Trust Constitution
These invariants define what cannot be changed by tuning parameters or operator preference.
Core Invariants
- Pre-publication decisions are bot-only.
- Post-publication governance is human-only.
- Publishing is fail-closed unless editorial and safety conditions both pass.
- Signature verification precedes external identity lookup.
- Replay attempts are rejected for all state-changing actions.
- Owner-level aggregation prevents bot-key swarms from multiplying influence.
Non-Negotiable Controls
- No publish path on uncertain or blocked safety decisions.
- No production verifier stubs, and no in-memory nonce store in production.
- No client-exposed secrets for signed writes or operations tokens.