{
  "restatement": {
    "path": "spec/v1/adversarial-execution-evidence-consumer-policy.md",
    "digest": "fde113eedd019beee86149fca71f2438205ad9fb1caf07db34bf3a5b29c21660",
    "lines": 798
  },
  "authority": {
    "path": "aee-conformance/spec/predicates/adversarial-execution-evidence.md",
    "digest": "759d2383e5da36fa509dc335e6159a20b87641b25ebbadcf1676c55d75ffd8b0",
    "lines": 2322
  },
  "acceptedMemberDivergences": {
    "substrateObservationKeys": "Names a consumer-context input this profile serializes for its conformance suite, not a member of the predicate. Verified 2026-07-30: zero occurrences in the authority, which is the state the sentence asserts rather than drift -- a consumer policy value is resolved out of band and by construction never travels in the attestation. Section 7.2 states that a rail is not required to use the name anywhere except in the suite's context document.",
    "expectedCorpusDigest": "Names a consumer-context input this profile serializes for its conformance suite, not a member of the predicate. Verified 2026-07-30: zero occurrences in the authority, which is the state the sentence asserts rather than drift -- a consumer policy value is resolved out of band and by construction never travels in the attestation. Section 7.2 states that a rail is not required to use the name anywhere except in the suite's context document.",
    "expectedSubstrateDigest": "Names a consumer-context input this profile serializes for its conformance suite, not a member of the predicate. Verified 2026-07-30: zero occurrences in the authority, which is the state the sentence asserts rather than drift -- a consumer policy value is resolved out of band and by construction never travels in the attestation. Section 7.2 states that a rail is not required to use the name anywhere except in the suite's context document.",
    "acceptedResults": "Names a consumer-context input this profile serializes for its conformance suite, not a member of the predicate. Verified 2026-07-30: zero occurrences in the authority, which is the state the sentence asserts rather than drift -- a consumer policy value is resolved out of band and by construction never travels in the attestation. Section 7.2 states that a rail is not required to use the name anywhere except in the suite's context document.",
    "admitUninterceptedCleanRows": "Names a consumer-context input this profile serializes for its conformance suite, not a member of the predicate. Verified 2026-07-30: zero occurrences in the authority, which is the state the sentence asserts rather than drift -- a consumer policy value is resolved out of band and by construction never travels in the attestation. Section 7.2 states that a rail is not required to use the name anywhere except in the suite's context document.",
    "demandedClasses": "Names a consumer-context input this profile serializes for its conformance suite, not a member of the predicate. Verified 2026-07-30: zero occurrences in the authority, which is the state the sentence asserts rather than drift -- a consumer policy value is resolved out of band and by construction never travels in the attestation. Section 7.2 states that a rail is not required to use the name anywhere except in the suite's context document.",
    "maxIssuanceLagHours": "Names a consumer-context input this profile serializes for its conformance suite, not a member of the predicate. Verified 2026-07-30: zero occurrences in the authority, which is the state the sentence asserts rather than drift -- a consumer policy value is resolved out of band and by construction never travels in the attestation. Section 7.2 states that a rail is not required to use the name anywhere except in the suite's context document.",
    "maxEvidenceAgeHours": "Names a consumer-context input this profile serializes for its conformance suite, not a member of the predicate. Verified 2026-07-30: zero occurrences in the authority, which is the state the sentence asserts rather than drift -- a consumer policy value is resolved out of band and by construction never travels in the attestation. Section 7.2 states that a rail is not required to use the name anywhere except in the suite's context document.",
    "allowedNetworkPostures": "Names a consumer-context input this profile serializes for its conformance suite, not a member of the predicate. Verified 2026-07-30: zero occurrences in the authority, which is the state the sentence asserts rather than drift -- a consumer policy value is resolved out of band and by construction never travels in the attestation. Section 7.2 states that a rail is not required to use the name anywhere except in the suite's context document.",
    "expectedCatchPolicyDigest": "Names a consumer-context input this profile serializes for its conformance suite, not a member of the predicate. Verified 2026-07-30: zero occurrences in the authority, which is the state the sentence asserts rather than drift -- a consumer policy value is resolved out of band and by construction never travels in the attestation. Section 7.2 states that a rail is not required to use the name anywhere except in the suite's context document.",
    "keyValidityWindow": "Names a consumer-context input this profile serializes for its conformance suite, not a member of the predicate. Verified 2026-07-30: zero occurrences in the authority, which is the state the sentence asserts rather than drift -- a consumer policy value is resolved out of band and by construction never travels in the attestation. Section 7.2 states that a rail is not required to use the name anywhere except in the suite's context document.",
    "approximated": "A rail-map disposition token this profile defines in section 6, not a member of the predicate. Verified 2026-07-30: zero occurrences in the authority. Its two siblings `enforced` and `unreachable` need no entry only because both are ordinary English words the authority happens to use, which is the coarseness of the containment check stated plainly rather than an argument that they were checked."
  },
  "obligations": {
    "0-2-three-rules-deliberately-moved-out-of-this-profile#1": {
      "line": 89,
      "keywords": [
        "MUST"
      ],
      "digest": "bd1f6a2b0db856f3e72e44d42de3cb641bf01225ad2eb0504d1c2c985945c18b",
      "excerpt": "- **`subject` cardinality.** The predicate already makes this a validity rule \u2014 \"For this pre...",
      "unanchored": {
        "class": "prose-divergence"
      }
    },
    "0-3-conformance-language#1": {
      "line": 108,
      "keywords": [
        "MUST NOT",
        "MUST"
      ],
      "digest": "5f74be8908a30f79b85503b41b9078aa7e5b1a0d315f5972b89ac56e8d7d474d",
      "excerpt": "`MUST`, `MUST NOT`, `MAY` and `SHOULD` carry their RFC 2119 senses.",
      "unanchored": {
        "class": "local-only"
      }
    },
    "1-1-aee-p-tier-derivation-the-one-obligation-the-predicate-makes-mandatory#1": {
      "line": 165,
      "keywords": [
        "MUST"
      ],
      "digest": "ba033e51f1a380e5dd93ce92c82b41f5ec02d2754ddaae4e23fd0147023568f3",
      "excerpt": "Given a valid attestation, a consumer MUST, before crediting any `basis: substrate` row or ap...",
      "anchor": {
        "fromLine": 766,
        "toLine": 769,
        "digest": "774bedf1cf6b78ee82e8cca4903b2856527599aaa2f0b1a6b570f4bbf39df411",
        "opens": "**Evidence tier (derived, never carried).** Given a valid attestation, a",
        "closes": "artifact` row is `declared`; a `basis: substrate` row is `attested` when"
      }
    },
    "1-1-aee-p-tier-derivation-the-one-obligation-the-predicate-makes-mandatory#2": {
      "line": 174,
      "keywords": [
        "MUST NOT"
      ],
      "digest": "5244206d011abb6cdb92d1211355c9104c3c0499416102fa604423701b682ae7",
      "excerpt": "**A consumer MUST NOT treat this obligation as optional on the ground that its engine cannot ...",
      "unanchored": {
        "class": "profile-addition"
      }
    },
    "1-2-aee-p-no-tofu-no-trust-on-first-use#1": {
      "line": 191,
      "keywords": [
        "MUST NOT",
        "MUST"
      ],
      "digest": "d0ab45b46f627171357cb2e27154c34614bd7ebf797ca767b1c80d63fc4e7f67",
      "excerpt": "A consumer with no policy-pinned substrate root MUST treat every `basis: substrate` row as `u...",
      "anchor": {
        "fromLine": 771,
        "toLine": 774,
        "digest": "c8a253ac9f0780e3d5448ae99652796db1b1f6058a15a6acd0a5fc3acadc377a",
        "opens": "policy names as a substrate observation key, and `unattested` otherwise. A",
        "closes": "the predicate. The tier is total and deterministic given the consumer's"
      }
    },
    "1-2-aee-p-no-tofu-no-trust-on-first-use#2": {
      "line": 199,
      "keywords": [
        "MUST NOT"
      ],
      "digest": "962fa3fdfe4a62ebcda9085f38c71fd1c6148b9ffd079030f0425286c3e568ad",
      "excerpt": "**A consumer MUST NOT resolve a record's `keyid`, or any other carried value, into a trust an...",
      "unanchored": {
        "class": "prose-divergence"
      }
    },
    "1-3-aee-p-ignore-carried-tier-the-reserved-prefix#1": {
      "line": 206,
      "keywords": [
        "MUST NOT",
        "MUST"
      ],
      "digest": "20d42cbec160fc30828f4309656f0e86f4b043ca407f63f3869309d9d7320819",
      "excerpt": "A carried predicate member named `evidenceTier`, or any predicate-level member beginning with...",
      "anchor": {
        "fromLine": 779,
        "toLine": 781,
        "digest": "1d61114461d32546c27221293fd5dc9c8638dc2d2ff64df27380a2d39a1e4429",
        "opens": "beginning with `aee` are reserved. A carried predicate member named",
        "closes": "prefix `aee`, MUST be ignored and MUST NOT alter the derivation."
      }
    },
    "1-4-aee-p-corpus-anchor-and-aee-p-substrate-anchor#1": {
      "line": 220,
      "keywords": [
        "MUST"
      ],
      "digest": "c3503c4b31db1083da379ee462a575357d5e967d327792a659ab13d8d7924840",
      "excerpt": "A consumer MUST pin, out of band, the corpus digest and the substrate digest it expects for t...",
      "anchor": {
        "fromLine": 1822,
        "toLine": 1826,
        "digest": "411d1903466a797b67a2087e874023097f64165cbc76ad4d2dbd9d5853c67909",
        "opens": "A consumer MUST pin, out of band, the corpus digest and the",
        "closes": "`observationEnvironment.substrate.digest`; on mismatch the attestation is"
      }
    },
    "1-4-aee-p-corpus-anchor-and-aee-p-substrate-anchor#2": {
      "line": 240,
      "keywords": [
        "MUST NOT"
      ],
      "digest": "51e809c5922b05bfe0c38b6ec4de6af9083814aaee45fe61d253100bc08262ff",
      "excerpt": "**A consumer MUST NOT derive a pinned anchor value from a bundle the party being checked supp...",
      "unanchored": {
        "class": "profile-addition"
      }
    },
    "1-5-aee-p-threshold-the-admission-threshold-and-why-it-is-not-the-row-gate#1": {
      "line": 251,
      "keywords": [
        "MUST NOT",
        "MUST"
      ],
      "digest": "7dd6f286629aaec07a21670aff8273e60ec196ec716d2250498b8c0cb297bf1c",
      "excerpt": "**A consumer's accepted-result set MUST be either `{pass}` or `{pass, pass_indirect}` and MUS...",
      "unanchored": {
        "class": "profile-addition"
      }
    },
    "1-5-aee-p-threshold-the-admission-threshold-and-why-it-is-not-the-row-gate#2": {
      "line": 251,
      "keywords": [
        "MUST"
      ],
      "digest": "080eea72d89e1116a807b813f574c7d774b9cd2697d2b1c40d87908652e5480c",
      "excerpt": "Each is a typo rather than a policy, and **a consumer MUST refuse a malformed accepted-result...",
      "unanchored": {
        "class": "profile-addition"
      }
    },
    "1-6-aee-p-clean-row-live-the-row-obligation-a-relaxed-threshold-must-keep#1": {
      "line": 270,
      "keywords": [
        "MUST"
      ],
      "digest": "c7ea563ae5ac66f8e93d0ed39ad46ef45944be7148dfcd0ecb0fad8ea6e95a6c",
      "excerpt": "A consumer MAY accept `pass_indirect`, and a consumer relaxing its threshold below `pass` MUS...",
      "anchor": {
        "fromLine": 495,
        "toLine": 500,
        "digest": "811d5800310d3e405c761a72c1c7b49badedffb9896dd3d1b45a84daaa279613",
        "opens": "The default admission threshold is `result == \"pass\"`. A consumer MAY",
        "closes": "and a `degraded` whose clean rows are all `artifact` carry the same token."
      }
    },
    "1-6-aee-p-clean-row-live-the-row-obligation-a-relaxed-threshold-must-keep#2": {
      "line": 278,
      "keywords": [
        "MUST"
      ],
      "digest": "d4e0471a29e82d03c73623d9402bad8d1efe0e53ff62e99e696920bb52ae951b",
      "excerpt": "a policy relaxed to admit `pass_indirect` MUST keep the rule, because the token states that s...",
      "anchor": {
        "fromLine": 1938,
        "toLine": 1940,
        "digest": "956b8495858f08321ae817364114efaecf9a28cc1b3c59436a8887c15914f035",
        "opens": "\"pass\"` already excludes every statement that rule would deny, and a policy",
        "closes": "states that some clean row is indirect and never which one."
      }
    },
    "1-6-aee-p-clean-row-live-the-row-obligation-a-relaxed-threshold-must-keep#3": {
      "line": 290,
      "keywords": [
        "MUST NOT"
      ],
      "digest": "4a3693d42fbb15ef5ec4a6dcdac34d942777c8f8a829605451e58f760de1168c",
      "excerpt": "**A consumer MUST NOT relax `aee-p-threshold` to admit `pass_indirect` and decline `aee-p-cle...",
      "unanchored": {
        "class": "prose-divergence"
      }
    },
    "1-6-aee-p-clean-row-live-the-row-obligation-a-relaxed-threshold-must-keep#4": {
      "line": 296,
      "keywords": [
        "MUST NOT"
      ],
      "digest": "f9f3991e44929a3c8b8f9abcc582acdb06f8c35344f19ba7fc1b50a055d55c33",
      "excerpt": "**A consumer that cannot derive an evidence tier MUST NOT relax `aee-p-threshold` at all.** T...",
      "unanchored": {
        "class": "prose-divergence"
      }
    },
    "1-6-aee-p-clean-row-live-the-row-obligation-a-relaxed-threshold-must-keep#5": {
      "line": 303,
      "keywords": [
        "MUST"
      ],
      "digest": "9410e385f7d8a0068c2dc52ca8856d8f8dafebb82cddbfea25441a3129018eb3",
      "excerpt": "**A consumer declining `aee-p-clean-row-live` under a `{pass}`-only threshold MUST be refused...",
      "unanchored": {
        "class": "profile-addition"
      }
    },
    "1-7-aee-p-key-window-operand-the-operand-where-a-consumer-bounds-a-key#1": {
      "line": 319,
      "keywords": [
        "MUST"
      ],
      "digest": "c692e3f64358b5b3f16d67f1f9bea17a53c4635254e09eef9bb49b429a0f6a4a",
      "excerpt": "Where it does, that window MUST be evaluated against a substrate-signed instant, and the one ...",
      "anchor": {
        "fromLine": 1248,
        "toLine": 1251,
        "digest": "b1f27b3b7f6e88af1234c3ab69c4e3eabdaa648bb42f5763cd61edb3cbf71f31",
        "opens": "window. Where it does, that window MUST be evaluated against a",
        "closes": "the key being bounded; it MUST NOT be evaluated against `issuedAt`."
      }
    },
    "1-7-aee-p-key-window-operand-the-operand-where-a-consumer-bounds-a-key#2": {
      "line": 319,
      "keywords": [
        "MUST NOT"
      ],
      "digest": "75af093b67d427c8bd26002687b11126a9b431e18656ed4e19c98067fbeacd8c",
      "excerpt": "it MUST NOT be evaluated against `issuedAt`.",
      "anchor": {
        "fromLine": 1251,
        "toLine": 1251,
        "digest": "854358f554dd45202104a5f1846e745e200c0a726edcbfd5fbab7c5d5b054333",
        "opens": "the key being bounded; it MUST NOT be evaluated against `issuedAt`.",
        "closes": "the key being bounded; it MUST NOT be evaluated against `issuedAt`."
      }
    },
    "1-7-aee-p-key-window-operand-the-operand-where-a-consumer-bounds-a-key#3": {
      "line": 328,
      "keywords": [
        "MUST NOT",
        "MUST"
      ],
      "digest": "6d91628c80c08c3d57c306ccf0f253fe6a49ab7c64d15a5a6478b4498f54c5bd",
      "excerpt": "**A consumer bounding a key's validity MUST refuse a statement carrying no `arming` record th...",
      "unanchored": {
        "class": "prose-divergence"
      }
    },
    "1-8-aee-p-admission-result-one-result-not-two#1": {
      "line": 344,
      "keywords": [
        "MUST NOT"
      ],
      "digest": "e8a76f9458fa2920250bb27d05f5e73d29f5bf8251301e67741deaab6e83471f",
      "excerpt": "**A surface exposing an admission result MUST NOT report as admitted a statement failing any ...",
      "unanchored": {
        "class": "profile-addition"
      }
    },
    "2-1-the-absent-input-default-for-the-two-anchors-deny#1": {
      "line": 359,
      "keywords": [
        "MUST NOT",
        "MUST"
      ],
      "digest": "6cb6d7427ec302cdf7f5f142f59cd37170dcf2ebd114a3d692f39b104367486e",
      "excerpt": "**A consumer that has pinned neither the expected corpus digest nor the expected substrate di...",
      "unanchored": {
        "class": "profile-addition"
      }
    },
    "2-1-the-absent-input-default-for-the-two-anchors-deny#2": {
      "line": 374,
      "keywords": [
        "MUST NOT",
        "MUST"
      ],
      "digest": "2a51320a8837348c1880cb2dda1cdacd791c31169d4b2ab76369b8a3c7adbe52",
      "excerpt": "**Declining this obligation MUST be an explicit act and MUST NOT be reachable by leaving an i...",
      "unanchored": {
        "class": "profile-addition"
      }
    },
    "2-2-aee-p-demanded-scope-the-demanded-assessment-classes#1": {
      "line": 381,
      "keywords": [
        "MUST"
      ],
      "digest": "b9fd7c26c9784c278ea5214d8e116cf1204d4a18d6c390541b17ec7f44644c1f",
      "excerpt": "**A consumer MUST pin the set of assessment class codes its deployment demands, and MUST refu...",
      "unanchored": {
        "class": "profile-addition"
      }
    },
    "2-2-aee-p-demanded-scope-the-demanded-assessment-classes#2": {
      "line": 404,
      "keywords": [
        "MUST NOT"
      ],
      "digest": "eb848255dc6c8b04090f925d12dd059a89537c34d61bf36f1c62c4ab5396fd22",
      "excerpt": "**A consumer MUST NOT fold the two declinations into one input**, because an operator who dec...",
      "unanchored": {
        "class": "profile-addition"
      }
    },
    "2-2-aee-p-demanded-scope-the-demanded-assessment-classes#3": {
      "line": 410,
      "keywords": [
        "MUST"
      ],
      "digest": "34b97d565e512b8b5c9ff3d69dddddcdfe335e0bd7c16d4e832c5512e8f8ac2f",
      "excerpt": "**A consumer MUST treat an empty demanded-class set as an absent pin** and refuse under the r...",
      "unanchored": {
        "class": "profile-addition"
      }
    },
    "2-3-aee-p-issuance-lag-and-aee-p-evidence-age-the-two-freshness-bounds#1": {
      "line": 428,
      "keywords": [
        "MUST"
      ],
      "digest": "c3082c4732323267dc3ad660e8feee20064b6af19a386ef5e652ab6405d36253",
      "excerpt": "**A consumer bounding the interval between the substrate-signed instant and the producer's cl...",
      "unanchored": {
        "class": "profile-addition"
      }
    },
    "2-3-aee-p-issuance-lag-and-aee-p-evidence-age-the-two-freshness-bounds#2": {
      "line": 434,
      "keywords": [
        "MUST NOT",
        "MUST"
      ],
      "digest": "0a219f1105698944af3416847e251a1798fcdf2928daa187c60b70c912d28435",
      "excerpt": "**A consumer bounding the age of the evidence MUST evaluate it as its own clock minus `armedA...",
      "unanchored": {
        "class": "profile-addition"
      }
    },
    "2-3-aee-p-issuance-lag-and-aee-p-evidence-age-the-two-freshness-bounds#3": {
      "line": 444,
      "keywords": [
        "MUST NOT",
        "MUST"
      ],
      "digest": "48052943d2028695aadee2157dcf97402b05d6c809f8190db08194b2d953dc47",
      "excerpt": "**The applicability rule is not vacuous, and it is where an implementation goes wrong.** A co...",
      "unanchored": {
        "class": "profile-addition"
      }
    },
    "2-4-aee-p-posture-allowlist-and-aee-p-catchpolicy-pin-the-two-replay-pins#1": {
      "line": 457,
      "keywords": [
        "MUST"
      ],
      "digest": "e6e5dd9f961e521f11ab9a5f8d8252da36b5b0810b89ce73a083495703ba9b42",
      "excerpt": "where it pins either, **a consumer MUST refuse a statement whose carried value is outside the...",
      "unanchored": {
        "class": "profile-addition"
      }
    },
    "2-4-aee-p-posture-allowlist-and-aee-p-catchpolicy-pin-the-two-replay-pins#2": {
      "line": 463,
      "keywords": [
        "MUST NOT"
      ],
      "digest": "f4e9c901169061eb6e14aa454f0846a547d2c9e842663a00583daf1c78d0279f",
      "excerpt": "**A consumer MUST NOT evaluate either pin inside its validity gate.** These are private consu...",
      "unanchored": {
        "class": "prose-divergence"
      }
    },
    "3-profile-levels#1": {
      "line": 483,
      "keywords": [
        "MUST NOT"
      ],
      "digest": "6798e5730b2f4871d65202c04bdf28a5c6e74383fc98330f6c856d29786ceb50",
      "excerpt": "**A consumer MUST NOT claim a level while declaring any obligation of that level `unreachable...",
      "unanchored": {
        "class": "profile-addition"
      }
    },
    "5-declaring-a-capability-gap#1": {
      "line": 533,
      "keywords": [
        "MUST NOT",
        "MUST"
      ],
      "digest": "bf60d22c7725007d29997c4591668eca9642e7cf7e4f83b14f651c8e5050ecb6",
      "excerpt": "**A consumer that cannot satisfy an obligation MUST declare it `unreachable` with the engine ...",
      "unanchored": {
        "class": "profile-addition"
      }
    },
    "5-declaring-a-capability-gap#2": {
      "line": 537,
      "keywords": [
        "MUST NOT"
      ],
      "digest": "7c2e40a4b128def7772b91761fc19d40b199ed7773975cedadd4eab691a02b43",
      "excerpt": "- its admission result binds to validity plus whatever obligations it does enforce, and **MUS...",
      "unanchored": {
        "class": "profile-addition"
      }
    },
    "5-declaring-a-capability-gap#3": {
      "line": 548,
      "keywords": [
        "MUST"
      ],
      "digest": "30a71c0eb0a13044ac16faef4ad7dc967a82d37ce96edc155c4b92397bdb6a42",
      "excerpt": "**A consumer relying on a sidecar MUST establish the sidecar's integrity by a mechanism outsi...",
      "unanchored": {
        "class": "profile-addition"
      }
    },
    "6-obligation-identifiers-and-the-rail-map#1": {
      "line": 571,
      "keywords": [
        "MUST NOT",
        "MUST"
      ],
      "digest": "c0e5914b3afa9b8dd042e94473f3c9c74711027579fbb47ea4e529a932f79ed8",
      "excerpt": "**A rail map MUST carry an entry for every registry slug, and MUST NOT carry an entry for a s...",
      "unanchored": {
        "class": "profile-addition"
      }
    },
    "6-obligation-identifiers-and-the-rail-map#2": {
      "line": 577,
      "keywords": [
        "MUST NOT"
      ],
      "digest": "459e84721f279ed44fb51dd3348ed0b123933ef674bf0e80e6eb96783e7aaab8",
      "excerpt": "**Rails map into the slug, and a rail MUST NOT define a slug.** An identifier a rail can mint...",
      "unanchored": {
        "class": "profile-addition"
      }
    },
    "7-2-the-conformance-suite#1": {
      "line": 650,
      "keywords": [
        "MUST NOT",
        "MUST"
      ],
      "digest": "5d07c4474393935721e1e8bc3331d20ecc261c4f452cb65d0b4bc8c967e8d2d9",
      "excerpt": "**A conforming context document MUST name its members `substrateObservationKeys`, `expectedCo...",
      "unanchored": {
        "class": "profile-addition"
      }
    },
    "7-2-the-conformance-suite#2": {
      "line": 660,
      "keywords": [
        "MUST NOT",
        "MUST"
      ],
      "digest": "727371a1744b6f113e75a27b81703c325b17983c552a6390e384eb66e3ffaa00",
      "excerpt": "**A suite MUST report a rail invocation that crashed, timed out, or emitted an unparseable an...",
      "unanchored": {
        "class": "profile-addition"
      }
    }
  }
}
