approvedcompleteAGPL-3.0
Governance spine: attestation ledger + action gate + trust window
008-governance-attestation
The platform's tamper-evident memory and its decision spine, built on the four crates extracted from OAP's policy-kernel: attest-ledger (tamper-evident record chain + signed anchors), canonical-keysort-json (byte-identical canonical JSON), action-gate (pure deterministic Gate over an ordered Check registry), and trust-window (rolling-window trust scorer mapping to graduated privilege). A napi-rs addon wraps the Rust crates; a governance/ Encore service exposes record/verify/gate/trust APIs that factory (005) and fleet (006) call at their privileged moments. This is the platform's differentiator: not that it deploys apps, but that every privileged act is gated, recorded, and independently verifiable.
- Depends on
- Establishes
- backend/governance/ (directory)
- Sections
- 008: Governance: attestation, gating, trust
- 1. Crate dependencies (read first)
- 2. Territory
- 3. Integration contract (for specs 005/006)
- 4. Acceptance
- 5. Out of scope
- 6. Status (2026-07-14)
- 2026-07-20: the addon transferred out; this spec narrowed, not retired
- Source
- specs/008-governance-attestation/spec.md @ f136bf323cecas of 2026-07-21 ยท shard 3d39fe45e4c9