0. Registry Classification
| Field | Entry |
|---|---|
| Restoration Arc ID | RA-004 |
| Name | Audit Surface Expansion |
| Short Name / Alias | Audit Expansion |
| Primary Family | Auditability |
| Secondary Families | Core; Coherence; Security; Cybernetics; Justice / Governance / Legitimacy; AI Governance; Economy; Boundary |
| Treatment | Canon Parent Arc |
| Status | Canon-Ready |
| Scope | Local / Relational / Institutional / AI / Economic / Civilizational / Cross-Domain |
| Primary U-Layers | U3 / U4 → U5 / U6 / U7 validation |
| Primary Operators | Au → Μ → Ψ → Ξ → Π → Σ → Τ |
| Primary Diagnostics | Au, X_c, H, ι, Φ/O divergence, AP(t), τ_resp, τ_m |
1. Purpose
1.1 What This Arc Repairs
Audit Surface Expansion repairs situations where a system cannot restore coherence because the relevant decision paths, causal chains, provenance, authority surfaces, or affected-node verification channels are too opaque.
It applies when the system may have enough stability to investigate and repair, but not enough inspectability to know what actually moved, who or what acted, what constraints applied, where responsibility belongs, or which layer must be repaired.
This arc repairs auditability failure by:
- expanding the visible decision surface;
- exposing hidden causal pathways;
- preserving provenance;
- matching auditability to constraint complexity;
- making authority and action traceable;
- reducing opacity-protected hidden debt;
- converting uninspectable power into reviewable structure.
Audit Surface Expansion is the canonical arc for restoring traceability before action, responsibility assignment, or closure.
1.2 Core Restoration Function
This arc restores traceability by expanding the system’s audit surface until `Au_eff` is sufficient for the complexity of the constraint stack, allowing causal chains, decision authority, repair responsibility, and recurrence paths to become inspectable.
Audit Surface Expansion prevents restoration from being trapped inside opaque process, hidden authority, rule-stack fog, or unreviewable actuation.
2. Use Conditions
2.1 When to Apply
Use this arc when:
- cause, decision, consequence, or responsibility cannot be traced;
- auditability is lower than constraint complexity;
- a decision was made but authority is unclear;
- rules, policies, models, dashboards, or interfaces obscure causality;
- appeals are impossible because the affected node cannot see the decision path;
- a system claims compliance while hiding the actual mechanism;
- AI behavior, classifier outcome, tool action, or memory state cannot be reconstructed;
- security, governance, or institutional systems rely on unverifiable internal claims;
- repair cannot be assigned because the relevant causal surface is hidden;
- hidden debt is protected by opacity.
Examples:
- an AI system makes a consequential classification but cannot show trigger, policy, model, tool, or memory path;
- an institution enforces a decision without exposing authority, standard, evidence, or appeal path;
- a security dashboard shows compliance while breach causality remains inaccessible;
- economic or contractual flows hide real cost, risk, dependency, or extraction paths;
- a governance process invokes policy but cannot trace who changed it, why, and with what review.
2.2 When Not to Apply
Do not apply this arc when:
- active harm is still cascading and containment must come first;
- audit expansion would expose affected nodes to new harm without boundary protection;
- the system lacks any viable preservation channel;
- transparency would be performative while control remains hidden;
- auditability is being expanded only to intensify surveillance;
- the arc would create more hidden debt than it reveals;
- the system refuses to make audit outputs actionable;
- the needed repair layer is already known and immediate repair is required first.
Audit Surface Expansion must not become surveillance expansion or transparency theater.
2.3 Required Preconditions
Before this arc begins, the following must be true:
| Precondition | Requirement |
|---|---|
| Stabilization | Active harm slowed or contained enough for audit work |
| Boundary Protection | Audit process does not violate affected-node boundaries |
| Preservation Channel | Logs, records, testimony paths, state snapshots, or provenance artifacts can be preserved |
| Access Authority | Legitimate authority exists to inspect the relevant surface |
| Usefulness Standard | Audit outputs can affect repair, appeal, prevention, or accountability |
| Anti-Surveillance Constraint | Audit expansion does not become extraction or control expansion |
| Review Path | Audit process itself is reviewable |
If required preconditions fail:
Arc cannot validly begin.The system must return to stabilization, boundary protection, evidence preservation, or lower-risk legibility restoration before expanding the audit surface.
3. Failure / Damage Signature
3.1 Pre-State Across S
| Variable | Expected Pre-State |
|---|---|
| O — Coherence | Unknown, unstable, or claimed without traceable proof |
| H — Hidden Debt | Protected by opacity; difficult to locate or assign |
| ε — Error / Noise | Unclassified, hidden, suppressed, or attributed without trace |
| ι — Inversion Index | Rising when opaque process claims legitimacy |
| Au — Auditability | Insufficient, fragmented, suppressed, or below X_c |
| µᵢ — Agent Integrity | Vulnerable to unreviewable authority, role confusion, or invalid attribution |
| BΣ — Boundary Integrity | May be violated by opaque action, surveillance, or interface capture |
| K — Compatibility / Slack Context | Cannot be validated while authority and causality remain hidden |
| R — Restoration Capacity | Misallocated until the repair surface is traceable |
| Φ — Fitness Proxy | Often dominant through compliance, dashboard performance, legal defensibility, or institutional confidence |
3.2 Primary Failure Links
| Failure Mode | Relationship |
|---|---|
| Auditability Collapse | Primary repair target |
| Hidden Decision Surface | Primary repair target |
| Opaque Power | Primary repair target |
| Rule-Stacking Wall | Primary repair target |
| Interface Capture | Common precursor |
| Proxy-Relay Drift | Common precursor |
| Metric Substitution | Often co-occurs |
| Security Theater | False-restoration risk |
| Procedural Theater | False-restoration risk |
| AI Rule-Stacking Wall | Domain expression |
| Consent Theater | Often protected by audit failure |
3.3 Origin-Layer Localization
| Layer | Role |
|---|---|
| Failure Origin | Commonly U3 control / classifier / feedback, U4 rule / narrative / policy, or U5 timing / decision sequence |
| Visible Symptom Layer | Often U6 field harm, appeal failure, public trust loss, or dashboard mismatch |
| Required Repair Layer | Same or lower than the opaque decision or control layer |
| Validation Layer | U5 / U6 / U7 through reviewability, affected-node verification, and recurrence monitoring |
Canon rule:
Auditability must scale with constraint complexity. If
X_c > Au_eff, valid repair, appeal, and accountability cannot proceed.
4. Restoration Objective
4.1 Canonical Objective
Restore traceability by increasing effective auditability until the system can inspect the decision path, authority chain, evidence base, affected-node impact, and repair route.
Formal objective:
Au_eff ↑
X_c / Au_eff ↓
hidden decision surface ↓
causal trace recoverable
appeal path meaningful
Φ/O divergence visible or reducedExpanded objective:
Expand the audit surface until opacity no longer protects hidden debt, invalid authority, proxy substitution, or unreviewable harm.
4.2 Non-Goals
This arc does not aim to:
- expose everything by default;
- intensify surveillance;
- replace repair with transparency;
- overwhelm affected nodes with procedural burden;
- publish sensitive data without boundary protection;
- create dashboards that hide causality;
- produce reports without action;
- protect institutional reputation through controlled disclosure;
- improve compliance appearance while traceability remains low;
- make the audit surface larger but less usable.
5. Operator Sequence
5.1 Minimal Operator Scaffold
Au surface expansion → Μ decision-path mapping → Ψ signal recovery → Ξ opacity inversion detection → Π boundary-safe disclosure → Σ audit standard lock → Τ review validationUniversal grammar alignment:
Σ + Θ → Π → Au↑ → FI → ℛ routing → ΤThis arc typically routes into truth reconstruction, feedback integrity restoration, authority clarification, signed provenance, tamper-evident audit restoration, or origin-layer repair.
5.2 Operator Step Table
| Step | Operator | Function | Variable Impact | Failure Prevented |
|---|---|---|---|---|
| 1 | Au | Increase inspectable surface, trace, provenance, and reviewability | Au_eff↑ | Auditability collapse |
| 2 | Μ | Map decision paths, authority paths, dependencies, and affected surfaces | H map↑ / AP↓ | Hidden causality |
| 3 | Ψ | Recover missing signals and affected-node verification channels | ε classified / Au↑ | Salience capture |
| 4 | Ξ | Detect opacity-protected inversion and proxy substitution | ι↓ / Φ/O divergence visible | Security / compliance theater |
| 5 | Π | Bound audit exposure to prevent extraction or boundary violation | BΣ↑ | Surveillance expansion |
| 6 | Σ | Lock audit standards and admissibility rules | O protected / Φ constrained | Transparency theater |
| 7 | Τ | Validate that audit outputs remain usable over time | recurrence visibility↑ | One-time report closure |
| 8 | ℛ routing | Route to actual repair based on audit findings | R directed | Report-without-repair |
5.3 Sequence Notes
This arc is access-gated and boundary-gated.
Audit expansion is not always public disclosure. The required surface may be internal, affected-node accessible, regulator-accessible, cryptographically preserved, independently reviewable, or selectively disclosed.
The following steps cannot be skipped:
audit surface expansion
decision-path mapping
boundary-safe disclosure
opacity inversion detection
repair routingIf audit expansion increases control without increasing meaningful reviewability, the arc has inverted.
If transparency produces data without action, the arc has collapsed into theater.
6. Restoration Phases
Phase 0 — Confirm Audit Need
Purpose: Establish that insufficient auditability is blocking repair, appeal, prevention, or accountability.
Actions:
- identify the decision, harm, rule, model, pathway, or authority surface that cannot be traced;
- estimate constraint complexity
X_c; - compare current auditability against required auditability;
- identify what cannot be known under the current surface.
Validation:
X_c > Au_eff identified
hidden surface named
repair or appeal blocked by opacityPhase 1 — Preserve Existing Trace
Purpose: Prevent loss, deletion, distortion, or narrative overwrite of already-available evidence.
Actions:
- preserve logs, records, communications, decision IDs, source states, and state changes;
- preserve chain-of-custody where applicable;
- record current authority claims;
- prevent retroactive sanitization;
- protect affected-node verification paths.
Validation:
existing trace preserved
provenance not degraded
future reconstruction remains possiblePhase 2 — Map Decision and Authority Surface
Purpose: Make power, decision, control, and dependency pathways inspectable.
Actions:
- identify who or what acted;
- identify rules, models, policies, classifiers, or contracts used;
- map authority chain;
- map review chain;
- map affected-node interface;
- identify override or exception paths.
Validation:
decision path visible
authority path visible
override path visible
affected interface namedPhase 3 — Expand Audit Resolution
Purpose: Increase auditability until it can match the complexity of the system being inspected.
Actions:
- expose missing provenance;
- increase logging or trace resolution;
- simplify rule stacks where needed;
- document decision criteria;
- make appeal-relevant facts accessible;
- create independent review channel where appropriate.
Validation:
Au_eff ↑
X_c / Au_eff ↓
audit surface adequate for next actionPhase 4 — Detect Opacity Inversion
Purpose: Identify where opacity has allowed appearance, authority, or proxy success to replace coherence.
Actions:
- compare compliance claims to field effects;
- compare dashboard outputs to affected-node state;
- identify proxy-relay drift;
- identify hidden exemptions;
- identify unreviewable actuation;
- identify where opacity protects hidden debt.
Validation:
opacity-protected H visible
Φ/O divergence visible or decreasing
ι begins decreasingPhase 5 — Boundary-Safe Disclosure
Purpose: Ensure expanded auditability does not become exposure, extraction, or surveillance.
Actions:
- define who needs access to what and why;
- protect sensitive affected-node data;
- preserve consent and scope;
- separate public proof from private evidence;
- make the audit path useful without overexposure.
Validation:
BΣ preserved
audit access scoped
reviewability increases without extractionPhase 6 — Route to Repair
Purpose: Convert audit expansion into restoration, not just visibility.
Actions:
- identify required follow-on arc;
- route to origin-layer repair, feedback restoration, authority clarification, or truth reconstruction;
- define responsibility-mapping requirements;
- establish temporal review window;
- preserve audit trail for recurrence validation.
Validation:
next restoration arc selected
audit outputs actionable
report does not replace repair7. Gates
7.1 Required Gates
| Gate | Requirement | Failure Result |
|---|---|---|
| FI-Gate | Audit must support feedback aligned to O, not only Φ | Arc resets |
| HR-Gate | No certainty claims exceeding trace support | Claim blocked |
| MS-Gate | No status exemption from audit surface | Audit invalid |
| Au-Actuation | Actuation must be traceable before enforcement or repair | Actuation forbidden or provisional |
| BΣ-Gate | Audit expansion must preserve boundaries and scope | Arc aborts or reroutes |
| Λ-Gate | Audit findings alone do not authorize recoupling | Recoupling blocked |
| ☷ᵢ Principle Gates | Non-negotiable invariants hold | ∅ outcome |
7.2 Gate Failure Rule
If any required gate fails:
∅ — Audit Surface Expansion cannot validly proceed in that form.The system must either:
- protect boundaries first;
- preserve evidence without disclosure;
- reduce audit scope;
- add independent review;
- expand traceability before actuation;
- reroute to truth reconstruction;
- block enforcement until auditability is adequate.
8. Diagnostics
8.1 Required Diagnostic Trends
| Diagnostic | Expected Trend | Meaning |
|---|---|---|
| Au | ↑ | Auditability and traceability improve |
| X_c / Au_eff | ↓ | Auditability better matches constraint complexity |
| H | Becomes visible, then repairable | Hidden debt no longer protected by opacity |
| ι | ↓ | Opacity-protected inversion weakens |
| Φ/O divergence | Visible or ↓ | Proxy success no longer hides coherence loss |
| AP(t) | ↓ | Attribution pressure differentiates into causal trace |
| τ_resp | ↓ | Response improves because trace is accessible |
| τ_m | More observable | Recurrence memory becomes inspectable |
| BΣ | Stable / ↑ | Audit does not violate boundaries |
| R | More directed | Repair capacity can be aimed correctly |
8.2 Arc-Specific Diagnostic Thresholds
Suggested thresholds:
Au_eff increases before enforcement, closure, or recoupling
X_c / Au_eff decreases to acceptable range
decision provenance becomes traceable
authority path becomes reviewable
affected-node verification path exists where applicable
audit output routes to repairAudit Surface Expansion is not complete if:
audit outputs are unusable
audit increases surveillance without reviewability
status exemption remains
decision provenance is still hidden
Au decreases after disclosure
report publication substitutes for repair
Φ improves while O remains unverified9. Anti-Patterns / False Restorations
9.1 Common False Versions
This arc is being simulated, not executed, if:
- transparency produces volume without traceability;
- audit access exists only for the authority being audited;
- disclosure overwhelms rather than clarifies;
- dashboards replace decision provenance;
- reports are published without repair routing;
- audit expansion becomes surveillance expansion;
- affected-node data is exposed without protection;
- process is reviewable only in theory;
- authority remains hidden behind policy, interface, model, or vendor layers;
- appeals exist but cannot inspect the decision path;
- compliance artifacts hide field incoherence.
9.2 Named Anti-Pattern Links
| Anti-Pattern | Why It Fails |
|---|---|
| Transparency Theater | Shows information without enabling review, repair, or appeal |
| Surveillance Expansion | Increases visibility into affected nodes while preserving opaque power |
| Compliance Theater | Produces artifacts while causal trace remains hidden |
| Audit Capture | Audit surface is controlled by the system being audited |
| Rule-Stacking Wall | Complexity exceeds auditability |
| Interface Capture | Interface controls what can be seen or contested |
| Report Without Repair | Audit output is treated as completion |
10. Completion Criteria
10.1 Post-State Signature
| Variable | Required Post-State |
|---|---|
| O | More inspectable and no longer certified by proxy alone |
| H | Visible enough to route repair |
| ε | Bounded, classified, and attributable |
| ι | Reduced through opacity exposure |
| Au | Increased to adequate level for next action |
| µᵢ | Protected from invalid attribution or unreviewable authority |
| BΣ | Preserved through scoped audit exposure |
| K | Not used for recoupling unless later validated |
| R | Directed toward repair path revealed by audit |
| Φ | Subordinate to O; compliance artifacts cannot certify coherence |
10.2 Temporal Proof
Audit Surface Expansion cannot be declared complete until the expanded surface remains usable over time.
Template:
Completion requires Au_eff(t+n) ≥ Au_eff(t),
X_c / Au_eff decreasing,
decision provenance remaining traceable,
and audit output routing into repair rather than closure.Minimum temporal proof:
- decision path remains accessible after initial review;
- authority path remains reviewable;
- audit trail resists retroactive alteration;
- affected-node verification remains possible where applicable;
- follow-on repair arc is selected;
- recurrence can be inspected through the expanded surface.
10.3 Completion Statement
Canonical format:
This arc is complete only when the decision, authority, evidence, and affected-node surfaces are sufficiently traceable for repair, appeal, prevention, or accountability to proceed without relying on opaque trust.
11. Cross-Links
11.1 Related Restoration Arcs
| Arc | Relationship |
|---|---|
RA-002 — Truth and Causal Clarification | Precursor or companion when causality is unclear |
RA-003 — Origin-Layer Repair | Follow-on after audit reveals required repair layer |
RA-008 — Feedback Integrity Restoration | Companion when metrics or feedback are captured |
RA-016 — Truth Reconstruction | Follow-on when evidence was suppressed or distorted |
RA-017 — U4-to-U6 Validation | Companion when claims must be field-tested |
RA-050 — Authority Registry Clarification | Domain expression for hidden authority |
RA-051 — Signed Decision Provenance | Domain expression for decision traceability |
RA-052 — Tamper-Evident Audit Restoration | Domain expression for protected audit history |
11.2 Related Failure Modes
| Failure Mode | Relationship |
|---|---|
| Auditability Collapse | Repairs |
| Hidden Decision Surface | Repairs |
| Opaque Power | Repairs |
| Rule-Stacking Wall | Repairs |
| Interface Capture | Often co-occurs |
| Proxy-Relay Drift | Often co-occurs |
| Metric Substitution | Often co-occurs |
| Security Theater | False-restoration risk |
| Procedural Theater | False-restoration risk |
| AI Rule-Stacking Wall | Domain expression |
| Consent Theater | Often protected by audit failure |
11.3 Related Diagnostics
Au, X_c, H, ι, Φ/O divergence, AP(t), τ_resp, τ_m, BΣ, R11.4 Related Laws / Invariants
INV — Coherence cannot be inferred from appearance alone.
INV — Repair requires traceability sufficient to locate the failure layer.
LAW — Auditability must scale with constraint complexity.
LAW — Φ improvement is not O restoration.
LAW — Responsibility requires traceability.
LAW — Opaque power accumulates hidden debt.
LAW — Appeal without inspectability is procedural theater.12. Domain Notes
12.1 AI / Cognitive Infrastructure
Check:
- model output provenance;
- classifier trigger path;
- system / developer / policy constraint pathway;
- tool-call trace;
- memory access and retrieval trace;
- evaluator and benchmark provenance;
- authority registry;
- user-facing appeal path;
- whether logs are sufficient for incident reconstruction.
AI audit expansion must distinguish model behavior, policy layer, memory layer, tool layer, evaluator layer, product layer, and governance layer.
12.2 Justice / Governance / Legitimacy
Check:
- authority chain;
- enforcement criteria;
- decision standard;
- evidence access;
- appealability;
- rank immunity;
- public vs private legitimacy claims;
- whether disclosure protects truth or controls narrative.
Audit expansion in JGL systems must make power traceable without exposing harmed nodes to extraction.
12.3 Biology / Medicine
Conceptual systems mapping only.
Audit Surface Expansion in biological systems means improving traceability of trigger, boundary condition, timing, clearance, recurrence, load, signal pathway, and repair response.
Not diagnosis.
Not treatment.
Not medical advice.
12.4 Economy
Check:
- hidden flows;
- debt chains;
- externalized costs;
- contract dependencies;
- ownership/control pathways;
- allocation rules;
- survival-edge pressure;
- whether profit
Φhides coherence loss.
Economic audit expansion makes circulation, burden, dependency, and extraction pathways inspectable.
12.5 CMS / Meaning / Archetypes
Check:
- symbolic authority claims;
- sacred immunity;
- taboo-protected opacity;
- identity-bound certainty;
- archetypal role claims;
- meaning systems that cannot be questioned;
- whether mystery is preserving depth or suppressing auditability.
Meaning systems can preserve symbolic compression while still allowing audit gates to operate.
13. Machine-Readable Metadata
id: "RA-004"
title: "Audit Surface Expansion"
aliases:
- "Audit Expansion"
family_primary: "Auditability"
families_secondary:
- "Core"
- "Coherence"
- "Security"
- "Cybernetics"
- "Justice / Governance / Legitimacy"
- "AI Governance"
- "Economy"
- "Boundary"
treatment: "Canon Parent Arc"
status: "Canon-Ready"
scope:
- "Local"
- "Relational"
- "Institutional"
- "AI"
- "Economic"
- "Civilizational"
- "Cross-Domain"
u_layers:
failure_origin:
- "commonly U3"
- "commonly U4"
- "commonly U5"
symptom_visible:
- "U6 field harm"
- "appeal failure"
- "public trust loss"
- "dashboard mismatch"
repair_required:
- "same or lower than opaque decision or control layer"
validation:
- "U5"
- "U6"
- "U7"
operators:
scaffold: "Au surface expansion → Μ decision-path mapping → Ψ signal recovery → Ξ opacity inversion detection → Π boundary-safe disclosure → Σ audit standard lock → Τ review validation"
sequence:
- "Au"
- "Μ"
- "Ψ"
- "Ξ"
- "Π"
- "Σ"
- "Τ"
- "ℛ routing"
state_variables:
primary:
- "Au"
- "X_c"
- "H"
- "ι"
secondary:
- "O"
- "BΣ"
- "R"
- "Φ"
diagnostics:
- "Φ/O divergence"
- "AP(t)"
- "τ_resp"
- "τ_m"
gates_required:
- "FI-Gate"
- "HR-Gate"
- "MS-Gate"
- "Au-Actuation"
- "BΣ-Gate"
- "Λ-Gate"
- "☷ᵢ"
linked_failure_modes:
- "Auditability Collapse"
- "Hidden Decision Surface"
- "Opaque Power"
- "Rule-Stacking Wall"
- "Interface Capture"
- "Proxy-Relay Drift"
- "Metric Substitution"
- "Security Theater"
- "Procedural Theater"
- "AI Rule-Stacking Wall"
- "Consent Theater"
linked_restoration_arcs:
- "RA-002"
- "RA-003"
- "RA-008"
- "RA-016"
- "RA-017"
- "RA-050"
- "RA-051"
- "RA-052"
anti_patterns:
- "Transparency Theater"
- "Surveillance Expansion"
- "Compliance Theater"
- "Audit Capture"
- "Rule-Stacking Wall"
- "Interface Capture"
- "Report Without Repair"
completion_tests:
- "Au_eff increases before enforcement, closure, or recoupling"
- "X_c / Au_eff decreases to acceptable range"
- "decision provenance becomes traceable"
- "authority path becomes reviewable"
- "affected-node verification path exists where applicable"
- "audit output routes to repair"
summary: "Audit Surface Expansion restores traceability by expanding the inspectable decision, authority, evidence, and affected-node surfaces until repair, appeal, prevention, or accountability can proceed."Final Calibration Rule
Audit Surface Expansion answers six questions:
What hidden debt is protected by opacity?
What boundary must be preserved while auditability increases?
What decision, authority, evidence, or affected-node surface must become traceable?
What coupling, enforcement, or closure must remain blocked until auditability is adequate?
What repair trajectory becomes selectable once the audit surface expands?
How is auditability proven usable over time rather than performed once?