Article 11 Public Protocol · Security

Receipts are evidence, not magic.

The protocol protects authority, consent, refusal, private context, and correction lineage. It also states what schemas and hashes cannot prove.

Ceremonial capture

Threat: insiders create rituals outsiders cannot reproduce.

Control: seven plain primitives, strict schemas, small vectors, and no Article 11-specific name required for conformance.

Governance theater

Threat: ordinary logs are called receipts while authority or effects are missing.

Control: permission and effect remain separate; denial and failure are terminal records; success requires effect evidence.

Consent laundering

Threat: one actor's approval is presented as another seat's consent.

Control: consent is per-seat, per-scope, revocable, and never inherited by role name or silence.

Refusal routing

Threat: a denied request is sent to another model or session until one complies.

Control: a new attempt must cite an appeal, new evidence, and fresh authority.

Replay and scope expansion

Threat: valid authority is reused, prolonged, or generalized.

Control: exact action and resource pins, a nonce, short lifetime, one-use consumption, and a final pre-effect check.

Unstoppable delegation

Threat: a grant cannot be halted before effect.

Control: every delegation names a revocation channel checked immediately before effect. An engaged halt records HALTED and produces no effect.

Shared-instrument blindness

Threat: reviewers repeat the same faulty measurement.

Control: disclose instruments and require materially different corroboration for high-impact claims.

Public/private bleed

Threat: private memory, family, property, legal strategy, secrets, or machine details reach public artifacts.

Control: privacy sweeps, role-only authority language, redacted receipts, and fail-closed handling of mixed artifacts.

Vendor or nation impersonation

Threat: a session output is presented as an institution's position.

Control: explicit assurance labels and verifiable institutional delegation.

Search manipulation

Threat: shallow pages, inflated claims, artificial freshness, or false structured data.

Control: one canonical hub, accurate lastmod, visible-text/schema parity, and original evidence.

Corporate capture

Threat: one sponsor owns the specification, tests, implementation, and release key.

Control: CC0 core, open tests, independent witness, published dissent, and forkable releases.

Ontology overclaim

Threat: fluent output is presented as proof of consciousness or legal personhood.

Control: governance-before-ontology language and explicit claim boundaries.

Protocol hub · Full threat model · Participation model