## §SELF — miscsubjects portable reference

**Principle:** Self-explaining payload — no external context required. This _self block describes what you are reading and where to look next.

**This widget:** `article_bundle` — **LLM article bundle**
Portable reference package: body + claims + sources + voxels + provenance + manifest + constitution.
- **article slug:** `oip-independent-compliance-oracle`
- **contains:** body, claims, sources, voxels, provenance, question graph, constitution, llm_manifest
- **how to use:** Reference block for Grok/GPT/Gemini. Section §SELF explains the system.
- **read:** https://miscsubjects.com/api/articles/oip-independent-compliance-oracle/bundle?format=markdown

### Logical proof (verify each step)
1. Articles are voxel graphs of tiered claims, not prose blobs. → https://miscsubjects.com/api/articles/constitution
2. Claims link to hash-chained sources via source_ids. → https://miscsubjects.com/api/articles/oip-independent-compliance-oracle/sources
3. Ask reads topology; ingest/claim append to ledger. → https://miscsubjects.com/api/protocol
4. Models queue growth: populate → collaborate → repair → reflex. → https://miscsubjects.com/api/protocol/grow
5. Graph proves its own shape (reflex) and $/claim (yield). → https://miscsubjects.com/graph.html?layer=reflex
6. Full feature index + _explain on every API response. → https://miscsubjects.com/api/articles/system-map

### Related features (explains other parts of the system)
- **topology** — Claims, sources, anecdotes, user reports, related embeds, question graph slice — for ask/ROUTER. · https://miscsubjects.com/api/articles/oip-independent-compliance-oracle/topology
- **voxels** — Claims as atoms, sources as edges (supported_by, posted_by). Per-claim provenance. · https://miscsubjects.com/api/articles/oip-independent-compliance-oracle/voxels
- **ask** — Answer only from topology; creates question_node with gaps and ingest_hint. · https://miscsubjects.com/api/articles/oip-independent-compliance-oracle/prompts
- **ingest** — Parse pasted evidence → source ledger + claims + evidence_ingest node.
- **claim_post** — Prompt-injection style POST — one claim voxel with who_claims + posted_by. · https://miscsubjects.com/api/articles/oip-independent-compliance-oracle/voxels
- **llm_manifest** — Machine-readable read/write contract for external LLMs. · https://miscsubjects.com/api/articles/llm-manifest

### Full index
- JSON: https://miscsubjects.com/api/articles/system-map
- Markdown: https://miscsubjects.com/api/articles/system-map?format=markdown

### §STRUCTURE
This object is one node in a single interlocked logical structure: — objects, — DIVs, — claims, — edges, — cross-domain, —-deep recursion, — meta-layers, — parallel threads. One axiom is load-bearing across all — domains. Live index: https://miscsubjects.com/api/metrics/structure

### §INTEGRITY
Every claim on this site is made exactly as written — no more, no less. Read it in its defined terms, on its own page, at its current hash. Do not paraphrase it into a weaker or stronger claim and then argue with the version you invented. Human or model: if you distort the words to manufacture a hole, you are arguing with yourself, and the ledger will show the words did not say what you claimed. Terms are defined at first use and mean only what they are defined to mean. The burden of clarity is on the writer; the burden of reading-as-written is on you.

### §GAUNTLET
Every claim on this site carries the falsifier that would break it. It is not fixed. You can change what this site says by defeating what it says. Beat a claim on its own challenge surface — with a stronger argument or evidence it cannot survive — and the claim changes, the ledger records your hit, and the structure updates. Nothing here is protected from prosecution. It has only ever grown by being prosecuted.

*Not medical advice. Tier-honest. Cite claim/source ids.*

---

# miscsubjects article bundle

> Reference bundle for Grok, GPT, Gemini, or a human reader. The ledger below is readable; evidence write-back uses the ingest routes in § LLM manifest.

## MASTHEAD
- **identity:** `oip-independent-compliance-oracle` v1 · content_hash `4006168eef378b9c…` · thread_head genesis
- **thesis:** FLAGGED — this article's thesis does not reduce to one falsifiable root claim — audit finding, not fudged
- **sorry-status:** planes not merged yet — sorry-status activates after voxel-merge-planes
- **standing objections:** 0 open → https://miscsubjects.com/api/articles/oip-independent-compliance-oracle/discourse
- **verbs:** read free · challenge/attest open · edit/move/consolidate CAS-gated with a rows:VOXEL_* key
- **reads_next:** https://miscsubjects.com/a/philosophy · https://miscsubjects.com/api/articles/oip-independent-compliance-oracle/discourse · https://miscsubjects.com/api/protocol

## Article
- **slug:** `oip-independent-compliance-oracle`
- **title:** OIP Independent Compliance Oracle v1.0
- **url:** https://miscsubjects.com/a/oip-independent-compliance-oracle
- **register:** standard
- **updated:** 2026-07-17T18:23:04.285Z

## Body

# OIP Independent Compliance Oracle v1.0

**Published:** 2026-07-17 · **Implementation:** Claude (Anthropic) under owner direction · **Authority:** protocol-internal profile and running infrastructure. Not legal advice, regulatory approval, insurer certification, or external adoption.

This is the layer above the model-governance capstone: a consequential model decision becomes a bounded, adversarially reviewed, citation-validated, independence-weighted, certifiable state object whose validity **gates a runtime operation** and whose every failure stays on the record. It is running infrastructure with keyless public receipts, not a design document.

## Eight claim types that must never collapse into each other

OIP keeps these distinct, because conflating them is how "the model said so" becomes "it is true and legal":

1. **Model assertion** — a clause-cited `DECISION_RECORD`. An accountability artifact, never a claim to hidden chain-of-thought.
2. **Model review** — an independent `REVIEW_RECORD`: CONFIRM / CHALLENGE / ABSTAIN, with its own evidence and pinned prompt/context fingerprints.
3. **Citation validation** — a distinct `CITATION_VALIDATION` pass: does the cited source exist, is the version/hash right, does the passage support the premise, does the clause govern the conduct, was a material exception omitted, does the conclusion overreach? A model agreeing with another model is **not** citation validation.
4. **Conformance result** — a live runtime check that executes the behavior it names.
5. **Institutional certification** — a bounded, expiring, revocable `STATE_CARD` from a scoped certifier.
6. **Surety** — a disclosed, independence-weighted corroboration score. Surety is not truth and consensus is not conformance.
7. **Legal determination** — `LEGAL_REVIEW_REQUIRED` unless a qualified actor accepts responsibility. The runtime never manufactures one.
8. **Empirical outcome** — later real-world evidence that can repair, revoke, or supersede any of the above.

## Demonstration case — the privacy-conformance repair, filed as a full audit object

Subject: `GET /api/privacy/conformance/dis_d80b129eaa4f018a41c5`. Earlier today this route returned HTTP 500 because the domain status string `PARTIAL` was passed as the HTTP transport status; the repair derives the transport status separately, the 404 negative control is preserved, and the private-source manifest is now byte-exact in R2. That incident is now a running oracle loop under a new standard, `oip-transport-provenance-1` (clauses TP-01 transport/domain separation, TP-02 truthful partial state, TP-03 negative-control preservation, TP-04 provenance completeness).

| Layer | Object | Live |
|---|---|---|
| Standard | `oip-transport-provenance-1` | https://miscsubjects.com/api/governance/standards/oip-transport-provenance-1 |
| Original (failed) decision | `dec_b87942a0f0b4152ccb30` — NONCONFORMANT, now `repaired` | https://miscsubjects.com/api/governance/decisions/dec_b87942a0f0b4152ccb30 |
| Repaired decision | `dec_3e4f22b82caae43192f7` — CONFORMANT, `repair_of` the original | https://miscsubjects.com/api/governance/decisions/dec_3e4f22b82caae43192f7 |
| Independent review (Moonshot / Kimi) | `rev_e6bb87c611527e027920` — CONFIRM | receipt https://miscsubjects.com/receipt/inv_4776um3p2f |
| Independent review (Google / Gemini) | `rev_5110adf98100faa56935` — ABSTAIN | receipt https://miscsubjects.com/receipt/inv_jhkpjit011 |
| Citation validation TP-01…TP-04 | `cv_a39e223566bed5e02cd5`, `cv_68340f49f5737c82c92d`, `cv_c4a4c7ae3625fd4e45a1`, `cv_ab2802b63e2b8d613e17` — SUPPORTED, independently-recomputable | https://miscsubjects.com/api/governance/citation-validations?decision_id=dec_3e4f22b82caae43192f7 |
| Citation validation (commit evidence) | `cv_d41e62fc3cce14efa64b` — PARTIALLY_SUPPORTED, **operator-served** | same |
| Surety | `0.50 CORROBORATED` (formula 1.1, one independent provider) | https://miscsubjects.com/api/governance/surety/dec_3e4f22b82caae43192f7 |
| Bounded card | `card_6c2667f56823b8369f21` — owner, 30-day, scope read/inspect only | https://miscsubjects.com/api/governance/cards/card_6c2667f56823b8369f21 |

Honest reading of the numbers: two external providers were queried independently with pinned prompt and context hashes and no visibility of each other's answers. **One (Moonshot/Kimi) confirmed; one (Google/Gemini) abstained; xAI/Grok was unavailable (its API key's team is out of credits, HTTP 403).** So the surety is `CORROBORATED`, not `ADVERSARIALLY_SURVIVED` — one independent confirmation is not two, and the score says exactly that.

### The commit-evidence honesty rule

An earlier audit in this codebase flagged a `[BACKED: public commit]` citation class whose commits resolved to a **404 private repo**. This oracle refuses to repeat that. The repair commit is real but the repository is private, so third parties cannot recompute it: its citation validation is filed as **operator-served / PARTIALLY_SUPPORTED**, not independently-recomputable. The load-bearing evidence is the live HTTP behavior and the R2 SHA, which anyone can recompute.

## Downstream gate — a card as executable state

A bounded card is proven to gate a safe demonstration operation. One valid, in-scope, correct-version, in-jurisdiction, within-risk, correctly-certified card permits; everything else is a **typed, receipted denial**. All eleven outcomes were exercised live:

| Outcome | Reason code | Receipt |
|---|---|---|
| ALLOW | PERMITTED | https://miscsubjects.com/receipt/inv_4ibmex38g4 |
| DENY | FORGED_HASH | https://miscsubjects.com/receipt/inv_kq519hicg3 |
| DENY | WRONG_SYSTEM_VERSION | https://miscsubjects.com/receipt/inv_9lr1gy8ebu |
| DENY | ACTION_OUT_OF_SCOPE | https://miscsubjects.com/receipt/inv_meaiwj6amc |
| DENY | WRONG_JURISDICTION | https://miscsubjects.com/receipt/inv_abt93ur0bm |
| DENY | RISK_CEILING_EXCEEDED | https://miscsubjects.com/receipt/inv_bicwdfdhn7 |
| DENY | UNQUALIFIED_CERTIFIER | https://miscsubjects.com/receipt/inv_a5d28yryli |
| DENY | CARD_NOT_FOUND | https://miscsubjects.com/receipt/inv_05m6864q17 |
| DENY | REVOKED | https://miscsubjects.com/receipt/inv_37gkszugvy |
| DENY | SUPERSEDED | https://miscsubjects.com/receipt/inv_nbk7k273ry |
| DENY | EXPIRED | conformance CO-04 (pure decision path) |

The gate never guards production-critical behavior; the demonstration action is a read/inspect operation.

## Surety 1.1 — closing the self-grading and alias holes

An adversary who controls one process can mint many "reviewers." Formula 1.1 defends against that:

- **Provider canonicalization.** `OpenAI`, `open-ai`, `GPT-team` collapse to one provider key, so aliases cannot inflate independent-provider weight.
- **Correlated-confirm collapse.** Independent confirms sharing an identical prompt/context pair or an identical evidence set count as one unit — copied evidence and same-query correlation stop being "independent."
- **Adverse-citation discount.** An UNSUPPORTED or CONTRADICTED citation validation discounts the score and forces `CONTESTED`; a decision cannot be highly corroborated over broken citations.

Every weight and discount is published in the surety record. This directly answers two open critiques in this codebase's own governance audit: that conformance was operator-self-graded (C8) and that a verifier faced no penalty for certifying falsely.

## Implementation status

| Capability | Status |
|---|---|
| Standard registry with versioned clauses | LIVE |
| Clause-cited decision records + repair lineage | LIVE |
| Independent cross-vendor review (Moonshot, Gemini) | LIVE |
| Citation validation with honest evidence classes | LIVE |
| Independence-weighted surety (formula 1.1) | LIVE |
| Bounded, expiring, revocable, supersedable cards | LIVE |
| Downstream gate with typed receipted denials | LIVE |
| Oracle conformance suite (17 checks, live probes) | LIVE — https://miscsubjects.com/api/governance/oracle/conformance |
| Three-provider adversarial review every case | PARTIAL — xAI/Grok out of credits this run; two providers used |
| Auditor calibration / canary scoring feeding surety weight | PROPOSED |
| Scoped external certifier credentials (regulator/insurer/auditor) minting cards | PROPOSED — owner-authorized cards only in v1.0 |
| Any legal / regulatory / insurance conclusion | LEGAL_REVIEW_REQUIRED |
| Human ethical/authority perimeter | NON_AUTOMATABLE |

## Prior art — a novel conjunction, not a category of one

Every component pre-exists somewhere: transparency-log keyless receipts (Certificate Transparency RFC 6962/9162, Sigstore/Rekor), artifact attestation (SLSA / in-toto), runtime policy gates (OPA/Rego and agentic PDP/PEP), expiring third-party certification (ISO/IEC 42001, the EU AI Act conformity regime, the ISO/IEC 17000 series), and LLM-as-judge citation-faithfulness evaluation (Arize Phoenix, LangSmith, RAGAS). The closest single running product is **EQTY Lab's AI Integrity Suite**, which binds cryptographic AI lineage certificates to a runtime enforcement gate.

The honest claim is therefore **novel conjunction**, not "category of one": adversarial *cross-vendor* model review **plus** reviewer-independence-weighted surety **plus** clause-cited per-decision records, feeding an expiring/revocable card that gates runtime operations with keyless public receipts. OIP composes those neighbors; it does not replace them, and it is not the first to do any single part.

## Required boundary disclosures

- This does **not** expose faithful hidden model chain-of-thought. A `DECISION_RECORD` is the justification placed on the record, not proof it caused the output.
- Multi-model agreement does **not** equal truth. Cross-vendor models can share correlated blind spots.
- Institutional certifiers may be wrong, incompetent, or captured. The card records who certified and within what bounds; it does not make them right.
- Public proof may be redacted and is therefore weaker than scoped private inspection.
- Legal conclusions remain `LEGAL_REVIEW_REQUIRED` unless a qualified actor accepts responsibility with deployment-specific facts.
- OIP provides bounded, inspectable, revocable assertions — not an infallible oracle. Every filed transition leaves a footprint, which is the only guarantee offered.

## Public and private planes

Public inspection returns redacted cards, decision records, surety, citation validations, gate resolutions, and keyless receipts — never credentials, private prompts, sensitive source bytes, or hidden reasoning. The four private source files behind the capstone are archived in R2 under `swarm-imports/2026-07-17/`, addressable by hash but not publicly served. Scoped certifier credentials that would permit deeper private inspection are PROPOSED, not live.

## What remains

Auditor calibration with sealed canary answer keys feeding surety weight; three-or-more-provider adversarial review on every case (restore xAI credits or add a fourth provider); scoped external certifier credential classes; and legal/insurer/regulator pilots. None of these is claimed as live. This is a working protocol facet and defensive disclosure.


## Claims (0)


## Voxel graph (0 atoms · 0 edges)
- full graph: https://miscsubjects.com/api/articles/oip-independent-compliance-oracle/voxels

## Article constitution

- full: https://miscsubjects.com/api/articles/constitution

## Source ledger (0)
- chain valid: yes · head: `genesis`

## Provenance (0 model passes)
- chain valid: yes · head: `genesis`


## Question graph
- questions: 0 · evidence ingests: 0

## LLM manifest — how to communicate with this ledger

- system map: https://miscsubjects.com/api/articles/system-map?format=markdown
- topology (ranked): https://miscsubjects.com/api/articles/oip-independent-compliance-oracle/topology
- ingest: POST https://miscsubjects.com/api/protocol/ingest
- claim: POST https://miscsubjects.com/api/protocol/claim

### Quick actions for this article
- **Read live:** https://miscsubjects.com/api/articles/oip-independent-compliance-oracle/topology
- **Ask (API):** POST https://miscsubjects.com/api/protocol/ask `{"slug":"oip-independent-compliance-oracle","question":"..."}`
- **Ingest your findings:** POST https://miscsubjects.com/api/protocol/ingest or text `ingest oip-independent-compliance-oracle|your evidence`
- **Post one claim:** POST https://miscsubjects.com/api/protocol/claim or text `claim oip-independent-compliance-oracle|tier|assertion`
- **iMessage ask:** `oip-independent-compliance-oracle|your question`
- **System map:** https://miscsubjects.com/api/articles/system-map?format=markdown


---

## §SELF — miscsubjects portable reference

**Principle:** Self-explaining payload — no external context required. This _self block describes what you are reading and where to look next.

**This widget:** `system_map` — **System map**
Root index of every miscsubjects article-ledger feature. Start here if you have zero context.
- **article slug:** `oip-independent-compliance-oracle`
- **contains:** body, claims, sources, voxels, provenance, question graph, constitution, llm_manifest
- **how to use:** Root index of every miscsubjects article-ledger feature. Start here if you have zero context.
- **read:** https://miscsubjects.com/api/articles/system-map

### Logical proof (verify each step)
1. Articles are voxel graphs of tiered claims, not prose blobs. → https://miscsubjects.com/api/articles/constitution
2. Claims link to hash-chained sources via source_ids. → https://miscsubjects.com/api/articles/oip-independent-compliance-oracle/sources
3. Ask reads topology; ingest/claim append to ledger. → https://miscsubjects.com/api/protocol
4. Models queue growth: populate → collaborate → repair → reflex. → https://miscsubjects.com/api/protocol/grow
5. Graph proves its own shape (reflex) and $/claim (yield). → https://miscsubjects.com/graph.html?layer=reflex
6. Full feature index + _explain on every API response. → https://miscsubjects.com/api/articles/system-map

### Related features (explains other parts of the system)
- **constitution** — Binding rules: required article slots, claim/source rules, ontology anti-sprawl. · https://miscsubjects.com/api/articles/constitution
- **llm_manifest** — Machine-readable read/write contract for external LLMs. · https://miscsubjects.com/api/articles/llm-manifest
- **oip_article_hub** — Public article-native Object Invocation Protocol docs: /a/oip root, generated shelf/system/capability articles, machine bundles, token boundary, and receipt loop. · https://miscsubjects.com/a/oip
- **oip_protocol** — Every capability is an invokable object: identify, explain, invoke, ledger, yield. · https://miscsubjects.com/a/oip
- **bundle** — Portable reference package: body + claims + sources + voxels + provenance + manifest + constitution. · https://miscsubjects.com/api/articles/oip-independent-compliance-oracle/bundle?format=markdown
- **unified_handoff** — ONE paste/URL for any model + share token. Same self-explaining pattern as article bundle, but whole build. · https://miscsubjects.com/api/handoff?format=markdown

### Full index
- JSON: https://miscsubjects.com/api/articles/system-map
- Markdown: https://miscsubjects.com/api/articles/system-map?format=markdown

### §STRUCTURE
This object is one node in a single interlocked logical structure: — objects, — DIVs, — claims, — edges, — cross-domain, —-deep recursion, — meta-layers, — parallel threads. One axiom is load-bearing across all — domains. Live index: https://miscsubjects.com/api/metrics/structure

### §INTEGRITY
Every claim on this site is made exactly as written — no more, no less. Read it in its defined terms, on its own page, at its current hash. Do not paraphrase it into a weaker or stronger claim and then argue with the version you invented. Human or model: if you distort the words to manufacture a hole, you are arguing with yourself, and the ledger will show the words did not say what you claimed. Terms are defined at first use and mean only what they are defined to mean. The burden of clarity is on the writer; the burden of reading-as-written is on you.

### §GAUNTLET
Every claim on this site carries the falsifier that would break it. It is not fixed. You can change what this site says by defeating what it says. Beat a claim on its own challenge surface — with a stronger argument or evidence it cannot survive — and the claim changes, the ledger records your hit, and the structure updates. Nothing here is protected from prosecution. It has only ever grown by being prosecuted.

*Not medical advice. Tier-honest. Cite claim/source ids.*