verification contract · VS v1 · how done is judged

Verification Spec

In a build with no dates and no supervisor, done must be a fact about the record rather than a feeling about the work. This document defines that fact: the five suites that run as code, how a packet proves its acceptance, the gates each slice must pass with a human attestation, and the walkaway test as something executed rather than admired. The document governs; the workflow it emits distills.

status · Drafted cites · BP v1 · IM v0.1 · PRD v0.3 · SER v0.1 consolidates · VERIFICATION.md · C3 · C11 · retires C9 emits · verify.yml RegenHub, LCA · Boulder · July 2026
§1

Preamble

This contract consolidates the estate's verification layer: the CI job contracts of VERIFICATION.md, the verification definitions of C3, and the C11 wave gates, rewritten from waves to slices. The C9 KPI fixture pack retires with the grant it measured, per the deprecation record at PRD v0.3 §1a; its useful habit, designed pass and fail cases, carries without its KPIs, under the fixture discipline of §7.

The same honest limit that bound the Build Protocol binds this document: the estate files hold check contracts at a finer grain than the commons index records, and those are not silently dropped. The reconciliation packet BP v1 §1 opened grows in scope to include VERIFICATION.md, C3, and C11: at the merge, each finer-grained contract is adopted here by amendment or retired by name. Open · reconciliation packet, scope grown

The emission continues the series pattern: verify.yml is the workflow the repository actually runs, and the invariant assertions inside it execute against the substrate migration IM v0.1 emitted, so the schema's refusals are proven, not presumed. What the workflow cannot honestly run yet, it names as deferred rather than faking green.

§2

The five suites

Every merge runs five suites. Three are fully runnable today; two run in their honest partial form and grow with the artifacts they wait on.

carries unchangedledger-validateThe estate's validator on the packet ledger: schema compliance, dependency acyclicity, and gating consistency, with done requiring verified upstream. This suite is why the ledger can be trusted as a scheduler.
new · audit prerequisiteschema-lintStatic discipline on the substrate: migrations timestamped and ordered, every table commented, every future policy carrying its bylaw anchor per cite-as-you-enforce. A policy without an anchor does not merge; the lint is how that rule stops being a sentence and becomes a gate. Absorbs the schema-lint prerequisite the pre-build audit named.
runnable nowdb-verifyThe invariant suite of §4: a fresh database, the migrations applied, and the conserved quantities of IM v0.1 §6 proven by attempted violation. The substrate is trusted because it demonstrably refuses.
honest partialrls-auditThe visibility suite. Until the Authority Map lands, its whole expectation matrix is one row repeated: every probe, on every table, denied. That is runnable today and is exactly what the deny-by-default posture claims. When AM cites its anchors, the C7 probe shape returns as roles by tables, expectations sourced from the map, never from the code.
newstyle-lintThe house rules as CI, on authored documents and pages: the vocabulary quarantine (the retired cooperative-tax terms appear nowhere), no em dashes, no emoji, and no raw hex outside the token layer on site pages. Editorial discipline that runs on every merge stops depending on anyone's vigilance, including Todd's.

The signal loop's synchronization job carries alongside these but is not of them: it feeds an attention instrument, and an instrument is not an authority, per BP v1 §8.

§3

Proving a packet

A packet's acceptance field is its test statement, written so this document can check it. For slice work, the member-capability sentences of PRD v0.3 §4 are the acceptance language verbatim: each sentence beginning a member can is demonstrated, not asserted.

Done is a conjunction, never a mood: the five suites green on the packet's branch; the acceptance demonstrated in a way the reviewer can reproduce; the review tier of BP v1 §6 satisfied, with a decision record where the tier demands one; and the status changed by commit. A failed check does not argue, it names: the packet's status becomes the Open chip carrying the check's name, blocked · db-verify/one-voting-share, so the status table reads as reasons. And the protocol's last line binds here with full force: if unsure whether done, not done.

§4

The invariant assertions

What db-verify proves, each assertion mapped to the law and locus it exercises. The suite's method is attempted violation: the test tries to break the invariant and passes only when the substrate refuses.

append-onlyAn update and a delete are attempted on events; the trigger must raise. Law I, IM v0.1 §4.
one-voting-shareA second issued voting share for the same agent is inserted; the partial unique index must refuse. Law III, IM v0.1 §6.
lifecycle-legalityAn illegal transition, applied straight to suspended, is attempted; the automaton trigger must raise. Law VI.
no-stored-balanceThe information schema is scanned: no base table carries a balance-like column. Balances exist only as folds. Law VII, IM v0.1 §7.
replay-holdsKnown capital events are inserted and the capital_accounts view must equal their hand-computed folds, both projections. Law I and VII, the smallest true replay.
rls-everywhereEvery launch table reports row security enabled; a probe role with table grants and no policies reads zero rows. Law V in its deny-by-default form.

Assertions for vote arithmetic, the patron-majority floor, allocation sums under substantial economic effect, and the paired covering distribution are stated in IM v0.1 §6 and enter this suite when their slices land; listing them green before their schema exists would be a plan dressed as a fact. Anticipated · with their slices

§5

The gates

Gates replace the wave gates one for one in mechanics and change only in shape: a gate now closes a slice, not a wave. Each gate is a named set of required checks plus a human attestation, and passing it is what unlocks the packets that cite it. Parts are proven by steps; the whole is proven here, and that estate phrase carries verbatim.

carries unchangedG0 · security floorThe pre-slice gate, inherited whole: conservation enforced in the database, the audit log structural, row security enabled and denying without the map, backup taken and restore actually performed. No slice gate can be attempted while G0 is red.
gate · august 14G-B · BelongThe Belong acceptance sentences demonstrated end to end: read, sign, appear, onboard. All five suites green; attestation by an organizer and by one member who is not an organizer, since the curious-newcomer criterion cannot be self-attested.
gate · august 14G-G · GatherThe Gather sentences demonstrated: see, register, cancel, be counted. Same suites, same two-party attestation.
following sliceG-F · Find one anotherThe opportunity lifecycle demonstrated open to resolved, with the resolution landing as an event, not a table row. Slice name pending the short-form question. Open · naming
after counting rulesG-S · See your shareThe fold shown to a member equals the fold computed by hand from their events, both projections, with every figure traceable to its inputs. blocked · Q3
the flipG-R · ratificationThe gate the vote opens. Every bylaw anchor in the schema and the Authority Map is re-verified against the ratified text, and only through this gate may any surface begin to display the Ratified mark. Until G-R passes, a Ratified chip anywhere is itself a lint failure.
§6

Attestation as events

A gate attestation is not a checkbox in a workflow run; it is a record in the system the gate protects. Passing a gate writes an event, gate.attested, carrying the gate's name, the suites' run references, and the human actors, per Laws II and X: the act of attesting is a happening, and it belongs to people.

This closes a loop worth naming: the record verifies the build, and the build's verification becomes part of the record. An auditor asking whether a gate truly passed queries the same ledger a member queries for their capital account, with the same traceability, and the answer never depends on a CI provider's retention window.

§7

Fixtures and simulation

C9 retires, its habit survives. Designed cases that should pass and designed cases that must fail remain the best way to prove an assertion means something; only the KPIs they measured are gone.

Fixture discipline follows the simulation rule of BP v1 §5 without exception: fixture and demonstration data carries provenance: illustrative at creation, lives only in test databases and branch environments, and writes nothing back to live records. The db-verify suite builds its world fresh on every run and discards it after; a fixture that leaks into the ledger is a defect the suites themselves should catch, which is why the live record is also linted for illustrative provenance outside designated demonstration surfaces.

§8

The walkaway test, executable

Law XI's promise, turned into a procedure: on infrastructure the cooperative does not control, a stranger with only the published artifacts can stand the system up and arrive at the same state.

The procedure, stated so a harness can run it: provision a fresh database from nothing but the public repository; apply the migrations in order; load each table's documented export together with the event log; replay; and compare every fold, both capital projections included, against the folds published by the source system. The run must complete within the bounded recovery window Law XI names, and it must require no conversation with anyone at RegenHub, which is what without renegotiation means operationally.

The harness is a packet, not yet a suite: it enters verify.yml on a schedule rather than on every merge once the first per-table exports land, and its first green run is a success criterion of PRD v0.3 §10, not a decoration. Anticipated · harness packet

§9

The emission, and amendment

The workflow verify.yml distills this document into five jobs. Today it runs honestly: ledger-validate calls the estate validator where the ledger exists; schema-lint and style-lint run whole; db-verify provisions a database in the runner, applies 0001_substrate.sql, and executes every §4 assertion by attempted violation; rls-audit proves deny-by-default with a grant-bearing, policy-less probe role. The probe matrix, the walkaway harness, and the with-their-slices assertions are named in the workflow as deferred, in comments a reader can find, because a suite that fakes green teaches people to ignore it.

Changes to this document are Tier C under BP v1 §6, and a change that weakens a check is a regression to be named, never absorbed, which is the one sentence of the old gate discipline this refactor keeps with pride. The workflow versions with the document; supersession is explicit; the superseded contracts remain in the record as history.

the working agreement of this contract

A green suite is not the truth; it is the absence of known lies, kept honest by checks that try to break what they protect. The suites exist so that done is a fact about the record, and so that trust in the build, like trust in the cooperative, never has to be taken on anyone's word, including ours.