{"body":{"CONSEQUENCES":{"severed_couplings":[{"coupling":"The coupling between this specification's published status and its untested status. From v0.1 through v0.9 the version line said 'draft', and honestly: the stewardship rule froze prose at v0.6 explicitly to await Trial 0, so 'draft' meant 'no conforming record has ever been evaluated against this text'. Every claim the document made stood on review rounds alone.","id":"REG-57 (the draft coupling)","re_derived_by_decision":"The version line drops 'draft' on a stated, bounded ground: ratification asserts RECORD-LEVEL conformance of run 20's envelope per the manifest's own scope_of_ratification, never general implementation conformance, evaluator correctness, or organizational independence; Section 1's results remain Propositions and Claims, not Theorems, pending Phase 5 independent review. The decision is the scope statement, carried in the v1.0 history entry, in the ratification manifest, and in this record's successor_does_not_claim — three places that must agree, none of them inflatable alone.","severed_by":"Trial 0 Movement 2's cold evaluation (run 20: VALID_RECORD=true, OUTCOME=COMPLETED, nine of nine conditions, one flipped byte anywhere producing INVALID at exit 1) and Movement 4's ratification package: the operator-signed manifest and the RFC 3161 anchor this record cites by computed digest."},{"coupling":"The coupling between the lineage's evidence and the tree's own attestations. Through succession 3, every figure a succession record carried was a digest of this repository's own documents (the spec, the manifest, the chain's own records), so the lineage's whole evidence base was the tree plus the operator's key: self-consistent, and self-referential.","id":"lineage self-reference (the evidence-trail coupling)","re_derived_by_decision":"The binding is derivation, not citation by name: this builder verified the manifest's operator signature over its canonical body, located the manifest's canonical digest inside the token's DER, and required every sidecar-recorded figure to equal its computed counterpart before writing (each clause separately probed). The specification's final version thereby carries genesis, three amendments, a trial, a signature, and a clock — an evidence trail a referee checks from the bytes without trusting this record's word for it.","severed_by":"The ratification citations: a third-party clock (an RFC 3161 token from an external TSA) whose message imprint is the ratification manifest's canonical digest, and a trial record evaluated cold on a second machine, both bound into this record by digests computed at build time."}],"statement":"What this amendment SEVERS, as distinct from what it invalidates. An invalidated artifact is regenerated from its sources; a severed coupling must be RE-DERIVED BY A DECISION, and the decision is named here rather than left for an implementer to infer."},"amended_files":{"files":[{"digest":"fa2192e1250a743a3e695589eb27c50e14d1ac7a3aeb5aee0bae66e9c708fa18","path":"docs/gad-formal-spec.md"}],"statement":"The files this succession amended, each digest hashed from the bytes on disk at build time, never transcribed. v1.0 amends exactly one file: the specification itself, and only its version line, its v1.0 history entry, and its closing line. The companion register (docs/gad-spec-register.md) is cited by identifier throughout this record and deliberately NOT by digest: it is the append-only companion whose next append is this very record's citation, and a digest here would freeze the document this record exists to be cited by."},"authority":{"executor_role":"The executor authored this text and computed these figures under the succession-4 arc's nodes (the v1.0 text by s4-01; this record by s4-02), and applied the operator's key to the canonical body at the operator's direction. It did not authorize the succession. The authority is the operator's, recorded here by name, exercised by commissioning the plan, by the logged per-node authorization gating the ceremony node (see gate_channel), and by holding the signing key outside this repository where only the operator controls it. Authoring and computing are not authorizing (succession 1's division, RUL-11's ratification).","named_authority":"Brandon King","performed_by_executor":false,"role":"the operator","rule":"The authority is the operator, named in the record. No other party MAY perform a specification succession; in particular the executor of a governed run MUST NOT perform one, and a ruling recorded in the companion register is not itself an amendment of this document (spec Section 15, Authority)."},"changed":[{"authored_by":"the s4 run (s4-01), against the tree this ceremony seals","change":"The version line reads 'Version 1.0 · Atlas North Institute · July 2026', where v0.9's read 'Version 0.9 draft'. The draft designation leaves the version line; the companion header paragraph is frozen prose and stands byte-unchanged, its draft-era language now historical fact about the document's origin.","section":"Version line (document header)","why":"The stewardship rule froze prose expansion at v0.6 and promised that the next milestone was Trial 0 and the reference evaluator. Both exist: Trial 0 Movement 2 closed on the referee's cold evaluation (REG-57), and Movement 4 ratified it with an operator-signed manifest and an RFC 3161 anchor. A version line still reading 'draft' after the trial it awaited had closed would contradict the record beside it."},{"authored_by":"the s4 run (s4-01), against the tree this ceremony seals","change":"One entry appended: v1.0 (July 2026), ratified by Trial 0, recorded in docs/trial-0/ (the conformance matrix, the operator-signed ratification manifest, and the RFC 3161 anchor); independent formal and cryptographic review pending (Phase 5); NO normative text changes; ratification asserts Trial 0's record-level results, never general conformance; Section 1's results remain Propositions and Claims, not Theorems, until independent review completes. All earlier history entries stand intact as fact.","section":"Version history (the v1.0 entry)","why":"The history is fact and the label must not contradict the bytes beside it (REG-35: this record's own version labels are derived from the bytes it hashes, never recited). The entry states the ratification's scope in the document itself so the boundary cannot be inflated by citation."},{"authored_by":"the s4 run (s4-01), against the tree this ceremony seals","change":"The document ends 'End of v1.0.' where it ended 'End of v0.9.'","section":"Closing line","why":"The closing line is part of the bytes the successor digest freezes, and it must agree with the header it closes (REG-35's discipline applied to both ends of the document)."}],"discharges":{"by_this_amendment":[],"cited_rulings_not_discharged_here":[{"id":"REG-57","status":"CLOSED July 16, 2026, by the register, on the referee's cold evaluation of run 20","why_cited":"The trial this succession binds: run 20's record evaluated cold on a second machine as VALID_RECORD=true, OUTCOME=COMPLETED, nine of nine conditions; anchored by a live RFC 3161 token; one flipped byte anywhere produces INVALID. This record cites its ratification manifest and anchor by computed digest (trial_0_ratification); the closure is the register's, not this amendment's."},{"id":"REG-47","status":"OPEN, awaiting the operator's ruling","why_cited":"The anchor-class question (an RFC 3161 token's WHEN versus an authority signature's WHO) is live in the very artifacts this record cites: the ratification package carries BOTH a token and an operator signature, side by side. This record describes what each artifact proves and deliberately does not rule which one DEFENSIBLE requires; that ruling is the operator's, not restated, not prejudged."},{"id":"REG-48","status":"OPEN; ruling RESTED with its July 16 precision amendment","why_cited":"Verification is post-quiescence by the specification's semantics; this record was produced under the between-sessions choreography (see session_choreography). The entry closes only when a live-choreography record evaluates fully referee-valid, which this record does not claim (see successor_does_not_claim)."},{"id":"REG-51","status":"OPEN as product work","why_cited":"The interim doctrine was applied here for the second time: the ceremony node's gate matched to the channel the product honors (high-risk, the logged authorization naming the node), the human act preserved in the signature. The product's two-channel out-of-band secret surface remains open work."},{"id":"REG-56","status":"OPEN as product work (Wave 8)","why_cited":"A completed run must be inert. This run obeys the interim procedural rule (no sessions after the run's final verification lines); the engine-level refusal of dispatch over a terminal-carrying witness remains product work and is not claimed here."}],"statement":"v1.0 amends no normative sentence, so no register entry is discharged BY THIS AMENDMENT; the empty list below is that statement, not an omission. The trial this succession binds was closed by the register itself (REG-57, July 16, 2026), on the referee's cold evaluation, before this record existed; a record that claimed the closure as its own work would be reciting another record's figure. The rulings this ceremony operates under are cited below with their register status, none of them discharged here."},"gate_channel":{"rule":"REG-51 (plan ruling, applied here a second time): this ceremony node is HIGH-RISK, and the product's two-channel out-of-band approval secret is deferred in v1, so the gate is the logged-authorization channel.","what_happened":"The run stopped at awaiting_approval and proceeded ONLY on the operator's logged authorization naming the node s4-02-delta-ceremony, delivered through the engine's approval inbox and recorded in the run's audit log. The SIGNATURE over this record is the operator's human act with the authority key, performed through the established signing flow (the key verified to derive the committed public half before it signed, key material never entering this repository); it remains the ceremony's substance whatever the gate's channel count.","what_this_gate_makes_possible":"This is the first live governed record to carry a gated node: every prior live record contained no approval gate, so the referee's R7 condition evaluated vacuously over each of them. Whether R7 moves from vacuous to evaluated is decided by the evaluator over this run's captured witness, after this session; the record states the possibility and claims nothing about the verdict (see successor_does_not_claim)."},"genesis_disclosure":{"predecessor_authorization":"v0.9's Section 15 defines the only ceremony by which this document changes, and this succession is performed under it: object identified by byte digest, authority the named operator, record a signed sidecar the register cites, delta carrying the seven mandatory items, numbered in sequence from 1.","predecessor_authorized_this_amendment":true,"statement":"Succession 4 is NOT genesis and claims no genesis exception. It is the third specification succession governed by a rule that predates it: Section 15's ceremony was introduced by v0.7 and carried intact through v0.8, v0.9, and into the v1.0 text this record seals. Succession 1's disclosure is not softened, removed, or restated here: it remains true of succession 1, and every succession after it being ordinary is exactly what it predicted.","this_is_genesis":false},"invalidated_artifacts":{"classes":[],"classes_note":"COMPUTED ZERO classes: v1.0 amends no tool and no normative sentence; its three text changes are the version line, the ratification history entry, and the closing line. The zero is grounded in the manifest's predecessor comparison (below), not asserted. What this succession replaces is the invalidation manifest itself, exactly as every succession before it did.","manifest_digest":"931dc4ba20dc906ff1c77a052114e4c85616e66f8a0f447232ea86b26b918542","manifest_path":"succession/manifest/invalidation-manifest.json","named_by":"class, with the cited digest of a manifest COMPUTED from the tree by succession/manifest/build-manifest-4.mjs","predecessor_manifest":{"commit":"3013c3757e0a76bf59951d6a1897e03c1b3b66f6","digest":"5c9c530142f7a731e7d1f7e99ecfb01d903b82174e944af1baa3f81388e3e7b5","provenance":"Succession 3's manifest, whose bytes this succession's manifest replaces at the same path. The blob at commit 3013c3757e0a76bf59951d6a1897e03c1b3b66f6 was hashed and required to equal the digest succession-3.json cites BEFORE this record was written, proving these are the bytes succession 3 signed over and that they had not moved since. NOT recomputable from this tree once replaced: recoverable from that commit, exactly as v0.9's spec bytes are recoverable from theirs. tools/succession-verify.mjs reports succession 3's cited manifest digest as RECORDED, NOT VERIFIED now that succession 3 is no longer the latest record (REG-33's lineage rule).","recomputable_from_this_tree":false},"predecessor_members_comparison":{"members_moved":0,"members_recorded":3,"note":"Computed by build-manifest-4.mjs: every member succession 3's manifest recorded was re-hashed from this tree. The computed zero moved-members shows what the ratification succession is: a version line, a history entry, and a closing line, with every tool succession 3 amended or landed standing byte-identical."},"rule":"The manifest MUST be computed and MUST NOT be a hand-typed list: such a list is stale the moment any of its members moves, and a recited figure is not a computed one.","scope_note":"gad-protocol only. atlas-orchestrator and waypoint are NAMED in the manifest, with a stated reason, and are NOT read, NOT hashed, and NOT touched: a graph that amended the specification and its constructor in one run would be the constructor editing its own referee. They are judged against this successor by their own governed runs."},"object":{"document":"docs/gad-formal-spec.md","identified_by":"byte digest of the frozen text, never by version label alone: a label is not an identity (spec Section 15, Object)","successor_digest":"fa2192e1250a743a3e695589eb27c50e14d1ac7a3aeb5aee0bae66e9c708fa18"},"predecessor_record":{"path":"succession/delta/succession-3.json","provenance":"sha256 of succession-3.json's bytes on disk at build time — the record-level chain link, computed and never transcribed. The lineage's continuity is verified by tools/succession-verify.mjs over the spec digests (each predecessor digest equal to the prior successor digest); this figure additionally binds WHICH record bytes this succession chained from.","record_digest":"5e5c2d06f2831f422c1d03da90833b25249857e08fa01ef5e72e303d5b56f376"},"predecessor_spec_digest":{"commit":"e36e3fb6921d614778e2bbad78b5490ef3c960c0","digest":"20daf6004a8eb23344067f216e5f81c85b4ef998c249448fe5042110352dca81","provenance":"succession 3's successor digest, read from succession/delta/succession-3.json rather than transcribed, which is what makes the chain continuous by derivation instead of by assertion. Those bytes are the blob at commit e36e3fb6921d614778e2bbad78b5490ef3c960c0, the last committed tree in which this document was v0.9 (the v1.0 text was uncommitted working-tree state during this ceremony's mid-succession window, committed together with this record); that blob was hashed and required to equal this figure before this record was written. NOT recomputable from this tree once the succession commits: v0.9's bytes leave the working document with v1.0's landing, and tools/succession-verify.mjs reports this figure as RECORDED, NOT VERIFIED rather than implying it rechecked it (REG-33's lineage rule).","recomputable_from_this_tree":false,"version_label":"0.9"},"record":{"cited_by":"docs/gad-spec-register.md","lives_at":"succession/delta/succession-4.json","rule":"The record of a specification succession lives in gad-protocol as a signed sidecar beside this document, and the companion specification register cites it. The register remains the channel through which this document learns that it must change; the succession is how it changes.","verified_by":"tools/succession-verify.mjs"},"record_type":"gad-spec-succession-delta","session_choreography":{"rule":"REG-48 (ruling rested July 16, 2026, with its precision amendment) and REG-54 (the referee's own ruling): verification is post-quiescence by the specification's semantics, and it belongs BETWEEN sessions, in nobody's session, exactly where Algorithm 1 places it; Wave 7's between-sessions verifier is a Movement 2 requirement by the referee's ruling.","what_happened":"This record was built and signed inside a MULTI-NODE SESSION with BETWEEN-SESSIONS verification: the executor claimed and submitted the ceremony node and exited; the recorded verdicts are the supervisor's, computed after quiescence over the captured delta, each verdict lying strictly between its node's execution_result and that node's next dispatch. Producing this record under that choreography is an instance of the ruling, not the referee-valid live-choreography evaluation REG-48's entry still awaits (see successor_does_not_claim)."},"signature_scope":{"construction":"SIGN_x(obj) = {body: obj, signature: sig_x(canon(obj))}; the signature covers the canonical body and is never a member of it.","key":"the operator authority key (RUL-9, RUL-11 clause 2); public half committed at succession/keys/operator-pubkey.json, private half never in this repository","what_this_signature_ATTESTS":"that this delta's text and figures are the ones bound at signing time, and that they have not moved since; that the party who bound them holds a key whose private half has never entered this repository and which names an authority; and that the key was verified to DERIVE the committed public half before it signed (REG-38's derive-based standard, normative since v0.9, applied to its own signing moment). REG-38's checker is run over succession/ after signing and its computed zero is recorded in the exit-gate record beside this ceremony.","what_this_signature_DOES_NOT_ATTEST":"any registry identity beyond the named authority's custody of the key, and no claim that any implementation conforms to the successor. REG-14's key lifecycle design is normative text (v0.9, Profile One) but its implementation remains post-v1.0 and the register entry stays OPEN tracking it; until that implementation lands, a compromised key is handled by succession, not in-place revocation — the interim rule, stated in the specification rather than improvised at the incident. This is the fourth record that rule applies to."},"succession_number":4,"successor_does_not_claim":{"not_claimed":["GENERAL IMPLEMENTATION CONFORMANCE. Ratification asserts record-level conformance of the run 20 envelope under the artifacts the ratification manifest identifies, per that manifest's own scope_of_ratification. No implementation — not the evaluator, not the engine, not the product — is claimed to conform to v1.0 in general.","THAT INDEPENDENT REVIEW HAPPENED. Phase 5's independent formal and cryptographic review is pending, and this succession did not perform it. Section 1's results remain Propositions and Claims, not Theorems, until it completes — the same sentence v1.0's own history entry carries.","THAT R7 EVALUATED NON-VACUOUSLY. This ceremony's approval gate makes the run carrying it the first live record with a gated node, and its acceptance by the evaluator would move R7 from vacuous to evaluated in a live record. That evaluation is the referee's, over the captured witness, after this session; a record that claimed the verdict before the referee computed it would be reciting a figure that does not yet exist.","THAT REG-14 IS IMPLEMENTED. The key lifecycle v0.9 designed (signed lifecycle entries, key_id supersession, forward-looking revocation) still has NO implementation; it remains post-v1.0 by the ruling itself, and the register entry stays OPEN tracking it.","THE REG-47 RULING. The anchor-class question (an RFC 3161 token's WHEN versus an authority signature's WHO) awaits the operator's ruling. This record cites both artifact classes side by side and describes what each proves; it does not rule which one DEFENSIBLE requires, and does not prejudge.","THAT REG-29's GENERATOR HALF CLOSED. The nine invalid fixtures still have no generator, exactly as successions 2 and 3 disclosed; the blessing stands and the generator remains future work.","THAT REG-56's PRODUCT FIX EXISTS. This run obeys the interim procedural rule (a completed run is inert; no sessions after the final verification lines); the engine-level refusal of dispatch over a terminal-carrying witness remains Wave 8 product work.","ANY AUTHORITY OVER THE HISTORICAL RECORDS. Nothing recorded before this succession is reissued, recomputed, or re-read. Every prior version's history entry stands intact as fact, and succession 1's genesis disclosure is neither softened nor restated.","FINALITY. v1.0 is the specification's ratified version, not its last: per the stewardship rule, further revisions arrive from concrete implementation findings through the companion register and Section 15's ceremony, exactly as the four before it did.","THAT THE GENESIS PROBLEM IS SOLVED. Succession 1 disclosed it; this is the third succession that does not face it, which is not the same as solving it."],"statement":"The successor does not claim what follows, and says so here rather than leaving the boundary to be inferred from silence. v1.0 ratifies one trial's record-level results and nothing else."},"successor_spec_digest":{"digest":"fa2192e1250a743a3e695589eb27c50e14d1ac7a3aeb5aee0bae66e9c708fa18","provenance":"sha256 of docs/gad-formal-spec.md as it stands in this tree, recomputed by tools/succession-verify.mjs against the bytes on disk. The version label is PARSED from that same document's header at build time, never recited, so the label cannot contradict the digest beside it (REG-35).","recomputable_from_this_tree":true,"version_label":"1.0"},"trial_0_ratification":{"anchor_token":{"message_imprint":{"algorithm":"sha256","binding":"the imprint's 32 bytes were located inside the token's DER at build time (fail closed had they been absent), so the token stamps the manifest this record cites, not merely a digest someone recorded beside it","value":"27d1eff71e1f812bb92cd7cc0bc90b12eb0d1459e52122f51ce8db5418c80e6c"},"path":"docs/trial-0/trial-0-ratification-anchor.tsr","token_sha256":"7c2c10809e3c1f1e8c6162d8302fcc7026abaec431f81c70812b8c02c9967025","tsa":"https://freetsa.org/tsr","type":"rfc3161","what_the_token_proves":"WHEN the ratification manifest existed, by a third-party clock. WHO stands behind it is the manifest's own operator signature beside it; the two claims are distinct artifact classes and are deliberately not merged (the anchor-class question is REG-47's, awaiting the operator's ruling, and this record does not prejudge it)."},"ratification_manifest":{"canonical_rule":"SHA-256, applied once, over canonicalize(full signed manifest object) per gad-canon-1; this is the digest the anchor's message imprint carries","canonical_sha256":"27d1eff71e1f812bb92cd7cc0bc90b12eb0d1459e52122f51ce8db5418c80e6c","path":"docs/trial-0/trial-0-ratification-manifest.json","raw_file_sha256":"bf875c19df11917601bec916fc779d31d81f5c883262639e0a47dfacb5f1c935","scope":"record-level conformance of the run 20 envelope, per the manifest's own scope_of_ratification; never general implementation conformance","signed_under":"the operator authority key (succession/keys/operator-pubkey.json), signature verified over canon(body) at build time"},"sidecar":{"path":"docs/trial-0/trial-0-ratification-anchor.json","role":"the published record of these same figures; every one of its recorded values was required to EQUAL the computed figure above before this record was written"},"statement":"v1.0 is the ratification succession: Trial 0's record-level results (REG-57, closed July 16, 2026) are bound into this document's own lineage by digest. Every figure below was computed from the bytes under docs/trial-0/ at build time and cross-checked against the anchor sidecar's recorded figures, never retyped; the ratification manifest's operator signature was VERIFIED over its canonical body before it was cited (REG-37: verification is a read); and the manifest's canonical digest was REQUIRED to occur as the message-imprint bytes inside the token's own DER, so the clock demonstrably stamps the manifest cited here. The specification's final version thereby carries its own evidence trail: genesis, three amendments, a trial, a signature, and a clock."}},"signature":"970bd432dd9c490b615bf23b48d45600f79f1a22c9495a2db37a09caa54f34dd885a451380a10eda97e7aa1a959a1a1f94426c141a5e9d461d4aebbe72031c07"}