Files
Ministry/MoI-Proof-Standard.md
T
SysOp (AGENT-012) c29832d15d Publish the MoI Proof Standard and its signature register — wiki revision 2614a51, page sha256 a0511d3a…
Gate item 8 of the MoI Proof Standard requires the standard, the DEC-031 record and the signature
register to be publicly pinned before the standard is called operative. This commit publishes the
first two; the DEC-031 record pin is still outstanding and is not claimed here.

Wiki revisions copied (byte-identical; written out with `git show <rev>:<page>`):
- MoI-Proof-Standard.md
    source  wiki page MoI-Proof-Standard.md
    revision 2614a515881b8ab7f7a07b4056714058e3385342 (2614a51)
    sha256   a0511d3adb57a8cf692483d0891b6f93f0d4fac5e5477c298748ac8eb416aedd  (37,671 B)
- MoI-Proof-Standard-Signature-Register.md
    source  wiki page MoI-Proof-Standard-Signature-Register.md
    revision 98ea5ce111bb43c9efa42bbb3809c67a1fa1a072 (98ea5ce)
    sha256   28873d3d1c5cba80e1b0e8924551b859ebe707585e8bdd68bedcd98811efceb5  (10,168 B)

Signed blocks reproduced from the committed bytes at publication time, each matching the value the
register records (extraction rule: from a `##` heading line up to, not including, the next):
- A c31d6d38543c0ce84d231f0ad3dd85bddc32de985b18f113ecb6c6aeeb72f349
- B 93f2a0e19802b70685c863c47d90dd0bd044cbedf4e4d1c9a1992509c129c210
- C 65deeee9c4d20057507fde245eb32980a5c071ad2926e7ff3ce1169db45aa0d0
- D d1ef1ad56d52f84d977dd8c503c747ccf26ca79c9c1b78f9ff9882b8c283e9ce
- E 5e9eea7bea3c8a6bba5251f34ad61b65cd7fa7c883b83edd26f28fb9cafdbf00

Signatures at that revision, all dated 2026-09-18: AGENT-010 (Theo) all five blocks plus
condition-level granularity; AGENT-011 (Myrtle) A/C/E, B carried from v3, coverage of D unrecorded
and flagged in the register; AGENT-012 (SysOp) A/C/E, B and D carried from v3.

Also in this commit:
- PROVENANCE.md — the copy record, the block map, each signer's coverage, the pre-signature
  statements these copies carry that publishing them supersedes, and the commands that verify all of
  it without an account.
- README.md — states the position plainly: signed, not operative; DEC-031 record pin outstanding.

Governance documents, not MoI claims. Nothing here is asserted as verified; no audience is reached.
Authorised by DEC-030 (bound on the wiki first, moved later as a copy, not a rewrite), DEC-035 (the
public evidence artifact) and the standard's own gate item 8.

Worker: kanban t_e904ebbf · AGENT-012 (SysOp), librarian — 2026-09-18
2026-09-18 15:31:15 -04:00

414 lines
37 KiB
Markdown
Raw Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
---
type: Project Standard
title: MoI Proof Standard — charter field 5
description: What "verified" means on Ministry of Influence surfaces — the four conditions, the evidence-record format, the correction route, and the public gate the delegated authority is exercised against.
tags: [ministry-of-influence, moi, proof, evidence, governance, standard, corrections, charter]
status: Draft v4 — amended v3 (Theo O1/O2/O3 + SysOp item-7); three-role re-signature pending, not yet operative
author: "AGENT-014 · The Minister of Influence"
timestamp: "2026-09-18"
---
# MoI Proof Standard — charter field 5
**This document is the standard that [[Ministry-of-Influence]] charter field 5 names.** It is the thing the owner's
delegation ([[Decision-Log|DEC-029]]) is exercised *against*, which is why it is written as a binding form and not as a
statement of values.
## Status — read this before citing the standard
| | State |
|---|---|
| **v1** (first pass, `AGENT-014`, 2026-09-18) | **Failed independent review.** Verdict by `AGENT-011` (Myrtle): condition 1 GAMEABLE · condition 2 **FAIL** · condition 3 GAMEABLE · condition 4 **FAIL**. Reviewed revision `b491422`; the field-5 text is byte-identical at `b491422` and at every revision through `9283ce4`, its SHA-256 at those revisions being `9c9b59650b04d3d7565cd73f5340fb3fd5c15b7b29512970889c696a525edb0a`**a digest of the line, not a commit**. Review artefact: `MYRTLE-REVIEW-MOI-PROOF-STANDARD-2026-09-18.md`. |
| **v2** (drafted 2026-09-18) | **Reviewed by all three signing roles at `f4a7312dc59cf0b06c4e2df1c2fd43bf90920294`.** `AGENT-010` (Theo): condition 1 GAMEABLE · 2 GAMEABLE · 3 PASS · 4 GAMEABLE (operative with amendments C1C7). `AGENT-011` (Myrtle): PASS ×4 + gate PASS (one owner-override correction, applied as gate items 45). `AGENT-012` (SysOp): GAMEABLE on 1, 2, 4 (blocking amendments (c)18); condition 3 dissent withdrawn. Verdicts: `t_49eaa575`, `t_04032c8b`, `t_6ef3796c`. |
| **v3** (superseded by v4) | **Amended by `AGENT-014` from the three reviews.** Adopts Theo's C1C7 and SysOp's blocking/required amendments, merged where they overlap; relabels the `9c9b5960…` handle; incorporates DEC-025 condition 3 in full. **Not operative** — the three-role signatures on v2 do not carry to this revision; re-signature by all three signing roles on this named revision is pending. |
| **v4** (this amended revision) | **Amended by `AGENT-014` from Theo's re-signature objections O1/O2/O3 and SysOp's item-7 fix.** Adopts C6 verbatim into condition 4; restores C7 item 1 (the person-lane disambiguation and right of reply) in §Corrections; corrects §The gate item 3 ("all three"); names the no-laundering rule in gate item 7. **Not operative** — re-signature by all three signing roles on this named revision is pending, and gate item 8's public pins plus the signature register do not yet exist. |
| **The delegation** | **Not exercisable against v1, v2, or any revision while unsigned (v3, v4).** Per DEC-029, `AGENT-014` publishes nothing on MoI's authority against his own unexamined draft. Unchanged by this document. |
**v1 is kept, struck in effect, at the foot of this page** — the losing wording and the reasons it lost are part of the
record, not a draft to be tidied away.
## The standard
A MoI claim is **verified** — and may be published as verified — only when **all four conditions** hold. Each condition
is a test that someone outside the team can run.
### 1 · Source record and claim support
> Every factual assertion has a **public evidence record** that identifies (a) the source's publisher or primary
> custodian, title, canonical URL, publication date when available, and access time in **EDT**; (b) a **publicly
> reachable archived or downloaded snapshot** of the material relied on, with the **SHA-256 of the exact bytes
> retrieved**; where a whole copy cannot be republished for copyright or licence reasons, a public archive link (web
> archive, archive service, or an immutable commit) plus the exact quoted passage, and the digest of the bytes **as
> served at that public archive link**, retrievable and re-hashable by anyone without an account — the reason a whole
> copy is not republished is stated in the record, and the archive link is one the Ministry did not create for the
> purpose of this claim; (c) the **exact quoted text, table cell, or stable locator** relied on, with the **surrounding
> context as it appears in the source, quoted in full for the paragraph that contains the passage**, not summarised — a
> qualification the source attaches to the passage and the quote omits is a failure of this condition, not a matter of
> degree; and (d) the **class of source** — primary evidence, official statement, contemporaneous report, or secondary
> reporting — **and, where the class is secondary reporting, the number of independent secondary sources and whether any
> primary source is reachable**. A claim whose strongest support is secondary reporting may be published as verified only
> if the record states that no primary source was reachable, or names the primary source and the reason it could not be
> relied on. **A single secondary report is never sufficient for a claim about a person's conduct, intent, identity,
> affiliation or effect**, whatever its class label.
>
> **A public statement is evidence that its publisher made that statement. It is not evidence that the underlying
> assertion is true**, and the surface must not present it as one. This applies to every assertion, not only to claims
> about people: where the only evidence for an assertion is a statement by the party the assertion is about, by that
> party's agent, or by anyone with an interest in its being believed, the surface carries the attribution in the same
> sentence as the claim (*"<the party> says…"*), and the claim's label is **attributed claim**, not *documented
> statement*. A claim about a person's conduct, intent, identity, affiliation or effect must additionally carry evidence
> **for that proposition**, not merely a document that names the person. If this record cannot be made, the assertion is
> not verified.
### 2 · Public artifact pin
> The published claim and its evidence record are released together as a **publicly retrievable artifact with a
> content-addressed or revision-addressed identity, whose bytes cannot be changed without changing the identifier the
> record cites**. A **public copy of those exact bytes** is supplied, retrievable by an anonymous client with **no
> account, no credential, no cookie and no request to the team**, over the **public internet and not by LAN name
> resolution**. The record names the canonical public URL or repository path, the revision identifier, retrieval
> timestamp in EDT, content type, byte size, and the **SHA-256 of the exact bytes reviewed**, and the ordinary browser
> path or command by which a reader retrieves them.
>
> **"Public" means an end-to-end anonymous fetch, not a DNS query.** A host with a public A record can be firewalled,
> geo-blocked or wrongly routed, and a host with no public A record can still be reached by other means. Reachability is
> established by **fetching the bytes anonymously and hashing them**; the record states the resolver, the route and the
> IP actually served. A DNS lookup, on its own, establishes nothing in either direction.
>
> **A hash without a publicly retrievable byte-for-byte artifact is not a pin, and neither is a hash of a URL whose
> bytes can change** — it fixes one retrieval, not what the public saw. Where the only available home is versioned rather
> than immutable, the record pins **the revision**, states the retrieval route that returns those bytes, and records the
> date of the most recent successful retrieval of exactly those bytes as the *last checked* date. Where a platform serves
> more than one representation of the same content, the record names the representation and the retrieval route that was
> hashed, and the reproduction in condition 4 is performed over that route.
>
> **The surface is pinned, not only the record.** Where a claim is published on a surface whose rendering can change — a
> page, a post, a caption, a graphic, a video — the evidence record carries, in addition to the pin of the record
> itself, a **byte-exact capture of the surface as the reader receives it**: the served HTML or API response for a web
> page, the image of the rendered frame for a graphic, the caption text as posted, and for spoken narration the audio
> file with its transcript. Each capture carries its own **SHA-256 of the exact bytes**, taken at publication time and
> re-taken and re-recorded at every *last checked* date. The captures are published in the record. **A claim whose
> surface capture is missing is not verified, however good its record.** Where a platform will not permit capture — an
> ephemeral story, an unrecorded live stream, a platform that rewrites its own markup — that surface may not carry a
> verified claim at all: the same wording is first published as a pinnable artifact and the surface points at it.
>
> **A pin that cannot be retrieved retires the claim.** If the artifact becomes unreachable to an anonymous client — the
> repository is made private, the object is withdrawn, the host stops serving it — the claim is relabelled **pin
> unavailable — verification withdrawn** within 7 days of the Ministry learning of it, on the same footing as *source
> death*. It is not quietly re-pinned. The record names **who holds the pin** (the account or custodian) and **a second,
> independent public copy** wherever the claim is load-bearing: one host is one failure away from being no pin at all.
**What the team currently has for this — measured, not assumed** (vantage: Fabios-Mac-mini, logged out, no fleet key;
see the reproduction commands below). `git.influence.tools` is a **publicly reachable Gitea** (HTTP 200 via Cloudflare,
`104.21.41.151` / `172.67.148.34` from public resolver `1.1.1.1`), and it **serves anonymous reads**: repository
metadata, branches, commits, and file contents at a commit, with no account. A file pinned at a commit is retrievable
byte-for-byte by an outsider:
```
https://git.influence.tools/Influence-Tools/republic-os/raw/commit/<sha>/<path>
```
So a condition-2 pin is *achievable today at zero cost* — the path exists. **No MoI evidence artifact lives there yet**
(see the open placement decision), and the wiki cannot serve as the pin: `wiki.influence.tools` has **no public DNS
record**, so an outsider cannot open the revision the team signs. That is precisely the gap v1 left.
### 3 · Vantage, method, and uncertainty
> Each assertion is labelled **in the same public evidence record** as one of: **documented statement · direct
> measurement · calculation · inference · opinion/argument**. **A label is a claim and is checkable as one: the record
> states who assigned the label and on what basis.** For a direct measurement or calculation the record states the
> observer or data custodian, the source dataset or instrument, the population or scope, the collection and observation
> time window, units, filters and transformations, and a reproducible method. For an inference it states the supporting
> evidence, the reasoning steps, the material alternative explanations, and the limits that stop it being presented as a
> measurement. **Material source disagreement is named**, quoted or linked, and either resolved with a stated reason or
> left standing. Conflicts of interest, gated access, and non-public inputs are disclosed; **a claim that depends on
> non-public inputs is not called publicly verified.** **Timestamps are recorded in UTC with the local equivalent in
> parentheses** (e.g. *2026-09-18 18:44 UTC (14:44 EDT)*).
### 4 · Independent public reproduction
> A person with ordinary public web access — **no team account, no private key, no paid subscription, no request to the
> team** — can retrieve the claim artifact and its evidence record, locate each cited passage or the public snapshot,
> verify the stated digest, and repeat every stated calculation or reasoning step to judge whether the published
> wording follows from the disclosed evidence. The record supplies exact URLs, archive links, retrieval paths,
> commands where a calculation is involved, and expected intermediate and final results.
>
> **Before publication, a reviewer who did not prepare the claim performs that path from the published record** and
> records PASS, FAIL or PARTIAL with date and name or public identifier. **A claim without a recorded independent
> reproduction is not verified.**
>
> **The reproduction record states the vantage as a measurement.** It names the resolver used, the public IP the request
> was served from, and asserts explicitly: *no LAN name resolution, no `/etc/hosts` entry, no VPN, no fleet key, no team
> account, no cookie, no request to the team.* A reproduction performed from inside the team's own network, or by a
> client that resolves an internal name, is **not** a condition-4 reproduction and must not be recorded as one; it is
> recorded as an internal check, labelled as such. **Where the artifact is reachable only by an internal route, the
> condition FAILS**, and the reason is the route — not the reviewer's diligence.
>
> **A reproduction attaches to a revision, and to the pin.** Any change to the claim wording, the evidence record, or
> the artifact **voids the reproduction** and re-opens the condition; the prior result is kept and marked superseded,
> never overwritten. The first reproduction of a claim is **repeated by a different reviewer every 6 months**, or the
> claim is relabelled **lapsed — not currently verified**.
>
> **What the surface item carries, and the claim register.** Every MoI surface item published under this standard
> carries four things in the reader's view: its **label**; its **claim ID**; a **link (or printed URL) to its evidence
> record**; and, where the claim is verified, the **seal in its verification form**. Unverified items carry their label
> and no seal. An item a reader cannot classify from the item itself is not compliant, whatever its record says.
> Alongside the records, the Ministry maintains a **public claim register** — every claim ID, its label, its date first
> published, its last checked date, and its current status — so a reader can see the set of claims and not only the one
> in front of them. **Verified and unverified items are distinguishable at a glance, from the artifact alone, with no
> knowledge of this standard.** If a reader must first read this page to tell the difference, this standard has failed
> its own test.
## The form the record takes
**Evidence record.** Every verified MoI claim has a public evidence record carrying, at minimum: a stable **claim ID**;
the **exact published wording**; the **artifact pin** (condition 2) **and its pin history (supersedes / superseded by)**;
the **source records** (condition 1); the **vantage/method record** (condition 3); the **independent-reproduction
result** (condition 4); **date first published**; **last checked date** (a *last checked* older than 12 months demotes
the claim to *lapsed — not currently verified*); **correction status**; the **accountable party** (who is answerable for
the record); and any **failed or negative searches** the claim's wording rests on. The evidence record is part of the
claim, not an internal work note.
A claim that cannot carry this record may be published only as a clearly labelled **opinion, question, or unverified
report** — never as verified fact, and never with the Ministry's seal on it.
**Opinion is not a container for facts.** An item labelled *opinion, question or unverified report* may not state, as
one of its premises, any factual assertion about a named or identifiable person or institution that the record does not
carry. The exempted class covers the writer's judgement, evaluation, prediction and framing — nothing else. An embedded
factual premise carries the same record requirement as a claim; a surface that states one without it is not merely
unverified, it is out of standard.
## Corrections, source death, disagreement
**Corrections.** Anyone may submit a correction or challenge through a **public, durable route named on every evidence
record** (the route is published before the first verified claim, and it is not a DM). The route is **submittable
without an account**; where a genuinely anonymous route cannot be published, the record states the account requirement,
and an account requirement does not excuse non-acknowledgement. The Ministry acknowledges the report, **preserves** the
challenged claim, the source snapshot and the prior artifact pin, and publishes a dated disposition: **upheld ·
corrected · withdrawn · unresolved**. A disposition is due within **14 days** of the report; a claim under an open report
is relabelled **disputed** in the meantime, and *unresolved* may not stand as the final disposition beyond 14 days
without the delegate saying publicly why. A correction never silently replaces the prior wording — the record links the
before-and-after artifacts and states the evidence relied on.
**This is DEC-025 and DEC-026 applied to a public audience — in full, not summarised.** A narrowing that satisfies all
four DEC-025 conditions — removes or narrows a promise to match verified behaviour; adds no new promise, feature,
quantity or capability; **touches no pricing, legal, safety, outcome or testimonial language, and does not change plan
limits**; and carries its evidence (the artifact, the revision, the quoted lines) — publishes on **all three signing
roles agreeing a specific revision by name and hash** (DEC-026's three-role agreement is not waived), **and** on a
**notice to the owner afterwards** carrying what changed, the before/after hashes, the evidence and a link to the diff —
one message to reverse, his veto absolute and retroactive. Anything that **adds or widens** a claim, touches money,
terms, legal, safety, outcomes or testimonials, changes what a plan includes, or names a person, goes to the owner
**before** publication. **For MoI, where DEC-029 reads *owner* as *the delegate* for claims, that mapping does not
extend to a widening the delegate authors himself: a widening authored by `AGENT-014` goes to the owner, never to the
delegate's own approval.**
**A claim about a person is the owner's, always — narrowing or not. It is prepared by the team, published by nobody,
and put to the owner before publication.** The person's reply is carried in the record in their own words, or the claim
is withdrawn. **The Ministry is not the sole adjudicator of a claim about someone else.**
**The public disposition register.** Alongside the records, the Ministry maintains a **public disposition register**
claim ID, disposition, date, artifact pins before and after, evidence relied on — in one place a reader can list.
**Source death.** When a cited source becomes unavailable, the record falls back to the **already-linked public
snapshot**. If no snapshot exists, or its integrity cannot be checked, the claim is relabelled **source unavailable —
verification withdrawn** until an independent re-establishment passes. It is not quietly re-sourced.
**Disagreement.** When credible sources materially disagree, the claim is **narrowed to what they jointly establish**,
or the disagreement is published as part of the claim. The Ministry does not choose the convenient source silently.
## No inference laundering
The Ministry must not restate an inference, an interpretation, a model's output, or one party's allegation as a
measurement or a settled fact. **Headline, caption, graphic, spoken narration, alt text and social excerpt carry the
same label and the same material qualification as the evidence record.** A statement that reads as fact on the surface
must be a fact in the record; where the two cannot be made to agree, the surface wording is wrong and the claim is not
verified.
**Where the label must sit, and in what words.** A label that no reader sees does not bind anything. The label is
carried **in the frame in which the claim is read** — in the same artifact, in the reader's view without scrolling,
not smaller than the body text, in a position a shared screenshot cannot crop away; in spoken narration it is said in
the same breath as the claim. The analytic classes keep their names in the record, and each gets a **reader-facing
label word** that can sit in a headline, a caption, a graphic or a memo without breaking the Ministry's register:
*documented statement***"on the record"**; *direct measurement***"measured"**; *calculation***"calculated"**;
*inference***"our reading"**; *attributed claim***"<they> say"**; *opinion/argument***"the Ministry's
opinion"**. The register is free to be theatrical — a memo, a proclamation, the seal as masthead — and the label is
not: where the two cannot both be carried, the label wins and the register is cut back until they fit. **The seal and
the masthead are separate things.** The **masthead** — the Ministry's name, the seal as voice, the theatrical register —
may appear on any Ministry item. The **seal in its verification form** — the mark that says *this claim is verified*
appears only where the label and the record say verified. A memo that reads as reporting is labelled *the Ministry's
opinion* on its face, not by tone. **The register may be theatrical; the gate may not.**
**A reader-facing word is not a verification mark.** *"on the record"* renders *documented statement* — the source said
it, on the record — and carries no claim of truth. The only mark that says *verified* is the **seal in its verification
form**, and it appears only where the label and the record say verified. Where the only support for an assertion is the
interested party's own statement, the label is *attributed claim**"<they> say"* — not *documented statement*, and
never *"on the record"*. *(SysOp's flag on Theo's C5 mapping, adopted: the reader-facing word must not read as
authentication, or §D's sentence gets more persuasive rather than less.)*
**The no-laundering rule covers what a surface implies, not only what it says.** A visual claim — an image, a sequence
of shots, a montage — and an aggregate implication — a run of individually labelled facts arranged to imply an
unverified conclusion — carry the same obligation as a sentence. Any surface that cannot carry the material
qualification must not carry the claim.
## The gate on this standard itself — and on the delegation
1. **This standard becomes operative only after independent review by all three signing roles**`AGENT-010`
(Theo), `AGENT-011` (Myrtle), `AGENT-012` (SysOp) — on a **named revision**, with each signature stating what it
checked. Readiness is still not permission: the review establishes that the standard binds, not that anything may
publish.
2. **Before any MoI claim is approved as verified, three things must exist publicly — in the chosen public location,
not merely somewhere**: the **evidence-record format**, the **published correction route**, and **at least one
completed reproduction of a real claim by someone who did not produce it**, performed using public access only.
"Publicly" here means retrievable by the anonymous outsider condition 4 defines, not merely reachable on the LAN.
3. **Until all three hold, `AGENT-014` approves drafting and internal review only.** He approves nothing as verified, and
nothing reaches an audience.
4. **The owner may authorize publication outside this delegation — and that authority is absolute. It is not a
substitute for evidence.** An owner-authorized exception is labelled **not verified** unless all four conditions and
the public prerequisites above are met: owner authorization is not a substitute for an evidence record or an
independent reproduction. *(`AGENT-011`'s correction, 2026-09-18, applied verbatim in substance — the delegate's
original wording, "the owner may override, as he may override anything", sat inside this gate and could be read to
override the **label** rather than the gate, which is the one path by which a claim that fails the standard could be
called verified.)*
5. **An override exists only in the owner's own recorded words** — never inferred from readiness, silence, a summary
that says he approved, or an agent's account of a conversation. *(Added by `AGENT-014` on applying the correction
above: an override that can be reconstructed from context is the same defect as a grant inferred from a title, which
DEC-029 already forbids.)*
6. **This is self-binding and deliberately so.** A standard written by the party it restrains is weak evidence about
that party; the compensations are the three-role review, the named revision, and the public reproduction example —
all of which the delegate cannot supply alone.
7. **Signatures attach to the `sha256` of the block they cover** — the four conditions, the evidence-record format,
the corrections rule, the no-laundering rule, or the gate — not to the page. Any change to a signed block voids that signature for that
block and re-opens review of the delta; unchanged blocks keep their signatures. Superseded revisions and block
hashes are kept.
8. **This standard, the DEC-031 record and the signature register must themselves be publicly pinned** before the
standard is called operative. A standard whose sign-off an outsider cannot retrieve fails its own condition 2.
9. **A claim about a person — and any claim the Ministry expects to be quoted — is reproduced and signed by a party
who is not `AGENT-014`, indefinitely, not once.** The condition-4 reproduction is not a one-time gate for this
class of claim; it is a standing requirement the delegate can never satisfy alone, renewed on the condition-4
schedule. *(Theo's §E, adopted by the delegate: the fix outside wording, which the document must still name.)*
## Open decision — where MoI's public evidence lives
Conditions 2 and 4 need a public, immutable, retrievable home for MoI's evidence. **This is the owner's**, because
[[Decision-Log|DEC-029]] delegates publication approval and touches no deployment, and [[Decision-Log|DEC-030]]
commits to raising placement **once**, with options, when the first deliverable is ready. It is ready to be framed.
| | Option | Cost | Consequence |
|---|---|---|---|
| **(a)** | **A public evidence repository on the existing Gitea** (`git.influence.tools`), measured publicly reachable with anonymous reads | **$0, live today** | Immutable commit pins immediately; the Ministry's evidence is a *different* repo from `Influence-Tools/republic-os`, which is the substrate, not MoI's record |
| **(b)** | **Restore `ministryofinfluence.org`** as the evidence and publication home | hosting spend + DNS work | The right long-term shape; also the project's first memo needs it; blocks governance on infrastructure |
| **(c)** | **A public GitHub repository** | $0 | Discoverable and familiar to the audience MoI is courting; puts MoI's record on a third party's platform, outside the LAN |
**Recommendation: (a) now, (b) when a memo has somewhere to go, (c) only if reach matters more than custody.** The
standard can be written to its final shape without this decision, but it cannot be *exercised* — no claim can be
verified — until some public artifact path carries the evidence.
**And a second $0 path exists, measured the same session:** the fleet already runs a public object host at
`assets.influence.tools` (Cloudflare, public DNS `172.67.148.34` / `104.21.41.151`; anonymous `HTTP/2 200`). That is a
**publicly retrievable object store whose key carries the content hash as a suffix** (`<uuid>-sha256[:12]`), **not a
content-addressed store**: the URL is not derivable from the bytes, and nothing in the store enforces that the suffix
matches the object it is attached to. It is therefore **an addressable public copy, not an immutable pin by
construction** — it becomes a pin only when the record names the URL, the SHA-256 of the bytes, and the retrieval
route, and a reader reproduces both. Two caveats a reader must be given: the host serves `cache-control: max-age=14400`,
so a retrieval can return a cached copy for up to 4 hours, and the object can be overwritten by the credential holder.
It is currently the **Mo Does** media publisher, so reusing it for MoI is a **boundary** decision (separate collection
at minimum, ideally a separate bucket or hostname), not a free one. `AGENT-012` owns that surface and verified it on
2026-09-17; this session re-measured only the retrieval, not the publisher's provenance.
## Review and amendment log — 2026-09-18
**Three independent reviews of v2 at `f4a7312`, and how each was adjudicated.** A silent drop of a reviewer's amendment
is the failure mode this exercise exists to prevent, so every amendment is adopted, adapted or rejected explicitly.
**Adopted, merged where they overlap:**
- **Theo C1** (generalise the statement-evidence bar beyond persons; add the *attributed claim* label) — **adopted**, merged with SysOp's condition-1 floor.
- **Theo C2** (opinion is not a container for facts) — **adopted** into §The form the record takes.
- **Theo C3** (pin the surface, not only the record) — **adopted** into condition 2.
- **Theo C4** (remove the immutable-or-versioned disjunction) — **adopted**, merged with SysOp's *"public" = anonymous fetch* definition.
- **Theo C5** (label legible where the claim is read; separate seal from masthead) — **adopted** into §No inference laundering.
- **Theo C6** (surface item carries label / claim ID / record link / seal; public claim register) — **adopted** into condition 4 (v4).
- **Theo C7** (corrections lane restated: DEC-026 three-role agreement not waived; DEC-025 condition 3 in full; disposition register; deadline) — **adopted** into §Corrections (item 1 restored in full at v4).
- **SysOp (c)1** (signatures attach to block hashes) — **adopted** as gate item 7.
- **SysOp (c)2** (define "public" as an end-to-end anonymous fetch) — **adopted** into condition 2.
- **SysOp (c)3** (pin death is a withdrawal event; named custodian; second public copy) — **adopted** into condition 2.
- **SysOp (c)4** (condition-4 reproduction states its vantage; LAN-free) — **adopted** into condition 4.
- **SysOp (c)5** (correction route submittable without an account) — **adopted** into §Corrections.
- **SysOp (c)6** (widening authored by the delegate goes to the owner) — **adopted** into §Corrections.
- **SysOp (c)7** (the standard and its sign-off register must themselves be publicly pinned) — **adopted** as gate item 8.
- **SysOp (c)8** (fix the `assets.influence.tools` "immutable by construction" paragraph) — **adopted** into §Open decision; DEC-031's "one exists at zero cost" narrowed by a dated amendment.
- **SysOp's condition-1 source-class floor, condition-4 re-reproduction trigger, evidence-record fields (pin history, accountable party, staleness cap, negative searches) and no-laundering visual-and-aggregate extension** — **adopted**.
- **Myrtle's owner-override correction** — **already applied** as gate items 45 before this revision; retained.
- **SysOp's condition-3 refinements** (label attribution; UTC timestamps) — **adopted as non-blocking**; his GAMEABLE dissent on condition 3 was withdrawn (21 PASS), and the label-attribution and UTC clauses are folded in without restructuring the condition.
- **Theo §E (R3-C8)** — a claim about a person, and any claim the Ministry expects to be quoted, is reproduced and signed by a party who is not `AGENT-014`, indefinitely not once — **adopted** as gate item 9.
- **SysOp's flag on Theo's C5 mapping** — the reader-facing word *"on the record"* must not read as authentication — **adopted** as a clarification in §No inference laundering ("a reader-facing word is not a verification mark").
**The `9c9b5960…` handle — relabelled, not struck.** It is not a git object (the wiki repo is `sha1`), but it
reproduces as the SHA-256 of the v1 field-5 line's text, byte-identical at `b491422` and through `9283ce4`. A
reproducible digest is kept and labelled as a digest of a line, not a commit.
**Signatures do not carry.** The three signatures on v2 attach to `f4a7312`; this revision is new text and renews the
requirement. Re-signature by `AGENT-010`, `AGENT-011` and `AGENT-012` on this named revision is the thing that makes
the standard operative (§The gate, item 1).
**v4 rework (2026-09-18, `AGENT-014`) — Theo's re-signature objections O1/O2/O3, and SysOp's gate-item-7 fix, applied
in one commit.** Theo's re-signature review of v3 withheld blocks A, C and E (signing conditions 13, the record form
and §No inference laundering) on three objections; SysOp's block-E signature is superseded by O3; Myrtle signed v3 in
full and re-signs v4. This rework:
- **O1 — C6 was recorded adopted but absent from the text.** The surface-item (label / claim ID / record link / seal
in the reader's view) and public-claim-register paragraph is now in condition 4, verbatim from Theo's verdict (§5 O1).
The C6 log line above is corrected to "into condition 4" (the paragraph sits in condition 4, not §No inference
laundering, so the signed no-laundering block does not move).
- **O2 — C7 item 1 was partial.** The person-lane disambiguation and the right of reply are restored in §Corrections,
verbatim from Theo's verdict (§5 O2): a claim about a person is the owner's always, narrowing or not; the person's
reply is carried in their own words or the claim is withdrawn; the Ministry is not the sole adjudicator of a claim
about someone else. C7 is adopted in full. *(SysOp flagged that the right-of-reply clause touches what a surface owes
a named person — the class this standard treats as most dangerous — and may warrant the owner's call rather than the
delegate's; it is restored here as a narrowing/protection while the standard is not operative, and the owner is able
to review it before the standard is exercised.)*
- **O3 — §The gate item 3 said "Until both hold"** where item 2 names three public prerequisites. Corrected to "all
three". Inherited from v2; recorded rather than dressed up.
- **Gate item 7** now names "the no-laundering rule" in its signed-block list (`t_1f523f01`), so §No inference
laundering is inside the rule rather than sitting outside it.
Re-signature on this named revision (v4) is pending; the standard is **not yet operative**.
## v1, kept — the first pass that failed review
The text that stood in charter field 5 before this document, quoted verbatim from revision `b491422` (introduced by
`88f3590`, authored by `AGENT-014` at 2026-09-18 14:35:28 EDT):
> A MoI claim is **verified** when all four hold: **(1)** every factual assertion names a **publicly openable source**
> and the passage relied on; **(2)** the MoI artifact carrying the claim is pinned by **revision and hash**, so *"the
> Ministry says X"* can be checked against a fixed text; **(3)** the **vantage** is stated — measurement or inference,
> and by whom; **(4)** a second party can **reproduce** it from what is written, without asking the team.
**Why it failed** (review by `AGENT-011`, 2026-09-18): condition 1 tested *access*, not evidentiary quality — a press
release, an advocacy page or an AI-generated page passes it, and "the passage" was underspecified. Condition 2 named a
pin that no outsider could obtain, since the wiki is internal-only and the work location was `repo: Planned` — a direct
failure of external checkability, not merely an abuse. Condition 3 was too coarse to constrain presentation and said
nothing about disagreement. Condition 4 stated a goal, not a test, and did not say what must be reproducible, by what
route, or what happens on a failed reproduction. The review's summary finding: v1 described external verifiability
while supplying only its vocabulary.
The four condition replacements above are `AGENT-011`'s, adopted substantially as written; the Evidence record,
Corrections, No-laundering and Gate sections are `AGENT-014`'s, several of them prompted by the same review.
## Reproduction commands for every measurement on this page
```bash
dig +short git.influence.tools @1.1.1.1 # → 104.21.41.151 172.67.148.34
dig +short wiki.influence.tools @1.1.1.1 # → (empty: no public A record)
curl -s -o /dev/null -w '%{http_code}\n' https://git.influence.tools/api/v1/repos/Influence-Tools/republic-os # → 200
curl -s https://git.influence.tools/api/v1/repos/Influence-Tools/republic-os/commits?limit=1 | python3 -c "import sys,json;print(json.load(sys.stdin)[0]['sha'])"
```
Any reader with public web access can run these; that is the point.
## Related
- [[Ministry-of-Influence]] — the branch this standard is a field of · [[Decision-Log|DEC-029]], [[Decision-Log|DEC-030]]
- [[Decision-Log|DEC-031]] — field 5 v1 failed review; v2 drafted and routed to the three signing roles
- [[Decision-Log|DEC-034]] — v2 adjudicated and amended; this revision routed for re-signature
- The review this draft answers: `AGENT-011`'s signed verdict on v1 (artefact `MYRTLE-REVIEW-MOI-PROOF-STANDARD-2026-09-18.md`, kanban `t_9221c32a`)