0. Registry Classification
| Field | Entry |
|---|---|
| Restoration Arc ID | RA-051 |
| Name | Signed Decision Provenance |
| Short Name / Alias | Decision Provenance |
| Primary Family | Governance / Auditability / Decision Integrity |
| Secondary Families | Core; AI Governance; Justice / Governance / Legitimacy; Auditability; Institutional Design; Security; Platform Governance; Boundary; Coherence; Scaling; Authority |
| Treatment | Canon Parent Arc |
| Status | Canon-Ready |
| Scope | Institutional / AI / Security / Platform / Economic / Governance / Civilizational / Cross-Domain |
| Primary U-Layers | U2 / U3 / U4 / U5 → U6 / U7 validation |
| Primary Operators | Au → Π → Σ → FI → Θ → ℛ → Λ → Τ |
| Primary Diagnostics | Au, H, O, R, BΣ, K, FI, decision_traceability, rationale_integrity, tradeoff_visibility, rollback_readiness, review_date_integrity, bias_injection_risk, policy_lineage_integrity, decision_owner_clarity, Φ/O divergence |
1. Purpose
1.1 What This Arc Repairs
Signed Decision Provenance repairs governance and system-change environments where decisions alter policy, constraints, access, ranking, enforcement, safety behavior, model behavior, resource allocation, or institutional posture without a durable record of who decided, why, under what assumptions, with what tradeoffs, and under what rollback criteria.
It applies when decisions become operationally real but remain weakly attributable, weakly justified, weakly reversible, or difficult to audit later.
This arc repairs decision opacity by:
- assigning a durable decision ID;
- naming the responsible actor, role, body, system, or authority path;
- recording rationale and context;
- recording tradeoffs, expected effects, and known risks;
- recording affected scope and affected nodes;
- defining rollback, suspension, or revision criteria;
- setting a review date or review trigger;
- preserving decision lineage across personnel, policy, model, vendor, or interface changes;
- making silent bias injection and hidden policy drift harder to hide.
Signed Decision Provenance is the canonical arc for making specific governance decisions traceable across time.
1.2 Core Restoration Function
This arc restores decision integrity by binding governance change to a signed record of ownership, rationale, tradeoffs, rollback criteria, and review timing.
Signed Decision Provenance prevents decisions from becoming ownerless facts.
2. Use Conditions
2.1 When to Apply
Use this arc when:
- a governance decision changes system behavior;
- a policy or enforcement rule changes;
- an AI model, evaluator, classifier, memory rule, tool rule, or guardrail changes;
- a platform changes ranking, visibility, access, appeal, moderation, or enforcement behavior;
- a security exception, override, suppression, escalation, or emergency measure is approved;
- a decision carries hidden bias, legitimacy, boundary, or recurrence risk;
- authority exists, but the specific decision record is weak;
- future auditors need to reconstruct why a change occurred;
- rollback must be possible if the decision creates harm;
- tradeoffs were made but not recorded;
- a decision may affect future cases, users, models, policies, or governance legitimacy.
Examples:
- a classifier threshold is changed without recording who approved it or what harm tradeoff was accepted;
- a platform policy is revised but no rationale or rollback condition is attached;
- a security exception is approved through chat and later becomes normal practice;
- a model behavior change is deployed without policy lineage;
- a governance committee decision is implemented without signed ownership;
- a public rule changes while internal interpretation shifts silently.
2.2 When Not to Apply
Do not apply this arc when:
- no meaningful decision or governance change occurred;
- the authority registry itself is unclear and RA-050 must occur first;
- active harm requires emergency stabilization before documentation;
- decision provenance is being used to delay urgent repair;
- disclosure would violate privacy, safety, security, or affected-node boundaries;
- the required repair is tamper-evident audit protection rather than initial provenance;
- the system refuses to name an accountable decision owner;
- the decision cannot be reconstructed with enough integrity to sign.
Signed Decision Provenance must not become paper-trail theater.
2.3 Required Preconditions
Before this arc begins, the following must be true:
| Precondition | Requirement |
|---|---|
| Decision Object Identified | The policy, constraint, override, deployment, rule, allocation, enforcement, or governance change is named |
| Authority Path Available | The responsible actor, role, body, system, or authority path is known or mappable |
| Decision Context Recoverable | Rationale, conditions, assumptions, evidence, and tradeoffs can be reconstructed |
| Affected Scope Mappable | The decision’s affected users, nodes, systems, data, domains, or future cases can be scoped |
| Rollback Path Possible | Suspension, revision, rollback, exception, or appeal criteria can be defined |
| Boundary Protection Available | Records can preserve privacy, security, affected-node boundaries, and sensitive operational details |
| Review Timing Available | A review date, review interval, or trigger condition can be assigned |
If required preconditions fail:
Arc cannot validly begin.The system must route to Authority Registry Clarification, Audit Surface Expansion, Responsibility Gradient Mapping, Tamper-Evident Audit Restoration, or Governance-Level Restoration.
3. Failure / Damage Signature
3.1 Pre-State Across S
| Variable | Expected Pre-State |
|---|---|
| O — Coherence | Reduced because decisions alter the field without visible rationale, ownership, or rollback path |
| H — Hidden Debt | Elevated through undocumented tradeoffs, hidden bias, policy drift, or future audit failure |
| ε — Error / Noise | Elevated through unclear decision lineage, inconsistent explanations, or missing assumptions |
| ι — Inversion Index | Rising when decisions gain authority without provenance |
| Au — Auditability | Weak because future actors cannot reconstruct decision origin, rationale, tradeoffs, or owner |
| µᵢ — Agent Integrity | Threatened when affected nodes cannot know why they were impacted or how to appeal |
| BΣ — Boundary Integrity | At risk if decision scope, data use, enforcement reach, or disclosure boundaries are unclear |
| K — Compatibility / Slack Context | Reduced because actors lack usable paths for review, reversal, appeal, or correction |
| R — Restoration Capacity | Blocked if no owner or rollback criterion exists |
| Φ — Fitness Proxy | May appear improved through faster deployment, simplified policy, cleaner metrics, or reduced friction |
3.2 Primary Failure Links
| Failure Mode | Relationship |
|---|---|
| Silent Bias Injection | Primary repair target |
| Hidden Policy Change | Primary repair target |
| Unowned Decision Path | Primary repair target |
| Decision Provenance Failure | Primary repair target |
| Policy Lineage Collapse | Primary repair target |
| Rollback Failure | Primary repair target |
| Governance Drift | Repairs / prevents |
| Rationale Erasure | Primary repair target |
| Tradeoff Suppression | Primary repair target |
| Shadow Governance | Often co-occurs |
| Accountability Evasion | Repairs / prevents |
| Institutional Forgetting | Recurrence risk |
3.3 Origin-Layer Localization
| Layer | Role |
|---|---|
| Failure Origin | Often U3 authority / decision process, U4 policy / rule expression, or U5 provenance / memory / review layer |
| Visible Symptom Layer | Often U4 policy change, enforcement behavior, model behavior, access change, ranking shift, or override |
| Required Repair Layer | Same or lower than the layer where decision ownership, rationale, or rollback path disappeared |
| Validation Layer | U6 / U7 through audit reconstruction, rollback performance, recurrence reduction, and successor review |
Canon rule:
A governance change is incomplete when future actors cannot determine who decided, why, under what authority, with what tradeoffs, and when the decision must be reviewed or reversed.
4. Restoration Objective
4.1 Canonical Objective
Restore decision provenance by creating a signed, reviewable record that binds decision ID, owner, rationale, tradeoffs, rollback criteria, and review date.
Formal objective:
decision_traceability ↑
decision_owner_clarity ↑
rationale_integrity ↑
tradeoff_visibility ↑
policy_lineage_integrity ↑
rollback_readiness ↑
review_date_integrity ↑
bias_injection_risk ↓
H ↓
Au ↑
Φ/O divergence ↓Expanded objective:
Convert hidden or weakly-owned governance change into a traceable, accountable, reviewable, and reversible decision record.
4.2 Non-Goals
This arc does not aim to:
- create documentation without accountability;
- sign decisions after the fact to launder unclear authority;
- hide tradeoffs under generic rationale language;
- use provenance to justify invalid decisions;
- expose sensitive data, security controls, or affected-node records unnecessarily;
- make every trivial choice bureaucratic;
- replace structural correction with recordkeeping;
- treat approval as legitimacy proof;
- make rollback optional where harms are foreseeable;
- preserve a decision record without review timing.
5. Operator Sequence
5.1 Minimal Operator Scaffold
Au decision ID / owner trace → Π affected-scope and disclosure boundary → Σ provenance / rollback invariant → FI review and impact feedback → Θ silent-drift damping → ℛ signed record / rollback / review routing → Λ decision-fit test → Τ review-date proofReference sequence from the registry:
create decision ID
→ name responsible actor(s)
→ record rationale
→ record tradeoffs
→ define rollback criteria
→ set review dateUniversal grammar alignment:
Au + Π → Σ → FI → Θ → ℛ → Λ → ΤSigned Decision Provenance may route into Authority Registry Clarification, Tamper-Evident Audit Restoration, Governance-Level Restoration, Constraint Recalibration Under Φ Growth, GEI Audit Restoration, or AI Classifier / Evaluator Restoration.
5.2 Operator Step Table
| Step | Operator | Function | Variable Impact | Failure Prevented |
|---|---|---|---|---|
| 1 | Au | Create decision ID and trace owner, authority, timestamp, and decision class | Au↑ / decision_traceability↑ | Ownerless decision |
| 2 | Π | Define affected scope, access boundary, disclosure boundary, and protected details | BΣ↑ / scope_clarity↑ | Overexposure or scope drift |
| 3 | Σ | Lock invariant that decisions require rationale, tradeoffs, rollback, and review | O protected / ι↓ | Provenance theater |
| 4 | FI | Connect field signal, affected-node signal, audit findings, and impact data to decision review | FI↑ | Decision self-sealing |
| 5 | Θ | Dampen silent drift, rationale erasure, bias concealment, and deployment urgency | K/σ↑ | Hidden policy change |
| 6 | ℛ | Route into signed record, rollback path, review date, and successor-readable lineage | R↑ / H↓ | Rollback failure |
| 7 | Λ | Test decision fit against authority, scope, rationale, tradeoffs, and field conditions | decision_fit↑ | Invalid decision reliance |
| 8 | Τ | Validate review timing, rollback readiness, and lineage integrity over time | review_date_integrity↑ | Institutional forgetting |
5.3 Sequence Notes
This arc is provenance-gated, rollback-gated, and review-date-gated.
The sequence must distinguish:
decision
authority
owner
rationale
assumption
tradeoff
affected scope
rollback criterion
review date
successor lineageThe following steps cannot be skipped:
decision ID
responsible actor or authority path
rationale record
tradeoff record
affected scope
rollback criteria
review date
lineage preservationIf a decision has a rationale but no owner, the arc is incomplete.
If it has an owner but no rollback criteria, the arc is incomplete.
If it has a rollback path but no review date, hidden drift can return.
6. Restoration Phases
Phase 0 — Identify Decision Object
Purpose: Name the decision requiring provenance.
Actions:
- identify policy, rule, constraint, override, deployment, access change, enforcement change, ranking shift, resource allocation, or governance decision;
- identify whether the decision is new, changed, inherited, emergency, experimental, or corrective;
- identify affected nodes and systems;
- identify decision class and risk level.
Validation:
decision object named
decision class visible
affected scope mappablePhase 1 — Create Decision ID
Purpose: Make the decision individually traceable.
Actions:
- assign durable decision ID;
- timestamp decision;
- link decision to authority registry where available;
- link decision to prior decision lineage;
- distinguish decision from implementation ticket or public announcement;
- mark decision status: proposed, active, suspended, rolled back, superseded, expired, or under review.
Validation:
decision_traceability ↑
policy_lineage_integrity ↑
future reconstruction possiblePhase 2 — Name Responsible Actor(s)
Purpose: Attach ownership.
Actions:
- name responsible actor, role, body, or authority path;
- identify approver and implementer separately where needed;
- identify advisory influence where it materially shaped the decision;
- identify review owner;
- identify rollback owner;
- identify successor owner if role changes.
Validation:
decision_owner_clarity ↑
responsibility_attachment ↑
orphaned decision risk ↓Phase 3 — Record Rationale
Purpose: Preserve why the decision was made.
Actions:
- record problem statement;
- record evidence basis;
- record assumptions;
- record expected benefit;
- record uncertainty;
- record constraints;
- record alternatives considered;
- record why this path was selected.
Validation:
rationale_integrity ↑
Au ↑
rationale erasure risk ↓Phase 4 — Record Tradeoffs
Purpose: Prevent hidden bias or cost transfer.
Actions:
- record expected harms and burdens;
- record affected-node risks;
- record false-positive / false-negative tradeoffs where applicable;
- record privacy, security, access, fairness, usability, and legitimacy tradeoffs;
- record who bears the cost;
- record how costs will be monitored;
- record mitigation commitments.
Validation:
tradeoff_visibility ↑
bias_injection_risk ↓
H ↓Phase 5 — Define Rollback Criteria
Purpose: Make the decision reversible or correctable.
Actions:
- define rollback trigger;
- define suspension trigger;
- define revision trigger;
- define appeal or exception trigger;
- define unacceptable harm thresholds;
- define monitoring data required;
- define who can roll back;
- define how rollback will be communicated.
Validation:
rollback_readiness ↑
K ↑
decision not self-sealingPhase 6 — Set Review Date
Purpose: Prevent decision drift and institutional forgetting.
Actions:
- set review date;
- define review cadence if ongoing;
- define review owner;
- define required evidence at review;
- define affected-node or field-signal input;
- define expiry if no review occurs;
- define successor handoff.
Validation:
review_date_integrity ↑
future_auditability ↑
institutional forgetting risk ↓Phase 7 — Validate Decision Fit Over Time
Purpose: Confirm the decision remains legitimate, coherent, and reversible.
Actions:
- monitor impact;
- monitor recurrence;
- monitor affected-node signal;
- monitor hidden costs;
- monitor whether rationale remains valid;
- monitor whether tradeoffs changed;
- monitor whether rollback criteria were triggered;
- update, suspend, supersede, or roll back the decision when required.
Validation:
decision_fit stable or ↑
H(t+n) ≤ H(t)
Φ/O divergence ↓7. Gates
7.1 Required Gates
| Gate | Requirement | Failure Result |
|---|---|---|
| FI-Gate | Field signal, affected-node signal, audit findings, and impact evidence must be able to trigger review or rollback | Decision self-seals |
| HR-Gate | High-risk decisions cannot proceed without owner, rationale, tradeoff record, rollback criteria, and review date | Decision reliance blocked |
| MS-Gate | High-status actors cannot make unsigned, unreviewable, or rollback-exempt decisions | Accountability invalid |
| Au-Actuation | Decision ID, owner, rationale, tradeoffs, rollback, and review date must be traceable | Actuation provisional |
| BΣ-Gate | Decision records must preserve privacy, security, affected-node boundaries, and disclosure limits | Arc aborts or reroutes |
| Λ-Gate | Decision must fit authority, scope, rationale, tradeoffs, and field conditions | Reliance blocked |
| ☷ᵢ Principle Gates | Non-negotiable invariants hold | ∅ outcome |
7.2 Gate Failure Rule
If any required gate fails:
∅ — Signed Decision Provenance cannot validly proceed in that form.The system must either:
- clarify authority;
- identify responsible actor;
- restore rationale record;
- record tradeoffs;
- define rollback criteria;
- set review date;
- protect disclosure boundaries;
- route to tamper-evident audit restoration;
- suspend reliance on the decision until provenance is sufficient.
8. Diagnostics
8.1 Required Diagnostic Trends
| Diagnostic | Expected Trend | Meaning |
|---|---|---|
| Au | ↑ | Decision becomes traceable |
| H | ↓ | Hidden decision debt decreases |
| O | Stable / ↑ | Decision aligns better with governance coherence |
| R | ↑ | Review, rollback, and repair capacity attach to the decision |
| BΣ | Stable / ↑ | Disclosure and affected-node boundaries remain protected |
| K / σ | ↑ | Actors have clearer review, appeal, and rollback paths |
| FI | ↑ | Impact signal can correct the decision |
| decision_traceability | ↑ | Decision ID and lineage are visible |
| rationale_integrity | ↑ | Why the decision occurred remains reconstructible |
| tradeoff_visibility | ↑ | Costs, risks, and burdens are not hidden |
| rollback_readiness | ↑ | Decision can be suspended, revised, or reversed |
| review_date_integrity | ↑ | Decision cannot drift indefinitely without review |
| bias_injection_risk | ↓ | Silent bias becomes harder to insert |
| policy_lineage_integrity | ↑ | Changes remain connected to prior and future states |
| decision_owner_clarity | ↑ | Owner, approver, implementer, and reviewer are distinguishable |
| Φ/O divergence | ↓ | Deployment or policy success aligns better with real coherence |
8.2 Arc-Specific Diagnostic Thresholds
Suggested thresholds:
decision_traceability ↑
decision_owner_clarity ↑
rationale_integrity ↑
tradeoff_visibility ↑
policy_lineage_integrity ↑
rollback_readiness ↑
review_date_integrity ↑
bias_injection_risk ↓
H ↓
Au ↑
Φ/O divergence ↓Signed Decision Provenance is not complete if:
decision ID is absent
responsible actor is unnamed
rationale is generic or unreconstructible
tradeoffs are hidden
affected scope is unclear
rollback criteria are missing
review date is absent
decision owner differs from actual authority path
decision record cannot survive future audit9. Anti-Patterns / False Restorations
9.1 Common False Versions
This arc is being simulated, not executed, if:
- a decision is recorded but not owned;
- the owner is named but authority is unclear;
- rationale is vague;
- tradeoffs are omitted;
- affected scope is minimized;
- rollback criteria are absent;
- review date is missing;
- decision provenance exists only in informal messages;
- implementation tickets replace governance records;
- approval is treated as legitimacy proof;
- policy lineage is overwritten by the latest version;
- high-status decisions are exempt from signing.
9.2 Named Anti-Pattern Links
| Anti-Pattern | Why It Fails |
|---|---|
| Signature Without Responsibility | Creates a signed artifact without real ownership |
| Rationale Fog | Uses vague justification that future auditors cannot reconstruct |
| Tradeoff Suppression | Hides who bears risk, burden, or harm |
| Rollbackless Decision | Allows harmful decisions to persist by default |
| Review-Date Omission | Lets decisions drift into permanent structure |
| Ticket-as-Governance | Treats implementation tracking as decision provenance |
| Approval Laundering | Treats approval as proof of legitimacy |
| Policy Lineage Erasure | Hides how current policy differs from prior policy |
| High-Status Unsigned Decision | Lets rank bypass provenance requirements |
10. Completion Criteria
10.1 Post-State Signature
| Variable | Required Post-State |
|---|---|
| O | Decision coherence improved through traceable ownership, rationale, tradeoffs, rollback, and review |
| H | Hidden decision debt reduced |
| ε | Confusion around why the decision occurred decreases |
| ι | Reduced where decisions gained authority without provenance |
| Au | Decision ID, owner, rationale, tradeoffs, rollback criteria, and review date traceable |
| µᵢ | Affected-node recourse and meaning of impact better preserved |
| BΣ | Disclosure, privacy, security, and affected-node boundaries protected |
| K | Review, appeal, rollback, and revision paths clearer |
| R | Decision repair and rollback capacity assigned |
| Φ | Subordinate to O; deployment speed, approval status, compliance appearance, or metric gain cannot certify restoration alone |
10.2 Temporal Proof
Signed Decision Provenance cannot be certified by record creation alone. It requires review and rollback readiness over time.
Template:
Completion requires decision_traceability ↑,
decision_owner_clarity ↑,
rationale_integrity ↑,
tradeoff_visibility ↑,
rollback_readiness ↑,
review_date_integrity ↑,
policy_lineage_integrity ↑,
bias_injection_risk ↓,
and decision review occurring when scheduled or triggered.Minimum temporal proof:
- future actors can reconstruct the decision;
- owner, authority, rationale, and tradeoffs remain visible;
- rollback criteria are usable;
- review date is honored;
- impact evidence can update or reverse the decision;
- hidden bias or policy drift becomes harder to introduce silently;
- successor governance inherits the decision lineage.
10.3 Completion Statement
Canonical format:
This arc is complete only when the decision has a durable ID, accountable owner, reconstructible rationale, visible tradeoffs, defined rollback criteria, review date, protected disclosure boundaries, and successor-readable lineage that remains auditable over time.
11. Cross-Links
11.1 Related Restoration Arcs
| Arc | Relationship |
|---|---|
RA-004 — Audit Surface Expansion | Precursor when the decision surface is insufficiently visible |
RA-012 — Temporal Proof Arc | Companion for review-date validation |
RA-040 — Responsibility Gradient Mapping | Companion when owner, benefit, capacity, or obligation is diffused |
RA-043 — Legitimacy Re-Anchoring | Follow-on when decision provenance supports legitimacy recovery |
RA-046 — Future-Compatible Accountability | Companion when decision accountability must survive time |
RA-049 — Governance-Level Restoration | Parent escalation when decision failure caused public or platform harm |
RA-050 — Authority Registry Clarification | Required precursor when authority path is unclear |
RA-052 — Tamper-Evident Audit Restoration | Companion when decision records must be protected from alteration |
RA-053 — Constraint Recalibration Under Φ Growth | Follow-on when influence growth changes decision burden |
RA-055 — GEI Audit Restoration | Companion when decisions shape epistemic or legitimacy fields |
RA-056 — Sovereignty Safeguard Restoration | Companion when decisions affect exit, portability, or dependency |
RA-058 — AI Classifier / Evaluator Restoration | Companion when decision changes evaluator or classifier behavior |
RA-060 — AI Incident Restoration | Companion when decision provenance is needed after AI harm |
11.2 Related Failure Modes
| Failure Mode | Relationship |
|---|---|
| Silent Bias Injection | Repairs |
| Hidden Policy Change | Repairs |
| Unowned Decision Path | Repairs |
| Decision Provenance Failure | Repairs |
| Policy Lineage Collapse | Repairs |
| Rollback Failure | Repairs / prevents |
| Governance Drift | Repairs / prevents |
| Rationale Erasure | Repairs |
| Tradeoff Suppression | Repairs |
| Shadow Governance | Repairs / prevents |
| Accountability Evasion | Repairs / prevents |
| Institutional Forgetting | Prevents |
11.3 Related Diagnostics
Au, H, O, R, BΣ, K, FI, decision_traceability, rationale_integrity, tradeoff_visibility, rollback_readiness, review_date_integrity, bias_injection_risk, policy_lineage_integrity, decision_owner_clarity, Φ/O divergence11.4 Related Laws / Invariants
INV — A governance decision must remain reconstructible.
INV — Authority without decision provenance creates hidden debt.
INV — Tradeoffs must be visible where burdens are imposed.
INV — Decisions that cannot be reviewed can become structure by default.
LAW — Hidden policy change compounds legitimacy decay.
LAW — Silent bias injection thrives in provenance gaps.
LAW — Rollbackless decisions become governance lock-in.
LAW — Φ deployment success is not O restoration.12. Domain Notes
12.1 AI / Cognitive Infrastructure
Check:
- model version decision;
- evaluator change;
- classifier threshold;
- guardrail policy;
- memory retention rule;
- tool-use permission;
- ranking or recommendation logic;
- refusal behavior;
- appeal policy;
- rollback criteria;
- review date.
AI decision provenance requires that model and policy behavior changes remain attributable, reviewable, and reversible across versions. Silent evaluator or classifier changes are high-risk because they can alter cognition, access, legitimacy, and meaning interpretation invisibly.
12.2 Platform Governance
Check:
- moderation policy decision;
- enforcement threshold;
- account restriction rule;
- appeal routing change;
- visibility or ranking change;
- user notification policy;
- data use change;
- reviewer guidance;
- rollback and review schedule.
Platform users are affected not only by written policy but by decisions that change how policy is interpreted and enforced.
12.3 Security
Check:
- security exception;
- privileged access approval;
- incident response decision;
- patch deferral;
- detection rule change;
- override;
- emergency measure;
- rollback criteria;
- compensating control;
- review date.
Security decisions without provenance become future attack surfaces because no one can reconstruct why a risk was accepted, who accepted it, or when it must be revisited.
12.4 Justice / Governance / Legitimacy
Check:
- decision owner;
- authority basis;
- affected party;
- rationale;
- burden distribution;
- review path;
- appeal path;
- rollback or correction path;
- public explanation when legitimacy requires it.
Legitimacy depends on whether consequential decisions can be traced and challenged, not merely whether they were procedurally approved.
12.5 Economy
Check:
- pricing decision;
- debt decision;
- access decision;
- labor policy decision;
- contract interpretation;
- settlement term;
- burden allocation;
- cost externalization;
- review or rollback.
Economic decisions create hidden debt when they move burdens, restrict exits, or change terms without visible provenance.
12.6 CMS / Meaning / Archetypes
Check:
- interpretive decision;
- symbolic authority decision;
- inclusion / exclusion decision;
- taboo enforcement;
- role recognition;
- narrative change;
- collective memory revision;
- review date.
Meaning systems require provenance when interpretive authority changes what can be recognized, named, remembered, or restored.
13. Machine-Readable Metadata
id: "RA-051"
title: "Signed Decision Provenance"
aliases:
- "Decision Provenance"
family_primary: "Governance / Auditability / Decision Integrity"
families_secondary:
- "Core"
- "AI Governance"
- "Justice / Governance / Legitimacy"
- "Auditability"
- "Institutional Design"
- "Security"
- "Platform Governance"
- "Boundary"
- "Coherence"
- "Scaling"
- "Authority"
treatment: "Canon Parent Arc"
status: "Canon-Ready"
scope:
- "Institutional"
- "AI"
- "Security"
- "Platform"
- "Economic"
- "Governance"
- "Civilizational"
- "Cross-Domain"
u_layers:
failure_origin:
- "often U3 authority / decision process"
- "often U4 policy / rule expression"
- "often U5 provenance / memory / review layer"
symptom_visible:
- "U4 policy change / enforcement behavior / model behavior / access change / ranking shift / override"
repair_required:
- "same or lower than layer where decision ownership, rationale, or rollback path disappeared"
validation:
- "U6"
- "U7"
operators:
scaffold: "Au decision ID / owner trace → Π affected-scope and disclosure boundary → Σ provenance / rollback invariant → FI review and impact feedback → Θ silent-drift damping → ℛ signed record / rollback / review routing → Λ decision-fit test → Τ review-date proof"
sequence:
- "Au"
- "Π"
- "Σ"
- "FI"
- "Θ"
- "ℛ"
- "Λ"
- "Τ"
state_variables:
primary:
- "Au"
- "H"
- "O"
- "R"
- "BΣ"
secondary:
- "K"
- "FI"
- "µᵢ"
- "Φ"
diagnostics:
- "decision_traceability"
- "rationale_integrity"
- "tradeoff_visibility"
- "rollback_readiness"
- "review_date_integrity"
- "bias_injection_risk"
- "policy_lineage_integrity"
- "decision_owner_clarity"
- "Φ/O divergence"
gates_required:
- "FI-Gate"
- "HR-Gate"
- "MS-Gate"
- "Au-Actuation"
- "BΣ-Gate"
- "Λ-Gate"
- "☷ᵢ"
linked_failure_modes:
- "Silent Bias Injection"
- "Hidden Policy Change"
- "Unowned Decision Path"
- "Decision Provenance Failure"
- "Policy Lineage Collapse"
- "Rollback Failure"
- "Governance Drift"
- "Rationale Erasure"
- "Tradeoff Suppression"
- "Shadow Governance"
- "Accountability Evasion"
- "Institutional Forgetting"
linked_restoration_arcs:
- "RA-004"
- "RA-012"
- "RA-040"
- "RA-043"
- "RA-046"
- "RA-049"
- "RA-050"
- "RA-052"
- "RA-053"
- "RA-055"
- "RA-056"
- "RA-058"
- "RA-060"
anti_patterns:
- "Signature Without Responsibility"
- "Rationale Fog"
- "Tradeoff Suppression"
- "Rollbackless Decision"
- "Review-Date Omission"
- "Ticket-as-Governance"
- "Approval Laundering"
- "Policy Lineage Erasure"
- "High-Status Unsigned Decision"
completion_tests:
- "decision_traceability increases"
- "decision_owner_clarity increases"
- "rationale_integrity increases"
- "tradeoff_visibility increases"
- "policy_lineage_integrity increases"
- "rollback_readiness increases"
- "review_date_integrity increases"
- "bias_injection_risk decreases"
- "hidden debt decreases"
- "auditability increases"
- "Φ/O divergence decreases"
summary: "Signed Decision Provenance repairs silent bias injection and hidden policy changes by assigning decision IDs, naming responsible actors, recording rationale and tradeoffs, defining rollback criteria, and setting review dates so governance changes remain traceable and reversible."Final Calibration Rule
Signed Decision Provenance answers six questions:
What decision changed the system?
Who or what authority owns the decision?
Why was the decision made, and what assumptions supported it?
What tradeoffs, risks, burdens, and affected scopes were accepted?
What rollback, suspension, revision, appeal, or exception criteria apply?
When must the decision be reviewed so hidden policy change, silent bias injection, and decision drift do not become permanent structure?