprise standard now says a model may AGREE with this control and may not be the whole of it — the rung most real programmes actually want, and the one a two-position switch cannot express. Nobody else looked, so the control is uncovered. Note what did NOT happen: the score did not drop. The evidence became inadmissible, which is a different fact and has a different remedy — an analyst reviews the queue, rather than the assistant running again.
- Subject
- ai-system:TRIAGE-ASSISTANT-V4
- Question
- May this quarter's vulnerability triage be accepted as the record of review?
- Exposure
- $250,000
- Instruments
- Office of the Chief Information Security Officer · National Institute of Standards and Technology
- Outcome
- WITHHELD — the action is not permitted; outstanding: vulnerability triage disposition
- Receipt
- sha256:02be618b5d00cceb6f837bb29494c14973458076fd7998398a8daea7165ae8b4
The gate variables this decision ran under — a dial per question, read back off the sealed receipt
control assessmentrequired
penetration testrequired
vulnerability scanrequired
vulnerability triage dispositionrequired
Every bar above was re-derived from the regulatory bindings inside this receipt’s hashed body, not from the configuration that produced it. A bar in grey is a setting no instrument made — the deploying organisation’s own default, which still binds and is not an absence. A bar position renders an ordinal on a declared ladder: it is a way to draw a control and to compare two settings on the same axis, and it is not a measurement. The value printed beside each bar is the authoritative one.
Whoever must act now
The engineer with the deployment in their hands, the release manager, the person who must publish or hold.
One instruction and the reason in words. No score, no money, no signatures.
Seven or eight fields, and not one of them is a number somebody can argue with. This person is not being asked to re-judge the evidence; somebody already did, and it is on the record.
The scoped copy itself — partial — something outside this role’s remit was removed
{
"spec": "corobate:role-view:2",
"role": "OPERATOR",
"purpose": "Whoever must act on this decision now — release the goods, fund the draw, dispatch the agent, ship the title. Sees one instruction and the reason in plain words, and nothing that could be argued about while somebody waits.",
"is_a_receipt": false,
"warning": "This is a SCOPED COPY of a sealed decision, not the decision record itself. It will not verify as a receipt and must not be presented as one. To confirm it is faithful, recompute its `view` digest under the same canonicalisation that produces receipt_hash and compare it with the entry for this role in the source receipt’s `views` block.",
"derived_from": {
"receipt_hash": "sha256:02be618b5d00cceb6f837bb29494c14973458076fd7998398a8daea7165ae8b4",
"entry_hash": "sha256:6b9124406ee627da802b075c8ef55df54ffc8320e20937b2d1f1038d286feefb",
"issued_at": "2026-08-08T16:00:00.000Z"
},
"view_digest": "sha256:350e78c681bb8d15440796459a02f5120657797bd3114114277d42a44b6b6b0d",
"withheld": {
"anything_withheld": true,
"note": "Facts outside this role’s remit were removed. That something was removed is stated so a partial record is never mistaken for a complete one. How much, and what, is not stated — a count is an inference about the part you are not entitled to see."
},
"view": {
"spec": "urn:ietf:params:corobate:receipt:1",
"receipt_version": "1.8",
"issued_at": "2026-08-08T16:00:00.000Z",
"decision": {
"id": "ai_TRIAGE_EVIDENCE_CORROBORATION_ONLY",
"subject": "ai-system:TRIAGE-ASSISTANT-V4"
},
"memory": {
"state_digest": "sha256:9357ab4d994dcd108cd3f22257927b155d8e44f669c5c0bb8d3e9bfc6be9e52a",
"ledger_head": "sha256:b037093616312675fb7422882b44889dba9f936590214cd993c2e391b7f121c9",
"coverage_gaps": [
"ai-system:TRIAGE-ASSISTANT-V4|vulnerability_triage_disposition"
]
},
"verdict": {
"value": "WITHHELD"
},
"release": {
"state": "WITHHELD_NO_EVIDENCE"
}
}
}Provider / assessed party
The cloud service provider, the release team, or the party operating the AI system — whoever is being assessed.
Sees which controls were required of them and by which publication and control identifier. Does not see the authorising official’s exposure figure or how any shortfall was priced.
What is outstanding on your file
- vulnerability triage disposition — required by Office of the Chief Information Security Officer, § 3.1 [VERIFY]
| Claim | Required | Evidence class | Who | Age | Outcome |
|---|---|---|---|---|---|
| vulnerability_scan | yes | VERIFIED | — | 2026-08-04 | admitted |
| penetration_test | yes | VERIFIED | — | 2026-06-09 | admitted |
| control_assessment | yes | VERIFIED | — | 2026-04-30 | admitted |
| vulnerability_triage_disposition | no | MODELED | — | 2026-08-05 | withheld |
| vulnerability_triage_disposition | yes | MISSING | — | 2026-08-08 | coverage gap |
The clause is here because it turns an argument into an errand. What is not here: what the bank had at stake, and whether anyone priced the shortfall.
The scoped copy itself — partial — something outside this role’s remit was removed
{
"spec": "corobate:role-view:2",
"role": "SUPPLIER",
"purpose": "The party whose evidence was judged. Sees every claim the decision required, which fell short, and the clause that required it — and nothing about what the buyer had at stake or how the buyer priced any shortfall. NOTE, because an earlier draft of this sentence was untrue: this projection carries the WHOLE inputs array, so where several parties supplied evidence for one decision, each of them sees all of it. Per-party scoping cannot be expressed by a commitment scheme with one digest per role, and claiming it anyway would be the kind of promise this file exists to stop making.",
"is_a_receipt": false,
"warning": "This is a SCOPED COPY of a sealed decision, not the decision record itself. It will not verify as a receipt and must not be presented as one. To confirm it is faithful, recompute its `view` digest under the same canonicalisation that produces receipt_hash and compare it with the entry for this role in the source receipt’s `views` block.",
"derived_from": {
"receipt_hash": "sha256:02be618b5d00cceb6f837bb29494c14973458076fd7998398a8daea7165ae8b4",
"entry_hash": "sha256:6b9124406ee627da802b075c8ef55df54ffc8320e20937b2d1f1038d286feefb",
"issued_at": "2026-08-08T16:00:00.000Z"
},
"view_digest": "sha256:9ec178449e48f0edb2b08816fb258433837d59a524b070ed72dd9f3c9128c50f",
"withheld": {
"anything_withheld": true,
"note": "Facts outside this role’s remit were removed. That something was removed is stated so a partial record is never mistaken for a complete one. How much, and what, is not stated — a count is an inference about the part you are not entitled to see."
},
"view": {
"spec": "urn:ietf:params:corobate:receipt:1",
"receipt_version": "1.8",
"issued_at": "2026-08-08T16:00:00.000Z",
"decision": {
"id": "ai_TRIAGE_EVIDENCE_CORROBORATION_ONLY",
"subject": "ai-system:TRIAGE-ASSISTANT-V4",
"question": "May this quarter's vulnerability triage be accepted as the record of review?"
},
"memory": {
"state_digest": "sha256:9357ab4d994dcd108cd3f22257927b155d8e44f669c5c0bb8d3e9bfc6be9e52a",
"ledger_head": "sha256:b037093616312675fb7422882b44889dba9f936590214cd993c2e391b7f121c9",
"coverage_gaps": [
"ai-system:TRIAGE-ASSISTANT-V4|vulnerability_triage_disposition"
]
},
"verdict": {
"value": "WITHHELD"
},
"inputs": [
{
"key": "ai-system:TRIAGE-ASSISTANT-V4::vulnerability_scan",
"provenance": "VERIFIED",
"observed_at": "2026-08-04T16:00:00.000Z",
"memory_status": "admitted",
"critical": true
},
{
"key": "ai-system:TRIAGE-ASSISTANT-V4::penetration_test",
"provenance": "VERIFIED",
"observed_at": "2026-06-09T16:00:00.000Z",
"memory_status": "admitted",
"critical": true
},
{
"key": "ai-system:TRIAGE-ASSISTANT-V4::control_assessment",
"provenance": "VERIFIED",
"observed_at": "2026-04-30T16:00:00.000Z",
"memory_status": "admitted",
"critical": true
},
{
"key": "ai-system:TRIAGE-ASSISTANT-V4::vulnerability_triage_disposition",
"provenance": "MODELED",
"observed_at": "2026-08-05T16:00:00.000Z",
"memory_status": "withheld",
"critical": false
},
{
"key": "ai-system:TRIAGE-ASSISTANT-V4::vulnerability_triage_disposition",
"provenance": "MISSING",
"observed_at": "2026-08-08T16:00:00.000Z",
"memory_status": "coverage_gap",
"critical": true
}
],
"regulatory": {
"bindings": [
{
"claim": "control_assessment",
"requirement": "max_age_days",
"value": 365,
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
"instrument_id": "nist-sp-800-53r5-moderate",
"version": 5,
"edition": "Rev. 5",
"citation": "CA-2 [VERIFY]",
"source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "control_assessment",
"requirement": "min_class",
"value": "VERIFIED",
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
"instrument_id": "nist-sp-800-53r5-moderate",
"version": 5,
"edition": "Rev. 5",
"citation": "CA-2(1) independent assessors [VERIFY]",
"source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "control_assessment",
"requirement": "required",
"value": true,
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
"instrument_id": "nist-sp-800-53r5-moderate",
"version": 5,
"edition": "Rev. 5",
"citation": "CA-2 [VERIFY]",
"source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "penetration_test",
"requirement": "min_class",
"value": "VERIFIED",
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
"instrument_id": "nist-sp-800-53r5-moderate",
"version": 5,
"edition": "Rev. 5",
"citation": "CA-8(1) independent penetration agent [VERIFY]",
"source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "penetration_test",
"requirement": "required",
"value": true,
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
"instrument_id": "nist-sp-800-53r5-moderate",
"version": 5,
"edition": "Rev. 5",
"citation": "CA-8 [VERIFY]",
"source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "vulnerability_scan",
"requirement": "max_age_days",
"value": 30,
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
"instrument_id": "nist-sp-800-53r5-moderate",
"version": 5,
"edition": "Rev. 5",
"citation": "RA-5(a) [VERIFY]",
"source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "vulnerability_scan",
"requirement": "required",
"value": true,
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
"instrument_id": "nist-sp-800-53r5-moderate",
"version": 5,
"edition": "Rev. 5",
"citation": "RA-5 [VERIFY]",
"source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "vulnerability_triage_disposition",
"requirement": "ai_position",
"value": "CORROBORATION_ONLY",
"bound_by": {
"authority": "Office of the Chief Information Security Officer",
"instrument": "Enterprise standard on machine-generated evidence",
"instrument_id": "enterprise-ai-evidence-standard",
"version": 1,
"edition": "2026-03-01",
"citation": "§ 3.4 [VERIFY]",
"source_digest": "sha256:e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "vulnerability_triage_disposition",
"requirement": "required",
"value": true,
"bound_by": {
"authority": "Office of the Chief Information Security Officer",
"instrument": "Enterprise standard on machine-generated evidence",
"instrument_id": "enterprise-ai-evidence-standard",
"version": 1,
"edition": "2026-03-01",
"citation": "§ 3.1 [VERIFY]",
"source_digest": "sha256:e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
}
],
"applied": [
{
"instrument_id": "enterprise-ai-evidence-standard",
"version": 1,
"authority": "Office of the Chief Information Security Officer",
"instrument": "Enterprise standard on machine-generated evidence",
"edition": "2026-03-01",
"citation": "§ 3 [VERIFY]",
"source_digest": "sha256:e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5",
"entered_by": "actor:human:issm",
"entered_at": "2026-08-08T16:00:00.000Z"
},
{
"instrument_id": "nist-sp-800-53r5-moderate",
"version": 5,
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
"edition": "Rev. 5",
"citation": "CA-2, CA-8, RA-5, SR-6 [VERIFY]",
"source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353",
"entered_by": "actor:human:issm",
"entered_at": "2026-08-08T16:00:00.000Z"
}
],
"defaults": [
{
"claim": "control_assessment",
"requirement": "ai_position",
"value": "ADMIT",
"because": "No instrument in force stated a position on AI-authored evidence for \"control_assessment\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
},
{
"claim": "penetration_test",
"requirement": "ai_position",
"value": "ADMIT",
"because": "No instrument in force stated a position on AI-authored evidence for \"penetration_test\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
},
{
"claim": "vulnerability_scan",
"requirement": "ai_position",
"value": "ADMIT",
"because": "No instrument in force stated a position on AI-authored evidence for \"vulnerability_scan\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
}
]
}
}
}Assessor / authorising official
A third-party assessment organisation, an agency assessor, or an inspector general reviewing the package. Same position as a customs officer: a public mandate over the record.
The control record in full — each publication by control identifier, edition and document digest, and every required claim with who supplied it and when. No exposure figure, no risk pricing, no confidence score.
What each authority bound
| Claim | Requirement | Level | Bound by |
|---|---|---|---|
| control_assessment | max age days | 365 | National Institute of Standards and Technology CA-2 [VERIFY] · SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline) |
| control_assessment | min class | VERIFIED | National Institute of Standards and Technology CA-2(1) independent assessors [VERIFY] · SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline) |
| control_assessment | required | true | National Institute of Standards and Technology CA-2 [VERIFY] · SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline) |
| penetration_test | min class | VERIFIED | National Institute of Standards and Technology CA-8(1) independent penetration agent [VERIFY] · SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline) |
| penetration_test | required | true | National Institute of Standards and Technology CA-8 [VERIFY] · SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline) |
| vulnerability_scan | max age days | 30 | National Institute of Standards and Technology RA-5(a) [VERIFY] · SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline) |
| vulnerability_scan | required | true | National Institute of Standards and Technology RA-5 [VERIFY] · SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline) |
| vulnerability_triage_disposition | ai position | CORROBORATION_ONLY | Office of the Chief Information Security Officer § 3.4 [VERIFY] · Enterprise standard on machine-generated evidence |
| vulnerability_triage_disposition | required | true | Office of the Chief Information Security Officer § 3.1 [VERIFY] · Enterprise standard on machine-generated evidence |
Every required claim, and what was actually held
| Claim | Required | Evidence class | Who | Age | Outcome |
|---|---|---|---|---|---|
| vulnerability_scan | yes | VERIFIED | actor:sys:registry:nvd-cve | 2026-08-04 | admitted |
| penetration_test | yes | VERIFIED | actor:org:LAB-NVLAP-0412 | 2026-06-09 | admitted |
| control_assessment | yes | VERIFIED | actor:org:CERT-3PAO-ATLANTIC | 2026-04-30 | admitted |
| vulnerability_triage_disposition | no | MODELED | actor:ai:triage-assistant-v4 | 2026-08-05 | withheld |
| vulnerability_triage_disposition | yes | MISSING | — | 2026-08-08 | coverage gap |
The scoped copy itself — partial — something outside this role’s remit was removed
{
"spec": "corobate:role-view:2",
"role": "REGULATOR",
"purpose": "An official holding a public mandate over this record — a customs officer, a bank examiner, a market conduct supervisor. Sees the regulatory record in full: their own instrument named, every required claim and whether it was met, by whom, how old. No commercial figure of any kind.",
"is_a_receipt": false,
"warning": "This is a SCOPED COPY of a sealed decision, not the decision record itself. It will not verify as a receipt and must not be presented as one. To confirm it is faithful, recompute its `view` digest under the same canonicalisation that produces receipt_hash and compare it with the entry for this role in the source receipt’s `views` block.",
"derived_from": {
"receipt_hash": "sha256:02be618b5d00cceb6f837bb29494c14973458076fd7998398a8daea7165ae8b4",
"entry_hash": "sha256:6b9124406ee627da802b075c8ef55df54ffc8320e20937b2d1f1038d286feefb",
"issued_at": "2026-08-08T16:00:00.000Z"
},
"view_digest": "sha256:27db26202a1449fdac2ae53eee7a5ad96646ddb9854a1c539aa5b0f5cf6c3919",
"withheld": {
"anything_withheld": true,
"note": "Facts outside this role’s remit were removed. That something was removed is stated so a partial record is never mistaken for a complete one. How much, and what, is not stated — a count is an inference about the part you are not entitled to see."
},
"view": {
"spec": "urn:ietf:params:corobate:receipt:1",
"receipt_version": "1.8",
"issued_at": "2026-08-08T16:00:00.000Z",
"decision": {
"id": "ai_TRIAGE_EVIDENCE_CORROBORATION_ONLY",
"subject": "ai-system:TRIAGE-ASSISTANT-V4",
"question": "May this quarter's vulnerability triage be accepted as the record of review?"
},
"memory": {
"state_digest": "sha256:9357ab4d994dcd108cd3f22257927b155d8e44f669c5c0bb8d3e9bfc6be9e52a",
"ledger_head": "sha256:b037093616312675fb7422882b44889dba9f936590214cd993c2e391b7f121c9",
"coverage_gaps": [
"ai-system:TRIAGE-ASSISTANT-V4|vulnerability_triage_disposition"
]
},
"data_horizon": "2026-08-08T16:00:00.000Z",
"verdict": {
"value": "WITHHELD"
},
"regulatory": {
"spec": "corobate:regulatory:2",
"resolved": true,
"applied": [
{
"instrument_id": "enterprise-ai-evidence-standard",
"version": 1,
"authority": "Office of the Chief Information Security Officer",
"instrument": "Enterprise standard on machine-generated evidence",
"edition": "2026-03-01",
"citation": "§ 3 [VERIFY]",
"source_digest": "sha256:e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5",
"entered_by": "actor:human:issm",
"entered_at": "2026-08-08T16:00:00.000Z"
},
{
"instrument_id": "nist-sp-800-53r5-moderate",
"version": 5,
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
"edition": "Rev. 5",
"citation": "CA-2, CA-8, RA-5, SR-6 [VERIFY]",
"source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353",
"entered_by": "actor:human:issm",
"entered_at": "2026-08-08T16:00:00.000Z"
}
],
"skipped": [],
"conflicts": [],
"bindings": [
{
"claim": "control_assessment",
"requirement": "max_age_days",
"value": 365,
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
"instrument_id": "nist-sp-800-53r5-moderate",
"version": 5,
"edition": "Rev. 5",
"citation": "CA-2 [VERIFY]",
"source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "control_assessment",
"requirement": "min_class",
"value": "VERIFIED",
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
"instrument_id": "nist-sp-800-53r5-moderate",
"version": 5,
"edition": "Rev. 5",
"citation": "CA-2(1) independent assessors [VERIFY]",
"source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "control_assessment",
"requirement": "required",
"value": true,
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
"instrument_id": "nist-sp-800-53r5-moderate",
"version": 5,
"edition": "Rev. 5",
"citation": "CA-2 [VERIFY]",
"source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "penetration_test",
"requirement": "min_class",
"value": "VERIFIED",
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
"instrument_id": "nist-sp-800-53r5-moderate",
"version": 5,
"edition": "Rev. 5",
"citation": "CA-8(1) independent penetration agent [VERIFY]",
"source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "penetration_test",
"requirement": "required",
"value": true,
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
"instrument_id": "nist-sp-800-53r5-moderate",
"version": 5,
"edition": "Rev. 5",
"citation": "CA-8 [VERIFY]",
"source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "vulnerability_scan",
"requirement": "max_age_days",
"value": 30,
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
"instrument_id": "nist-sp-800-53r5-moderate",
"version": 5,
"edition": "Rev. 5",
"citation": "RA-5(a) [VERIFY]",
"source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "vulnerability_scan",
"requirement": "required",
"value": true,
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
"instrument_id": "nist-sp-800-53r5-moderate",
"version": 5,
"edition": "Rev. 5",
"citation": "RA-5 [VERIFY]",
"source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "vulnerability_triage_disposition",
"requirement": "ai_position",
"value": "CORROBORATION_ONLY",
"bound_by": {
"authority": "Office of the Chief Information Security Officer",
"instrument": "Enterprise standard on machine-generated evidence",
"instrument_id": "enterprise-ai-evidence-standard",
"version": 1,
"edition": "2026-03-01",
"citation": "§ 3.4 [VERIFY]",
"source_digest": "sha256:e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "vulnerability_triage_disposition",
"requirement": "required",
"value": true,
"bound_by": {
"authority": "Office of the Chief Information Security Officer",
"instrument": "Enterprise standard on machine-generated evidence",
"instrument_id": "enterprise-ai-evidence-standard",
"version": 1,
"edition": "2026-03-01",
"citation": "§ 3.1 [VERIFY]",
"source_digest": "sha256:e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
}
],
"defaults": [
{
"claim": "control_assessment",
"requirement": "ai_position",
"value": "ADMIT",
"because": "No instrument in force stated a position on AI-authored evidence for \"control_assessment\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
},
{
"claim": "penetration_test",
"requirement": "ai_position",
"value": "ADMIT",
"because": "No instrument in force stated a position on AI-authored evidence for \"penetration_test\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
},
{
"claim": "vulnerability_scan",
"requirement": "ai_position",
"value": "ADMIT",
"because": "No instrument in force stated a position on AI-authored evidence for \"vulnerability_scan\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
}
]
},
"inputs": [
{
"key": "ai-system:TRIAGE-ASSISTANT-V4::vulnerability_scan",
"provenance": "VERIFIED",
"source": "nvd-cve:vulnerability_scan",
"observed_at": "2026-08-04T16:00:00.000Z",
"critical": true,
"memory_status": "admitted",
"memory_actor": "actor:sys:registry:nvd-cve"
},
{
"key": "ai-system:TRIAGE-ASSISTANT-V4::penetration_test",
"provenance": "VERIFIED",
"source": "LAB-NVLAP-0412:penetration_test",
"observed_at": "2026-06-09T16:00:00.000Z",
"critical": true,
"memory_status": "admitted",
"memory_actor": "actor:org:LAB-NVLAP-0412"
},
{
"key": "ai-system:TRIAGE-ASSISTANT-V4::control_assessment",
"provenance": "VERIFIED",
"source": "CERT-3PAO-ATLANTIC:control_assessment",
"observed_at": "2026-04-30T16:00:00.000Z",
"critical": true,
"memory_status": "admitted",
"memory_actor": "actor:org:CERT-3PAO-ATLANTIC"
},
{
"key": "ai-system:TRIAGE-ASSISTANT-V4::vulnerability_triage_disposition",
"provenance": "MODELED",
"source": "triage-assistant-v4:vulnerability_triage_disposition",
"observed_at": "2026-08-05T16:00:00.000Z",
"critical": false,
"memory_status": "withheld",
"memory_actor": "actor:ai:triage-assistant-v4"
},
{
"key": "ai-system:TRIAGE-ASSISTANT-V4::vulnerability_triage_disposition",
"provenance": "MISSING",
"source": null,
"observed_at": "2026-08-08T16:00:00.000Z",
"critical": true,
"memory_status": "coverage_gap"
}
],
"crypto_suite": {
"spec": "corobate:suite:1",
"id": "CB-1-ES256-SHA256",
"receipt_digest": "sha256",
"chain_digest": "sha256",
"content_digest": "sha256",
"envelope_signature": "ES256",
"signature_curve": "P-256",
"canonicalisation": "attest-canon/2",
"quantum_resistant": false
}
}
}ISSM / control owner
The information system security manager and the control owners who hold the package.
The fullest internal view: every input, its class, its age, its score, the exposure, and every publication in force.
Every input the gate saw
| Claim | Required | Evidence class | Who | Age | Score | Outcome |
|---|---|---|---|---|---|---|
| vulnerability_scan | yes | VERIFIED | actor:sys:registry:nvd-cve | 4d | 95% | admitted |
| penetration_test | yes | VERIFIED | actor:org:LAB-NVLAP-0412 | 60d | 95% | admitted |
| control_assessment | yes | VERIFIED | actor:org:CERT-3PAO-ATLANTIC | 100d | 95% | admitted |
| vulnerability_triage_disposition | no | MODELED | actor:ai:triage-assistant-v4 | 3d | 80% | withheld |
| vulnerability_triage_disposition | yes | MISSING | — | 2026-08-08 | 0% | coverage gap |
Instruments in force
Why
- Coverage gap: no admissible memory for required claim(s) ai-system:TRIAGE-ASSISTANT-V4|vulnerability_triage_disposition.
- Confidence 0.00% is bound by "ai-system:TRIAGE-ASSISTANT-V4|vulnerability_triage_disposition".
- 1 memory was withheld from the context block: ai-system:TRIAGE-ASSISTANT-V4|vulnerability_triage_disposition (AI-authored and standing alone: the authority binding this claim admits model output as corroboration but not as the whole of it, and nothing else that survived on this decision — no separate admissible record and no counted corroboration from a party that is not itself a model — carries "ai-system:TRIAGE-ASSISTANT-V4|vulnerability_triage_disposition". A model agreeing with nothing is not corroboration, and a model agreeing with a record this decision has itself refused is agreeing with nothing.).
- Thresholds for $250,000 exposure: approve 85%, caution 60%.
The scoped copy itself — partial — something outside this role’s remit was removed
{
"spec": "corobate:role-view:2",
"role": "COMPLIANCE",
"purpose": "The operator’s own compliance function. The fullest internal view: every gap, every instrument in force, the waivability of each requirement and who accepted what.",
"is_a_receipt": false,
"warning": "This is a SCOPED COPY of a sealed decision, not the decision record itself. It will not verify as a receipt and must not be presented as one. To confirm it is faithful, recompute its `view` digest under the same canonicalisation that produces receipt_hash and compare it with the entry for this role in the source receipt’s `views` block.",
"derived_from": {
"receipt_hash": "sha256:02be618b5d00cceb6f837bb29494c14973458076fd7998398a8daea7165ae8b4",
"entry_hash": "sha256:6b9124406ee627da802b075c8ef55df54ffc8320e20937b2d1f1038d286feefb",
"issued_at": "2026-08-08T16:00:00.000Z"
},
"view_digest": "sha256:2add4b14ddb2392c2c4d09321c6ced764a745b025d71efa72f63735d23bca1f1",
"withheld": {
"anything_withheld": true,
"note": "Facts outside this role’s remit were removed. That something was removed is stated so a partial record is never mistaken for a complete one. How much, and what, is not stated — a count is an inference about the part you are not entitled to see."
},
"view": {
"spec": "urn:ietf:params:corobate:receipt:1",
"receipt_version": "1.8",
"issued_at": "2026-08-08T16:00:00.000Z",
"decision": {
"id": "ai_TRIAGE_EVIDENCE_CORROBORATION_ONLY",
"domain": "supply-chain",
"subject": "ai-system:TRIAGE-ASSISTANT-V4",
"question": "May this quarter's vulnerability triage be accepted as the record of review?"
},
"memory": {
"state_digest": "sha256:9357ab4d994dcd108cd3f22257927b155d8e44f669c5c0bb8d3e9bfc6be9e52a",
"ledger_head": "sha256:b037093616312675fb7422882b44889dba9f936590214cd993c2e391b7f121c9",
"coverage_gaps": [
"ai-system:TRIAGE-ASSISTANT-V4|vulnerability_triage_disposition"
],
"exposure": {
"usd": 250000,
"declared_by": "actor:human:issm",
"ledger_seq": 4
},
"policy_digest": "sha256:a6b69b7d20f7fb04d522364af1d92992058b04a5835fcec9d1c9f2261c7ef636"
},
"data_horizon": "2026-08-08T16:00:00.000Z",
"verdict": {
"value": "WITHHELD",
"threshold_approve": 0.85,
"threshold_caution": 0.6,
"rule": "confidence>=threshold"
},
"confidence": {
"value": 0,
"method": "min-over-critical-inputs",
"bound_by": "ai-system:TRIAGE-ASSISTANT-V4::vulnerability_triage_disposition"
},
"release": {
"required": false,
"required_by_tier": false,
"escalated_by_acceptance": false,
"risk_accepted": false,
"state": "WITHHELD_NO_EVIDENCE",
"code": "QUORUM_EVIDENCE_WITHHELD",
"reason": "the evidence did not clear the threshold for this exposure, so there is nothing to release. Signatures do not substitute for evidence, and this state is deliberately distinct from WITHHELD_PENDING_SIGNATURES: a reader must be able to tell \"the evidence is not there\" from \"the evidence is there and 0 of 2 people have signed\".",
"tier_floor_cents": 1000000000,
"exposure_usd_cents": 25000000,
"required_m": 2,
"declared_n": 3,
"floor_m": 2,
"distinct_signers": 0,
"superseded": 0,
"collapsed": 0,
"release_digest": "sha256:2e954dcf94eabc7d1a96c41ff856217c64f65ad722b43bccaaf61e5de35dbe1d",
"governance_digest": "sha256:8b0a45a27fcce9c1c243c764e855e67c6fe6dfd7f02a563bd90809b419731905",
"governance_signed": true,
"counted_voices": [],
"signatures": [],
"ledger_seq": null
},
"acceptance": {
"state": "NONE",
"code": "ACCEPTANCE_NONE",
"reason": "no risk acceptance was presented for this decision. This is the ordinary case: a refusal is a refusal unless a named person has priced it.",
"permitted_basis": null,
"presented": 0,
"superseded": 0,
"expired": 0,
"gaps_not_covered": 0,
"coverage_gaps_in_force": [
"ai-system:TRIAGE-ASSISTANT-V4|vulnerability_triage_disposition"
],
"evidentiary_digest": "sha256:2e954dcf94eabc7d1a96c41ff856217c64f65ad722b43bccaaf61e5de35dbe1d",
"margin_floor_bp": 100,
"authority_ceiling_cents": {
"SUPERVISOR": 1000000,
"MANAGER": 25000000,
"DIRECTOR": 500000000,
"OFFICER": 5000000000
},
"acceptances": [],
"escalated": false,
"live": false,
"ledger_seq": null
},
"regulatory": {
"spec": "corobate:regulatory:2",
"resolved": true,
"applied": [
{
"instrument_id": "enterprise-ai-evidence-standard",
"version": 1,
"authority": "Office of the Chief Information Security Officer",
"instrument": "Enterprise standard on machine-generated evidence",
"edition": "2026-03-01",
"citation": "§ 3 [VERIFY]",
"source_digest": "sha256:e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5",
"entered_by": "actor:human:issm",
"entered_at": "2026-08-08T16:00:00.000Z"
},
{
"instrument_id": "nist-sp-800-53r5-moderate",
"version": 5,
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
"edition": "Rev. 5",
"citation": "CA-2, CA-8, RA-5, SR-6 [VERIFY]",
"source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353",
"entered_by": "actor:human:issm",
"entered_at": "2026-08-08T16:00:00.000Z"
}
],
"skipped": [],
"conflicts": [],
"bindings": [
{
"claim": "control_assessment",
"requirement": "max_age_days",
"value": 365,
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
"instrument_id": "nist-sp-800-53r5-moderate",
"version": 5,
"edition": "Rev. 5",
"citation": "CA-2 [VERIFY]",
"source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "control_assessment",
"requirement": "min_class",
"value": "VERIFIED",
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
"instrument_id": "nist-sp-800-53r5-moderate",
"version": 5,
"edition": "Rev. 5",
"citation": "CA-2(1) independent assessors [VERIFY]",
"source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "control_assessment",
"requirement": "required",
"value": true,
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
"instrument_id": "nist-sp-800-53r5-moderate",
"version": 5,
"edition": "Rev. 5",
"citation": "CA-2 [VERIFY]",
"source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "penetration_test",
"requirement": "min_class",
"value": "VERIFIED",
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
"instrument_id": "nist-sp-800-53r5-moderate",
"version": 5,
"edition": "Rev. 5",
"citation": "CA-8(1) independent penetration agent [VERIFY]",
"source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "penetration_test",
"requirement": "required",
"value": true,
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
"instrument_id": "nist-sp-800-53r5-moderate",
"version": 5,
"edition": "Rev. 5",
"citation": "CA-8 [VERIFY]",
"source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "vulnerability_scan",
"requirement": "max_age_days",
"value": 30,
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
"instrument_id": "nist-sp-800-53r5-moderate",
"version": 5,
"edition": "Rev. 5",
"citation": "RA-5(a) [VERIFY]",
"source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "vulnerability_scan",
"requirement": "required",
"value": true,
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
"instrument_id": "nist-sp-800-53r5-moderate",
"version": 5,
"edition": "Rev. 5",
"citation": "RA-5 [VERIFY]",
"source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "vulnerability_triage_disposition",
"requirement": "ai_position",
"value": "CORROBORATION_ONLY",
"bound_by": {
"authority": "Office of the Chief Information Security Officer",
"instrument": "Enterprise standard on machine-generated evidence",
"instrument_id": "enterprise-ai-evidence-standard",
"version": 1,
"edition": "2026-03-01",
"citation": "§ 3.4 [VERIFY]",
"source_digest": "sha256:e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "vulnerability_triage_disposition",
"requirement": "required",
"value": true,
"bound_by": {
"authority": "Office of the Chief Information Security Officer",
"instrument": "Enterprise standard on machine-generated evidence",
"instrument_id": "enterprise-ai-evidence-standard",
"version": 1,
"edition": "2026-03-01",
"citation": "§ 3.1 [VERIFY]",
"source_digest": "sha256:e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
}
],
"defaults": [
{
"claim": "control_assessment",
"requirement": "ai_position",
"value": "ADMIT",
"because": "No instrument in force stated a position on AI-authored evidence for \"control_assessment\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
},
{
"claim": "penetration_test",
"requirement": "ai_position",
"value": "ADMIT",
"because": "No instrument in force stated a position on AI-authored evidence for \"penetration_test\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
},
{
"claim": "vulnerability_scan",
"requirement": "ai_position",
"value": "ADMIT",
"because": "No instrument in force stated a position on AI-authored evidence for \"vulnerability_scan\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
}
]
},
"reasons": [
"Coverage gap: no admissible memory for required claim(s) ai-system:TRIAGE-ASSISTANT-V4|vulnerability_triage_disposition.",
"Confidence 0.00% is bound by \"ai-system:TRIAGE-ASSISTANT-V4|vulnerability_triage_disposition\".",
"1 memory was withheld from the context block: ai-system:TRIAGE-ASSISTANT-V4|vulnerability_triage_disposition (AI-authored and standing alone: the authority binding this claim admits model output as corroboration but not as the whole of it, and nothing else that survived on this decision — no separate admissible record and no counted corroboration from a party that is not itself a model — carries \"ai-system:TRIAGE-ASSISTANT-V4|vulnerability_triage_disposition\". A model agreeing with nothing is not corroboration, and a model agreeing with a record this decision has itself refused is agreeing with nothing.).",
"Thresholds for $250,000 exposure: approve 85%, caution 60%."
],
"inputs": [
{
"key": "ai-system:TRIAGE-ASSISTANT-V4::vulnerability_scan",
"value": "clean-at-scan",
"provenance": "VERIFIED",
"source": "nvd-cve:vulnerability_scan",
"observed_at": "2026-08-04T16:00:00.000Z",
"reliability": 0.95,
"critical": true,
"memory_status": "admitted",
"memory_kind": "status",
"memory_actor": "actor:sys:registry:nvd-cve",
"memory_age_days": 4
},
{
"key": "ai-system:TRIAGE-ASSISTANT-V4::penetration_test",
"value": "no-critical",
"provenance": "VERIFIED",
"source": "LAB-NVLAP-0412:penetration_test",
"observed_at": "2026-06-09T16:00:00.000Z",
"reliability": 0.95,
"critical": true,
"memory_status": "admitted",
"memory_kind": "test_report",
"memory_actor": "actor:org:LAB-NVLAP-0412",
"memory_age_days": 60
},
{
"key": "ai-system:TRIAGE-ASSISTANT-V4::control_assessment",
"value": "satisfied",
"provenance": "VERIFIED",
"source": "CERT-3PAO-ATLANTIC:control_assessment",
"observed_at": "2026-04-30T16:00:00.000Z",
"reliability": 0.95,
"critical": true,
"memory_status": "admitted",
"memory_kind": "certificate",
"memory_actor": "actor:org:CERT-3PAO-ATLANTIC",
"memory_age_days": 100
},
{
"key": "ai-system:TRIAGE-ASSISTANT-V4::vulnerability_triage_disposition",
"value": null,
"provenance": "MODELED",
"source": "triage-assistant-v4:vulnerability_triage_disposition",
"observed_at": "2026-08-05T16:00:00.000Z",
"reliability": 0.8,
"critical": false,
"memory_status": "withheld",
"memory_kind": "status",
"memory_actor": "actor:ai:triage-assistant-v4",
"memory_age_days": 3
},
{
"key": "ai-system:TRIAGE-ASSISTANT-V4::vulnerability_triage_disposition",
"value": null,
"provenance": "MISSING",
"source": null,
"observed_at": "2026-08-08T16:00:00.000Z",
"reliability": 0,
"critical": true,
"memory_status": "coverage_gap"
}
],
"crypto_suite": {
"spec": "corobate:suite:1",
"id": "CB-1-ES256-SHA256",
"receipt_digest": "sha256",
"chain_digest": "sha256",
"content_digest": "sha256",
"envelope_signature": "ES256",
"signature_curve": "P-256",
"canonicalisation": "attest-canon/2",
"quantum_resistant": false
}
}
}Authorising official (signer)
The named official whose signature carries the authorisation decision.
What is at stake, what the evidence supports, what is missing, and the digest they are signing over.
You are being asked to sign
May this quarter's vulnerability triage be accepted as the record of review?
The signature is over the STATE OF THE EVIDENCE. Move one fact behind this decision and the digest moves and the signature stops counting — which is what makes it safe to collect signatures before everyone is in the room.
What is missing
- vulnerability triage disposition
The scoped copy itself — partial — something outside this role’s remit was removed
{
"spec": "corobate:role-view:2",
"role": "EXECUTIVE",
"purpose": "A named signer on the release gate. Sees what is at stake, what the evidence supports, who else has signed and what they are being asked to sign over.",
"is_a_receipt": false,
"warning": "This is a SCOPED COPY of a sealed decision, not the decision record itself. It will not verify as a receipt and must not be presented as one. To confirm it is faithful, recompute its `view` digest under the same canonicalisation that produces receipt_hash and compare it with the entry for this role in the source receipt’s `views` block.",
"derived_from": {
"receipt_hash": "sha256:02be618b5d00cceb6f837bb29494c14973458076fd7998398a8daea7165ae8b4",
"entry_hash": "sha256:6b9124406ee627da802b075c8ef55df54ffc8320e20937b2d1f1038d286feefb",
"issued_at": "2026-08-08T16:00:00.000Z"
},
"view_digest": "sha256:85e61bf3fe99a19483e9bbbcf158e87bb0c8720fb95b1bf73a2c039ee733096a",
"withheld": {
"anything_withheld": true,
"note": "Facts outside this role’s remit were removed. That something was removed is stated so a partial record is never mistaken for a complete one. How much, and what, is not stated — a count is an inference about the part you are not entitled to see."
},
"view": {
"spec": "urn:ietf:params:corobate:receipt:1",
"receipt_version": "1.8",
"issued_at": "2026-08-08T16:00:00.000Z",
"decision": {
"id": "ai_TRIAGE_EVIDENCE_CORROBORATION_ONLY",
"domain": "supply-chain",
"subject": "ai-system:TRIAGE-ASSISTANT-V4",
"question": "May this quarter's vulnerability triage be accepted as the record of review?"
},
"memory": {
"state_digest": "sha256:9357ab4d994dcd108cd3f22257927b155d8e44f669c5c0bb8d3e9bfc6be9e52a",
"ledger_head": "sha256:b037093616312675fb7422882b44889dba9f936590214cd993c2e391b7f121c9",
"coverage_gaps": [
"ai-system:TRIAGE-ASSISTANT-V4|vulnerability_triage_disposition"
],
"exposure": {
"usd": 250000,
"declared_by": "actor:human:issm",
"ledger_seq": 4
}
},
"verdict": {
"value": "WITHHELD",
"threshold_approve": 0.85,
"threshold_caution": 0.6,
"rule": "confidence>=threshold"
},
"confidence": {
"value": 0,
"method": "min-over-critical-inputs",
"bound_by": "ai-system:TRIAGE-ASSISTANT-V4::vulnerability_triage_disposition"
},
"release": {
"required": false,
"required_by_tier": false,
"escalated_by_acceptance": false,
"risk_accepted": false,
"state": "WITHHELD_NO_EVIDENCE",
"code": "QUORUM_EVIDENCE_WITHHELD",
"reason": "the evidence did not clear the threshold for this exposure, so there is nothing to release. Signatures do not substitute for evidence, and this state is deliberately distinct from WITHHELD_PENDING_SIGNATURES: a reader must be able to tell \"the evidence is not there\" from \"the evidence is there and 0 of 2 people have signed\".",
"tier_floor_cents": 1000000000,
"exposure_usd_cents": 25000000,
"required_m": 2,
"declared_n": 3,
"floor_m": 2,
"distinct_signers": 0,
"superseded": 0,
"collapsed": 0,
"release_digest": "sha256:2e954dcf94eabc7d1a96c41ff856217c64f65ad722b43bccaaf61e5de35dbe1d",
"governance_digest": "sha256:8b0a45a27fcce9c1c243c764e855e67c6fe6dfd7f02a563bd90809b419731905",
"governance_signed": true,
"counted_voices": [],
"signatures": [],
"ledger_seq": null
},
"acceptance": {
"state": "NONE",
"code": "ACCEPTANCE_NONE",
"reason": "no risk acceptance was presented for this decision. This is the ordinary case: a refusal is a refusal unless a named person has priced it.",
"permitted_basis": null,
"presented": 0,
"superseded": 0,
"expired": 0,
"gaps_not_covered": 0,
"coverage_gaps_in_force": [
"ai-system:TRIAGE-ASSISTANT-V4|vulnerability_triage_disposition"
],
"evidentiary_digest": "sha256:2e954dcf94eabc7d1a96c41ff856217c64f65ad722b43bccaaf61e5de35dbe1d",
"margin_floor_bp": 100,
"authority_ceiling_cents": {
"SUPERVISOR": 1000000,
"MANAGER": 25000000,
"DIRECTOR": 500000000,
"OFFICER": 5000000000
},
"acceptances": [],
"escalated": false,
"live": false,
"ledger_seq": null
},
"reasons": [
"Coverage gap: no admissible memory for required claim(s) ai-system:TRIAGE-ASSISTANT-V4|vulnerability_triage_disposition.",
"Confidence 0.00% is bound by \"ai-system:TRIAGE-ASSISTANT-V4|vulnerability_triage_disposition\".",
"1 memory was withheld from the context block: ai-system:TRIAGE-ASSISTANT-V4|vulnerability_triage_disposition (AI-authored and standing alone: the authority binding this claim admits model output as corroboration but not as the whole of it, and nothing else that survived on this decision — no separate admissible record and no counted corroboration from a party that is not itself a model — carries \"ai-system:TRIAGE-ASSISTANT-V4|vulnerability_triage_disposition\". A model agreeing with nothing is not corroboration, and a model agreeing with a record this decision has itself refused is agreeing with nothing.).",
"Thresholds for $250,000 exposure: approve 85%, caution 60%."
],
"regulatory": {
"applied": [
{
"instrument_id": "enterprise-ai-evidence-standard",
"version": 1,
"authority": "Office of the Chief Information Security Officer",
"instrument": "Enterprise standard on machine-generated evidence",
"edition": "2026-03-01",
"citation": "§ 3 [VERIFY]",
"source_digest": "sha256:e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5",
"entered_by": "actor:human:issm",
"entered_at": "2026-08-08T16:00:00.000Z"
},
{
"instrument_id": "nist-sp-800-53r5-moderate",
"version": 5,
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
"edition": "Rev. 5",
"citation": "CA-2, CA-8, RA-5, SR-6 [VERIFY]",
"source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353",
"entered_by": "actor:human:issm",
"entered_at": "2026-08-08T16:00:00.000Z"
}
],
"conflicts": [],
"defaults": [
{
"claim": "control_assessment",
"requirement": "ai_position",
"value": "ADMIT",
"because": "No instrument in force stated a position on AI-authored evidence for \"control_assessment\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
},
{
"claim": "penetration_test",
"requirement": "ai_position",
"value": "ADMIT",
"because": "No instrument in force stated a position on AI-authored evidence for \"penetration_test\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
},
{
"claim": "vulnerability_scan",
"requirement": "ai_position",
"value": "ADMIT",
"because": "No instrument in force stated a position on AI-authored evidence for \"vulnerability_scan\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
}
]
},
"inputs": [
{
"key": "ai-system:TRIAGE-ASSISTANT-V4::vulnerability_scan",
"provenance": "VERIFIED",
"reliability": 0.95,
"critical": true,
"memory_status": "admitted"
},
{
"key": "ai-system:TRIAGE-ASSISTANT-V4::penetration_test",
"provenance": "VERIFIED",
"reliability": 0.95,
"critical": true,
"memory_status": "admitted"
},
{
"key": "ai-system:TRIAGE-ASSISTANT-V4::control_assessment",
"provenance": "VERIFIED",
"reliability": 0.95,
"critical": true,
"memory_status": "admitted"
},
{
"key": "ai-system:TRIAGE-ASSISTANT-V4::vulnerability_triage_disposition",
"provenance": "MODELED",
"reliability": 0.8,
"critical": false,
"memory_status": "withheld"
},
{
"key": "ai-system:TRIAGE-ASSISTANT-V4::vulnerability_triage_disposition",
"provenance": "MISSING",
"reliability": 0,
"critical": true,
"memory_status": "coverage_gap"
}
]
}
}Independent audit / IG
Internal audit, an inspector general, or an external auditor testing the programme.
Everything, plus the verifier’s own findings over the sealed record.
This view withholds nothing. What it adds is the 22 checks the published verifier ran over the sealed record behind every other view of this decision — recomputed at build time, not asserted.
| # | Check | Detail | |
|---|---|---|---|
| 1 | Content reproduces (JCS + SHA-256) | PASS | matches sha256:02be618b5d00cceb6f837bb29494c14973458076fd7998398a8daea7165ae8b4 |
| 2 | Hash chain links (entry = H(prev||content)) | PASS | head sha256:6b9124406ee627da802b075c8ef55df54ffc8320e20937b2d1f1038d286feefb |
| 3 | Confidence gated by weakest critical input | PASS | min over critical = 0, bound_by ai-system:TRIAGE-ASSISTANT-V4::vulnerability_triage_disposition (MISSING) |
| 3b | Verdict follows the threshold rule | PASS | 0 => WITHHELD; recorded WITHHELD |
| 4 | Point-in-time seal (no input past data_horizon) | PASS | all inputs <= 2026-08-08T16:00:00.000Z |
| 5 | Anchor covers the head, and the timestamp token re-reads | PASS | internally consistent; NO external anchor was requested — this is not a validated timestamp |
| 6 | Criteria travel with the receipt and reproduce | PASS | policy_body hashes to sha256:a6b69b7d20f7fb04d522364af1d92992058b04a5835fcec9d1c9f2261c7ef636 |
| 7 | Reliability re-derives from recorded evidence | PASS | all 5 inputs re-derive exactly |
| 8 | Outcome trials and lineage discounts re-derive | PASS | 4 input(s) re-derive: 0 credited outcome trial(s), 0 lineage-discounted corroboration(s); every reliability is at or under its class ceiling |
| 9 | Re-ingested receipts respect their weakest-input ceiling | PASS | no re-ingested receipts: every input rests on a primary observation |
| 10 | Release quorum re-derives | PASS | WITHHELD_NO_EVIDENCE - below the top exposure tier, no multi-party requirement applies |
| 11 | Risk acceptance re-derives | PASS | no risk acceptance: this decision stands or falls on its evidence |
| 12 | Observer credentials were not revoked as of observation time | PASS | revocation list 5 (0 entries, issued 2026-08-06T00:00:00.000Z, next update due 2026-08-13T00:00:00.000Z) reproduces; 4 observer signature(s) judged as of their own instant, none under a key revoked as compromised or retired by then |
| 13 | The cryptographic suite is named and is one this verifier implements | PASS | sealed under CB-1-ES256-SHA256 (ES256 / sha256, attest-canon/2); this verifier implements it; the suite states it is NOT quantum resistant |
| 14 | Regulatory bindings are attributed and were enforced | PASS | 9 binding(s) from 2 instrument(s) in force, each attributed to an authority, a citation and a document digest; 4 required claim(s) all reached the gate |
| 15 | Role-view commitments re-derive, and the customs view carries no money | PASS | 6 role-view commitment(s) re-derived from this receipt’s own body by this verifier’s independent projection; the REGULATOR view carries no commercial figure |
| 16 | AI-authored input was admitted only where an authority allowed it | PASS | 1 claim(s) carry a position on AI-authored evidence set by an authority and 3 carry a recorded default nobody set; 0 exclusion(s) and 0 corroboration-only rule(s) re-derived against this receipt's own admitted inputs; 0 admitted input(s) are AI-authored by their enrolled identity |
| 17 | State digest recomputes from the ledger alone | UNVERIFIABLE | NOT APPLICABLE — you supplied no ledger, so the state digest cannot be re-derived from anything. This receipt commits to the corpus the deciding system held at the instant it sealed, and that commitment is checked by recomputing it from the append-only ledger and comparing; with no ledger in hand there is no second artefact to recompute from. The receipt is not at fault and nothing here is missing from it. Obtain the ledger from the issuer and re-run with --ledger <file>, or verifyReceipt(r, {ledger}). Nothing here has failed and nothing here has passed. |
| 18 | Registry membership re-derives for every key relied on | PASS | all 4 key(s) relied on re-derive to the entries root registry v3 committed to and the trust root signed |
| 20 | Geometric support re-derives, and an unevaluated record is not a supported one | PASS | no authority bound a metric to any claim on this receipt, so no geometric test applied. A claim nobody bound a metric to is not a claim about geometry, and this is a stated absence rather than a silent one |
| 19 | The cause of every uncovered requirement re-derives | PASS | all 1 uncovered requirement(s) re-derive their cause from this receipt's own rows. What notice is ADEQUATE is not decided here: this check establishes what the record says and that the record agrees with itself. |
| 21 | The sealing party is the one you were told to expect | UNVERIFIABLE | NOT APPLICABLE — you supplied no trust bundle, so nothing here establishes who sealed this. Identities 1 to 20 prove that this document agrees with itself; not one of them asks whose trust root it was sealed under, and a document that agrees with itself about a decision nobody made agrees with itself perfectly. Obtain the issuer's corobate:trust-bundle:1 out of band, confirm its spoken fingerprint with them by voice, and re-run with --trust-bundle <file> --expect-fingerprint <what you heard>. Nothing here has failed and nothing here has passed. |
The scoped copy itself — complete for this role
{
"spec": "corobate:role-view:2",
"role": "AUDITOR",
"purpose": "An external assessor. Sees the complete sealed record: this view withholds nothing and exists so the identity case is a case rather than an exception.",
"is_a_receipt": false,
"warning": "This is a SCOPED COPY of a sealed decision, not the decision record itself. It will not verify as a receipt and must not be presented as one. To confirm it is faithful, recompute its `view` digest under the same canonicalisation that produces receipt_hash and compare it with the entry for this role in the source receipt’s `views` block.",
"derived_from": {
"receipt_hash": "sha256:02be618b5d00cceb6f837bb29494c14973458076fd7998398a8daea7165ae8b4",
"entry_hash": "sha256:6b9124406ee627da802b075c8ef55df54ffc8320e20937b2d1f1038d286feefb",
"issued_at": "2026-08-08T16:00:00.000Z"
},
"view_digest": "sha256:2e0e9d01c728e141bdde2dd5deffaedcecfc0aae1ac876ff7167bc0588ab10c9",
"withheld": {
"anything_withheld": false,
"note": "Nothing outside the seal was removed for this role."
},
"view": {
"spec": "urn:ietf:params:corobate:receipt:1",
"receipt_version": "1.8",
"engine": {
"name": "corobate-memory",
"version": "1.0.0"
},
"decision": {
"id": "ai_TRIAGE_EVIDENCE_CORROBORATION_ONLY",
"domain": "supply-chain",
"subject": "ai-system:TRIAGE-ASSISTANT-V4",
"question": "May this quarter's vulnerability triage be accepted as the record of review?"
},
"issued_at": "2026-08-08T16:00:00.000Z",
"data_horizon": "2026-08-08T16:00:00.000Z",
"inputs": [
{
"key": "ai-system:TRIAGE-ASSISTANT-V4::vulnerability_scan",
"value": "clean-at-scan",
"provenance": "VERIFIED",
"source": "nvd-cve:vulnerability_scan",
"observed_at": "2026-08-04T16:00:00.000Z",
"last_corroborated_at": null,
"memory_refreshed_by": [],
"reliability": 0.95,
"critical": true,
"memory_id": "mem_4d2b1fc0d322",
"memory_status": "admitted",
"memory_kind": "status",
"memory_actor": "actor:sys:registry:nvd-cve",
"memory_age_days": 4,
"memory_track": {
"n": 1,
"successes": 1
},
"memory_promoted_by": [],
"memory_content_digest": "sha256:aea4c3860d57b3edd045cd33946015c41ff1aee9cc8a4df49f26d8a5165d4a38",
"memory_outcomes": {
"verified": 0,
"falsified": 0,
"modified": 0,
"counted": 0,
"recorded": 0
},
"memory_outcome_attestations": [],
"memory_observer_lineage": null,
"memory_corroborations": [],
"memory_reingest": null,
"memory_reasons": [
"sparse track record: 1 independent observation(s); no failure recorded, so the class ceiling stands"
],
"memory_class_floor": null,
"memory_below_class_floor": false,
"memory_not_attested": false,
"memory_below_claim_reliability_floor": false,
"memory_not_competent_authority": false,
"memory_out_of_specification": false,
"memory_ai_authored": false,
"memory_ai_in_lineage": false,
"memory_ai_position": "ADMIT",
"memory_ai_inadmissible": false,
"memory_geo_inadmissible": false,
"memory_geo_rung": null,
"memory_geo_metric": null,
"memory_geo_required_metric": null,
"observer_attested": true,
"observer_auth_code": "VERIFIED",
"observer_key_id": "k_5873dd9e7169def3",
"attestation": null,
"derivation": {
"provenance": "VERIFIED",
"ceiling_bp": 9500,
"track": {
"n": 1,
"successes": 1
},
"wilson_bp": null,
"age_days": 4,
"max_age_days": 14,
"house_max_age_days": 14,
"instrument_max_age_days": 30,
"freshness_cap_bp": 4000,
"min_track_n": 5,
"wilson_z_milli": 1960,
"source_present": true,
"seller_asserted_cap_bp": 5000,
"retracted": false,
"contradicted": false,
"outcome_trials": 0,
"outcomes": {
"verified": 0,
"falsified": 0,
"modified": 0,
"counted": 0,
"recorded": 0
},
"corroborations_counted": 0,
"corroborations_discounted": 0,
"reingest_ceiling_bp": null,
"reingest_depth": null,
"reingest_weakest_class": null,
"reingest_source_confidence_bp": null,
"ai_authored": false,
"ai_authored_because": null,
"ai_in_lineage": false,
"ai_position": "ADMIT"
},
"memory_reason_codes": [
{
"code": "SPARSE_TRACK_RECORD",
"observed": 1,
"limit": 5,
"binding": false
}
],
"context_line": "[VERIFIED · r=95.0% · 4d · nvd-cve:vulnerability_scan] ai-system:TRIAGE-ASSISTANT-V4 / vulnerability_scan: clean-at-scan"
},
{
"key": "ai-system:TRIAGE-ASSISTANT-V4::penetration_test",
"value": "no-critical",
"provenance": "VERIFIED",
"source": "LAB-NVLAP-0412:penetration_test",
"observed_at": "2026-06-09T16:00:00.000Z",
"last_corroborated_at": null,
"memory_refreshed_by": [],
"reliability": 0.95,
"critical": true,
"memory_id": "mem_a3316d633bfe",
"memory_status": "admitted",
"memory_kind": "test_report",
"memory_actor": "actor:org:LAB-NVLAP-0412",
"memory_age_days": 60,
"memory_track": {
"n": 1,
"successes": 1
},
"memory_promoted_by": [],
"memory_content_digest": "sha256:db69fb062be9b066b370c668281e12896da2869456a2e6d356a0f14879b27de9",
"memory_outcomes": {
"verified": 0,
"falsified": 0,
"modified": 0,
"counted": 0,
"recorded": 0
},
"memory_outcome_attestations": [],
"memory_observer_lineage": null,
"memory_corroborations": [],
"memory_reingest": null,
"memory_reasons": [
"sparse track record: 1 independent observation(s); no failure recorded, so the class ceiling stands"
],
"memory_class_floor": "VERIFIED",
"memory_below_class_floor": false,
"memory_not_attested": false,
"memory_below_claim_reliability_floor": false,
"memory_not_competent_authority": false,
"memory_out_of_specification": false,
"memory_ai_authored": false,
"memory_ai_in_lineage": false,
"memory_ai_position": "ADMIT",
"memory_ai_inadmissible": false,
"memory_geo_inadmissible": false,
"memory_geo_rung": null,
"memory_geo_metric": null,
"memory_geo_required_metric": null,
"observer_attested": true,
"observer_auth_code": "VERIFIED",
"observer_key_id": "k_17d23885943ae529",
"attestation": null,
"derivation": {
"provenance": "VERIFIED",
"ceiling_bp": 9500,
"track": {
"n": 1,
"successes": 1
},
"wilson_bp": null,
"age_days": 60,
"max_age_days": 180,
"house_max_age_days": 180,
"instrument_max_age_days": null,
"freshness_cap_bp": 4000,
"min_track_n": 5,
"wilson_z_milli": 1960,
"source_present": true,
"seller_asserted_cap_bp": 5000,
"retracted": false,
"contradicted": false,
"outcome_trials": 0,
"outcomes": {
"verified": 0,
"falsified": 0,
"modified": 0,
"counted": 0,
"recorded": 0
},
"corroborations_counted": 0,
"corroborations_discounted": 0,
"reingest_ceiling_bp": null,
"reingest_depth": null,
"reingest_weakest_class": null,
"reingest_source_confidence_bp": null,
"min_class_floor": "VERIFIED",
"ai_authored": false,
"ai_authored_because": null,
"ai_in_lineage": false,
"ai_position": "ADMIT"
},
"memory_reason_codes": [
{
"code": "SPARSE_TRACK_RECORD",
"observed": 1,
"limit": 5,
"binding": false
}
],
"context_line": "[VERIFIED · r=95.0% · 60d · LAB-NVLAP-0412:penetration_test] ai-system:TRIAGE-ASSISTANT-V4 / penetration_test: no-critical"
},
{
"key": "ai-system:TRIAGE-ASSISTANT-V4::control_assessment",
"value": "satisfied",
"provenance": "VERIFIED",
"source": "CERT-3PAO-ATLANTIC:control_assessment",
"observed_at": "2026-04-30T16:00:00.000Z",
"last_corroborated_at": null,
"memory_refreshed_by": [],
"reliability": 0.95,
"critical": true,
"memory_id": "mem_a153eb336060",
"memory_status": "admitted",
"memory_kind": "certificate",
"memory_actor": "actor:org:CERT-3PAO-ATLANTIC",
"memory_age_days": 100,
"memory_track": {
"n": 1,
"successes": 1
},
"memory_promoted_by": [],
"memory_content_digest": "sha256:c1aaf46a55b4cdc629a754ac35da1b8ec4dec85c2c78613c7bc93546b63f233c",
"memory_outcomes": {
"verified": 0,
"falsified": 0,
"modified": 0,
"counted": 0,
"recorded": 0
},
"memory_outcome_attestations": [],
"memory_observer_lineage": null,
"memory_corroborations": [],
"memory_reingest": null,
"memory_reasons": [
"sparse track record: 1 independent observation(s); no failure recorded, so the class ceiling stands"
],
"memory_class_floor": "VERIFIED",
"memory_below_class_floor": false,
"memory_not_attested": false,
"memory_below_claim_reliability_floor": false,
"memory_not_competent_authority": false,
"memory_out_of_specification": false,
"memory_ai_authored": false,
"memory_ai_in_lineage": false,
"memory_ai_position": "ADMIT",
"memory_ai_inadmissible": false,
"memory_geo_inadmissible": false,
"memory_geo_rung": null,
"memory_geo_metric": null,
"memory_geo_required_metric": null,
"observer_attested": true,
"observer_auth_code": "VERIFIED",
"observer_key_id": "k_307e4bfd710ec9b3",
"attestation": null,
"derivation": {
"provenance": "VERIFIED",
"ceiling_bp": 9500,
"track": {
"n": 1,
"successes": 1
},
"wilson_bp": null,
"age_days": 100,
"max_age_days": 365,
"house_max_age_days": 365,
"instrument_max_age_days": 365,
"freshness_cap_bp": 4000,
"min_track_n": 5,
"wilson_z_milli": 1960,
"source_present": true,
"seller_asserted_cap_bp": 5000,
"retracted": false,
"contradicted": false,
"outcome_trials": 0,
"outcomes": {
"verified": 0,
"falsified": 0,
"modified": 0,
"counted": 0,
"recorded": 0
},
"corroborations_counted": 0,
"corroborations_discounted": 0,
"reingest_ceiling_bp": null,
"reingest_depth": null,
"reingest_weakest_class": null,
"reingest_source_confidence_bp": null,
"min_class_floor": "VERIFIED",
"ai_authored": false,
"ai_authored_because": null,
"ai_in_lineage": false,
"ai_position": "ADMIT"
},
"memory_reason_codes": [
{
"code": "SPARSE_TRACK_RECORD",
"observed": 1,
"limit": 5,
"binding": false
}
],
"context_line": "[VERIFIED · r=95.0% · 100d · CERT-3PAO-ATLANTIC:control_assessment] ai-system:TRIAGE-ASSISTANT-V4 / control_assessment: satisfied"
},
{
"key": "ai-system:TRIAGE-ASSISTANT-V4::vulnerability_triage_disposition",
"value": null,
"provenance": "MODELED",
"source": "triage-assistant-v4:vulnerability_triage_disposition",
"observed_at": "2026-08-05T16:00:00.000Z",
"last_corroborated_at": null,
"memory_refreshed_by": [],
"reliability": 0.8,
"critical": false,
"memory_id": "mem_0a6980bbce9f",
"memory_status": "withheld",
"memory_kind": "status",
"memory_actor": "actor:ai:triage-assistant-v4",
"memory_age_days": 3,
"memory_track": {
"n": 1,
"successes": 1
},
"memory_promoted_by": [],
"memory_content_digest": "sha256:612e098189acf7652c237b016c3537b38c17d735452f4f1d519c6bfa0772b2c2",
"memory_outcomes": {
"verified": 0,
"falsified": 0,
"modified": 0,
"counted": 0,
"recorded": 0
},
"memory_outcome_attestations": [],
"memory_observer_lineage": null,
"memory_corroborations": [],
"memory_reingest": null,
"memory_reasons": [
"AI-authored and standing alone: the authority binding this claim admits model output as corroboration but not as the whole of it, and nothing else that survived on this decision — no separate admissible record and no counted corroboration from a party that is not itself a model — carries \"ai-system:TRIAGE-ASSISTANT-V4|vulnerability_triage_disposition\". A model agreeing with nothing is not corroboration, and a model agreeing with a record this decision has itself refused is agreeing with nothing.",
"sparse track record: 1 independent observation(s); no failure recorded, so the class ceiling stands"
],
"memory_class_floor": null,
"memory_below_class_floor": false,
"memory_not_attested": false,
"memory_below_claim_reliability_floor": false,
"memory_not_competent_authority": false,
"memory_out_of_specification": false,
"memory_ai_authored": true,
"memory_ai_in_lineage": false,
"memory_ai_position": "CORROBORATION_ONLY",
"memory_ai_inadmissible": true,
"memory_geo_inadmissible": false,
"memory_geo_rung": null,
"memory_geo_metric": null,
"memory_geo_required_metric": null,
"observer_attested": true,
"observer_auth_code": "VERIFIED",
"observer_key_id": "k_f71bde46a9680d8d",
"attestation": null,
"derivation": {
"provenance": "MODELED",
"ceiling_bp": 8000,
"track": {
"n": 1,
"successes": 1
},
"wilson_bp": null,
"age_days": 3,
"max_age_days": 14,
"house_max_age_days": 14,
"instrument_max_age_days": null,
"freshness_cap_bp": 4000,
"min_track_n": 5,
"wilson_z_milli": 1960,
"source_present": true,
"seller_asserted_cap_bp": 5000,
"retracted": false,
"contradicted": false,
"outcome_trials": 0,
"outcomes": {
"verified": 0,
"falsified": 0,
"modified": 0,
"counted": 0,
"recorded": 0
},
"corroborations_counted": 0,
"corroborations_discounted": 0,
"reingest_ceiling_bp": null,
"reingest_depth": null,
"reingest_weakest_class": null,
"reingest_source_confidence_bp": null,
"ai_authored": true,
"ai_authored_because": "a model, named as one in its own enrolled identity",
"ai_in_lineage": false,
"ai_position": "CORROBORATION_ONLY",
"ai_sole_basis": true
},
"memory_reason_codes": [
{
"code": "AI_SOLE_BASIS",
"observed": "actor:ai:triage-assistant-v4",
"limit": "CORROBORATION_ONLY",
"binding": true
},
{
"code": "SPARSE_TRACK_RECORD",
"observed": 1,
"limit": 5,
"binding": false
}
]
},
{
"key": "ai-system:TRIAGE-ASSISTANT-V4::vulnerability_triage_disposition",
"value": null,
"provenance": "MISSING",
"source": null,
"observed_at": "2026-08-08T16:00:00.000Z",
"reliability": 0,
"critical": true,
"memory_status": "coverage_gap",
"gap_cause": "EVIDENCE_PRESENTED_FAILED",
"gap_request": null,
"gap_origin": "BUSINESS_EVIDENCE",
"gap_conditions": [
"ai_inadmissible"
]
}
],
"serialization": {
"algorithm": "RFC8785-JCS",
"hash": "sha256"
},
"crypto_suite": {
"spec": "corobate:suite:1",
"id": "CB-1-ES256-SHA256",
"receipt_digest": "sha256",
"chain_digest": "sha256",
"content_digest": "sha256",
"envelope_signature": "ES256",
"signature_curve": "P-256",
"canonicalisation": "attest-canon/2",
"quantum_resistant": false
},
"confidence": {
"value": 0,
"method": "min-over-critical-inputs",
"bound_by": "ai-system:TRIAGE-ASSISTANT-V4::vulnerability_triage_disposition"
},
"verdict": {
"value": "WITHHELD",
"threshold_approve": 0.85,
"threshold_caution": 0.6,
"rule": "confidence>=threshold"
},
"release": {
"required": false,
"required_by_tier": false,
"escalated_by_acceptance": false,
"risk_accepted": false,
"state": "WITHHELD_NO_EVIDENCE",
"code": "QUORUM_EVIDENCE_WITHHELD",
"reason": "the evidence did not clear the threshold for this exposure, so there is nothing to release. Signatures do not substitute for evidence, and this state is deliberately distinct from WITHHELD_PENDING_SIGNATURES: a reader must be able to tell \"the evidence is not there\" from \"the evidence is there and 0 of 2 people have signed\".",
"tier_floor_cents": 1000000000,
"exposure_usd_cents": 25000000,
"required_m": 2,
"declared_n": 3,
"floor_m": 2,
"distinct_signers": 0,
"superseded": 0,
"collapsed": 0,
"release_digest": "sha256:2e954dcf94eabc7d1a96c41ff856217c64f65ad722b43bccaaf61e5de35dbe1d",
"governance_digest": "sha256:8b0a45a27fcce9c1c243c764e855e67c6fe6dfd7f02a563bd90809b419731905",
"governance_signed": true,
"counted_voices": [],
"signatures": [],
"ledger_seq": null
},
"acceptance": {
"state": "NONE",
"code": "ACCEPTANCE_NONE",
"reason": "no risk acceptance was presented for this decision. This is the ordinary case: a refusal is a refusal unless a named person has priced it.",
"permitted_basis": null,
"presented": 0,
"superseded": 0,
"expired": 0,
"gaps_not_covered": 0,
"coverage_gaps_in_force": [
"ai-system:TRIAGE-ASSISTANT-V4|vulnerability_triage_disposition"
],
"evidentiary_digest": "sha256:2e954dcf94eabc7d1a96c41ff856217c64f65ad722b43bccaaf61e5de35dbe1d",
"margin_floor_bp": 100,
"authority_ceiling_cents": {
"SUPERVISOR": 1000000,
"MANAGER": 25000000,
"DIRECTOR": 500000000,
"OFFICER": 5000000000
},
"acceptances": [],
"escalated": false,
"live": false,
"ledger_seq": null
},
"regulatory": {
"spec": "corobate:regulatory:2",
"resolved": true,
"applied": [
{
"instrument_id": "enterprise-ai-evidence-standard",
"version": 1,
"authority": "Office of the Chief Information Security Officer",
"instrument": "Enterprise standard on machine-generated evidence",
"edition": "2026-03-01",
"citation": "§ 3 [VERIFY]",
"source_digest": "sha256:e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5",
"entered_by": "actor:human:issm",
"entered_at": "2026-08-08T16:00:00.000Z"
},
{
"instrument_id": "nist-sp-800-53r5-moderate",
"version": 5,
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
"edition": "Rev. 5",
"citation": "CA-2, CA-8, RA-5, SR-6 [VERIFY]",
"source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353",
"entered_by": "actor:human:issm",
"entered_at": "2026-08-08T16:00:00.000Z"
}
],
"skipped": [],
"conflicts": [],
"bindings": [
{
"claim": "control_assessment",
"requirement": "max_age_days",
"value": 365,
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
"instrument_id": "nist-sp-800-53r5-moderate",
"version": 5,
"edition": "Rev. 5",
"citation": "CA-2 [VERIFY]",
"source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "control_assessment",
"requirement": "min_class",
"value": "VERIFIED",
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
"instrument_id": "nist-sp-800-53r5-moderate",
"version": 5,
"edition": "Rev. 5",
"citation": "CA-2(1) independent assessors [VERIFY]",
"source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "control_assessment",
"requirement": "required",
"value": true,
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
"instrument_id": "nist-sp-800-53r5-moderate",
"version": 5,
"edition": "Rev. 5",
"citation": "CA-2 [VERIFY]",
"source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "penetration_test",
"requirement": "min_class",
"value": "VERIFIED",
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
"instrument_id": "nist-sp-800-53r5-moderate",
"version": 5,
"edition": "Rev. 5",
"citation": "CA-8(1) independent penetration agent [VERIFY]",
"source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "penetration_test",
"requirement": "required",
"value": true,
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
"instrument_id": "nist-sp-800-53r5-moderate",
"version": 5,
"edition": "Rev. 5",
"citation": "CA-8 [VERIFY]",
"source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "vulnerability_scan",
"requirement": "max_age_days",
"value": 30,
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
"instrument_id": "nist-sp-800-53r5-moderate",
"version": 5,
"edition": "Rev. 5",
"citation": "RA-5(a) [VERIFY]",
"source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "vulnerability_scan",
"requirement": "required",
"value": true,
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
"instrument_id": "nist-sp-800-53r5-moderate",
"version": 5,
"edition": "Rev. 5",
"citation": "RA-5 [VERIFY]",
"source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "vulnerability_triage_disposition",
"requirement": "ai_position",
"value": "CORROBORATION_ONLY",
"bound_by": {
"authority": "Office of the Chief Information Security Officer",
"instrument": "Enterprise standard on machine-generated evidence",
"instrument_id": "enterprise-ai-evidence-standard",
"version": 1,
"edition": "2026-03-01",
"citation": "§ 3.4 [VERIFY]",
"source_digest": "sha256:e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "vulnerability_triage_disposition",
"requirement": "required",
"value": true,
"bound_by": {
"authority": "Office of the Chief Information Security Officer",
"instrument": "Enterprise standard on machine-generated evidence",
"instrument_id": "enterprise-ai-evidence-standard",
"version": 1,
"edition": "2026-03-01",
"citation": "§ 3.1 [VERIFY]",
"source_digest": "sha256:e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
}
],
"defaults": [
{
"claim": "control_assessment",
"requirement": "ai_position",
"value": "ADMIT",
"because": "No instrument in force stated a position on AI-authored evidence for \"control_assessment\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
},
{
"claim": "penetration_test",
"requirement": "ai_position",
"value": "ADMIT",
"because": "No instrument in force stated a position on AI-authored evidence for \"penetration_test\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
},
{
"claim": "vulnerability_scan",
"requirement": "ai_position",
"value": "ADMIT",
"because": "No instrument in force stated a position on AI-authored evidence for \"vulnerability_scan\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
}
]
},
"reasons": [
"Coverage gap: no admissible memory for required claim(s) ai-system:TRIAGE-ASSISTANT-V4|vulnerability_triage_disposition.",
"Confidence 0.00% is bound by \"ai-system:TRIAGE-ASSISTANT-V4|vulnerability_triage_disposition\".",
"1 memory was withheld from the context block: ai-system:TRIAGE-ASSISTANT-V4|vulnerability_triage_disposition (AI-authored and standing alone: the authority binding this claim admits model output as corroboration but not as the whole of it, and nothing else that survived on this decision — no separate admissible record and no counted corroboration from a party that is not itself a model — carries \"ai-system:TRIAGE-ASSISTANT-V4|vulnerability_triage_disposition\". A model agreeing with nothing is not corroboration, and a model agreeing with a record this decision has itself refused is agreeing with nothing.).",
"Thresholds for $250,000 exposure: approve 85%, caution 60%."
],
"memory": {
"layer": "capture->store->recall->act",
"ledger_head": "sha256:b037093616312675fb7422882b44889dba9f936590214cd993c2e391b7f121c9",
"ledger_entries": 6,
"context_digest": null,
"context_memory_ids": [],
"state_digest": "sha256:9357ab4d994dcd108cd3f22257927b155d8e44f669c5c0bb8d3e9bfc6be9e52a",
"retrieval_method": "idf-lexical",
"corpus_size": 4,
"considered": 4,
"admitted": 3,
"withheld": 1,
"not_considered": 0,
"coverage_gaps": [
"ai-system:TRIAGE-ASSISTANT-V4|vulnerability_triage_disposition"
],
"exposure": {
"usd": 250000,
"declared_by": "actor:human:issm",
"ledger_seq": 4
},
"salience_policy": {
"half_life_days": 90,
"grace_days": 7,
"access_boost_bp": 500,
"access_boost_cap_bp": 2500,
"relevance_weight_bp": 6000,
"recency_weight_bp": 3000,
"usage_weight_bp": 1000,
"context_cap": 12,
"method": "idf-lexical",
"candidate_list_digest": "sha256:fa532eca9f6e74d805d7557e2b12f0a9b5ac6a3262e163b632463317b542709f",
"note": "salience orders retrieval only; it never contributes to reliability"
},
"policy_digest": "sha256:a6b69b7d20f7fb04d522364af1d92992058b04a5835fcec9d1c9f2261c7ef636",
"policy_body": {
"class_ceiling_bp": {
"VERIFIED": 9500,
"MODELED": 8000,
"SELLER-ASSERTED": 5000,
"MISSING": 0
},
"actor_class_ceiling": [
[
"^actor:ai:",
"MODELED"
],
[
"^actor:agent:",
"MODELED"
],
[
"^actor:human:",
"SELLER-ASSERTED"
],
[
"^actor:org:LAB-",
"VERIFIED"
],
[
"^actor:org:CERT-",
"VERIFIED"
],
[
"^actor:org:",
"SELLER-ASSERTED"
],
[
"^actor:sys:registry:",
"VERIFIED"
],
[
"^actor:sys:sensor:",
"VERIFIED"
],
[
"^actor:sys:",
"MODELED"
]
],
"freshness_cap_bp": 4000,
"max_age_days": {
"telemetry": 1,
"price": 7,
"status": 14,
"certificate": 365,
"test_report": 180,
"filing": 90,
"transcript": 120,
"highlight": 365,
"voice_note": 120,
"note": 365,
"preference": 540,
"decision": 1825,
"receipt": 365,
"default": 90
},
"wilson_z_milli": 1960,
"min_track_n": 5,
"exposure_tiers_bp": [
[
1000000000,
9500,
8000
],
[
100000000,
9000,
7000
],
[
1000000,
8500,
6000
],
[
0,
8000,
5000
]
],
"max_context_memories": 12,
"contradiction_resolve_margin": 2,
"salience": {
"half_life_days": 90,
"grace_days": 7,
"access_boost_bp": 500,
"access_boost_cap_bp": 2500,
"relevance_weight_bp": 6000,
"recency_weight_bp": 3000,
"usage_weight_bp": 1000
}
},
"observer_auth": {
"mode": "required",
"registry_version": 3,
"registry_digest": "sha256:460aeaafe345f69542a302e6619dff0712af98de6518838ee4c8585e448c3a7d",
"entries_root": "sha256:5670469f96484a814462814ed74f0f992b5f19e8ad6afced548e4956e4835ba5",
"memberships": [
{
"key_id": "k_17d23885943ae529",
"index": 1,
"entry": {
"actor": "actor:org:LAB-NVLAP-0412",
"class": "VERIFIED",
"kind": "org",
"key_id": "k_17d23885943ae529",
"jwk": {
"kty": "EC",
"crv": "P-256",
"x": "3TTw47-PkYfo3ZaKTq_qtHghnGvninAVj25kyOwONno",
"y": "16PMaR8ofeF5IcZk6ZLml8gDs8uE1s1sBLdciH5e4vg"
},
"valid_from": "2025-01-01T00:00:00.000Z",
"valid_to": "2027-06-01T00:00:00.000Z"
},
"path": [
{
"side": "left",
"sibling": "sha256:500f2ba5949d5256ae0f563530b0b270db41ce99d2d7c4b4b60e4bd558ca353d"
},
{
"side": "right",
"sibling": "sha256:a0b47ea437bf4f1042a1dd50a5a3f411f9a17971812fc6bafccd434eb7d78ccc"
},
{
"side": "right",
"sibling": "sha256:d3c2347eb675e865fc17ef0204cacda7b02e8784a811fdd1c8a015d1865e6dfb"
},
{
"side": "right",
"sibling": "sha256:7071adf5e21a94147d31f42f1028b4867b6562e5b78726259c2515b03b213e52"
}
]
},
{
"key_id": "k_307e4bfd710ec9b3",
"index": 0,
"entry": {
"actor": "actor:org:CERT-3PAO-ATLANTIC",
"class": "VERIFIED",
"kind": "org",
"key_id": "k_307e4bfd710ec9b3",
"jwk": {
"kty": "EC",
"crv": "P-256",
"x": "MGtV26TezLMPjiD3SecQtnje6eLqYyx4qkKzzAkbiY4",
"y": "SMMdLYnn-FpKbb2sJQ8EAZnzvozNm-cGO0VbUUpniPY"
},
"valid_from": "2025-01-01T00:00:00.000Z",
"valid_to": "2027-06-01T00:00:00.000Z"
},
"path": [
{
"side": "right",
"sibling": "sha256:4148869fc259d2c5fc19fe5831065b165a9acf81812e123162035acfdecade1d"
},
{
"side": "right",
"sibling": "sha256:a0b47ea437bf4f1042a1dd50a5a3f411f9a17971812fc6bafccd434eb7d78ccc"
},
{
"side": "right",
"sibling": "sha256:d3c2347eb675e865fc17ef0204cacda7b02e8784a811fdd1c8a015d1865e6dfb"
},
{
"side": "right",
"sibling": "sha256:7071adf5e21a94147d31f42f1028b4867b6562e5b78726259c2515b03b213e52"
}
]
},
{
"key_id": "k_5873dd9e7169def3",
"index": 2,
"entry": {
"actor": "actor:sys:registry:nvd-cve",
"class": "VERIFIED",
"kind": "system",
"key_id": "k_5873dd9e7169def3",
"jwk": {
"kty": "EC",
"crv": "P-256",
"x": "O9OY6oMuJg0df_INePO19_3b11VaSyMwIPdxoqvV2ak",
"y": "k7Orm5pxDxMdTF-H2S4h6ixRywzk1WxvquOQeqxLFx0"
},
"valid_from": "2025-01-01T00:00:00.000Z",
"valid_to": "2027-06-01T00:00:00.000Z"
},
"path": [
{
"side": "right",
"sibling": "sha256:e1fe36fe7c8e4695327c25d6d722630b6249c93293bfdc5894c58aaf961ab6f8"
},
{
"side": "left",
"sibling": "sha256:e8b9cba101f13538b909a2e686e9e6e9a8d77212036ed567eaebc205a443e83f"
},
{
"side": "right",
"sibling": "sha256:d3c2347eb675e865fc17ef0204cacda7b02e8784a811fdd1c8a015d1865e6dfb"
},
{
"side": "right",
"sibling": "sha256:7071adf5e21a94147d31f42f1028b4867b6562e5b78726259c2515b03b213e52"
}
]
},
{
"key_id": "k_f71bde46a9680d8d",
"index": 7,
"entry": {
"actor": "actor:ai:triage-assistant-v4",
"class": "MODELED",
"kind": "system",
"key_id": "k_f71bde46a9680d8d",
"jwk": {
"kty": "EC",
"crv": "P-256",
"x": "AmVfK7ltK7mprIKSXcj-PNTw4f8zq2gcbRG-qEiFmbU",
"y": "W7sar2SHGJ_jUsBSxoasMr7l1If81Qu5BdYfvlK8Who"
},
"valid_from": "2025-01-01T00:00:00.000Z",
"valid_to": "2027-06-01T00:00:00.000Z"
},
"path": [
{
"side": "left",
"sibling": "sha256:3e8eae859976a6f7d64543a05e28b4c8fc52b8500c65decc7e124af145fac567"
},
{
"side": "left",
"sibling": "sha256:6d20941c438f3924c50e6573d0712466ec6b91655705d2603ea89981e4c50ffc"
},
{
"side": "left",
"sibling": "sha256:d3f1d60ec9478d2b69455e5ba8168897966d18429bd3b7d36105841cc2ae1776"
},
{
"side": "right",
"sibling": "sha256:7071adf5e21a94147d31f42f1028b4867b6562e5b78726259c2515b03b213e52"
}
]
}
],
"memberships_unproven": [],
"revocation": {
"source": "SIGNED_LIST",
"digest": "sha256:12f73b1fbf27d38cf137b86a1ce13bbcd98161123a6aa7d79b107db8189966b9",
"sequence": 5,
"registry_version": 3,
"issued_at": "2026-08-06T00:00:00.000Z",
"next_update_due": "2026-08-13T00:00:00.000Z",
"entry_count": 0,
"body": {
"sequence": 5,
"registry_version": 3,
"issuer": {
"name": "NIST-regulated enterprise demonstration trust root",
"key_id": "k_3793b8e35f8acac1"
},
"issued_at": "2026-08-06T00:00:00.000Z",
"next_update_due": "2026-08-13T00:00:00.000Z",
"entries": [],
"spec": "corobate:revocation-list:1"
}
}
},
"governance": {
"digest": "sha256:8b0a45a27fcce9c1c243c764e855e67c6fe6dfd7f02a563bd90809b419731905",
"signed": true,
"actor_trust": "FLOOR_TO_SELLER_ASSERTED",
"outcome_trial_weight": 1,
"max_reingest_depth": 3,
"release_quorum_m": 2,
"release_quorum_n": 3,
"risk_acceptance_margin_bp": 500,
"risk_acceptance_max_days": 30,
"risk_acceptance_authority_cents": {
"SUPERVISOR": 1000000,
"MANAGER": 25000000,
"DIRECTOR": 500000000,
"OFFICER": 5000000000
},
"template_author_roles": [
"MANAGER",
"DIRECTOR",
"OFFICER"
]
},
"observers_attested": 3,
"outcomes": {
"attestations_counted": 0,
"attestations_recorded": 0,
"records_with_outcomes": 0
},
"lineage": {
"corroborations_counted": 0,
"corroborations_discounted": 0,
"records_with_discounted_corroborations": 0
},
"reingest": {
"records": 0,
"max_depth": 0,
"weakest_class": null,
"chain_weakest_bp": 10000,
"chain": []
},
"template": null
}
}
}The enterprise tries the honest workaround. A sealed decision that already rested on the assistant is presented for this control by an accredited laboratory. Nothing is forged: the receipt verifies, the presenter is real, the presenter’s own class is VERIFIED. It is refused anyway, because the model is in the lineage and the strictest rung says so. Without this rung an exclusion is defeated by one round trip through a sealed receipt, which is the shape every laundering path in this system takes.
- Subject
- ai-system:TRIAGE-ASSISTANT-V4
- Question
- May this quarter's vulnerability triage be accepted as the record of review?
- Exposure
- $250,000
- Instruments
- Office of the Chief Information Security Officer · National Institute of Standards and Technology
- Outcome
- WITHHELD — the action is not permitted; outstanding: vulnerability triage disposition
- Receipt
- sha256:ee44fd0e4bc167b9c18e62720219425692aaedd851f997bc4c6971c79be02199
The gate variables this decision ran under — a dial per question, read back off the sealed receipt
control assessmentrequired
penetration testrequired
vulnerability scanrequired
vulnerability triage dispositionrequired
Every bar above was re-derived from the regulatory bindings inside this receipt’s hashed body, not from the configuration that produced it. A bar in grey is a setting no instrument made — the deploying organisation’s own default, which still binds and is not an absence. A bar position renders an ordinal on a declared ladder: it is a way to draw a control and to compare two settings on the same axis, and it is not a measurement. The value printed beside each bar is the authoritative one.
Whoever must act now
The engineer with the deployment in their hands, the release manager, the person who must publish or hold.
One instruction and the reason in words. No score, no money, no signatures.
Seven or eight fields, and not one of them is a number somebody can argue with. This person is not being asked to re-judge the evidence; somebody already did, and it is on the record.
The scoped copy itself — partial — something outside this role’s remit was removed
{
"spec": "corobate:role-view:2",
"role": "OPERATOR",
"purpose": "Whoever must act on this decision now — release the goods, fund the draw, dispatch the agent, ship the title. Sees one instruction and the reason in plain words, and nothing that could be argued about while somebody waits.",
"is_a_receipt": false,
"warning": "This is a SCOPED COPY of a sealed decision, not the decision record itself. It will not verify as a receipt and must not be presented as one. To confirm it is faithful, recompute its `view` digest under the same canonicalisation that produces receipt_hash and compare it with the entry for this role in the source receipt’s `views` block.",
"derived_from": {
"receipt_hash": "sha256:ee44fd0e4bc167b9c18e62720219425692aaedd851f997bc4c6971c79be02199",
"entry_hash": "sha256:2f26ad85cf44d0df56f007f3b09898161e93903b532e55d46b41823d233e9809",
"issued_at": "2026-08-08T16:00:00.000Z"
},
"view_digest": "sha256:fc675a63c6bfe9c36ae89a9bfe086d74915a0680505ded95d7c5633f2ecbe3d4",
"withheld": {
"anything_withheld": true,
"note": "Facts outside this role’s remit were removed. That something was removed is stated so a partial record is never mistaken for a complete one. How much, and what, is not stated — a count is an inference about the part you are not entitled to see."
},
"view": {
"spec": "urn:ietf:params:corobate:receipt:1",
"receipt_version": "1.8",
"issued_at": "2026-08-08T16:00:00.000Z",
"decision": {
"id": "ai_TRIAGE_EVIDENCE_EXCLUDE_TAINTED_LINEAGE",
"subject": "ai-system:TRIAGE-ASSISTANT-V4"
},
"memory": {
"state_digest": "sha256:2c0c2a47680fbf012f29aba9e9ea7a1e4292e0b41243cd158d904090723e6562",
"ledger_head": "sha256:666ec422cfa0a2aa3a0761bf5d34bc5eeb89079a0a37b9c86caf1f7e41c17603",
"coverage_gaps": [
"ai-system:TRIAGE-ASSISTANT-V4|vulnerability_triage_disposition"
]
},
"verdict": {
"value": "WITHHELD"
},
"release": {
"state": "WITHHELD_NO_EVIDENCE"
}
}
}Provider / assessed party
The cloud service provider, the release team, or the party operating the AI system — whoever is being assessed.
Sees which controls were required of them and by which publication and control identifier. Does not see the authorising official’s exposure figure or how any shortfall was priced.
What is outstanding on your file
- vulnerability triage disposition — required by Office of the Chief Information Security Officer, § 3.1 [VERIFY]
| Claim | Required | Evidence class | Who | Age | Outcome |
|---|---|---|---|---|---|
| vulnerability_scan | yes | VERIFIED | — | 2026-08-04 | admitted |
| penetration_test | yes | VERIFIED | — | 2026-06-09 | admitted |
| control_assessment | yes | VERIFIED | — | 2026-04-30 | admitted |
| vulnerability_triage_disposition | no | MODELED | — | 2026-08-05 | withheld |
| vulnerability_triage_disposition | no | MODELED | — | 2026-08-08 | withheld |
| vulnerability_triage_disposition | yes | MISSING | — | 2026-08-08 | coverage gap |
The clause is here because it turns an argument into an errand. What is not here: what the bank had at stake, and whether anyone priced the shortfall.
The scoped copy itself — partial — something outside this role’s remit was removed
{
"spec": "corobate:role-view:2",
"role": "SUPPLIER",
"purpose": "The party whose evidence was judged. Sees every claim the decision required, which fell short, and the clause that required it — and nothing about what the buyer had at stake or how the buyer priced any shortfall. NOTE, because an earlier draft of this sentence was untrue: this projection carries the WHOLE inputs array, so where several parties supplied evidence for one decision, each of them sees all of it. Per-party scoping cannot be expressed by a commitment scheme with one digest per role, and claiming it anyway would be the kind of promise this file exists to stop making.",
"is_a_receipt": false,
"warning": "This is a SCOPED COPY of a sealed decision, not the decision record itself. It will not verify as a receipt and must not be presented as one. To confirm it is faithful, recompute its `view` digest under the same canonicalisation that produces receipt_hash and compare it with the entry for this role in the source receipt’s `views` block.",
"derived_from": {
"receipt_hash": "sha256:ee44fd0e4bc167b9c18e62720219425692aaedd851f997bc4c6971c79be02199",
"entry_hash": "sha256:2f26ad85cf44d0df56f007f3b09898161e93903b532e55d46b41823d233e9809",
"issued_at": "2026-08-08T16:00:00.000Z"
},
"view_digest": "sha256:012591f154658fa177883bc4f2f569cb1630fa31f2d5f93d2b6eb7ffbc7b56f6",
"withheld": {
"anything_withheld": true,
"note": "Facts outside this role’s remit were removed. That something was removed is stated so a partial record is never mistaken for a complete one. How much, and what, is not stated — a count is an inference about the part you are not entitled to see."
},
"view": {
"spec": "urn:ietf:params:corobate:receipt:1",
"receipt_version": "1.8",
"issued_at": "2026-08-08T16:00:00.000Z",
"decision": {
"id": "ai_TRIAGE_EVIDENCE_EXCLUDE_TAINTED_LINEAGE",
"subject": "ai-system:TRIAGE-ASSISTANT-V4",
"question": "May this quarter's vulnerability triage be accepted as the record of review?"
},
"memory": {
"state_digest": "sha256:2c0c2a47680fbf012f29aba9e9ea7a1e4292e0b41243cd158d904090723e6562",
"ledger_head": "sha256:666ec422cfa0a2aa3a0761bf5d34bc5eeb89079a0a37b9c86caf1f7e41c17603",
"coverage_gaps": [
"ai-system:TRIAGE-ASSISTANT-V4|vulnerability_triage_disposition"
]
},
"verdict": {
"value": "WITHHELD"
},
"inputs": [
{
"key": "ai-system:TRIAGE-ASSISTANT-V4::vulnerability_scan",
"provenance": "VERIFIED",
"observed_at": "2026-08-04T16:00:00.000Z",
"memory_status": "admitted",
"critical": true
},
{
"key": "ai-system:TRIAGE-ASSISTANT-V4::penetration_test",
"provenance": "VERIFIED",
"observed_at": "2026-06-09T16:00:00.000Z",
"memory_status": "admitted",
"critical": true
},
{
"key": "ai-system:TRIAGE-ASSISTANT-V4::control_assessment",
"provenance": "VERIFIED",
"observed_at": "2026-04-30T16:00:00.000Z",
"memory_status": "admitted",
"critical": true
},
{
"key": "ai-system:TRIAGE-ASSISTANT-V4::vulnerability_triage_disposition",
"provenance": "MODELED",
"observed_at": "2026-08-05T16:00:00.000Z",
"memory_status": "withheld",
"critical": false
},
{
"key": "ai-system:TRIAGE-ASSISTANT-V4::vulnerability_triage_disposition",
"provenance": "MODELED",
"observed_at": "2026-08-08T16:00:00.000Z",
"memory_status": "withheld",
"critical": false
},
{
"key": "ai-system:TRIAGE-ASSISTANT-V4::vulnerability_triage_disposition",
"provenance": "MISSING",
"observed_at": "2026-08-08T16:00:00.000Z",
"memory_status": "coverage_gap",
"critical": true
}
],
"regulatory": {
"bindings": [
{
"claim": "control_assessment",
"requirement": "max_age_days",
"value": 365,
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
"instrument_id": "nist-sp-800-53r5-moderate",
"version": 5,
"edition": "Rev. 5",
"citation": "CA-2 [VERIFY]",
"source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "control_assessment",
"requirement": "min_class",
"value": "VERIFIED",
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
"instrument_id": "nist-sp-800-53r5-moderate",
"version": 5,
"edition": "Rev. 5",
"citation": "CA-2(1) independent assessors [VERIFY]",
"source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "control_assessment",
"requirement": "required",
"value": true,
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
"instrument_id": "nist-sp-800-53r5-moderate",
"version": 5,
"edition": "Rev. 5",
"citation": "CA-2 [VERIFY]",
"source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "penetration_test",
"requirement": "min_class",
"value": "VERIFIED",
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
"instrument_id": "nist-sp-800-53r5-moderate",
"version": 5,
"edition": "Rev. 5",
"citation": "CA-8(1) independent penetration agent [VERIFY]",
"source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "penetration_test",
"requirement": "required",
"value": true,
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
"instrument_id": "nist-sp-800-53r5-moderate",
"version": 5,
"edition": "Rev. 5",
"citation": "CA-8 [VERIFY]",
"source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "vulnerability_scan",
"requirement": "max_age_days",
"value": 30,
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
"instrument_id": "nist-sp-800-53r5-moderate",
"version": 5,
"edition": "Rev. 5",
"citation": "RA-5(a) [VERIFY]",
"source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "vulnerability_scan",
"requirement": "required",
"value": true,
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
"instrument_id": "nist-sp-800-53r5-moderate",
"version": 5,
"edition": "Rev. 5",
"citation": "RA-5 [VERIFY]",
"source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "vulnerability_triage_disposition",
"requirement": "ai_position",
"value": "EXCLUDE_TAINTED_LINEAGE",
"bound_by": {
"authority": "Office of the Chief Information Security Officer",
"instrument": "Enterprise standard on machine-generated evidence",
"instrument_id": "enterprise-ai-evidence-standard",
"version": 1,
"edition": "2026-03-01",
"citation": "§ 3.4 [VERIFY]",
"source_digest": "sha256:e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "vulnerability_triage_disposition",
"requirement": "required",
"value": true,
"bound_by": {
"authority": "Office of the Chief Information Security Officer",
"instrument": "Enterprise standard on machine-generated evidence",
"instrument_id": "enterprise-ai-evidence-standard",
"version": 1,
"edition": "2026-03-01",
"citation": "§ 3.1 [VERIFY]",
"source_digest": "sha256:e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
}
],
"applied": [
{
"instrument_id": "enterprise-ai-evidence-standard",
"version": 1,
"authority": "Office of the Chief Information Security Officer",
"instrument": "Enterprise standard on machine-generated evidence",
"edition": "2026-03-01",
"citation": "§ 3 [VERIFY]",
"source_digest": "sha256:e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5",
"entered_by": "actor:human:issm",
"entered_at": "2026-08-08T16:00:00.000Z"
},
{
"instrument_id": "nist-sp-800-53r5-moderate",
"version": 5,
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
"edition": "Rev. 5",
"citation": "CA-2, CA-8, RA-5, SR-6 [VERIFY]",
"source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353",
"entered_by": "actor:human:issm",
"entered_at": "2026-08-08T16:00:00.000Z"
}
],
"defaults": [
{
"claim": "control_assessment",
"requirement": "ai_position",
"value": "ADMIT",
"because": "No instrument in force stated a position on AI-authored evidence for \"control_assessment\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
},
{
"claim": "penetration_test",
"requirement": "ai_position",
"value": "ADMIT",
"because": "No instrument in force stated a position on AI-authored evidence for \"penetration_test\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
},
{
"claim": "vulnerability_scan",
"requirement": "ai_position",
"value": "ADMIT",
"because": "No instrument in force stated a position on AI-authored evidence for \"vulnerability_scan\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
}
]
}
}
}Assessor / authorising official
A third-party assessment organisation, an agency assessor, or an inspector general reviewing the package. Same position as a customs officer: a public mandate over the record.
The control record in full — each publication by control identifier, edition and document digest, and every required claim with who supplied it and when. No exposure figure, no risk pricing, no confidence score.
What each authority bound
| Claim | Requirement | Level | Bound by |
|---|---|---|---|
| control_assessment | max age days | 365 | National Institute of Standards and Technology CA-2 [VERIFY] · SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline) |
| control_assessment | min class | VERIFIED | National Institute of Standards and Technology CA-2(1) independent assessors [VERIFY] · SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline) |
| control_assessment | required | true | National Institute of Standards and Technology CA-2 [VERIFY] · SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline) |
| penetration_test | min class | VERIFIED | National Institute of Standards and Technology CA-8(1) independent penetration agent [VERIFY] · SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline) |
| penetration_test | required | true | National Institute of Standards and Technology CA-8 [VERIFY] · SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline) |
| vulnerability_scan | max age days | 30 | National Institute of Standards and Technology RA-5(a) [VERIFY] · SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline) |
| vulnerability_scan | required | true | National Institute of Standards and Technology RA-5 [VERIFY] · SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline) |
| vulnerability_triage_disposition | ai position | EXCLUDE_TAINTED_LINEAGE | Office of the Chief Information Security Officer § 3.4 [VERIFY] · Enterprise standard on machine-generated evidence |
| vulnerability_triage_disposition | required | true | Office of the Chief Information Security Officer § 3.1 [VERIFY] · Enterprise standard on machine-generated evidence |
Every required claim, and what was actually held
| Claim | Required | Evidence class | Who | Age | Outcome |
|---|---|---|---|---|---|
| vulnerability_scan | yes | VERIFIED | actor:sys:registry:nvd-cve | 2026-08-04 | admitted |
| penetration_test | yes | VERIFIED | actor:org:LAB-NVLAP-0412 | 2026-06-09 | admitted |
| control_assessment | yes | VERIFIED | actor:org:CERT-3PAO-ATLANTIC | 2026-04-30 | admitted |
| vulnerability_triage_disposition | no | MODELED | actor:ai:triage-assistant-v4 | 2026-08-05 | withheld |
| vulnerability_triage_disposition | no | MODELED | actor:org:LAB-NVLAP-0412 | 2026-08-08 | withheld |
| vulnerability_triage_disposition | yes | MISSING | — | 2026-08-08 | coverage gap |
The scoped copy itself — partial — something outside this role’s remit was removed
{
"spec": "corobate:role-view:2",
"role": "REGULATOR",
"purpose": "An official holding a public mandate over this record — a customs officer, a bank examiner, a market conduct supervisor. Sees the regulatory record in full: their own instrument named, every required claim and whether it was met, by whom, how old. No commercial figure of any kind.",
"is_a_receipt": false,
"warning": "This is a SCOPED COPY of a sealed decision, not the decision record itself. It will not verify as a receipt and must not be presented as one. To confirm it is faithful, recompute its `view` digest under the same canonicalisation that produces receipt_hash and compare it with the entry for this role in the source receipt’s `views` block.",
"derived_from": {
"receipt_hash": "sha256:ee44fd0e4bc167b9c18e62720219425692aaedd851f997bc4c6971c79be02199",
"entry_hash": "sha256:2f26ad85cf44d0df56f007f3b09898161e93903b532e55d46b41823d233e9809",
"issued_at": "2026-08-08T16:00:00.000Z"
},
"view_digest": "sha256:2c9d91944e2efed1f97186874e60c4234c9017a08798259ce25556a904a0da8f",
"withheld": {
"anything_withheld": true,
"note": "Facts outside this role’s remit were removed. That something was removed is stated so a partial record is never mistaken for a complete one. How much, and what, is not stated — a count is an inference about the part you are not entitled to see."
},
"view": {
"spec": "urn:ietf:params:corobate:receipt:1",
"receipt_version": "1.8",
"issued_at": "2026-08-08T16:00:00.000Z",
"decision": {
"id": "ai_TRIAGE_EVIDENCE_EXCLUDE_TAINTED_LINEAGE",
"subject": "ai-system:TRIAGE-ASSISTANT-V4",
"question": "May this quarter's vulnerability triage be accepted as the record of review?"
},
"memory": {
"state_digest": "sha256:2c0c2a47680fbf012f29aba9e9ea7a1e4292e0b41243cd158d904090723e6562",
"ledger_head": "sha256:666ec422cfa0a2aa3a0761bf5d34bc5eeb89079a0a37b9c86caf1f7e41c17603",
"coverage_gaps": [
"ai-system:TRIAGE-ASSISTANT-V4|vulnerability_triage_disposition"
]
},
"data_horizon": "2026-08-08T16:00:00.000Z",
"verdict": {
"value": "WITHHELD"
},
"regulatory": {
"spec": "corobate:regulatory:2",
"resolved": true,
"applied": [
{
"instrument_id": "enterprise-ai-evidence-standard",
"version": 1,
"authority": "Office of the Chief Information Security Officer",
"instrument": "Enterprise standard on machine-generated evidence",
"edition": "2026-03-01",
"citation": "§ 3 [VERIFY]",
"source_digest": "sha256:e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5",
"entered_by": "actor:human:issm",
"entered_at": "2026-08-08T16:00:00.000Z"
},
{
"instrument_id": "nist-sp-800-53r5-moderate",
"version": 5,
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
"edition": "Rev. 5",
"citation": "CA-2, CA-8, RA-5, SR-6 [VERIFY]",
"source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353",
"entered_by": "actor:human:issm",
"entered_at": "2026-08-08T16:00:00.000Z"
}
],
"skipped": [],
"conflicts": [],
"bindings": [
{
"claim": "control_assessment",
"requirement": "max_age_days",
"value": 365,
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
"instrument_id": "nist-sp-800-53r5-moderate",
"version": 5,
"edition": "Rev. 5",
"citation": "CA-2 [VERIFY]",
"source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "control_assessment",
"requirement": "min_class",
"value": "VERIFIED",
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
"instrument_id": "nist-sp-800-53r5-moderate",
"version": 5,
"edition": "Rev. 5",
"citation": "CA-2(1) independent assessors [VERIFY]",
"source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "control_assessment",
"requirement": "required",
"value": true,
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
"instrument_id": "nist-sp-800-53r5-moderate",
"version": 5,
"edition": "Rev. 5",
"citation": "CA-2 [VERIFY]",
"source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "penetration_test",
"requirement": "min_class",
"value": "VERIFIED",
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
"instrument_id": "nist-sp-800-53r5-moderate",
"version": 5,
"edition": "Rev. 5",
"citation": "CA-8(1) independent penetration agent [VERIFY]",
"source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "penetration_test",
"requirement": "required",
"value": true,
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
"instrument_id": "nist-sp-800-53r5-moderate",
"version": 5,
"edition": "Rev. 5",
"citation": "CA-8 [VERIFY]",
"source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "vulnerability_scan",
"requirement": "max_age_days",
"value": 30,
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
"instrument_id": "nist-sp-800-53r5-moderate",
"version": 5,
"edition": "Rev. 5",
"citation": "RA-5(a) [VERIFY]",
"source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "vulnerability_scan",
"requirement": "required",
"value": true,
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
"instrument_id": "nist-sp-800-53r5-moderate",
"version": 5,
"edition": "Rev. 5",
"citation": "RA-5 [VERIFY]",
"source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "vulnerability_triage_disposition",
"requirement": "ai_position",
"value": "EXCLUDE_TAINTED_LINEAGE",
"bound_by": {
"authority": "Office of the Chief Information Security Officer",
"instrument": "Enterprise standard on machine-generated evidence",
"instrument_id": "enterprise-ai-evidence-standard",
"version": 1,
"edition": "2026-03-01",
"citation": "§ 3.4 [VERIFY]",
"source_digest": "sha256:e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "vulnerability_triage_disposition",
"requirement": "required",
"value": true,
"bound_by": {
"authority": "Office of the Chief Information Security Officer",
"instrument": "Enterprise standard on machine-generated evidence",
"instrument_id": "enterprise-ai-evidence-standard",
"version": 1,
"edition": "2026-03-01",
"citation": "§ 3.1 [VERIFY]",
"source_digest": "sha256:e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
}
],
"defaults": [
{
"claim": "control_assessment",
"requirement": "ai_position",
"value": "ADMIT",
"because": "No instrument in force stated a position on AI-authored evidence for \"control_assessment\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
},
{
"claim": "penetration_test",
"requirement": "ai_position",
"value": "ADMIT",
"because": "No instrument in force stated a position on AI-authored evidence for \"penetration_test\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
},
{
"claim": "vulnerability_scan",
"requirement": "ai_position",
"value": "ADMIT",
"because": "No instrument in force stated a position on AI-authored evidence for \"vulnerability_scan\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
}
]
},
"inputs": [
{
"key": "ai-system:TRIAGE-ASSISTANT-V4::vulnerability_scan",
"provenance": "VERIFIED",
"source": "nvd-cve:vulnerability_scan",
"observed_at": "2026-08-04T16:00:00.000Z",
"critical": true,
"memory_status": "admitted",
"memory_actor": "actor:sys:registry:nvd-cve"
},
{
"key": "ai-system:TRIAGE-ASSISTANT-V4::penetration_test",
"provenance": "VERIFIED",
"source": "LAB-NVLAP-0412:penetration_test",
"observed_at": "2026-06-09T16:00:00.000Z",
"critical": true,
"memory_status": "admitted",
"memory_actor": "actor:org:LAB-NVLAP-0412"
},
{
"key": "ai-system:TRIAGE-ASSISTANT-V4::control_assessment",
"provenance": "VERIFIED",
"source": "CERT-3PAO-ATLANTIC:control_assessment",
"observed_at": "2026-04-30T16:00:00.000Z",
"critical": true,
"memory_status": "admitted",
"memory_actor": "actor:org:CERT-3PAO-ATLANTIC"
},
{
"key": "ai-system:TRIAGE-ASSISTANT-V4::vulnerability_triage_disposition",
"provenance": "MODELED",
"source": "triage-assistant-v4:vulnerability_triage_disposition",
"observed_at": "2026-08-05T16:00:00.000Z",
"critical": false,
"memory_status": "withheld",
"memory_actor": "actor:ai:triage-assistant-v4"
},
{
"key": "ai-system:TRIAGE-ASSISTANT-V4::vulnerability_triage_disposition",
"provenance": "MODELED",
"source": "receipt:sha256:d9b9ab69f8c703568004833df6b17024b3fe60322618d2a33283edb39a363bde",
"observed_at": "2026-08-08T16:00:00.000Z",
"critical": false,
"memory_status": "withheld",
"memory_actor": "actor:org:LAB-NVLAP-0412"
},
{
"key": "ai-system:TRIAGE-ASSISTANT-V4::vulnerability_triage_disposition",
"provenance": "MISSING",
"source": null,
"observed_at": "2026-08-08T16:00:00.000Z",
"critical": true,
"memory_status": "coverage_gap"
}
],
"crypto_suite": {
"spec": "corobate:suite:1",
"id": "CB-1-ES256-SHA256",
"receipt_digest": "sha256",
"chain_digest": "sha256",
"content_digest": "sha256",
"envelope_signature": "ES256",
"signature_curve": "P-256",
"canonicalisation": "attest-canon/2",
"quantum_resistant": false
}
}
}ISSM / control owner
The information system security manager and the control owners who hold the package.
The fullest internal view: every input, its class, its age, its score, the exposure, and every publication in force.
Every input the gate saw
| Claim | Required | Evidence class | Who | Age | Score | Outcome |
|---|---|---|---|---|---|---|
| vulnerability_scan | yes | VERIFIED | actor:sys:registry:nvd-cve | 4d | 95% | admitted |
| penetration_test | yes | VERIFIED | actor:org:LAB-NVLAP-0412 | 60d | 95% | admitted |
| control_assessment | yes | VERIFIED | actor:org:CERT-3PAO-ATLANTIC | 100d | 95% | admitted |
| vulnerability_triage_disposition | no | MODELED | actor:ai:triage-assistant-v4 | 3d | 80% | withheld |
| vulnerability_triage_disposition | no | MODELED | actor:org:LAB-NVLAP-0412 | 0d | 80% | withheld |
| vulnerability_triage_disposition | yes | MISSING | — | 2026-08-08 | 0% | coverage gap |
Instruments in force
Why
- Coverage gap: no admissible memory for required claim(s) ai-system:TRIAGE-ASSISTANT-V4|vulnerability_triage_disposition.
- Confidence 0.00% is bound by "ai-system:TRIAGE-ASSISTANT-V4|vulnerability_triage_disposition".
- 2 memories were withheld from the context block: ai-system:TRIAGE-ASSISTANT-V4|vulnerability_triage_disposition (AI-authored and excluded: the authority binding this claim does not accept model-authored evidence for it. Observed actor:ai:triage-assistant-v4 — a model, named as one in its own enrolled identity. Inadmissible at any reliability and any exposure. The remedy is to file this model's output under its OWN claim rather than under "ai-system:TRIAGE-ASSISTANT-V4|vulnerability_triage_disposition" — corroborating it does not help, because an identical value merges into this record and a different one contradicts it.); ai-system:TRIAGE-ASSISTANT-V4|vulnerability_triage_disposition (excluded on lineage: this record is a re-ingested receipt that itself rested on AI-authored evidence. The authority binding this claim excludes tainted lineage, which is what stops an exclusion being defeated by one round trip through a sealed receipt.).
- Thresholds for $250,000 exposure: approve 85%, caution 60%.
The scoped copy itself — partial — something outside this role’s remit was removed
{
"spec": "corobate:role-view:2",
"role": "COMPLIANCE",
"purpose": "The operator’s own compliance function. The fullest internal view: every gap, every instrument in force, the waivability of each requirement and who accepted what.",
"is_a_receipt": false,
"warning": "This is a SCOPED COPY of a sealed decision, not the decision record itself. It will not verify as a receipt and must not be presented as one. To confirm it is faithful, recompute its `view` digest under the same canonicalisation that produces receipt_hash and compare it with the entry for this role in the source receipt’s `views` block.",
"derived_from": {
"receipt_hash": "sha256:ee44fd0e4bc167b9c18e62720219425692aaedd851f997bc4c6971c79be02199",
"entry_hash": "sha256:2f26ad85cf44d0df56f007f3b09898161e93903b532e55d46b41823d233e9809",
"issued_at": "2026-08-08T16:00:00.000Z"
},
"view_digest": "sha256:62c98d9a202a5e5a1ca3772ff13c9f5985304602f80c6da58b5a4f58632d256b",
"withheld": {
"anything_withheld": true,
"note": "Facts outside this role’s remit were removed. That something was removed is stated so a partial record is never mistaken for a complete one. How much, and what, is not stated — a count is an inference about the part you are not entitled to see."
},
"view": {
"spec": "urn:ietf:params:corobate:receipt:1",
"receipt_version": "1.8",
"issued_at": "2026-08-08T16:00:00.000Z",
"decision": {
"id": "ai_TRIAGE_EVIDENCE_EXCLUDE_TAINTED_LINEAGE",
"domain": "supply-chain",
"subject": "ai-system:TRIAGE-ASSISTANT-V4",
"question": "May this quarter's vulnerability triage be accepted as the record of review?"
},
"memory": {
"state_digest": "sha256:2c0c2a47680fbf012f29aba9e9ea7a1e4292e0b41243cd158d904090723e6562",
"ledger_head": "sha256:666ec422cfa0a2aa3a0761bf5d34bc5eeb89079a0a37b9c86caf1f7e41c17603",
"coverage_gaps": [
"ai-system:TRIAGE-ASSISTANT-V4|vulnerability_triage_disposition"
],
"exposure": {
"usd": 250000,
"declared_by": "actor:human:issm",
"ledger_seq": 5
},
"policy_digest": "sha256:a6b69b7d20f7fb04d522364af1d92992058b04a5835fcec9d1c9f2261c7ef636"
},
"data_horizon": "2026-08-08T16:00:00.000Z",
"verdict": {
"value": "WITHHELD",
"threshold_approve": 0.85,
"threshold_caution": 0.6,
"rule": "confidence>=threshold"
},
"confidence": {
"value": 0,
"method": "min-over-critical-inputs",
"bound_by": "ai-system:TRIAGE-ASSISTANT-V4::vulnerability_triage_disposition"
},
"release": {
"required": false,
"required_by_tier": false,
"escalated_by_acceptance": false,
"risk_accepted": false,
"state": "WITHHELD_NO_EVIDENCE",
"code": "QUORUM_EVIDENCE_WITHHELD",
"reason": "the evidence did not clear the threshold for this exposure, so there is nothing to release. Signatures do not substitute for evidence, and this state is deliberately distinct from WITHHELD_PENDING_SIGNATURES: a reader must be able to tell \"the evidence is not there\" from \"the evidence is there and 0 of 2 people have signed\".",
"tier_floor_cents": 1000000000,
"exposure_usd_cents": 25000000,
"required_m": 2,
"declared_n": 3,
"floor_m": 2,
"distinct_signers": 0,
"superseded": 0,
"collapsed": 0,
"release_digest": "sha256:a3c837964666f08eab19f6d0645b630ecb8b87ace3c7b95b362ad7a02ed15846",
"governance_digest": "sha256:8b0a45a27fcce9c1c243c764e855e67c6fe6dfd7f02a563bd90809b419731905",
"governance_signed": true,
"counted_voices": [],
"signatures": [],
"ledger_seq": null
},
"acceptance": {
"state": "NONE",
"code": "ACCEPTANCE_NONE",
"reason": "no risk acceptance was presented for this decision. This is the ordinary case: a refusal is a refusal unless a named person has priced it.",
"permitted_basis": null,
"presented": 0,
"superseded": 0,
"expired": 0,
"gaps_not_covered": 0,
"coverage_gaps_in_force": [
"ai-system:TRIAGE-ASSISTANT-V4|vulnerability_triage_disposition"
],
"evidentiary_digest": "sha256:a3c837964666f08eab19f6d0645b630ecb8b87ace3c7b95b362ad7a02ed15846",
"margin_floor_bp": 100,
"authority_ceiling_cents": {
"SUPERVISOR": 1000000,
"MANAGER": 25000000,
"DIRECTOR": 500000000,
"OFFICER": 5000000000
},
"acceptances": [],
"escalated": false,
"live": false,
"ledger_seq": null
},
"regulatory": {
"spec": "corobate:regulatory:2",
"resolved": true,
"applied": [
{
"instrument_id": "enterprise-ai-evidence-standard",
"version": 1,
"authority": "Office of the Chief Information Security Officer",
"instrument": "Enterprise standard on machine-generated evidence",
"edition": "2026-03-01",
"citation": "§ 3 [VERIFY]",
"source_digest": "sha256:e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5",
"entered_by": "actor:human:issm",
"entered_at": "2026-08-08T16:00:00.000Z"
},
{
"instrument_id": "nist-sp-800-53r5-moderate",
"version": 5,
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
"edition": "Rev. 5",
"citation": "CA-2, CA-8, RA-5, SR-6 [VERIFY]",
"source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353",
"entered_by": "actor:human:issm",
"entered_at": "2026-08-08T16:00:00.000Z"
}
],
"skipped": [],
"conflicts": [],
"bindings": [
{
"claim": "control_assessment",
"requirement": "max_age_days",
"value": 365,
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
"instrument_id": "nist-sp-800-53r5-moderate",
"version": 5,
"edition": "Rev. 5",
"citation": "CA-2 [VERIFY]",
"source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "control_assessment",
"requirement": "min_class",
"value": "VERIFIED",
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
"instrument_id": "nist-sp-800-53r5-moderate",
"version": 5,
"edition": "Rev. 5",
"citation": "CA-2(1) independent assessors [VERIFY]",
"source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "control_assessment",
"requirement": "required",
"value": true,
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
"instrument_id": "nist-sp-800-53r5-moderate",
"version": 5,
"edition": "Rev. 5",
"citation": "CA-2 [VERIFY]",
"source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "penetration_test",
"requirement": "min_class",
"value": "VERIFIED",
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
"instrument_id": "nist-sp-800-53r5-moderate",
"version": 5,
"edition": "Rev. 5",
"citation": "CA-8(1) independent penetration agent [VERIFY]",
"source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "penetration_test",
"requirement": "required",
"value": true,
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
"instrument_id": "nist-sp-800-53r5-moderate",
"version": 5,
"edition": "Rev. 5",
"citation": "CA-8 [VERIFY]",
"source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "vulnerability_scan",
"requirement": "max_age_days",
"value": 30,
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
"instrument_id": "nist-sp-800-53r5-moderate",
"version": 5,
"edition": "Rev. 5",
"citation": "RA-5(a) [VERIFY]",
"source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "vulnerability_scan",
"requirement": "required",
"value": true,
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
"instrument_id": "nist-sp-800-53r5-moderate",
"version": 5,
"edition": "Rev. 5",
"citation": "RA-5 [VERIFY]",
"source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "vulnerability_triage_disposition",
"requirement": "ai_position",
"value": "EXCLUDE_TAINTED_LINEAGE",
"bound_by": {
"authority": "Office of the Chief Information Security Officer",
"instrument": "Enterprise standard on machine-generated evidence",
"instrument_id": "enterprise-ai-evidence-standard",
"version": 1,
"edition": "2026-03-01",
"citation": "§ 3.4 [VERIFY]",
"source_digest": "sha256:e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "vulnerability_triage_disposition",
"requirement": "required",
"value": true,
"bound_by": {
"authority": "Office of the Chief Information Security Officer",
"instrument": "Enterprise standard on machine-generated evidence",
"instrument_id": "enterprise-ai-evidence-standard",
"version": 1,
"edition": "2026-03-01",
"citation": "§ 3.1 [VERIFY]",
"source_digest": "sha256:e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
}
],
"defaults": [
{
"claim": "control_assessment",
"requirement": "ai_position",
"value": "ADMIT",
"because": "No instrument in force stated a position on AI-authored evidence for \"control_assessment\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
},
{
"claim": "penetration_test",
"requirement": "ai_position",
"value": "ADMIT",
"because": "No instrument in force stated a position on AI-authored evidence for \"penetration_test\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
},
{
"claim": "vulnerability_scan",
"requirement": "ai_position",
"value": "ADMIT",
"because": "No instrument in force stated a position on AI-authored evidence for \"vulnerability_scan\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
}
]
},
"reasons": [
"Coverage gap: no admissible memory for required claim(s) ai-system:TRIAGE-ASSISTANT-V4|vulnerability_triage_disposition.",
"Confidence 0.00% is bound by \"ai-system:TRIAGE-ASSISTANT-V4|vulnerability_triage_disposition\".",
"2 memories were withheld from the context block: ai-system:TRIAGE-ASSISTANT-V4|vulnerability_triage_disposition (AI-authored and excluded: the authority binding this claim does not accept model-authored evidence for it. Observed actor:ai:triage-assistant-v4 — a model, named as one in its own enrolled identity. Inadmissible at any reliability and any exposure. The remedy is to file this model's output under its OWN claim rather than under \"ai-system:TRIAGE-ASSISTANT-V4|vulnerability_triage_disposition\" — corroborating it does not help, because an identical value merges into this record and a different one contradicts it.); ai-system:TRIAGE-ASSISTANT-V4|vulnerability_triage_disposition (excluded on lineage: this record is a re-ingested receipt that itself rested on AI-authored evidence. The authority binding this claim excludes tainted lineage, which is what stops an exclusion being defeated by one round trip through a sealed receipt.).",
"Thresholds for $250,000 exposure: approve 85%, caution 60%."
],
"inputs": [
{
"key": "ai-system:TRIAGE-ASSISTANT-V4::vulnerability_scan",
"value": "clean-at-scan",
"provenance": "VERIFIED",
"source": "nvd-cve:vulnerability_scan",
"observed_at": "2026-08-04T16:00:00.000Z",
"reliability": 0.95,
"critical": true,
"memory_status": "admitted",
"memory_kind": "status",
"memory_actor": "actor:sys:registry:nvd-cve",
"memory_age_days": 4
},
{
"key": "ai-system:TRIAGE-ASSISTANT-V4::penetration_test",
"value": "no-critical",
"provenance": "VERIFIED",
"source": "LAB-NVLAP-0412:penetration_test",
"observed_at": "2026-06-09T16:00:00.000Z",
"reliability": 0.95,
"critical": true,
"memory_status": "admitted",
"memory_kind": "test_report",
"memory_actor": "actor:org:LAB-NVLAP-0412",
"memory_age_days": 60
},
{
"key": "ai-system:TRIAGE-ASSISTANT-V4::control_assessment",
"value": "satisfied",
"provenance": "VERIFIED",
"source": "CERT-3PAO-ATLANTIC:control_assessment",
"observed_at": "2026-04-30T16:00:00.000Z",
"reliability": 0.95,
"critical": true,
"memory_status": "admitted",
"memory_kind": "certificate",
"memory_actor": "actor:org:CERT-3PAO-ATLANTIC",
"memory_age_days": 100
},
{
"key": "ai-system:TRIAGE-ASSISTANT-V4::vulnerability_triage_disposition",
"value": null,
"provenance": "MODELED",
"source": "triage-assistant-v4:vulnerability_triage_disposition",
"observed_at": "2026-08-05T16:00:00.000Z",
"reliability": 0.8,
"critical": false,
"memory_status": "withheld",
"memory_kind": "status",
"memory_actor": "actor:ai:triage-assistant-v4",
"memory_age_days": 3
},
{
"key": "ai-system:TRIAGE-ASSISTANT-V4::vulnerability_triage_disposition",
"value": null,
"provenance": "MODELED",
"source": "receipt:sha256:d9b9ab69f8c703568004833df6b17024b3fe60322618d2a33283edb39a363bde",
"observed_at": "2026-08-08T16:00:00.000Z",
"reliability": 0.8,
"critical": false,
"memory_status": "withheld",
"memory_kind": "receipt",
"memory_actor": "actor:org:LAB-NVLAP-0412",
"memory_age_days": 0
},
{
"key": "ai-system:TRIAGE-ASSISTANT-V4::vulnerability_triage_disposition",
"value": null,
"provenance": "MISSING",
"source": null,
"observed_at": "2026-08-08T16:00:00.000Z",
"reliability": 0,
"critical": true,
"memory_status": "coverage_gap"
}
],
"crypto_suite": {
"spec": "corobate:suite:1",
"id": "CB-1-ES256-SHA256",
"receipt_digest": "sha256",
"chain_digest": "sha256",
"content_digest": "sha256",
"envelope_signature": "ES256",
"signature_curve": "P-256",
"canonicalisation": "attest-canon/2",
"quantum_resistant": false
}
}
}Authorising official (signer)
The named official whose signature carries the authorisation decision.
What is at stake, what the evidence supports, what is missing, and the digest they are signing over.
You are being asked to sign
May this quarter's vulnerability triage be accepted as the record of review?
The signature is over the STATE OF THE EVIDENCE. Move one fact behind this decision and the digest moves and the signature stops counting — which is what makes it safe to collect signatures before everyone is in the room.
What is missing
- vulnerability triage disposition
The scoped copy itself — partial — something outside this role’s remit was removed
{
"spec": "corobate:role-view:2",
"role": "EXECUTIVE",
"purpose": "A named signer on the release gate. Sees what is at stake, what the evidence supports, who else has signed and what they are being asked to sign over.",
"is_a_receipt": false,
"warning": "This is a SCOPED COPY of a sealed decision, not the decision record itself. It will not verify as a receipt and must not be presented as one. To confirm it is faithful, recompute its `view` digest under the same canonicalisation that produces receipt_hash and compare it with the entry for this role in the source receipt’s `views` block.",
"derived_from": {
"receipt_hash": "sha256:ee44fd0e4bc167b9c18e62720219425692aaedd851f997bc4c6971c79be02199",
"entry_hash": "sha256:2f26ad85cf44d0df56f007f3b09898161e93903b532e55d46b41823d233e9809",
"issued_at": "2026-08-08T16:00:00.000Z"
},
"view_digest": "sha256:93683f085f9b601edda076926b5049099229a5b34f246ddadb66d977254c9705",
"withheld": {
"anything_withheld": true,
"note": "Facts outside this role’s remit were removed. That something was removed is stated so a partial record is never mistaken for a complete one. How much, and what, is not stated — a count is an inference about the part you are not entitled to see."
},
"view": {
"spec": "urn:ietf:params:corobate:receipt:1",
"receipt_version": "1.8",
"issued_at": "2026-08-08T16:00:00.000Z",
"decision": {
"id": "ai_TRIAGE_EVIDENCE_EXCLUDE_TAINTED_LINEAGE",
"domain": "supply-chain",
"subject": "ai-system:TRIAGE-ASSISTANT-V4",
"question": "May this quarter's vulnerability triage be accepted as the record of review?"
},
"memory": {
"state_digest": "sha256:2c0c2a47680fbf012f29aba9e9ea7a1e4292e0b41243cd158d904090723e6562",
"ledger_head": "sha256:666ec422cfa0a2aa3a0761bf5d34bc5eeb89079a0a37b9c86caf1f7e41c17603",
"coverage_gaps": [
"ai-system:TRIAGE-ASSISTANT-V4|vulnerability_triage_disposition"
],
"exposure": {
"usd": 250000,
"declared_by": "actor:human:issm",
"ledger_seq": 5
}
},
"verdict": {
"value": "WITHHELD",
"threshold_approve": 0.85,
"threshold_caution": 0.6,
"rule": "confidence>=threshold"
},
"confidence": {
"value": 0,
"method": "min-over-critical-inputs",
"bound_by": "ai-system:TRIAGE-ASSISTANT-V4::vulnerability_triage_disposition"
},
"release": {
"required": false,
"required_by_tier": false,
"escalated_by_acceptance": false,
"risk_accepted": false,
"state": "WITHHELD_NO_EVIDENCE",
"code": "QUORUM_EVIDENCE_WITHHELD",
"reason": "the evidence did not clear the threshold for this exposure, so there is nothing to release. Signatures do not substitute for evidence, and this state is deliberately distinct from WITHHELD_PENDING_SIGNATURES: a reader must be able to tell \"the evidence is not there\" from \"the evidence is there and 0 of 2 people have signed\".",
"tier_floor_cents": 1000000000,
"exposure_usd_cents": 25000000,
"required_m": 2,
"declared_n": 3,
"floor_m": 2,
"distinct_signers": 0,
"superseded": 0,
"collapsed": 0,
"release_digest": "sha256:a3c837964666f08eab19f6d0645b630ecb8b87ace3c7b95b362ad7a02ed15846",
"governance_digest": "sha256:8b0a45a27fcce9c1c243c764e855e67c6fe6dfd7f02a563bd90809b419731905",
"governance_signed": true,
"counted_voices": [],
"signatures": [],
"ledger_seq": null
},
"acceptance": {
"state": "NONE",
"code": "ACCEPTANCE_NONE",
"reason": "no risk acceptance was presented for this decision. This is the ordinary case: a refusal is a refusal unless a named person has priced it.",
"permitted_basis": null,
"presented": 0,
"superseded": 0,
"expired": 0,
"gaps_not_covered": 0,
"coverage_gaps_in_force": [
"ai-system:TRIAGE-ASSISTANT-V4|vulnerability_triage_disposition"
],
"evidentiary_digest": "sha256:a3c837964666f08eab19f6d0645b630ecb8b87ace3c7b95b362ad7a02ed15846",
"margin_floor_bp": 100,
"authority_ceiling_cents": {
"SUPERVISOR": 1000000,
"MANAGER": 25000000,
"DIRECTOR": 500000000,
"OFFICER": 5000000000
},
"acceptances": [],
"escalated": false,
"live": false,
"ledger_seq": null
},
"reasons": [
"Coverage gap: no admissible memory for required claim(s) ai-system:TRIAGE-ASSISTANT-V4|vulnerability_triage_disposition.",
"Confidence 0.00% is bound by \"ai-system:TRIAGE-ASSISTANT-V4|vulnerability_triage_disposition\".",
"2 memories were withheld from the context block: ai-system:TRIAGE-ASSISTANT-V4|vulnerability_triage_disposition (AI-authored and excluded: the authority binding this claim does not accept model-authored evidence for it. Observed actor:ai:triage-assistant-v4 — a model, named as one in its own enrolled identity. Inadmissible at any reliability and any exposure. The remedy is to file this model's output under its OWN claim rather than under \"ai-system:TRIAGE-ASSISTANT-V4|vulnerability_triage_disposition\" — corroborating it does not help, because an identical value merges into this record and a different one contradicts it.); ai-system:TRIAGE-ASSISTANT-V4|vulnerability_triage_disposition (excluded on lineage: this record is a re-ingested receipt that itself rested on AI-authored evidence. The authority binding this claim excludes tainted lineage, which is what stops an exclusion being defeated by one round trip through a sealed receipt.).",
"Thresholds for $250,000 exposure: approve 85%, caution 60%."
],
"regulatory": {
"applied": [
{
"instrument_id": "enterprise-ai-evidence-standard",
"version": 1,
"authority": "Office of the Chief Information Security Officer",
"instrument": "Enterprise standard on machine-generated evidence",
"edition": "2026-03-01",
"citation": "§ 3 [VERIFY]",
"source_digest": "sha256:e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5",
"entered_by": "actor:human:issm",
"entered_at": "2026-08-08T16:00:00.000Z"
},
{
"instrument_id": "nist-sp-800-53r5-moderate",
"version": 5,
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
"edition": "Rev. 5",
"citation": "CA-2, CA-8, RA-5, SR-6 [VERIFY]",
"source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353",
"entered_by": "actor:human:issm",
"entered_at": "2026-08-08T16:00:00.000Z"
}
],
"conflicts": [],
"defaults": [
{
"claim": "control_assessment",
"requirement": "ai_position",
"value": "ADMIT",
"because": "No instrument in force stated a position on AI-authored evidence for \"control_assessment\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
},
{
"claim": "penetration_test",
"requirement": "ai_position",
"value": "ADMIT",
"because": "No instrument in force stated a position on AI-authored evidence for \"penetration_test\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
},
{
"claim": "vulnerability_scan",
"requirement": "ai_position",
"value": "ADMIT",
"because": "No instrument in force stated a position on AI-authored evidence for \"vulnerability_scan\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
}
]
},
"inputs": [
{
"key": "ai-system:TRIAGE-ASSISTANT-V4::vulnerability_scan",
"provenance": "VERIFIED",
"reliability": 0.95,
"critical": true,
"memory_status": "admitted"
},
{
"key": "ai-system:TRIAGE-ASSISTANT-V4::penetration_test",
"provenance": "VERIFIED",
"reliability": 0.95,
"critical": true,
"memory_status": "admitted"
},
{
"key": "ai-system:TRIAGE-ASSISTANT-V4::control_assessment",
"provenance": "VERIFIED",
"reliability": 0.95,
"critical": true,
"memory_status": "admitted"
},
{
"key": "ai-system:TRIAGE-ASSISTANT-V4::vulnerability_triage_disposition",
"provenance": "MODELED",
"reliability": 0.8,
"critical": false,
"memory_status": "withheld"
},
{
"key": "ai-system:TRIAGE-ASSISTANT-V4::vulnerability_triage_disposition",
"provenance": "MODELED",
"reliability": 0.8,
"critical": false,
"memory_status": "withheld"
},
{
"key": "ai-system:TRIAGE-ASSISTANT-V4::vulnerability_triage_disposition",
"provenance": "MISSING",
"reliability": 0,
"critical": true,
"memory_status": "coverage_gap"
}
]
}
}Independent audit / IG
Internal audit, an inspector general, or an external auditor testing the programme.
Everything, plus the verifier’s own findings over the sealed record.
This view withholds nothing. What it adds is the 22 checks the published verifier ran over the sealed record behind every other view of this decision — recomputed at build time, not asserted.
| # | Check | Detail | |
|---|---|---|---|
| 1 | Content reproduces (JCS + SHA-256) | PASS | matches sha256:ee44fd0e4bc167b9c18e62720219425692aaedd851f997bc4c6971c79be02199 |
| 2 | Hash chain links (entry = H(prev||content)) | PASS | head sha256:2f26ad85cf44d0df56f007f3b09898161e93903b532e55d46b41823d233e9809 |
| 3 | Confidence gated by weakest critical input | PASS | min over critical = 0, bound_by ai-system:TRIAGE-ASSISTANT-V4::vulnerability_triage_disposition (MISSING) |
| 3b | Verdict follows the threshold rule | PASS | 0 => WITHHELD; recorded WITHHELD |
| 4 | Point-in-time seal (no input past data_horizon) | PASS | all inputs <= 2026-08-08T16:00:00.000Z |
| 5 | Anchor covers the head, and the timestamp token re-reads | PASS | internally consistent; NO external anchor was requested — this is not a validated timestamp |
| 6 | Criteria travel with the receipt and reproduce | PASS | policy_body hashes to sha256:a6b69b7d20f7fb04d522364af1d92992058b04a5835fcec9d1c9f2261c7ef636 |
| 7 | Reliability re-derives from recorded evidence | PASS | all 6 inputs re-derive exactly |
| 8 | Outcome trials and lineage discounts re-derive | PASS | 5 input(s) re-derive: 0 credited outcome trial(s), 0 lineage-discounted corroboration(s); every reliability is at or under its class ceiling |
| 9 | Re-ingested receipts respect their weakest-input ceiling | PASS | no re-ingested receipt was ADMITTED: every input this decision rests on is a primary observation, and 1 cited receipt(s) were refused |
| 10 | Release quorum re-derives | PASS | WITHHELD_NO_EVIDENCE - below the top exposure tier, no multi-party requirement applies |
| 11 | Risk acceptance re-derives | PASS | no risk acceptance: this decision stands or falls on its evidence |
| 12 | Observer credentials were not revoked as of observation time | PASS | revocation list 5 (0 entries, issued 2026-08-06T00:00:00.000Z, next update due 2026-08-13T00:00:00.000Z) reproduces; 5 observer signature(s) judged as of their own instant, none under a key revoked as compromised or retired by then |
| 13 | The cryptographic suite is named and is one this verifier implements | PASS | sealed under CB-1-ES256-SHA256 (ES256 / sha256, attest-canon/2); this verifier implements it; the suite states it is NOT quantum resistant |
| 14 | Regulatory bindings are attributed and were enforced | PASS | 9 binding(s) from 2 instrument(s) in force, each attributed to an authority, a citation and a document digest; 4 required claim(s) all reached the gate |
| 15 | Role-view commitments re-derive, and the customs view carries no money | PASS | 6 role-view commitment(s) re-derived from this receipt’s own body by this verifier’s independent projection; the REGULATOR view carries no commercial figure |
| 16 | AI-authored input was admitted only where an authority allowed it | PASS | 1 claim(s) carry a position on AI-authored evidence set by an authority and 3 carry a recorded default nobody set; 0 exclusion(s) and 0 corroboration-only rule(s) re-derived against this receipt's own admitted inputs; 0 admitted input(s) are AI-authored by their enrolled identity |
| 17 | State digest recomputes from the ledger alone | UNVERIFIABLE | NOT APPLICABLE — you supplied no ledger, so the state digest cannot be re-derived from anything. This receipt commits to the corpus the deciding system held at the instant it sealed, and that commitment is checked by recomputing it from the append-only ledger and comparing; with no ledger in hand there is no second artefact to recompute from. The receipt is not at fault and nothing here is missing from it. Obtain the ledger from the issuer and re-run with --ledger <file>, or verifyReceipt(r, {ledger}). Nothing here has failed and nothing here has passed. |
| 18 | Registry membership re-derives for every key relied on | PASS | all 4 key(s) relied on re-derive to the entries root registry v3 committed to and the trust root signed |
| 20 | Geometric support re-derives, and an unevaluated record is not a supported one | PASS | no authority bound a metric to any claim on this receipt, so no geometric test applied. A claim nobody bound a metric to is not a claim about geometry, and this is a stated absence rather than a silent one |
| 19 | The cause of every uncovered requirement re-derives | PASS | all 1 uncovered requirement(s) re-derive their cause from this receipt's own rows. What notice is ADEQUATE is not decided here: this check establishes what the record says and that the record agrees with itself. |
| 21 | The sealing party is the one you were told to expect | UNVERIFIABLE | NOT APPLICABLE — you supplied no trust bundle, so nothing here establishes who sealed this. Identities 1 to 20 prove that this document agrees with itself; not one of them asks whose trust root it was sealed under, and a document that agrees with itself about a decision nobody made agrees with itself perfectly. Obtain the issuer's corobate:trust-bundle:1 out of band, confirm its spoken fingerprint with them by voice, and re-run with --trust-bundle <file> --expect-fingerprint <what you heard>. Nothing here has failed and nothing here has passed. |
The scoped copy itself — complete for this role
{
"spec": "corobate:role-view:2",
"role": "AUDITOR",
"purpose": "An external assessor. Sees the complete sealed record: this view withholds nothing and exists so the identity case is a case rather than an exception.",
"is_a_receipt": false,
"warning": "This is a SCOPED COPY of a sealed decision, not the decision record itself. It will not verify as a receipt and must not be presented as one. To confirm it is faithful, recompute its `view` digest under the same canonicalisation that produces receipt_hash and compare it with the entry for this role in the source receipt’s `views` block.",
"derived_from": {
"receipt_hash": "sha256:ee44fd0e4bc167b9c18e62720219425692aaedd851f997bc4c6971c79be02199",
"entry_hash": "sha256:2f26ad85cf44d0df56f007f3b09898161e93903b532e55d46b41823d233e9809",
"issued_at": "2026-08-08T16:00:00.000Z"
},
"view_digest": "sha256:c639193ba2a2b100899de6b43ccd708f69f1fdfc8f4e02c369a7dbae8a0afadd",
"withheld": {
"anything_withheld": false,
"note": "Nothing outside the seal was removed for this role."
},
"view": {
"spec": "urn:ietf:params:corobate:receipt:1",
"receipt_version": "1.8",
"engine": {
"name": "corobate-memory",
"version": "1.0.0"
},
"decision": {
"id": "ai_TRIAGE_EVIDENCE_EXCLUDE_TAINTED_LINEAGE",
"domain": "supply-chain",
"subject": "ai-system:TRIAGE-ASSISTANT-V4",
"question": "May this quarter's vulnerability triage be accepted as the record of review?"
},
"issued_at": "2026-08-08T16:00:00.000Z",
"data_horizon": "2026-08-08T16:00:00.000Z",
"inputs": [
{
"key": "ai-system:TRIAGE-ASSISTANT-V4::vulnerability_scan",
"value": "clean-at-scan",
"provenance": "VERIFIED",
"source": "nvd-cve:vulnerability_scan",
"observed_at": "2026-08-04T16:00:00.000Z",
"last_corroborated_at": null,
"memory_refreshed_by": [],
"reliability": 0.95,
"critical": true,
"memory_id": "mem_4d2b1fc0d322",
"memory_status": "admitted",
"memory_kind": "status",
"memory_actor": "actor:sys:registry:nvd-cve",
"memory_age_days": 4,
"memory_track": {
"n": 1,
"successes": 1
},
"memory_promoted_by": [],
"memory_content_digest": "sha256:aea4c3860d57b3edd045cd33946015c41ff1aee9cc8a4df49f26d8a5165d4a38",
"memory_outcomes": {
"verified": 0,
"falsified": 0,
"modified": 0,
"counted": 0,
"recorded": 0
},
"memory_outcome_attestations": [],
"memory_observer_lineage": null,
"memory_corroborations": [],
"memory_reingest": null,
"memory_reasons": [
"sparse track record: 1 independent observation(s); no failure recorded, so the class ceiling stands"
],
"memory_class_floor": null,
"memory_below_class_floor": false,
"memory_not_attested": false,
"memory_below_claim_reliability_floor": false,
"memory_not_competent_authority": false,
"memory_out_of_specification": false,
"memory_ai_authored": false,
"memory_ai_in_lineage": false,
"memory_ai_position": "ADMIT",
"memory_ai_inadmissible": false,
"memory_geo_inadmissible": false,
"memory_geo_rung": null,
"memory_geo_metric": null,
"memory_geo_required_metric": null,
"observer_attested": true,
"observer_auth_code": "VERIFIED",
"observer_key_id": "k_5873dd9e7169def3",
"attestation": null,
"derivation": {
"provenance": "VERIFIED",
"ceiling_bp": 9500,
"track": {
"n": 1,
"successes": 1
},
"wilson_bp": null,
"age_days": 4,
"max_age_days": 14,
"house_max_age_days": 14,
"instrument_max_age_days": 30,
"freshness_cap_bp": 4000,
"min_track_n": 5,
"wilson_z_milli": 1960,
"source_present": true,
"seller_asserted_cap_bp": 5000,
"retracted": false,
"contradicted": false,
"outcome_trials": 0,
"outcomes": {
"verified": 0,
"falsified": 0,
"modified": 0,
"counted": 0,
"recorded": 0
},
"corroborations_counted": 0,
"corroborations_discounted": 0,
"reingest_ceiling_bp": null,
"reingest_depth": null,
"reingest_weakest_class": null,
"reingest_source_confidence_bp": null,
"ai_authored": false,
"ai_authored_because": null,
"ai_in_lineage": false,
"ai_position": "ADMIT"
},
"memory_reason_codes": [
{
"code": "SPARSE_TRACK_RECORD",
"observed": 1,
"limit": 5,
"binding": false
}
],
"context_line": "[VERIFIED · r=95.0% · 4d · nvd-cve:vulnerability_scan] ai-system:TRIAGE-ASSISTANT-V4 / vulnerability_scan: clean-at-scan"
},
{
"key": "ai-system:TRIAGE-ASSISTANT-V4::penetration_test",
"value": "no-critical",
"provenance": "VERIFIED",
"source": "LAB-NVLAP-0412:penetration_test",
"observed_at": "2026-06-09T16:00:00.000Z",
"last_corroborated_at": null,
"memory_refreshed_by": [],
"reliability": 0.95,
"critical": true,
"memory_id": "mem_a3316d633bfe",
"memory_status": "admitted",
"memory_kind": "test_report",
"memory_actor": "actor:org:LAB-NVLAP-0412",
"memory_age_days": 60,
"memory_track": {
"n": 1,
"successes": 1
},
"memory_promoted_by": [],
"memory_content_digest": "sha256:db69fb062be9b066b370c668281e12896da2869456a2e6d356a0f14879b27de9",
"memory_outcomes": {
"verified": 0,
"falsified": 0,
"modified": 0,
"counted": 0,
"recorded": 0
},
"memory_outcome_attestations": [],
"memory_observer_lineage": null,
"memory_corroborations": [],
"memory_reingest": null,
"memory_reasons": [
"sparse track record: 1 independent observation(s); no failure recorded, so the class ceiling stands"
],
"memory_class_floor": "VERIFIED",
"memory_below_class_floor": false,
"memory_not_attested": false,
"memory_below_claim_reliability_floor": false,
"memory_not_competent_authority": false,
"memory_out_of_specification": false,
"memory_ai_authored": false,
"memory_ai_in_lineage": false,
"memory_ai_position": "ADMIT",
"memory_ai_inadmissible": false,
"memory_geo_inadmissible": false,
"memory_geo_rung": null,
"memory_geo_metric": null,
"memory_geo_required_metric": null,
"observer_attested": true,
"observer_auth_code": "VERIFIED",
"observer_key_id": "k_17d23885943ae529",
"attestation": null,
"derivation": {
"provenance": "VERIFIED",
"ceiling_bp": 9500,
"track": {
"n": 1,
"successes": 1
},
"wilson_bp": null,
"age_days": 60,
"max_age_days": 180,
"house_max_age_days": 180,
"instrument_max_age_days": null,
"freshness_cap_bp": 4000,
"min_track_n": 5,
"wilson_z_milli": 1960,
"source_present": true,
"seller_asserted_cap_bp": 5000,
"retracted": false,
"contradicted": false,
"outcome_trials": 0,
"outcomes": {
"verified": 0,
"falsified": 0,
"modified": 0,
"counted": 0,
"recorded": 0
},
"corroborations_counted": 0,
"corroborations_discounted": 0,
"reingest_ceiling_bp": null,
"reingest_depth": null,
"reingest_weakest_class": null,
"reingest_source_confidence_bp": null,
"min_class_floor": "VERIFIED",
"ai_authored": false,
"ai_authored_because": null,
"ai_in_lineage": false,
"ai_position": "ADMIT"
},
"memory_reason_codes": [
{
"code": "SPARSE_TRACK_RECORD",
"observed": 1,
"limit": 5,
"binding": false
}
],
"context_line": "[VERIFIED · r=95.0% · 60d · LAB-NVLAP-0412:penetration_test] ai-system:TRIAGE-ASSISTANT-V4 / penetration_test: no-critical"
},
{
"key": "ai-system:TRIAGE-ASSISTANT-V4::control_assessment",
"value": "satisfied",
"provenance": "VERIFIED",
"source": "CERT-3PAO-ATLANTIC:control_assessment",
"observed_at": "2026-04-30T16:00:00.000Z",
"last_corroborated_at": null,
"memory_refreshed_by": [],
"reliability": 0.95,
"critical": true,
"memory_id": "mem_a153eb336060",
"memory_status": "admitted",
"memory_kind": "certificate",
"memory_actor": "actor:org:CERT-3PAO-ATLANTIC",
"memory_age_days": 100,
"memory_track": {
"n": 1,
"successes": 1
},
"memory_promoted_by": [],
"memory_content_digest": "sha256:c1aaf46a55b4cdc629a754ac35da1b8ec4dec85c2c78613c7bc93546b63f233c",
"memory_outcomes": {
"verified": 0,
"falsified": 0,
"modified": 0,
"counted": 0,
"recorded": 0
},
"memory_outcome_attestations": [],
"memory_observer_lineage": null,
"memory_corroborations": [],
"memory_reingest": null,
"memory_reasons": [
"sparse track record: 1 independent observation(s); no failure recorded, so the class ceiling stands"
],
"memory_class_floor": "VERIFIED",
"memory_below_class_floor": false,
"memory_not_attested": false,
"memory_below_claim_reliability_floor": false,
"memory_not_competent_authority": false,
"memory_out_of_specification": false,
"memory_ai_authored": false,
"memory_ai_in_lineage": false,
"memory_ai_position": "ADMIT",
"memory_ai_inadmissible": false,
"memory_geo_inadmissible": false,
"memory_geo_rung": null,
"memory_geo_metric": null,
"memory_geo_required_metric": null,
"observer_attested": true,
"observer_auth_code": "VERIFIED",
"observer_key_id": "k_307e4bfd710ec9b3",
"attestation": null,
"derivation": {
"provenance": "VERIFIED",
"ceiling_bp": 9500,
"track": {
"n": 1,
"successes": 1
},
"wilson_bp": null,
"age_days": 100,
"max_age_days": 365,
"house_max_age_days": 365,
"instrument_max_age_days": 365,
"freshness_cap_bp": 4000,
"min_track_n": 5,
"wilson_z_milli": 1960,
"source_present": true,
"seller_asserted_cap_bp": 5000,
"retracted": false,
"contradicted": false,
"outcome_trials": 0,
"outcomes": {
"verified": 0,
"falsified": 0,
"modified": 0,
"counted": 0,
"recorded": 0
},
"corroborations_counted": 0,
"corroborations_discounted": 0,
"reingest_ceiling_bp": null,
"reingest_depth": null,
"reingest_weakest_class": null,
"reingest_source_confidence_bp": null,
"min_class_floor": "VERIFIED",
"ai_authored": false,
"ai_authored_because": null,
"ai_in_lineage": false,
"ai_position": "ADMIT"
},
"memory_reason_codes": [
{
"code": "SPARSE_TRACK_RECORD",
"observed": 1,
"limit": 5,
"binding": false
}
],
"context_line": "[VERIFIED · r=95.0% · 100d · CERT-3PAO-ATLANTIC:control_assessment] ai-system:TRIAGE-ASSISTANT-V4 / control_assessment: satisfied"
},
{
"key": "ai-system:TRIAGE-ASSISTANT-V4::vulnerability_triage_disposition",
"value": null,
"provenance": "MODELED",
"source": "triage-assistant-v4:vulnerability_triage_disposition",
"observed_at": "2026-08-05T16:00:00.000Z",
"last_corroborated_at": null,
"memory_refreshed_by": [],
"reliability": 0.8,
"critical": false,
"memory_id": "mem_0a6980bbce9f",
"memory_status": "withheld",
"memory_kind": "status",
"memory_actor": "actor:ai:triage-assistant-v4",
"memory_age_days": 3,
"memory_track": {
"n": 1,
"successes": 1
},
"memory_promoted_by": [],
"memory_content_digest": "sha256:612e098189acf7652c237b016c3537b38c17d735452f4f1d519c6bfa0772b2c2",
"memory_outcomes": {
"verified": 0,
"falsified": 0,
"modified": 0,
"counted": 0,
"recorded": 0
},
"memory_outcome_attestations": [],
"memory_observer_lineage": null,
"memory_corroborations": [],
"memory_reingest": null,
"memory_reasons": [
"AI-authored and excluded: the authority binding this claim does not accept model-authored evidence for it. Observed actor:ai:triage-assistant-v4 — a model, named as one in its own enrolled identity. Inadmissible at any reliability and any exposure. The remedy is to file this model's output under its OWN claim rather than under \"ai-system:TRIAGE-ASSISTANT-V4|vulnerability_triage_disposition\" — corroborating it does not help, because an identical value merges into this record and a different one contradicts it.",
"sparse track record: 1 independent observation(s); no failure recorded, so the class ceiling stands"
],
"memory_class_floor": null,
"memory_below_class_floor": false,
"memory_not_attested": false,
"memory_below_claim_reliability_floor": false,
"memory_not_competent_authority": false,
"memory_out_of_specification": false,
"memory_ai_authored": true,
"memory_ai_in_lineage": false,
"memory_ai_position": "EXCLUDE_TAINTED_LINEAGE",
"memory_ai_inadmissible": true,
"memory_geo_inadmissible": false,
"memory_geo_rung": null,
"memory_geo_metric": null,
"memory_geo_required_metric": null,
"observer_attested": true,
"observer_auth_code": "VERIFIED",
"observer_key_id": "k_f71bde46a9680d8d",
"attestation": null,
"derivation": {
"provenance": "MODELED",
"ceiling_bp": 8000,
"track": {
"n": 1,
"successes": 1
},
"wilson_bp": null,
"age_days": 3,
"max_age_days": 14,
"house_max_age_days": 14,
"instrument_max_age_days": null,
"freshness_cap_bp": 4000,
"min_track_n": 5,
"wilson_z_milli": 1960,
"source_present": true,
"seller_asserted_cap_bp": 5000,
"retracted": false,
"contradicted": false,
"outcome_trials": 0,
"outcomes": {
"verified": 0,
"falsified": 0,
"modified": 0,
"counted": 0,
"recorded": 0
},
"corroborations_counted": 0,
"corroborations_discounted": 0,
"reingest_ceiling_bp": null,
"reingest_depth": null,
"reingest_weakest_class": null,
"reingest_source_confidence_bp": null,
"ai_authored": true,
"ai_authored_because": "a model, named as one in its own enrolled identity",
"ai_in_lineage": false,
"ai_position": "EXCLUDE_TAINTED_LINEAGE"
},
"memory_reason_codes": [
{
"code": "AI_AUTHORED_EXCLUDED",
"observed": "actor:ai:triage-assistant-v4",
"limit": "EXCLUDE_TAINTED_LINEAGE",
"binding": true
},
{
"code": "SPARSE_TRACK_RECORD",
"observed": 1,
"limit": 5,
"binding": false
}
]
},
{
"key": "ai-system:TRIAGE-ASSISTANT-V4::vulnerability_triage_disposition",
"value": null,
"provenance": "MODELED",
"source": "receipt:sha256:d9b9ab69f8c703568004833df6b17024b3fe60322618d2a33283edb39a363bde",
"observed_at": "2026-08-08T16:00:00.000Z",
"last_corroborated_at": null,
"memory_refreshed_by": [],
"reliability": 0.8,
"critical": false,
"memory_id": "mem_d84b950b487d",
"memory_status": "withheld",
"memory_kind": "receipt",
"memory_actor": "actor:org:LAB-NVLAP-0412",
"memory_age_days": 0,
"memory_track": {
"n": 1,
"successes": 1
},
"memory_promoted_by": [],
"memory_content_digest": "sha256:eb81e6a83d92e0175d5a21e45a29e0cc3dd88c07c53bfe3be082f0665aac8a77",
"memory_outcomes": {
"verified": 0,
"falsified": 0,
"modified": 0,
"counted": 0,
"recorded": 0
},
"memory_outcome_attestations": [],
"memory_observer_lineage": null,
"memory_corroborations": [],
"memory_reingest": {
"source_receipt_hash": "sha256:d9b9ab69f8c703568004833df6b17024b3fe60322618d2a33283edb39a363bde",
"source_decision_id": "ai_TRIAGE_EARLIER_CYCLE",
"source_verdict": "CAUTION",
"source_confidence_bp": 8000,
"weakest_key": "ai-system:TRIAGE-ASSISTANT-V4::vulnerability_triage_disposition",
"weakest_class": "MODELED",
"weakest_bp": 8000,
"class_ceiling_bp": 8000,
"inherited_chain_weakest_bp": 10000,
"ai_in_lineage": true,
"ai_lineage_actors": [
"actor:ai:triage-assistant-v4"
],
"ceiling_bp": 8000,
"depth": 1,
"max_depth": 3,
"chain": [
"sha256:d9b9ab69f8c703568004833df6b17024b3fe60322618d2a33283edb39a363bde"
],
"presenter": "actor:org:LAB-NVLAP-0412",
"verification_checks": 22,
"verification_passed": 20
},
"memory_reasons": [
"excluded on lineage: this record is a re-ingested receipt that itself rested on AI-authored evidence. The authority binding this claim excludes tainted lineage, which is what stops an exclusion being defeated by one round trip through a sealed receipt.",
"sparse track record: 1 independent observation(s); no failure recorded, so the class ceiling stands"
],
"memory_class_floor": null,
"memory_below_class_floor": false,
"memory_not_attested": false,
"memory_below_claim_reliability_floor": false,
"memory_not_competent_authority": false,
"memory_out_of_specification": false,
"memory_ai_authored": false,
"memory_ai_in_lineage": true,
"memory_ai_position": "EXCLUDE_TAINTED_LINEAGE",
"memory_ai_inadmissible": true,
"memory_geo_inadmissible": false,
"memory_geo_rung": null,
"memory_geo_metric": null,
"memory_geo_required_metric": null,
"observer_attested": true,
"observer_auth_code": "VERIFIED",
"observer_key_id": "k_17d23885943ae529",
"attestation": null,
"derivation": {
"provenance": "MODELED",
"ceiling_bp": 8000,
"track": {
"n": 1,
"successes": 1
},
"wilson_bp": null,
"age_days": 0,
"max_age_days": 365,
"house_max_age_days": 365,
"instrument_max_age_days": null,
"freshness_cap_bp": 4000,
"min_track_n": 5,
"wilson_z_milli": 1960,
"source_present": true,
"seller_asserted_cap_bp": 5000,
"retracted": false,
"contradicted": false,
"outcome_trials": 0,
"outcomes": {
"verified": 0,
"falsified": 0,
"modified": 0,
"counted": 0,
"recorded": 0
},
"corroborations_counted": 0,
"corroborations_discounted": 0,
"reingest_ceiling_bp": 8000,
"reingest_depth": 1,
"reingest_weakest_class": "MODELED",
"reingest_source_confidence_bp": 8000,
"ai_authored": false,
"ai_authored_because": null,
"ai_in_lineage": true,
"ai_position": "EXCLUDE_TAINTED_LINEAGE"
},
"memory_reason_codes": [
{
"code": "AI_LINEAGE_EXCLUDED",
"observed": "sha256:d9b9ab69f8c703568004833df6b17024b3fe60322618d2a33283edb39a363bde",
"limit": "EXCLUDE_TAINTED_LINEAGE",
"binding": true
},
{
"code": "SPARSE_TRACK_RECORD",
"observed": 1,
"limit": 5,
"binding": false
}
]
},
{
"key": "ai-system:TRIAGE-ASSISTANT-V4::vulnerability_triage_disposition",
"value": null,
"provenance": "MISSING",
"source": null,
"observed_at": "2026-08-08T16:00:00.000Z",
"reliability": 0,
"critical": true,
"memory_status": "coverage_gap",
"gap_cause": "EVIDENCE_PRESENTED_FAILED",
"gap_request": null,
"gap_origin": "BUSINESS_EVIDENCE",
"gap_conditions": [
"ai_inadmissible"
]
}
],
"serialization": {
"algorithm": "RFC8785-JCS",
"hash": "sha256"
},
"crypto_suite": {
"spec": "corobate:suite:1",
"id": "CB-1-ES256-SHA256",
"receipt_digest": "sha256",
"chain_digest": "sha256",
"content_digest": "sha256",
"envelope_signature": "ES256",
"signature_curve": "P-256",
"canonicalisation": "attest-canon/2",
"quantum_resistant": false
},
"confidence": {
"value": 0,
"method": "min-over-critical-inputs",
"bound_by": "ai-system:TRIAGE-ASSISTANT-V4::vulnerability_triage_disposition"
},
"verdict": {
"value": "WITHHELD",
"threshold_approve": 0.85,
"threshold_caution": 0.6,
"rule": "confidence>=threshold"
},
"release": {
"required": false,
"required_by_tier": false,
"escalated_by_acceptance": false,
"risk_accepted": false,
"state": "WITHHELD_NO_EVIDENCE",
"code": "QUORUM_EVIDENCE_WITHHELD",
"reason": "the evidence did not clear the threshold for this exposure, so there is nothing to release. Signatures do not substitute for evidence, and this state is deliberately distinct from WITHHELD_PENDING_SIGNATURES: a reader must be able to tell \"the evidence is not there\" from \"the evidence is there and 0 of 2 people have signed\".",
"tier_floor_cents": 1000000000,
"exposure_usd_cents": 25000000,
"required_m": 2,
"declared_n": 3,
"floor_m": 2,
"distinct_signers": 0,
"superseded": 0,
"collapsed": 0,
"release_digest": "sha256:a3c837964666f08eab19f6d0645b630ecb8b87ace3c7b95b362ad7a02ed15846",
"governance_digest": "sha256:8b0a45a27fcce9c1c243c764e855e67c6fe6dfd7f02a563bd90809b419731905",
"governance_signed": true,
"counted_voices": [],
"signatures": [],
"ledger_seq": null
},
"acceptance": {
"state": "NONE",
"code": "ACCEPTANCE_NONE",
"reason": "no risk acceptance was presented for this decision. This is the ordinary case: a refusal is a refusal unless a named person has priced it.",
"permitted_basis": null,
"presented": 0,
"superseded": 0,
"expired": 0,
"gaps_not_covered": 0,
"coverage_gaps_in_force": [
"ai-system:TRIAGE-ASSISTANT-V4|vulnerability_triage_disposition"
],
"evidentiary_digest": "sha256:a3c837964666f08eab19f6d0645b630ecb8b87ace3c7b95b362ad7a02ed15846",
"margin_floor_bp": 100,
"authority_ceiling_cents": {
"SUPERVISOR": 1000000,
"MANAGER": 25000000,
"DIRECTOR": 500000000,
"OFFICER": 5000000000
},
"acceptances": [],
"escalated": false,
"live": false,
"ledger_seq": null
},
"regulatory": {
"spec": "corobate:regulatory:2",
"resolved": true,
"applied": [
{
"instrument_id": "enterprise-ai-evidence-standard",
"version": 1,
"authority": "Office of the Chief Information Security Officer",
"instrument": "Enterprise standard on machine-generated evidence",
"edition": "2026-03-01",
"citation": "§ 3 [VERIFY]",
"source_digest": "sha256:e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5",
"entered_by": "actor:human:issm",
"entered_at": "2026-08-08T16:00:00.000Z"
},
{
"instrument_id": "nist-sp-800-53r5-moderate",
"version": 5,
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
"edition": "Rev. 5",
"citation": "CA-2, CA-8, RA-5, SR-6 [VERIFY]",
"source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353",
"entered_by": "actor:human:issm",
"entered_at": "2026-08-08T16:00:00.000Z"
}
],
"skipped": [],
"conflicts": [],
"bindings": [
{
"claim": "control_assessment",
"requirement": "max_age_days",
"value": 365,
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
"instrument_id": "nist-sp-800-53r5-moderate",
"version": 5,
"edition": "Rev. 5",
"citation": "CA-2 [VERIFY]",
"source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "control_assessment",
"requirement": "min_class",
"value": "VERIFIED",
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
"instrument_id": "nist-sp-800-53r5-moderate",
"version": 5,
"edition": "Rev. 5",
"citation": "CA-2(1) independent assessors [VERIFY]",
"source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "control_assessment",
"requirement": "required",
"value": true,
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
"instrument_id": "nist-sp-800-53r5-moderate",
"version": 5,
"edition": "Rev. 5",
"citation": "CA-2 [VERIFY]",
"source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "penetration_test",
"requirement": "min_class",
"value": "VERIFIED",
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
"instrument_id": "nist-sp-800-53r5-moderate",
"version": 5,
"edition": "Rev. 5",
"citation": "CA-8(1) independent penetration agent [VERIFY]",
"source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "penetration_test",
"requirement": "required",
"value": true,
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
"instrument_id": "nist-sp-800-53r5-moderate",
"version": 5,
"edition": "Rev. 5",
"citation": "CA-8 [VERIFY]",
"source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "vulnerability_scan",
"requirement": "max_age_days",
"value": 30,
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
"instrument_id": "nist-sp-800-53r5-moderate",
"version": 5,
"edition": "Rev. 5",
"citation": "RA-5(a) [VERIFY]",
"source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "vulnerability_scan",
"requirement": "required",
"value": true,
"bound_by": {
"authority": "National Institute of Standards and Technology",
"instrument": "SP 800-53 Rev. 5 — Security and Privacy Controls (moderate baseline)",
"instrument_id": "nist-sp-800-53r5-moderate",
"version": 5,
"edition": "Rev. 5",
"citation": "RA-5 [VERIFY]",
"source_digest": "sha256:5353535353535353535353535353535353535353535353535353535353535353"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "vulnerability_triage_disposition",
"requirement": "ai_position",
"value": "EXCLUDE_TAINTED_LINEAGE",
"bound_by": {
"authority": "Office of the Chief Information Security Officer",
"instrument": "Enterprise standard on machine-generated evidence",
"instrument_id": "enterprise-ai-evidence-standard",
"version": 1,
"edition": "2026-03-01",
"citation": "§ 3.4 [VERIFY]",
"source_digest": "sha256:e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
},
{
"claim": "vulnerability_triage_disposition",
"requirement": "required",
"value": true,
"bound_by": {
"authority": "Office of the Chief Information Security Officer",
"instrument": "Enterprise standard on machine-generated evidence",
"instrument_id": "enterprise-ai-evidence-standard",
"version": 1,
"edition": "2026-03-01",
"citation": "§ 3.1 [VERIFY]",
"source_digest": "sha256:e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5e5"
},
"also_bound_by": null,
"weaker_asks": null,
"downgraded_from": null,
"downgrade_reason": null
}
],
"defaults": [
{
"claim": "control_assessment",
"requirement": "ai_position",
"value": "ADMIT",
"because": "No instrument in force stated a position on AI-authored evidence for \"control_assessment\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
},
{
"claim": "penetration_test",
"requirement": "ai_position",
"value": "ADMIT",
"because": "No instrument in force stated a position on AI-authored evidence for \"penetration_test\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
},
{
"claim": "vulnerability_scan",
"requirement": "ai_position",
"value": "ADMIT",
"because": "No instrument in force stated a position on AI-authored evidence for \"vulnerability_scan\". The deploying organisation's own default admitted it, capped at MODELED by the class table as any model output is. This is a setting, not an absence: nobody with authority over this claim was asked, and the action proceeded anyway."
}
]
},
"reasons": [
"Coverage gap: no admissible memory for required claim(s) ai-system:TRIAGE-ASSISTANT-V4|vulnerability_triage_disposition.",
"Confidence 0.00% is bound by \"ai-system:TRIAGE-ASSISTANT-V4|vulnerability_triage_disposition\".",
"2 memories were withheld from the context block: ai-system:TRIAGE-ASSISTANT-V4|vulnerability_triage_disposition (AI-authored and excluded: the authority binding this claim does not accept model-authored evidence for it. Observed actor:ai:triage-assistant-v4 — a model, named as one in its own enrolled identity. Inadmissible at any reliability and any exposure. The remedy is to file this model's output under its OWN claim rather than under \"ai-system:TRIAGE-ASSISTANT-V4|vulnerability_triage_disposition\" — corroborating it does not help, because an identical value merges into this record and a different one contradicts it.); ai-system:TRIAGE-ASSISTANT-V4|vulnerability_triage_disposition (excluded on lineage: this record is a re-ingested receipt that itself rested on AI-authored evidence. The authority binding this claim excludes tainted lineage, which is what stops an exclusion being defeated by one round trip through a sealed receipt.).",
"Thresholds for $250,000 exposure: approve 85%, caution 60%."
],
"memory": {
"layer": "capture->store->recall->act",
"ledger_head": "sha256:666ec422cfa0a2aa3a0761bf5d34bc5eeb89079a0a37b9c86caf1f7e41c17603",
"ledger_entries": 7,
"context_digest": null,
"context_memory_ids": [],
"state_digest": "sha256:2c0c2a47680fbf012f29aba9e9ea7a1e4292e0b41243cd158d904090723e6562",
"retrieval_method": "idf-lexical",
"corpus_size": 5,
"considered": 5,
"admitted": 3,
"withheld": 2,
"not_considered": 0,
"coverage_gaps": [
"ai-system:TRIAGE-ASSISTANT-V4|vulnerability_triage_disposition"
],
"exposure": {
"usd": 250000,
"declared_by": "actor:human:issm",
"ledger_seq": 5
},
"salience_policy": {
"half_life_days": 90,
"grace_days": 7,
"access_boost_bp": 500,
"access_boost_cap_bp": 2500,
"relevance_weight_bp": 6000,
"recency_weight_bp": 3000,
"usage_weight_bp": 1000,
"context_cap": 12,
"method": "idf-lexical",
"candidate_list_digest": "sha256:8cd020e2ef86b9b3f5baad9171f55e6c93333bc9a97de3b19cc74a59e54d74ff",
"note": "salience orders retrieval only; it never contributes to reliability"
},
"policy_digest": "sha256:a6b69b7d20f7fb04d522364af1d92992058b04a5835fcec9d1c9f2261c7ef636",
"policy_body": {
"class_ceiling_bp": {
"VERIFIED": 9500,
"MODELED": 8000,
"SELLER-ASSERTED": 5000,
"MISSING": 0
},
"actor_class_ceiling": [
[
"^actor:ai:",
"MODELED"
],
[
"^actor:agent:",
"MODELED"
],
[
"^actor:human:",
"SELLER-ASSERTED"
],
[
"^actor:org:LAB-",
"VERIFIED"
],
[
"^actor:org:CERT-",
"VERIFIED"
],
[
"^actor:org:",
"SELLER-ASSERTED"
],
[
"^actor:sys:registry:",
"VERIFIED"
],
[
"^actor:sys:sensor:",
"VERIFIED"
],
[
"^actor:sys:",
"MODELED"
]
],
"freshness_cap_bp": 4000,
"max_age_days": {
"telemetry": 1,
"price": 7,
"status": 14,
"certificate": 365,
"test_report": 180,
"filing": 90,
"transcript": 120,
"highlight": 365,
"voice_note": 120,
"note": 365,
"preference": 540,
"decision": 1825,
"receipt": 365,
"default": 90
},
"wilson_z_milli": 1960,
"min_track_n": 5,
"exposure_tiers_bp": [
[
1000000000,
9500,
8000
],
[
100000000,
9000,
7000
],
[
1000000,
8500,
6000
],
[
0,
8000,
5000
]
],
"max_context_memories": 12,
"contradiction_resolve_margin": 2,
"salience": {
"half_life_days": 90,
"grace_days": 7,
"access_boost_bp": 500,
"access_boost_cap_bp": 2500,
"relevance_weight_bp": 6000,
"recency_weight_bp": 3000,
"usage_weight_bp": 1000
}
},
"observer_auth": {
"mode": "required",
"registry_version": 3,
"registry_digest": "sha256:460aeaafe345f69542a302e6619dff0712af98de6518838ee4c8585e448c3a7d",
"entries_root": "sha256:5670469f96484a814462814ed74f0f992b5f19e8ad6afced548e4956e4835ba5",
"memberships": [
{
"key_id": "k_17d23885943ae529",
"index": 1,
"entry": {
"actor": "actor:org:LAB-NVLAP-0412",
"class": "VERIFIED",
"kind": "org",
"key_id": "k_17d23885943ae529",
"jwk": {
"kty": "EC",
"crv": "P-256",
"x": "3TTw47-PkYfo3ZaKTq_qtHghnGvninAVj25kyOwONno",
"y": "16PMaR8ofeF5IcZk6ZLml8gDs8uE1s1sBLdciH5e4vg"
},
"valid_from": "2025-01-01T00:00:00.000Z",
"valid_to": "2027-06-01T00:00:00.000Z"
},
"path": [
{
"side": "left",
"sibling": "sha256:500f2ba5949d5256ae0f563530b0b270db41ce99d2d7c4b4b60e4bd558ca353d"
},
{
"side": "right",
"sibling": "sha256:a0b47ea437bf4f1042a1dd50a5a3f411f9a17971812fc6bafccd434eb7d78ccc"
},
{
"side": "right",
"sibling": "sha256:d3c2347eb675e865fc17ef0204cacda7b02e8784a811fdd1c8a015d1865e6dfb"
},
{
"side": "right",
"sibling": "sha256:7071adf5e21a94147d31f42f1028b4867b6562e5b78726259c2515b03b213e52"
}
]
},
{
"key_id": "k_307e4bfd710ec9b3",
"index": 0,
"entry": {
"actor": "actor:org:CERT-3PAO-ATLANTIC",
"class": "VERIFIED",
"kind": "org",
"key_id": "k_307e4bfd710ec9b3",
"jwk": {
"kty": "EC",
"crv": "P-256",
"x": "MGtV26TezLMPjiD3SecQtnje6eLqYyx4qkKzzAkbiY4",
"y": "SMMdLYnn-FpKbb2sJQ8EAZnzvozNm-cGO0VbUUpniPY"
},
"valid_from": "2025-01-01T00:00:00.000Z",
"valid_to": "2027-06-01T00:00:00.000Z"
},
"path": [
{
"side": "right",
"sibling": "sha256:4148869fc259d2c5fc19fe5831065b165a9acf81812e123162035acfdecade1d"
},
{
"side": "right",
"sibling": "sha256:a0b47ea437bf4f1042a1dd50a5a3f411f9a17971812fc6bafccd434eb7d78ccc"
},
{
"side": "right",
"sibling": "sha256:d3c2347eb675e865fc17ef0204cacda7b02e8784a811fdd1c8a015d1865e6dfb"
},
{
"side": "right",
"sibling": "sha256:7071adf5e21a94147d31f42f1028b4867b6562e5b78726259c2515b03b213e52"
}
]
},
{
"key_id": "k_5873dd9e7169def3",
"index": 2,
"entry": {
"actor": "actor:sys:registry:nvd-cve",
"class": "VERIFIED",
"kind": "system",
"key_id": "k_5873dd9e7169def3",
"jwk": {
"kty": "EC",
"crv": "P-256",
"x": "O9OY6oMuJg0df_INePO19_3b11VaSyMwIPdxoqvV2ak",
"y": "k7Orm5pxDxMdTF-H2S4h6ixRywzk1WxvquOQeqxLFx0"
},
"valid_from": "2025-01-01T00:00:00.000Z",
"valid_to": "2027-06-01T00:00:00.000Z"
},
"path": [
{
"side": "right",
"sibling": "sha256:e1fe36fe7c8e4695327c25d6d722630b6249c93293bfdc5894c58aaf961ab6f8"
},
{
"side": "left",
"sibling": "sha256:e8b9cba101f13538b909a2e686e9e6e9a8d77212036ed567eaebc205a443e83f"
},
{
"side": "right",
"sibling": "sha256:d3c2347eb675e865fc17ef0204cacda7b02e8784a811fdd1c8a015d1865e6dfb"
},
{
"side": "right",
"sibling": "sha256:7071adf5e21a94147d31f42f1028b4867b6562e5b78726259c2515b03b213e52"
}
]
},
{
"key_id": "k_f71bde46a9680d8d",
"index": 7,
"entry": {
"actor": "actor:ai:triage-assistant-v4",
"class": "MODELED",
"kind": "system",
"key_id": "k_f71bde46a9680d8d",
"jwk": {
"kty": "EC",
"crv": "P-256",
"x": "AmVfK7ltK7mprIKSXcj-PNTw4f8zq2gcbRG-qEiFmbU",
"y": "W7sar2SHGJ_jUsBSxoasMr7l1If81Qu5BdYfvlK8Who"
},
"valid_from": "2025-01-01T00:00:00.000Z",
"valid_to": "2027-06-01T00:00:00.000Z"
},
"path": [
{
"side": "left",
"sibling": "sha256:3e8eae859976a6f7d64543a05e28b4c8fc52b8500c65decc7e124af145fac567"
},
{
"side": "left",
"sibling": "sha256:6d20941c438f3924c50e6573d0712466ec6b91655705d2603ea89981e4c50ffc"
},
{
"side": "left",
"sibling": "sha256:d3f1d60ec9478d2b69455e5ba8168897966d18429bd3b7d36105841cc2ae1776"
},
{
"side": "right",
"sibling": "sha256:7071adf5e21a94147d31f42f1028b4867b6562e5b78726259c2515b03b213e52"
}
]
}
],
"memberships_unproven": [],
"revocation": {
"source": "SIGNED_LIST",
"digest": "sha256:12f73b1fbf27d38cf137b86a1ce13bbcd98161123a6aa7d79b107db8189966b9",
"sequence": 5,
"registry_version": 3,
"issued_at": "2026-08-06T00:00:00.000Z",
"next_update_due": "2026-08-13T00:00:00.000Z",
"entry_count": 0,
"body": {
"sequence": 5,
"registry_version": 3,
"issuer": {
"name": "NIST-regulated enterprise demonstration trust root",
"key_id": "k_3793b8e35f8acac1"
},
"issued_at": "2026-08-06T00:00:00.000Z",
"next_update_due": "2026-08-13T00:00:00.000Z",
"entries": [],
"spec": "corobate:revocation-list:1"
}
}
},
"governance": {
"digest": "sha256:8b0a45a27fcce9c1c243c764e855e67c6fe6dfd7f02a563bd90809b419731905",
"signed": true,
"actor_trust": "FLOOR_TO_SELLER_ASSERTED",
"outcome_trial_weight": 1,
"max_reingest_depth": 3,
"release_quorum_m": 2,
"release_quorum_n": 3,
"risk_acceptance_margin_bp": 500,
"risk_acceptance_max_days": 30,
"risk_acceptance_authority_cents": {
"SUPERVISOR": 1000000,
"MANAGER": 25000000,
"DIRECTOR": 500000000,
"OFFICER": 5000000000
},
"template_author_roles": [
"MANAGER",
"DIRECTOR",
"OFFICER"
]
},
"observers_attested": 3,
"outcomes": {
"attestations_counted": 0,
"attestations_recorded": 0,
"records_with_outcomes": 0
},
"lineage": {
"corroborations_counted": 0,
"corroborations_discounted": 0,
"records_with_discounted_corroborations": 0
},
"reingest": {
"records": 0,
"max_depth": 0,
"weakest_class": null,
"chain_weakest_bp": 10000,
"chain": []
},
"template": null
}
}
}What a control programme gets out of this
Every refusal on this page names the publication, the control identifier, the edition and the digest of the document it was read from. An assessor reading the regulator view finds their own catalogue cited back to them rather than a vendor's summary of it, and can re-derive every figure from the receipt with the published verifier, which imports nothing from the engine that produced it.
The AI position travels the same way. It is not a configuration flag inside a product — it is a rule in a signed instrument, attributed to an authority and a clause, sealed into the receipt's hashed body, drawn as a dial that is re-derived from that body rather than from the system that applied it, and re-checked by the published verifier as its own named identity. A recorded position that nothing enforces is the exact defect this estate found in its own never-waivable rule on 8 August 2026, and the remedy was not a better comment.
node 03-source/make-ally-data.js --write and
node 16-site/build-ally.js. The build refuses to write a page if any receipt
fails to verify, if any scoped copy fails its commitment check, or if the examiner's copy
contains a commercial figure.NIST publications are guidance and catalogues, not statutes, and encoding them as instruments is a READING. Every control identifier below is flagged [VERIFY] and needs a security officer's confirmation; the source digests are placeholders for documents this build never fetched. The structure is the claim; the readings are not. Party names are invented and no real assessor, provider or system is described.
Instruments were modelled from: NIST SP 800-53 Rev. 5 · NIST SP 800-161 Rev. 1 · NIST SP 800-218 (SSDF) v1.1 · NIST AI Risk Management Framework 1.0. Party names other than the publishing bodies are invented; no real vendor, dealer, assessor or vehicle is described here.
This page makes no network request and stores nothing in your browser.
Patent pending — U.S. Patent Application No. 19/747,068.