Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
47 changes: 26 additions & 21 deletions app/public/generated/corpus.json

Large diffs are not rendered by default.

2 changes: 1 addition & 1 deletion docs/annexes/ANNEX_AF.md
Original file line number Diff line number Diff line change
Expand Up @@ -44,7 +44,7 @@ Detection triggers elevated scrutiny review, not automatic denial. The review mu

**Slow-burn shared-hardship safe harbor:** Genuine co-located or co-affiliated hardship frequently arrives without a formal emergency declaration — a single plant closing before any oracle declaration, an extended-kinship network in deep poverty, the failure of a single-employer town. Where the reviewing body finds documented evidence of such a cluster — a shared employer, a shared locality, or a shared kinship or housing network experiencing genuine concurrent hardship — the affected persons receive the same presumption of an innocent explanation that the community-disaster safe harbor grants. The reviewer documents the shared-hardship basis, and the flagged collusion pattern is treated as explained rather than suspect. This pathway requires no declared emergency; it requires only credible documentation of co-located or co-affiliated hardship, and like the declared-disaster safe harbor it suspends elevated scrutiny for the affected cluster for 2 quarters.

**Attestation-graph data minimization.** The hardship attestation graph maps the support networks of people in hardship and must never become a reusable surveillance asset. Access to the attestation graph is purpose-limited to exploitation review under this annex: only the reviewing bodies and independent panels conducting an active collusion-detection review may view it, and only the subgraph relevant to the case under review. The graph is retained only as long as needed for active and appealable reviews and is purged on a fixed retention schedule once a review and its appeal window have closed; confirmed safe-harbor or innocent-explanation cases are purged at closure. The attestation graph may not be repurposed for eligibility scoring, civic-standing assessment, law-enforcement referral, or any use beyond exploitation review, and may not be exported, sold, or shared outside the reviewing function. Every access is logged and auditable. The graph's regime is recorded in the per-domain calibration table of the [Monitoring Administrative Safety Packet](../governance/Monitoring_Administrative_Safety_Packet.md) (P-075); its unspecified retention-schedule length is registered there as an open gap.
**Attestation-graph data minimization.** The hardship attestation graph maps the support networks of people in hardship and must never become a reusable surveillance asset. Access to the attestation graph is purpose-limited to exploitation review under this annex: only the reviewing bodies and independent panels conducting an active collusion-detection review may view it, and only the subgraph relevant to the case under review. The graph is retained only as long as needed for active and appealable reviews and is purged on a fixed retention schedule once a review and its appeal window have closed; confirmed safe-harbor or innocent-explanation cases are purged at closure. The attestation graph may not be repurposed for eligibility scoring, civic-standing assessment, law-enforcement referral, or any use beyond exploitation review, and may not be exported, sold, or shared outside the reviewing function. Every access is logged and auditable. The graph's regime is recorded in the per-domain calibration table of the [Monitoring Administrative Safety Packet](../governance/Monitoring_Administrative_Safety_Packet.md) (P-075); its retention schedule is calibrated there. The fixed schedule is: stripped to a case-pseudonym at intake, fully purged once the review and its appeal-spine (ANNEX_L §L7) window close + 30 days, with a 180-day ceiling past appeal-window close (FC-212, RESERVED; this retention ceiling is distinct from the §AF3 two-quarter scrutiny-suspension safe harbor).

### AF4. Service Record Slow-Decay During Extended Pause (Annex K4 Amendment)
During a Protected Pause Window, Service Record decays at 20% of the normal quarterly rate rather than being fully frozen. Voice decay freeze is unchanged — Voice cliff-effect protection is preserved in full. The Service Record slow-decay applies only during quarters in which a Protected Pause Window is active.
Expand Down
2 changes: 1 addition & 1 deletion docs/annexes/ANNEX_AJ.md
Original file line number Diff line number Diff line change
Expand Up @@ -300,7 +300,7 @@ New worked examples may be added through the standard P-004 amendment process as

**Public scope of monitoring:** What is monitored is public even where specific numeric thresholds are restricted. The categories and scope of social-layer monitoring — which outcomes are observed, which correlations are tested, which vendor-level and population-level signals are collected, and for which boundary patterns — are published in plain language so that operators, vendors, and participants retain the clear notice of what is prohibited that this annex requires (Purpose, item 2). Only the calibrated numeric trigger values may be withheld in the Restricted Register per P-021 (Annex AO), and only to prevent gaming of the exact thresholds. Each restricted item carries a published, specific justification for why that value — and no broader category of information — is held restricted. The Restricted Register may narrow the precision of notice; it may not erode the notice itself. Any monitoring scope not published in this register is not authorised.

**Data purpose-limitation:** The vendor-level and population-level data collected to detect above-ledger bypass is purpose-limited to bypass-detection and the enforcement process in Section 4, and to nothing else. This data is PII-stripped at the earliest point consistent with detection (per Annex AM), is retained only for the bounded period necessary to establish patterns and adjudicate findings and is then deleted, is access-limited to the Enforcement Panel and detection staff acting under that mandate, and is never repurposed for general population surveillance, civic scoring, eligibility determination, commercial use, or any objective outside bypass-detection. The remedy against wealth purchasing the survival floor must not itself become a general-purpose surveillance asset; a monitoring programme that exceeds these limits is itself a Babel-risk failure of this annex and is subject to Ombuds review under Annex AI. These constraints are P-004 protected and may not be relaxed through ordinary operational updates. This clause is recorded, unmodified, in the per-domain calibration table of the [Monitoring Administrative Safety Packet](../governance/Monitoring_Administrative_Safety_Packet.md) (P-075); cross-domain joins follow the linkage rule there.
**Data purpose-limitation:** The vendor-level and population-level data collected to detect above-ledger bypass is purpose-limited to bypass-detection and the enforcement process in Section 4, and to nothing else. This data is PII-stripped at the earliest point consistent with detection (per Annex AM), is retained only for the bounded period necessary to establish patterns and adjudicate findings and is then deleted, is access-limited to the Enforcement Panel and detection staff acting under that mandate, and is never repurposed for general population surveillance, civic scoring, eligibility determination, commercial use, or any objective outside bypass-detection. The remedy against wealth purchasing the survival floor must not itself become a general-purpose surveillance asset; a monitoring programme that exceeds these limits is itself a Babel-risk failure of this annex and is subject to Ombuds review under Annex AI. These constraints are P-004 protected and may not be relaxed through ordinary operational updates. This clause is recorded, unmodified, in the per-domain calibration table of the [Monitoring Administrative Safety Packet](../governance/Monitoring_Administrative_Safety_Packet.md) (P-075); cross-domain joins follow the linkage rule there. Identifiable bypass-detection records are retained no longer than the related enforcement matter requires — draft anchor 90 days post enforcement-matter finality, with a 180-day ceiling on identifiable hold while no case has formed and a 365-day absolute cap from collection (FC-211, RESERVED; bound by the Enforcement Panel and Federated Ombuds before detection activates). The 365-day "from collection" cap is anchored per underlying record at first ingestion of that person's data and is never reset by re-derivation, feature re-extraction, or opening a new pattern-build; a pattern-build that has run 180 days without a formed case strips to aggregate regardless of build status. Where enforcement-matter finality + 90 days would exceed 365 days from collection, the 365-day absolute cap governs.

---

Expand Down
2 changes: 1 addition & 1 deletion docs/annexes/ANNEX_C.md
Original file line number Diff line number Diff line change
Expand Up @@ -53,7 +53,7 @@ Quarterly cycles reduce governance noise while keeping the system responsive. Mo

**Breach of cadence is not advisory.** When a required cadence event is missed or its outputs are not produced by the scheduled date, the lapse triggers automatic escalation to Independent Oversight and is recorded in an audit-visible lapse log. Every threat that depended on the missed event reverts to a degraded, unverified status — its prior evidence is no longer treated as current — until the event is completed and fresh evidence is filed. A threat may not be reported as having passing controls while any of its cadence obligations are overdue. This makes compliance theater costly and visible rather than silent.

**Recourse for the monitored person.** Continuous monitoring includes anomaly detection and fraud/coercion flags applied to identifiable people. Any person flagged by such monitoring receives notice of the flag in plain language and an accessible path to appeal it, including human review and correction of erroneous data. Adverse action that rests on a contested flag is paused or made reversible while the appeal is pending, except where a narrow, time-limited emergency action under C-6 is justified. The dignity of the monitored is protected alongside the integrity of the monitoring; see also Annex A §A3–A4.
**Recourse for the monitored person.** Continuous monitoring includes anomaly detection and fraud/coercion flags applied to identifiable people. Any person flagged by such monitoring receives notice of the flag in plain language and an accessible path to appeal it, including human review and correction of erroneous data. Adverse action that rests on a contested flag is paused or made reversible while the appeal is pending, except where a narrow, time-limited emergency action under C-6 is justified. The dignity of the monitored is protected alongside the integrity of the monitoring; see also Annex A §A3–A4; flag expiry follows FC-214 (resolution + 30 days, 180-day max age).

**Purpose limitation and secondary-use challenge.** Monitoring data may be used only for the control purpose named in the Monitoring Purpose Register required by [P-069](../governance/Patch_Log.md) and by the Minimization and Purpose-Limitation Doctrine (P-075) in the [Monitoring Administrative Safety Packet](../governance/Monitoring_Administrative_Safety_Packet.md). Any secondary use, cross-dashboard join (per the cross-domain linkage rule there), raw-data access expansion, retention extension, or individual-level linkage requires published review before use. A monitored person, affected cohort, trusted intermediary, or Federated Ombuds reviewer may challenge a monitoring stream on purpose-creep, re-identification, excessive retention, inadequate appeal, or operator self-certification grounds. A challenged secondary use is paused unless an independently published emergency finding states why delay would create immediate CSM harm.

Expand Down
2 changes: 1 addition & 1 deletion docs/annexes/ANNEX_D.md
Original file line number Diff line number Diff line change
Expand Up @@ -130,7 +130,7 @@ Minimum lockbox functions:

Assessment must be narrow, explainable, contestable, and purpose-limited.

**D6.1 Minimum necessary data.** Assessors may collect only the data needed to determine the named source base, protected ordinary use, and beneficial control. Data collected for Commons Return may not be reused for policing, immigration enforcement, employment screening, credit scoring, marketing, political targeting, or social ranking. Commons Return data practice is calibrated in the master minimization standard ([Monitoring Administrative Safety Packet](../governance/Monitoring_Administrative_Safety_Packet.md), P-075); its unspecified stripping point and retention period are registered there as open gaps, and dataset joining follows the cross-domain linkage rule there (which generalizes §D6.5).
**D6.1 Minimum necessary data.** Assessors may collect only the data needed to determine the named source base, protected ordinary use, and beneficial control. Data collected for Commons Return may not be reused for policing, immigration enforcement, employment screening, credit scoring, marketing, political targeting, or social ranking. Commons Return data practice is calibrated in the master minimization standard ([Monitoring Administrative Safety Packet](../governance/Monitoring_Administrative_Safety_Packet.md), P-075); its stripping point and retention period are calibrated there, and dataset joining follows the cross-domain linkage rule there (which generalizes §D6.5). Assessment data is PII-stripped to aggregate at assessment finality and retained no later than the appeal-spine window close + 30 days, with an 18-month identifiable cap (FC-213, RESERVED).

Commons Return assessment data is a monitoring stream for purposes of [P-069](../governance/Patch_Log.md) and the [Monitoring Administrative Safety Packet](../governance/Monitoring_Administrative_Safety_Packet.md). Before any assessment stream operates, the Monitoring Purpose Register must name its source base, fields, lane, raw-access rule, retention clock, independent reviewer, join limits, forbidden uses, and appeal path.

Expand Down
Loading
Loading