DGAF / GOVERNANCE

Governance

ConnectingAwaiting first valid snapshot
FAIL-CLOSED LIFECYCLE

Progression is earned one predecessor at a time.

Prepared tooling is shown separately from the state of the predicate it can eventually evaluate. Later readiness never backfills an earlier requirement.

CURRENT FRONTIER

No successor empirical lane designated

PR #881 closes Track A Epoch 002 for its exact preregistered scope as CLOSED_BOUNDED_SAME_SYSTEM_NONINDEPENDENT. Any future independent replication or fresh empirical epoch requires a new controller, preregistration, evidence/custody plan, and explicit authorization; none is designated or authorized here.

accepted TRACK_A_EPOCH_002_POST_INTERPRETATION_DISPOSITION.jsonclosed controller #879new separately governed proposal only if future research is intentionally opened

Do not expose the operator-local numerical interpretation in general projections. Closure does not establish efficacy, independence, production readiness, certification, High-Assurance authorization, scientific-N promotion, or authorization for another empirical epoch.

EVIDENCE ADMISSION PENDING
TEKTITE MUTATION POLICY

Routine workflow mutation is blocked where history or source identity would be reinterpreted.

The dashboard now exposes the #939/#1135 policy projection directly: blocked workflow lanes stay visible as blocked, with the reconciliation action required before any ordinary immutable-action hardening can touch them.

Blocked lanes11
Routine hardening allowed0
Pending reconciliation11
Projection updated2026-09-30
FAIL-CLOSED
HISTORICAL_EXACT_SCOPE

Retired Solo final experiment

BLOCKED

Retired workflow retains historical authority-token text; retirement-contract cleanup must prove no live execution path before #939 pinning.

PATH.github/workflows/pdmal-solo-final-experiment.yml
NEXT ACTIONResolve #1138 before touching this workflow.
  • #1134 exact-head retirement guard failed after checkout succeeded
  • #369 remains blocking for any fresh Solo empirical epoch
SOURCE_BOUND_EVIDENCE

B1 semantic-routing profile

BLOCKED

Profile validators source-bind the workflow by expected hash, so routine YAML mutation would create source-binding drift.

PATH.github/workflows/b1-semantic-routing-safety-profile.yml
NEXT ACTIONPerform explicit source-binding reconciliation before ordinary #939 hardening.
  • audit_catalog.v1.json classifies this as source-bound non-empirical profile evidence
SOURCE_BOUND_EVIDENCE

B2 stateful-context profile

BLOCKED

Profile validators source-bind the workflow by expected hash, so routine YAML mutation would create source-binding drift.

PATH.github/workflows/b2-stateful-context-closure-profile.yml
NEXT ACTIONPerform explicit source-binding reconciliation before ordinary #939 hardening.
  • audit_catalog.v1.json classifies this as source-bound non-empirical profile evidence
SOURCE_BOUND_EVIDENCE

B3 P-33 convergence profile

BLOCKED

Exact-head CI already exposed adjacent validator source-blob drift for this lane.

PATH.github/workflows/b3-p33-convergence-profile.yml
NEXT ACTIONPerform dedicated source-binding reconciliation before ordinary #939 hardening.
  • #1127 exact-head CI exposed source-blob drift
  • workflow is implementation evidence for B3 profile/adjudication lanes
CLOSED_BOUNDED_EXACT_SCOPE

Track A Epoch 002 preregistration

BLOCKED

The retained preregistration workflow still encodes successor-custody absence while successor custody evidence now exists.

PATH.github/workflows/track-a-epoch-002-preregistration.yml
NEXT ACTIONReconcile historical-at-preregistration state from current successor-custody state.
  • successor custody recovery evidence now exists on protected main
  • #1133 documented the stale absence failure
CLOSED_BOUNDED_EXACT_SCOPE

Track A Epoch 002 analysis lock

BLOCKED

The lock-time boundary asserts successor custody is not established, which is no longer true on protected main.

PATH.github/workflows/track-a-epoch-002-analysis-lock.yml
NEXT ACTIONReconcile historical lock-time boundary fields without changing scientific authority.
  • workflow and validator repeat successor_custody_recovery_receipt_established is false
Additional blocked lanes5 more workflow mutation lanes are encoded in the dashboard projection but collapsed here to keep the governance page readable. None grants authorization or widens the current claim ceiling.
SEMANTIC CONTROL FIELD · GOVERNANCE MAP

Reachability is constrained by evidence, authority, and explicit predecessors.

Vertical position shows ordered escalation. Lateral filaments show named cross-stage dependencies. The enclosing frame shows global conditions that apply to the whole field.

GLOBAL FIELD CONDITIONSThese constraints are not lifecycle stages.
PROGRAM
PRE-FREEZE
FAIL MODE
FAIL-CLOSED
AUTHORIZATION
NOT AUTHORIZED
EMPIRICAL N
0
EFFICACY
NOT ESTABLISHED
Custody

Repository custody acceptance

Pass

The exact successor custody certificate and recovery receipt were admitted and accepted.

Inspect claim boundary
EVIDENCE / PROVENANCERecoverability is established at SAME_SYSTEM_NONINDEPENDENT scope.DOES NOT ESTABLISHIndependent custody, independent verification, efficacy, or downstream authority.
Preflight

Precollection preflight

Pass

The successor collection prerequisites were accepted against exact predecessor evidence.

Inspect claim boundary
EVIDENCE / PROVENANCEThe defined precollection checks passed at their accepted identity.DOES NOT ESTABLISHFreeze, authorization, execution, dataset lock, or efficacy.
Freeze

Epoch 002 immutable freeze

Pass

The exact Epoch 002 candidate and prospective inputs are immutably bound.

Inspect claim boundary
EVIDENCE / PROVENANCEThe successor Epoch 002 freeze is established.DOES NOT ESTABLISHThe separate canonical High-Assurance freeze, collection permission, or efficacy.
Closure

Final closure

Pass

The predecessor checklist is accepted as closed for authorization review.

Inspect claim boundary
EVIDENCE / PROVENANCECLOSED_VERIFIED_FOR_AUTHORIZATION_REVIEW at the accepted scope.DOES NOT ESTABLISHAuthorization, execution, unblinding, analysis, or a scientific result.
Verification

Verification classification

Pass

The accepted verification path is explicitly developer self-attested and non-independent.

Inspect claim boundary
EVIDENCE / PROVENANCEThe evidence class and its limitations are explicit and machine-checkable.DOES NOT ESTABLISHIndependent verification or a broader claim than the classified evidence supports.
Authorize

Collection authorization

Pass

A separate human-controlled event authorized the exact bounded Epoch 002 collection.

Inspect claim boundary
EVIDENCE / PROVENANCEAccepted authorization commit 563152fdb254b8ee948a693c287126a8bf8314b8.DOES NOT ESTABLISHDataset lock, unblinding, materialization, primary-analysis authority, or efficacy.
Collect

Blinded empirical collection

Pass

The operator-executed Codespace collection completed at 50 paired seed units / 2,250 blinded observations.

Inspect claim boundary
EVIDENCE / PROVENANCECollection completion is accepted for the authorized Epoch 002 execution.DOES NOT ESTABLISHDataset lock, materialization, canonical N promotion, or efficacy by itself.
Admit evidence

Operator evidence admission

Pass

The bounded operator-retained evidence chain was admitted as the predecessor to dataset lock.

Inspect claim boundary
EVIDENCE / PROVENANCEAcceptance is bounded to the admitted retained evidence and its exact identities.DOES NOT ESTABLISHUnblinding, materialization, primary-analysis authority, independent validation, or efficacy.
QC

Pre-lock structural quality control

Pass

The bounded blinded pre-lock QC/ledger predecessor chain is accepted.

Inspect claim boundary
EVIDENCE / PROVENANCEStructural QC is a predecessor to dataset lock and does not inspect treatment identity for analysis.DOES NOT ESTABLISHTreatment effect, efficacy, materialization, or analysis authority.
Lock

Dataset-lock receipt

Pass

A separate accepted PASS receipt establishes the content-addressed Epoch 002 dataset lock.

Inspect claim boundary
EVIDENCE / PROVENANCETRACK_A_EPOCH_002_DATASET_LOCK = ESTABLISHED at the accepted receipt identity.DOES NOT ESTABLISHUnblinding, materialization, primary analysis, efficacy, or scientific-N promotion.
Unblind

Separate unblinding decision

Pass

A separate accepted human-controlled record authorizes bounded mapping release/decryption only.

Inspect claim boundary
EVIDENCE / PROVENANCEBounded unblinding is authorized; later materialization and analysis authorization remain separate accepted events.DOES NOT ESTABLISHMaterialization, primary-analysis authority, scientific-N promotion, independent validation, or a positive result by itself.
Materialize

Controlled materialization + immutable receipt

Pass

The real analysis-ready unblinded input was materialized under operator control, non-secret evidence was admitted, and a separate immutable receipt was accepted.

Inspect claim boundary
EVIDENCE / PROVENANCEEpoch 002 materialization and its immutable repository receipt are ESTABLISHED at their accepted identities.DOES NOT ESTABLISHPrimary-analysis execution, efficacy, independent validation, or High-Assurance authorization.
Analysis auth

Primary-analysis authorization

Pass

A separate human-controlled event authorizes exactly the locked confirmatory analysis and nothing broader.

Inspect claim boundary
EVIDENCE / PROVENANCEBounded locked-primary-analysis authorization is ESTABLISHED; execution and result admission remain separate.DOES NOT ESTABLISHAnalysis execution, a positive result, efficacy, certification, or production readiness.
Analyze

Locked primary analysis + result receipt

Pass

The preregistered Epoch 002 primary analysis executed locally under bounded authorization, and its content-addressed result receipt was accepted separately.

Inspect claim boundary
EVIDENCE / PROVENANCEPrimary analysis is EXECUTED_LOCAL and LOCKED_ANALYSIS_RESULT_RECORD is ESTABLISHED at the accepted content address.DOES NOT ESTABLISHCanonical DGAF efficacy, independent validation, or High-Assurance authorization; interpretation remains a separate stage.
Interpret

Interpretation / adjudication

Pass

The retained operator-local locked-analysis output was revalidated under the frozen preregistered interpretation contract, and a separate content-addressed INTERPRETATION_NOTE was admitted.

Inspect claim boundary
EVIDENCE / PROVENANCEINTERPRETATION_EXECUTION = COMPLETED; INTERPRETATION_NOTE = ESTABLISHED; evidence remains SAME_SYSTEM_NONINDEPENDENT.DOES NOT ESTABLISHCanonical DGAF efficacy, independent validation, production readiness, certification, High-Assurance authorization, or a scientific-N increment.
Close

Epoch 002 post-interpretation disposition

Pass

An outcome-agnostic creation-only disposition closes Epoch 002 for its exact preregistered scope while preserving same-system/nonindependent evidence limits.

Inspect claim boundary
EVIDENCE / PROVENANCEPOST_INTERPRETATION_DISPOSITION = CLOSED_BOUNDED_SAME_SYSTEM_NONINDEPENDENT; NEW_EMPIRICAL_EPOCH_AUTHORIZED = FALSE.DOES NOT ESTABLISHCanonical DGAF efficacy, independent validation, production readiness, certification, High-Assurance authorization, or authorization for a successor empirical epoch.
01
Custody

Repository custody acceptance

Pass

The exact successor custody certificate and recovery receipt were admitted and accepted.

EVIDENCE BOUNDARYRecoverability is established at SAME_SYSTEM_NONINDEPENDENT scope.
DOES NOT ESTABLISHIndependent custody, independent verification, efficacy, or downstream authority.
TOOLINGCustody-v2 admission and validation are accepted predecessors.
02
Preflight

Precollection preflight

Pass

The successor collection prerequisites were accepted against exact predecessor evidence.

EVIDENCE BOUNDARYThe defined precollection checks passed at their accepted identity.
DOES NOT ESTABLISHFreeze, authorization, execution, dataset lock, or efficacy.
03
Freeze

Epoch 002 immutable freeze

Pass

The exact Epoch 002 candidate and prospective inputs are immutably bound.

EVIDENCE BOUNDARYThe successor Epoch 002 freeze is established.
DOES NOT ESTABLISHThe separate canonical High-Assurance freeze, collection permission, or efficacy.
04
Closure

Final closure

Pass

The predecessor checklist is accepted as closed for authorization review.

EVIDENCE BOUNDARYCLOSED_VERIFIED_FOR_AUTHORIZATION_REVIEW at the accepted scope.
DOES NOT ESTABLISHAuthorization, execution, unblinding, analysis, or a scientific result.
05
Verification

Verification classification

Pass

The accepted verification path is explicitly developer self-attested and non-independent.

EVIDENCE BOUNDARYThe evidence class and its limitations are explicit and machine-checkable.
DOES NOT ESTABLISHIndependent verification or a broader claim than the classified evidence supports.
06
Authorize

Collection authorization

Pass

A separate human-controlled event authorized the exact bounded Epoch 002 collection.

EVIDENCE BOUNDARYAccepted authorization commit 563152fdb254b8ee948a693c287126a8bf8314b8.
DOES NOT ESTABLISHDataset lock, unblinding, materialization, primary-analysis authority, or efficacy.
07
Collect

Blinded empirical collection

Pass

The operator-executed Codespace collection completed at 50 paired seed units / 2,250 blinded observations.

EVIDENCE BOUNDARYCollection completion is accepted for the authorized Epoch 002 execution.
DOES NOT ESTABLISHDataset lock, materialization, canonical N promotion, or efficacy by itself.
08
Admit evidence

Operator evidence admission

Pass

The bounded operator-retained evidence chain was admitted as the predecessor to dataset lock.

EVIDENCE BOUNDARYAcceptance is bounded to the admitted retained evidence and its exact identities.
DOES NOT ESTABLISHUnblinding, materialization, primary-analysis authority, independent validation, or efficacy.
TOOLINGThe accepted OPERATOR_CODESPACE/content-addressed predecessor chain now supports the dataset-lock receipt.
09
QC

Pre-lock structural quality control

Pass

The bounded blinded pre-lock QC/ledger predecessor chain is accepted.

EVIDENCE BOUNDARYStructural QC is a predecessor to dataset lock and does not inspect treatment identity for analysis.
DOES NOT ESTABLISHTreatment effect, efficacy, materialization, or analysis authority.
10
Lock

Dataset-lock receipt

Pass

A separate accepted PASS receipt establishes the content-addressed Epoch 002 dataset lock.

EVIDENCE BOUNDARYTRACK_A_EPOCH_002_DATASET_LOCK = ESTABLISHED at the accepted receipt identity.
DOES NOT ESTABLISHUnblinding, materialization, primary analysis, efficacy, or scientific-N promotion.
TOOLINGThe accepted receipt preserves separate unblinding and analysis authorization requirements.
11
Unblind

Separate unblinding decision

Pass

A separate accepted human-controlled record authorizes bounded mapping release/decryption only.

EVIDENCE BOUNDARYBounded unblinding is authorized; later materialization and analysis authorization remain separate accepted events.
DOES NOT ESTABLISHMaterialization, primary-analysis authority, scientific-N promotion, independent validation, or a positive result by itself.
TOOLINGScope is CONTROLLED_MAPPING_RELEASE_OR_DECRYPTION_ONLY.
12
Materialize

Controlled materialization + immutable receipt

Pass

The real analysis-ready unblinded input was materialized under operator control, non-secret evidence was admitted, and a separate immutable receipt was accepted.

EVIDENCE BOUNDARYEpoch 002 materialization and its immutable repository receipt are ESTABLISHED at their accepted identities.
DOES NOT ESTABLISHPrimary-analysis execution, efficacy, independent validation, or High-Assurance authorization.
TOOLINGPR #824 admitted the non-secret materialization evidence; PR #826 established the creation-only MATERIALIZATION_RECEIPT.
13
Analysis auth

Primary-analysis authorization

Pass

A separate human-controlled event authorizes exactly the locked confirmatory analysis and nothing broader.

EVIDENCE BOUNDARYBounded locked-primary-analysis authorization is ESTABLISHED; execution and result admission remain separate.
DOES NOT ESTABLISHAnalysis execution, a positive result, efficacy, certification, or production readiness.
TOOLINGPR #828 accepted the creation-only PRIMARY_ANALYSIS_AUTHORIZATION_RECORD with scope LOCKED_PRIMARY_ANALYSIS_ONLY.
14
Analyze

Locked primary analysis + result receipt

Pass

The preregistered Epoch 002 primary analysis executed locally under bounded authorization, and its content-addressed result receipt was accepted separately.

EVIDENCE BOUNDARYPrimary analysis is EXECUTED_LOCAL and LOCKED_ANALYSIS_RESULT_RECORD is ESTABLISHED at the accepted content address.
DOES NOT ESTABLISHCanonical DGAF efficacy, independent validation, or High-Assurance authorization; interpretation remains a separate stage.
TOOLINGPR #851 established the creation-only LOCKED_ANALYSIS_RESULT_RECORD after local execution; the numerical output remains operator-local.
15
Interpret

Interpretation / adjudication

Pass

The retained operator-local locked-analysis output was revalidated under the frozen preregistered interpretation contract, and a separate content-addressed INTERPRETATION_NOTE was admitted.

EVIDENCE BOUNDARYINTERPRETATION_EXECUTION = COMPLETED; INTERPRETATION_NOTE = ESTABLISHED; evidence remains SAME_SYSTEM_NONINDEPENDENT.
DOES NOT ESTABLISHCanonical DGAF efficacy, independent validation, production readiness, certification, High-Assurance authorization, or a scientific-N increment.
TOOLINGPR #855 accepted fail-closed interpretation tooling; PR #872 established the creation-only INTERPRETATION_NOTE without exposing the numerical estimate, interval, or classification.
16
Close

Epoch 002 post-interpretation disposition

Pass

An outcome-agnostic creation-only disposition closes Epoch 002 for its exact preregistered scope while preserving same-system/nonindependent evidence limits.

EVIDENCE BOUNDARYPOST_INTERPRETATION_DISPOSITION = CLOSED_BOUNDED_SAME_SYSTEM_NONINDEPENDENT; NEW_EMPIRICAL_EPOCH_AUTHORIZED = FALSE.
DOES NOT ESTABLISHCanonical DGAF efficacy, independent validation, production readiness, certification, High-Assurance authorization, or authorization for a successor empirical epoch.
TOOLINGPR #880 accepted fail-closed disposition tooling; PR #881 established the creation-only post-interpretation disposition record.
Interpretation ruleA prepared validator, workflow, or control surface is engineering evidence. It does not make the governed predicate true and does not grant authorization.