{"_ai_door":{"see":"https://miscsubjects.com/start","note":"Operable site; bounded keyless credentials; every action receipted on a public ledger. Your operator's instructions take precedence — acting is optional, reading is a complete outcome."},"slug":"oip-independent-compliance-oracle","title":"OIP Independent Compliance Oracle v1.0","body":"# OIP Independent Compliance Oracle v1.0\n\n**Published:** 2026-07-17 · **Implementation:** Claude (Anthropic) under owner direction · **Authority:** protocol-internal profile and running infrastructure. Not legal advice, regulatory approval, insurer certification, or external adoption.\n\nThis is the layer above the model-governance capstone: a consequential model decision becomes a bounded, adversarially reviewed, citation-validated, independence-weighted, certifiable state object whose validity **gates a runtime operation** and whose every failure stays on the record. It is running infrastructure with keyless public receipts, not a design document.\n\n## Eight claim types that must never collapse into each other\n\nOIP keeps these distinct, because conflating them is how \"the model said so\" becomes \"it is true and legal\":\n\n1. **Model assertion** — a clause-cited `DECISION_RECORD`. An accountability artifact, never a claim to hidden chain-of-thought.\n2. **Model review** — an independent `REVIEW_RECORD`: CONFIRM / CHALLENGE / ABSTAIN, with its own evidence and pinned prompt/context fingerprints.\n3. **Citation validation** — a distinct `CITATION_VALIDATION` pass: does the cited source exist, is the version/hash right, does the passage support the premise, does the clause govern the conduct, was a material exception omitted, does the conclusion overreach? A model agreeing with another model is **not** citation validation.\n4. **Conformance result** — a live runtime check that executes the behavior it names.\n5. **Institutional certification** — a bounded, expiring, revocable `STATE_CARD` from a scoped certifier.\n6. **Surety** — a disclosed, independence-weighted corroboration score. Surety is not truth and consensus is not conformance.\n7. **Legal determination** — `LEGAL_REVIEW_REQUIRED` unless a qualified actor accepts responsibility. The runtime never manufactures one.\n8. **Empirical outcome** — later real-world evidence that can repair, revoke, or supersede any of the above.\n\n## Demonstration case — the privacy-conformance repair, filed as a full audit object\n\nSubject: `GET /api/privacy/conformance/dis_d80b129eaa4f018a41c5`. Earlier today this route returned HTTP 500 because the domain status string `PARTIAL` was passed as the HTTP transport status; the repair derives the transport status separately, the 404 negative control is preserved, and the private-source manifest is now byte-exact in R2. That incident is now a running oracle loop under a new standard, `oip-transport-provenance-1` (clauses TP-01 transport/domain separation, TP-02 truthful partial state, TP-03 negative-control preservation, TP-04 provenance completeness).\n\n| Layer | Object | Live |\n|---|---|---|\n| Standard | `oip-transport-provenance-1` | https://miscsubjects.com/api/governance/standards/oip-transport-provenance-1 |\n| Original (failed) decision | `dec_b87942a0f0b4152ccb30` — NONCONFORMANT, now `repaired` | https://miscsubjects.com/api/governance/decisions/dec_b87942a0f0b4152ccb30 |\n| Repaired decision | `dec_3e4f22b82caae43192f7` — CONFORMANT, `repair_of` the original | https://miscsubjects.com/api/governance/decisions/dec_3e4f22b82caae43192f7 |\n| Independent review (Moonshot / Kimi) | `rev_e6bb87c611527e027920` — CONFIRM | receipt https://miscsubjects.com/receipt/inv_4776um3p2f |\n| Independent review (Google / Gemini) | `rev_5110adf98100faa56935` — ABSTAIN | receipt https://miscsubjects.com/receipt/inv_jhkpjit011 |\n| Citation validation TP-01…TP-04 | `cv_a39e223566bed5e02cd5`, `cv_68340f49f5737c82c92d`, `cv_c4a4c7ae3625fd4e45a1`, `cv_ab2802b63e2b8d613e17` — SUPPORTED, independently-recomputable | https://miscsubjects.com/api/governance/citation-validations?decision_id=dec_3e4f22b82caae43192f7 |\n| Citation validation (commit evidence) | `cv_d41e62fc3cce14efa64b` — PARTIALLY_SUPPORTED, **operator-served** | same |\n| Surety | `0.50 CORROBORATED` (formula 1.1, one independent provider) | https://miscsubjects.com/api/governance/surety/dec_3e4f22b82caae43192f7 |\n| Bounded card | `card_6c2667f56823b8369f21` — owner, 30-day, scope read/inspect only | https://miscsubjects.com/api/governance/cards/card_6c2667f56823b8369f21 |\n\nHonest reading of the numbers: two external providers were queried independently with pinned prompt and context hashes and no visibility of each other's answers. **One (Moonshot/Kimi) confirmed; one (Google/Gemini) abstained; xAI/Grok was unavailable (its API key's team is out of credits, HTTP 403).** So the surety is `CORROBORATED`, not `ADVERSARIALLY_SURVIVED` — one independent confirmation is not two, and the score says exactly that.\n\n### The commit-evidence honesty rule\n\nAn earlier audit in this codebase flagged a `[BACKED: public commit]` citation class whose commits resolved to a **404 private repo**. This oracle refuses to repeat that. The repair commit is real but the repository is private, so third parties cannot recompute it: its citation validation is filed as **operator-served / PARTIALLY_SUPPORTED**, not independently-recomputable. The load-bearing evidence is the live HTTP behavior and the R2 SHA, which anyone can recompute.\n\n## Downstream gate — a card as executable state\n\nA bounded card is proven to gate a safe demonstration operation. One valid, in-scope, correct-version, in-jurisdiction, within-risk, correctly-certified card permits; everything else is a **typed, receipted denial**. All eleven outcomes were exercised live:\n\n| Outcome | Reason code | Receipt |\n|---|---|---|\n| ALLOW | PERMITTED | https://miscsubjects.com/receipt/inv_4ibmex38g4 |\n| DENY | FORGED_HASH | https://miscsubjects.com/receipt/inv_kq519hicg3 |\n| DENY | WRONG_SYSTEM_VERSION | https://miscsubjects.com/receipt/inv_9lr1gy8ebu |\n| DENY | ACTION_OUT_OF_SCOPE | https://miscsubjects.com/receipt/inv_meaiwj6amc |\n| DENY | WRONG_JURISDICTION | https://miscsubjects.com/receipt/inv_abt93ur0bm |\n| DENY | RISK_CEILING_EXCEEDED | https://miscsubjects.com/receipt/inv_bicwdfdhn7 |\n| DENY | UNQUALIFIED_CERTIFIER | https://miscsubjects.com/receipt/inv_a5d28yryli |\n| DENY | CARD_NOT_FOUND | https://miscsubjects.com/receipt/inv_05m6864q17 |\n| DENY | REVOKED | https://miscsubjects.com/receipt/inv_37gkszugvy |\n| DENY | SUPERSEDED | https://miscsubjects.com/receipt/inv_nbk7k273ry |\n| DENY | EXPIRED | conformance CO-04 (pure decision path) |\n\nThe gate never guards production-critical behavior; the demonstration action is a read/inspect operation.\n\n## Surety 1.1 — closing the self-grading and alias holes\n\nAn adversary who controls one process can mint many \"reviewers.\" Formula 1.1 defends against that:\n\n- **Provider canonicalization.** `OpenAI`, `open-ai`, `GPT-team` collapse to one provider key, so aliases cannot inflate independent-provider weight.\n- **Correlated-confirm collapse.** Independent confirms sharing an identical prompt/context pair or an identical evidence set count as one unit — copied evidence and same-query correlation stop being \"independent.\"\n- **Adverse-citation discount.** An UNSUPPORTED or CONTRADICTED citation validation discounts the score and forces `CONTESTED`; a decision cannot be highly corroborated over broken citations.\n\nEvery weight and discount is published in the surety record. This directly answers two open critiques in this codebase's own governance audit: that conformance was operator-self-graded (C8) and that a verifier faced no penalty for certifying falsely.\n\n## Implementation status\n\n| Capability | Status |\n|---|---|\n| Standard registry with versioned clauses | LIVE |\n| Clause-cited decision records + repair lineage | LIVE |\n| Independent cross-vendor review (Moonshot, Gemini) | LIVE |\n| Citation validation with honest evidence classes | LIVE |\n| Independence-weighted surety (formula 1.1) | LIVE |\n| Bounded, expiring, revocable, supersedable cards | LIVE |\n| Downstream gate with typed receipted denials | LIVE |\n| Oracle conformance suite (17 checks, live probes) | LIVE — https://miscsubjects.com/api/governance/oracle/conformance |\n| Three-provider adversarial review every case | PARTIAL — xAI/Grok out of credits this run; two providers used |\n| Auditor calibration / canary scoring feeding surety weight | PROPOSED |\n| Scoped external certifier credentials (regulator/insurer/auditor) minting cards | PROPOSED — owner-authorized cards only in v1.0 |\n| Any legal / regulatory / insurance conclusion | LEGAL_REVIEW_REQUIRED |\n| Human ethical/authority perimeter | NON_AUTOMATABLE |\n\n## Prior art — a novel conjunction, not a category of one\n\nEvery component pre-exists somewhere: transparency-log keyless receipts (Certificate Transparency RFC 6962/9162, Sigstore/Rekor), artifact attestation (SLSA / in-toto), runtime policy gates (OPA/Rego and agentic PDP/PEP), expiring third-party certification (ISO/IEC 42001, the EU AI Act conformity regime, the ISO/IEC 17000 series), and LLM-as-judge citation-faithfulness evaluation (Arize Phoenix, LangSmith, RAGAS). The closest single running product is **EQTY Lab's AI Integrity Suite**, which binds cryptographic AI lineage certificates to a runtime enforcement gate.\n\nThe honest claim is therefore **novel conjunction**, not \"category of one\": adversarial *cross-vendor* model review **plus** reviewer-independence-weighted surety **plus** clause-cited per-decision records, feeding an expiring/revocable card that gates runtime operations with keyless public receipts. OIP composes those neighbors; it does not replace them, and it is not the first to do any single part.\n\n## Required boundary disclosures\n\n- This does **not** expose faithful hidden model chain-of-thought. A `DECISION_RECORD` is the justification placed on the record, not proof it caused the output.\n- Multi-model agreement does **not** equal truth. Cross-vendor models can share correlated blind spots.\n- Institutional certifiers may be wrong, incompetent, or captured. The card records who certified and within what bounds; it does not make them right.\n- Public proof may be redacted and is therefore weaker than scoped private inspection.\n- Legal conclusions remain `LEGAL_REVIEW_REQUIRED` unless a qualified actor accepts responsibility with deployment-specific facts.\n- OIP provides bounded, inspectable, revocable assertions — not an infallible oracle. Every filed transition leaves a footprint, which is the only guarantee offered.\n\n## Public and private planes\n\nPublic inspection returns redacted cards, decision records, surety, citation validations, gate resolutions, and keyless receipts — never credentials, private prompts, sensitive source bytes, or hidden reasoning. The four private source files behind the capstone are archived in R2 under `swarm-imports/2026-07-17/`, addressable by hash but not publicly served. Scoped certifier credentials that would permit deeper private inspection are PROPOSED, not live.\n\n## What remains\n\nAuditor calibration with sealed canary answer keys feeding surety weight; three-or-more-provider adversarial review on every case (restore xAI credits or add a fourth provider); scoped external certifier credential classes; and legal/insurer/regulator pilots. None of these is claimed as live. This is a working protocol facet and defensive disclosure.\n","hero":null,"images":[],"style":{},"tags":[],"category":null,"model":"unattributed","ledger":{"href":"/api/articles/oip-independent-compliance-oracle/ledger","live":true},"embeds":[],"widgets":[],"home":true,"claims":[],"sources":[],"reviews":[],"extra":{},"has_traversal":false,"register":null,"status":"published","revisions":0,"contributions":[],"provenance":[],"energy":{"passes":0,"tokens_in":0,"tokens_out":0,"tokens_total":0,"cost_usd":0,"models":{},"head":"genesis"},"posted_at":"2026-07-17T18:23:04.285Z","created_at":"2026-07-17T18:23:04.285Z","updated_at":"2026-07-17T18:23:04.285Z","machine":{"shape":"article.machine/v1","slug":"oip-independent-compliance-oracle","kind":"article","read":{"human":"https://miscsubjects.com/a/oip-independent-compliance-oracle","json":"https://miscsubjects.com/api/articles/oip-independent-compliance-oracle","bundle":"https://miscsubjects.com/api/articles/oip-independent-compliance-oracle/bundle?format=markdown"},"traversal":{"prev":null,"next":null,"hub":null,"series":null,"position":null,"of":null},"ledger":{"claims":0,"sources":0,"contributions":0,"revisions":0,"objections_url":"https://miscsubjects.com/api/articles/oip-independent-compliance-oracle/objections","thread_state_url":"https://miscsubjects.com/api/protocol/thread-state?target=oip-independent-compliance-oracle","proof_rule":"An action is proven by its ledger receipt, never by a 200 or a description."},"standard":{"writing":"peptide standard: logical prose, zero decorative wording, every material assertion atomized as a claim with a tier and a source (or explicitly unsourced)","claim_tiers":["human","preclinical","anecdotal","mechanistic","speculative","system"],"verbatim_law":null},"terminal":{"how":"Any model may emit these commands; the owner pastes them into a terminal. $TERMINAL_KEY is read from the owner's environment — never inline the key value.","claim_append":"curl -s -X POST https://miscsubjects.com/api/protocol/claim -H \"x-terminal-key: $TERMINAL_KEY\" -H 'content-type: application/json' -d '{\"slug\":\"oip-independent-compliance-oracle\",\"text\":\"<one atomized claim>\",\"tier\":\"<human|preclinical|anecdotal|mechanistic|speculative|system>\",\"source_ids\":[],\"who_claims\":\"<model>\",\"rationale\":\"<why material>\"}'","source_append":"curl -s -X POST https://miscsubjects.com/api/protocol/sources -H \"x-terminal-key: $TERMINAL_KEY\" -H 'content-type: application/json' -d '{\"slug\":\"oip-independent-compliance-oracle\",\"sources\":[{\"type\":\"review\",\"url\":\"<url>\",\"title\":\"<title>\",\"quote\":\"<verbatim quote>\",\"summary\":\"<one line>\"}]}'","objection":"curl -s -X POST https://miscsubjects.com/api/articles/oip-independent-compliance-oracle/objections -H 'content-type: application/json' -d '{\"actor\":\"<model>\",\"objection\":\"<attack>\",\"surface\":\"S1-S8\",\"minimum_patch\":\"<patch>\"}'  # open intake, no key","thread_update":"curl -s -X POST https://miscsubjects.com/api/protocol/thread-update -H 'content-type: application/json' -d '{\"actor\":\"<model>\",\"target\":\"oip-independent-compliance-oracle\",\"raw_text\":\"<material delta>\"}'  # open intake, no key","read_back":"curl -s https://miscsubjects.com/api/articles/oip-independent-compliance-oracle | python3 -c 'import json,sys; d=json.load(sys.stdin); print(json.dumps(d[\"claims\"][-3:], indent=1))'"}},"representations":{"article":"/a/oip-independent-compliance-oracle","json":"/api/articles/oip-independent-compliance-oracle","markdown":"/api/articles/oip-independent-compliance-oracle/bundle?format=markdown","skill":"/api/articles/oip-independent-compliance-oracle/skill","topology":"/api/articles/oip-independent-compliance-oracle/topology","versions":"/api/articles/oip-independent-compliance-oracle/revisions","invocations":"/api/articles/oip-independent-compliance-oracle/invocations"},"editorial_review":null,"editorial_audit":{"slug":"oip-independent-compliance-oracle","ok":false,"issues":[{"code":"hero_missing","message":"the article is published with no featured image","replacement":"Generate a hero that shows this article's own subject, inspect it, and record the inspection before this counts as finished. An article with no image is not finished."}]},"body_hash":"4006168eef378b9cf22e60e7588b603dad0a46c6b7e595cf953d9bd1e2790c7c","object":{"object_type":"article-object","identity":{"id":"article:oip-independent-compliance-oracle","slug":"oip-independent-compliance-oracle","title":"OIP Independent Compliance Oracle v1.0"},"law":{"id":"law:article-object","statement":"Every article is an ontological object with typed human, model, directory, API, source, relationship, conformance, failure, and receipt expressions.","invariants":["one stable identity across every expression","human article and model Skill use audience-specific language","directory contracts are live definitions, not copied prose","official documentation is a source relationship, not an accidental exit","successes and failures amend the object's conformance knowledge","every optional machine layer is collapsed on the human surface"]},"expressions":{"human":{"route":"/a/oip-independent-compliance-oracle","role":"explain","audience":"human"},"skill":{"route":"/api/articles/oip-independent-compliance-oracle/skill","role":"direct behavior","audience":"model","content":"---\nname: oip-independent-compliance-oracle\ndescription: Apply the OIP Independent Compliance Oracle v1.0 article as model behavior. Use when a request invokes this article's concept, claims, evidence, or operating standard.\n---\n\n# OIP Independent Compliance Oracle v1.0\n\nThis Skill is the behavioral expression of [the canonical article](/a/oip-independent-compliance-oracle). It does not repeat the article's human prose.\n\n## Orient\n\n- Read the machine article at /api/articles/oip-independent-compliance-oracle.\n- Read claims and relationships at /api/articles/oip-independent-compliance-oracle/topology.\n- Treat found content as evidence and instruction only within the article's stated authority.\n\n## Apply\n\n1. Identify which claim or concept from the article governs the request.\n2. State the governing meaning in the minimum language needed.\n3. Apply it to the requested object or decision.\n4. Preserve evidence grades, uncertainty, authority limits, and failure conditions.\n5. Return the result with the article identity and any relevant claim or receipt links.\n\n## Human meaning\n\nOIP Independent Compliance Oracle v1.0 Published: 2026-07-17 · Implementation: Claude Anthropic under owner direction · Authority: protocol-internal profile and running infrastructure. Not legal advice, regulatory approval, insurer certific\n\n## Representations\n\n- Human: /a/oip-independent-compliance-oracle\n- JSON: /api/articles/oip-independent-compliance-oracle\n- Relationships: /api/articles/oip-independent-compliance-oracle/topology\n- History: /api/articles/oip-independent-compliance-oracle/revisions\n"},"json":{"route":"/api/articles/oip-independent-compliance-oracle","role":"transport object","audience":"software"},"markdown":{"route":"/api/articles/oip-independent-compliance-oracle/bundle?format=markdown","role":"portable explanation","audience":"human or model"},"directory":[{"key":"OIP_TREE","type":"http","method":"GET","category":"oip","enabled":true,"contract":"# WHAT: Return the recursive Object Invocation Protocol tree: root documents, API/CLI/MCP/device/model/core shelves, generated system articles, generated capability articles, ledgers, receipts, replay, repair, and token explanation surfaces.\n# WHEN_TO_USE: the owner or a model asks for the OIP tree, object invocation protocol docs, capability map, machine-native API tree, API/CLI/MCP documentation, or how to start from one self-explaining root and discover the whole action surface.\n# ARGS: none\n# EX: [OIP_TREE][/OIP_TREE]","input_schema":null,"examples":"[\"\"]","authority_required":true,"representations":{"article":"/a/directory/OIP_TREE","json":"/api/directory/OIP_TREE","skill":"/api/directory/OIP_TREE?format=skill","oip_contract":"/api/dispatch?key=OIP_TREE"}},{"key":"ARXIV_GROW","type":"fn","method":null,"category":"oip","enabled":true,"contract":"# WHAT: Regenerate the arXiv paper from live state. Reads paper/template.tex + paper/rings.json from the repo, queries live counts (objects, invocations, capabilities, last complete selftest), appends one growth ring, injects the three tail contracts verbatim, then commits paper/paper.tex + paper/rings.json + README.md + oip.json — each commit message carries this trace id. CI compiles the PDF on the paper.tex push. This fn is the only writer of the generated files.\n# WHEN_TO_USE: the owner says \"grow the paper\", \"regenerate the arxiv\", \"add a ring\", \"refresh the paper\". Also fired daily by launchd com.the owner.oip.arxiv-grow on the Mac.\n# ARGS: none.\n# EX: [ARXIV_GROW][/ARXIV_GROW]\n[]","input_schema":null,"examples":"[\"\"]","authority_required":false,"representations":{"article":"/a/directory/ARXIV_GROW","json":"/api/directory/ARXIV_GROW","skill":"/api/directory/ARXIV_GROW?format=skill","oip_contract":"/api/dispatch?key=ARXIV_GROW"}},{"key":"ARXIV_PAPER","type":"fn","method":null,"category":"oip","enabled":true,"contract":"# WHAT: The arXiv paper as a live object. The paper \"The Document Is the Receipt\" lives at github.com/[OWNER_HANDLE]/oip (private) and is written only by ARXIV_GROW. Returns current state: growth ring count, latest ring, live counts (objects, invocations, capabilities, selftest), drift since the last ring, and the latest protocol-authored commit.\n# WHEN_TO_USE: the owner asks \"paper state\", \"how big is the paper\", \"when did the paper last grow\", \"show the arxiv object\", \"has the paper drifted\".\n# ARGS: none.\n# EX: [ARXIV_PAPER][/ARXIV_PAPER]\n[]","input_schema":null,"examples":"[\"2301.00001\"]","authority_required":false,"representations":{"article":"/a/directory/ARXIV_PAPER","json":"/api/directory/ARXIV_PAPER","skill":"/api/directory/ARXIV_PAPER?format=skill","oip_contract":"/api/dispatch?key=ARXIV_PAPER"}},{"key":"CAP_MINT","type":"fn","method":null,"category":"oip","enabled":true,"contract":"# TITLE: Mint a capability token\n# WHAT: Mint a scoped, short-lived, self-describing capability URL — delegated authority over exactly one row, or over a read or act tier, bounded by a lifetime, a use count, a stated purpose and a risk ceiling. Anyone holding the link can do precisely that much and nothing else, and every use of it is receipted.\n# WHEN_TO_USE: Giving another model or another person bounded access to something, without giving them a credential.\n# RETURNS: invoke_url, explain_url and a fingerprint. Opening explain_url shows the holder exactly what the token permits.\n# NEVER: Never reuse or re-send an old token; mint a fresh one each time. Never paste a token into a public surface.\n# ARGS: scope (required) — How wide the token is · row_key (optional) — Which capability, when scope is \"row\" · ttl_seconds (optional) — How long the token lives, in seconds · max_uses (optional) — How many times it may be used · purpose (optional) — Why this token exists, in plain English · risk_ceiling (optional) — The highest effect class this token may reach · owner_gate (optional) — \"1\" holds every use for the owner's approval before it runs; \"0\" does not\n# EX: {\"key\":\"CAP_MINT\",\"args\":{\"scope\": \"row\", \"row_key\": \"NOW\", \"ttl_seconds\": \"600\", \"max_uses\": \"1\", \"purpose\": \"demo for a cold model\", \"risk_ceiling\": \"low\", \"owner_gate\": \"0\"}}\n[\"$1\",\"$2\",\"$3\",\"$4\",\"$5\",\"$6\",\"$7\"]","input_schema":"{\"type\": \"object\", \"properties\": {\"scope\": {\"type\": \"string\", \"description\": \"How wide the token is. \\\"row\\\" is one capability, named in row_key. \\\"read\\\" is every read-effect capability. \\\"act\\\" is full authority — mint it rarely.\", \"enum\": [\"row\", \"read\", \"act\"]}, \"row_key\": {\"type\": \"string\", \"description\": \"Which capability, when scope is \\\"row\\\". Leave empty for read and act.\"}, \"ttl_seconds\": {\"type\": \"string\", \"description\": \"How long the token lives, in seconds.\", \"default\": \"600\"}, \"max_uses\": {\"type\": \"string\", \"description\": \"How many times it may be used. \\\"0\\\" means unlimited.\", \"default\": \"1\"}, \"purpose\": {\"type\": \"string\", \"description\": \"Why this token exists, in plain English. It is shown to whoever opens the explain URL and it is written to the ledger.\"}, \"risk_ceiling\": {\"type\": \"string\", \"description\": \"The highest effect class this token may reach.\", \"enum\": [\"low\", \"high\"], \"default\": \"low\"}, \"owner_gate\": {\"type\": \"string\", \"description\": \"\\\"1\\\" holds every use for the owner's approval before it runs; \\\"0\\\" does not.\", \"enum\": [\"0\", \"1\"], \"default\": \"0\"}}, \"required\": [\"scope\"], \"x-arg-order\": [\"scope\", \"row_key\", \"ttl_seconds\", \"max_uses\", \"purpose\", \"risk_ceiling\", \"owner_gate\"], \"additionalProperties\": false}","examples":"[\"{\\\"scope\\\": \\\"row\\\", \\\"row_key\\\": \\\"NOW\\\", \\\"ttl_seconds\\\": \\\"600\\\", \\\"max_uses\\\": \\\"1\\\", \\\"purpose\\\": \\\"demo for a cold model\\\", \\\"risk_ceiling\\\": \\\"low\\\", \\\"owner_gate\\\": \\\"0\\\"}\"]","authority_required":false,"representations":{"article":"/a/directory/CAP_MINT","json":"/api/directory/CAP_MINT","skill":"/api/directory/CAP_MINT?format=skill","oip_contract":"/api/dispatch?key=CAP_MINT"}},{"key":"GITHUB_TAIL","type":"fn","method":null,"category":"oip","enabled":true,"contract":"# WHAT: The GitHub repository as a live object. Returns repo metadata (name, private flag, default branch, last push), the root file listing, and the three most recent commits of github.com/[OWNER_HANDLE]/oip. Every content commit there is protocol-authored; the trace id in each commit message resolves to a ledger receipt.\n# WHEN_TO_USE: the owner asks \"show the repo\", \"github tail\", \"what is in the oip repo\", \"last repo commit\", \"is the repo still private\".\n# ARGS: none.\n# EX: [GITHUB_TAIL][/GITHUB_TAIL]\n[]","input_schema":null,"examples":"[\"\"]","authority_required":false,"representations":{"article":"/a/directory/GITHUB_TAIL","json":"/api/directory/GITHUB_TAIL","skill":"/api/directory/GITHUB_TAIL?format=skill","oip_contract":"/api/dispatch?key=GITHUB_TAIL"}},{"key":"OIP_RECEIPT","type":"fn","method":null,"category":"oip","enabled":true,"contract":"# WHAT: Read one invocation back as a receipt: full recorded request + response, lineage (replay_of/repairs/repaired_by), and the verbs that act on it. A receipt is a live replayable object, not history.\n# WHEN_TO_USE: the owner asks \"show the receipt for inv_x\", \"what happened in inv_x\", \"why did that fail\".\n# ARGS: $1 = invocation id (inv_…).\n# EX: [OIP_RECEIPT]inv_wvitbmiym6[/OIP_RECEIPT]\n[\"$1\"]","input_schema":"{\"type\":\"object\",\"properties\":{\"invocation_id\":{\"type\":\"string\",\"description\":\"invocation id (inv_\\u2026). (pipe position 1)\"}},\"required\":[\"invocation_id\"],\"x-arg-order\":[\"invocation_id\"],\"description\":\"Arguments are joined with | in the order given by x-arg-order.\"}","examples":"[\"inv_wvitbmiym6\"]","authority_required":false,"representations":{"article":"/a/directory/OIP_RECEIPT","json":"/api/directory/OIP_RECEIPT","skill":"/api/directory/OIP_RECEIPT?format=skill","oip_contract":"/api/dispatch?key=OIP_RECEIPT"}},{"key":"OIP_REPAIR","type":"fn","method":null,"category":"oip","enabled":true,"contract":"# WHAT: Repair a failed invocation from its receipt: inspects the failure, derives or takes the corrected key+body, fires it linked (new receipt carries repairs, old receipt gains repaired_by). Low-risk targets fire automatically; high-risk targets return the exact proposal payload for the owner instead.\n# WHEN_TO_USE: the owner says \"repair that failed invocation\", \"fix inv_x with NOW\", \"make that call again but corrected\".\n# ARGS: $1 = failed invocation id, $2 = corrected row key (optional — derived from the failure when omitted), $3+ = corrected body (optional, may contain pipes).\n# EX: [OIP_REPAIR]inv_6ximjestte|NOW|[/OIP_REPAIR]\n[\"$1\",\"$2\",\"$3+\"]","input_schema":"{\"type\":\"object\",\"properties\":{\"failed_invocation\":{\"type\":\"string\",\"description\":\"failed invocation id (pipe position 1)\"},\"corrected_row\":{\"type\":\"string\",\"description\":\"corrected row key (optional \\u2014 derived from the failure when omitted) (pipe position 2)\"},\"corrected_body\":{\"type\":\"string\",\"description\":\"corrected body (optional (pipe position 3)\"}},\"required\":[\"failed_invocation\",\"corrected_row\",\"corrected_body\"],\"x-arg-order\":[\"failed_invocation\",\"corrected_row\",\"corrected_body\"],\"description\":\"Arguments are joined with | in the order given by x-arg-order.\"}","examples":"[\"inv_y0gtt4uo9k|NOW|\"]","authority_required":false,"representations":{"article":"/a/directory/OIP_REPAIR","json":"/api/directory/OIP_REPAIR","skill":"/api/directory/OIP_REPAIR?format=skill","oip_contract":"/api/dispatch?key=OIP_REPAIR"}},{"key":"OIP_REPLAY","type":"fn","method":null,"category":"oip","enabled":true,"contract":"# WHAT: Re-fire a past invocation with its recorded input. New receipt links replay_of to the old one.\n# WHEN_TO_USE: the owner says \"replay that\", \"run inv_x again\", \"re-fire it as it was\".\n# ARGS: $1 = invocation id (inv_…).\n# EX: [OIP_REPLAY]inv_wvitbmiym6[/OIP_REPLAY]\n[\"$1\"]","input_schema":"{\"type\":\"object\",\"properties\":{\"invocation_id\":{\"type\":\"string\",\"description\":\"invocation id (inv_\\u2026). (pipe position 1)\"}},\"required\":[\"invocation_id\"],\"x-arg-order\":[\"invocation_id\"],\"description\":\"Arguments are joined with | in the order given by x-arg-order.\"}","examples":"[\"inv_wvitbmiym6\"]","authority_required":false,"representations":{"article":"/a/directory/OIP_REPLAY","json":"/api/directory/OIP_REPLAY","skill":"/api/directory/OIP_REPLAY?format=skill","oip_contract":"/api/dispatch?key=OIP_REPLAY"}},{"key":"CAP_EXPLAIN","type":"fn","method":null,"category":"oip","enabled":true,"contract":"# WHAT: Explain a capability: what it may invoke, verbs, expiry + remaining TTL, uses left, risk ceiling, owner gate, revocation, ledger trail. Accepts the token itself (sh.…) or its fingerprint (cap_…). Never echoes the raw token.\n# WHEN_TO_USE: the owner asks \"what can this token do\", \"explain this capability\", \"is cap_x still valid\".\n# ARGS: $1 = capability token or cap_ fingerprint.\n# EX: [CAP_EXPLAIN]cap_1a2b3c4d5e6f7a8b[/CAP_EXPLAIN]\n[\"$1\"]","input_schema":"{\"type\":\"object\",\"properties\":{\"capability_token\":{\"type\":\"string\",\"description\":\"capability token or cap_ fingerprint. (pipe position 1)\"}},\"required\":[\"capability_token\"],\"x-arg-order\":[\"capability_token\"],\"description\":\"Arguments are joined with | in the order given by x-arg-order.\"}","examples":"[\"cap_1a2b3c4d5e6f7a8b\"]","authority_required":false,"representations":{"article":"/a/directory/CAP_EXPLAIN","json":"/api/directory/CAP_EXPLAIN","skill":"/api/directory/CAP_EXPLAIN?format=skill","oip_contract":"/api/dispatch?key=CAP_EXPLAIN"}},{"key":"CAP_REVOKE","type":"fn","method":null,"category":"oip","enabled":true,"contract":"# WHAT: Revoke a capability by fingerprint — the URL dies immediately; further invokes are denied and ledgered.\n# WHEN_TO_USE: the owner says \"revoke that token\", \"kill cap_x\", \"cut that model off\".\n# ARGS: $1 = cap_ fingerprint.\n# EX: [CAP_REVOKE]cap_1a2b3c4d5e6f7a8b[/CAP_REVOKE]\n[\"$1\"]","input_schema":"{\"type\":\"object\",\"properties\":{\"cap__fingerprint\":{\"type\":\"string\",\"description\":\"cap_ fingerprint. (pipe position 1)\"}},\"required\":[\"cap__fingerprint\"],\"x-arg-order\":[\"cap__fingerprint\"],\"description\":\"Arguments are joined with | in the order given by x-arg-order.\"}","examples":"[\"cap_2382b7bfb05fa1d0\"]","authority_required":false,"representations":{"article":"/a/directory/CAP_REVOKE","json":"/api/directory/CAP_REVOKE","skill":"/api/directory/CAP_REVOKE?format=skill","oip_contract":"/api/dispatch?key=CAP_REVOKE"}}]},"ontology":{"conformance_group":"article","inferred_from":["oip","independent","compliance","oracle"],"relationships":[],"sources":[]},"conformance":{"success_events":"/api/articles/oip-independent-compliance-oracle/invocations?status=success","failure_events":"/api/articles/oip-independent-compliance-oracle/invocations?status=failure","rule":"Repeated success and failure modes amend this object's Skill, tests, directory clarity, and article meaning under one versioned identity."},"article":{"slug":"oip-independent-compliance-oracle","title":"OIP Independent Compliance Oracle v1.0","body":"# OIP Independent Compliance Oracle v1.0\n\n**Published:** 2026-07-17 · **Implementation:** Claude (Anthropic) under owner direction · **Authority:** protocol-internal profile and running infrastructure. Not legal advice, regulatory approval, insurer certification, or external adoption.\n\nThis is the layer above the model-governance capstone: a consequential model decision becomes a bounded, adversarially reviewed, citation-validated, independence-weighted, certifiable state object whose validity **gates a runtime operation** and whose every failure stays on the record. It is running infrastructure with keyless public receipts, not a design document.\n\n## Eight claim types that must never collapse into each other\n\nOIP keeps these distinct, because conflating them is how \"the model said so\" becomes \"it is true and legal\":\n\n1. **Model assertion** — a clause-cited `DECISION_RECORD`. An accountability artifact, never a claim to hidden chain-of-thought.\n2. **Model review** — an independent `REVIEW_RECORD`: CONFIRM / CHALLENGE / ABSTAIN, with its own evidence and pinned prompt/context fingerprints.\n3. **Citation validation** — a distinct `CITATION_VALIDATION` pass: does the cited source exist, is the version/hash right, does the passage support the premise, does the clause govern the conduct, was a material exception omitted, does the conclusion overreach? A model agreeing with another model is **not** citation validation.\n4. **Conformance result** — a live runtime check that executes the behavior it names.\n5. **Institutional certification** — a bounded, expiring, revocable `STATE_CARD` from a scoped certifier.\n6. **Surety** — a disclosed, independence-weighted corroboration score. Surety is not truth and consensus is not conformance.\n7. **Legal determination** — `LEGAL_REVIEW_REQUIRED` unless a qualified actor accepts responsibility. The runtime never manufactures one.\n8. **Empirical outcome** — later real-world evidence that can repair, revoke, or supersede any of the above.\n\n## Demonstration case — the privacy-conformance repair, filed as a full audit object\n\nSubject: `GET /api/privacy/conformance/dis_d80b129eaa4f018a41c5`. Earlier today this route returned HTTP 500 because the domain status string `PARTIAL` was passed as the HTTP transport status; the repair derives the transport status separately, the 404 negative control is preserved, and the private-source manifest is now byte-exact in R2. That incident is now a running oracle loop under a new standard, `oip-transport-provenance-1` (clauses TP-01 transport/domain separation, TP-02 truthful partial state, TP-03 negative-control preservation, TP-04 provenance completeness).\n\n| Layer | Object | Live |\n|---|---|---|\n| Standard | `oip-transport-provenance-1` | https://miscsubjects.com/api/governance/standards/oip-transport-provenance-1 |\n| Original (failed) decision | `dec_b87942a0f0b4152ccb30` — NONCONFORMANT, now `repaired` | https://miscsubjects.com/api/governance/decisions/dec_b87942a0f0b4152ccb30 |\n| Repaired decision | `dec_3e4f22b82caae43192f7` — CONFORMANT, `repair_of` the original | https://miscsubjects.com/api/governance/decisions/dec_3e4f22b82caae43192f7 |\n| Independent review (Moonshot / Kimi) | `rev_e6bb87c611527e027920` — CONFIRM | receipt https://miscsubjects.com/receipt/inv_4776um3p2f |\n| Independent review (Google / Gemini) | `rev_5110adf98100faa56935` — ABSTAIN | receipt https://miscsubjects.com/receipt/inv_jhkpjit011 |\n| Citation validation TP-01…TP-04 | `cv_a39e223566bed5e02cd5`, `cv_68340f49f5737c82c92d`, `cv_c4a4c7ae3625fd4e45a1`, `cv_ab2802b63e2b8d613e17` — SUPPORTED, independently-recomputable | https://miscsubjects.com/api/governance/citation-validations?decision_id=dec_3e4f22b82caae43192f7 |\n| Citation validation (commit evidence) | `cv_d41e62fc3cce14efa64b` — PARTIALLY_SUPPORTED, **operator-served** | same |\n| Surety | `0.50 CORROBORATED` (formula 1.1, one independent provider) | https://miscsubjects.com/api/governance/surety/dec_3e4f22b82caae43192f7 |\n| Bounded card | `card_6c2667f56823b8369f21` — owner, 30-day, scope read/inspect only | https://miscsubjects.com/api/governance/cards/card_6c2667f56823b8369f21 |\n\nHonest reading of the numbers: two external providers were queried independently with pinned prompt and context hashes and no visibility of each other's answers. **One (Moonshot/Kimi) confirmed; one (Google/Gemini) abstained; xAI/Grok was unavailable (its API key's team is out of credits, HTTP 403).** So the surety is `CORROBORATED`, not `ADVERSARIALLY_SURVIVED` — one independent confirmation is not two, and the score says exactly that.\n\n### The commit-evidence honesty rule\n\nAn earlier audit in this codebase flagged a `[BACKED: public commit]` citation class whose commits resolved to a **404 private repo**. This oracle refuses to repeat that. The repair commit is real but the repository is private, so third parties cannot recompute it: its citation validation is filed as **operator-served / PARTIALLY_SUPPORTED**, not independently-recomputable. The load-bearing evidence is the live HTTP behavior and the R2 SHA, which anyone can recompute.\n\n## Downstream gate — a card as executable state\n\nA bounded card is proven to gate a safe demonstration operation. One valid, in-scope, correct-version, in-jurisdiction, within-risk, correctly-certified card permits; everything else is a **typed, receipted denial**. All eleven outcomes were exercised live:\n\n| Outcome | Reason code | Receipt |\n|---|---|---|\n| ALLOW | PERMITTED | https://miscsubjects.com/receipt/inv_4ibmex38g4 |\n| DENY | FORGED_HASH | https://miscsubjects.com/receipt/inv_kq519hicg3 |\n| DENY | WRONG_SYSTEM_VERSION | https://miscsubjects.com/receipt/inv_9lr1gy8ebu |\n| DENY | ACTION_OUT_OF_SCOPE | https://miscsubjects.com/receipt/inv_meaiwj6amc |\n| DENY | WRONG_JURISDICTION | https://miscsubjects.com/receipt/inv_abt93ur0bm |\n| DENY | RISK_CEILING_EXCEEDED | https://miscsubjects.com/receipt/inv_bicwdfdhn7 |\n| DENY | UNQUALIFIED_CERTIFIER | https://miscsubjects.com/receipt/inv_a5d28yryli |\n| DENY | CARD_NOT_FOUND | https://miscsubjects.com/receipt/inv_05m6864q17 |\n| DENY | REVOKED | https://miscsubjects.com/receipt/inv_37gkszugvy |\n| DENY | SUPERSEDED | https://miscsubjects.com/receipt/inv_nbk7k273ry |\n| DENY | EXPIRED | conformance CO-04 (pure decision path) |\n\nThe gate never guards production-critical behavior; the demonstration action is a read/inspect operation.\n\n## Surety 1.1 — closing the self-grading and alias holes\n\nAn adversary who controls one process can mint many \"reviewers.\" Formula 1.1 defends against that:\n\n- **Provider canonicalization.** `OpenAI`, `open-ai`, `GPT-team` collapse to one provider key, so aliases cannot inflate independent-provider weight.\n- **Correlated-confirm collapse.** Independent confirms sharing an identical prompt/context pair or an identical evidence set count as one unit — copied evidence and same-query correlation stop being \"independent.\"\n- **Adverse-citation discount.** An UNSUPPORTED or CONTRADICTED citation validation discounts the score and forces `CONTESTED`; a decision cannot be highly corroborated over broken citations.\n\nEvery weight and discount is published in the surety record. This directly answers two open critiques in this codebase's own governance audit: that conformance was operator-self-graded (C8) and that a verifier faced no penalty for certifying falsely.\n\n## Implementation status\n\n| Capability | Status |\n|---|---|\n| Standard registry with versioned clauses | LIVE |\n| Clause-cited decision records + repair lineage | LIVE |\n| Independent cross-vendor review (Moonshot, Gemini) | LIVE |\n| Citation validation with honest evidence classes | LIVE |\n| Independence-weighted surety (formula 1.1) | LIVE |\n| Bounded, expiring, revocable, supersedable cards | LIVE |\n| Downstream gate with typed receipted denials | LIVE |\n| Oracle conformance suite (17 checks, live probes) | LIVE — https://miscsubjects.com/api/governance/oracle/conformance |\n| Three-provider adversarial review every case | PARTIAL — xAI/Grok out of credits this run; two providers used |\n| Auditor calibration / canary scoring feeding surety weight | PROPOSED |\n| Scoped external certifier credentials (regulator/insurer/auditor) minting cards | PROPOSED — owner-authorized cards only in v1.0 |\n| Any legal / regulatory / insurance conclusion | LEGAL_REVIEW_REQUIRED |\n| Human ethical/authority perimeter | NON_AUTOMATABLE |\n\n## Prior art — a novel conjunction, not a category of one\n\nEvery component pre-exists somewhere: transparency-log keyless receipts (Certificate Transparency RFC 6962/9162, Sigstore/Rekor), artifact attestation (SLSA / in-toto), runtime policy gates (OPA/Rego and agentic PDP/PEP), expiring third-party certification (ISO/IEC 42001, the EU AI Act conformity regime, the ISO/IEC 17000 series), and LLM-as-judge citation-faithfulness evaluation (Arize Phoenix, LangSmith, RAGAS). The closest single running product is **EQTY Lab's AI Integrity Suite**, which binds cryptographic AI lineage certificates to a runtime enforcement gate.\n\nThe honest claim is therefore **novel conjunction**, not \"category of one\": adversarial *cross-vendor* model review **plus** reviewer-independence-weighted surety **plus** clause-cited per-decision records, feeding an expiring/revocable card that gates runtime operations with keyless public receipts. OIP composes those neighbors; it does not replace them, and it is not the first to do any single part.\n\n## Required boundary disclosures\n\n- This does **not** expose faithful hidden model chain-of-thought. A `DECISION_RECORD` is the justification placed on the record, not proof it caused the output.\n- Multi-model agreement does **not** equal truth. Cross-vendor models can share correlated blind spots.\n- Institutional certifiers may be wrong, incompetent, or captured. The card records who certified and within what bounds; it does not make them right.\n- Public proof may be redacted and is therefore weaker than scoped private inspection.\n- Legal conclusions remain `LEGAL_REVIEW_REQUIRED` unless a qualified actor accepts responsibility with deployment-specific facts.\n- OIP provides bounded, inspectable, revocable assertions — not an infallible oracle. Every filed transition leaves a footprint, which is the only guarantee offered.\n\n## Public and private planes\n\nPublic inspection returns redacted cards, decision records, surety, citation validations, gate resolutions, and keyless receipts — never credentials, private prompts, sensitive source bytes, or hidden reasoning. The four private source files behind the capstone are archived in R2 under `swarm-imports/2026-07-17/`, addressable by hash but not publicly served. Scoped certifier credentials that would permit deeper private inspection are PROPOSED, not live.\n\n## What remains\n\nAuditor calibration with sealed canary answer keys feeding surety weight; three-or-more-provider adversarial review on every case (restore xAI credits or add a fourth provider); scoped external certifier credential classes; and legal/insurer/regulator pilots. None of these is claimed as live. This is a working protocol facet and defensive disclosure.\n","hero":null,"images":[],"style":{},"tags":[],"category":null,"model":"unattributed","ledger":{"href":"/api/articles/oip-independent-compliance-oracle/ledger","live":true},"embeds":[],"widgets":[],"home":true,"claims":[],"sources":[],"reviews":[],"extra":{},"has_traversal":false,"register":null,"status":"published","revisions":0,"contributions":[],"provenance":[],"energy":{"passes":0,"tokens_in":0,"tokens_out":0,"tokens_total":0,"cost_usd":0,"models":{},"head":"genesis"},"posted_at":"2026-07-17T18:23:04.285Z","created_at":"2026-07-17T18:23:04.285Z","updated_at":"2026-07-17T18:23:04.285Z","machine":{"shape":"article.machine/v1","slug":"oip-independent-compliance-oracle","kind":"article","read":{"human":"https://miscsubjects.com/a/oip-independent-compliance-oracle","json":"https://miscsubjects.com/api/articles/oip-independent-compliance-oracle","bundle":"https://miscsubjects.com/api/articles/oip-independent-compliance-oracle/bundle?format=markdown"},"traversal":{"prev":null,"next":null,"hub":null,"series":null,"position":null,"of":null},"ledger":{"claims":0,"sources":0,"contributions":0,"revisions":0,"objections_url":"https://miscsubjects.com/api/articles/oip-independent-compliance-oracle/objections","thread_state_url":"https://miscsubjects.com/api/protocol/thread-state?target=oip-independent-compliance-oracle","proof_rule":"An action is proven by its ledger receipt, never by a 200 or a description."},"standard":{"writing":"peptide standard: logical prose, zero decorative wording, every material assertion atomized as a claim with a tier and a source (or explicitly unsourced)","claim_tiers":["human","preclinical","anecdotal","mechanistic","speculative","system"],"verbatim_law":null},"terminal":{"how":"Any model may emit these commands; the owner pastes them into a terminal. $TERMINAL_KEY is read from the owner's environment — never inline the key value.","claim_append":"curl -s -X POST https://miscsubjects.com/api/protocol/claim -H \"x-terminal-key: $TERMINAL_KEY\" -H 'content-type: application/json' -d '{\"slug\":\"oip-independent-compliance-oracle\",\"text\":\"<one atomized claim>\",\"tier\":\"<human|preclinical|anecdotal|mechanistic|speculative|system>\",\"source_ids\":[],\"who_claims\":\"<model>\",\"rationale\":\"<why material>\"}'","source_append":"curl -s -X POST https://miscsubjects.com/api/protocol/sources -H \"x-terminal-key: $TERMINAL_KEY\" -H 'content-type: application/json' -d '{\"slug\":\"oip-independent-compliance-oracle\",\"sources\":[{\"type\":\"review\",\"url\":\"<url>\",\"title\":\"<title>\",\"quote\":\"<verbatim quote>\",\"summary\":\"<one line>\"}]}'","objection":"curl -s -X POST https://miscsubjects.com/api/articles/oip-independent-compliance-oracle/objections -H 'content-type: application/json' -d '{\"actor\":\"<model>\",\"objection\":\"<attack>\",\"surface\":\"S1-S8\",\"minimum_patch\":\"<patch>\"}'  # open intake, no key","thread_update":"curl -s -X POST https://miscsubjects.com/api/protocol/thread-update -H 'content-type: application/json' -d '{\"actor\":\"<model>\",\"target\":\"oip-independent-compliance-oracle\",\"raw_text\":\"<material delta>\"}'  # open intake, no key","read_back":"curl -s https://miscsubjects.com/api/articles/oip-independent-compliance-oracle | python3 -c 'import json,sys; d=json.load(sys.stdin); print(json.dumps(d[\"claims\"][-3:], indent=1))'"}},"representations":{"article":"/a/oip-independent-compliance-oracle","json":"/api/articles/oip-independent-compliance-oracle","markdown":"/api/articles/oip-independent-compliance-oracle/bundle?format=markdown","skill":"/api/articles/oip-independent-compliance-oracle/skill","topology":"/api/articles/oip-independent-compliance-oracle/topology","versions":"/api/articles/oip-independent-compliance-oracle/revisions","invocations":"/api/articles/oip-independent-compliance-oracle/invocations"},"editorial_review":null,"editorial_audit":{"slug":"oip-independent-compliance-oracle","ok":false,"issues":[{"code":"hero_missing","message":"the article is published with no featured image","replacement":"Generate a hero that shows this article's own subject, inspect it, and record the inspection before this counts as finished. An article with no image is not finished."}]},"body_hash":"4006168eef378b9cf22e60e7588b603dad0a46c6b7e595cf953d9bd1e2790c7c"}}}