# GAD manifesto ceremony — handoff

Run 38, project "GAD manifesto ceremony", completed 2026-08-25.
A two-node governed run under Atlas Orchestrator with `protocol_mode: v0_6`,
supervised by Waypoint, gated on a typed operator approval, and exported as a
GAD envelope that a machine which was never here can judge.

## The artifact under governance

| | |
|---|---|
| document | `gad-manifesto.md`, 7191 bytes, UTF-8, LF |
| sha256 | `0fd6ff73b40cc974bf5323a1b394a3eea240d740520f4f6ebbc5962f7626a911` |
| repo | `gad-manifesto-ceremony`, commit `e282970` |

## The record

| | |
|---|---|
| plan identity | `6cbbcd02ce4ca62d21d10f26218699fcafac15f527fc98094a635a66d042a6f6` |
| genesis (chain root) | `61d03ef47a14d842c5f028a97eff623647028d785291a28259cd19704594dafd` |
| root_core | `253d9e8c62154f5a3edfd409c1e7480fefd9ca978af86e1efd477c7b3e2fd629` |
| root_envelope | `b26c2cae0e0e875520b6c54157c70715a24cc2c7e9c9e0f2dcbe585c0db84b57` |
| anchor | RFC 3161, freetsa.org, over `root_core` |
| witness | 28 entries, terminal (`plan_completed`) |

Contents: 2 dispatches, 2 execution results, **13 verdicts** (one per check),
**5 probes** (one per proxy check, all fired), 1 `gate_request`, 1 `approval`.

## What was checked

`stage-artifact` derived the governed copy under `record/`, emitted the digest
it computed, and built three probe fixtures. `verify-frozen-checks` ran the
frozen checks and, by reaching done, authorized publication.

The three contracted conditions, each asserted against the staged copy:

1. its sha256 equals the contracted digest;
2. it contains three exact strings — the approval sentence, the dateline
   `July 2026, amended August 2026`, and the CC BY-ND colophon line;
3. its em-dash count is zero.

Each carries a negative probe that runs the identical assertion against a copy
mutated in exactly one code point, and must fail. A seventh check verifies the
probe fixtures are single-code-point mutations mutated in the region their own
check reads, so no probe can fire for the wrong reason.

Node evidence class: `server_observed_proxy` on both nodes. Eight checks are
`server_verified` (engine-owned filesystem reads); five are proxy checks, whose
pass/fail logic was authored rather than engine-owned. A node's class is the
weakest of its checks. This is the price of the probe rule: `proxy_command` is
the only check kind that can carry "the same assertion must fail against this
other file", and it is always `server_observed_proxy`.

## The gate

`verify-frozen-checks` was flagged irreversible and stopped for approval before
it was handed out. Two independent channels were required and both were
supplied: a logged authorization naming the node, recorded verbatim as

> I, Brandon King, authorize verify-frozen-checks to run.

and an out-of-band approval file carrying a secret the executor never receives.
Clearing the gate published nothing; it authorized publication to proceed.

## Verifying this record on another machine

Requires Node 22+ and the `gad-protocol` evaluator (`evaluator/dist/cli.js`).
The policy and the record's public keys travel in this bundle. Run from inside
the `record-run-38-…` directory.

**1 — check the bundle arrived intact** (from the `handoff` directory):

    sha256sum -c SHA256SUMS

**2 — mint an independent evaluator key.** The evaluator signs its own
judgment; a key shipped by the party being evaluated would defeat the point.
This writes `evaluator-key.json` (private, keep it) and `keys-for-eval.json`
(the record's engine and principal keys plus your evaluator public key):

    node -e "const c=require('crypto'),f=require('fs');const{publicKey,privateKey}=c.generateKeyPairSync('ed25519');const pub=publicKey.export({type:'spki',format:'der'}).toString('hex');f.writeFileSync('evaluator-key.json',JSON.stringify({keys:{evaluator:{algorithm:'ed25519',private_key_pkcs8_hex:privateKey.export({type:'pkcs8',format:'der'}).toString('hex'),public_key_spki_hex:pub}}},null,2));const k=JSON.parse(f.readFileSync('pubkeys.json','utf8'));k.keys.evaluator={algorithm:'ed25519',public_key_spki_hex:pub};f.writeFileSync('keys-for-eval.json',JSON.stringify(k,null,2));console.log('minted evaluator-key.json + keys-for-eval.json')"

**3 — evaluate:**

    node <path-to>\gad-protocol\evaluator\dist\cli.js .\envelope --policy .\policy-gad4-default.json --keys .\keys-for-eval.json --evaluator-key .\evaluator-key.json --out .\q.json

Expected:

    valid:     true
    outcome:   COMPLETED
    satisfied: true
    R1..R9: pass

Exit code 0 means CONTRACT_SATISFIED. `q.json` is the signed evaluator
judgment, written outside the envelope so the original is never mutated.

## Known limitations of this record

Stated because a record that hides its gaps is worth less than one that names
them.

**1. The manifesto's digest is not in the chain root.** The manifest records
`spec_hash: null`, so genesis binds the plan but not the document. Cause:
`buildManifest` in `atlas-orchestrator/src/provenance.ts` receives `projectDir`
but calls `hashSpecFile(graph.spec_path)`, which resolves against the engine
process's current working directory instead. When cwd is not the project dir
the hash silently becomes null rather than failing. The preceding run (37) on
identical inputs recorded the hash correctly, so this is non-deterministic.
The digest is still named in the frozen plan (present in this bundle, its hash
in the manifest) and asserted by a check whose verdict is in the witness — that
chain holds. What is absent is the identity-level binding.

**2. DEFENSIBLE evaluates false.** The policy `gad4-default` requires an anchor
of kind `post_run_root_anchor`; the exporter emits kinds
`rfc3161_anchor_note` and `post_run_root_rfc3161_token`. A naming mismatch, not
a missing anchor — the RFC 3161 token is present and timestamps `root_core`
exactly. The reference record (run 36, the succession-7 ceremony) fails
identically under the same policy, so this is a pre-existing seam between the
exporter and the policy vocabulary, not a property of this run.

**3. The gate principal is a fixed development key.** The principal public key
`d3d918c6…` is the same value across run 36 and run 38, and the witness records
the approver as `dev-principal`. What is personally the operator's is the typed
authorization text and the out-of-band secret; the Ed25519 signature over the
approval body is made with the app's principal key, not a personal one.

**4. Run 37 is in the bundle as archived history.** An earlier attempt at this
ceremony ran without `protocol_mode`, producing an honest but non-GAD record
with no witness and nothing to export. Its state and log are archived under
`record/archive/run-90760778-…` in the evidence zip. It is history, not a
failure that was hidden.
