A frozen standard has one legal way to change: its own Section 15 ceremony. On July 16 that ceremony ran for the third time, under governance, with a human signature at its center. Four long-standing governance debts became normative text, the spec moved from v0.8 to v0.9, and the amendment record was chain-linked to its predecessors by derivation, not trust. The signing act was then swept for leaked key material by a checker the same ceremony had just made law. It found nothing. Any stranger can re-verify all of it with three commands.
Governed AI Development's formal specification is frozen: no one, including its authors, may edit it in place. Amendments arrive only as successions — signed delta records that bind the new document's digest and chain to the previous amendment. Succession 3, sealed July 16, rested four debts the project's own register had carried for days:
The ceremony itself ran as a governed plan under the reference stack, with an approval gate that stopped the run until the operator's logged authorization named the ceremony node, and a signature performed with an authority key that never entered the repository. The proof of that last claim is not a promise: the derive-based checker born two nodes earlier swept the succession directory after signing. 17 files, 149 candidates, 0 findings.
Getting here consumed four frozen plans in one arc — and zero edits to any of them. The first plan demanded a verification that its own first node made impossible (mid-ceremony, the lineage verifier is supposed to fail: the document is deliberately ahead of the sealed record). The executor refused to fake it, refused to waive it, and stopped. The second plan hit a gate the product could not honor: the two-channel irreversible approval's secret is deferred in the shipping product, so the gate was unpassable as authored. The plan was superseded to match the gate to the channel the product honors, with the gap recorded, rather than pretending a channel existed. The third plan's exit check overreached its own jurisdiction — it demanded an append-only register and a signed record body satisfy a style rule that only ever governed the spec — and the executor declined to break a signature to satisfy a checkbox.
Every one of those stops is in the register with its author named. The lineage that resulted is sealed, signed, and boring to verify — which is the point.
Clone the repository, install, and run:
node tools/succession-verify.mjs --strict
Expected final line, quoted from the run this record describes:
succession:verify passed (3 record(s); lineage sealed at succession-3)
What that one line recomputes: every succession record discovered from the directory, every signature verified under the operator authority public key, each record's predecessor digest matched against the document the previous record sealed, and the latest record's successor digest matched against the v0.9 document on disk, byte for byte. The genesis is disclosed, never softened: v0.6 did not authorize its own amendment, and succession 1 carries a dev-signed exhibit saying exactly that — whose signature, since this ceremony's REG-37 adoption, is verified rather than merely displayed.
This section exists because the archive's rule is that defects are evidence. All four authoring defects below belong to the advisory layer that wrote the plans, and all four were caught by the machinery before they could corrupt a record.
The signature attests ceremony, not authorship, and not correctness. It says: the operator, holding the authority key, stood behind this amendment record at this moment, and the record binds these exact bytes. Whether the amendments are wise is argued in the register and judged, eventually, by independent review. And per the specification's own Section 12A: nothing about this repository's tooling is grandfathered into conformance by pedigree — including the run that performed this ceremony, whose own record is the subject of field record No. 6.
It proves: the specification's amendment path works under governance, three times running; a signed, chain-linked lineage, re-verifiable by another party, exists from v0.6's disclosed genesis to v0.9; four governance rules moved from register debt to normative text; and the key-hygiene rule was enforced, by derivation, on the very act that sealed it.
It does not prove: that the amendments are correct (Propositions and Claims, per the spec's own header, until independent formal and cryptographic review completes); that the reference tooling is conformant (bundle conformance is per-record; constructor and operational conformance require their own assessment, never pedigree); or that the ceremony's approval gate is as strong as designed — the two-channel form awaits its product wiring, and this archive says so out loud.