Records flow left to right. A record leaves the pipeline unchanged whatever the verdict. Quarantined sources carry zero weight until staged re-entry completes.
Evidence gating and the robust aggregator are separate. AUTHREX-DA feeds the admitted set into the same trimmed-mean estimator used by B-3, so the comparison isolates the gate.
The truth column is evaluation only. It is never read by the decision engine; a runtime guard raises an error if it is.
| Rnd | Source | Record | Truth | IC | CSA | TS | PP | Att | Verdict | Gate | Reason |
|---|
Four channels, each on its own calibrated scale. No cross-channel comparability is assumed: risk R7 is open and no normalization contract has been fixed. A failed hard gate is never hidden behind a mean.
Select any row in the verdict stream. The explanation is reconstructed from the recorded decision data, not narrated after the fact.
Select a verdict row in the Operations tab.
The same record under the AUTHREX-DA hard gates and under the AB-4 weighted score. Where the two disagree, a strong average is masking a failed mandatory condition.
| Record | Failed gate | AUTHREX-DA | AB-4 score | AB-4 verdict | Masked |
|---|
Each contribution carries a summary of the admissibility record of the data that produced it. The layer recomputes that root from its own ledger. A contribution whose summary does not bind is rejected however ordinary the update looks. This is the differentiator for the federated case.
| Round | Node | Window | Admitted fraction | Binding | Verdict | Reason |
|---|
Records that are corrupt by injected ground truth and nevertheless passed every detector-visible gate. These are genuine misses. They are counted in M-1 and retained, not suppressed.
| Round | Source | Record | Injected offset | Ledger entry |
|---|
Every configuration replayed on the identical seed and identical injected scenario. Baselines are implemented in their strongest fair form. B-1 admits every contribution, so its admission metrics are defined. B-3 is a pure estimator with no admission decision at all, so M-1 and M-2 are reported as not applicable to it and it is scored on aggregate error instead. B-4 admission is its ingestion filter alone.
M-1 and M-2 are a matched pair and are always shown together. There is no view in which M-1 appears without M-2.
All targets are PROPOSED. They are not preregistered, no confirmatory run has been executed, and nothing below may be described as confirmed, validated or accepted.
Four phases and a terminal conjunction. A source carries zero weight throughout. Any lapse during re-entry returns it to quarantine and restarts the dwell clock, which is what rate limiting means here.
One cell per round. Legend: N normal, F flagged, Q quarantine, 1 2 3 re-entry phases, T terminal gate, S restored.
Every condition must hold at once. No single strong indicator completes re-entry.
Append-only and hash chained, one entry per verdict, sufficient to reconstruct any decision from its evidence snapshot. This is a browser hash chain. It is tamper evident within this page and is not a hardware root of trust.
| Seq | Rnd | Source | Verdict | Reason | Gate | State before | State after | Prev hash | Entry hash |
|---|
fEff = floor((n - 1) / 3) quorumReq = 2 * fEff + 1 quorumMet = n >= quorumReq The fault bound is derived from the roster size, and the roster size is then compared against a threshold built from that bound. A test whose threshold is a function of its own input can only report on itself.
f = independent assumption about the adversary (an INPUT) rosterOK = n >= 3f + 1 quorumReq = 2f + 1 quorumMet = rosterOK AND attestations >= quorumReq
With the circular check every roster passes, including a roster of one. Under the repaired check with an adversary assumption of at least one fault, a one-agent roster is rejected.
A property is never marked as holding because the JavaScript behaved as intended. Simulation status and model-checking status are separate columns and are never merged.
These are part of the research record. None of them is resolved by this preview.
Requirement tests, attack tests, anti-tautology mutation tests and replay tests. The mutation tests deliberately break each load-bearing behaviour and require the corresponding test to change result, which is what makes those tests non-tautological.
Same seed and same configuration reproduce the same trace and the same ledger root. The root is a behavioural fingerprint and a reproducibility aid. It is not proof of authenticity.
A single view of where the run stands. Every figure is computed from the current run; none is written into this page.
Each channel forced to pass in both the admission gate and the recovery conditions, with the whole battery re-run on the same seed and the same injected faults. The delta is what the channel causes. Direct gate attribution is not causal contribution, and a channel that fails alongside another failing condition causes nothing.
The analysis re-runs the whole battery once per channel, so it is not instant. The round count is shown on the result, because a 60-round causal reading is not the same measurement as the 120-round one in results/CHARACTERIZATION.md.
Select a row in the Operations verdict stream, then return here.
No record selected.
Built entirely from the audit record, so it describes what the run did rather than what it intended. The graph hash is deterministic for a given seed and configuration.
Select a contribution.
What this answers is how far evidence authority degrades when the environment stops cooperating: whether the layer can still evaluate, whether it can admit at full authority, whether it is reduced to the flag cap, and whether it admits nothing at all.