| 01 | Human-directed inquiry can imply authority | Addressed / materially reconciled | Build 14.1 now states inquiry initiation/direction does not create authority; SIW R2 independently revalidates current authority before protected transitions. |
| 02 | Acceptance is underspecified | Addressed / materially reconciled | SIW R2 separates acceptance/appraisal from authorization, binding, application and consequence; accepted status does not itself create continuation authority. |
| 03 | Binding can conflate approval and authorization | Addressed / materially reconciled | SIW R2 keeps proposal, acceptance, authorization, binding and application distinct, with exact-state and current-standing checks. |
| 04 | Evidence can be mistaken for truth | Addressed / materially reconciled | Build 14.1 states evidence/provenance do not establish truth, authority or current standing by themselves; deeper controls preserve evidence as evidence. |
| 05 | Inspectable is not the same as auditable | Addressed / materially reconciled | SIW R2 establishes independently auditable repository/review evidence and separates inspectability from independent verification/conformance. |
| 06 | Lineage does not establish validity | Addressed / materially reconciled | SIW R2 preserves lineage/provenance while requiring separate current standing; Canon contracts keep lineage distinct from standing/currentness. |
| 07 | Provenance is not authority | Addressed / materially reconciled | Build 14.1 and deeper controls explicitly prevent provenance/authorship from becoming authority. |
| 08 | Positive authority model is insufficiently exposed | Addressed / materially reconciled | Approved four-path Canon authority architecture plus SIW current-standing controls establish a positive authority model; Build 14.2 can expose that model without inventing new runtime. |
| 09 | Revalidation requires explicit temporal semantics | Addressed / materially reconciled | SIW R2 requires fresh current-standing revalidation at protected transitions and rejects expired/revoked/stale standing. |
| 10 | TOCTOU / check-to-use boundary | Addressed / materially reconciled | Sprint 12 adds an atomic commit-boundary standing prerequisite immediately before all-or-none mutation, addressing check-to-use drift. |
| 11 | Exact-state identity must be formal | Addressed / materially reconciled | Canonical hashing, exact expected versions, version guards and object/version identity provide the formal exact-state basis. |
| 12 | Controlled progression can create authority by momentum | Addressed / materially reconciled | SIW fail-closed progression controls and Build 14.1 consequence-boundary language prevent progression alone from creating authority. |
| 13 | Progression bias | Addressed / materially reconciled | Progression is separated from authority by current-standing revalidation and zero-mutation denial; public wording now removes implied authority from progression. |
| 14 | User-controlled progression is not authorization | Addressed / materially reconciled | Build 14.1 makes user-controlled depth presentation-only; SIW R2 separately determines authority from current standing. |
| 15 | Proficiency inference can leak into authority | Addressed / materially reconciled | Build 14.1 explicitly neutralizes proficiency/local-interaction signals: they cannot establish competence, role, standing, permission or authority. |
| 16 | Advanced profile can imply greater authority | Addressed / materially reconciled | Build 14.1 states Guided, Explorer and Advanced are presentation/interaction depth, not authorization classes. |
| 17 | Audience taxonomy can become competence hierarchy | Addressed / materially reconciled | The public audience continuum is presentation depth only; the profile hardening prevents audience or experience depth from acquiring authority. |
| 18 | Simple surface must not conceal semantic consequence | Addressed / materially reconciled | The site now distinguishes explanation depth from consequence authority and explicitly disclaims operational-runtime status where appropriate. |
| 19 | Current / in-progress / future adjacency can inflate capability | Addressed / materially reconciled | Build 14.1 maturity labels separate implemented, tested, reviewed, experimental, planned and open work from current capability. |
| 20 | Historical and current version ontology | Addressed / materially reconciled | Public historical/current/future labeling is reinforced by Canon exact/current-standing/historical resolution semantics. |
| 21 | Future, experimental, proposed and research are distinct | Addressed / materially reconciled | Build 14.1 maturity taxonomy distinguishes experimental, planned and open specification from current implemented behavior. |
| 22 | Model Gateway candidate material requires downstream boundary | Addressed / materially reconciled | Hosted Model Gateway execution is disabled; provider output remains candidate material and the Gateway is architecturally separate from ordinary Canon reads. |
| 23 | Transformation can launder provenance | Retained open | Full transformation lineage for AI-origin material through edit, review, branch, merge and later knowledge state is not established end-to-end. |
| 24 | Branch merge can contaminate epistemic status | Addressed / materially reconciled | SIW R2 selective-merge work preserves branch-finding provenance, exact finding references, conflict/appraisal state and bounded authorization transitions. |
| 25 | Composite authority requires formal distinction | Retained open | The searched accepted/control surfaces did not establish a complete composite-authority model or attack test for partial authorities recombining. |
| 26 | Consent and authorization must remain distinct | Retained open | Consent appears in lineage/context, but a formal current consent-versus-authorization model is not established in the present R2/Canon control surface. |
| 27 | Consequence needs more than binary classification | Addressed / materially reconciled | Protection, activation, binding and consequence remain distinct control classes; Build 14.2 treats consequence as a protected material transition rather than a generic workflow step. |
| 28 | Inspection can itself have consequences | Addressed / materially reconciled | Canon access/disclosure semantics and public privacy boundaries materially reconcile the claim that inspection is not literally consequence-free, without asserting a full disclosure-policy engine. |
| 29 | Protected state requires formal predicate | Retained open | A formal protected-state predicate spanning sensitivity, ownership, law, policy and consequence is not yet established. |
| 30 | Policy precedence is not explicit | Retained open | No deterministic cross-policy precedence hierarchy was established by the deeper-control search. |
| 31 | Refusal reasons require classification | Addressed / materially reconciled | SIW R2 uses closed reason-code sets, fail-closed protection/standing checks and zero-mutation denial, providing classified refusal behavior. |
| 32 | Refusal needs escalation / reconsideration path | Retained open | A generalized refusal-to-escalation/reconsideration workflow is not established. |
| 33 | User intent and user instruction are distinct | Retained open | A formal intent-versus-instruction object/model and transition semantics are not established. |
| 34 | Bounded inquiry does not automatically establish scope authority | Addressed / materially reconciled | Build 14.1 separates inquiry initiation from authority; SIW R2 additionally requires same-inquiry/current-owner/current-standing conditions before protected transitions. |
| 35 | Scope drift across governance boundaries | Addressed / materially reconciled | SIW target restrictions, cross-inquiry denial and current-standing walls provide bounded scope-drift control; the public consequence boundary makes the semantic transition visible. |
| 36 | Consequential actions require semantic friction | Addressed / materially reconciled | Build 14.1 exposes the consequence boundary and SIW fail-closed transitions add system friction; no claim is made that every future UI transition is implemented. |
| 37 | Document / resource / knowledge object ontology | Addressed / materially reconciled | Canon control architecture distinguishes governed object identity, representation identity and versions; registered resources do not automatically become governed Canon objects. |
| 38 | Multiple representations must resolve to same object/version | Addressed / materially reconciled | Canon C2 requires exact, current-standing and historical resolution against the same governed object identity across viewers/representations. |
| 39 | Staleness must be represented as state | Addressed / materially reconciled | Canon C1/C2 explicitly distinguish current, stale/unknown and historical states; latest available is not automatically current. |
| 40 | Revocation lifecycle | Addressed / materially reconciled | SIW R2 revalidates current standing and fails closed on expired/revoked authority at transition time; this materially addresses the revocation race even though broader propagation can remain future work. |
| 41 | Expiration / suspension semantics | Addressed / materially reconciled | Time-bounded/current-standing semantics and as-of/currentness basis address expiration/staleness at protected transitions. |
| 42 | Authority and jurisdiction are distinct | Retained open | A complete authority-jurisdiction model across organization, purpose, domain and geography is not yet established. |
| 43 | Delegation chains require explicit control | Retained open | Delegation ceilings, chaining, propagation and revocation semantics are not established as a complete model. |
| 44 | Executor substitution requires strict handling | Addressed / materially reconciled | SIW R2/WEDGE lineage and adversarial controls address replay/substitution and require current authorized actor/executor conditions rather than inherited execution authority. |
| 45 | Formal actor model | Retained open | Actor roles exist in bounded contexts, but a generalized formal actor model spanning principal, reviewer, decision-maker, executor and affected party is incomplete. |
| 46 | AI model should remain non-agentic with no standing | Addressed / materially reconciled | Model identity/capability is explicitly non-authoritative in SIW R2; Canon separates Model Gateway material from admission/standing. |
| 47 | Human review can create circular validation | Addressed / materially reconciled | SIW R2 prevents model authorship, prior acceptance or human review from substituting for current authority; provenance remains preserved rather than laundered. |
| 48 | Uncertainty must propagate | Retained open | End-to-end uncertainty propagation through transformation, branch, merge and governed object states is not established. |
| 49 | Negative evidence needs explicit representation | Retained open | Canon has unresolved/not-found/unknown semantics, but a complete negative-evidence workflow distinguishing search absence, contradiction and disproval is not yet implemented. |
| 50 | Search boundaries / search provenance must be preserved | Retained open | A complete evidence-producing search provenance record for corpus, query, exclusions, timestamp, mechanism, result set and corpus version is not established. |
| 51 | Governance must withstand adversarial humans | Addressed / materially reconciled | SIW R2 contains adversarial/concurrency, stale-standing, replay/substitution and fail-closed tests; Build 14.2 still distinguishes tested families from untested attack classes. |
| 52 | Sophisticated terminology is not enforcement | Addressed / materially reconciled | Build 14.1 explicitly separates sophisticated terminology/architecture from demonstrated implementation and disclaims operational-runtime claims. |
| 53 | Public language can exceed demonstrated implementation | Addressed / materially reconciled | Build 14.1 public-review maturity discipline separates specified, implemented, tested, independently reviewed, partial, experimental, planned and open work. |
| 54 | Verified must be criterion-scoped | Addressed / materially reconciled | Build 14.1 scopes Verified to a stated check, criterion, record, method, profile or boundary; it is not a global truth/authority badge. |
| 55 | Review environment trust paradox | Addressed / materially reconciled | The review surface is now an open technical-review candidate; URL access/noindex does not establish reviewer identity, role, competence, authority or standing. |
| 56 | Feedback identity and governance standing | Addressed / materially reconciled | Build 14.1 states feedback is review input only and does not create reviewer identity, competence, Canon/SIW standing or decision authority. |
| 57 | Review process itself needs governance | Retained open | A formal review-provenance model covering identity, competence, method, independence and authority of review evidence remains incomplete. |
| 58 | Independent and internal review are distinct | Addressed / materially reconciled | SIW R2 explicitly separates implementation engineer and independent reviewer roles; Build 14.1 maturity labels also bound what Independent Review means. |
| 59 | Conflict-of-interest model | Retained open | A formal conflict-of-interest declaration/evaluation model for reviewers and decision-makers is not established. |
| 60 | Separation of duties | Retained open | Project process separates proposal, review and authorization in many places, but a generalized risk-based separation-of-duties model is not yet formalized. |
| 61 | Decision should be first-class | Retained open | Decision is used as a control concept, but a first-class governed Decision object with maker, authority, alternatives, evidence, conditions and outcome is not established. |
| 62 | Rationale is distinct from evidence | Retained open | Rationale appears in records, but a first-class governed Rationale object explicitly distinct from evidence is not established. |
| 63 | Binding may create obligation | Retained open | Binding/consequence controls exist, but a governed Obligation object for duties, deadlines, completion, failure and escalation is not established. |
| 64 | Exception model | Retained open | Isolated exceptions exist in process records, but a general governed policy-exception model is not established. |
| 65 | Human-readable explanation at consequential transition | Addressed / materially reconciled | For the present public-review site, consequential actions are explanatory rather than live; pages expose authority/evidence/consequence distinctions without claiming a production transition UI. |
| 66 | Why-am-I-seeing-this explanations | Addressed / materially reconciled | Current public surfaces provide reasons/boundaries in explanatory form; a universal runtime why-am-I-seeing-this service is outside the present website claim. |
| 67 | Governance must not turn users into compliance operators | Addressed / materially reconciled | Progressive disclosure, direct paths and experience-depth controls keep governance complexity beneath a simpler surface without treating depth as authority. |
| 68 | Terminology overload | Addressed / materially reconciled | The lexicon, direct paths, progressive disclosure and audience-depth design materially address terminology load while preserving exact terms for expert review. |
| 69 | Knowledge object and governed object are distinct | Addressed / materially reconciled | Canon C1/GRX separate governed object identity, representation, standing and resolution classes; not every knowledge artifact receives the same governed status. |
| 70 | Status metadata must not inherit authority | Addressed / materially reconciled | Canon currentness/standing are orthogonal and Build 14.1 scopes Verified, preventing metadata inheritance from silently creating authority. |
| 71 | Negative capability / explicit unknown states | Addressed / materially reconciled | Canon C1/C2 preserve unresolved, not-found, unavailable, historical and unknown-currentness semantics rather than forcing false certainty. |
| 72 | Model must not close its own epistemic loop | Retained open | Model authority is bounded, but exploratory versus confirmation search and self-confirming epistemic loops are not yet governed as a complete mechanism. |
| 73 | Branching can amplify confirmation bias | Retained open | Selective-merge controls exist, but explicit anti-confirmation-bias requirements for contradictory/excluded evidence and falsification-oriented branching remain incomplete. |
| 74 | Adversarial provenance testing | Retained open | Some stale-standing/replay/substitution adversarial tests exist, but the complete forged-provenance/prompt-injection/malicious-evidence attack suite is not established or publicly demonstrated. |
| 75 | Semantic distinctions must remain invariant through lifecycle | Addressed / materially reconciled | Across R2 and approved Canon control architecture, acceptance, authority, current standing, binding, consequence and model output remain separate; Build 14.2 treats this as an invariant family rather than claiming one universal linear lifecycle. |