AUTHREX-DA Data Admissibility Layer release build ... PROPOSED / ENGINEERING PREVIEW
Epistemic status. This console is an engineering preview. It is not a WP-3 exit, its runs are not WP-4 confirmatory evidence, and none of its numbers are preregistered results. All data is synthetic and seeded. Nothing here has been tested on physical hardware, fielded, certified, or verified by an independent party. No TRL determination is claimed. The governed object is a data record or model contribution. The layer emits verdicts and reasons; it never modifies, imputes, reconstructs or repairs a payload. Robust aggregation is prior art and is used, not claimed.

Operations

Records flow left to right. A record leaves the pipeline unchanged whatever the verdict. Quarantined sources carry zero weight until staged re-entry completes.

↓ quarantined sources

Sources

Aggregation at the current round

Evidence gating and the robust aggregator are separate. AUTHREX-DA feeds the admitted set into the same trimmed-mean estimator used by B-3, so the comparison isolates the gate.

Verdict stream

The truth column is evaluation only. It is never read by the decision engine; a runtime guard raises an error if it is.

RndSourceRecordTruthICCSATSPPAttVerdictGateReason

Evidence and decision

Four channels, each on its own calibrated scale. No cross-channel comparability is assumed: risk R7 is open and no normalization contract has been fixed. A failed hard gate is never hidden behind a mean.

Channel inspector

Explain this decision

Select any row in the verdict stream. The explanation is reconstructed from the recorded decision data, not narrated after the fact.

Select a verdict row in the Operations tab.

Non-compensatory against compensatory

The same record under the AUTHREX-DA hard gates and under the AB-4 weighted score. Where the two disagree, a strong average is masking a failed mandatory condition.

RecordFailed gateAUTHREX-DAAB-4 scoreAB-4 verdictMasked

IF-4 model contribution binding

Each contribution carries a summary of the admissibility record of the data that produced it. The layer recomputes that root from its own ledger. A contribution whose summary does not bind is rejected however ordinary the update looks. This is the differentiator for the federated case.

RoundNodeWindowAdmitted fractionBindingVerdictReason

DA-P2 demonstration, ground-truth admission soundness

Records that are corrupt by injected ground truth and nevertheless passed every detector-visible gate. These are genuine misses. They are counted in M-1 and retained, not suppressed.

RoundSourceRecordInjected offsetLedger entry

Comparison mode

Every configuration replayed on the identical seed and identical injected scenario. Baselines are implemented in their strongest fair form. B-1 admits every contribution, so its admission metrics are defined. B-3 is a pure estimator with no admission decision at all, so M-1 and M-2 are reported as not applicable to it and it is scored on aggregate error instead. B-4 admission is its ingestion filter alone.

Metrics

M-1 and M-2 are a matched pair and are always shown together. There is no view in which M-1 appears without M-2.

Current configuration

Hypotheses

All targets are PROPOSED. They are not preregistered, no confirmatory run has been executed, and nothing below may be described as confirmed, validated or accepted.

Exploratory observations

Quarantine and staged re-entry

Four phases and a terminal conjunction. A source carries zero weight throughout. Any lapse during re-entry returns it to quarantine and restarts the dwell clock, which is what rate limiting means here.

Per-source state timeline

One cell per round. Legend: N normal, F flagged, Q quarantine, 1 2 3 re-entry phases, T terminal gate, S restored.

Terminal gate conditions

Every condition must hold at once. No single strong indicator completes re-entry.

Re-entry gaming

Audit record

Append-only and hash chained, one entry per verdict, sufficient to reconstruct any decision from its evidence snapshot. This is a browser hash chain. It is tamper evident within this page and is not a hardware root of trust.

SeqRndSourceVerdictReasonGateState beforeState afterPrev hashEntry hash

WP-0 quorum repair

This view does not substitute for the TLC result. It illustrates the two formulations. The model-checking result is reported in the Assurance tab, and it comes from a new candidate model, not from a re-check of the historical artifact, which was not supplied.

Circular formulation, as published

fEff      = floor((n - 1) / 3)
quorumReq = 2 * fEff + 1
quorumMet = n >= quorumReq

The fault bound is derived from the roster size, and the roster size is
then compared against a threshold built from that bound. A test whose
threshold is a function of its own input can only report on itself.

Repaired formulation

f          = independent assumption about the adversary   (an INPUT)
rosterOK   = n >= 3f + 1
quorumReq  = 2f + 1
quorumMet  = rosterOK AND attestations >= quorumReq

Side by side over roster size

With the circular check every roster passes, including a roster of one. Under the repaired check with an adversary assumption of at least one fault, a one-agent roster is rejected.

Assurance

Formal obligations

A property is never marked as holding because the JavaScript behaved as intended. Simulation status and model-checking status are separate columns and are never merged.

Candidate quorum model, TLC results

Requirements

Open limitations

These are part of the research record. None of them is resolved by this preview.

Test suite

Requirement tests, attack tests, anti-tautology mutation tests and replay tests. The mutation tests deliberately break each load-bearing behaviour and require the corresponding test to change result, which is what makes those tests non-tautological.

Reproducibility manifest

Same seed and same configuration reproduce the same trace and the same ledger root. The root is a behavioural fingerprint and a reproducibility aid. It is not proof of authenticity.

Mission assurance status

A single view of where the run stands. Every figure is computed from the current run; none is written into this page.

Source posture

Self-assessed engineering readiness

Causal evidence contribution

Each channel forced to pass in both the admission gate and the recovery conditions, with the whole battery re-run on the same seed and the same injected faults. The delta is what the channel causes. Direct gate attribution is not causal contribution, and a channel that fails alongside another failing condition causes nothing.

The analysis re-runs the whole battery once per channel, so it is not instant. The round count is shown on the result, because a 60-round causal reading is not the same measurement as the 120-round one in results/CHARACTERIZATION.md.

Purpose-bound authorization

Bounded by construction. This layer answers what an admitted record may be used for, which is a strictly narrower question than whether it is admissible. It can only remove permissions. It never adds authority, never overrides a gate and never revisits a denial. A test exhausts the decision space to confirm that no use is ever authorized above the base verdict. Every threshold in it is PROPOSED and none is established.

Authorization across the current run

Selected record

Select a row in the Operations verdict stream, then return here.

No record selected.

Provenance, lineage and data bill of materials

Built entirely from the audit record, so it describes what the run did rather than what it intended. The graph hash is deterministic for a given seed and configuration.

Data bill of materials

Lineage

Which records stand behind a contribution

Select a contribution.

Contested and degraded operations

Overlays, never scenarios. A scenario carrying a second fault is no longer an isolated experiment, so these conditions are applied as explicit overlays on the benign control population. With no overlay requested the engine trace is bit identical, which a test enforces against the archived canonical ledger root.

What this answers is how far evidence authority degrades when the environment stops cooperating: whether the layer can still evaluate, whether it can admit at full authority, whether it is reduced to the flag cap, and whether it admits nothing at all.

Assurance evidence package

What this is not. Not a certification, an accreditation, an authorization, a TRL determination, an acquisition rating or an endorsement by any organization. All data is synthetic. Rev 1.1 reserves DEMONSTRATED for an archived result carrying a public DOI or a dated tool log. Nothing here is archived under that rule. Nothing here is archived under that rule, so no row claims it. TEST_PASS_LOCAL means an automated test passed on synthetic data on this machine, PARTIAL_LOCAL means the same with a stated coverage gap, and the evidence class is PROPOSED throughout.

Requirements traceability

Negative results retained

Package manifest