Skip to content

WallGuard clean-room synthesis path #12

Description

@mdheller

Parent: SocioProphet/sociosphere#392
Depends on: SocioProphet/policy-fabric#86
Related: SocioProphet/sherlock-search#60

Purpose

Define and implement the Holmes-side clean-room synthesis path for WallGuard.

Holmes may synthesize across sources only when WallGuard permits the source/destination combination. When direct use is forbidden, Holmes should support clean-room release patterns that preserve permitted abstractions while blocking restricted source leakage.

Required behaviors

  • consume wall-filtered retrieval results only
  • preserve source/resource labels through investigation state
  • refuse cross-wall synthesis when policy denies it
  • produce clean-room release requests when sanitized output is possible
  • emit/reference WallDecisionReceipts for sensitive synthesis decisions

Fixtures

  • same-wall synthesis allowed with receipt reference
  • cross-wall synthesis denied
  • clean-room summary generated from permitted abstractions only
  • contaminated investigation state cannot be reused in unrelated matter
  • missing wall context fails closed for restricted synthesis

Acceptance criteria

  • Holmes never treats semantic similarity as permission.
  • Holmes does not become policy authority.
  • Clean-room output includes source-label and decision-receipt metadata.
  • No dependency on noncanonical or unlicensed repos.

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions