SCOPE 2.2 makes SCOPE the sole issuer/enforcer of machine-verifiable scientific
authorization grants, sharing one contracts wheel (scientific-authorization-contracts==2.2.0)
with AKTA. Institutional pilot hardening (AS-01..AS-08) adds freeze, independence,
review modes, grant bindings, runtime evidence, append-only outcomes, quality
metrics v3.0, runbooks, and offline reconstruction gates.
- Contracts package
2.2.0withgrant/status/manifestmodules and covers-based operation DAGs - Fully immutable grants (
FinalizedGrant,CanonicalGrantBytes) and complete source-chain hash bindings - Shared signed
scientific-authorization-manifest-v1 - Signed grant-status attestations (
scope-grant-status-v1) - Lifecycle:
exhaustedreplacesused/consumed; idempotency domain(tenant, grant, key, action_hash) - Fail-closed mandatory controls with
control_evidence; no fabricated issuance context - Split preflight vs authorize-and-consume APIs; clean-wheel packaging; mandatory AKTA interop runner on release tags
| Work order | Deliverable |
|---|---|
| AS-01 | Frozen packets, content_revision, action_chain_id |
| AS-02 | Reviewer independence evidence (not honesty/competence proof) |
| AS-03 | First-class review_mode; shadow/read-only cannot authorize |
| AS-04 | Institutional grant bindings (chain, digests, environment, revocation) |
| AS-05 | Runtime evidence export; OVK out-of-repo (local fake only) |
| AS-06 | Append-only outcome links and reviewer reflections |
| AS-07 | Quality metrics v3.0 with denominators/missingness; calibration proxies only |
| AS-08 | Runbooks, examples/institutional_pilot_as/, offline gates |
This release does not certify scientific correctness, live institutional IdP, WORM Object Lock retention, or remote ledger authority. Those remain operator infrastructure. See ADR-0001, ADR-0010, and definition_of_done.md.
See migration_2.2.md, AS migration docs (migration_*.md),
scope_2_2_release_invariant.md, and
runbooks/.
python scripts/run_institutional_offline_gates.py
python scripts/reconstruct_pilot_chain.py --pilot-dir examples/institutional_pilot_as --institutional-stack