Operate / Institutions
Institution launch outcome
Operate governed proof, identity, settlement, evidence, exceptions, custody, and release controls as one exact system.
Implementation rail · governance controls, conformance matrix, evidence register, and release attestation
Exact execution and operator checks
- 01
Operator check
Assign institutional control owners
Bind each law, proof, identity, Settlement, custody, exception, evidence, signature, release, and recovery control to an owner and exact source.
Substantive records: /trust/governance · /trust/hierarchy
Expected: Separation of duties and evidence ownership are explicit.
- 02
Exact mechanic
Run governance:check
pnpm governance:check- Mechanic
- pnpm governance:check
- Authentication and account boundary
- Authorized local repository checkout; the command proves only the checked repository boundary.
- Exact source
package.json· SHA-256 132f99232dfaf26f7186b73752938d1377042808f42d60d374fe7b2e57c7646b
Expected: Required controls, owners, exceptions, and policy bindings pass.
- 03
Exact mechanic
Run governance:evidence-check
pnpm governance:evidence-check- Mechanic
- pnpm governance:evidence-check
- Authentication and account boundary
- Authorized local repository checkout; the command proves only the checked repository boundary.
- Exact source
package.json· SHA-256 132f99232dfaf26f7186b73752938d1377042808f42d60d374fe7b2e57c7646b
Expected: Every institutional claim has exact admissible evidence.
- 04
Operator check
Qualify release and continuity
Verify governance signatures, run primitive conformance, bind dated deployment and smoke evidence, test key rotation and incident recovery, and retain explicit non-claims for unobserved state.
Substantive records: /reference/releases · /trust/exceptions
Expected: The institution operates one evidence-bound system without authority inversion.
Complete operating anatomy
Every boundary required to ship.
- Solved outcome
- Every institutional claim maps to law, sealed evidence, an executable check, a failure meaning, recovery, custody, and explicit non-claim.
- Prerequisites
- Hold the institutional law register, primitive inventory, control owners, separation of duties, evidence register, exception register, key custody, conformance matrix, release process, incident procedure, retention policy, and production observation plan.
- Exact primitive
- institutional proof and governance
- Governing law
- Institution launch outcome is governed by governance-controls: Required control records exist and satisfy the script's exact structural checks. governance-evidence: Registered evidence entries satisfy the checker's exact presence, binding, and status rules. authority-boundaries: Assigned control custody remains separated by recorded boundary.
- Source-of-truth order
- Receiz law → sealed artifact truth → deterministic proof object state → verified durable local or register truth → authenticated snapshot → server distribution, synchronization, indexing, and publication → database, session, observability, and interface projections.
- Expected artifact, receipt, or state
- A checked governance and evidence package with named owners, boundaries, exceptions, signatures, and dated release evidence.
- Inspection
- Inspect the control boundary, evidence digest, conformance result, exception status, signature, and attestation binding. Inspection exposes structure and receipt fields; inspection never establishes verification.
- Independent verification
- Independent verification for institution-outcome: pnpm governance:check && pnpm governance:evidence-check && pnpm governance:verify-artifact-signature. This establishes only the institutional proof and governance boundary named by the bound sources; The implementation rail remains beneath proof authority: governance controls, conformance matrix, evidence register, and release attestation.
- Offline behavior
- Committed governance, evidence, signatures, and proof artifacts remain inspectable and verifiable locally.
- Identity and account boundary
- Public Record Moment, Seal File, Verify, Export, and public proof reading are account-free. Identity is optional and adds continuity, custody, recovery, and governed private controls after proof admission.
- Security boundary
- Assign custody and separation of duties, preserve immutable evidence, rotate controlled keys, and never infer unobserved production operation.
- Conformance command
pnpm governance:check- Deployment checks
- Qualify every control against exact source and evidence, run governance and primitive conformance, verify signatures, test exception expiry, key rotation, incident containment, continuity, release attestation, deployment, smoke, rollback, and audit retrieval.
- Production checklist
- Map owners; validate sources; run governance; run evidence; verify signatures; inspect exceptions; execute rotation drill; execute incident drill; run primitive suites; attest release; observe deployment and smoke; rehearse rollback; retrieve audit package.
- Rollback and containment
- Containment for institution-outcome: Institutional qualification fails. Bind the missing field and rerun governance checks. The exception is invalid. Close the gap or issue a newly authorized bounded exception. The affected institutional claim is rejected. Contain the boundary and regenerate only from exact authorized evidence. Preserve every stronger held artifact and admitted state while the named boundary is corrected.
Fail closed
Mutation and failure matrix
A control lacks an owner, source, evidence, or exact non-claim.
- Effect
- Institutional qualification fails.
- Retry
- Do not accept policy prose alone.
- Recovery
- Bind the missing field and rerun governance checks.
An exception is expired, unsigned, overbroad, or hides a primitive regression.
- Effect
- The exception is invalid.
- Retry
- Do not extend it implicitly.
- Recovery
- Close the gap or issue a newly authorized bounded exception.
Evidence signature, digest, release, deployment, or smoke dimension disagrees.
- Effect
- The affected institutional claim is rejected.
- Retry
- Do not collapse dimensions into a pass.
- Recovery
- Contain the boundary and regenerate only from exact authorized evidence.
Exact authority
Claim-to-source bindings
Required control records exist and satisfy the script's exact structural checks.
scripts/check_governance_controls.tsgovernance-control · SHA-256 8fa9d6429e8775c2fbea9b731078aab4a7d978f649bd6323d01b1199e8c7c4a8Registered evidence entries satisfy the checker's exact presence, binding, and status rules.
scripts/check_governance_evidence.tsevidence-register · SHA-256 4d887a3943808bec1f3d274b02bd4cf7cfc9f3b39c5e34169c709ddc97c8263cAssigned control custody remains separated by recorded boundary.
docs/governance/control-boundaries.v1.mdnormative-governance · SHA-256 da31636848c373e8d54e8d101885e15a9a29f7f8a734cf5fe675b7e7d5ec166e
One complete system