{"schema_version":2,"claims":[{"id":"receipt-integrity-depth","kind":"security","status":"normative","owners":["/spec","/bulla","/bulla/quickstart","/bulla/concepts","/bulla/demos","/buyers"],"evidence_refs":["bulla/spec/action-receipt-v0.2.md","bulla/spec/vectors/expected.json"],"statements":["Bulla can recompute an ActionReceipt, authenticate supported signatures under supplied trust material, and verify supported inclusion proofs."],"limitation":"Verification establishes only the reported digest, identity, or inclusion depth; it does not establish the truth of the underlying process.","compact_limitation":"Verification checks the record, not the underlying process.","plain_limitation":"This checks the receipt file. Evidence from the systems that performed or observed the action is still needed to establish what happened.","agent_projection":{"statement":"Bulla can recompute an ActionReceipt, authenticate supported signatures under supplied trust material, and verify supported inclusion proofs.","tasks":["verify a retained ActionReceipt","inspect verification depth"],"routes":["/spec","/bulla/quickstart","/bulla/concepts"],"never_infer":["Verification establishes only the reported digest, identity, or inclusion depth; it does not establish the truth of the underlying process."]}},{"id":"coherence-fee-jurisdiction","kind":"security","status":"bounded","owners":["/bulla/demos","/research/architecture","/methodology"],"evidence_refs":["bulla/FALSIFICATIONS.md","papers/CANON.md#program-commitments"],"limitation":"The coherence fee measures undisclosed conventions in a pinned composition model; it is not Bulla's safety foundation or an execution-failure predictor."},{"id":"trusted-root-boundary","kind":"security","status":"implemented","owners":["/spec","/bulla/demos","/research/architecture"],"evidence_refs":["bulla/src/bulla/recourse_gate.py","bulla/tests/test_recourse_gate.py"],"limitation":"A host's assertion about its own root is not independent grounding; the relying party must obtain or anchor the root separately."},{"id":"witness-history-boundary","kind":"security","status":"normative","owners":["/evidence","/research/witnessing","/research/architecture"],"evidence_refs":["bulla/spec/routed-inference-profile-v0.1-draft.md","glyph/data/operator-state.json"],"limitation":"Witness evidence establishes what entered a witnessed history; it does not prove the underlying execution occurred or reveal omitted actions."},{"id":"recourse-boundary","kind":"security","status":"bounded","owners":["/bulla/concepts","/evidence","/research/witnessing","/research/architecture"],"evidence_refs":["bulla/spec/routed-inference-profile-status.json"],"limitation":"A consistently conveyed remedy adapter establishes recourse terms, not that a forum, remedy, or settlement path is operational."},{"id":"published-version","kind":"maturity","status":"generated","owners":["/","/bulla/quickstart","/bulla/cli","/evidence","/bulla","/bulla/integrations"],"evidence_refs":["bulla/releases/pypi-project.json"],"statements":["Published install commands and stable examples are generated from the exact Bulla release evidence accepted by PyPI."],"limitation":"Commands labelled published are captured from the exact artifact accepted by PyPI; repository source is not substituted for it.","plain_limitation":"The command shown here comes from the package published on PyPI, not from unreleased repository code.","agent_projection":{"statement":"Published install commands and stable examples are generated from the exact Bulla release evidence accepted by PyPI.","tasks":["install the published package","run a stable example"],"routes":["/bulla/quickstart","/bulla/cli"],"never_infer":["Commands labelled published are captured from the exact artifact accepted by PyPI; repository source is not substituted for it."]}},{"id":"source-candidate-version","kind":"maturity","status":"generated","owners":["/evidence"],"evidence_refs":["bulla/src/bulla/__init__.py"],"limitation":"Repository source may match or lead the latest PyPI release. Publication status and receipt coverage come from PyPI and release records, not version text alone."},{"id":"release-coverage","kind":"quantitative","status":"generated","owners":["/evidence"],"evidence_refs":["bulla/releases/coverage.json","bulla/releases/pypi-project.json"],"limitation":"Coverage is calculated against the PyPI release denominator and does not count unanchored actions outside it."},{"id":"actionreceipt-conformance","kind":"quantitative","status":"generated","owners":["/spec","/evidence","/review","/methodology"],"evidence_refs":["bulla/spec/vectors/expected.json","bulla/spec/vectors/independent_check.py"],"limitation":"Passing the supplied vectors establishes fixture parity, not independent implementation or live-system correctness.","plain_limitation":"The browser and packaged checker agree on the published examples. That does not show how a separate implementation or live system will behave."},{"id":"routed-profile-status","kind":"maturity","status":"draft","owners":["/evidence","/review","/research/witnessing"],"evidence_refs":["bulla/spec/routed-inference-profile-status.json","bulla/spec/routed-inference-vectors/expected.json"],"limitation":"The routed profile is a local, full-disclosure, single-router/single-provider draft with no live provider, settlement adapter, or independent implementation."},{"id":"reproduction-profile-status","kind":"maturity","status":"draft","owners":["/review"],"evidence_refs":["bulla/spec/reproduction-profile-v0.1-draft.md","bulla/spec/reproduction-examples/attempt-blocked.json","bulla/tests/test_reproduction_profile.py"],"limitation":"The reproduction profile is a v0.1 draft with example receipts and a local reconciliation test. No external party has submitted a reproduction under it. It does not obtain access, establish that a reproduced claim is true, or adjudicate a divergence.","compact_limitation":"v0.1 draft with local examples; no external submission, and no verification of the claim under test."},{"id":"plurality-status","kind":"maturity","status":"generated","owners":["/evidence","/review","/research/witnessing","/about","/methodology"],"evidence_refs":["glyph/data/operator-state.json","glyph/data/independent-witnesses/ledger.json"],"limitation":"An operated composition-deed log or project-controlled witness fixture is not independent ActionReceipt witness plurality; W is derived only from active repository qualifications under unique outside control domains."},{"id":"independent-witness-evidence","kind":"maturity","status":"recorded-zero","owners":["/","/research/witnessing","/evidence","/status","/participate","/participate/witness"],"evidence_refs":["glyph/data/evidence-contract.json","glyph/data/independent-witnesses/ledger.json","glyph/data/independent-witnesses/candidate.schema.json","glyph/data/independent-witnesses/event.schema.json","glyph/data/independent-witnesses/ledger.schema.json","glyph/data/independent-witnesses/event-v2.schema.json","glyph/data/independent-witnesses/ledger-v2.schema.json","glyph/data/independent-witnesses/review-basis.schema.json","glyph/data/independent-witnesses/review-result.schema.json","glyph/data/independent-witnesses/intake-test/result.json","glyph/data/independent-witnesses/PROFILE.md","glyph/data/independent-witnesses/WIRE-FORMAT.md","glyph/data/independent-witnesses/THREAT-MODEL.md","glyph/scripts/build_independent_witness_intake_test.py","glyph/scripts/check_independent_witness_evidence.py","glyph/scripts/independent_witness_intake.py","glyph/scripts/test_independent_witness_evidence.py","bulla/spec/receipt-witness-operator-kit/generated/kit-facts.json","bulla/spec/receipt-witness-operator-kit/source/readme-first.md"],"statements":["W counts unique active outside organizational control domains only after a retained witness candidate, public endpoint probe, control findings, exact review basis, and PASS review result are bound by a merged QUALIFY event.","The public witness ledger is W0 · intake open; the project-controlled exercise is VALID_CANDIDATE · NOT_COUNTED."],"limitation":"A qualified W record establishes one separately controlled witness operation over the submitted public release records. It does not cryptographically establish organizational independence, receipt truth, occurrence, continuing availability, policy compliance, production fitness, bond value, recourse, or a witness market.","plain_limitation":"W records one separately controlled witness operation after a PASS repository review. UNCHECKABLE is not rejection. A qualification does not make the retained receipts true or promise that the service remains available.","agent_projection":{"statement":"The public witness ledger is W0 · intake open; the project-controlled exercise is VALID_CANDIDATE · NOT_COUNTED.","tasks":["operate an independent witness candidate","inspect the W evidence rule"],"routes":["/","/research/witnessing","/evidence","/status","/participate","/participate/witness"],"never_infer":["A qualified W record establishes one separately controlled witness operation over the submitted public release records. It does not cryptographically establish organizational independence, receipt truth, occurrence, continuing availability, policy compliance, production fitness, bond value, recourse, or a witness market."]}},{"id":"proxy-observe-boundary","kind":"maturity","status":"published","owners":["/bulla/demos"],"evidence_refs":["bulla/examples/live-mcp-proxy/README.md","bulla/src/bulla/live_proxy.py"],"limitation":"The demonstrated proxy advises and records; it does not silently modify traffic or verify underlying tool execution."},{"id":"research-status-discipline","kind":"research-status","status":"normative","owners":["/","/research","/about"],"evidence_refs":["glyph/COPY-STANDARDS.md"],"statements":["Current implementation mechanisms and experiments are repository-source research; they are not capabilities of the released Bulla package."],"limitation":"Formal verification applies to the stated mathematical object; empirical identification, conjecture, correction, and released-package capability remain separately labelled.","agent_projection":{"statement":"Current implementation mechanisms and experiments are repository-source research; they are not capabilities of the released Bulla package.","tasks":["distinguish released Bulla capabilities from repository-source research"],"routes":["/","/research","/about"],"never_infer":["Formal verification applies to the stated mathematical object; empirical identification, conjecture, correction, and released-package capability remain separately labelled."]}},{"id":"exact-repair-scope","kind":"research-status","status":"bounded","owners":["/bulla/demos","/research/architecture"],"evidence_refs":["papers/composition-doctrine/paper.md","bulla/examples/epistemic-demo/README.md"],"limitation":"Exact means minimum-cost within the pinned finite repair model; it is not proof of safe execution or a universal real-world cost."},{"id":"calibration-corpus-status","kind":"quantitative","status":"frozen","owners":["/research/calibration","/methodology"],"evidence_refs":["bulla/calibration/data/tier3/report/state-of-agent-coherence.md","bulla/FALSIFICATIONS.md"],"limitation":"The frozen calibration labels are schema-derived annotations; their correlation with the coherence fee is not execution-derived and does not estimate runtime failure."},{"id":"babel-dev-benchmark","kind":"quantitative","status":"frozen","owners":["/research/babel","/methodology"],"evidence_refs":["benchmark/coherence-gym/results_canonical/LEADERBOARD.md","benchmark/coherence-gym/instances/holdout_manifest.json"],"limitation":"Public scores are frozen dev-split reference results; official ranking uses a hidden holdout and controlled benchmark performance is not production safety."},{"id":"integration-surface-status","kind":"maturity","status":"published","owners":["/bulla/integrations"],"evidence_refs":["bulla/docs/HOSTS.md","bulla/docs/FRAMEWORKS.md","glyph/data/published-cli.json"],"limitation":"The documented command surface is pinned to the accepted published wheel; static adapters cannot observe dynamically registered tools.","plain_limitation":"These adapters come from the published package. Static analysis cannot see tools created only while an application is running."},{"id":"formal-verification-jurisdiction","kind":"research-status","status":"generated","owners":["/methodology"],"evidence_refs":["papers/research-status.yaml","papers/tarski-coherence/lean/TarskiCoherence.lean"],"limitation":"Machine checking applies to the stated formal object and hypotheses; it does not establish empirical identification, execution truth, or operational recourse."},{"id":"claims-gate-coverage","kind":"maturity","status":"implemented","owners":["/methodology"],"evidence_refs":["glyph/scripts/check-claims.mjs","glyph/scripts/check-claim-registry.mjs","glyph/scripts/check-facts.mjs"],"limitation":"The gates reject registered drift and known relational overclaims; they do not prove that every possible misleading formulation has been anticipated."},{"id":"open-license-exit","kind":"maturity","status":"published","owners":["/about"],"evidence_refs":["bulla/pyproject.toml","bulla/LICENSE"],"limitation":"An open format and license permit independent exit; they do not themselves create an independent implementation, witness, or operator."},{"id":"historical-lineage","kind":"research-status","status":"sourced-reconstruction","owners":["/about"],"evidence_refs":["glyph/data/historical-sources.json"],"statements":["Writing began with receipts.","Glyph defines the mark. Bulla is the envelope.","Attested numerals: N14 = ten · N01 = one."],"limitation":"The headline compresses the administrative origin of Mesopotamian writing into a category statement. The Late Uruk specimen is a sourced conceptual reconstruction and the correspondence is functional, not a literal translation, direct technological lineage, or origin claim for glyphic writing; numeral values follow published sign lists, and no commodity readings or totals are asserted.","compact_limitation":"Conceptual reconstruction · functional continuity, not literal equivalence."},{"id":"eval-incident-relevance","kind":"research-status","status":"sourced-reconstruction","owners":["/research/eval-incident"],"evidence_refs":["bulla/spec/eval-receipt-profile-v0.2-draft.md","bulla/examples/eval-incident-replay/README.md"],"statements":["Bulla can bind authority, action-boundary decisions, evidence references, and recourse without claiming to provide containment.","An action that leaves no receipt is found only by reconciling against a separately retained denominator.","The standalone no-Bulla replay checker recomputes receipt digests and event coverage without importing Bulla; issuer authenticity remains a separate cryptographic rung."],"limitation":"A sourced analysis of the publicly described incident shape (Hugging Face 2026-07-16; OpenAI 2026-07-21), not a reproduction of either organization's records and not a claim of prevention. The replay is synthetic, with no real exploit, credential, or payload. The supplied checker verifies digest integrity and internal coverage consistency, not ed25519 issuer authenticity, denominator completeness, or organizational independence. An accepted observer can omit rows.","compact_limitation":"Sourced analysis · records and reconciles; does not contain or prevent."},{"id":"incident-packet-status","kind":"maturity","status":"experimental","owners":["/bulla/experimental/incident-packet","/evidence"],"evidence_refs":["bulla/spec/agent-incident-packet/PROFILE.md","bulla/examples/agent-incident-packet/README.md","bulla/src/bulla/experimental/incident_pilots.py","bulla/tests/test_agent_incident_pilots.py"],"statements":["The source-only Agent Incident Packet profile keeps packet integrity, receipt verification, authority, coverage, redaction binding, witness evidence, party conflict, and reliance as separate dimensions.","Each represented protocol requires one exact decision/effect anchor pair and accepted denominator checkpoints bound to the reported snapshot bytes.","Live timeline and publish receipts require ActionReceipt v0.4 with conventions: []; convention-bearing historical receipts remain opaque evidence artifacts.","The HTTP and MCP pilots use real localhost process boundaries and expose a direct bypass through a target-side denominator.","Team-operated processes, keys, fixtures, checkers, and witnesses do not increment external evidence counters."],"limitation":"The profile, deterministic fixtures, checkers, and localhost pilots are team-authored source evidence. A packet supports zero or one witness reference. Multiple-witness aggregation remains unresolved. The empty-convention rule belongs only to this experimental profile and does not change ActionReceipt v0.4; cross-runtime convention evaluation remains outside the verification contract. Denominator checkpoints authenticate what an accepted path-separated observer reported; they do not prove completeness or organizational independence, and an accepted observer can self-shorten rows. The evidence does not establish production containment, disclosure safety, external implementation parity, independent witnessing, or incident truth. External A/J/I/W and replay counts remain 0/0/0/0 and r0.","compact_limitation":"Experimental · SOURCE_ONLY · team-operated · A0/J0/I0/W0 · r0."},{"id":"acceptance-contract-alpha","kind":"maturity","status":"experimental","owners":["/bulla/experimental/acceptance-contract"],"evidence_refs":["bulla/spec/acceptance-contract/PROFILE.md","bulla/spec/acceptance-contract/generated/site-projection.json","bulla/spec/acceptance-contract/generated/expected/missing.json","bulla/spec/acceptance-contract/generated/expected/passing.json","bulla/spec/acceptance-contract/generated/expected/failing.json","bulla/src/bulla/experimental/acceptance_contract.py","bulla/spec/acceptance-contract/formal/AcceptanceContract.lean"],"statements":["The same synthetic staging claim and receiver observation remain fixed while rollback evidence changes from missing to PASS or FAIL.","The missing state returns HOLD_FOR_EVIDENCE and a conditional request for a correctly bound rollback-test record.","The passing state returns PROCEED and ELIGIBLE while authorization remains NOT_ISSUED and execution remains NOT_ATTEMPTED.","The failing state returns REFUSE and INELIGIBLE.","The profile remains source-only and external counters remain A0/J0/I0/W0 · r0."],"limitation":"The profile, transaction, roles, keys, records, evaluator, and formal model are project-authored. A conditional evidence request does not establish that the requested test exists, will pass, or guarantees promotion. The result does not establish deployment occurrence, worldly truth, receiver-record completeness, legal enforceability, production use, organizational independence, or external implementation parity.","compact_limitation":"Experimental · SOURCE_ONLY · synthetic-public · team-operated · A0/J0/I0/W0 · r0.","plain_limitation":"This synthetic demonstration evaluates retained records under one project-authored policy. It does not deploy anything or establish that the agent's claim is true."},{"id":"inference-clearing-alpha","kind":"maturity","status":"experimental","owners":["/bulla/experimental/inference-clearing"],"evidence_refs":["bulla/spec/inference-clearing/PROFILE.md","bulla/spec/inference-clearing/expected-verdict.json","bulla/spec/inference-clearing/site-projection.json","bulla/spec/inference-clearing/hostile-cases.json","bulla/src/bulla/experimental/inference_clearing.py"],"statements":["Both synthetic providers return byte-identical BACKUP artifacts.","After both provider processes terminate, the retained, term-bound model reproduces one input-to-output relation; the opaque record supplies no model to rerun.","Under the supplied buyer policy, the reproduced relation is payment-eligible while authorization remains NOT_ISSUED and settlement remains NOT_ATTEMPTED; the opaque response is refused.","Adding effect-bypass-001 to the supplied receiver record leaves receipt integrity verified, changes coverage from COVERED to UNCOVERED, and makes payment ineligible.","Project-authored Python, standalone Node, and browser implementations verify the complete experimental profile after the provider processes terminate and reproduce the same machine-decidable report from retained inputs and a separately supplied context.","The profile remains source-only and external counters remain A0/J0/I0/W0 · r0."],"limitation":"The profile uses one closed synthetic task and team-controlled roles, evidence, keys, receiver records, witness roots, policies, and settlement reports. Reproduction establishes a retained model-input-output relation, not which model the provider historically ran, answer truth, model quality, or family identity. Coverage is relative to the supplied receiver record and does not establish its completeness. The result does not establish payment execution, custody, collectibility, production clearing, organizational independence, representative adoption, or worldly truth. Python, Node, and browser agreement is project-authored corroboration rather than external implementation evidence.","compact_limitation":"Experimental · SOURCE_ONLY · synthetic-public · team-operated · A0/J0/I0/W0 · r0.","plain_limitation":"This demonstration uses synthetic records and project-authored checkers. It does not establish what model a provider actually ran, whether the answer is true, whether the action log is complete, or whether money moved."},{"id":"accountability-circuit-behavior","kind":"security","status":"implemented","owners":["/buyers","/research/accountability-circuit","/evidence"],"evidence_refs":["bulla/spec/assurance-linker/accountability-circuit-v0.2/PROFILE.md","bulla/spec/assurance-linker/accountability-circuit-v0.2/expected-verdicts.json","bulla/spec/assurance-linker/accountability-circuit-v0.2/manifest.json","bulla/spec/assurance-linker/accountability-circuit-v0.2/reports/breach-authorized.json","bulla/spec/assurance-linker/accountability-circuit-v0.2/formal-fixture-map.json","glyph/src/lib/accountability-circuit.generated.json","glyph/src/lib/accountability-circuit-kernel.mjs","glyph/reviews/2026-08-17-accountability-circuit/PUBLICATION-DISPOSITION.md","papers/interpolant-envelope/lean/InterpolantEnvelope/AssuranceLinker.lean"],"statements":["The accountability-circuit implementation binds one closed structured promise to exact evidence, witness, challenge, authority, capital, and consequence requirements.","For the five synthetic USD-cent scenarios, Python, standalone Node, and the browser compute the same consequence-bearing report fields.","The witness checks membership and append-only history under externally supplied trust roots; the deterministic checker establishes equality or mismatch over supplied delivery bytes.","The verifier distinguishes consequence eligibility from a separately issued authorization and from the rail adapter's report of an attempted event.","The model-identity control remains a self-asserted semantic dispute and cannot produce automatic financial recourse."],"limitation":"The accountability circuit is an experimental source implementation over project-authored synthetic promises, evidence, keys, witness roots, roles, and fixture-rail reports. Its browser, Python, and Node agreement establishes verifier behavior over supplied records, not complete observation, independent witnessing, worldly execution, real custody, collectibility, legal enforceability, production operation, actual settlement, or adoption. The published Bulla package creates and verifies ActionReceipts; it does not include the complete circuit.","compact_limitation":"Implemented synthetic verifier behavior; operating independence, complete observation, real custody, enforceability, production use, and real settlement are not established.","plain_limitation":"The demonstration computes what the supplied synthetic records permit. It does not prove that every real action was observed, that the roles are independent, or that money moved.","agent_projection":{"statement":"The accountability-circuit implementation binds one closed structured promise to exact evidence, witness, challenge, authority, capital, and consequence requirements.","tasks":["inspect consequence eligibility","distinguish authorization from an attempt report"],"routes":["/research/accountability-circuit","/evidence"],"never_infer":["The accountability circuit is an experimental source implementation over project-authored synthetic promises, evidence, keys, witness roots, roles, and fixture-rail reports. Its browser, Python, and Node agreement establishes verifier behavior over supplied records, not complete observation, independent witnessing, worldly execution, real custody, collectibility, legal enforceability, production operation, actual settlement, or adoption. The published Bulla package creates and verifies ActionReceipts; it does not include the complete circuit."]}},{"id":"reliance-map-behavior","kind":"security","status":"implemented","owners":["/research/declared-lineage","/evidence"],"evidence_refs":["bulla/spec/reliance-map/PROFILE.md","bulla/spec/reliance-map/PREREGISTRATION.md","bulla/spec/reliance-map/generated/manifest.json","bulla/spec/reliance-map/generated/expected-report.json","bulla/src/bulla/experimental/reliance_map.py","bulla/spec/reliance-map/check.mjs","bulla/spec/reliance-map/kernel.mjs","bulla/tests/test_reliance_map.py","glyph/scripts/reliance-map.test.ts","glyph/src/lib/reliance-map.generated.json","glyph/src/lib/reliance-map-browser.ts"],"statements":["The Reliance Map computes correction propagation over an accepted finite graph and separately reports declared descendants, complete branches with no declared path, and incomplete lineage.","The frozen example contains 10,000 synthetic declared decisions with 2,500 affected, 5,000 not affected under the accepted graph, and 2,500 undetermined results.","Every affected result carries a replayable declared path from the correction target to the decision.","Python, standalone Node, and the browser compute the same semantic report; presentation coordinates are committed under a separate root."],"limitation":"The Reliance Map is an experimental source implementation over a project-authored synthetic graph, correction notice, keys, and context. Its result is relative to the accepted declared graph. It does not establish correction truth, complete worldly dependency capture, action safety, rollback, consequence authorization, independent operation, production use, or adoption. It is not part of the installed Bulla package.","compact_limitation":"Implemented correction propagation over an accepted synthetic graph; complete dependency capture, rollback, authorization, independent operation, and production use are not established.","plain_limitation":"The map identifies declared paths that require rechecking. It does not prove that every real dependency was recorded, reverse an action, or authorize a consequence.","agent_projection":{"statement":"The Reliance Map computes correction propagation over an accepted finite graph and separately reports declared descendants, complete branches with no declared path, and incomplete lineage.","tasks":["trace a declared correction path","inspect incomplete lineage"],"routes":["/research/declared-lineage","/evidence"],"never_infer":["The Reliance Map is an experimental source implementation over a project-authored synthetic graph, correction notice, keys, and context. Its result is relative to the accepted declared graph. It does not establish correction truth, complete worldly dependency capture, action safety, rollback, consequence authorization, independent operation, production use, or adoption. It is not part of the installed Bulla package."]}},{"id":"witness-covenant-behavior","kind":"security","status":"implemented","owners":["/research/answerability-network","/research/witnessing","/evidence"],"evidence_refs":["bulla/spec/witness-covenant/PROFILE.md","bulla/spec/witness-covenant/WIRE-FORMAT.md","bulla/spec/witness-covenant/PREREGISTRATION.md","bulla/spec/witness-covenant/CORRECTION-001.md","bulla/spec/witness-covenant/reports/fork-authorized.json","bulla/src/bulla/experimental/witness_covenant.py","bulla/spec/witness-covenant/kernel.mjs","bulla/spec/witness-covenant/formal-fixture-map.json","bulla/tests/test_witness_covenant.py","papers/interpolant-envelope/lean/InterpolantEnvelope/AssuranceLinker.lean"],"statements":["The witness covenant covers one objective service fault: two authentic different roots for the same operator, log, authority epoch, and tree size.","Remedy eligibility requires the jointly observed fork, a closed challenge, an adequate dedicated allocation, and the exact covenant binding.","A separately named authority must sign the exact consequence, amount, destination, checkpoint, covenant, and capital binding before the Test-ledger adapter may report an attempt.","Adding the fixture-reported bond changes capital and recourse only; it does not improve witness trust, history integrity, receipt grounding, or provider claims."],"limitation":"The witness covenant is an experimental source implementation over project-authored keys, checkpoints, challenge records, allocations, authorities, and Test-ledger reports. It does not establish independent operation, receipt truth, complete observation, custody, collectibility, deterrence, actual recovery, real settlement, production operation, or a witness market. It is not part of the installed Bulla package.","compact_limitation":"Objective fork and bounded fixture recourse are implemented; independent operation, custody, collection, recovery, and production use are not established.","plain_limitation":"The covenant covers one signed-history fault. It does not make the witnessed claims true or show that a real bond can be collected.","agent_projection":{"statement":"The witness covenant covers one objective service fault: two authentic different roots for the same operator, log, authority epoch, and tree size.","tasks":["verify a same-size witness fork","inspect bounded fixture recourse"],"routes":["/research/witnessing","/research/answerability-network"],"never_infer":["The witness covenant is an experimental source implementation over project-authored keys, checkpoints, challenge records, allocations, authorities, and Test-ledger reports. It does not establish independent operation, receipt truth, complete observation, custody, collectibility, deterrence, actual recovery, real settlement, production operation, or a witness market. It is not part of the installed Bulla package."]}},{"id":"answerability-network-behavior","kind":"security","status":"implemented","owners":["/research/answerability-network","/research/witnessing","/research/architecture","/evidence"],"evidence_refs":["bulla/spec/answerability-network/PROFILE.md","bulla/spec/answerability-network/WIRE-FORMAT.md","bulla/spec/answerability-network/PREREGISTRATION.md","bulla/spec/answerability-network/manifest.json","bulla/spec/answerability-network/reports/fork-authorized.json","bulla/src/bulla/experimental/answerability_network.py","bulla/spec/answerability-network/kernel.mjs","bulla/spec/answerability-network/formal-fixture-map.json","bulla/tests/test_answerability_network.py","glyph/scripts/answerability-network.test.ts","glyph/src/workers/answerability-network.worker.ts","papers/interpolant-envelope/lean/InterpolantEnvelope/AssuranceLinker.lean"],"statements":["The Answerability Network composes one synthetic inference procurement, a selected ActionReceipt, leaf-bound witnessed history, a bounded witness covenant, and an accepted 10,000-decision Reliance Map.","Two authentic same-size witness heads with different roots establish the covered witness fault only when jointly supplied to the verifier.","The accepted recall notice marks exactly 2,500 declared descendants for recheck, keeps 5,000 complete unrelated decisions separate, and leaves 2,500 decisions with incomplete ancestry unresolved.","Python, standalone Node, and the browser compute the same six consequence-bearing reports, including challenge, eligibility, authorization, and Test-ledger attempt separation.","The model-identity control remains challenge-required and cannot use the objective witness-fork remedy."],"limitation":"The Answerability Network is an experimental source implementation over project-authored synthetic transactions, keys, witness views, graph declarations, challenge records, capital observations, and Test-ledger reports. It is not part of the installed Bulla package. It does not establish provider-result truth, complete dependency capture, witness independence, custody, collectibility, dollars moved, production operation, customer activity, or adoption.","compact_limitation":"Implemented synthetic composition; complete dependency capture, independent witnessing, real custody, settlement, and production use are not established.","plain_limitation":"The example verifies supplied synthetic records and declared dependency paths. It does not prove that every dependency was recorded, that the witness is independent, or that money moved.","agent_projection":{"statement":"The Answerability Network composes one synthetic inference procurement, a selected ActionReceipt, leaf-bound witnessed history, a bounded witness covenant, and an accepted 10,000-decision Reliance Map.","tasks":["reproduce the answerability reports","trace a recheck path","test automatic-recourse refusal"],"routes":["/research/answerability-network","/evidence"],"never_infer":["The Answerability Network is an experimental source implementation over project-authored synthetic transactions, keys, witness views, graph declarations, challenge records, capital observations, and Test-ledger reports. It is not part of the installed Bulla package. It does not establish provider-result truth, complete dependency capture, witness independence, custody, collectibility, dollars moved, production operation, customer activity, or adoption."]}},{"id":"assurance-linker-status","kind":"maturity","status":"experimental","owners":["/bulla/experimental/assurance-linker","/bulla/experimental/assurance-linker/trial","/bulla/experimental/accountability-circuit/candidate/b770da454743a9668b2f7e5cafe2c036314ba6c0c4517d49c8c7da693e341faf","/evidence","/bulla/experimental/assurance-linker/reference"],"evidence_refs":["bulla/spec/assurance-linker/PROFILE.md","bulla/spec/assurance-linker/PREREGISTRATION.md","bulla/spec/assurance-linker/expected-verdict.json","bulla/spec/assurance-linker/accountability-circuit-v0.2/PROFILE.md","bulla/spec/assurance-linker/accountability-circuit-v0.2/expected-verdicts.json","bulla/spec/assurance-linker/accountability-circuit-v0.2/manifest.json","glyph/reviews/2026-08-17-accountability-circuit/PROTOCOL.md","glyph/src/lib/accountability-circuit.generated.json","bulla/spec/assurance-linker/formal-fixture-map.json","bulla/spec/assurance-linker/trial-v0.2/results.json","bulla/spec/assurance-linker/trial-v0.2/freeze.json","bulla/spec/assurance-linker/stranger-doorway-v0.2-r5/readiness.json","bulla/spec/assurance-linker/stranger-doorway-v0.2-r5/correction.json","bulla/spec/assurance-linker/stranger-doorway-v0.2-r5/scoring-capsule-freeze.json","bulla/spec/assurance-linker/stranger-doorway-v0.2-r5/prior-revisions-preservation.json","bulla/spec/assurance-linker/stranger-doorway-v0.2-r5/semantic-root.json","bulla/spec/assurance-linker/stranger-doorway-v0.2-r5/ceremony-root.json","bulla/spec/assurance-linker/stranger-doorway-v0.2-r5/trial-envelope.json","bulla/spec/assurance-linker/stranger-doorway-v0.2-r5/corpus-reuse.json","bulla/spec/assurance-linker/stranger-doorway-v0.2-r5/publication-identity.json","bulla/src/bulla/experimental/assurance_linker.py","bulla/src/bulla/experimental/assurance_bitcoin.py","papers/interpolant-envelope/lean/InterpolantEnvelope/AssuranceLinker.lean"],"statements":["The source-only Assurance Linker compiles closed structured promises into explicit evidence, authority, coverage, capital, recourse, and consequence requirements.","The verifier keeps evidence grounding, guarantee obligations, coverage, capital allocation, consequence eligibility, and reliance as separate dimensions.","Python and standalone Node reports agree on eight deterministic synthetic dossiers.","The additive 0.2 accountability-circuit profile has Python, standalone Node, and browser agreement on five synthetic USD-cent dossiers with externally supplied witness roots, deterministic byte comparison, authenticated causal order and adjacent mismatch checkpoints, challenge state, declared capital allocation, consequence eligibility, exact authorization, and a separately witnessed fixture-attempt report.","The hash-addressed candidate route commits to the circuit evidence plus the candidate presentation, browser kernel, verifier sources, frozen questionnaire, formal source, and exact build dependency lock; an anonymous deployed-body probe remains unrecorded.","The 0.2 fixture distinguishes remedy eligibility, authorization to attempt, and a reported sandbox attempt; actual funds remain NOT_ESTABLISHED.","The Bitcoin Core 31.1 adapter projects a synthetic regtest UTXO into the same abstract lock interface as the fixture rail.","The original Trial 0.2 readiness attempt did not establish complete input-to-output coverage for every operative closed-schema value.","The checked fixture comparison shows that receipt integrity remains VERIFIED while one receiver-recorded bypass changes required coverage from COVERED to UNCOVERED and payment from ELIGIBLE to INELIGIBLE.","Trial 0.2-r5 preserves the r4 semantic root exactly and changes only publication, qualification, provenance, recruitment, and presentation controls.","The Trial 0.2-r5 public surface is a publication-neutral clean-room checker doorway; no mirror publication set, cold-reader calibration, candidate contact, or blind attempt has occurred.","The r5 checker envelope excludes reference verifier, authoring compiler, generator, mutation, hidden-input, hidden-answer, and coordinator scoring source during the CLEAN_ROOM_ONLY epoch.","Trial 0.1 is a superseded calibration instrument and is not admissible for external evidence counters.","External authors, adjudicators, implementations, witnesses, and replays remain zero."],"limitation":"The profiles, Trial 0.2-r5 instrument, and accountability-circuit candidate use team-authored synthetic promises, cases, expected projections, implementations, evidence, keys, witness roots, rail observations, and settlement roles. The accountability candidate has no bound anonymous deployment or reader attempts, so comprehension remains NOT_COMPUTED. No Trial 0.2-r5 mirror publication set, cold-reader calibration, or foreign checker attempt has occurred. Surface completeness is relative to named frozen schemas, rules, and protected fields; it does not cover every open-world interaction. Foreign authorability, independent reproduction, institutional handling, operational separation, and marginal decision value remain blocked. The evidence does not establish worldly truth, complete observation, external collateral encumbrance, custody, collectibility, legal enforceability, organizational independence, production safety, actual settlement, actuarial calibration, or mainnet readiness. Bitcoin remains optional, separate, sat-denominated, and does not evaluate predicates. External A/J/I/W and replay counts remain 0/0/0/0 and r0.","compact_limitation":"Experimental · SOURCE_ONLY · synthetic-public · team-operated · A0/J0/I0/W0 · r0."},{"id":"verification-report-depths","kind":"security","status":"implemented","owners":["/bulla/blind-spot"],"evidence_refs":["glyph/src/lib/receipt-verify.ts","glyph/src/lib/pinned-inclusion.ts","glyph/src/lib/examples/pinned-inclusion-proof.json"],"limitation":"The browser recomputes receipt digests, executable bounds, and a local RFC 6962 inclusion proof against a pinned fixture root. It does not verify signature identity, actor time, underlying execution, or independent witness operation.","compact_limitation":"Digest and local pinned-root checks are recomputed; identity, actor time, execution, and independent operation are not."},{"id":"reliance-decision-separation","kind":"security","status":"implemented","owners":["/bulla/concepts"],"evidence_refs":["bulla/src/bulla/reliance.py","bulla/spec/vectors/reliance-rely.json"],"limitation":"The three-exit reliance decision and its receipt are implemented in the Bulla library and exercised by library vectors; no live downstream relier operates on this site.","compact_limitation":"Decision flow is implemented in Bulla; no live downstream relier operates here.","statements":["Verification reports. Policy decides."]},{"id":"semantic-settlement","kind":"research-status","status":"internal-captive","owners":["/evidence"],"evidence_refs":["bulla/spec/semantic-boundary-v0.3-experimental.md","bulla/spec/semantic-finality-v0.1-experimental.md","bulla/bench/golden/v0.3/bulla-semantic-boundary-stack-v0.3.json","bulla/bench/invention/semantic-settlement/SPRINT-STATUS.md"],"limitation":"The claim flow is a finite captive research profile. It binds authorized institutional transitions; it does not establish worldly truth, legal validity, production settlement, custody, or independent forum behavior.","compact_limitation":"Replayable institutional claim flow · not worldly truth, legal validity, custody, or production settlement."},{"id":"control-plane-alpha-status","kind":"maturity","status":"experimental","owners":["/bulla/experimental/control-plane"],"evidence_refs":["glyph/data/control-plane-alpha.json","glyph/src/lib/control-plane-alpha.ts","glyph/src/components/ControlPlaneAlpha.tsx","bulla/spec/control-plane-alpha/PROFILE.md","bulla/spec/control-plane-alpha/expected-verdict.json","bulla/spec/control-plane-alpha/contexts/alpha-context.json"],"statements":["The source implementation defines one closed synthetic MCP authorization, receiver, denominator, witness, and packet-publication loop.","The preregistered result keeps decision coverage 2/2 and effect coverage 1/2 as separate anchors.","The package surface remains SOURCE_ONLY, the target surface is PUBLIC_ALPHA, and deployment status comes from the tracked control-plane evidence ledger."],"limitation":"The public-alpha contract defines one synthetic MCP sandbox. Bulla controls the authorization, receiver, denominator, witness, and publication keys. A deployment establishes execution across path-separated services; it does not establish customer authority, denominator completeness, organizational independence, production safety, or incident truth.","compact_limitation":"Experimental · SOURCE_ONLY · PUBLIC_ALPHA target · deployment state generated from tracked evidence."},{"id":"answerable-computing-definition","kind":"maturity","status":"normative","owners":["/"],"evidence_refs":["glyph/COPY-STANDARDS.md","bulla/spec/action-receipt-v0.2.md","bulla/src/bulla/reliance.py","bulla/spec/witness-covenant/PROFILE.md","bulla/spec/reliance-map/PROFILE.md"],"statements":["In Answerable Computing, the party relying on machine work can retain the transaction record and evaluate the evidence under its own policy.","The party relying on machine work decides what evidence to accept under its own policy.","Acceptance alone authorizes neither correction nor recourse.","Fault evidence, correction authority, and recourse authority remain separate."],"limitation":"This definition names Glyph Standard's program jurisdiction. It does not imply that repository-source research is a capability of the released Bulla package, complete observation, correction truth, automatic enforcement, legal effect, independent operation, or adoption.","agent_projection":{"statement":"In Answerable Computing, the party relying on machine work can retain the transaction record and evaluate the evidence under its own policy.","tasks":["identify the party relying on machine work","separate evidence acceptance from correction and recourse authority"],"routes":["/"],"never_infer":["This definition names Glyph Standard's program jurisdiction. It does not imply that repository-source research is a capability of the released Bulla package, complete observation, correction truth, automatic enforcement, legal effect, independent operation, or adoption."]}},{"id":"category-thesis","kind":"maturity","status":"dated-thesis","owners":["/","/research/answerability-network","/evidence"],"evidence_refs":["glyph/data/ecosystem-landscape.json"],"as_of":"2026-08-20","statements":["Compute is becoming its own customer.","Machine-initiated work can cross payment, deployment, permission, data, and inference boundaries before a person reviews the individual transaction.","Agents can procure inference, call tools, initiate payments, request deployments, and pass results between systems."],"falsifier":"Disconfirm by 2030-12-31 if two independently governed datasets, each covering at least 1,000,000 consequential inference, tool, payment, deployment, permission, or data transactions, report machine-initiated requests below 1% with no positive year-over-year trend throughout 2028–2030.","limitation":"This is a dated category thesis, not a measurement of present transaction volume, Bulla adoption, or autonomous economic activity.","plain_limitation":"This category thesis does not claim that machine-initiated transactions dominate today or that Bulla has been adopted for them.","agent_projection":{"statement":"Agents can procure inference, call tools, initiate payments, request deployments, and pass results between systems.","tasks":["locate the receiving-party policy boundary"],"routes":["/","/research/answerability-network","/evidence"],"never_infer":["This is a dated category thesis, not a measurement of present transaction volume, Bulla adoption, or autonomous economic activity."]}},{"id":"answerable-computing-law","kind":"security","status":"experimental","owners":["/research","/research/answerability-network"],"evidence_refs":["bulla/spec/answerability-network/PROFILE.md","bulla/spec/witness-covenant/PROFILE.md","bulla/spec/reliance-map/PROFILE.md"],"statements":["No orphaned consequence. No silent discharge.","Under the Answerability Network profile, a consequence must reference the eligible predicate and the authority that permitted it.","When the profile accepts evidence defeat, declared dependents remain marked for recheck or unresolved; they are not silently cleared."],"limitation":"These rules are profile-relative verifier properties over supplied records; they do not establish complete observation, worldly causation, legal effect, actual settlement, or complete dependency capture.","agent_projection":{"statement":"Under the Answerability Network profile, a consequence must reference the eligible predicate and the authority that permitted it.","tasks":["inspect consequence provenance","trace accepted evidence defeat"],"routes":["/research","/research/answerability-network"],"never_infer":["These rules are profile-relative verifier properties over supplied records; they do not establish complete observation, worldly causation, legal effect, actual settlement, or complete dependency capture."]}},{"id":"ecosystem-position","kind":"maturity","status":"dated-comparison","owners":["/bulla/ecosystem"],"evidence_refs":["glyph/data/ecosystem-landscape.json"],"statements":["Bulla addresses the retained transaction record and local policy boundary used by a receiving party.","The cited communication, telemetry, action-record, audit, payment, and transparency protocols answer adjacent or complementary questions.","No interoperability adapter is claimed for any listed protocol."],"limitation":"The ecosystem comparison is a dated reading of the cited primary sources. It does not establish complete market coverage, exclusive differentiation, implemented interoperability, adoption, or comparative superiority.","compact_limitation":"Dated primary-source comparison; no adapter, adoption, completeness, or superiority claim."},{"id":"coverage-denominator-demo","kind":"security","status":"implemented","owners":["/bulla","/bulla/blind-spot","/bulla/demos","/bulla/quickstart","/buyers"],"evidence_refs":["bulla/examples/agent-fleet-blind-spot/run_demo.py","bulla/tests/test_agent_fleet_blind_spot_example.py","glyph/src/lib/event-coverage.ts"],"statements":["Bulla can compare a supplied receipt set with a supplied receiver action record and report unmatched action identifiers."],"limitation":"Coverage is computed relative to the supplied denominator; a compromised or incomplete independent log narrows what reconciliation can find. The browser recomputes digests and the set difference over unsigned fixture receipts and does not verify signer identity or the denominator's independence.","compact_limitation":"Coverage is only as strong as the independent denominator supplied.","plain_limitation":"Bulla can find actions in the supplied action log that have no matching receipt. It cannot find actions missing from that log.","agent_projection":{"statement":"Bulla can compare a supplied receipt set with a supplied receiver action record and report unmatched action identifiers.","tasks":["reconcile receipts with receiver records","find unmatched supplied actions"],"routes":["/bulla","/bulla/blind-spot"],"never_infer":["Coverage is computed relative to the supplied denominator; a compromised or incomplete independent log narrows what reconciliation can find. The browser recomputes digests and the set difference over unsigned fixture receipts and does not verify signer identity or the denominator's independence."]}},{"id":"receiver-context-contract","kind":"security","status":"implemented","owners":["/bulla"],"evidence_refs":["bulla/src/bulla/action_receipt.py","bulla/src/bulla/reliance.py","bulla/src/bulla/coverage.py","glyph/src/lib/receipt-verify.ts","glyph/src/lib/event-coverage.ts","glyph/src/lib/reliance-policy.ts"],"statements":["The receiving application or agent supplies trusted roots, policy, action denominator, time, and revocation context; Bulla computes record verification, coverage, and a local RELY, REFUSE, or ESCALATE decision.","The principal is the person or organization that selects the receiver's roots and policy."],"limitation":"Receiver-supplied context and Bulla's local outputs do not establish worldly truth, occurrence, denominator completeness, custody, settlement, organizational independence, or the suitability of the selected policy.","agent_projection":{"statement":"The receiving application or agent supplies trusted roots, policy, action denominator, time, and revocation context; Bulla computes record verification, coverage, and a local RELY, REFUSE, or ESCALATE decision.","tasks":["identify the runtime receiver","identify the principal","supply receiver trust and policy context"],"routes":["/bulla"],"never_infer":["Receiver-supplied context and Bulla's local outputs do not establish worldly truth, occurrence, denominator completeness, custody, settlement, organizational independence, or the suitability of the selected policy."]}},{"id":"external-reliance-decision-evidence","kind":"maturity","status":"recorded-zero","owners":["/","/evidence","/status","/participate"],"evidence_refs":["glyph/data/evidence-contract.json","glyph/data/external-reliance-decisions/ledger.json","glyph/data/external-reliance-decisions/intake-context.json","glyph/data/external-reliance-decisions/intake-key.json","glyph/data/external-reliance-decisions/intake-key.schema.json","glyph/data/external-reliance-decisions/intake-test-result.json","glyph/data/external-reliance-decisions/ledger.schema.json","glyph/data/external-reliance-decisions/member.schema.json","glyph/data/external-reliance-decisions/record.schema.json","glyph/data/external-reliance-decisions/PROFILE.md","glyph/data/external-reliance-decisions/WIRE-FORMAT.md","glyph/data/external-reliance-decisions/THREAT-MODEL.md","glyph/data/external-reliance-decisions/FIRST-D.md","glyph/scripts/build_external_reliance_intake_test.py","glyph/scripts/check_external_reliance_evidence.py","glyph/scripts/external_reliance_intake.py","glyph/scripts/verify-intake-test-result.mjs","glyph/scripts/test-intake-test-result.mjs","glyph/scripts/replay_external_reliance_runtime.py","bulla/tests/test_external_reliance_evidence.py","bulla/src/bulla/reliance.py"],"statements":["D counts a unique receiver-signed boundary receipt only after its bulla.rely decision recomputes under the named published ReliancePolicy and an accepted intake signer binds the candidate package, control findings, reviewer identity, runtime replay, and qualification time.","The public ledger is D0 · intake open; candidate packets are NOT_COUNTED until a signed qualification event and head merge.","A supplied-checker replay does not increment D."],"limitation":"A qualified D record establishes one signed receiver-policy computation over supplied records and an attributed intake determination about organizational control. It does not mathematically establish organizational independence, provider-claim truth, policy suitability, actor time, or any later payment, deployment, control grant, or handoff.","plain_limitation":"D records a signed receiver-policy computation and an attributable intake review. It does not prove organizational independence, later action, or the underlying provider claim.","agent_projection":{"statement":"The public ledger is D0 · intake open; candidate packets are NOT_COUNTED until a signed qualification event and head merge.","tasks":["prepare an external reliance candidate","inspect the D evidence rule"],"routes":["/","/evidence","/status","/participate"],"never_infer":["A qualified D record establishes one signed receiver-policy computation over supplied records and an attributed intake determination about organizational control. It does not mathematically establish organizational independence, provider-claim truth, policy suitability, actor time, or any later payment, deployment, control grant, or handoff."]}},{"id":"retained-evidence-drill-result","kind":"research-status","status":"computed","owners":["/","/research/retained-evidence","/evidence"],"evidence_refs":["glyph/data/retained-evidence-drill/PROFILE.md","glyph/data/retained-evidence-drill/WIRE-FORMAT.md","glyph/data/retained-evidence-drill/THREAT-MODEL.md","glyph/data/retained-evidence-drill/report.json","glyph/src/lib/retained-evidence.generated.json","glyph/scripts/generate-retained-evidence-drill.mjs","glyph/scripts/test-retained-evidence-drill.mjs","bulla/spec/answerability-network/kernel.mjs","bulla/spec/witness-covenant/kernel.mjs","bulla/spec/reliance-map/kernel.mjs"],"statements":["The retained packet reproduces the published judgment from packet members alone; repository input and prior receiver state are not supplied, installed Bulla is not used, and no Glyph Standard route is requested.","Authentic fork evidence alone establishes the witness conflict but does not authorize propagation.","When an accepted correction notice is added, the receiver recomputes the declared recheck set from retained artifacts.","In the frozen fixture, the transaction record digest remains unchanged while the published, fault-observed, and corrected judgment digests differ.","In the frozen fixture, declared lineage reduces the review set from 10,000 to 5,000 without clearing incomplete ancestry."],"limitation":"The packet establishes local historical reproduction under supplied verifiers and receiver contexts. Its launcher blocks enumerated Node network interfaces but does not establish operating-system network isolation. It does not establish freshness, current revocation or external state, independent operation, occurrence, worldly truth, custody, settlement, causal independence, or completeness beyond the accepted declaration.","plain_limitation":"The retained packet reproduces a historical result from supplied artifacts. It does not establish current external state or make declared separation a proof of causal independence.","agent_projection":{"statement":"The retained packet reproduces the published judgment from packet members alone; repository input and prior receiver state are not supplied, installed Bulla is not used, and no Glyph Standard route is requested.","tasks":["reproduce the retained-evidence drill","inspect the judgment delta","compare the review-all control"],"routes":["/research/retained-evidence","/evidence"],"never_infer":["The packet establishes local historical reproduction under supplied verifiers and receiver contexts. Its launcher blocks enumerated Node network interfaces but does not establish operating-system network isolation. It does not establish freshness, current revocation or external state, independent operation, occurrence, worldly truth, custody, settlement, causal independence, or completeness beyond the accepted declaration."]}},{"id":"compute-contract-drill-result","kind":"research-status","status":"computed","owners":["/research/compute-contract-drill","/evidence"],"evidence_refs":["glyph/data/compute-contract-drill/PROFILE.md","glyph/data/compute-contract-drill/WIRE-FORMAT.md","glyph/data/compute-contract-drill/THREAT-MODEL.md","glyph/data/compute-contract-drill/report.schema.json","glyph/data/compute-contract-drill/report.json","glyph/src/lib/compute-contract-drill.generated.json","glyph/scripts/generate-compute-contract-drill.mjs","glyph/scripts/test-compute-contract-drill.mjs","bulla/spec/attestation-boundary/PROFILE.md","bulla/spec/attestation-boundary/generated/report.json","docs/research/witness-assurance/v0.2/README.md","docs/research/witness-assurance/v0.2/generated-report.json","bulla/spec/answerability-network/kernel.mjs","bulla/spec/reliance-map/kernel.mjs"],"statements":["The public AIR and NVIDIA artifacts verify within their separate scopes but do not share an authenticated event binding; the execution relation is NOT_ESTABLISHED and the source-only receiver policy returns ESCALATE.","A project-operated constructed control binds the six declared fixture dimensions and reaches RELY under the source-only receiver policy.","The constructed control moves no funds, establishes no externality, and increments no W, D, I, or replay counter."],"limitation":"The drill is a project-operated, fixture-bound evaluator reachability result. It does not establish live H100 execution, worldly occurrence, provider identity, organizational independence, production reliance, legal effect, enforceability, collectibility, external custody, real settlement, or completeness outside its declared packet and receiver policy.","plain_limitation":"The public artifacts remain unbound and the constructed acceptance is a project-operated control, not production assurance.","agent_projection":{"statement":"The public AIR and NVIDIA artifacts verify within their separate scopes but do not share an authenticated event binding; the execution relation is NOT_ESTABLISHED and the source-only receiver policy returns ESCALATE.","tasks":["inspect the six-dimensional claim matrix","reproduce the Compute Contract Drill","compare the unbound case with the project-operated closed control"],"routes":["/research/compute-contract-drill","/evidence"],"never_infer":["The drill is a project-operated, fixture-bound evaluator reachability result. It does not establish live H100 execution, worldly occurrence, provider identity, organizational independence, production reliance, legal effect, enforceability, collectibility, external custody, real settlement, or completeness outside its declared packet and receiver policy."]}},{"id":"evidence-locked-consequence-result","kind":"research-status","status":"computed","owners":["/research/evidence-locked-consequence","/evidence"],"evidence_refs":["bulla/spec/control-plane-alpha/effect-lock/PROFILE.md","bulla/spec/control-plane-alpha/effect-lock/WIRE-FORMAT.md","bulla/spec/control-plane-alpha/effect-lock/THREAT-MODEL.md","bulla/spec/control-plane-alpha/effect-lock/drill/PROFILE.md","bulla/spec/control-plane-alpha/effect-lock/drill/report.json","bulla/spec/control-plane-alpha/effect-lock/drill/report.schema.json","packages/bulla-control-plane-alpha/scripts/generate-effect-lock-drill.mjs","packages/bulla-control-plane-alpha/scripts/test-effect-lock-drill.mjs","packages/bulla-control-plane-alpha/scripts/test-effect-lock-schemas.mjs","glyph/scripts/generate-effect-lock-evidence.mjs","glyph/src/lib/effect-lock.generated.json"],"statements":["Inside the closed project-operated receiver fixture, the protected state append is reachable through the candidate target only after the target verifies the exact required records and consumes one receiver-issued grant. One grant produces at most one committed effect."],"limitation":"Scope is limited to the closed project-operated fixture and its declared route graph. Nothing here establishes cloud or platform administrator containment, absence of copied receiver credentials, source or deployment immutability, worldly truth, policy correctness, provider execution, undisclosed external effects, production safety, or legal effect. Packet reproduction verifies retained records and disposition; it does not re-execute the Durable Objects runtime.","plain_limitation":"Candidate separation covers one protected append inside the declared project-operated receiver fixture. It does not establish that a deployment or platform administrator cannot bypass the boundary.","agent_projection":{"statement":"Inside the closed project-operated receiver fixture, the protected state append is reachable through the candidate target only after the target verifies the exact required records and consumes one receiver-issued grant. One grant produces at most one committed effect.","tasks":["compare the baseline bypass with the receiver-owned lock","reproduce the three effect-lock dispositions","inspect the retained grant, effect record, and state roots"],"routes":["/research/evidence-locked-consequence","/evidence"],"never_infer":["Scope is limited to the closed project-operated fixture and its declared route graph. Nothing here establishes cloud or platform administrator containment, absence of copied receiver credentials, source or deployment immutability, worldly truth, policy correctness, provider execution, undisclosed external effects, production safety, or legal effect. Packet reproduction verifies retained records and disposition; it does not re-execute the Durable Objects runtime."]}},{"id":"bulla-product-identity","kind":"maturity","status":"normative","owners":["/","/bulla","/about"],"evidence_refs":["glyph/COPY-STANDARDS.md","bulla/spec/action-receipt-v0.2.md","bulla/releases/pypi-project.json","bulla/src/bulla/reliance.py","bulla/src/bulla/coverage.py"],"statements":["Receipts for Agents.","Bulla is the answerability protocol family published by Glyph Standard.","ActionReceipt is Bulla's stable transaction format.","Bulla is the answerability protocol family published by Glyph Standard; ActionReceipt is its stable transaction format.","Bulla's category is Answerable Computing; its technical property is Transaction Answerability.","The installed Bulla package creates and verifies ActionReceipts, applies a caller-supplied ReliancePolicy, and reconciles receipts with supplied receiver records.","Glyph Standard develops Bulla.","Bulla is Glyph Standard's shipped system for Answerable Computing.","Glyph Standard develops Bulla, its shipped system for Answerable Computing. ActionReceipt is Bulla's stable transaction format."],"limitation":"Repository-source research profiles are outside the installed package unless a published release explicitly includes them.","agent_projection":{"statement":"Bulla is the answerability protocol family published by Glyph Standard; ActionReceipt is its stable transaction format.","tasks":["choose between the stable package and a repository-source profile"],"routes":["/","/bulla"],"never_infer":["Repository-source research profiles are outside the installed package unless a published release explicitly includes them."]}},{"id":"reliance-policy-presets","kind":"security","status":"implemented","owners":["/bulla","/buyers"],"evidence_refs":["glyph/data/published-reliance-policies.json","bulla/src/bulla/action_receipt.py","bulla/src/bulla/reliance.py","bulla/tests/test_reliance.py"],"statements":["Bulla 0.48.0 publishes named strict, pragmatic, and evidence-strict ReliancePolicy definitions whose canonical hashes bind their exact accepted states.","Strict excludes unresolved and adverse temporal or revocation states; it accepts within_window or not_applicable for temporal status and not_revoked or not_applicable for revocation status. Pragmatic additionally accepts unresolved for both.","Evidence-strict retains the strict policy states and requires receiver-verified evidence grounding of third_party_anchored or execution_verified.","Receipt-carried grounding labels alone do not satisfy evidence-strict. The receiver supplies the exact digest-to-class context, and Bulla binds that context by hash when it records a signed bulla.rely decision.","ReliancePolicy outcomes remain RELY, REFUSE, or ESCALATE; the application decides what downstream action, if any, follows."],"limitation":"A ReliancePolicy computes a local decision over receiver-supplied verification fields. Receiver acceptance of an evidence-grounding context does not establish provider truth, occurrence, independence, custody, settlement, downstream effect, legal sufficiency, risk suitability, or a universal default.","agent_projection":{"statement":"Bulla 0.48.0 publishes named strict, pragmatic, and evidence-strict ReliancePolicy definitions whose canonical hashes bind their exact accepted states.","tasks":["choose a receiver policy","pin a policy hash","supply an evidence-grounding context","recompute RELY, REFUSE, or ESCALATE"],"routes":["/buyers"],"never_infer":["A ReliancePolicy computes a local decision over receiver-supplied verification fields. Receiver acceptance of an evidence-grounding context does not establish provider truth, occurrence, independence, custody, settlement, downstream effect, legal sufficiency, risk suitability, or a universal default."]}}]}