Origin
A methodology that claims AI-executed work can carry its own proof needs a party that can check the proof without trusting the tool that produced it. If the only evaluator lives inside the orchestrator, "the record verifies" means "the orchestrator says so," which is the self-grading the discipline rejects at the level of the executor and would be reintroducing at the level of the engine. gad-protocol was built as that separate party. It is maintained as a distinct codebase by design. Constructors — any orchestrator implementing the specification — live elsewhere and are judged by the tools here. The evaluator's dependency graph never includes any constructor; it runs on a clean machine against an envelope, a policy, and public keys, nothing else. Trust comes from the record and the recomputation, not from the tool that produced the record.
Design
Every protocol object has a JSON Schema under draft 2020-12 strict mode, with positive and negative examples: plans, witness entries, envelopes, attestations, operators, and policies. The canonical byte form is RFC 8785 with domain tags, published with test vectors, so two independent implementations produce identical bytes for identical objects and digests are reproducible. The node and plan state machines are encoded as a transition table, with one invalid trace committed for every forbidden transition. A predicate registry and evidence-strength rules define the two-axis effective evidence class. A default trust policy (gad4-default) names what GAD-4 defensibility requires. Conformance fixtures are built deterministically with committed development keys that sign fixtures and nothing else: four valid envelopes, one per reachable outcome plus a multi-node session, and nine invalid envelopes, each with one targeted defect per condition R1 through R9 — a mutated byte, a freeze after dispatch, a missing execution result, an unsigned verdict, unprobed proxy credit, an open flag at a verified terminal, an approval after its consequence, a retry over bound, a claim class above its support. gad-evaluate takes an envelope, a policy, and public keys, recomputes everything from the bytes, and emits a signed attestation with a verdict and exit code.
Structure
Every checker behind every script carries a planted-defect probe mode, because a checker that has never been shown to fail has not been shown to check. The Phase 1 exit gate proves the evaluator accepts all four valid fixtures with their expected outcomes, rejects all nine invalid fixtures each by its named condition, that one flipped byte in a core member makes VALID_RECORD false, that an unsupported claim class fails on R9, that adding an attestation produces a successor envelope without mutating the original, and that two independent fixture builds yield an identical root. The succession lineage is the specification's amendment machinery in cryptographic form: each amendment is a signed sidecar delta whose Ed25519 signature verifies under the committed operator authority key, whose seven mandatory items are present, and whose chain is continuous, each record's predecessor digest equal to the prior record's successor digest, with the head recomputed from the specification's actual bytes on disk. The genesis is honestly disclosed: v0.6 did not authorize its own amendment, no artifact claims it did, and the verifier checks that the disclosure has not been softened. The companion register is the specification's only open channel for findings, triaged into four categories, and a ruling there is never an amendment.
Defense
The referee said no to its own makers. Trial 0 audited the reference implementation against the specification with the gap register published either way, and the negative results are recorded as evidence rather than embarrassment. Four governed executions produced no GAD record because protocol mode was never armed; the export reported the absence rather than fabricating a record. Run 15 produced a record the evaluator rejected on R3, seven counts. Run 18 produced a record rejected on R3 and R5. Run 20 produced a record the evaluator accepted, nine of nine conditions, with every formal verdict recomputed by gad-evaluate on a second machine running a different operating system from the producing stack, nothing recited from the producing run's own reports. The same record's byte-flip counterexample is committed: one byte flipped in the witness flips R1 and R2 to FAIL and VALID_RECORD to false. The conformance matrix states its scope of conclusion first — record-level conformance only, for the identified envelope, under the named evaluator, artifacts, keys, and policy — and distinguishes PASS from DEMONSTRATED from VACUOUS PASS from HARNESS-DEMONSTRATED, so a predicate that passed because its trigger never occurred is never presented as exercised. The R4 row states that signature consistency under a supplied key says nothing about the keyholder's organizational identity or custody. The ratification is signed over a manifest that binds the matrix digest together with the specification, lineage head, record roots, anchor token, evaluator, policy, schemas, registries, and open residue — never over the prose alone.
Status
Active. Specification v0.8 at succession-2 on July 15, 2026; v1.3 with successions 1 through 7 by July 17, all seven Ed25519-signed records and their exit-gate records in-repo. Trial 0 Movements 1 through 3 complete: historical records determined not to constitute valid envelopes with nothing backfilled, a live conforming record (run 20, produced by Waypoint and Atlas Orchestrator) accepted on a second machine, and the conformance matrix finalized and digest-bound, with an RFC 3161 timestamp anchor over the record root. Phase 5 independent formal and cryptographic review not begun; until it completes, all results are Propositions and Claims. No license file; the release manifests record the absence as deliberate pending counsel. Normative arm of GAD; judges Atlas Orchestrator and Waypoint records; never depends on either.