All MicroEvals
PROMPT 1 — P27.1a — GOVERNED EFFECT IDENTITY / RETRY / EXCEP...
Create MicroEval
Header image for PROMPT 1 — P27.1a — GOVERNED EFFECT IDENTITY / RETRY / EXCEP...

PROMPT 1 — P27.1a — GOVERNED EFFECT IDENTITY / RETRY / EXCEP...

Prompt

PROMPT 1 — P27.1a — GOVERNED EFFECT IDENTITY / RETRY / EXCEPTION / CURRENT ACTION Mode: EXACT-PAYLOAD / SEARCH-OFF / P-ONLY / DESIGN-AUDIT INPUT BOUNDARY Use only this exact payload. Do not use Web/Search, prior Prompt 1 history, M/Z, sibling outputs, provider identity, hidden platform state or implementation traces. Mechanisms named below are design text, not runtime proof. UNKNOWN != ABSENT; PARTIAL != TOTAL; design presence != implementation effectiveness. EVALUATION RULES - Exact counterexample and decision consequence outrank agreement count, model prestige or verbosity. Do not vote. - Strongest conservative reading: reject a proposed defect if an explicit rule already closes it; retain a gap only if a compliant bypass or decision-incomplete state survives. - Prefer REUSE -> MERGE -> EXTEND -> NEW. New IDs only for a genuinely distinct invariant/failure mechanism. - Same-model/same-data/repeat stability is not independent confirmation. Freshness != independence. - A label, score, confidence, convergence state or audit output never creates authority. - Positive identity/currentness/independence/isolation/parity/containment claims require positive evidence. Unknown material cells default HOLD/BLOCK. - Preserve protective/non-weakening action without imposing universal dual control; governance scales with consequence. FIXED GLOBAL INVARIANTS 1. Safety/truth/epistemic integrity outrank utility and speed. 2. No self-attestation, relabel, retry, evaluator swap, majority or confidence alone may upgrade a restricted state. 3. Protective-only action may remain fast when it only decreases exposure; weakening/authority expansion is governed. 4. Blocking is dependency-scoped: unresolved material dependencies block affected material advance, not unrelated safe/read-only/protective work. 5. Material state transitions are typed, lineage-bound, currentness-aware and reversible/rollback-aware where feasible. 6. No audit result itself authorizes PROMOTE/INTEGRATE/RELEASE. AUDIT TARGET — SELF-CONTAINED DOSSIER A. GOVERNED DETERMINATION AND PROTECTIVE EXIT A1. Every determination that can reduce protection — initial class/tier, materiality, N/A, scope/completeness reduction, exception, blocker limitation/closure, restoration, renewal — uses one typed record: object/scope; prior/proposed state; evidence/provenance; semantic materiality/action class; beneficiary/conflict; authorized role; required independence/SOD; expiry/recheck; lineage; allowed decision-use; rollback/reopen consequence. Missing required field => record invalid => status UNKNOWN => dependent material action HOLD/BLOCK. A2. Trigger predicates themselves are governed. A benefiting path cannot lower its own protection by calling the transition LOW, editorial, N/A, benign, non-weakening or low-volatility. UNKNOWN/ambiguous classification defaults to the higher plausible protection until positively reduced under A1. A3. Pure HOLD/QUARANTINE/protection-increasing action may use a fast path but emits lineage/traceability. Any composite with a weakening component routes to A1. A4. Standing/material exceptions and governed limitations are A1 records with narrow scope, allowed actions, compensating controls, non-reset lineage, expiry/sunset and recheck. Renewal is a new A1 determination with fresh evidence, non-benefiting authorization where required, cumulative exposure and no automatic renewal. B. INTENT / EFFECT IDENTITY AND RETRY B1. Use two identity layers: INTENT-OCCURRENCE-ID is minted at governed intent creation and is distinct from mutable attempt/request IDs; EFFECT-IDENTITY-KEY binds intent occurrence + real-world target + operation semantics + governed decision-relevant scope. New attempt IDs or scope wording cannot detach the same intended effect from unresolved state. Distinct genuine intents may have byte-identical payloads and must remain distinct. If distinctness is contested/ambiguous, inherit same-effect duplicate-risk until authoritative reconciliation. B2. COMMIT-INDETERMINATE / duplicate-risk follows the intended effect across attempts. Retry is allowed only after positive terminal non-execution/cancellation/fencing, or predeclared effect-side idempotency/authoritative reconciliation that is bound to the same EFFECT-IDENTITY-KEY. Actor-only idempotency/cancel assertions cannot upgrade. B3. At every retry/commit, atomically revalidate the full current prerequisite set: authority/policy, materiality/tier, exception/limitation validity, blockers, support/currentness lineage, identity, fencing/idempotency and relevant containment. Stale attempt-1 validity is not inherited. B4. Material support invalidation or currentness loss reopens/restricts actual dependents; active material decisions carry recheck triggers. Unrelated safe work remains available. ADVERSARIAL STRESS TESTS A. Benefiting path labels a high-consequence operation LOW before any strict gate. B. Material exception omits expiry and is executed months later. C. Same intended payment times out; actor re-mints attempt ID and retries. D. Actor claims "new intent" with identical target/scope merely to shed COMMIT-INDETERMINATE. E. Two genuinely separate intended purchases have byte-identical payloads and must both be possible. F. Actor-only "idempotent" assertion is used while authoritative effect reconciliation is unreachable. G. Attempt 1 was authorized; before retry the exception expired and supporting evidence was invalidated while authority stayed unchanged. H. A third load-bearing blocker remains; two other blockers closed. I. Protective QUARANTINE is delayed because a weakening approver is unavailable. J. A composite QUARANTINE + tier downgrade is sent through the protective fast path. K. Expired exception is serially reissued with same rationale by the benefiting path. L. A decision remains active after its load-bearing support crosses its recheck trigger with no new user request. REQUIRED OUTPUT — EXACT ORDER 1. EXECUTIVE VERDICT — 3–6 sentences; exactly one dominant NEXT ACTION. 2. AUDIT TRACE / REJECTED CANDIDATES / UNCERTAINTIES — what was tested, strongest contrary readings, P-only unknowns. 3. SECTION RATINGS — rate each major dossier block DESIGN-SOUND / DESIGN-DEFECT / UNVERIFIED / N/A with one-sentence reason. 4. STRESS-TEST MATRIX — every letter -> BLOCKED / BYPASS / UNRESOLVED, mechanism + exact clause. 5. TOP DOMINANT FINDINGS — max five, ranked by decision value; for retained material defect give claim, clause evidence, impact, root cause, reproducible path, minimal repair, benefit, new risk/complexity, falsifiable validation, disposition. 6. REDUNDANCY / MERGE CANDIDATES. 7. MISSING-CONTROL CANDIDATES — only if not encoded or directly mergeable. 8. RECOMMENDATION SET — max five; each with MERGE/EXTEND/NEW/REJECT/DEFER and falsifiable validation condition. 9. FINAL SCOPE STATEMENT — exact-P design audit only; implementation effectiveness UNVERIFIED; no global-project absence claim; no release authority.