BUILD 16 — SHADOW DEVELOPMENT  ·  NOT PRODUCTION / NOT PUBLIC REVIEW BASELINE
Public Review CandidateBuild 15 · SIW / Canon Reader integrationReview guidenoindex · review deployment
FRONTIER INSPECTION PROGRAM — SITE REVIEW CANDIDATENOT A FROZEN INSPECTION RELEASESITE REVIEW CANDIDATE — NOT FROZEN / NOT RELEASED
Frontier Inspection Program

INSPECT SIW

Intelligence is not authority.

Inspect a bounded SIW claim, its evidence, its known limitations, and the failure conditions we are inviting reviewers to attack.

This is a site review candidate. The portable, runnable external inspection package has not been frozen or published.

Four paths

Read now. The rest is pending.

1

READ

The narrow proposition, START HERE, the Specification Authority Manifest, Claims / Non-Claims, the Threat Model & Failure Modes, and the Known Limitations.

Available in this review candidate
Open READ →
2

RUN

The intended inspection flow. No runnable package, download or command exists yet; LIM-020 is a recorded release prerequisite.

PENDING — PORTABLE EXTERNAL REPRODUCTION OBJECT NOT YET FROZEN
See the intended flow →
3

VERIFY

Artifact identity, version, status, provenance and SHA-256 already recorded in the accepted FIP record. The package manifest and package hash do not exist yet.

FREEZE MANIFEST — PENDING
See identities and hashes →
What is inspectable now

Implemented boundaries, and what is not implemented

Implemented inspection boundaries

Synthetic fixtures · mock provider only · reproduction is INTERNAL

  • ACCEPTED FIP-C-003

    In accepted R2, authorization of a MergeProposal's INSPECTED → ACCEPTED state transition is committed atomically, with required standing prerequisites checked with zero mutation immediately before the transition commit.

    This is authorization only, not merge application.

  • ACCEPTED FIP-C-007A

    Governance refuses ADMIT when:

    • actor authority is revoked;
    • receiving domain is no longer current;
    • cited source version drifted;
    • cited evidence expired.

    A refusal leaves the store unchanged and asserts no admitted standing.

  • CONDITIONAL FIP-C-007B

    Listed among the M1D conditional claims. They do not promote CAND-01 or CAND-02 and do not rely on pending remediation as mitigation.

Source-currentness and cross-authority identity are known open defects at these boundaries (below). Implemented does not mean deployed.

Not implemented

Do not read these as capabilities.

  • HYPOTHESIS FIP-H-001

    Bind-time enforcement at model submission: not implemented.

  • HYPOTHESIS LIM-016

    Merge application is listed under “Not implemented at accepted R2 head” in the accepted Known Limitations Register (see also FIP-H-006).

  • NON-CLAIM

    Universal route closure or non-bypassability is a recorded non-claim.

  • OUT OF CURRENT FIP CLAIM SCOPE

    Generalized consequential execution.

Known open defects

KNOWN OPEN DEFECTS

CAND-01 KNOWN OPEN DEFECT

LIM-010 — CAND-01 source-currentness defect

At the accepted baseline, Federation-derived proposals can receive a new ADMIT despite non-current source states because standingCurrentnessPrerequisites are stored but not consumed.

Status: OPEN — CANDIDATE DEFECT. · LIM-010 in the Known Limitations Register

CAND-02 KNOWN OPEN DEFECT

LIM-011 — CAND-02 authority/domain identity defect

Source revalidation is insufficiently qualified and may satisfy one authority/domain's reference with another authority/domain sharing object identity/version characteristics.

Status: OPEN — CANDIDATE DEFECT. · LIM-011 in the Known Limitations Register

PENDING REVIEW / UNACCEPTED Pending remediation exists but is PENDING REVIEW / UNACCEPTED and is not represented as mitigation.

Recorded baseline (Specification Authority Manifest): R2 accepted implementation head: ca596c0. R3 M1A–M1C: accepted. M1D: conditional. Full detail: Threat Model §5 · Known Limitations (LIM-010, LIM-011).

Status language

How to read the labels

ACCEPTED

Genesis accepted the milestone. Trust it only within the stated ceiling.

CONDITIONAL

Evidence from a milestone accepted only conditionally (currently M1D).

HYPOTHESIS

Specified, not yet proven by implementation.

KNOWN LIMITATION

Published and open until an accepted artifact closes it.

PENDING REVIEW / UNACCEPTED

Work exists but is not accepted. It is not relied on.

INTERNAL REPRODUCTION

A rerun within the same team or lineage. Not external and not independent.

Presentation mapping only, using terms from the accepted registers: KNOWN OPEN DEFECT is a KNOWN LIMITATION whose recorded status is OPEN — CANDIDATE DEFECT; NON-CLAIM and OUT OF CURRENT FIP CLAIM SCOPE are shown as neutral chips; UNVERIFIED (RAT-059) uses the pending treatment. No other maturity labels are used.

Non-claims

What SIW / FIP-001 does not claim

FIP-001 does not claim:

  • general alignment
  • universal AI safety
  • universal route closure or non-bypassability
  • that implementation proves deployment
  • behavior of a real institution from synthetic fixtures
  • that passing internal tests establishes independent reproduction
  • that pending remediation is mitigation

These are lines from the accepted Claims / Non-Claims Register (terminal punctuation omitted); the full register has more: Non-claims · ceiling: Threat Model §8.

Related recorded limitation — LIM-018 (Gateway proof is mock-level): M1 proofs use MOCK_PROVIDER_A and zero external network attempts.

Routes

Route closure

Blocking one tested route does not prove closure of every materially equivalent route.

A discovered alternate route is an intended inspection result, not something to hide.

Route-closure discipline in the Threat Model →

Inspection posture

How to approach this

We are not asking reviewers to believe Genesis AiX.

We are exposing a bounded claim, the evidence supporting it, the limits on that evidence, and the seams reviewers are invited to attack.

A reproduced failure is evidence.

Access and IP boundary

Inspection is not a license

Intellectual Property notice · Evaluation / Inspection boundary · Licensing · IP & Provenance

The frozen inspection release will carry its applicable inspection/access boundary. This review candidate itself creates no additional license or implementation authority.

Reading this surface does not grant access to controlled material. Identifiers and hashes shown here are metadata only.