Author SHA1 Message Date
temoin-agentandClaude Fable 5.1 f3d7383748 SPEC v1.2 : la mesure nomme ce qu'elle a examiné (relations.confirms)
gardes du contrat / conformite (pull_request) Successful in 28s
Le sens est la décision entière : c'est la MESURE qui déclare ce qu'elle
confirme, jamais l'assertion confirmée qui pointe en retour. Trois raisons
suffisantes chacune : l'assertion confirmée existe déjà et ne se réécrit
pas ; l'instrument sait ce qu'il a mesuré — le lien est inféré, jamais
saisi ; et l'auteur d'une confirmation est la machine, non l'agent dont
l'affirmation est confirmée. Le runner refuse confirms sur autre chose
qu'une mesure de provenance measured.

Mineur et ignorable : un consommateur qui ignore la clé la préserve.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-09-21 13:53:04 +02:00
oat_gitadmin 52706a26a7 Merge pull request 'SPEC v1.1 : une décroissance montrée nomme sa lecture' (#2) from contrat/lecture-de-decroissance into master
gardes du contrat / conformite (push) Successful in 18s
Reviewed-on: #2
Reviewed-by: oat_gitadmin <admin@openathle.com>
2026-09-19 09:00:39 +00:00
temoin-agentandClaude Opus 5 1954dcb704 SPEC v1.1 : une décroissance montrée nomme sa lecture
gardes du contrat / conformite (pull_request) Successful in 18s
Un auditeur qui voit une confiance décrue ne peut pas la reproduire s'il
ignore quelle fonction l'a produite, dans quelle version, à quelle date.
Deux lectures divergentes du même verbatim se valent alors, sans qu'on
puisse dire pourquoi : c'est l'opposabilité qui se fissure, non le fait.

Champ 15 confidence_reading (§4.1), OPTIONNEL — présent seulement quand
l'émetteur EXPOSE une valeur qu'il a dérivée ; ses quatre clés sont alors
requises (policy, version, value, as_of). Le verbatim reste intact au
champ 8. Règle de conformité au §9 : une valeur dérivée non déclarée
n'est pas conforme. Additif et ignorable — un consommateur v1.0 le
préserve et passe, comme §8 l'exige de tout champ inconnu.

Relevé par une lecture extérieure du 2026-09-19 : « c'est une ligne du
contrat, pas une ADR ». Elle avait raison sur les deux points.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-09-19 10:13:31 +02:00
8 changed files with 179 additions and 11 deletions
+47 -5
View File
@@ -1,4 +1,4 @@
# Assertion Envelope — Specification v1.0
# Assertion Envelope — Specification v1.2
**Status**: stable. Declared v1.0 upon the first real federated exchange
between two distinct jurisdictions — openathle → Prismagram, endorsed
@@ -84,12 +84,12 @@ fields (§7).
| 5 | `statement` | string | REQUIRED. What is asserted, in one sentence or few |
| 6 | `evidence` | list of `{kind, ref}` | REQUIRED, MAY be empty. A conflict without evidence asks to be believed; evidence names where the fact lives |
| 7 | `provenance` | string | REQUIRED. One of §6. Transported verbatim (§2.2) |
| 8 | `confidence` | number | REQUIRED. `0.0`–`1.0`. Transported verbatim. Interpretation policies — decay, half-life, thresholds — are consumer-local readings and MUST NOT modify the transported value |
| 8 | `confidence` | number | REQUIRED. `0.0`–`1.0`. Transported verbatim. Interpretation policies — decay, half-life, thresholds — are consumer-local readings and MUST NOT modify the transported value. A consumer that *exposes* such a reading declares it (field 15, §4.1) |
| 9 | `endorsement` | object or null | REQUIRED. `{by, at, rite}`; `rite` is one of `pr_approval`, `ui`, `batch`. `null` means: no human has endorsed this — which is a fact, not a defect |
| 10 | `jurisdiction` | string | REQUIRED. MUST equal the prefix of `id`. Lowercase ASCII, no separators |
| 11 | `at` | string | REQUIRED. RFC 3339 timestamp of the asserted state |
| 12 | `lifecycle` | string | REQUIRED. One of `proposed`, `endorsed`, `superseded`, `rejected`, `under_revision` |
| 13 | `relations` | object | REQUIRED, MAY be empty. Keys among `amends`, `supersedes`, `depends_on`, `satellite_of`; values are lists of prefixed ids |
| 13 | `relations` | object | REQUIRED, MAY be empty. Keys among `amends`, `supersedes`, `depends_on`, `satellite_of`, `confirms` (v1.2); values are lists of prefixed ids |
| 14 | `deadline` | string or null | REQUIRED. RFC 3339. When a falsifiable statement expires into a verdict |
| 15 | `falsification` | string or null | REQUIRED. What observation would make this assertion false. A hypothesis without one is not a hypothesis |
@@ -97,6 +97,37 @@ fields (§7).
assertion; `endorsement` records the proven event. The two are irreducible:
a declared status is not an approval (ADR-070 §3.2).
### 4.1 Declared readings (v1.1)
| # | Field | Type | Rule |
|---|---|---|---|
| 15 | `confidence_reading` | object | OPTIONAL. Present only when the sender exposes a value it has itself derived from `confidence`. Keys: `policy` (string, the reading's name), `version` (string), `value` (number `0.0`–`1.0`), `as_of` (RFC 3339 timestamp). All four REQUIRED when the object is present |
A decayed confidence is a reading, not a fact. Two auditors applying two decay
functions to the same verbatim value, on two dates, would disagree without
either being wrong — and neither could say why. This field makes the reading
quotable: the verbatim value stays in field 8, the reading stands beside it,
named, versioned and dated.
It is OPTIONAL because a consumer that never exposes a derived value never owes
one; it is not optional for those who do (§9).
### 4.2 `confirms` — the measure names what it examined (v1.2)
A `measure` assertion MAY carry `relations.confirms`: the prefixed ids of the
assertions it examined. The direction is deliberate and it is the whole point:
**the measure declares what it confirms; the confirmed assertion is never
edited to point back.** Three reasons, each sufficient. The confirmed
assertion already exists and is append-only. The instrument already knows what
it measured — the link is inferred, never typed. And the author of a
confirmation is the machine that measured, not the agent whose claim is being
confirmed: a producer MUST NOT emit `confirms` on anything but a `measure` of
provenance `measured`.
A consumer MAY derive, from `confirms`, which assertions have been examined
and when — and MAY treat an assertion that no measure has ever confirmed
differently from one that has. That reading is consumer-local (§4.1).
## 5. Classes
`invariant`, `step_realized`, `transition`, `traversal`, `stressor`,
@@ -132,6 +163,13 @@ a standard field is a contract change under §8.
declared stable, nothing more. Consumers MUST treat `envelope: "0.1"`
messages as v1.0 messages; the schema accepts both values. This equivalence
is specific to this pair and will not be repeated across future MAJORs.
- **v1.1 adds field 15 `confidence_reading`** (§4.1) and the consumer rule that
governs it (§9). Additive and ignorable: a v1.0 consumer that meets the field
preserves it and moves on, exactly as §8 requires of any unknown field. No
existing field, class, provenance or rule changed.
- **v1.2 adds the relation kind `confirms`** (§4.2), carried by measures only.
Additive and ignorable: a consumer that does not know the kind preserves it
as any unknown key of `relations` and moves on.
- At most **two published versions per year**. Deprecation is announced in
this file at least one version before removal.
- Consumers MUST accept any message whose `envelope` shares their MAJOR and
@@ -155,7 +193,10 @@ MUST NOT emit an endorsement it did not witness as a dated event; MUST NOT
emit `measured` provenance for anything a machine did not measure.
**Consumer** — MUST NOT mutate `id`, `provenance` or `confidence` of a
received assertion; MUST NOT reject messages carrying unknown classes or
received assertion; MUST, when it presents or relays a confidence value it has
derived from the transported one, carry the verbatim value unchanged **and**
declare the applied reading in `confidence_reading` (§4.1) — an undeclared
derived value is not conformant, because nobody can reproduce it; MUST NOT reject messages carrying unknown classes or
unknown fields (preserve, expose, move on); MUST record received assertions
append-only; MAY annotate, reference and aggregate received assertions under
its own identity, and MUST NOT present the result as the origin's.
@@ -163,6 +204,7 @@ its own identity, and MUST NOT present the result as the origin's.
## 10. What this contract does not do
It does not say how assertions are stored, projected, displayed or decayed —
those are jurisdiction-local. It does not transport source documents: sealing
those are jurisdiction-local. It says only that a decay, once shown, names
itself (§4.1): the contract governs what is claimed, never how it is computed. It does not transport source documents: sealing
and encrypting source payloads is storage, not exchange. It does not decide
who is right: it keeps both parties quotable, at their own risk.
@@ -0,0 +1,20 @@
{
"reason": "confirms is the measure's word about what it examined; an agent claiming its own assertion is confirmed is self-attestation with a pointer (SPEC §4.2).",
"message": {
"envelope": "1.2",
"id": "temoin/EVI-999",
"class": "step_realized",
"subject": "x",
"statement": "y",
"evidence": [],
"provenance": "agent:claude-code",
"confidence": 0.4,
"endorsement": null,
"jurisdiction": "temoin",
"at": "2026-09-21T08:00:00Z",
"lifecycle": "proposed",
"relations": { "confirms": ["openathle/MES-INV-011-2"] },
"deadline": null,
"falsification": null
}
}
@@ -0,0 +1,21 @@
{
"reason": "A declared reading without its version is unreproducible: two auditors on two dates could not tell whether they read alike. All four keys are required when the object is present (SPEC §4.1).",
"message": {
"envelope": "1.1",
"id": "temoin/EVI-999",
"class": "measure",
"subject": "x",
"statement": "y",
"evidence": [],
"provenance": "measured",
"confidence": 1.0,
"endorsement": null,
"jurisdiction": "temoin",
"at": "2026-09-19T08:00:00Z",
"lifecycle": "proposed",
"relations": {},
"deadline": null,
"falsification": null,
"confidence_reading": { "policy": "half-life-by-class", "value": 0.87, "as_of": "2026-09-19T08:00:00Z" }
}
}
@@ -0,0 +1,23 @@
{
"envelope": "1.1",
"id": "temoin/EVI-129",
"class": "measure",
"subject": "INV-011",
"statement": "Detected mishoused on 8 September, reinforced on 10 — the loop closed.",
"evidence": [{ "kind": "coupe", "ref": "openathle/MES-INV-011-2" }],
"provenance": "measured",
"confidence": 1.0,
"endorsement": null,
"jurisdiction": "temoin",
"at": "2026-09-10T12:12:20.466Z",
"lifecycle": "proposed",
"relations": {},
"deadline": null,
"falsification": null,
"confidence_reading": {
"policy": "half-life-by-class",
"version": "1",
"value": 0.87,
"as_of": "2026-09-19T08:00:00Z"
}
}
@@ -0,0 +1,17 @@
{
"envelope": "1.2",
"id": "openathle/MES-INV-011-2",
"class": "measure",
"subject": "INV-011",
"statement": "INV-011 : vérifié à son étage (domaine) et au-dessus — défense en profondeur.",
"evidence": [{ "kind": "epreuve:domaine", "ref": "quarkus-backoffice/src/test/java/org/openathle/LicenceConfig/Domain/ValueObject/RegistryClubRefTest.java:1" }],
"provenance": "measured",
"confidence": 1.0,
"endorsement": null,
"jurisdiction": "openathle",
"at": "2026-09-10T12:12:20.466Z",
"lifecycle": "proposed",
"relations": { "confirms": ["openathle/INV-011"] },
"deadline": null,
"falsification": null
}
+5
View File
@@ -34,6 +34,11 @@ function crossFieldErrors(msg) {
if (prefix !== msg.jurisdiction)
errs.push(`jurisdiction "${msg.jurisdiction}" must equal the prefix of id ("${prefix}")`);
}
// §4.2 (v1.2) : la mesure nomme ce qu'elle a examiné — et elle seule.
if (Array.isArray(msg?.relations?.confirms) && msg.relations.confirms.length > 0) {
if (msg.class !== 'measure' || msg.provenance !== 'measured')
errs.push(`relations.confirms is carried by a measure of provenance measured only (got class "${msg.class}", provenance "${msg.provenance}")`);
}
return errs;
}
+44 -4
View File
@@ -1,8 +1,8 @@
{
"$schema": "https://json-schema.org/draft/2020-12/schema",
"$id": "https://prismagram.com/published-language/envelope/1.0/assertion.schema.json",
"title": "Assertion Envelope v0.1",
"description": "Producer contract for envelope v0.1 messages (SPEC.md §4). One cross-field rule cannot be expressed here and is enforced by the conformance runner: `jurisdiction` MUST equal the prefix of `id`.",
"title": "Assertion Envelope v1.2",
"description": "Producer contract for envelope v1.1 messages (SPEC.md §4). One cross-field rule cannot be expressed here and is enforced by the conformance runner: `jurisdiction` MUST equal the prefix of `id`.",
"type": "object",
"required": [
"envelope",
@@ -25,9 +25,11 @@
"envelope": {
"enum": [
"0.1",
"1.0"
"1.0",
"1.1",
"1.2"
],
"description": "Version of the contract. v1.0 is substantively identical to v0.1 (SPEC §8): both values validate. A message that does not declare its version is not versioned (A1 §3)."
"description": "Version of the contract. v1.0 is substantively identical to v0.1 (SPEC §8): both values validate. v1.1 adds the optional declared reading (§4.1); v1.2 adds the relation kind `confirms` (§4.2). A message that does not declare its version is not versioned (A1 §3)."
},
"id": {
"type": "string",
@@ -153,6 +155,10 @@
},
"satellite_of": {
"$ref": "#/$defs/idList"
},
"confirms": {
"$ref": "#/$defs/idList",
"description": "v1.2, §4.2. Carried by a `measure` of provenance `measured` only: the ids it examined. The measure points at what it confirms; the confirmed assertion is never edited to point back."
}
},
"additionalProperties": false
@@ -178,6 +184,40 @@
"minLength": 1
}
]
},
"confidence_reading": {
"type": "object",
"description": "OPTIONAL (SPEC §4.1, v1.1). Present only when the sender exposes a value it derived from `confidence`. A derived value shown without this object is not conformant: nobody could reproduce it.",
"required": [
"policy",
"version",
"value",
"as_of"
],
"additionalProperties": false,
"properties": {
"policy": {
"type": "string",
"minLength": 1,
"description": "Name of the reading applied — not the value it produced."
},
"version": {
"type": "string",
"minLength": 1,
"description": "Version of that reading. Two auditors on two dates must be able to tell whether they read alike."
},
"value": {
"type": "number",
"minimum": 0,
"maximum": 1,
"description": "The derived value. The verbatim one stays in `confidence`, untouched."
},
"as_of": {
"type": "string",
"format": "date-time",
"description": "When the reading was taken. A decay without a date is not reproducible."
}
}
}
},
"patternProperties": {
+2 -2
View File
@@ -1,9 +1,9 @@
{
"name": "published-language",
"version": "0.1.0",
"version": "1.2.0",
"private": true,
"type": "module",
"description": "Contrat d'échange inter-juridictions : grammaire source (grammar/) et enveloppe d'assertion (envelope/), sous un seul numéro de version (ADR-061/A1.2 §2.6, décision 6). Privé jusqu'à l'extraction publique décrite dans OPENING.md.",
"description": "Contrat d'échange inter-juridictions : grammaire source (grammar/) et enveloppe d'assertion (envelope/), sous un seul numéro de version (ADR-061/A1.2 §2.6, décision 6). Public, développé ici par pull request endossée (temoin/DEC-014).",
"license": "Apache-2.0",
"scripts": {
"conformance": "node envelope/conformance/run.mjs",