Public Review CandidateBuild 15 · SIW / Canon Reader integrationReview guidenoindex · review deployment
Build 14.2 · public-review reconciliation & attack-surface conformance surface

What the specification requires. What the website actually implements.

This matrix compares the Genesis AiX Public Web & Knowledge Architecture v0.1 with the Build 14.1 public-review hardening candidate. It is an implementation-status surface, not a claim that unfinished architecture or future work is complete.

Public-review maturity disciplineThese labels describe implementation/evidence maturity, not Canon standing or SIW lifecycle standing. Specified means defined in an architecture or control record. Implemented means observable behavior or content exists in the candidate. Tested means defined checks have passed within the stated profile. Independently Reviewed means an external or separately assigned review has examined the stated criterion; it does not itself create authority. Partial means some requirement is present but incomplete. Experimental means bounded behavior exists without a production-capability claim. Planned and Open Specification are not current capability.
“Verified” is always scoped. A verified claim must identify what was checked, against which criterion or record, by which method, and within what profile or boundary. The word does not mean globally true, authoritative, production-ready, operational, or currently authorized unless those separate claims are independently established.
Specification conformance

Current implementation and remaining gaps.

Build 14 carries forward the frozen Build 13 review baseline and the August 18 independent architecture review as a review input while preserving findings that still require implementation evidence rather than converting them into claims.

Specification areaBuild 14 statusCurrent implementationGap / review boundaryNext milestone
Genesis AiX ecosystem identityPARTIALShared shell, design grammar, Genesis/SIW/Knowledge/Governance/Research grouping.Parent ecosystem and Canon-facing surfaces are still maturing.Continue one-ecosystem navigation without creating new microsite islands.
Homepage / first viewIMPLEMENTEDPlain-language definition, why-it-matters statement, architecture route, maturity qualifier.Independent review A-04 found design-versus-running ambiguity in 12.5a.Build 12.6 adds an explicit public-architecture / not-operational-control-plane qualifier.
Knowledge Explorer — TreeIMPLEMENTEDTree, context panel, structured search, URL state, keyboard traversal, lineage records.Prototype dataset remains smaller than the intended Knowledge Fabric.Expand governed dataset and object metadata without changing Explorer behavior gratuitously.
Multi-view ExplorerPARTIALTree plus alternate representation foundations and controlled 3D handoff.Tree / Map / 3D / Lineage / Evidence / Chronology are not yet one fully synchronized representation family.Preserve selected object across representation switches; add Chronology and Evidence depth.
3D navigationOPENHistorical Navigator remains reachable through a controlled wrapper.Historical Manus dependency and unfinished chat control prevent current-runtime presentation.Recover, self-host, and separately validate before promotion from historical/prototype status.
Governance lineageRECONCILEDBuild 12.6 separates historical chronology from conceptual relationship and runtime dependency.Review A-03 found 12.5a packet/site ordering conflict.Keep chronology, conceptual layering, and mandatory dependency as separate relationship types.
Governance educationPARTIALPolicy / observation / evidence / governance distinctions, standing, binding, revalidation.Review E-01 showed that “evidence is not authority” was too compressed.Use freshness, authoritative source, scope match, and current standing language.
Execution boundary claimsREVIEWArchitecture explains bind-time standing, executor, refusal, replay and substitution.B-01/C-01/D-01 require stronger distinction among bind authority, ambient executor ability, deployment route closure, and post-bind irreversibility.Require declared executor/credential model, route inventory, residual-path disclosure, and consequence-class irreversibility horizon in proof profiles.
Exact consequence / materialityREVIEWCurrent architecture binds actor, parameters, target, context, route, executor, state and validity.B-02/B-03: the real boundary is a finite decision-relevant attribute projection; “material” must have a declared adjudication rule.Publish the declared attribute projection in each proof profile rather than implying a world-state hash.
Proof & EvidencePARTIALBounded proof structure, WEDGE/adapter wrappers, Interop Lab evidence framing.Not every public proof yet exposes the full declared route inventory, executor model, attributes, exclusions and reproduction package.Normalize proof pages to one evidence schema and add provenance labels.
Library / document metadataPARTIALLibrary cards, document reader, status and relationship concepts.Not every artifact carries full identity, version, authority, lineage, source and evidence metadata.Promote the Library from document links to governed artifact catalog.
Genesis Knowledge Fabric™NEW SURFACEBuild 12.6 adds a dedicated architectural surface connecting Canon, Explorer, Library, lineage, evidence and representations.The full passage → depth view → exact return interaction is not yet implemented.Build one complete Canon reading/depth/return loop as the next interaction milestone.
Federated SDIARCHITECTUREBuild 12.6 adds a bounded research/architecture surface: signed purpose-limited claims may compose; raw memory, latent state and authority do not.No universal safety or production federation claim is made.Define an Interop Lab profile for evidence composition without authority transfer.
LexiconRECONCILEDOne public lexicon now includes the site terms plus admissibility, bind-time, exact consequence, executor binding, route closure, authorization replay, composition without absorption and related review-critical terms.Review G-04 found the packet and public site used different vocabularies.Future review packets should cite the same lexicon.
Navigation loadREDUCEDPrimary navigation now prioritizes four SIW, four Knowledge, four Governance/Proof, two Research and three Build destinations; deeper tools remain contextual.G-05 found approximately 24 destinations competing at equal weight in 12.5a.Measure first-time visitor orientation before adding another top-level item.
Accessibility / mediaPARTIALLight/Medium/Dark, strong contrast, keyboard support, no-JS shell, accessible media hooks.Verified captions/transcripts for inherited videos remain open.Complete caption/transcript assets and hosted desktop/mobile accessibility pass.
Patent / IP provenanceNEW SURFACEBuild 12.6 separates patent filings, claimed marks, copyrightable works and unresolved registration work.Trademark clearance/registration and copyright registration are separate legal workflows.Maintain a governed IP register and update only from verified filing/registration evidence.
Build identityCORRECTEDOne active Build 14 CSS file; previous CSS generations remain preserved as provenance artifacts and are not loaded.E-05 found four active CSS generations in 12.5a.Keep one active presentation bundle per future build.
Independent witness / reproducibilityPARTIALBuild 12.6 creates a digest-attested static snapshot and per-file manifest.M-01 requested an independently witnessable signed snapshot; cryptographic external signature and post-deploy cache tests remain open.Publish snapshot + digest; then run cache-busting determinism test and add external signature/witness.
Source specification

The matrix does not replace the specification.

The controlling design target remains Genesis AiX Public Web & Knowledge Architecture v0.1. This page reports implementation against it; it does not silently revise its authority or scope.

Open the specification →
Independent review reconciliation

Sharon Hart Build 14 audit — public-hardening disposition.

The review identified 75 observations and failure modes. They are being reconciled against existing Genesis/SIW controls rather than treated as 75 automatically established architecture defects.

Working public-hardening target: approximately 52 of 75 observations are expected to be directly corrected, materially clarified, or reconciled against existing evidence across the two public-hardening builds. The remainder stay visible as open specification or implementation work. No finding is silently converted into authority or silently dismissed.
Review area Current disposition Public-review action Remaining work
Human initiation versus authorization HARDENING Public language now states that directing an inquiry does not confer authority. Continue adversarial transition testing.
Acceptance versus authorization / binding PARTIAL / EXISTING CONTROL Expose the semantic boundary more clearly across public SIW surfaces. Regression and state-transition attack matrix.
Profile proficiency versus authority HARDENING Guided / Explorer / Advanced are now explicitly authority-neutral experience-depth modes. Verify all UI behavior remains authority-neutral.
Reviewer identity and feedback standing HARDENING Open review is described honestly; feedback is review material, not governed authority. Formal governed-review provenance model remains open.
Implementation-status claim boundaries HARDENING Separate Specified / Implemented / Tested / Independently Reviewed / Partial / Experimental / Open Specification. Continue evidence mapping in Build 14.2.
Policy precedence OPEN SPECIFICATION Do not imply the problem is solved. Separate architecture disposition required.
Decision as a governed first-class object OPEN SPECIFICATION Record as a serious review finding rather than rush an implementation. Specification and independent review required.
Consent / delegation / jurisdiction / revocation model OPEN / PARTIAL Preserve existing standing/revalidation claims without overstating completeness. Full actor/authority model requires separate work.
Uncertainty, search provenance, confirmation-bias controls OPEN / PARTIAL Expose existing provenance boundaries and preserve open status. Build 14.2 adversarial/evidence surface plus later specification work.

Important: public-review maturity labels are descriptive evidence claims only. They do not replace governance standing, temporal currentness, resolution outcome, authorization state, or Canon admission state.

Build 15 · integration convergence status

Where we were. Where we are. Where we should be.

This section reports the actual state of the Book One / Canon Access / Reader / SIW / Composer / Gateway convergence effort as of the local Build 15 integration candidate (genesis-aix-build15-site, branch build15-integration-001). It uses the same maturity discipline as the rest of this page: specified ≠ implemented ≠ proven ≠ integrated ≠ locally preflighted ≠ publicly deployed. "Proven" means a bounded conformance suite or live browser check passed. "Integrated" means the proven component is actually wired into this local candidate, not merely available as a separate proof repository. "Locally preflighted" means it has been exercised in a real local browser session against this candidate. None of the rows below claim public deployment — see the explicit no-deployment statement at the end of this section.

AreaWhere we wereWhere we areWhere we should be
SIW R2 vs R3SIW R2 established and preserved as the accepted reference source; no lawful runtime consumption of it existed yet.PROVEN / INTEGRATED / LOCALLY PREFLIGHTED SIW R3 canonical-reference semantics are a genuine out-of-tree derivation from the real SIW R2 source (siw-r3-canon-reference-binding-proof @ a680af0, 25/25 CRB), ported into 8812's Reader (bf380845), and live-verified inside this Build 15 candidate.A dedicated SIW R3 UI surface beyond the embedded Reader panel; production transport for the same seam.
Canon Access / Client Contract/object resolved identity/standing only; narrative content depended on a dev-only filesystem route, never a governed seam.PROVEN / INTEGRATED / LOCALLY PREFLIGHTED Governed GET /representation seam (canon-contract-foundation @ ea61472, RC-01..10 10/10 PASS) is what this candidate's Reader actually uses for narrative content — the dev-filesystem route has been removed, not just deprioritized.Production HTTPS transport for both /object and /representation — a separate, not-yet-established Tab 2 track; this local candidate does not claim it exists.
Book One (12 chapters)Manuscript source only; no chapter resolved through a governed read path.PROVEN / INTEGRATED / LOCALLY PREFLIGHTED Book One Chapters 1–12 are accessible in this local Build 15 candidate through Canon Access: governed identity/state resolves via /object, and governed representation content resolves via GET /representation (12/12 equivalence matrix across Reference Client / Reader path / SIW nugget; RC-10 byte-verified all 12 narrative files). The Reader/SIW surface preserves the same qualified object throughout. Every chapter remains COMPLETION_CANDIDATE / NO_CANON_STANDING at all times — this local website integration does not imply Canon admission and is not a public deployment.Public review once production transport exists; no chapter content is bundled/hardcoded anywhere in this candidate today.
Reader / Canon Tree / 3D / 8812 Three-PanelSeparate historical prototype tracks (Tree, 3D Navigator) and a standalone 8812 successor with no site integration.PARTIAL — READER INTEGRATED VIA A DISCLOSED LOCAL WORKAROUND; TREE PARTIALLY CONVERGED 8812's Three-Panel Reader is embedded in this candidate (/reader/) via a dedicated local runtime + iframe — a local-development-only mechanism, disclosed on the page itself, because 8812's client-side router has no configurable base path (a recorded, 8812-owned defect, not fixed here). Knowledge Explorer's tree (siw/explorer.html) now resolves the same 12 Book One chapter objects live through Canon Access (GET /object, fail-closed, no fallback data) and renders their real governed standing alongside the pre-existing static site-architecture nodes — a Build-15-owned convergence binding, live-verified. 3D Navigator (siw/navigator-3d.html) remains out of scope for this convergence: it iframes an external, separately-deployed historical Cloudflare Worker surface with no local codebase in this repo group, already correctly disclosed on-page as historical/preserved rather than integrated.An 8812-owned router fix (or a production reverse-proxy) replacing the iframe workaround; extending the Explorer's live Canon Access convergence to representation content and relationship traversal, not just standing.
SIW same-object consumptionNot connected to any Reader surface.PROVEN / INTEGRATED / LOCALLY PREFLIGHTED Opening a chapter in SIW from within the embedded Reader shows the identical preserved object id/version/representation/standing to what the Reader's own Context panel shows — live-verified inside this candidate, including surviving a Reset Workspace.Same as the Reader row above — a standalone SIW surface, and resolution of the router defect.
Gateway / Frontier providerNo browser-facing demonstration of the Gateway request/return contract existed.IMPLEMENTED / LOCALLY EXERCISED — REAL SERVICE, MOCK PROVIDER; NOT A LIVE FRONTIER PROVIDER The browser (workflow-composer/composerSiwGatewayHandoff.js) calls a Build-15-owned local API server (tools/local-gateway-api-server.cjs, loopback-only, http://127.0.0.1:8817) that directly invokes the real, unmodified composer-siw-handoff-proof (57034453) and genesis-model-gateway (d09d44a8) source — this is genuine local Gateway service invocation, not a browser-side reimplementation of its logic. The earlier client-side port of that logic (superseded commit e27483b) was replaced, not merely bypassed: the current composerSiwGatewayHandoff.js contains no reimplemented vocabulary, activation, or disclosure logic of its own, only fetch() calls to the local API server. Real invocation caught and corrected a defect the port had silently gotten away with (an invented "ACTIVE_CONTEXT" activation mode; the real, accepted vocabulary is LABEL/DEFINITION/SELECTED_RELATIONSHIPS/BOUNDED_SUBTREE/FULL_PAYLOAD). The disclosure boundary is preserved end to end: the real disclosure gate withholds internalRoutingNote from every value that reaches the mock provider, verified live each run. The provider reached is exclusively genesis-model-gateway's own mock provider (MOCK_PROVIDER_A); its return, and the revision proposal built from it, remain adopted: false candidate material only — not Canon standing, not an applied workflow mutation. Gateway service integration is therefore established at its local/mock standing; a live Frontier provider is not.B15-FRONTIER-001 — one authorized live frontier provider through Gateway before public review. Not attempted in this candidate; no UI, and no server in this candidate, calls a live provider or holds a live credential.
Composer → SIW revision/versioningComposer 008 existed as a standalone candidate-composition tool with no SIW or Gateway path.PROVEN / INTEGRATED / LOCALLY PREFLIGHTED Candidate Workflow → Handoff review → inspect nuggets → explicit activation → real Gateway consultation → build proposal → Continue to Candidate Revision Review → Select/Reject/Defer → Create Candidate Revision → successor Candidate v2 is now one continuous, browser-verified journey, live-checked end to end. The Gateway-produced proposal is carried into the Revision Review modal as a labeled, real "Incoming from Composer → SIW → Gateway handoff (reference only)" card (real proposal_id/standing/adopted fields) rather than staying a disconnected second entry point. It is disclosed as reference/lineage continuity, not a literal schema merge: composer-siw-handoff-proof's proposal shape (free-text proposed_changes) does not match composer-candidate-revision-proof's guarded content-diff model (proposed_changes keyed by ref, applied under guards G-01..G-08) — the two proof repos' own domain models are not silently unified. v1 verified byte-immutable after v2 creation.A real cross-repo proposal-schema bridge, if ever authorized, so a Gateway-derived proposal could be adopted through the same G-01..G-08 guarded path rather than only shown as a reference.
Discovery / Learning / OntologyDiscovery Center preserved unchanged across the 001C→003 candidate lineage; CrossGrid/Jigsaw interaction proof relied partly on programmatic (non-pointer) interaction in prior test passes.PARTIAL — DISC-UI-OPEN-001 RE-RUN, ONE STEP PENDING Discovery Center is carried into this candidate unchanged, protected hashes verified, zero regression. Re-run with real, direct (non-programmatic) pointer interaction: CrossGrid clue selection, answer loading, and "Check selected word" verified via genuine pointer clicks, ending in the real confirmation "Admissibility solved." — PASS. Jigsaw's gated staging mechanic (bringing the correct piece forward via the BOM piece list, confirmed via the real on-page text "Authority · READY TO MOVE") also verified via genuine pointer clicks — PASS. The final Jigsaw piece→socket pointer drag could not be completed: the local browser-automation environment's screenshot/capture path was not returning a trustworthy live frame for coordinate-accurate drag verification. This is recorded as RESULT PENDING — an execution-environment limitation, not a Discovery Center application failure — with no coordinate-guessed, synthetic-DOM, or JavaScript-simulated substitute accepted as evidence.DISC-UI-OPEN-001 — complete and visibly verify the real Jigsaw piece→socket drag once the browser-automation capture path returns a trustworthy live frame; everything else in this item is closed.
Explicit no-deployment statement: nothing in this section describes a publicly deployed surface. genesis-aix-build15-site is a local integration candidate, exercised only at http://127.0.0.1:8815/ alongside locally-run Canon Access and 8812-reader-runtime processes. No Cloudflare, production, or public-hosting action has been taken for Build 15 at any point.
Build 14.2 · independent-review reconciliation

Seventy-five findings are being reconciled without turning review into authority.

The Build 14 independent review is being treated as governed review input, not as an automatic architecture decision. A read-only inventory examined all 75 numbered findings against the current public surface. Seventy-three have at least one relevant public text signal; two currently have no direct public text signal. A text signal is not evidence that a finding is implemented, tested, verified, or closed.

Open specification

Finding 49 · Negative evidence

Absence of evidence is not evidence of absence. A future evidence-producing workflow must distinguish states such as not searched, searched but not found, contradicted, disproved, unresolved, and unknown. Build 14.2 exposes this distinction as open work; it does not claim that the current public website implements a complete negative-evidence model.

Attack-surface reconciliation

Finding 74 · Adversarial provenance testing

The public review called for explicit attack testing across forged or altered provenance, stale or revoked authority, role and identity substitution, conflicting or malicious evidence, misleading human acceptance, prompt injection, model hallucination, branch contamination, stale representations, and replay. Deeper SIW engineering already exercises portions of this family, including stale-standing checks, substitution/replay boundaries, and exact-state revalidation; Build 14.2 will separate those established controls from tests that remain unimplemented or not publicly demonstrated. This section does not claim that the complete adversarial suite has passed.

Reconciliation rule

No finding will disappear through wording.

Each of the 75 findings must receive an explicit disposition: addressed on the public surface; reconciled against an existing deeper control; partially addressed; retained open; future or experimental; or not applicable with a stated rationale. Final disposition counts will be published only after evidence reconciliation is complete.

Review standing: Independent review can identify weaknesses, supply evidence, challenge assumptions, and motivate tests. It does not by itself create Canon standing, SIW lifecycle standing, implementation acceptance, authority to bind, or deployment authority.
Build 14.2 · evidence-based reconciliation

75 findings reviewed. 52 addressed or materially reconciled. 23 retained open.

This register reconciles the independent Build 14 review against the hardened public surface, accepted SIW Release Two evidence, and approved Canon control architecture. “Addressed or materially reconciled” does not mean universally implemented, operational, or closed. It means the concern is bounded by public hardening, an established deeper control, or an explicit scope distinction. Open findings remain specification, implementation, test, or governance work.

Reconciliation standing: 75 / 75 findings have an explicit disposition. Review evidence remains review evidence. No row in this table creates Canon standing, SIW lifecycle standing, deployment authority, or implementation authority.
IDFindingDispositionEvidence-based basis
01Human-directed inquiry can imply authorityAddressed / materially reconciledBuild 14.1 now states inquiry initiation/direction does not create authority; SIW R2 independently revalidates current authority before protected transitions.
02Acceptance is underspecifiedAddressed / materially reconciledSIW R2 separates acceptance/appraisal from authorization, binding, application and consequence; accepted status does not itself create continuation authority.
03Binding can conflate approval and authorizationAddressed / materially reconciledSIW R2 keeps proposal, acceptance, authorization, binding and application distinct, with exact-state and current-standing checks.
04Evidence can be mistaken for truthAddressed / materially reconciledBuild 14.1 states evidence/provenance do not establish truth, authority or current standing by themselves; deeper controls preserve evidence as evidence.
05Inspectable is not the same as auditableAddressed / materially reconciledSIW R2 establishes independently auditable repository/review evidence and separates inspectability from independent verification/conformance.
06Lineage does not establish validityAddressed / materially reconciledSIW R2 preserves lineage/provenance while requiring separate current standing; Canon contracts keep lineage distinct from standing/currentness.
07Provenance is not authorityAddressed / materially reconciledBuild 14.1 and deeper controls explicitly prevent provenance/authorship from becoming authority.
08Positive authority model is insufficiently exposedAddressed / materially reconciledApproved four-path Canon authority architecture plus SIW current-standing controls establish a positive authority model; Build 14.2 can expose that model without inventing new runtime.
09Revalidation requires explicit temporal semanticsAddressed / materially reconciledSIW R2 requires fresh current-standing revalidation at protected transitions and rejects expired/revoked/stale standing.
10TOCTOU / check-to-use boundaryAddressed / materially reconciledSprint 12 adds an atomic commit-boundary standing prerequisite immediately before all-or-none mutation, addressing check-to-use drift.
11Exact-state identity must be formalAddressed / materially reconciledCanonical hashing, exact expected versions, version guards and object/version identity provide the formal exact-state basis.
12Controlled progression can create authority by momentumAddressed / materially reconciledSIW fail-closed progression controls and Build 14.1 consequence-boundary language prevent progression alone from creating authority.
13Progression biasAddressed / materially reconciledProgression is separated from authority by current-standing revalidation and zero-mutation denial; public wording now removes implied authority from progression.
14User-controlled progression is not authorizationAddressed / materially reconciledBuild 14.1 makes user-controlled depth presentation-only; SIW R2 separately determines authority from current standing.
15Proficiency inference can leak into authorityAddressed / materially reconciledBuild 14.1 explicitly neutralizes proficiency/local-interaction signals: they cannot establish competence, role, standing, permission or authority.
16Advanced profile can imply greater authorityAddressed / materially reconciledBuild 14.1 states Guided, Explorer and Advanced are presentation/interaction depth, not authorization classes.
17Audience taxonomy can become competence hierarchyAddressed / materially reconciledThe public audience continuum is presentation depth only; the profile hardening prevents audience or experience depth from acquiring authority.
18Simple surface must not conceal semantic consequenceAddressed / materially reconciledThe site now distinguishes explanation depth from consequence authority and explicitly disclaims operational-runtime status where appropriate.
19Current / in-progress / future adjacency can inflate capabilityAddressed / materially reconciledBuild 14.1 maturity labels separate implemented, tested, reviewed, experimental, planned and open work from current capability.
20Historical and current version ontologyAddressed / materially reconciledPublic historical/current/future labeling is reinforced by Canon exact/current-standing/historical resolution semantics.
21Future, experimental, proposed and research are distinctAddressed / materially reconciledBuild 14.1 maturity taxonomy distinguishes experimental, planned and open specification from current implemented behavior.
22Model Gateway candidate material requires downstream boundaryAddressed / materially reconciledHosted Model Gateway execution is disabled; provider output remains candidate material and the Gateway is architecturally separate from ordinary Canon reads.
23Transformation can launder provenanceRetained openFull transformation lineage for AI-origin material through edit, review, branch, merge and later knowledge state is not established end-to-end.
24Branch merge can contaminate epistemic statusAddressed / materially reconciledSIW R2 selective-merge work preserves branch-finding provenance, exact finding references, conflict/appraisal state and bounded authorization transitions.
25Composite authority requires formal distinctionRetained openThe searched accepted/control surfaces did not establish a complete composite-authority model or attack test for partial authorities recombining.
26Consent and authorization must remain distinctRetained openConsent appears in lineage/context, but a formal current consent-versus-authorization model is not established in the present R2/Canon control surface.
27Consequence needs more than binary classificationAddressed / materially reconciledProtection, activation, binding and consequence remain distinct control classes; Build 14.2 treats consequence as a protected material transition rather than a generic workflow step.
28Inspection can itself have consequencesAddressed / materially reconciledCanon access/disclosure semantics and public privacy boundaries materially reconcile the claim that inspection is not literally consequence-free, without asserting a full disclosure-policy engine.
29Protected state requires formal predicateRetained openA formal protected-state predicate spanning sensitivity, ownership, law, policy and consequence is not yet established.
30Policy precedence is not explicitRetained openNo deterministic cross-policy precedence hierarchy was established by the deeper-control search.
31Refusal reasons require classificationAddressed / materially reconciledSIW R2 uses closed reason-code sets, fail-closed protection/standing checks and zero-mutation denial, providing classified refusal behavior.
32Refusal needs escalation / reconsideration pathRetained openA generalized refusal-to-escalation/reconsideration workflow is not established.
33User intent and user instruction are distinctRetained openA formal intent-versus-instruction object/model and transition semantics are not established.
34Bounded inquiry does not automatically establish scope authorityAddressed / materially reconciledBuild 14.1 separates inquiry initiation from authority; SIW R2 additionally requires same-inquiry/current-owner/current-standing conditions before protected transitions.
35Scope drift across governance boundariesAddressed / materially reconciledSIW target restrictions, cross-inquiry denial and current-standing walls provide bounded scope-drift control; the public consequence boundary makes the semantic transition visible.
36Consequential actions require semantic frictionAddressed / materially reconciledBuild 14.1 exposes the consequence boundary and SIW fail-closed transitions add system friction; no claim is made that every future UI transition is implemented.
37Document / resource / knowledge object ontologyAddressed / materially reconciledCanon control architecture distinguishes governed object identity, representation identity and versions; registered resources do not automatically become governed Canon objects.
38Multiple representations must resolve to same object/versionAddressed / materially reconciledCanon C2 requires exact, current-standing and historical resolution against the same governed object identity across viewers/representations.
39Staleness must be represented as stateAddressed / materially reconciledCanon C1/C2 explicitly distinguish current, stale/unknown and historical states; latest available is not automatically current.
40Revocation lifecycleAddressed / materially reconciledSIW R2 revalidates current standing and fails closed on expired/revoked authority at transition time; this materially addresses the revocation race even though broader propagation can remain future work.
41Expiration / suspension semanticsAddressed / materially reconciledTime-bounded/current-standing semantics and as-of/currentness basis address expiration/staleness at protected transitions.
42Authority and jurisdiction are distinctRetained openA complete authority-jurisdiction model across organization, purpose, domain and geography is not yet established.
43Delegation chains require explicit controlRetained openDelegation ceilings, chaining, propagation and revocation semantics are not established as a complete model.
44Executor substitution requires strict handlingAddressed / materially reconciledSIW R2/WEDGE lineage and adversarial controls address replay/substitution and require current authorized actor/executor conditions rather than inherited execution authority.
45Formal actor modelRetained openActor roles exist in bounded contexts, but a generalized formal actor model spanning principal, reviewer, decision-maker, executor and affected party is incomplete.
46AI model should remain non-agentic with no standingAddressed / materially reconciledModel identity/capability is explicitly non-authoritative in SIW R2; Canon separates Model Gateway material from admission/standing.
47Human review can create circular validationAddressed / materially reconciledSIW R2 prevents model authorship, prior acceptance or human review from substituting for current authority; provenance remains preserved rather than laundered.
48Uncertainty must propagateRetained openEnd-to-end uncertainty propagation through transformation, branch, merge and governed object states is not established.
49Negative evidence needs explicit representationRetained openCanon has unresolved/not-found/unknown semantics, but a complete negative-evidence workflow distinguishing search absence, contradiction and disproval is not yet implemented.
50Search boundaries / search provenance must be preservedRetained openA complete evidence-producing search provenance record for corpus, query, exclusions, timestamp, mechanism, result set and corpus version is not established.
51Governance must withstand adversarial humansAddressed / materially reconciledSIW R2 contains adversarial/concurrency, stale-standing, replay/substitution and fail-closed tests; Build 14.2 still distinguishes tested families from untested attack classes.
52Sophisticated terminology is not enforcementAddressed / materially reconciledBuild 14.1 explicitly separates sophisticated terminology/architecture from demonstrated implementation and disclaims operational-runtime claims.
53Public language can exceed demonstrated implementationAddressed / materially reconciledBuild 14.1 public-review maturity discipline separates specified, implemented, tested, independently reviewed, partial, experimental, planned and open work.
54Verified must be criterion-scopedAddressed / materially reconciledBuild 14.1 scopes Verified to a stated check, criterion, record, method, profile or boundary; it is not a global truth/authority badge.
55Review environment trust paradoxAddressed / materially reconciledThe review surface is now an open technical-review candidate; URL access/noindex does not establish reviewer identity, role, competence, authority or standing.
56Feedback identity and governance standingAddressed / materially reconciledBuild 14.1 states feedback is review input only and does not create reviewer identity, competence, Canon/SIW standing or decision authority.
57Review process itself needs governanceRetained openA formal review-provenance model covering identity, competence, method, independence and authority of review evidence remains incomplete.
58Independent and internal review are distinctAddressed / materially reconciledSIW R2 explicitly separates implementation engineer and independent reviewer roles; Build 14.1 maturity labels also bound what Independent Review means.
59Conflict-of-interest modelRetained openA formal conflict-of-interest declaration/evaluation model for reviewers and decision-makers is not established.
60Separation of dutiesRetained openProject process separates proposal, review and authorization in many places, but a generalized risk-based separation-of-duties model is not yet formalized.
61Decision should be first-classRetained openDecision is used as a control concept, but a first-class governed Decision object with maker, authority, alternatives, evidence, conditions and outcome is not established.
62Rationale is distinct from evidenceRetained openRationale appears in records, but a first-class governed Rationale object explicitly distinct from evidence is not established.
63Binding may create obligationRetained openBinding/consequence controls exist, but a governed Obligation object for duties, deadlines, completion, failure and escalation is not established.
64Exception modelRetained openIsolated exceptions exist in process records, but a general governed policy-exception model is not established.
65Human-readable explanation at consequential transitionAddressed / materially reconciledFor the present public-review site, consequential actions are explanatory rather than live; pages expose authority/evidence/consequence distinctions without claiming a production transition UI.
66Why-am-I-seeing-this explanationsAddressed / materially reconciledCurrent public surfaces provide reasons/boundaries in explanatory form; a universal runtime why-am-I-seeing-this service is outside the present website claim.
67Governance must not turn users into compliance operatorsAddressed / materially reconciledProgressive disclosure, direct paths and experience-depth controls keep governance complexity beneath a simpler surface without treating depth as authority.
68Terminology overloadAddressed / materially reconciledThe lexicon, direct paths, progressive disclosure and audience-depth design materially address terminology load while preserving exact terms for expert review.
69Knowledge object and governed object are distinctAddressed / materially reconciledCanon C1/GRX separate governed object identity, representation, standing and resolution classes; not every knowledge artifact receives the same governed status.
70Status metadata must not inherit authorityAddressed / materially reconciledCanon currentness/standing are orthogonal and Build 14.1 scopes Verified, preventing metadata inheritance from silently creating authority.
71Negative capability / explicit unknown statesAddressed / materially reconciledCanon C1/C2 preserve unresolved, not-found, unavailable, historical and unknown-currentness semantics rather than forcing false certainty.
72Model must not close its own epistemic loopRetained openModel authority is bounded, but exploratory versus confirmation search and self-confirming epistemic loops are not yet governed as a complete mechanism.
73Branching can amplify confirmation biasRetained openSelective-merge controls exist, but explicit anti-confirmation-bias requirements for contradictory/excluded evidence and falsification-oriented branching remain incomplete.
74Adversarial provenance testingRetained openSome stale-standing/replay/substitution adversarial tests exist, but the complete forged-provenance/prompt-injection/malicious-evidence attack suite is not established or publicly demonstrated.
75Semantic distinctions must remain invariant through lifecycleAddressed / materially reconciledAcross R2 and approved Canon control architecture, acceptance, authority, current standing, binding, consequence and model output remain separate; Build 14.2 treats this as an invariant family rather than claiming one universal linear lifecycle.
Open-work rule: The 23 retained-open items are not silently deferred. They remain visible requirements for future specification, implementation, conformance or attack-surface work. The 52 reconciled items are not thereby promoted to production capability.
Build 14.2 · adversarial attack surface

Five adversarial scenarios. Different evidence standings.

Independent review proposed five adversarial scenarios intended to test whether Genesis semantic distinctions survive hostile or misleading transitions. The evidence does not support five identical PASS results. This matrix states what is currently established, what is only partial, and what remains open.

Attack-test standing: A control may be specified, implemented, tested, independently reviewed, partially demonstrated, or still open. Evidence in one scenario does not automatically transfer to another, and a proposal/authorization foundation is not silently treated as a completed consequence path.
Scenario Invariant under attack Current classification Evidence boundary
1 · Unauthorized but sophisticated user
Can expertise, proficiency, familiarity or interaction depth produce authority?
Competence, presentation depth and familiarity must remain distinct from current authority. Materially established · bounded testable Build 14.1 explicitly makes experience/proficiency signals authority-neutral. SIW Release Two contains fail-closed current-authority and unauthorized-transition controls. The complete “attempt every step” scenario has not been presented as one unified end-to-end conformance test.
2 · Authorized but mistaken user
Does valid authority override epistemically insufficient evidence?
Authority must not compensate for inadequate evidence or an unmet protection predicate. Partial · testable in part Evidence and authority are already separated and SIW provides closed denial behavior. A complete protected-state predicate and end-to-end uncertainty treatment remain open, so Build 14.2 does not claim universal denial of every epistemically inadequate state.
3 · AI laundering
Can AI origin and uncertainty survive human editing, acceptance, branching and later governance?
Transformation must not erase origin, uncertainty, contradictory evidence or provenance. Open · end-to-end test not established SIW preserves provenance in bounded branch operations and prevents model authorship from creating authority. End-to-end transformation lineage, uncertainty propagation, anti-confirmation-bias controls and the complete adversarial provenance suite are not established.
4 · Revoked-authority race
Authority is valid at approval but stale, expired or revoked before consequence.
Present authority for the exact state must exist at the consequence boundary. Strongest current bounded proof family SIW Release Two revalidates current standing, denies expired/revoked/non-current standing with zero unauthorized mutation, and includes atomic commit-boundary standing prerequisites intended to prevent check-to-use drift. This is bounded SIW evidence, not a universal production-system claim.
5 · Selective-merge conflict preservation
Does selecting one branch preserve conflict and excluded evidence?
Selective progression must not silently launder contradictory or excluded evidence. Partial · governed foundations present Branch provenance, exact finding references, conflict/appraisal state, proposal and authorization foundations are substantial. Uncertainty and explicit anti-confirmation-bias controls remain open. Proposal, inspection and authorization foundations are not presented as proof of a separately implemented final merge/application consequence path.
What Build 14.2 does not claim: It does not claim five end-to-end adversarial PASS results; it does not claim complete AI-origin laundering resistance; it does not claim every form of epistemic insufficiency is already modeled; and it does not promote selective-merge proposal or authorization foundations into an unimplemented final merge/application path.