The Sovereign Jurisdiction Network

Abstract

A company applying to a foreign registry may already hold evidence of its status from its home registry. Reusing that evidence can avoid repeated collection. The receiving registry must still decide under its own rules, including any change since the evidence was issued. This paper asks how independent authorities can cooperate on those terms. We construct a network of signed statements and destination-approved recognition rules. Separate records distinguish received evidence, local decisions, rights, and cash instructions. Each change checks the authority, purpose, time, and records on which it depends. The preservation theorem shows that every admitted use remains attributable to its source and receiving authority. It also establishes reproducible history and prevents conflicting updates or later revocation from changing the recorded basis of earlier decisions. Further constructions preserve local questions and continuing duties across recognition routes. Their institutional effect depends on authentic governing instruments, current authority evidence, and the applicable execution or settlement rules.

Author note. The author has a commercial interest in systems of the kind this paper describes.

1 Reusing a Foreign Registry Statement

Consider company registries North and South. A company registered in North applies to South to register a branch. North has already examined its home registration and can report its standing. South needs that evidence, but must also answer its own questions about the proposed branch. Requiring the company to reproduce the same evidence adds work. Treating North’s answer as South’s authorization would assign the decision to the wrong institution.

North signs that company x is in good standing at time t_0. South may use that statement when deciding whether x can register a branch. An authorized South officer still applies South’s law and writes South’s record. The officer may act through a standing delegation when South’s rule permits automatic decisions. North supplies the source fact. South determines its permitted local use.

Now suppose the company presents the same statement later, or for a different purpose. Its original signature can remain authentic after its permitted use expires. South can also withdraw its recognition rule between an initial check and the branch-registration entry. A complete account must identify both what South accepted and which rules still authorized the actual decision. Preserving the earlier statement alone does not answer the second question.

The construction gives each institution its own records and authority. A recognition rule specifies which foreign evidence a receiving institution may use and which questions it must answer locally. We call this directed relationship a corridor. It can carry North’s status evidence to South without giving North power over South’s branch register. A later recipient must apply its own rule, even when South has already accepted the statement.

The mathematical question concerns a sequence of such decisions: which local checks suffice to preserve this separation throughout the sequence? We represent each change by an authorized event with a single target record. The main theorem derives attribution and reproducible history from those transition rules. Checks on all changing dependencies ensure that a decision still satisfies its conditions when the event occurs.

Rights and cash require their own authorized events. The network’s evidence record owns no rights, moves no money, and supplies no legal finality. Where a receiving institution creates a right or instructs a payment, its governing instrument and the relevant provider rules determine that further effect. This distinction also matters when a decision is revoked, a route changes, or an obligation survives an institutional succession.

Existing work supplies parts of this construction. Simple Public Key Infrastructure (SPKI) and KeyNote describe scoped authority and local trust decisions (References [6] and [7]). Signed credential systems carry identity evidence across organizations (References [9][11]). The question here is how such evidence enters a changing local record while each institution retains its own decision and authority. Sections 2 and 3 state the event model and its preservation result. The later constructions address recognition, execution, and governance under that same separation.

2 Records and Authorized Changes

South must retain North’s statement, the rule permitting its use, and South’s resulting decision as distinct records. We call an institution’s locally administered record service a deployment. Its technical operator serves the records under the institution’s authority. The operator and the competent institution can be different parties.

The model records authorized changes to those records. Each decision uses finite evidence, so its admission can be checked. The theorem concerns every finite sequence admitted by these rules.

2.1 Records and statements

Let \mathcal{V} be a finite nonempty set of deployments. For each v\in\mathcal{V}, let D_v=(L_v,Q_v,I_v,A_v) contain four append-only sequences. An append-only sequence retains earlier entries when a later entry records a correction or withdrawal. Here L_v is the local institutional record, Q_v is the authority-and-policy history, I_v is the issuance record, and A_v is the acceptance record. The whole state is \Sigma=\left((D_v)_{v\in\mathcal{V}},\mathcal{G},\mathcal{R},\mathcal{K}\right). \mathcal{G} records transport and route derivations. Write \mathcal{R}=\bigsqcup_{v\in\mathcal{V}}R_v, \qquad \mathcal{K}=\bigsqcup_{v\in\mathcal{V}}K_v. The rights and cash records are constitutive local registers. Each R_v records creation, current holding, transfer, and extinguishment under the authority of v. Each K_v records an instruction and the evidence that a named provider completed or reversed it. A K_v entry records the institution’s determination. The provider’s rulebook and governing law determine cash movement and legal effect. No event in \mathcal{G} can write either register.

A delegation explains why a particular signer may act for an institution. Its starting point is a constitutive authority: power conferred by the institution’s governing basis, from which the recorded delegations descend. The model takes that basis as an institutional premise.

Definition 2.1 (Authority witness).

An authority witness at deployment v is a finite chain a_0\rightsquigarrow a_1\rightsquigarrow\cdots\rightsquigarrow a_m whose first link is a constitutive authority of v. Each later link is a signed delegation within the scope and validity interval of the preceding link. The final authority a_m names the permitted act, scope, subject, purpose, and validity interval.

The root of this chain is local. A foreign statement can satisfy an evidence rule. It cannot create a constitutive authority at its destination.

The authority record distinguishes the competent institution, its delegated decision maker, and its technical operator. Infrastructure credentials identify the operator. The governing instrument determines the decision power. An instrument profile binds its retained bytes, applicable law, competent office, permitted acts, conditions, and adoption rule. Each profile records legal effective time separately from recording time. A policy amendment uses the authority fixed by its predecessor profile.

The statement must identify exactly what was asserted and for which use. A cryptographic digest identifies its encoded bytes. A digital signature authenticates that digest under a signing key. Canonical encoding gives those fields one specified byte representation.

Definition 2.2 (Institutional statement).

An institutional statement is a tuple s=(\mathsf{id},u,\mathsf{scope},\mathsf{subject},\mathsf{purpose}, \mathsf{predicate},\mathsf{value},[t_0,t_1],w,d,\sigma). Here u is the issuing deployment, and w is its issuance authority witness. The digest d is computed from canonical bytes of every preceding field. The value \sigma signs d. Thus a change of scope, subject, purpose, predicate, value, or validity interval changes the signed object.

South next needs a rule connecting the foreign statement to its own question. Approval of that rule belongs to South. Different destinations can give the same statement different treatment.

Definition 2.3 (Directed acceptance policy).

A directed policy p_{uv}^{j} is an immutable version approved by a destination authority witness. It names the permitted source u, exact subject relation, purpose, predicate, required local questions, treatment, validity interval, and predecessor. Its digest binds all these fields. Withdrawal ends future reliance without erasing earlier decisions.

Evidence may reach South through an intermediate institution. South then needs the complete sequence of recognition rules, including the authority for each one. A route derivation retains that sequence.

Definition 2.4 (Complete route derivation).

A route derivation for statement s at destination v_k is \pi=(v_0\xrightarrow{p_1}v_1\xrightarrow{p_2}\cdots \xrightarrow{p_k}v_k),\qquad v_0=\mathsf{issuer}(s). It also contains a valid destination-authority witness for every p_i. The derivation is complete only if every edge is present, ordered, and bound to the same statement digest.

2.2 Historical verification and present use

The later presentation in the registry example requires two checks: whether North made the earlier assertion, and whether South may rely on it now. Every assertion retains its original act identifier and signed validity interval. Each later receipt identifies that assertion and the receiving institution’s treatment. A receipt preserves the source interval. Reuse under delegation can run automatically while retaining the original act and its current-use conditions.

Write t_a for an act’s occurrence time and t for the proposed use time. Write k for the evidence cutoff. An authority or policy fact records its effective interval and recording time. The view at cutoff k uses only facts recorded by k. A later correction appends its authority, effective time, and predecessor. It preserves the evidence view used for the earlier decision.

For request q, a verifier returns four separate results: (\mathsf{Bytes}(m,k),\mathsf{History}(s,t_a,k), \mathsf{Reliance}(s,q,t,k),\mathsf{Act}(q,t,k)). The first result reports \mathsf{Available}, \mathsf{Missing}, or \mathsf{Corrupt} for the required retained bytes. Historical verification checks the original signature and authority under the recorded evidence view. Reliance applies the destination’s current purpose, policy, source-validity, and authority-use conditions. Operational authorization checks the distinct local act and its named execution stage.

A historical result distinguishes verified, refuted, and unresolved premises. Reliance and operational authorization distinguish admissible, refused, and pending results. Missing required bytes or an incomplete authority feed produces pending, with the exact unresolved dependency. A known expired-use interval produces refusal for that use. Neither result erases the authenticated earlier assertion.

A digest alone cannot supply the bytes required to verify it. A retained preimage is the original byte string whose digest is recorded. A retained-preimage manifest m names every required object’s digest, encoding, byte length, authorized retrieval locations, retention interval, and responsible custodian. It covers source statements, signatures, authority instruments, policies, status evidence, and derivation inputs. A verifier retrieves the permitted bytes and checks their digests. Content-addressed references locate evidence. They do not certify retrieval. A completeness witness binds the authority-source scope, status head, observation cutoff, and applicable currentness rule.

Proposition 2.5 (Separate historical and current-use results).

Fix a complete retained package and its cutoff. Historical verification is reproducible from that package. Changing only use time or destination policy can change reliance while preserving the historical result. Missing a required preimage prevents a verified result for the dependent check.

Proof. Historical verification reads the original act and the fixed evidence view. The changed use inputs occur only in reliance and operational authorization. Their change therefore leaves historical evaluation unchanged. A dependent verification rule requires its checked preimage. Missing bytes leave that premise unresolved. ◻

For example, an assertion issued at time 2 has a use interval [2,5]. At time 7, its retained signature can verify historically. That assertion cannot satisfy a current-use rule requiring membership in [2,5]. A later recognition receipt leaves the interval unchanged. Restoring missing bytes permits the suspended check to resume with its original request and dependencies.

2.3 Events

The preceding objects describe evidence and authority. We now specify the changes a deployment may make with them. An event constructor fixes one kind of change, its sole target record, and its admission conditions. Its guard is the collection of conditions that must hold before that change is admitted. The current head identifies the record’s latest committed state. A new event names that head as its predecessor, so it cannot silently replace an intervening change.

The event set \mathcal{E} is the disjoint union of the following classes: \begin{align*} \mathcal{E}_Q &={\{\mathsf{Grant},\mathsf{Revoke},\mathsf{Publish},\mathsf{Withdraw}\}},\\ \mathcal{E}_I &={\{\mathsf{Issue}\}},\\ \mathcal{E}_G &={\{\mathsf{Transport},\mathsf{RouteExtend}\}},\\ \mathcal{E}_A &={\{\mathsf{Accept},\mathsf{Reject}\}},\\ \mathcal{E}_L &={\{\mathsf{LocalCommit}\}},\\ \mathcal{E}_R &={\{\mathsf{RightCreate},\mathsf{RightTransfer},\mathsf{RightExtinguish}\}},\\ \mathcal{E}_K &={\{\mathsf{CashInstruct},\mathsf{CashConfirm},\mathsf{CashReverse}\}}. \end{align*} Every event carries a unique identifier, time, predecessor head, scope, subject, purpose, payload, authority chain, digest, and signature. Its constructor fixes the sole target record. A successful event appends one immutable entry.

South can check a recognition rule immediately before another authorized event withdraws it. Protecting the branch record alone would miss that change. The signed guard witness therefore binds every mutable input to the constructor. These inputs include authority, policy, route, acceptance, revocation, and resource records. Absence and range queries bind collection or index heads. The witness also binds rule versions and the records that determine dependency owners and participants. Instrumented guard reads enforce this dependency set.

An operation can be authorized locally before it is dispatched or accepted by a provider. The governing rule determines when the relevant authority must hold. An authority-use contract names the act and the stage at which authority is required. It distinguishes three obligations. Historical validity establishes authority for a recorded earlier act. Consumed authorization establishes a specific effect at its named consumption stage under the governing instrument. Continuing authority must hold through a named later stage, such as dispatch or provider acceptance. Each contract binds its legal basis, scope, subject, purpose, interval, and exact command. A software status alone cannot make authorization irrevocable.

The transition relation is the following guarded construction. These clauses define the permitted changes. For cash events, an occurrence is the provider event recorded by the evidence. An allocation attributes an amount from that occurrence to an instruction. The unpaid amount is the part still due. A reservation retains the capacity that an unresolved command can still use.

\mathsf{Grant}

Append to Q_v. Create one delegated authority whose scopes, subjects, purposes, and validity interval are contained in its active parent grant.

\mathsf{Revoke}

Append to Q_v. End one active non-constitutive grant prospectively. Preserve the grant and every earlier use.

\mathsf{Publish}

Append to Q_v. Create one policy version under the predecessor’s adoption authority. A directed version binds source, subject relation, purpose, predicate, required questions, treatment, and interval. A governance version binds its instrument profile, permitted transition, exact predecessor, conditions, and institutional authority. Its adoption follows the rule already in force.

\mathsf{Withdraw}

Append to Q_v. End future use of one active policy version signed by v. Preserve earlier uses.

\mathsf{Issue}

Append to I_v. Create the statement digest and signature after checking the issuer’s scope, subject, purpose, predicate, and interval.

\mathsf{Transport}

Append to \mathcal{G}. Start a route for the exact issued-statement digest. Change no institutional, rights, or cash record.

\mathsf{RouteExtend}

Append to \mathcal{G}. Extend only the current route by one active directed-policy digest that matches the same statement, subject, purpose, and predicate.

\mathsf{Accept}

Append to A_v. Bind the statement digest, original act, complete route, active destination policy, request, required answers, treatment, and decision authority. Bind the retained-preimage manifest, evidence cutoff, historical result, and current reliance result.

\mathsf{Reject}

Append to A_v. Bind the same objects as acceptance and add the destination’s signed reason for refusal.

\mathsf{LocalCommit}

Append to L_v. Every local rule lists its required evidence predicates. The event must cite exactly one current acceptance for each required predicate, with the same subject and purpose, and must carry a separate local authority witness.

\mathsf{RightCreate}

Append to R_v. Require an absent right identifier, an initial holder, a legal basis, and an authority for that right and purpose.

\mathsf{RightTransfer}

Append to R_v. Require an active right, the recorded current holder as transferor, a distinct transferee, and matching authority.

\mathsf{RightExtinguish}

Append to R_v. Require an active right, its recorded current holder, and matching extinguishment authority. Mark that right extinguished.

\mathsf{CashInstruct}

Append to K_v. Require a new instruction identifier, payer, payee, positive amount, currency, provider reference, and matching authority. Mark the instruction open.

\mathsf{CashConfirm}

Append to K_v. Record an authenticated provider occurrence for the instruction’s payer, payee, and currency. Bind its positive amount, canonical occurrence identity, and admitted allocation. A correction form binds that occurrence, its predecessor assertion, and correction authority. It can revise the asserted amount to zero without a new occurrence. Update supported performance, unpaid amount, and reservation together. Partial performance leaves the remainder explicit.

\mathsf{CashReverse}

Append to K_v. Record an authenticated return or reversal occurrence linked to the earlier payment. Bind its amount, reason, and attribution to prior performance. A correction form revises that occurrence’s assertion under correction authority and binds its predecessor assertion. Correction does not require another physical reversal. Update net support, unpaid amount, and reservation together. Preserve the earlier occurrence and its history.

The decisive separation is now explicit. Acceptance can change only A_v. A local rule can require that acceptance, but \mathsf{LocalCommit} remains a new authorized event. Rights and cash have their own constructors, current-state guards, and authorities. No type conversion crosses these records.

A cash occurrence uses the provider namespace, record kind, and stable reference. Assertion and allocation identities remain separate. Repeated evidence for one occurrence adds no performance. The allocation authority bounds each attributed amount by the instruction’s unpaid amount and the occurrence’s available support. Its complete guard spans every competing allocation.

For instruction amount z, let p be supported allocated performance and u=z-p its unpaid amount. Funding status is open, partial, or complete according as p=0, 0<p<z, or p=z. A reversal’s attributed amount cannot exceed the unreversed prior allocation. Excess observed payment or debit remains recorded for reconciliation. It supplies no unsupported discharge.

Command closure remains separate from funding status. Partial performance does not prove that the original command cannot perform its remainder. Uncertain command capacity retains its reservation. Release requires terminal remainder evidence or a provider-enforced transfer of that capacity. A reversal supplies no new dispatch authority.

An authoritative correction changes the assertion about its existing occurrence. The cash record retains the assertion history and resulting support deficit. A correction is distinct from a physical return or reversal. Current cash and claim projections use the same corrected allocation state.

2.4 Validity conditions

The event clauses specify individual changes. The following conditions require every admitted step to respect its target, authority, current dependencies, and retained history. A transaction applies its changes together or leaves them unapplied. Strict serializability gives concurrent transactions the effect of one order consistent with completed real-time precedence. A finite history h=e_1\cdots e_n is valid when every prefix satisfies six conditions.

N1.

Complete partition. Every state change has one of the sixteen constructors and the unique target fixed by that constructor.

N2.

Effect locality. An event changes only its declared target record. No evidence event changes L_v, \mathcal{R}, or \mathcal{K}.

N3.

Witnessed authority and bytes. The authority chain begins at a constitutive root and ends at the signer. Every delegation covers the event’s scope, subject, purpose, and time. The canonical digest covers every event field, and the signature verifies that digest.

N4.

Constructor guard and current reliance. Every constructor satisfies its clause above. Acceptance verifies the exact statement digest, issuance, subject, purpose, predicate, route, active policy, required answers, and applicable revocation information. A local commit cites every required acceptance and checks each authority-use contract at its named stage. Historical issuance validity remains distinct from current permission to rely on the statement. A rights event names the current holder. A cash event matches the instruction fields and its required external witness. Revocation and withdrawal bar subsequent uses that require the affected current authority. A lawfully consumed authorization retains only the effect and scope fixed by its governing instrument.

N5.

Dependency-complete guarded append. One strictly serializable transaction validates the target predecessor and every declared mutable dependency version. It supplies one consistent dependency state and event time to the applicable semantic checks. N4 determines constructor admissibility. N5 protects the observed versions until the entry and new head become durable together. A conflicting version change causes reevaluation or rejection.

N6.

Ordered immutable history. Event times do not decrease within a record. Recorded identifiers, payloads, digests, signatures, and policy versions never change.

These conditions constrain admissible transitions. They do not assume the conclusions below. In particular, replay and attribution quantify over whole histories, while the conditions govern one transition at a time.

Condition N5 protects the complete guard read set while changing one target record. A local transaction covers locally owned dependencies. Current dependencies owned elsewhere require their owners’ participation under Section 5.1. A signed snapshot proves its recorded contents. Its continued current-use validity follows the authority-use contract. Atomic institutional records retain the distinct completion and finality rules of external providers.

3 The Preservation Theorem

The main result connects these local checks to the complete record. South can reconstruct its own decisions and identify each foreign assertion on which they relied. A later event can change future permission while preserving the evidence used earlier. This is the point of the event construction: the authority boundary survives repeated use, concurrent changes, and revocation.

For a target record X, write \operatorname{proj}_X(h) for the subsequence of events whose declared target is X. Let \operatorname{fold}_X(X^0,\operatorname{proj}_X(h)) apply those events in order from the initial value X^0.

Theorem 3.1 (Authority-preserving institutional network).

Let h be a finite valid history satisfying N1–N6. Then all six statements hold.

  1. Local replay. For every v and every X\in\{L_v,Q_v,I_v,A_v\}, X(h)=\operatorname{fold}_X\bigl(X^0,\operatorname{proj}_X(h)\bigr). The corresponding equation holds for \mathcal{G}, \mathcal{R}, and \mathcal{K}.

  2. Complete attribution. Every foreign fact in A_v has a signed source statement, source authority chain, complete route derivation, authorized destination policy, and authorized local decision. The same attribution accompanies every citation of that fact by L_v.

  3. Freedom from lost updates. Two successful appends to one record cannot consume the same predecessor head. Every constructor guard holds in the serial predecessor state at its named use stage.

  4. Time safety. Every accepted fact was valid under the policy, authority, and revocation information required at its acceptance time. Later changes cannot rewrite that historical basis.

  5. Prospective revocation. After effective revocation, each later stage requiring that current authority rejects its use. An authorization lawfully consumed earlier retains its instrument-defined effect and scope. A separately authorized later version remains possible.

  6. Decidable acceptance. A complete finite package decides whether the proposed transition is admissible. Missing required evidence returns a finite pending result naming its dependencies. Signature, digest, scope, time, route, and head checks terminate.

Proof. Induct on h. The empty history is immediate. For prefix h' and valid event e, N1 gives one class and target. N2 leaves every other component unchanged. Appending e to its target is exactly the corresponding projected fold, which proves replay.

For an accepted fact, N3 validates canonical bytes, signatures, the issuance chain, and the destination chain. N4 supplies the exact statement, complete route, active policies, subject-purpose match, and required local answers. A local commit must cite every acceptance named by its rule. N6 preserves every earlier witness. Attribution follows.

Under N5, the first append consuming head q atomically replaces it. A second append declaring q then fails its comparison. N4 establishes constructor admissibility against the observed state. N5 preserves that state through the append. Together they establish guard truth in the serial predecessor state at the named use stage.

N4 checks the applicable policy, time, and revocation data at each named use stage. N2 and N6 preserve the event and its immutable basis. This proves time safety. After effective revocation, N4 rejects each later stage requiring the revoked current authority. An earlier consumed authorization has only its instrument-defined effect. A later grant has a different identifier. Prospective revocation follows.

Every presented object is finite. Manifest checks identify missing dependencies. With all required bytes present, signature, digest, scope, time, route, and head checks terminate. Their finite conjunction decides admissibility. Missing evidence produces a pending result rather than an invented premise. ◻

Corollary 3.2 (Evidence-only extension).

If a valid event extends only \mathcal{G} or an acceptance record, then every existing entry of L_v, \mathcal{R}, and \mathcal{K} remains unchanged.

The corollary is the formal reason that recognition does not transfer authority. It adds evidence or a local evidentiary treatment. A separate authorized event must change a local record, a right, or cash.

3.1 Four independent necessity witnesses

Each construction removes one condition and retains the other five. The prefix may contain several events. The violating extension is one transition.

  1. Without N1, allow a right transfer outside the event partition. The right changes while every projection remains unchanged, so replay fails.

  2. Without N2, let one acceptance event append to both A_v and L_u. An event foreign to L_u changes it, so local replay fails.

  3. Without N3, record an otherwise admissible issuance with a corrupted source signature. Transport and acceptance use its exact recorded digest, active route, and destination rule. N1, N2, N4, N5, and N6 hold, but source attribution fails.

  4. Without N4, correctly issue, transport, and route a statement. Withdraw the destination policy, then present a separately signed acceptance at a later time. Bind the current acceptance head and complete dependency versions, including the withdrawn policy record. Serialize observation and append under N5. With N4 removed, semantic rejection of the withdrawn policy is absent. N1, N2, N3, N5, and N6 hold, while time safety and prospective revocation fail.

These histories establish necessity for N1–N4 relative to the stated conclusions. We do not supply necessity witnesses for N5 or N6. They are sufficient conditions used by the theorem, not claimed minimal assumptions.

A finite sequential two-deployment event model exercises all sixteen constructors in one valid trace. It also enumerates all 1{,}120 interleavings of independent rights, cash, withdrawal, and revocation tails that preserve their internal orders. It rejects 37 mutations covering the constructor partition, target locality, authority scope and chain, subject-purpose binding, canonical digest, signature, predecessor, time, required evidence, current holder, and cash-state guards. These finite calculations corroborate the definitions. They do not prove Theorem 3.1 for unbounded histories.

4 Directed Recognition Between Institutions

Return to South’s branch application. Its recognition rule can reuse North’s status evidence while retaining South’s current licensing question. That distinction requires more than a list of recognized domains. The corridor must state what evidence travels, how South treats it, and which questions or duties remain with their owning authorities.

The directed acceptance policy in Section 2 supplied the rule for one accepted statement. The following corridor policy describes its domain-specific content and the obligations retained when rules form a route.

Let \mathcal{D} be the finite set of compliance domains. A deployment’s compliance state assigns its own grade and applicability treatment to each relevant domain. The companion paper How Compliance Composes defines that typed object and proves its composition rules (Reference [1]). We restate only the type and identities needed here.

Definition 4.1 (Directed corridor policy).

Fix request context q, destination v, and use time t. Context binds the act, subject, purpose, and applicable rule versions. A directed policy is \mathcal{P}_{uv}=(\mathsf{id},u,v,R_{uv},F_{uv}, \varphi_{uv},\gamma_{uv},a_{uv},[t_0,t_1],\Omega_{uv}). The carrying set R_{uv}\subseteq\mathcal D selects evidence domains. The fresh-question set F_{uv}\subseteq\mathcal D selects destination questions requiring current local evaluation. The sets can overlap. The predicate \gamma_{uv} states admissible contexts, and a_{uv} is the destination’s policy authority. The obligation record \Omega_{uv} retains each clause, owning authority, destination, trigger, request, instrument, deadline, stage, and disclosure requirement. Fresh questions are its designated local-evaluation clauses. The signed digest binds the complete tuple, exact context, retained instrument, and predecessor.

A grade is an ordered summary of evidence treatment in one domain. To compare different institutions’ treatments, their local meanings must first be represented in the same ordered set. Monotonicity means that increasing the input grade cannot decrease the transported grade. Deflationarity means that transport cannot increase the grade above its input. Bottom preservation keeps the least grade fixed.

For each carried domain d, fix a common comparison grade G_d with least element \bot_d. The map \varphi_{uv,d}^{q,t}:G_d\to G_d is monotone and bottom-preserving. It is deflationary in that comparison grade. Distinct local encodings require explicit semantics-preserving embeddings into G_d. An unavailable embedding leaves the transport type unresolved.

The transported object is a typed evidence witness, with original act, subject, purpose, source interval, and policy derivation. Its grade summarizes only witnesses jointly admissible for q and t. Import appends the witness and its treatment. It leaves the destination’s authoritative decision record unchanged.

The labels describe actual component maps. Full denotes identity. Partial denotes a specified deflationary non-identity map. Conditional enables the declared map when its named carriage prerequisite holds. An identity-on-success profile and a guarded discount are both possible. A resolved false prerequisite supplies no admitted witness. An unanswered prerequisite remains unresolved. None denotes absence from the carrying set. A label alone determines neither permission nor an ordering between policies. Fix a common domain and context universe for comparison. For fully resolved policies, extend each map by \widehat\varphi_{P,d}^{q,t}(g)= \begin{cases} \varphi_{P,d}^{q,t}(g),&\text{if transport is carried and admitted},\\ \bot_d,&\text{if transport is explicitly excluded or refused}. \end{cases} An unresolved context or missing embedding leaves the comparison unresolved. It does not become bottom. Evidence-map comparison uses P\preceq Q \quad\Longleftrightarrow\quad \widehat\varphi_{P,d}^{q,t}(g)\leq \widehat\varphi_{Q,d}^{q,t}(g) \text{ for every }(d,q,t,g). This order compares transported evidence grades. Fresh questions, policy authority, and operational permission retain their separate checks. Partial and Conditional maps can be incomparable. A representation that infers fresh questions by complement represents only policies whose declared fresh set equals \mathcal D\setminus R. It cannot encode an overlapping fresh question.

Here the request-dependent notation A_v(q) denotes a set of required domains, distinct from the acceptance sequence A_v above. Let A_v(q) contain every domain required by the local act. Each domain has a current local decision J_{v,d}(q,t)\in\{\mathsf{Allow},\mathsf{Refuse},\mathsf{Pending}\}. An authorized local rule can reuse a transported witness to answer a question automatically. A question in F_{uv} still requires its destination-owned current evaluation. Where discretion is required, the signed answer binds the exact question and permitted use. Other supported evaluations run under reusable delegation.

The act is permitted only if its local authority is valid and every required decision is \mathsf{Allow}. Required evidence availability and reliance must also pass. Any current refusal refuses the act. An unresolved required question keeps the act pending. Inapplicability requires the local rule’s explicit treatment.

Proposition 4.2 (Recognition preserves reserved decisions).

Import can discharge an evidence requirement without changing an authoritative local refusal. If a required local decision is \mathsf{Refuse}, transport alone cannot permit the act.

Proof. Transport changes the evidence store and its derivation receipts. It does not write the authoritative decision record. Permission requires every required decision to equal \mathsf{Allow}. The unchanged refusal therefore prevents permission. An admitted foreign witness can satisfy another evidence predicate without a second source act or signature. ◻

For example, source evidence can establish an applicant’s identity while the destination separately decides a reserved licensing question. Both questions can concern the same domain. Recognized evidence removes repeated identity collection. The destination can permit the licence under its own current rule or retain a refusal.

The sanctions domain follows the same separation. Reliance on source screening requires an instrument binding list version, matching rule, ownership aggregation, transaction context, and interval. Destination law supplies the permitted scope of reliance. Its reserved questions remain in the fresh set, including carried domains.

For a fixed admissible context, evidence transport along u\to v\to w composes as R_{uw}=R_{uv}\cap R_{vw},\qquad \varphi_{uw,d}^{q,t} =\varphi_{vw,d}^{q,t}\circ\varphi_{uv,d}^{q,t}. The route retains the ordered policies and destination-tagged fresh obligations (v,F_{uv}) and (w,F_{vw}). These obligations do not collapse into a destination-free union. The composite context requires each edge’s admitted context and valid authority-use contract.

Function composition is associative. Monotonicity, bottom preservation, and deflationarity survive composition in the common grades. An identity transport retains its evidence witness. These transport identities leave every local decision at its owning destination. New evidence derived at an intermediate destination carries its own admitted derivation or source act. It cannot refresh the original assertion by relabeling its receipt.

4.1 A complete interface for recognition

An identity file can answer an evidence question while the receiving authority retains a current licensing decision. Both can concern one domain. A complete interface carries the file, the local question, and every duty that its use creates. The carrying set alone determines none of those duties.

A source cell is one attributed source observation with its scope and evidence. An obligation body records what must be done, by whom, and under which trigger. An effect plan identifies the acts that a permission allows. Their occurrence, and the duties they activate, require the corresponding events.

Definition 4.3 (Recognition receipt).

A recognition receipt contains four components:

  1. The original attributable source cells. Each cell retains its authority, jurisdiction, domain, subject, purpose, source act, rule, instrument, scope, interval, value, and derivation roots.

  2. The current treatment of each cell under the carried grade maps.

  3. The ordered complete policies, with their exact request contexts, authority records, intervals, and carriage prerequisites.

  4. The instantiated obligation bodies, with their owning authorities, identities, deadlines, stages, and disclosure requirements. Separate completion events determine their current status under each named rule.

An obligation’s role distinguishes fresh decisions, prerequisites to a named effect, and continuing duties created by that effect. The last remain conditional until admitted events establish their triggers. Permission alone supplies an effect plan. The same cell or obligation identifier has one immutable admitted body. A conflicting body makes the receipt inadmissible. Obligation identity binds the legal trigger and request. A repeated delivery retains the existing obligation. A new legal trigger has its own identity.

The common corridor record retains the independent carrying and fresh fields. The fresh mask is the domain projection of its local-evaluation obligations. Import prerequisites determine when evidence may enter. Other questions can remain pending while imported evidence supplies their inputs. Their owning destination decides them under its own rule. An obligation reaches completion only through its named completion rule. Higher grades leave reporting and payment duties intact. Admission checks the prerequisites of its named stage. A later reporting duty can remain outstanding after the authorized act that creates it. Traversal identity is separate from policy identity. An exact traversal retry retains its result. A new traversal can reuse the same policy.

An evidence grade and a judgment about applicability answer different questions. The product of an applicable grade and an applicability-marker set records the two axes. In increasing order, the applicable grades are NonCompliant, Pending, and Compliant, with an additional empty-fold top. This top is the identity for aggregation when no applicable grade has been supplied. It does not assert a compliant observation. The markers are NotApplicable and Exempt. Each family aggregates applicable grades by minimum and markers by union. Thus NonCompliant from one authority and NotApplicable from another retain both observations. The receiver admits the source cells before calculating this summary. A local five-label display alone cannot reconstruct their separate scope judgments.

Proposition 4.4 (Lossless receiver normalization).

Fix the finite domain, clause, and grade-map vocabulary. The producer and receiver representations of Definition 4.3 are inverse when both retain all named fields. Their conversion preserves carrying/fresh overlap and authority-indexed obligations. Composing receipts by concatenating complete policies preserves those fields under either parenthesization, when their immutable source and obligation records are compatible.

Proof. Fieldwise conversion followed by its inverse returns the original record. The two masks occupy independent fields. Obligation records retain their own destinations even when their domains coincide. Concatenation is associative, as is compatible union of immutable cells and obligation records. Per-cell grade treatment composes by function composition. Each edge retains its own authority and request context. None of these operations writes a local decision or completes a duty. ◻

This normalization concerns admitted records. The receiving instrument supplies the legal basis for their use. A transport summary is a projection of the record, with the corresponding restricted meaning.

Example 4.5 (Reuse followed by a reserved local decision).

Let one domain contain identity evidence and a licensing question. The source supplies an admitted identity cell at grade Compliant. The corridor carries that domain at identity and also lists it as fresh. Import supplies the identity witness while the local question remains Pending. The destination’s current rule reuses the witness and records its own Allow. An authorized licence-issuance event activates one report due at its specified deadline. Repeating the import supplies neither a second source act nor a second reporting obligation. A destination Refuse instead remains binding under Proposition 4.2.

4.2 Replacing a running route

An institution may replace an existing route while requests or duties remain outstanding. Equal final grades can conceal different reports, deadlines, or permitted disclosures. Route substitution therefore uses the observation contract of the relying institution. Each observation contains its verdict, authority attribution, evidence treatment, effect plan, outstanding obligations, deadlines, disclosure, and continuation status.

For a bounded model, represent a route by a finite deterministic total machine over admitted evidence, local-answer, policy, and time events. An event produces an observation and a successor state. The observation contract specifies everything the relying institution treats as relevant. A finite input word is a finite sequence of these events. Refused and unresolved events have explicit outcomes. To compare two machines, explore their reachable state-pair graph. At every pair, compare the observations for every input and retain any distinguishing input word.

Proposition 4.6 (Complete finite route comparison).

For two such machines over the same alphabet and observation contract, the product comparison terminates. It returns a distinguishing finite word exactly when some finite word gives different observation sequences.

Proof. The product has finitely many state pairs. Each explored pair has a recorded input path. A different next observation therefore supplies a distinguishing word. If every explored transition agrees, induction on input length proves equal output sequences. Any differing sequence has a first different output at a reachable pair, which the procedure checks. ◻

Two machines can pass despite different internal cache states. Two Allow outcomes fail when they impose different reports or deadlines. Omitting those fields would change the observation contract and its conclusion. The finite comparison proves the behavior of the encoded machines. Instrument adoption, actual evaluator refinement, and unbounded or nondeterministic environments retain their separate proof obligations.

4.3 Route cost

Behavioral equivalence does not estimate delay or the chance that a route encounters an impediment. The following expression addresses a separate probabilistic question for a declared use. Corridors are directed. \mathcal P_{uv} and \mathcal P_{vu} may differ in carrying sets, fresh questions, maps, authority, and interval. A path u=v_0,\ldots,v_k=v has route friction \Phi(u\leadsto v)=1-\prod_{i=1}^{k}(1-\rho_i). Here \rho_i\in[0,1] is the independently estimated friction of edge i for this use. To interpret the expression as the probability of at least one impediment, each estimate must refer to its specified edge event. The product assumes independent edge risks. Correlated edges require a joint model. The maximum is not equivalent.

4.4 The compliance passport

A compliance passport is a portable package of statements, derivations, and the retained evidence needed to check them. Its recognition receipts retain the complete carried contents and duties. The passport carries this evidence to a destination whose own policy governs its use. The genesis record is the initial trusted record from which the presented chain begins. Before using the passport, a destination performs six checks:

  1. Validate the passport schema and every content digest.

  2. Verify the chain from the declared genesis record to the presented head.

  3. Verify each source signature and issuance-authority witness at issuance time.

  4. Verify every corridor edge, immutable policy version, and destination authority in the route.

  5. Check the retained manifest, source intervals, evidence cutoff, status completeness, and named authority-use stage.

  6. Apply the local domain mapping, reserved-domain rule, evidentiary treatment, and decision authority.

These checks return the separate historical, reliance, and operational results from Section 2.2. Retained packages support offline historical verification at their recorded cutoff. Current use requires the applicable authority-source contract. Selective presentation proves the disclosed relation while leaving omitted required premises pending. The source and destination remain accountable for their respective assertions and decisions.

4.5 Corridor receipts

A recognition receipt describes what a route carries. An acceptance receipt records the destination’s signed decision to admit a statement from that package. Its digests identify the statement, route policies, and retained manifest used for that decision. An acceptance receipt contains \begin{split} (&\mathsf{issuer},\mathsf{destination},\mathsf{subject}, \mathsf{statementDigest},\mathsf{route},\\ &\mathsf{originalAct},\mathsf{originalValidity}, \mathsf{policyDigests},\mathsf{sourceAuthorityDigest},\\ &\mathsf{destinationDecisionAuthority},\mathsf{manifestDigest}, \mathsf{evidenceCutoff},\mathsf{useStage},\\ &\mathsf{localTreatment},\mathsf{acceptedAt}, \mathsf{priorReceiptDigest},\mathsf{signature}). \end{split} The signature covers canonical bytes of every preceding field, including the predecessor link. A mismatched link rejects extension. JSON Canonicalization Scheme fixes JSON bytes, not institutional meaning (Reference [8]).

4.6 What a sequence of disclosures reveals

Recognition can authorize selective disclosure instead of transfer of the complete source record. The destination must then account for what its earlier disclosures already revealed. A permitted answer changes what its recipient can infer from later answers. Suppose three records contain values A,B,C. Releasing their pairwise sums gives r_1=A+B,\qquad r_2=B+C,\qquad r_3=A+C, \qquad A=\frac{r_1+r_3-r_2}{2}. Each answer combines two records. Together, the answers determine every record. A valid signature authenticates this disclosure without limiting the recipient’s subsequent calculation.

The exact linear case admits a complete test. Fix one source snapshot x\in\mathbb Q^n, where n>0. Public row vectors describe the permitted queries. A matrix H records every row already observed by one recipient coalition, together with its declared linear auxiliary knowledge. The coalition includes recipients whose observations can be combined. Purpose labels remain permission conditions within this common history. Let q_1,\ldots,q_m be protected rows, whose values q_jx must remain undetermined. Assume each q_j lies outside the row span of H.

Proposition 4.7 (Exact linear disclosure criterion).

For a proposed public query matrix R, put M=\begin{pmatrix}H\\R\end{pmatrix}. The observations Mx determine qx for every x\in\mathbb Q^n exactly when q belongs to the row span of M. Otherwise, every compatible source x belongs to a rational affine family with the same observations and distinct values of qx.

Proof. If q=\lambda M, then qx=\lambda(Mx). Conversely, if q lies outside the row span, elementary elimination supplies v\in\ker M with qv=1. Every x+tv, for t\in\mathbb Q, gives the same observation Mx, while q(x+tv)=qx+t. Thus the observations cannot determine qx. ◻

For the three-record example, the first two rows leave direction (1,-1,1) unobserved. All three protected coordinates remain undetermined. A second release of 2(A+B) preserves this property. The third pairwise sum removes that direction and fails the criterion. The admissible query set therefore includes useful aggregates and exact linear combinations of previously admitted answers.

Definition 4.8 (Disclosure admission).

A release is admissible when every required source permission holds and q_j\notin\operatorname{rowspan}\begin{pmatrix}H\\R\end{pmatrix} \qquad (1\leq j\leq m). The admitting store durably appends the complete matrix R before returning any component of Rx.

The condition is exact for this observation model. Its source domain is the unrestricted rational space. For nonnegative A,B, the observation A+B=0 already determines both values. That inference uses the domain constraint, which a row-span test alone omits. Nonlinear constraints, approximate inference, and statistical privacy require their own models. The public query choices must also be independent of private values. A privately chosen query can disclose information through its identity, even when its numeric answer passes the test.

4.7 Durable admission for concurrent requests

Two requests can each pass against one history and fail when combined. After releasing A+B, both B+C and A+C pass separately. Admitting both would disclose A,B,C. Each coalition therefore uses one authoritative disclosure store for the fixed snapshot and protection profile. Every admitted release participates in its serial order.

A local disclosure-store implementation uses an immediate SQLite transaction. SQLite provides the local transactional database for this construction. It reads the committed history, checks current grants, composes the new rows, and performs exact rational elimination. On success, it records the command, query, result, source lineage, grant digests, and predecessor. Only the committed transaction can return numeric results. A retry binds the same command to the same artifact, purpose, audience, and retention deadline. It checks current release permission before returning the recorded result.

Proposition 4.9 (Preservation under serial disclosure).

Assume the initial history satisfies Definition 4.8’s row-span condition. Assume one trusted store serializes admission and every numeric release follows its durable commit. Then every committed history leaves each protected row outside its row span. Repeated delivery of one committed result adds no row to that span.

Proof. Induct over committed transactions. A refused transaction leaves the history unchanged. An admitted transaction checks exactly the successor history before committing it. The condition therefore holds after each commit. A repeated row lies in the span of its first occurrence. ◻

A crash before commitment releases nothing through this interface. A crash after commitment preserves the disclosure in the history even when delivery remains uncertain. Retrying then returns its recorded value. This conservative treatment prevents a failed acknowledgment from restoring permission to disclose an incompatible query. Deleting an output under its retention rule also preserves the rows needed to account for what a recipient may remember.

The store protects its stated coalition and snapshot. Separate stores need a common admission authority before their outputs can compose under this result. Later auxiliary knowledge and changed protection rules require a new comparison against all existing observations. Trusted storage, complete mediation, authenticated coalition membership, and current authority evidence remain explicit implementation premises.

4.8 Permissions of derived artifacts

The cumulative disclosure test answers whether a release reconstructs a protected value. The right to perform the computation is a separate question. Computation, disclosure, model training, and commercial use are distinct acts. A source grant names its instrument, source, act, purpose, audience, validity interval, and retention bounds. The host admits the instrument and its authority evidence. The construction preserves that evidence without deciding its legal adequacy.

An immutable operation plan binds the exact input artifacts, public transformation, operation class, and classification authority. Execution accepts that plan identifier and obtains the operation class from the admitted record. The caller cannot relabel a training plan as computation. The competent authority still determines the licensed meaning of an act. An identical matrix can implement different purposes, so its coefficients alone cannot establish that classification.

Represent an artifact by (T,L), where its values are Tx and L contains all source obligations inherited from its parents. For a public linear transformation U, derivation produces (UT,L). Several parents contribute their stacked rows and the union of their source obligations. A zero coefficient preserves the obligation of a source used in that derivation. A different, independently authorized computation can use a smaller set of inputs.

Definition 4.10 (Action-specific permission composition).

For act a, purpose p, audience c, use time t, and retention deadline d, choose one applicable grant for every source in L. Each chosen grant must permit exactly this act, purpose, and audience at time t. If source i requires retention within [\ell_i,u_i], then \max\bigl(t,\max_{i\in L}\ell_i\bigr) \leq d\leq\min_{i\in L}u_i. Every parent artifact must also remain available under its own retention deadline. An empty interval refuses this use and preserves its reason.

Grant composition takes an intersection across source obligations. A separately issued training grant changes the training decision only within its own scope. Disclosure and commercial use retain their own grants. Effective revocations govern each subsequent use while the earlier grant and its historical use remain recorded.

Proposition 4.11 (Preservation of source obligations).

Every artifact constructed from admitted parents retains every source obligation of those parents. An authorized derived use supplies one current, action-specific grant for every retained source.

Proof. The source case has its single source obligation. Derivation takes the union of parent obligations, so induction preserves each source. Authorization checks every element of that union against the named act and scope. Linear simplification changes the rows, leaving the union unchanged. ◻

An aggregate can consequently support local research while its training request remains refused. With separately admitted training grants, a public full-column-rank design X yields the least-squares coefficient map (X^{\mathsf T}X)^{-1}X^{\mathsf T}. This map acts on the admitted response artifacts and preserves their source obligations. Releasing its coefficients passes through the same cumulative disclosure test. An intercept-only fit releases a mean when its history permits it. A saturated fit can determine the original responses and is refused by the exact reconstruction rule.

The local disclosure-store implementation checks these mechanisms with exact fractions, real process races, and process termination on both sides of commitment. It retains grant evidence and deadlines in trusted local storage. Enforced deletion, undisclosed recipient knowledge, general statistical learning, and actual instrument authority have separate evidence requirements. In particular, permission to compute a result leaves its disclosure decision dependent on both source rights and accumulated observations.

5 Executing a Decision Against Current Records

The recognition rules determine what a destination may do. Execution must ensure that the facts supporting that permission remain current until the required act. South’s proposed branch entry must fail if a relevant withdrawal becomes effective before that stage.

A deployment can realize the event model through one authenticated write boundary: the point through which every protected record change must pass. The theorem below assumes exclusive control of that boundary and complete protection of the decision’s dependencies. Reference [2] gives the companion account of local commitment.

Theorem 5.1 (Conditional one-writer realization, N=1).

Let N=1 be the number of authenticated writers for deployment v, and fix its protected records. Assume:

T1.

The deployment writer alone holds write credentials.

T2.

Every write-reaching path passes through one commit boundary implementing N3–N6. One strictly serializable transaction validates the complete guard dependencies and target predecessor. It protects them through durable append and checks time-dependent guards at the actual durable event.

T3.

The storage schema prevents direct update and deletion of protected entries.

T4.

Record heads use a collision-resistant digest.

Then every served storage mutation is an admitted append linked to its predecessor head. Its guard holds in the serial predecessor state at its named use stage.

Proof. Exclusive credentials place every admitted write at the deployment writer. The domination assumption sends every write-reaching path through the commit boundary. Its predecessor check prevents two successful writes from consuming one head. Its complete dependency protection preserves every mutable guard premise through durable append. The schema restricts the record effect to append. Collision resistance makes substitution below a served head detectable. ◻

This is a conditional deployment theorem. Raw storage replacement, compromised credentials, a missed write path, schema alteration, or digest failure lies outside its conclusion.

5.1 Realizing complete guard transactions

The main implementation difficulty is discovering everything the decision reads. A direct lookup can depend on an ownership rule, which identifies a different authority and another required participant. Those determining records must also remain fixed. An authority-resolution root identifies the admitted record from which authority lookup starts. A participant-selection root similarly determines whose agreement the transaction requires.

For event e with target X_e, let \mathcal{D}_e contain every mutable input to its guard. Its witness contains \rho_e=\{(Y,\operatorname{head}(Y)):Y\in\mathcal{D}_e\cup\{X_e\}\}. The set includes indirect reads through rules, accepted evidence, and authority chains. It also includes corridor, authority-resolution, membership, and participant-selection roots. Collection heads protect absence and range queries. Instrumented reads enforce completeness. A conservative implementation can bind the complete protected-state head.

A reservation prevents a conflicting change while the decision is unresolved. Read mode protects a required value. Write mode also reserves the record to be changed. The witness fixes every resource and its reservation mode before acquisition. The constructor’s known target has write mode. Every other dependency has read mode. Repeated resource identifiers coalesce at the strongest required mode. The target therefore acquires write mode on its first reservation.

Within one deployment, a commit mutex and one durable transaction suffice. Every protected-state writer uses that mutex, including administrative and revocation paths. The boundary validates \rho_e, evaluates the guard, and appends before releasing it. It reads the admitted clock at the actual durable event. Clock-error bounds must make interval acceptance conservative. A proposal timestamp cannot establish authority at a later commit. Immutable signature checks can run beforehand when the boundary binds their exact input bytes.

Strict read and write reservations can replace the mutex. They must protect the complete dependency set through durable append. Separate validation followed by an unprotected append permits revocation between the two operations. Checking only the target head also permits that history.

Current dependencies owned elsewhere.

Each required owner validates the exact event and durably reserves its dependency versions. The destination reserves its target and local dependencies. Prepared records bind the transaction identifier, event digest, participant set, dependency roots, resource modes, permissible interval, named use stage, and fencing epoch. A fencing epoch identifies the admitted writer generation. Its verifier rejects a delayed writer from an earlier generation.

The destination uses a replicated decision journal under an explicit fault model. Its commit transition durably records the exact event, new head, and transaction outcome together. Commit requires every required preparation and valid time constraints at that transition. The decision journal records one terminal outcome for the transaction. It supplies transaction agreement, while constitutive authority remains with each participant.

The dependency roots determine the complete participants and resource modes before reservation acquisition. Preparation revalidates those roots. A changed root invalidates the attempt. Existing preparations resolve terminal abort before a fresh attempt recalculates the complete dependency set. Participants retain conflicting-state protection until the terminal decision is resolved. They cannot release a prepared reservation solely because a local timer expires. Deadline expiry requests an abort through the decision journal. Commit and abort compete in that journal’s single terminal transition.

Recovery reconstructs unresolved reservations before it admits conflicting writes. A replacement writer preserves the obligations of earlier prepared transactions. A local epoch change cannot cancel a remotely committed decision. Recovery queries the decision journal and applies its exact result. An unknown outcome retains its reservations.

Participants acquire reservations in one canonical order on deployment and record identifiers, using their declared final modes. They never upgrade a held read reservation. A changed resource set or stronger required mode requests terminal abort before release and retry. Unknown outcomes retain the existing reservations. Fair queues resolve contention. Retries use the same immutable command identity and a distinct transaction attempt. Under eventual communication and recovery, a finite valid transaction can complete when its dependencies remain admissible long enough. These conditions provide progress for useful operations and prevent circular reservation waits.

The complete policy and obligation records from Section 4.1 also enter this guard dependency set. So do their discovery, authority-resolution, and participant-selection roots. If an obligation reads a shared allocation record, that record’s authoritative owner participates. An alias-resolution or ownership-root change invalidates the old participant discovery. The attempt follows terminal abort before recomputing and preparing a new dependency set. This requirement applies to absence predicates and indirect reads through adopted rule definitions.

Authority at the required stage.

A record reservation preserves recorded state. Its institutional basis must also authorize the particular use through the named stage. One sufficient basis is an enforceable limited authorization consumed at that stage. Another places effective revocation and the named use at the same authoritative serialization boundary. A storage fence alone supplies neither basis.

Each preparation declares which basis applies. Under the shared-boundary basis, effective revocation participates in the terminal decision instead of waiting behind a storage reservation. A prepared vote alone cannot predetermine that decision. Under the limited-authorization basis, the instrument defines the particular use preserved through its named stage.

Revocation intake preserves both effective time and recorded time. It never withholds a notice to maintain a prepared guard. Before commit, an effective revocation that defeats the use contract causes abort. A lawfully consumed earlier authorization retains exactly its granted effect. Later or retroactive evidence enters the correction procedure and current-use assessment while preserving the original record.

The authority source supplies the currentness and availability premises required by its use contract. An unobserved legal change cannot become known merely through a valid signature or an unchanged local head. A current-use conclusion therefore requires an institutionally sufficient reservation or an authoritative revocation/use boundary. The protocol carries this obligation explicitly.

A durable local authorization can precede dispatch or provider acceptance. Each later stage applies its own authority-use contract. A queue or outbox retry cannot promote an earlier-stage witness into continuing authority. If the governing rule requires authority at provider acceptance, that provider participates in the named transition. An exact delegated command also suffices when its governing instrument makes that earlier acceptance effective and irrevocable. Otherwise the later dispatch or acceptance performs a fresh current-use transition. The program preserves its identity and resumes through the same typed runtime.

Proposition 5.2 (Guard transaction refinement).

Assume complete dependency enumeration, exclusive reservation enforcement, one durable terminal decision, correct recovery, and the stated authority-source and clock premises. Every committed guard transaction implements one transition satisfying N3–N6 at its named use stage.

Proof. Order transactions by their durable terminal transitions. A successful transaction has matching target and dependency versions at its transition. Exclusive protection preserves every mutable guard input. The guard checks the actual event time and exact request bytes. Its named authority-use contract supplies each required institutional premise. Thus the guard holds in the serial predecessor state. The terminal transition appends one entry with its new head. Recovery preserves the same decision and reservations. Induction gives the required refinement. ◻

A provider completion, physical delivery, or later legally operative act has its own named transition and evidence. The local append theorem covers its recorded decision. Its broader institutional effect follows the corresponding authority-use and provider contract. This construction preserves automated execution, suspension, recovery, and sovereign participation across those boundaries.

5.2 Capacity with local dependencies

Complete dependencies also identify which decisions can proceed independently. A service domain is a unit with an exclusion or capacity constraint, such as a record owner or provider. Service domains differ from the compliance domains used to classify evidence. A network can add execution capacity through additional independently served domains. The complete dependency set determines whether those domains can work concurrently. A command’s service footprint includes its storage, decision journal, authority checks, communication, workers, and required provider stages. Shared services count even when their names are absent from the business request.

Fix a batch of m\geq1 ready commands using N active service domains. Every command has a nonempty footprint. Each domain represents an exclusion or capacity constraint. Two commands conflict when their footprints intersect. This conservative rule can serialize compatible reads. It gives a sufficient schedule without assuming free service capacity.

Readiness includes exact requests, valid authority-use contracts, and separately available funding or resource allocations. Every remaining command must remain feasible after each admitted batch prefix. Fresh attempts rebind current heads and check their guards. Commands that need another command’s output belong to a later readiness phase.

Proposition 5.3 (Distributed execution capacity).

Let k,h be positive integers. Assume each command uses at most k domains and each domain serves at most h commands in the batch. Suppose:

  1. Every disjoint-footprint wave completes successfully within \tau>0, including its required admission, coordination, and provider work.

  2. Scheduling and preparation take at most S\geq0. Outside work respects the reserved service capacity.

  3. Every command preserves the common occurrence and allocation invariants under Section 5.1.

Then the batch admits a schedule with C waves and completion time T>0 satisfying C\leq\min\{m,k(h-1)+1\},\qquad T\leq S+C\tau. Its completed-command rate satisfies \frac{m}{T}\geq \frac{N}{k\{S+\tau[k(h-1)+1]\}}. The resulting execution preserves the common resource invariants.

Proof. A command shares each of its at most k domains with at most h-1 other commands. Its conflict-graph degree is therefore at most k(h-1). Greedy coloring gives at most k(h-1)+1 colors, and at most m colors suffice. Each color is a disjoint-footprint wave. The service premise completes that wave within \tau. Persistent feasibility permits the succeeding waves. Including preparation gives the time bound.

Every active domain belongs to at least one command footprint. Hence N\leq km. Combining this inequality with the time bound gives the rate bound. Disjoint-footprint events commute under complete dependency enumeration. N5 serializes conflicting events. Induction applies the assumed resource invariant to the resulting execution. ◻

The bound scales with active domains when k,h,\tau, and S remain bounded. Idle deployments contribute no throughput floor. A repeated schedule can amortize its construction cost. Each reuse still checks the current authority, dependencies, and reserved capacity. A central scheduler whose work grows with the entire batch must include that cost in S.

The bounded service premise is stronger than eventual communication and recovery. A partition can retain safe reservations while suspending completion. A shared decision journal, universal provider, authority-resolution service, or resource owner can increase h or \tau. A larger network alone does not remove those constraints.

Dependent workflows retain their required order. For L successive ready phases with uniform k,h,S,\tau, a sufficient completion bound is L\{S+[k(h-1)+1]\tau\}. A chain of independently funded commands requiring predecessor completion receipts can require L=m. Each command changes its own hosted token and appends its receipt. The next command checks that immutable receipt. Each command then touches at most two local services. Funding conflicts can likewise defeat persistent feasibility. The runtime must construct feasible phases, rather than infer them from small footprints.

A positive construction partitions N=kg domains into g independent corridor groups. Give each group h funded commands with stable authority and disjoint allocations. One command per group executes in each of h waves. The gh commands finish in service time at most h\tau. Their service rate is at least N/(k\tau). Both endpoints and any required provider services belong to their group’s counted footprint.

Economic quantities.

The rate of completed decisions does not measure the assets they concern. Repeated recognition can produce many receipts for one resource. The same identity discipline must therefore govern aggregate support before that support is valued. For each canonical resource occurrence o, let c_o be its admitted support. Let x_{o,j} be the currently supported slice allocated to obligation j. The authoritative allocation boundary for occurrence o enforces x_{o,j}\geq0,\qquad \sum_jx_{o,j}\leq c_o. Jurisdictional receipts reference these same slices. Additional recognition creates neither another occurrence nor additional support. Unsupported historical allocations retain their owners and correction obligations outside currently available capacity. Current spendable funding keeps its separate balance and reservation equation.

A supported asset stock uses one declared economic perimeter and counts each canonical asset once. Constitutive interests and their underlying assets cannot both enter the same look-through total. With supported quantities q_a(t) and externally justified prices p_a(t) in one numeraire, that total is V(t)=\sum_{a\in\mathcal U(t)}p_a(t)q_a(t). Here \mathcal U(t) contains distinct assets at the common valuation cutoff. Resource quantities with different units remain separate before valuation.

An aggregate value target V_\ast requires evidenced support and prices satisfying V(t)\geq V_\ast. Disjoint asset sets contribute their values additively. A limit on one support domain therefore need not limit the aggregate to that same amount. The service premise includes the actual representation, validation, and storage costs of the supported quantities. Increasing independently supported asset domains can increase aggregate support. Supplying persistently feasible activity across their bounded service footprints also increases execution capacity under the proposition’s conditions.

Completed commands per time, transferred quantity per time, supported stock, and economic value have different units. Authorized reuse can increase transfer flow while leaving supported stock unchanged. Revenue requires actual fees and executed activity. Net returns additionally require costs, losses, and invested capital. Those quantities follow their economic evidence rather than the authority-preservation theorem.

6 Bilateral Signed Commitment

A single-target event records one institution’s decision. Some agreements require two institutions to authorize the same terms. A bilateral signed commitment collects those matching decisions while each endpoint retains its local writer. Reference [3] gives the session form and evidence attributing conflicting conduct.

Protocol finality F_P means ledger confirmation: a valid commit certificate is durably recorded at the named endpoint. Legal finality is the effect that governing law and the applicable system rules give that record. The two properties have different authorities and measurement boundaries.

For agreement digest d, each endpoint moves through \mathsf{Init}\rightarrow\mathsf{Locked}\rightarrow\mathsf{Verified} \rightarrow\mathsf{Committed}, with \mathsf{Aborted} available through the agreed terminal-decision protocol. A lock names d, its endpoint, predecessor, deadline, and authority. Verification checks both locks and current policies. A commit certificate contains both authorizations over one digest and validity interval. An endpoint can decline preparation locally. Once prepared, deadline or validity failure requests a durable abort decision. Prepared reservations remain until the unique terminal outcome is resolved under Section 5.1. Matching authorizations supply the certificate. The terminal record binds that certificate to the transaction decision.

Proposition 6.1 (Matching-authorization certificate).

Assume unforgeable signatures and valid endpoint witnesses. If an honest endpoint records \mathsf{Committed}(d), both sovereign authorities authorized d. Their local writes need not be simultaneous.

Proof. Commitment requires both endpoint signatures over d and one validity interval. Unforgeability and valid witnesses attribute those signatures. Earlier recording by one endpoint cannot change their digest. ◻

Ledger confirmation is not legal finality. The certificate proves matching authorization. It does not determine the agreement’s legal effect.

Proposition 6.2 (Two-sovereign commit bound).

Fix two endpoints joined by a channel that may be partitioned indefinitely. No third party helps choose the terminal. No deterministic commit protocol has all three properties. Agreement forbids one committed endpoint beside one aborted endpoint. Bounded termination gives both endpoints fixed terminal deadlines. Nontrivial validity commits an all-consent delivered execution and requires evidence of both consents.

Proof sketch. List the delivery prefixes of the all-consent execution, and impose a permanent partition after each. Bounded termination assigns terminals from local views. At the empty prefix, validity forces both to abort. At the full prefix, both commit. Consider the first delivery that changes a terminal. Only its recipient’s view changed. Agreement requires the other endpoint’s fixed terminal to equal the recipient’s terminal before and after that delivery, which is impossible. ◻

The bound requires relaxing termination, agreement, or validity during an indefinite partition. The certificate proposition remains valid. Common-terminal recovery needs durable certificate availability and eventual delivery.

6.1 Partitions and healing

After communication returns, the endpoints compare signed records.

  1. An endpoint can decline preparation when its deadline passes. Local absence of a second lock or certificate proves no global absence. A prepared transaction requests abort through the unique durable terminal decision. It retains its reservations while the outcome remains unknown.

  2. With two matching locks, either endpoint can assemble the authorization certificate during the validity interval. It submits that certificate to the agreed terminal-decision protocol.

  3. With a certificate at one endpoint, the other verifies the certificate and the durable terminal decision before applying the outcome.

  4. Competing signed digests satisfy no commit rule. Their signed conflict attributes the disagreement and supplies a blame witness for the dispute route.

The construction guarantees attributable agreement evidence. Partition availability, certificate replication, and common-terminal recovery remain communication and honest-recovery assumptions.

7 Corridor Governance

A receiving institution also needs to know which recognition rule is in force. Adoption, suspension, and replacement change future use while earlier decisions and continuing duties remain recorded. The lifecycle below separates those policy states from the authority required to enter them.

7.1 Lifecycle

A typestate records which stage of this lifecycle a corridor version has reached. A corridor version follows the typestate \begin{split} \mathsf{Draft}&\rightarrow\mathsf{PendingEndpointRatification} \rightarrow\mathsf{PendingRouteNotice}\\ &\rightarrow\mathsf{RatifiedPendingWindow}\rightarrow\mathsf{Active}. \end{split} The \mathsf{Active} state has six outgoing branches. The stopping states are \mathsf{Halted}, \mathsf{Suspended}, and \mathsf{Revoked}. The record states are \mathsf{SupersededDraining}, \mathsf{Retired}, and \mathsf{DisputedOverlay}. The pending states retain the ratifications, notices, or activation window still required. SupersededDraining retains unresolved work under a replaced version. Retired records the end of that version’s use. Every transition names its authority, scope, effective time, predecessor, and notices. \mathsf{DisputedOverlay} records a commenced proceeding over the base state without replacing it.

A watcher observes a deployment’s signed records and reports what it has checked. Its observation can supply evidence for an authorized decision. Four rules preserve the authority boundary.

  1. Watchers observe, sign observations, and attribute disagreement. They do not amend law or corridor policy.

  2. A registration change uses the named registration authority and its instrument-defined conditions. A bond draw uses a separate custodian mandate, liability decision, and funded bond record. A blame certificate supplies evidence for those decisions.

  3. A destination authority may tighten its recognition treatment prospectively under its local rule.

  4. Loosening recognition requires endpoint ratification, route notice, and passport checks. Shared sanctions reliance also requires a current shared-authority certificate and revocation check.

The accession of new participants is a separate construction, developed in Accession Networks (Reference [4]). Disputes about terminal disagreement, emergency relief, and the \mathsf{DisputedOverlay} proceeding belong to the dispute layer (Reference [5]).

7.2 Watcher evidence

Several signatures can come from keys under one controller. The receiver therefore needs evidence about who signed and which signers can fail together. An epoch is the fixed configuration under which those signatures are compared. A watcher epoch binds the principal registry, control graph, graph policy, certificate policy, and authenticated time anchor. The registry maps each signing key to one stable watcher principal. Multiple keys for that principal count once. A key cannot name two principals.

The control graph records ownership, decision power, operating authority, and signing-key administration. Each relationship binds its source, effective interval, evidence date, and responsible attestor. The graph policy selects relationships representing common compromise under its threat model. It includes indirect control. Connected components of selected relationships form the admitted control blocs. Each bloc groups principals connected by the common-control relationships selected in that policy.

Separate policies can describe observation integrity and service availability. Shared hosting can create an availability dependency without granting signing authority. The graph records these different relationships. An unresolved control record contributes no certified diversity. Its principal can still supply an observation. Unknown controllers cannot form a separately countable bloc.

For epoch e and certificate c, let S_e(c) contain its distinct eligible signing principals. Let \mathcal B_e partition the principals covered by admitted control evidence. The certificate requires |S_e(c)|\geq\theta_e,\qquad \bigl|\{B\in\mathcal B_e:B\cap S_e(c)\neq\varnothing\}\bigr| \geq K_e. The first threshold counts principals. The second counts covered control blocs. Every signature binds the same corridor, observation digest, slot, epoch, registry, graph, policy, purpose, and time anchor. Its signer wrapper binds the principal identity. Versions from different epochs cannot form one certificate.

The signing predicate requires receipt of the complete named observation, its deployment signature, and its contextual bindings. An honest watcher signs only after those checks.

Proposition 7.1 (Honest observation witness).

Assume signature unforgeability, sound principal registration, and enforcement of the signing predicate. An admitted certificate contains an honest signature under either bound:

  1. At most f_e<\theta_e eligible signing principals are dishonest.

  2. All dishonest signing principals occupy at most b_e<K_e admitted control blocs.

That signer checked the certificate’s exact observation.

Proof. Under the first bound, at least \theta_e distinct signers include more principals than the dishonest set. Under the second, at least K_e covered blocs include more blocs than those containing dishonest signers. Either case supplies an honest signer. Unforgeability attributes its signature, and the signing predicate gives the stated check. ◻

The second bound counts every bloc containing a dishonest signer, including partial compromise. It requires coverage of all dishonest signing principals by the admitted graph. Graph components are a deterministic property of the evidence. Their institutional meaning depends on accurate and complete control evidence. They establish neither statistical independence nor the truth of each observed institutional assertion.

A fault configuration such as n_e\geq3f_e+1 selects a budget. Here the first count is the number of eligible principals in the epoch. Actual deployment evidence must support that budget. For weighted counting, the signing weight must exceed the assumed dishonest weight. Bonded weight supplies no organizational diversity. Consensus and availability require their separate protocol premises.

A controller change publishes a successor graph epoch. Current-use admission rechecks the applicable graph and registry versions under N5. The old certificate retains its historical signatures but loses current eligibility where the classification changed. Discovery of concealed historical control corrects the historical diversity assessment. It preserves signature authenticity rather than preserving an incorrect control assumption.

Key rotation retains principal identity and both counts. A signer-supplied earlier timestamp cannot revive a revoked key. A successor certificate can qualify automatically when its eligible signers satisfy the current policies. Evidentiary ineligibility remains separate from registration sanctions and bond liability.

For example, with \theta_e=K_e=3, three covered principals in distinct blocs can certify one observation. Three keys for one principal count once. Three principals sharing a selected signing controller count as one bloc. A common hosting dependency can affect their availability assessment independently.

Two valid deployment-signed observations at the same corridor, epoch, and height form a fork witness when their digests differ. Different heights ordinarily show record growth.

7.3 Institutional instruments

An instrument profile connects a machine transition to the institution empowered to give it effect. Its common fields are \begin{split} (&\mathsf{instrumentDigest},\mathsf{jurisdiction}, \mathsf{competentOffice},\mathsf{delegatedRole},\\ &\mathsf{technicalOperator},\mathsf{acts},\mathsf{scope}, \mathsf{conditions},\mathsf{effectiveInterval},\\ &\mathsf{recordedAt},\mathsf{adoptionRule},\mathsf{noticeRule}, \mathsf{challengeRule},\mathsf{terminationRule}). \end{split} The instrument’s retained text and authentic adoption evidence support these fields. A profile states the operative clauses for each transition. A mapping determination has its own competent issuer, scope, effective interval, and retained basis. Reusable determinations can support repeated automatic checks under their use contracts.

Three typed extensions supply the required governance acts.

Emergency mandate.

Name the trigger predicate, evidentiary threshold, affected acts, start rule, duration, countermand office, resumption office, notice channel, and challenge route. Each timing rule derives from the instrument.

Succession instrument.

Name predecessor and successor offices, surviving competence, effective time, adoption authority, record custodian, and explicit dispositions of rights and duties. Bind the prepared-transaction inventory, retained manifest, continuation rules, and authority-feed endpoints. A split allocates each competence explicitly. Joint competence names its joint decision rule.

Bond mandate.

Name the obligor, beneficiary, custodian, funded account, currency, pledged amount, permitted liability decisions, draw conditions, amount limit, notice, challenge, and release rule. Bind the provider’s payment and reversal contract. A liability assessment and available bond funding have separate fields.

Admission checks the predecessor authority profile, exact act, operative clause, conditions, use stage, and required signatures. Every required preimage must be available. A missing mandate yields a pending transition with the exact missing authority dependency. An authorized standing mandate lets subsequent conforming acts proceed automatically.

Governance versions enter Q_v through \mathsf{Publish} under the existing adoption rule. Their immutable payloads bind the instrument profile and transition conditions. \mathsf{Grant}, \mathsf{Revoke}, and \mathsf{Withdraw} retain their scoped effects. Constitutive change requires the independently effective institutional instrument specified by the predecessor authority structure. A technical operator cannot create that basis through publication.

Proposition 7.2 (Instrument-bound governance).

Assume authentic instruments, faithful scoped mappings, and complete current-use evidence. An admitted governance event uses an act authorized by its predecessor profile. Publication cannot supply its own missing adoption power.

Proof. Admission checks the act and conditions against the predecessor’s retained instrument profile. The proposal cannot select a weaker predecessor. N5 protects that dependency through the event. The instrument and mapping premises establish the permitted institutional act. Missing adoption power fails its required premise before publication. ◻

7.4 Emergency power and countermand

Each destination’s emergency mandate determines its available halt and countermand powers. A halt identifies the affected acts, effective interval, trigger evidence, and governing clause. An immediate halt uses the mandate’s immediate-effect rule. A notice or countermand window applies only where the instrument requires it. The directive binds a single-use identifier and the exact scope. New reliance follows the halt state. Existing acceptances and unresolved obligations remain recorded.

Countermand checks the relationship between the named offices under the same mandate. Resumption checks its designated authority and release conditions. The runtime can perform a delegated automatic halt when authenticated evidence satisfies a preauthorized trigger. A discretionary trigger requires its authorized determination. Joint action uses the corresponding participant decision protocol. Delivery, key custody, and clock premises remain explicit.

An emergency-relief order directs parties only within its jurisdiction and authority. It displaces a sovereign halt only under a rule adopted by the halting authority (Reference [5]).

7.5 Jurisdiction continuity

The jurisdiction lifecycle map records creation, active competence, termination, merger, split, and scope amendment. The succession instrument supplies the lawful relation between those states. The runtime first validates that instrument and binds the affected authority-resolution roots.

A continuation package contains the old record heads, retained-preimage manifest, effective authority map, outstanding obligations, and every unresolved prepared transaction. The successor acknowledges custody and reconstructs those reservations before conflicting writes. Existing terminal decisions retain their exact event and command identities. A changed configuration supplies no abort or second dispatch.

Activation uses the existing adoption rule and the applicable guard transaction. It changes future authority resolution only for the instrument’s assigned scope. Dependent destinations apply their own recognition policies to the continuation package. Historical source acts keep their original issuers. An express adoption can authorize continued use without forging a replacement source act.

Proposition 7.3 (Obligation-preserving succession).

Assume a valid succession instrument, complete continuation inventory, and conforming reservation recovery. Activation preserves each unresolved obligation and prepared transaction until its authorized terminal transition.

Proof. The inventory binds the predecessor heads and all outstanding entries. Activation requires reconstruction of each entry under its preserved identity. Recovery retains every unresolved reservation and applies existing terminal decisions once. No activation rule discharges an obligation or redispatches an external command. Each later change therefore needs its own authorized transition. ◻

A valid split can route two disjoint competences to different successors and let both continue their permitted operations. Shared obligations retain their named common decision authority. A missing continuity instrument leaves the affected use pending while unrelated authority scopes continue.

7.6 Bond enforcement

A bond decision names its governing clause, liability basis, claimant, liable party, amount, currency, and decision authority. A watcher observation or fork witness can satisfy an evidentiary condition. The bond instrument determines the liability and draw power.

For a funded bond balance B, let r be prior reservations and e prior encumbrances. Define f=\max(B-r-e,0),\qquad d=\max(r+e-B,0). Then B+d=f+r+e. A new draw x requires 0<x\leq f and the mandate’s amount limit. Admission reserves x under the guard transaction before dispatch. An assessed receivable remains separate from B. A decrease in B records the resulting deficit without erasing prior reservations or liability.

The custodian executes the exact admitted command under its named authority-use contract. Confirmation requires its occurrence evidence. A paid debit reduces the funded balance and the command’s funded reservation in the same accounting update. Each debit applies once. Partial performance preserves the unpaid amount and remaining execution reservation. A return or reversal has its own occurrence and correction transition. Authorized release requires the instrument’s release conditions and resolution of outstanding command capacity.

Proposition 7.4 (Funded bond draw bound).

Fix balance and encumbrances, with initial reservations r_0\leq B-e. Let A_t total new reservations and L_t total authorized releases. Then r_t=r_0+A_t-L_t\leq B-e,\qquad A_t\leq f_0+L_t. Thus outstanding reservations remain funded while authorized releases permit reuse. Each reservation retains its command attribution.

Proof. A reservation increases r by x\leq B-e-r. An authorized release decreases r by at most its outstanding amount. Both preserve 0\leq r\leq B-e. Summing these updates gives r_t=r_0+A_t-L_t. Rearranging the upper bound gives A_t\leq f_0+L_t. Unique command identities preserve attribution through retry and resolution. ◻

7.7 Entrenched floor

Ordinary policy amendment must respect any clauses whose amendment authority was fixed outside that policy. We call those protected clauses an entrenched floor. The following result concerns enforcement of the existing signature requirement. It assumes that the requirement has the stated institutional basis.

Let F be a fixed set of floor clauses and E_F their required signature set. The validator changes F only when E_F signs the exact replacement.

Proposition 7.5 (No self-created amendment power).

Assume E_F is fixed outside mutable corridor policy and signatures are unforgeable. An ordinary amendment cannot reduce E_F or remove a floor clause without the authorization already required by E_F.

Proof. The validator reads fixed E_F, not the mutable proposal. A self-authorizing weaker proposal therefore fails unless it already carries every signature in E_F. ◻

Hart, Ross, and Suber study the distinction between ordinary rules and amendment authority (References [30][32]). The proposition states only the cryptographic consequence of fixing E_F externally.

7.8 Cryptographic continuity and trust boundary

Retained evidence may need to remain verifiable after a signing scheme is retired. An archival profile specifies the signatures required for acceptance and how successor evidence preserves the old record. One such profile can require an AND envelope of Ed25519, ML-DSA-65, and SLH-DSA-SHA2-128s. Each component signs the same canonical bytes and suite tag. Verification requires all three. Its signature field is 64+3{,}309+7{,}856=11{,}229\ \text{bytes}. The count excludes keys, tags, and encoding. RFC 8032 and NIST FIPS 204 and 205 give the component sizes (References [26][28]). Accepted forgery requires every verification relation to pass. This claim assumes component unforgeability, secure key binding, and correct verification.

Before retirement, the archive appends a successor-scheme witness over the prior digest while the old profile remains trusted. Re-anchoring preserves the historical entry. Later verification follows the witness chain specified by RFC 4998 (Reference [29]).

Cryptography proves neither evaluator fidelity nor policy correctness. Colluding evaluators can sign false statements. A defective authorized policy can return a wrong conclusion. Seniority and independence therefore require evidence beyond signatures. The control-evidence policy states which controllers must differ and which correlated failures remain in its threat model.

8 Learning from Accepted Evidence

The same records that preserve attribution can inform later route selection. Their reuse remains subject to the cumulative disclosure and source-permission rules above. An acceptance can place its observation and receipt in one atomic entry. The observation records statement class, treatment, route, decision time, and outcome. Authorized aggregates can estimate route reliability, latency, revocation frequency, and domain friction.

Only authorized aggregates cross corridors. Raw records remain local unless policy admits them. Coarsening gives no quantitative privacy bound because small groups, linked releases, and auxiliary data can identify subjects. Any bound needs an adversary, release rule, and privacy definition.

Attributed observations can improve estimates and identify weak routes. The marginal value of evidence can diminish as observations repeat, but this paper states no quantitative growth law. Authority remains with its source institution. Repeated foreign statements create no local power, and connectivity creates no network owner.

9 Payment Instructions, Liquidity, and Finality

A receiving institution may use recognized evidence to authorize a payment-related act. The evidence record can support that decision, while the cash record must identify the distinct provider occurrence. The event separation therefore identifies what a payment claim must measure. Message transmission, ledger confirmation, legal finality, liquidity funding, and beneficiary receipt are different events. Du’s 2026 remarks make this system boundary explicit, and the supporting working paper studies bank, operator, and stablecoin routes (References [17] and [18]). These sources motivate the boundary. They do not prove Theorem 3.1.

Swift transports payment instructions. It does not itself settle the cash obligation. In Swift’s study of first-quarter 2025 traffic for the forty largest receiving countries in its sample, 75\% of payments reached the beneficiary bank within ten minutes. Average network transit took less than 20\% of the end-to-end time, while the receiving-side portion took 80\% (Reference [19]). The measured event is arrival at the beneficiary bank, not beneficiary credit or legal finality. Faster transport shortens the smaller measured portion. Portable institutional evidence can reduce one part of the receiving-side work, but it does not complete the cash leg.

A money-transfer operator can join two domestic payments using prefunded local accounts. The customer can receive funds before the operator rebalances its residual position across currencies. The completion clock is local credit to the named beneficiary. The later rebalancing clock belongs to the operator. Du, Huang, and Scharfstein analyze this structure for selected United States–Europe retail routes and show that software, local access, prefunding, foreign exchange, compliance, and internal netting jointly determine the observed price (Reference [18]). Their sample does not supply a universal operator cost.

CLS illustrates a different construction. It synchronizes the payment instructions for both currency legs through payment-versus-payment and gives those legs finality under its rules. For the eighteen currencies in CLSSettlement during the first half of 2025, CLS reported an average daily settled value of USD 7.9 trillion and a 96\% reduction from multilateral netting before later liquidity tools (Reference [20]). The population is CLS-eligible foreign-exchange instructions, and the measured liquidity result belongs to its daily settlement cycle. It is not a claim about every foreign-exchange trade.

Fedwire shows why the rulebook boundary matters. The Federal Reserve describes the Fedwire Funds Service as real-time gross settlement in central-bank money, with transfers immediate, final, and irrevocable once processed (Reference [21]). That statement concerns eligible participants’ Reserve Bank accounts. It does not by itself state when an ultimate beneficiary can use funds outside those accounts.

Settlement speed depends on liquidity allocation, delay costs, and network structure. Garratt, Bech, Nanut Petrič, and Ates construct an auction that elicits liquidity offers and side payments for queued real-time gross settlement (RTGS) obligations, then study simulations calibrated to four payment systems (Reference [22]). Capponi and Chang model settlement speed against netting, liquidity cost, default probability, and crisis severity (Reference [23]). Their result makes the optimum depend on network structure and liquidity conditions. Neither result supports a universal shorter window.

Principle 8 of the Principles for Financial Market Infrastructures (PFMI) requires an infrastructure to define when settlement is final, while the European Settlement Finality Directive supplies a legal rule for protected systems (References [24] and [25]).

Those sources confirm the distinction used here. The value F_P is the protocol’s ledger-confirmation event. Legal finality comes from the applicable legal and institutional rule.

9.1 Allocation under a current execution grant

The cash-event model already separates a physical payment occurrence from its evidence and allocations. We now construct one local allocation operation under a current execution grant. Its authority check uses a logical point within a transaction. The stronger requirement of authority at actual durable commitment remains separate. Consider a narrower operation than payment execution. Physical credit has already been admitted, and a payable obligation already exists. The operation allocates specified slices of that credit to specified portions of the obligation. Its difficulty is to preserve the authority for that allocation while the records used to identify it can change. A route can acquire a different owner; a credit alias can resolve differently; an indirect rule can cease to permit the act.

Fix a finite allocation grammar. A request q names an immutable command, an obligation route, a credit route, an exact amount, an evidence package, and its original request time. Evaluation resolves the routes and records the exact payable portions and physical slices to be used. It also retains the historical recognition context at evaluation time t_0. That context includes the original request, local decisions, source evidence, obligations, and their admitted resolutions. Imported evidence must still satisfy the separately authorized local decision.

Ordered interval selection.

Fix a positive quantum \delta shared by the selected obligations and credit. The requested amount is n\delta for a positive integer n. An obligation portion (r,a,b) denotes the original duty’s cells (r,a),\ldots,(r,b-1). Its half-open interval [a,b) has integer endpoints and measure b-a. Physical portions use the same interval convention within their canonical occurrence. Obligation indices start at zero. Physical indices start at one. Every interval lies within its recorded quantity, and intervals for one identity have disjoint interiors.

An alias is an ordered list of obligation portions. The order determines selection, even when a later interval has smaller endpoints. For example, taking four cells from ((r,8,11),(s,2,5),(r,0,2)) \quad\text{selects}\quad ((r,8,11),(s,2,3)). Evaluation intersects each portion with the duty’s current payable intervals, preserving alias order. It then takes the first n cells by subtracting interval lengths and splitting the last selected interval. Physical selection takes the first n unused cells of the canonical occurrence after subtracting its used intervals. Adjacent intervals coalesce only when doing so preserves their order.

Lemma 9.1 (Finite portion correspondence).

Expand each interval into its finite ordered sequence of cells. Interval intersection with payable cells, subtraction of used cells, and prefix selection give the same selected sequences as their expanded operations. Consequently the interval selection preserves the selected identities, quantity, and absence of repeated cells.

Proof. Within [a,b), intersection retains exactly the cells satisfying the membership condition. Subtraction retains its complementary cells in the original order. Apply these operations to successive intervals and concatenate their results. A prefix consumes either the whole next interval or its initial segment [a,a+k) for the remaining quantity k. Induction on the interval list proves equality with the expanded prefix. Disjointness prevents repetition, and each interval contributes exactly its length. ◻

The finite expansion defines the correspondence. Evaluation operates on endpoints. Its costs still depend on interval fragmentation, endpoint arithmetic, and retained history. The representation gives no constant-cost bound as these quantities grow.

What must remain current.

The catalog contains the admitted routes, owners, rules, and authority records used to interpret the request. The allocation ledger records the available slices and their attributed uses. Let C be the admitted catalog and L the allocation ledger. Every evaluator query passes through a closed read interface. A query footprint records what the evaluator actually read, so execution can detect a relevant change without invalidating a preparation for every unrelated update. Its recorded footprint is \mathcal F(q;C,L)= \{(r,a,H(\mathsf{read}(C,L;r,a)))\}, where r is a query constructor, a its exact arguments, and H a collision-resistant digest. The record contains the result of every query actually made by the evaluator.

The constructors cover indirect obligation and credit routes, the active representation, alias portions, original duty bindings, current payable capacity, physical occurrence aliases, returns, prior allocations, and prior use of the command. Catalog reads cover owners, indirect rules, source and derivation admissions, corridor and authority-use contracts, local decision authorities, obligation resolutions, prior activations, and participant keys. An absence check records the complete relevant prefix with its versioned entries, including deletion records. Inserting and then removing a conflicting hold therefore changes the footprint. A hold on another obligation need not do so.

These dependencies determine the participants and resource modes. Selected obligation roots and physical credit have write mode; their authority and interpretation records have read mode. The footprint is complete for this grammar because each query constructor returns the full record used by that constructor, and every evaluator branch uses the read interface. Arbitrary code with untracked reads is outside this construction.

A grant for the bound allocation.

The preparation fixes a plan P containing q, t_0, the footprint, the selected allocation, its local observations, the participants and their admitted keys, and an execution interval W=[u,v]. Every participant signs the same plan under a distinct execution-grant domain. This includes the local decision authorities as well as the discovered resource owners and source authorities. The governing instruments must admit that signature as permission to execute this particular allocation during W.

The whole interval W lies inside every required source, corridor, and authority-use interval. This grant supplies separate permission for execution; it does not extend an old decision’s historical meaning. At execution, changed ownership, rule admissions, source admissions, revocation, or participant keys invalidate the preparation through their recorded queries. The original request and recognition context remain unchanged. After abort, the same command may receive a new attempt and a fresh grant. Its historical request time does not become the new execution time.

The allocation boundary.

One local transaction contains the catalog check, allocation, and command outcome. Preparation previews the actual allocation operation under a rollback savepoint and records the digest of its result. It thereby binds the selected effect without consuming credit. A new commit first checks the recorded queries and repeats the evaluator, requiring the same complete semantic result. It then checks all execution signatures and calls the same allocation operation against the current ledger. The result must equal the previewed result.

The allocation operation preserves the canonical occurrence and obligation identities. It consumes the selected available physical slices and payable duty portions together. Neither an evidentiary alias nor another jurisdiction’s receipt creates an additional slice. The command result records this local allocation, rather than asserting a newly dispatched or settled provider payment.

The transaction samples an admitted monotone logical clock before reevaluation, before allocation, and after the allocation write. Each successful sample lies in W and is no earlier than t_0. Expiry during the write rolls that write back. The last successful sample is the logical execution time t_*. Only then does the transaction record the allocation result and its immutable command outcome and complete the durable commit.

Proposition 9.2 (Guarded allocation at a logical execution point).

Assume complete mediation for the stated grammar, authentic current catalog entries and execution grants, collision resistance, a correct monotone logical clock, and ordinary atomic durability of the local transaction. A newly committed command has exactly its bound allocation and stored outcome. Its recorded guards pass in the locked pre-allocation state. Its unchanged catalog-based authority predicates and execution grants authorize that allocation at t_*\in W, under their admitted logical-execution interpretation. Replaying the committed command returns its stored outcome without another allocation.

Proof. The transaction excludes competing catalog and ledger writes. Matching query digests preserves every recorded input at validation. Repeating the evaluator checks that those inputs still select the same participants, local observations, and allocation. Verification under the unchanged admitted keys supplies every required execution grant. The allocation method checks payable and physical capacity in the pre-allocation state, consumes the selected slices, and produces exactly the bound result. It leaves the catalog-based authority predicates unchanged. The post-write clock check supplies t_*\in W; a failed check rolls back the allocation. Atomic commit persists that allocation and its command outcome together. A later invocation finds the immutable outcome before attempting another allocation. A crash before commit preserves the predecessor, while a crash after commit permits recovery of that same outcome. ◻

The time in this proposition is a logical execution point inside the transaction. Durable commit may finish later, even after v. This construction therefore does not discharge the stronger actual-durable-event clock premise of Theorem 5.1 or the distributed realization in Section 5.1. A rule requiring authority at durable commit or at provider acceptance needs a boundary that enforces that later stage. Signatures and an earlier clock sample cannot supply it.

The footprint also preserves useful independence. Two preparations can refer to different obligation roots and physical occurrences while sharing unchanged read-only authority records. If the first allocation changes none of the second’s recorded query results or selected result, and the second’s grant remains valid, the second can commit without replacing its preparation. The local database still serializes their writes. This is stability under unrelated changes, rather than a claim of parallel database writes or bounded network latency.

Admission of incurred obligations.

The committed outcome retains the exact permitting observations and identifies the allocation by its result digest. Let c be this committed act and O_c the compatible union of their post-effect obligation bodies. Reconstruction checks the committed plan, observations, allocation receipt, and retained allocation history. A query returns each o\in O_c as incurred at t_*. It reports admission as Awaiting until the separate activation transition succeeds. It also reports whether the original deadline has passed. Thus the recognition status Conditional before activation does not conceal an incurred duty.

For o\in O_c, let a(o) be its governing authority. An activation binds c, the obligation identity, a(o), the original context and trigger, t_*, and its evidence. A new admission requires that authority’s signature over this activation and its admission request. The signed request also binds the committed outcome, obligation digest, current authority key and epoch, and current obligation and activation-policy records. The policy names the obligation, authority, trigger, legal basis, and validity interval. It must cover the entire signed admission window, whose start is no earlier than t_*. The admission transaction reconstructs these bindings, verifies the signature, and checks its logical time against that window.

The admitted lookup uses the complete key H(c,\mathsf{id}(o),a(o)). Its value repeats those three fields. Each consuming query checks both the key and value. Different authorities can therefore admit different duties of one committed act without replacing a shared authority entry. The store admits at most one activation for each obligation identity. It retains the activation, scoped binding, and admission outcome atomically. Each request has an admission identifier, or nonce. Repeating the same nonce and signed envelope returns the stored outcome.

Proposition 9.3 (Committed duties and scoped admission).

Assume Proposition 9.2’s premises and an authenticated store with a monotonic history. Assume current obligation and activation-policy admissions, unforgeable governing-authority signatures, and separately admitted later corridors, decisions, and fulfilments. Every successful obligation query exposes all of O_c, including duties awaiting activation admission. Each new admitted activation binds its exact member of O_c to c under that duty’s current governing authority. A later successful consumption preserves every original obligation body. A valid positive fulfilment dated between t_* and the original deadline yields Satisfied after activation, once its time is reached. Admission, replay, and reporting leave the allocation ledger unchanged.

Proof. Reconstruction derives O_c from the stored observations and checks their binding to the actual allocation. The query iterates over this union before checking which activations exist. An absent activation therefore leaves an explicit incurred entry. For a new admission, reconstruction requires exact equality with the signed payload under the current catalog. Signature verification identifies the admitted key of a(o). The scoped lookup binds all three identities, so another duty or authority cannot substitute its activation. The unique obligation entry prevents a second activation. The nonce record makes exact replay idempotent.

Later consumption reconstructs the corridor receipt and requires it to contain every original obligation body unchanged. The status rule checks the activation, fulfilment authority, original context, answer, and dates. A positive answer at or after the trigger and by the deadline yields Satisfied at a query time admitting that answer. The admission transaction writes only the catalog and admission records. Queries and later consumption read those records without performing another allocation. ◻

A later Permit still requires its separately admitted local decision and the required evidence. Permission alone does not complete a reporting duty. Admission authenticates the trigger record under its governing rule. It supplies neither a new mandate nor funding. Its clock check, like t_*, occurs inside the transaction. Authority required at its later durable commit or at an external provider stage retains a separate enforcement obligation.

Representation and authority limits.

The catalog must contain the institutionally required facts. A local snapshot cannot reveal an unreported legal change or authenticate a false provider occurrence. The composed construction uses ordered intervals in one authenticated SQLite authority with a monotonic history. Migration of historical per-cell preparations and query footprints to the interval representation requires a separate argument. Independent database copies and rollback of a complete authenticated snapshot require external exclusivity and rollback protection. The interval correspondence supplies no distributed transaction refinement. Current authority, admitted corridor and fulfilment meanings, retained evidence, and later provider effects retain their stated premises.

10 Claim Classification

Tier Claims in this paper
finite model evidence The sequential two-deployment model admits sixteen constructors, enumerates 1{,}120 terminal interleavings, and rejects 37 specified mutations. Its cash traces use whole-instruction receipts.
mechanized parametric No theorem is claimed in this tier. The executable bounds, names, and deterministic signature relation are fixed.
paper-proved The preservation theorem and the stated results on guard refinement, capacity, recognition and normalization, finite route comparison, disclosure, source obligations, historical use, governance, succession, bonds, certificates, amendment, scoped logical-execution allocation, finite interval correspondence, and admission of incurred duties. Each uses its named hypotheses.
institutional and implementation premises Authority-source currentness, instrument competence, control-evidence completeness, custodian performance, retained-byte availability, and refinement of the transaction implementation.
Conditional claims.

The one-writer realization requires T1–T4. Route-friction multiplication requires independent edge risks. Watcher, hybrid-signature, countermand, and post-partition conclusions require the assumptions stated in their sections.

Heuristic claims.

The control graph records specified common causes rather than statistical independence. Route-friction estimates require identified edge probabilities and dependence. Diminishing marginal evidence value remains a qualitative account.

Open questions.

N5 or N6 is minimal only if removing it yields a history that preserves the other conditions and breaks a named conclusion. Byzantine progress requires its communication, quorum, and recovery premises. Composable privacy requires an adversary and release mechanism. Instrument profiles require authentic adoption evidence from the competent institutions. Concrete deployments must supply those profiles, current control evidence, retained bytes, and provider mandates.

11 Related Foundations

SPKI and KeyNote scope authority without a universal naming authority (References [6] and [7]). Verifiable Credentials, ICAO travel documents, and the verifiable Legal Entity Identifier carry signed identity evidence across organizations (References [9][11]). This paper governs local use.

Certificate Transparency and hash-linked timestamps support append-only evidence (References [12] and [13]). Atomic-commit and consensus results bound bilateral commitment (References [14][16]). The PFMI and Settlement Finality Directive distinguish confirmation, settlement, and legal effect (References [24] and [25]). These distinctions motivate separate evidence, rights, and cash records. The certificate proves matching authorization, not global consensus.

12 Conclusion

South can reuse North’s company-status statement and still decide the branch application under its own current rule. The paper’s construction preserves that distinction across complete histories: every accepted use retains its source, route, local policy, and deciding authority. A change to evidence alone leaves the local institutional, rights, and cash records unchanged.

The later results address what this separation requires during continued operation. Routes retain local questions and duties. Execution protects the records on which a decision depends. Disclosure accounts for earlier answers, and succession preserves unresolved work. The allocation construction applies the same discipline to already admitted physical credit under its stated logical-time premise. Its interval representation preserves finite portions, and subsequent admission retains each incurred duty under its own authority. Authentic instruments, current authority evidence, and provider performance remain external premises at the stages that require them.

References

[1] R. Lorgat, How Compliance Composes, 2026.

[2] R. Lorgat, Programmable Institutions, 2026.

[3] R. Lorgat, Op: A Typed Bytecode for Compliance-Carrying Operations, 2026.

[4] R. Lorgat, Accession Networks, 2026.

[5] R. Lorgat, Recourse, 2026.

[6] C. Ellison et al., “SPKI Certificate Theory,” RFC 2693, 1999.

[7] M. Blaze et al., “The KeyNote Trust-Management System Version 2,” RFC 2704, 1999.

[8] A. Rundgren et al., “JSON Canonicalization Scheme,” RFC 8785, 2020.

[9] W3C, “Verifiable Credentials Data Model v2.0,” 2025.

[10] ICAO, Machine Readable Travel Documents, Doc 9303.

[11] GLEIF, “Introducing the Verifiable LEI.”

[12] B. Laurie et al., “Certificate Transparency Version 2.0,” RFC 9162, 2021.

[13] S. Haber and W. S. Stornetta, “How to Time-Stamp a Digital Document,” J. Cryptology 3, 99–111, 1991.

[14] J. Gray and L. Lamport, “Consensus on Transaction Commit,” ACM TODS 31(1):133–160, 2006.

[15] M. Fischer, N. Lynch, and M. Paterson, “Impossibility of Distributed Consensus with One Faulty Process,” J. ACM 32(2), 374–382, 1985.

[16] C. Dwork, N. Lynch, and L. Stockmeyer, “Consensus in the Presence of Partial Synchrony,” J. ACM 35(2), 288–323, 1988.

[17] W. Du, “Three Myths About Payment Innovation,” panel remarks, Jackson Hole Economic Policy Symposium, 29 August 2026.

[18] W. Du, C. Huang, and D. Scharfstein, “Competing Rails for Cross-Border Payments: Banks, Fintechs, and Stablecoins,” Harvard Business School working paper, 15 February 2026.

[19] Swift, Spotlight on Speed 2025: Why the Last Mile Is the Longest, 2025.

[20] D. Bullmann, “Keeping Settlement Risk High on the Public Policy Agenda,” Eurofi, 30 September 2025.

[21] Board of Governors of the Federal Reserve System, “Fedwire Funds Services,” updated 25 June 2024.

[22] R. Garratt, M. Bech, M. Nanut Petrič, and C. Ates, “Auction-Based Liquidity Saving Mechanisms,” BIS Working Paper 1318, 2025.

[23] A. Capponi and J.-W. Chang, “Settlement Speed and Financial Stability,” FEDS 2025-101, 2025.

[24] Committee on Payment and Settlement Systems and Technical Committee of IOSCO, Principles for Financial Market Infrastructures, 2012.

[25] European Parliament and Council, Directive 98/26/EC on Settlement Finality, 1998.

[26] S. Josefsson and I. Liusvaara, “Edwards-Curve Digital Signature Algorithm,” RFC 8032, 2017.

[27] NIST, FIPS 204, Module-Lattice-Based Digital Signature Standard, 2024.

[28] NIST, FIPS 205, Stateless Hash-Based Digital Signature Standard, 2024.

[29] T. Gondrom et al., “Evidence Record Syntax,” RFC 4998, 2007.

[30] H. L. A. Hart, The Concept of Law, 3rd ed.

[31] A. Ross, “On Self-Reference and a Puzzle in Constitutional Law,” Mind 78(309), 1969.

[32] P. Suber, The Paradox of Self-Amendment, 1990.