approvedcompleteAGPL-3.0

Governance spine: attestation ledger + action gate + trust window

008-governance-attestation

The platform's tamper-evident memory and its decision spine, built on the four crates extracted from OAP's policy-kernel: attest-ledger (tamper-evident record chain + signed anchors), canonical-keysort-json (byte-identical canonical JSON), action-gate (pure deterministic Gate over an ordered Check registry), and trust-window (rolling-window trust scorer mapping to graduated privilege). A napi-rs addon wraps the Rust crates; a governance/ Encore service exposes record/verify/gate/trust APIs that factory (005) and fleet (006) call at their privileged moments. This is the platform's differentiator: not that it deploys apps, but that every privileged act is gated, recorded, and independently verifiable.

Establishes
  • backend/governance/ (directory)
Sections
  • 008: Governance: attestation, gating, trust
  • 1. Crate dependencies (read first)
  • 2. Territory
  • 3. Integration contract (for specs 005/006)
  • 4. Acceptance
  • 5. Out of scope
  • 6. Status (2026-07-14)
  • 2026-07-20: the addon transferred out; this spec narrowed, not retired
Source
specs/008-governance-attestation/spec.md @ f136bf323cecas of 2026-07-21 ยท shard 3d39fe45e4c9