{
  "schema_version": 1,
  "generated_at": "2026-08-01",
  "refresh": "regenerated with each release and each deployment",
  "registry": {
    "schema_version": 3,
    "as_of": "2026-08-01",
    "title": "What Exists Today",
    "capabilities": [
      {
        "id": "action-receipt",
        "label": "ActionReceipt",
        "maturity": "released",
        "availability": "PYPI_RELEASED",
        "established": "Portable ActionReceipt v0.2 records, canonical hashing, cryptographic verification, and reference vectors.",
        "not_established": "The worldly truth of the recorded claim or occurrence of the underlying event.",
        "evidence_class": "released implementation and reproducible fixtures",
        "evidence_provenance": {
          "author_origin": "TEAM_AUTHORED",
          "adjudication_origin": "MACHINE_CHECKED",
          "replay_mode": "INTERNAL_REPRODUCIBLE",
          "closure_warrant": "NOT_APPLICABLE"
        },
        "canonical_refs": [
          "bulla/spec/action-receipt-v0.2.md",
          "bulla/spec/vectors/expected.json"
        ],
        "external_counts": {
          "authors": 0,
          "adjudicators": 0,
          "implementations": 0,
          "witnesses": 0
        },
        "supersession_refs": [],
        "correction_refs": [
          "bulla/spec/action-receipt-v0.4-draft.md"
        ],
        "external_replays": 0
      },
      {
        "id": "authority-scope",
        "label": "Authority and scope",
        "maturity": "released-draft",
        "availability": "PYPI_RELEASED",
        "established": "Opt-in v0.3 implementation binds issuer authorization, delegation, and structured scope checks.",
        "not_established": "The legality, legitimacy, or institutional sufficiency of the authored authority policy.",
        "evidence_class": "released draft with local conformance fixtures",
        "evidence_provenance": {
          "author_origin": "TEAM_AUTHORED",
          "adjudication_origin": "MACHINE_CHECKED",
          "replay_mode": "INTERNAL_REPRODUCIBLE",
          "closure_warrant": "NOT_APPLICABLE"
        },
        "canonical_refs": [
          "bulla/spec/action-receipt-v0.3-draft.md",
          "bulla/spec/delegation-design-note.md"
        ],
        "external_counts": {
          "authors": 0,
          "adjudicators": 0,
          "implementations": 0,
          "witnesses": 0
        },
        "supersession_refs": [],
        "correction_refs": [
          "bulla/spec/action-receipt-v0.4-draft.md"
        ],
        "external_replays": 0
      },
      {
        "id": "strict-receipt-ingestion",
        "label": "Strict receipt ingestion",
        "maturity": "released-draft",
        "availability": "PYPI_RELEASED",
        "established": "A single byte-oriented parser rejects duplicate members, non-finite values, off-schema closed objects, and declared size, depth, node, and string limits before cryptographic verification.",
        "not_established": "Independent hostile-input review or immunity to every parser implementation defect.",
        "evidence_class": "published in Bulla 0.44.4 with internal adversarial fixtures",
        "evidence_provenance": {
          "author_origin": "TEAM_AUTHORED",
          "adjudication_origin": "MACHINE_CHECKED",
          "replay_mode": "INTERNAL_REPRODUCIBLE",
          "closure_warrant": "NOT_APPLICABLE"
        },
        "canonical_refs": [
          "bulla/src/bulla/receipt_parser.py",
          "bulla/tests/test_action_receipt_v04.py",
          "bulla/releases/0.44.4.json"
        ],
        "external_counts": {
          "authors": 0,
          "adjudicators": 0,
          "implementations": 0,
          "witnesses": 0
        },
        "supersession_refs": [],
        "correction_refs": [],
        "external_replays": 0
      },
      {
        "id": "action-receipt-v04",
        "label": "ActionReceipt v0.4 occurrence binding",
        "maturity": "released-draft",
        "availability": "PYPI_RELEASED",
        "established": "The draft separately authenticates content, one claimed occurrence, and its authority envelope under a portable integer-only canonical data model; Python and Node reference checkers agree on the fixed vector.",
        "not_established": "Worldly occurrence, witnessed time, cross-platform independent parity, or promotion over the normative v0.2 default.",
        "evidence_class": "opt-in draft published in Bulla 0.44.4 with internal cross-language reference checks",
        "evidence_provenance": {
          "author_origin": "TEAM_AUTHORED",
          "adjudication_origin": "MACHINE_CHECKED",
          "replay_mode": "INTERNAL_REPRODUCIBLE",
          "closure_warrant": "NOT_APPLICABLE"
        },
        "canonical_refs": [
          "bulla/spec/action-receipt-v0.4-draft.md",
          "bulla/spec/vectors/v04-occurrence-bound.json",
          "bulla/releases/0.44.4.json"
        ],
        "external_counts": {
          "authors": 0,
          "adjudicators": 0,
          "implementations": 0,
          "witnesses": 0
        },
        "supersession_refs": [],
        "correction_refs": [],
        "external_replays": 0
      },
      {
        "id": "semantic-invention",
        "label": "Semantic invention",
        "maturity": "experimental",
        "availability": "PYPI_RELEASED",
        "established": "Finite FRSL-1 packages and negative certificates are independently replayable on the captive Golden corpus.",
        "not_established": "Foreign generality, open-world completeness, or a stable semantic API.",
        "evidence_class": "internal captive benchmark",
        "evidence_provenance": {
          "author_origin": "TEAM_AUTHORED",
          "adjudication_origin": "MACHINE_PLANTED",
          "replay_mode": "INTERNAL_REPRODUCIBLE",
          "closure_warrant": "FINITE_EXACT"
        },
        "canonical_refs": [
          "bulla/spec/semantic-boundary-v0.3-experimental.md",
          "bulla/bench/golden/v0.3/manifest.json"
        ],
        "external_counts": {
          "authors": 0,
          "adjudicators": 0,
          "implementations": 0,
          "witnesses": 0
        },
        "supersession_refs": [],
        "correction_refs": [],
        "external_replays": 0
      },
      {
        "id": "partial-envelopes",
        "label": "Partial envelopes",
        "maturity": "experimental",
        "availability": "PYPI_RELEASED",
        "established": "Checked RELY and REFUSE regions preserve residual escalation under a declared finite closure warrant.",
        "not_established": "Completeness outside the declared model class or safety under an unmodeled closure expansion.",
        "evidence_class": "internal formal and executable evidence",
        "evidence_provenance": {
          "author_origin": "TEAM_AUTHORED",
          "adjudication_origin": "MACHINE_CHECKED",
          "replay_mode": "INTERNAL_REPRODUCIBLE",
          "closure_warrant": "FINITE_EXACT"
        },
        "canonical_refs": [
          "bulla/bench/golden/v0.3/PROFILE.md",
          "papers/interpolant-envelope/lean/InterpolantEnvelope/GoldenV02.lean"
        ],
        "external_counts": {
          "authors": 0,
          "adjudicators": 0,
          "implementations": 0,
          "witnesses": 0
        },
        "supersession_refs": [],
        "correction_refs": [],
        "external_replays": 0
      },
      {
        "id": "semantic-finality",
        "label": "Semantic Finality",
        "maturity": "experimental",
        "availability": "PYPI_RELEASED",
        "established": "Replayable provisional, reserve, conflict, refinement, finalization, and stale-epoch transitions in a finite shadow model.",
        "not_established": "Production settlement, real custody, collectibility, actuarial value, or institutional efficacy.",
        "evidence_class": "internal state-machine and Golden evidence",
        "evidence_provenance": {
          "author_origin": "TEAM_AUTHORED",
          "adjudication_origin": "MACHINE_PLANTED",
          "replay_mode": "INTERNAL_REPRODUCIBLE",
          "closure_warrant": "BOUNDED_EXACT"
        },
        "canonical_refs": [
          "bulla/src/bulla/experimental/semantic_finality.py",
          "bulla/bench/golden/v0.1/manifest.json"
        ],
        "external_counts": {
          "authors": 0,
          "adjudicators": 0,
          "implementations": 0,
          "witnesses": 0
        },
        "supersession_refs": [],
        "correction_refs": [
          "bulla/bench/golden/v0.2/STATUS.md"
        ],
        "external_replays": 0
      },
      {
        "id": "claim-flow-v04",
        "label": "Claim Flow v0.4",
        "maturity": "experimental",
        "availability": "PYPI_RELEASED",
        "established": "Typed appraisal, forum, precedent, applicability, and settlement transitions with explicit authority provenance.",
        "not_established": "External legal validity, foreign applicability judgments, or automatic institutional authority.",
        "evidence_class": "internal formal and captive benchmark evidence",
        "evidence_provenance": {
          "author_origin": "TEAM_AUTHORED",
          "adjudication_origin": "MACHINE_PLANTED",
          "replay_mode": "INTERNAL_REPRODUCIBLE",
          "closure_warrant": "BOUNDED_EXACT"
        },
        "canonical_refs": [
          "bulla/spec/claim-flow-v0.4-experimental.md",
          "bulla/src/bulla/experimental/claim_flow.py"
        ],
        "external_counts": {
          "authors": 0,
          "adjudicators": 0,
          "implementations": 0,
          "witnesses": 0
        },
        "supersession_refs": [],
        "correction_refs": [],
        "external_replays": 0
      },
      {
        "id": "generalization-v05",
        "label": "Generalization Constitution v0.5",
        "maturity": "experimental",
        "availability": "SOURCE_ONLY",
        "established": "Candidate, adoption, and applicability remain separate, with checked finite safe-scope frontiers and effect-laundering controls.",
        "not_established": "Foreign transfer, external applicability judgments, or a stable precedent API.",
        "evidence_class": "internal formal and captive-control evidence",
        "evidence_provenance": {
          "author_origin": "TEAM_AUTHORED",
          "adjudication_origin": "MACHINE_PLANTED",
          "replay_mode": "INTERNAL_REPRODUCIBLE",
          "closure_warrant": "BOUNDED_EXACT"
        },
        "canonical_refs": [
          "bulla/spec/generalization-constitution-v0.5-experimental.md",
          "bulla/bench/golden/v0.5/PROFILE.md"
        ],
        "external_counts": {
          "authors": 0,
          "adjudicators": 0,
          "implementations": 0,
          "witnesses": 0
        },
        "supersession_refs": [],
        "correction_refs": [],
        "external_replays": 0
      },
      {
        "id": "golden-gate",
        "label": "Golden Gate qualification",
        "maturity": "experimental",
        "availability": "PYPI_RELEASED",
        "established": "The finite checker core supports typed abstention and reproducible qualification; benchmark packets add captive mutation, portability, custody, and control evidence.",
        "not_established": "Reviewer-originated results, independent validation, production safety, or open-world completeness.",
        "evidence_class": "implemented methods with internal captive evidence",
        "evidence_provenance": {
          "author_origin": "TEAM_AUTHORED",
          "adjudication_origin": "MACHINE_PLANTED",
          "replay_mode": "INTERNAL_REPRODUCIBLE",
          "closure_warrant": "BOUNDED_EXACT"
        },
        "canonical_refs": [
          "bulla/src/bulla/experimental/golden.py",
          "bulla/bench/golden/v0.3/PROFILE.md",
          "papers/golden-gate/paper.md"
        ],
        "external_counts": {
          "authors": 0,
          "adjudicators": 0,
          "implementations": 0,
          "witnesses": 0
        },
        "supersession_refs": [],
        "correction_refs": [],
        "external_replays": 0
      },
      {
        "id": "receipt-coupled-dispatch",
        "label": "Receipt-coupled dispatch",
        "maturity": "experimental",
        "availability": "SOURCE_ONLY",
        "established": "The reference boundary durably commits an authorized intent before external I/O, preserves uncertain outcomes, enforces committed adapter capabilities, and prevents duplicate effects under its captive verified-idempotency contract.",
        "not_established": "Distributed atomicity, production payment safety, external adapter conformance, or nonlocal integration value.",
        "evidence_class": "internal exhaustive model, crash fixtures, and captive adapters",
        "evidence_provenance": {
          "author_origin": "TEAM_AUTHORED",
          "adjudication_origin": "MACHINE_CHECKED",
          "replay_mode": "INTERNAL_REPRODUCIBLE",
          "closure_warrant": "BOUNDED_EXACT"
        },
        "canonical_refs": [
          "bulla/src/bulla/experimental/action_boundary.py",
          "bulla/bench/golden/v0.6/report.json"
        ],
        "external_counts": {
          "authors": 0,
          "adjudicators": 0,
          "implementations": 0,
          "witnesses": 0
        },
        "supersession_refs": [],
        "correction_refs": [],
        "external_replays": 0
      },
      {
        "id": "agent-incident-packet",
        "label": "Agent Incident Packet v0.1",
        "maturity": "experimental",
        "availability": "SOURCE_ONLY",
        "established": "The source profile requires an exact decision/effect anchor pair for each represented protocol and binds each reported denominator snapshot to a signed checkpoint whose issuer is accepted through external role context. Live timeline and publish receipts use ActionReceipt v0.4 with conventions: []; convention-bearing historical receipts remain opaque evidence artifacts only. Team-operated fixtures also bind non-circular redaction records and accepted reviewer statements, party statements, corrections, and witness evidence without collapsing their verification dimensions.",
        "not_established": "A packet supports zero or one witness reference. Multiple-witness aggregation remains unresolved. Cross-runtime convention evaluation, denominator completeness, organizational independence, production containment, disclosure safety, external implementation parity, independent witnessing, and incident truth also remain unestablished. The empty-convention rule narrows this experimental profile and does not change ActionReceipt v0.4. An accepted observer can self-shorten rows.",
        "evidence_class": "team-operated deterministic fixtures and isolated localhost HTTP/MCP pilots",
        "evidence_provenance": {
          "author_origin": "TEAM_AUTHORED",
          "adjudication_origin": "MACHINE_CHECKED",
          "replay_mode": "INTERNAL_REPRODUCIBLE",
          "closure_warrant": "NOT_APPLICABLE"
        },
        "canonical_refs": [
          "bulla/spec/agent-incident-packet/PROFILE.md",
          "bulla/src/bulla/experimental/incident_packet.py",
          "bulla/spec/agent-incident-packet/expected-verdict.json"
        ],
        "external_counts": {
          "authors": 0,
          "adjudicators": 0,
          "implementations": 0,
          "witnesses": 0
        },
        "supersession_refs": [],
        "correction_refs": [],
        "external_replays": 0
      },
      {
        "id": "inference-clearing-alpha",
        "label": "Recheckable Inference alpha",
        "maturity": "experimental",
        "availability": "SOURCE_ONLY",
        "established": "Two synthetic providers return byte-identical BACKUP artifacts. After both provider processes terminate, the retained, term-bound integer model reproduces one input-to-output relation while the opaque record supplies no model to rerun. Under the separately supplied buyer policy, the first relation is payment-eligible but not authorized or settled; the opaque response is refused. Adding one unmatched receiver effect leaves receipt integrity verified, changes coverage from 1/1 to 1/2, and makes payment ineligible. Project-authored Python, standalone Node, and browser verifiers reproduce these bounded reports.",
        "not_established": "Historical provider execution, answer truth, model quality, complete receiver denominators, payment execution, external implementation parity, organizational independence, custody, collectibility, production clearing, or worldly truth. All roles and evidence remain synthetic and team-controlled.",
        "evidence_class": "three deterministic bundles, team-operated localhost roles, project-authored Python, standalone Node, and browser parity, transient hostile mutations, and a finite abstract model",
        "evidence_provenance": {
          "author_origin": "TEAM_AUTHORED",
          "adjudication_origin": "MACHINE_CHECKED",
          "replay_mode": "INTERNAL_REPRODUCIBLE",
          "closure_warrant": "FINITE_EXACT"
        },
        "canonical_refs": [
          "bulla/spec/inference-clearing/PROFILE.md",
          "bulla/spec/inference-clearing/expected-verdict.json",
          "bulla/spec/inference-clearing/inference-clearing-reproduction-kit.tar.sha256",
          "bulla/src/bulla/experimental/inference_clearing.py"
        ],
        "external_counts": {
          "authors": 0,
          "adjudicators": 0,
          "implementations": 0,
          "witnesses": 0
        },
        "supersession_refs": [],
        "correction_refs": [],
        "external_replays": 0
      },
      {
        "id": "assurance-linker-alpha",
        "label": "Assurance Linker alpha",
        "maturity": "experimental",
        "availability": "SOURCE_ONLY",
        "established": "The source profile deterministically compiles a closed structured promise into explicit evidence, authority, coverage, capital, recourse, and consequence requirements. Python and standalone Node verifiers agree on eight team-authored dossiers. The checked fixture comparison shows that receipt integrity remains VERIFIED while a receiver-recorded bypass changes required coverage from COVERED to UNCOVERED and payment from ELIGIBLE to INELIGIBLE. The finite formal model checks eight assurance invariants. A Bitcoin Core 31.1 regtest adapter demonstrates synthetic rail mechanics while preserving the rail-neutral report. Trial 0.2-r5 preserves the r4 semantic root exactly and adds a deterministic publication bundle, two-mirror retrieval requirements, dimensional checker-source provenance, and interleaved recruitment.",
        "not_established": "No anonymous two-mirror publication set, cold-reader calibration, candidate round, or foreign checker attempt has occurred for Trial 0.2-r5; recruitment and blind execution remain unauthorized. Foreign authorability, independent checker reproduction, external institutional handling, operational separation, marginal decision value, economic adoptability, representative developer demand, worldly truth, complete denominators, external collateral encumbrance, custody, collectibility, legal enforceability, organizational independence, production safety, actuarial calibration, source-to-image correspondence, or mainnet readiness remain unestablished. Recruitment uses investigator-selected, uncompensated volunteers. The Bitcoin adapter is optional and does not evaluate predicates or replace the named settlement authority.",
        "evidence_class": "team-authored deterministic fixtures, team-authored checker parity, finite abstract-model checks, one local Bitcoin Core regtest execution, and a team-operated Trial 0.2-r5 publication-neutral checker doorway",
        "evidence_provenance": {
          "author_origin": "TEAM_AUTHORED",
          "adjudication_origin": "MACHINE_CHECKED",
          "replay_mode": "INTERNAL_REPRODUCIBLE",
          "closure_warrant": "FINITE_EXACT"
        },
        "canonical_refs": [
          "bulla/spec/assurance-linker/PROFILE.md",
          "bulla/spec/assurance-linker/expected-verdict.json",
          "bulla/spec/assurance-linker/formal-fixture-map.json",
          "bulla/spec/assurance-linker/trial-v0.2/results.json",
          "bulla/spec/assurance-linker/trial-v0.2/freeze.json",
          "bulla/spec/assurance-linker/stranger-doorway-v0.2-r5/readiness.json",
          "bulla/spec/assurance-linker/stranger-doorway-v0.2-r5/correction.json",
          "bulla/spec/assurance-linker/stranger-doorway-v0.2-r5/scoring-capsule-freeze.json",
          "bulla/spec/assurance-linker/stranger-doorway-v0.2-r5/prior-revisions-preservation.json",
          "bulla/spec/assurance-linker/stranger-doorway-v0.2-r5/semantic-root.json",
          "bulla/spec/assurance-linker/stranger-doorway-v0.2-r5/ceremony-root.json",
          "bulla/spec/assurance-linker/stranger-doorway-v0.2-r5/trial-envelope.json",
          "bulla/spec/assurance-linker/stranger-doorway-v0.2-r5/corpus-reuse.json",
          "bulla/spec/assurance-linker/stranger-doorway-v0.2-r5/publication-identity.json",
          "papers/interpolant-envelope/lean/InterpolantEnvelope/AssuranceLinker.lean"
        ],
        "external_counts": {
          "authors": 0,
          "adjudicators": 0,
          "implementations": 0,
          "witnesses": 0
        },
        "supersession_refs": [
          "bulla/spec/assurance-linker/stranger-doorway-v0.2-r5/correction.json"
        ],
        "correction_refs": [
          "bulla/spec/assurance-linker/stranger-doorway-v0.2-r5/correction.json"
        ],
        "external_replays": 0
      },
      {
        "id": "executable-recourse",
        "label": "Executable recourse",
        "maturity": "experimental",
        "availability": "SOURCE_ONLY",
        "established": "A local receipt trace can open, acknowledge, evidence, decide, authorize, complete, route, expire, and close a challenge while keeping forum and remedy authority distinct.",
        "not_established": "A separately controlled forum, operational reachability, institutional efficacy, or automatic enforcement of a semantic finding.",
        "evidence_class": "internal replay and authority-separation fixtures; reachability captive",
        "evidence_provenance": {
          "author_origin": "TEAM_AUTHORED",
          "adjudication_origin": "MACHINE_CHECKED",
          "replay_mode": "INTERNAL_REPRODUCIBLE",
          "closure_warrant": "BOUNDED_EXACT"
        },
        "canonical_refs": [
          "bulla/src/bulla/experimental/challenge.py",
          "bulla/tests/test_executable_challenge.py"
        ],
        "external_counts": {
          "authors": 0,
          "adjudicators": 0,
          "implementations": 0,
          "witnesses": 0
        },
        "supersession_refs": [],
        "correction_refs": [],
        "external_replays": 0
      },
      {
        "id": "precedent-compounding",
        "label": "Precedent compounding",
        "maturity": "research",
        "availability": "RESEARCH_ONLY",
        "established": "Compounding was observed in a team-authored, machine-planted, bounded-exact lineage benchmark and survives the declared captive controls.",
        "not_established": "Generalized compounding on foreign meanings, independent adjudication, or economic value.",
        "evidence_class": "internal captive observation",
        "evidence_provenance": {
          "author_origin": "TEAM_AUTHORED",
          "adjudication_origin": "MACHINE_PLANTED",
          "replay_mode": "INTERNAL",
          "closure_warrant": "BOUNDED_EXACT"
        },
        "canonical_refs": [
          "bulla/bench/golden/v0.4/interpretation.json",
          "bulla/bench/golden/v0.5/report.json"
        ],
        "external_counts": {
          "authors": 0,
          "adjudicators": 0,
          "implementations": 0,
          "witnesses": 0
        },
        "supersession_refs": [
          "bulla/bench/golden/v0.5/PROFILE.md"
        ],
        "correction_refs": [
          "bulla/bench/golden/v0.4/INTERPRETATION.md"
        ],
        "external_replays": 0
      },
      {
        "id": "control-plane-alpha",
        "label": "Public control-plane alpha candidate",
        "maturity": "experimental",
        "availability": "SOURCE_ONLY",
        "established": "Deterministic fixtures, source checkers, and local Cloudflare-runtime tests exercise one closed synthetic MCP authorization, receiver, denominator, witness, coverage, and packet-publication loop.",
        "not_established": "The generated control-plane evidence ledger reports whether a public endpoint has tracked deployment evidence. Customer authority, denominator completeness, organizational independence, production safety, and incident truth remain unestablished.",
        "evidence_class": "team-authored deterministic fixtures and local Cloudflare-runtime tests",
        "evidence_provenance": {
          "author_origin": "TEAM_AUTHORED",
          "adjudication_origin": "MACHINE_CHECKED",
          "replay_mode": "INTERNAL_REPRODUCIBLE",
          "closure_warrant": "BOUNDED_EXACT"
        },
        "canonical_refs": [
          "bulla/spec/control-plane-alpha/PROFILE.md",
          "bulla/spec/control-plane-alpha/expected-verdict.json",
          "packages/bulla-control-plane-alpha/README.md"
        ],
        "external_counts": {
          "authors": 0,
          "adjudicators": 0,
          "implementations": 0,
          "witnesses": 0
        },
        "supersession_refs": [],
        "correction_refs": [],
        "external_replays": 0
      },
      {
        "id": "witness-plurality",
        "label": "Witness plurality",
        "maturity": "blocked",
        "availability": "BLOCKED",
        "established": "A local checkpoint and inclusion-proof primitive is specified and tested.",
        "not_established": "Independent witness operators, plurality, stake, or a production witness network.",
        "evidence_class": "local fixture only",
        "evidence_provenance": {
          "author_origin": "TEAM_AUTHORED",
          "adjudication_origin": "MACHINE_CHECKED",
          "replay_mode": "INTERNAL",
          "closure_warrant": "NOT_APPLICABLE"
        },
        "canonical_refs": [
          "bulla/src/bulla/experimental/checkpoint.py",
          "glyph/data/operator-state.json"
        ],
        "external_counts": {
          "authors": 0,
          "adjudicators": 0,
          "implementations": 0,
          "witnesses": 0
        },
        "supersession_refs": [],
        "correction_refs": [],
        "external_replays": 0
      },
      {
        "id": "risk-insurance",
        "label": "Risk and insurance",
        "maturity": "research",
        "availability": "RESEARCH_ONLY",
        "established": "The program contains mathematical ambiguity-reserve and worst-case exposure mechanisms under declared finite models.",
        "not_established": "Underwriter validation, actuarial calibration, product pricing, or real collateral custody.",
        "evidence_class": "internal research architecture",
        "evidence_provenance": {
          "author_origin": "TEAM_AUTHORED",
          "adjudication_origin": "NOT_ADJUDICATED",
          "replay_mode": "INTERNAL",
          "closure_warrant": "BOUNDED_EXACT"
        },
        "canonical_refs": [
          "bulla/src/bulla/experimental/semantic_finality.py",
          "papers/research-status.yaml"
        ],
        "external_counts": {
          "authors": 0,
          "adjudicators": 0,
          "implementations": 0,
          "witnesses": 0
        },
        "supersession_refs": [],
        "correction_refs": [],
        "external_replays": 0
      }
    ],
    "evidence_contract_ref": "glyph/data/evidence-contract.json"
  },
  "evidence_contract": {
    "schema_version": 1,
    "as_of": "2026-07-21",
    "authority": "Normative definitions for the external counters on the status registry. A counter may change only together with evidence that satisfies the definition here. The prose companion is bulla/docs/EVIDENCE-CONTRACT.md; if they disagree, this file governs.",
    "counters": {
      "authors": {
        "label": "External authors",
        "increments_when": "A person or organization outside the team authors previously unseen cases, seams, or interpretations that the system is then evaluated against.",
        "requires": [
          "authored material was not visible to the team before freezing the evaluation",
          "authorship is attributable and disclosed",
          "team assistance limited to format documentation and intake mechanics"
        ],
        "does_not_count": [
          "team-authored cases with external review",
          "synthetic identities or agents operated by the team",
          "cases derived from team-supplied templates with cosmetic changes"
        ]
      },
      "adjudicators": {
        "label": "External adjudicators",
        "increments_when": "A person outside the team decides contested semantic or conformance cases whose outcomes were not known to the team in advance.",
        "requires": [
          "adjudicator is organizationally separate from the team",
          "blind to team-preferred outcomes where the protocol requires blindness",
          "decisions recorded and retained verbatim, including disagreements"
        ],
        "does_not_count": [
          "machine oracles authored by the team",
          "advisory review of team-decided outcomes"
        ]
      },
      "implementations": {
        "label": "Independent implementations",
        "increments_when": "An outside party implements the normative format from the specification, without importing Bulla or adapting team-authored verifier code, and passes the public vectors plus previously unseen adversarial vectors.",
        "requires": [
          "no Bulla imports and no adaptation of team-authored checker source",
          "implementation and build instructions published",
          "byte-identical hashes and equivalent rejection behavior on the vector suite",
          "contact with the team during development documented"
        ],
        "does_not_count": [
          "running a supplied checker on supplied artifacts (see external_replays)",
          "ports produced with team pairing or code review beyond specification clarification"
        ]
      },
      "witnesses": {
        "label": "Independent witnesses",
        "increments_when": "A service under separate organizational control verifies, retains, and proves inclusion of ActionReceipts, publishing signed checkpoints the team does not control.",
        "requires": [
          "separate control domain: distinct legal control, key custody, and operational authority",
          "verified intake, inclusion proofs, consistency proofs, and signed checkpoints",
          "declared retention and privacy policy"
        ],
        "does_not_count": [
          "team-controlled instances on separate infrastructure (fault-domain diversity is not independence)",
          "read-only mirrors of a team-operated log"
        ]
      },
      "external_replays": {
        "label": "External replays",
        "auxiliary": true,
        "never_increments": [
          "implementations"
        ],
        "increments_when": "A person outside the team runs a supplied checker on supplied artifacts and reports the result.",
        "establishes": "An external person reproduced the team's supplied procedure on the team's supplied artifacts.",
        "does_not_establish": "An independent implementation, an external author, or any adjudication."
      }
    },
    "ladder": [
      {
        "evidence": "Outsider runs supplied checker on supplied artifacts",
        "counts_as": "external_replays"
      },
      {
        "evidence": "Outsider writes a second checker from the specification",
        "counts_as": "implementations"
      },
      {
        "evidence": "Outsider authors previously unseen cases",
        "counts_as": "authors"
      },
      {
        "evidence": "Outsider decides contested semantic cases",
        "counts_as": "adjudicators"
      },
      {
        "evidence": "Separately controlled service retains receipts",
        "counts_as": "witnesses"
      }
    ],
    "disclosure": {
      "paid_work": "Paid external participation may count, with the engagement and payment disclosed alongside the evidence.",
      "team_assistance": "Specification clarification and intake mechanics are permitted. Shared code, pairing, debugging of the external artifact, or outcome discussion before freeze disqualify the counter increment."
    },
    "temporal_labels": {
      "claimed_at": "Supplied by the actor. Not bound into the signed occurrence identity under wire v0.2/v0.3; see action-receipt v0.4 draft.",
      "received_at": "Observed by a witness at intake.",
      "witnessed_at": "Included in a signed witness checkpoint.",
      "anchored_before": "Externally timestamped upper bound (for example OpenTimestamps confirmation)."
    },
    "release_coverage": {
      "release_receipt_required_since": "0.44.0",
      "contemporaneous": "producer.minted == post-publication, minted by the release workflow after PyPI acceptance",
      "reconstructed": "retroactively assembled from surviving artifacts; never reclassified as contemporaneous",
      "policy": "Historical unreceipted releases remain missing. The enforcement epoch is immutable."
    }
  }
}
