{"slug":"big-four-isae-3000-ai-assurance","title":"AI assurance under ISAE 3000: the evidence object the engagement is missing","body":"## The engagement the profession has accepted without an evidence object\n\nISAE 3000 (Revised) — the IAASB's *Assurance Engagements Other than Audits or Reviews of Historical Financial Information* — is the standard the large firms reach for when a client asks for assurance over something that is not a set of accounts: controls, processes, and now AI systems. Its demands are not exotic. The practitioner must apply **professional skepticism and judgement**; obtain **sufficient appropriate evidence**; assess the **suitability of the criteria** the subject matter is measured against; and document the engagement so that *an experienced practitioner, having no previous connection with the engagement, can understand the significant matters and the basis for the conclusion*.\n\nThe newer sustainability standard, **ISSA 5000** — approved by the IAASB in September 2024, effective for periods beginning on or after 15 December 2026 — carries the same architecture into information produced by *systems and estimation processes*, not ledgers. The profession is moving toward assuring machine-produced conclusions, and every major firm is standing up an AI assurance practice against the demand created by the EU AI Act, ISO/IEC 42001, and clients who want a signed opinion that their AI system does what its documentation says.\n\nNow put the standard next to the subject matter. For a large language model deployed the ordinary way, **there is nothing to inspect**. The system emits answers, not records of how each answer was reached that anyone can re-open, compare, or test. The practitioner's toolkit — inspection, reperformance, recalculation — has no object to operate on. What fills the gap today is testimony about the process: policy documents, governance minutes, a sampled review where a human agreed with the model's output. That is evidence *about the organisation*, not evidence about the decisions.\n\nAn experienced practitioner handed that file cannot reconstruct why any individual decision came out the way it did. The documentation requirement — the sentence in the standard that operationalises all the others — is being met at the wrong altitude.\n\n## A candidate evidence object, running\n\nThis site runs a decision system built the other way around: the evidence object comes first, and the decision is only valid if the object exists. Every claim below opens to a live receipt.\n\nOne governed decision works like this. The **rule set** — the criteria, in assurance vocabulary — is pinned to a content hash, so the version applied is beyond dispute; the **record** under review is hashed the same way. Three model seats across two model families each receive the identical rule set and record under a governing constitution that compels a fixed output shape: the verdict, the clauses relied on, a clause-by-clause derivation (did each clause's condition trigger, does it support or defeat the action, on which evidence records), the records that were **absent**, the strongest rejected alternative, and what evidence would flip the conclusion.\n\nA deterministic parser — ordinary software, not another model — voids anything structurally invalid: an invented clause, a missing field, an absent decision line can never authorise. The surviving findings go to the **derivation-agreement gate**, which compares not verdicts but derivations, tuple by tuple. Only when independent seats agree on the answer *and* on the clause-level route to it does the decision seal. Anything less escalates to a named human, and the escalation is itself a permanent receipt.\n\n[[embed:source:s1]]\n\nRead that as an evidence-gathering procedure. Inspection: the sealed record carries complete payloads, not summaries. Reperformance: the hashed rule set and record can be re-run through the same seats later. Recalculation: the gate's comparison is deterministic and repeatable from the preserved derivations. The object is *shaped to provide* what ISAE 3000's evidence requirement asks for — a design claim, not a conformance claim; the distance between the two is measured further down.\n\n## Skepticism, mechanised — the exhibit\n\nThe centre of ISAE 3000 is professional skepticism. Here is what that looks like executed by machinery. Three seats returned the **same conclusion**, citing the **same clauses** — and the gate still refused to conclude, because two of them had derived that conclusion through different trigger states:\n\n[[embed:source:s2]]\n\nIn a testimony-based file, \"three independent reviewers concurred\" closes the working paper. Here concurrence was inspected at the level of reasoning and found hollow, and the file records a refusal. When the panel does agree derivation-for-derivation, the artifact is just as inspectable — the one clean authorisation on record:\n\n[[embed:source:s3]]\n\nThe gate itself has a documented failure, and this is the part a practitioner should weigh most. Its first version compared clause *numbers* and sealed an approval on citations that matched by number while meaning different things — false convergence. The seal was retracted as invalid; the repaired gate compares canonical derivation tuples, and both the defective seal and its replacement are public receipts, linked from the gate write-up above. An instrument that documents its own failed audit is exhibiting the behaviour it proposes to evidence.\n\n## Design effectiveness: the governing text is a measured variable\n\nDoes the governing constitution actually cause the auditable behaviour, or would the models behave this way anyway? That has a measured answer. A 72-call controlled study ran three prompt arms — bare, thin instructions, full constitution — across three models, eight runs each, on a case with known ground truth:\n\n[[embed:source:s4]]\n\nAuditable structure — declared-absent records, flip conditions, rejected alternatives — appeared in **zero of 48 ungoverned calls** and only under the constitution. Clause-citation agreement rose from 0.74 to 0.95 (Jaccard) as governance tightened. For a test of design effectiveness that is the load-bearing finding: the control is a causal input with a measured effect, not a style preference.\n\n## Operating effectiveness: the calibration study, with its limits attached\n\nThe question a signing partner actually needs answered is not \"do the seats agree\" but \"how often does the sealed outcome authorise a wrong answer.\" The first calibration study exists: 30 oracle-labelled synthetic cases, balanced across should-affirm, should-deny, and should-abstain, run through the production gate:\n\n[[embed:source:s5]]\n\nThe numbers, exactly: glm-5.2 was correct on 30 of 30 cases, kimi-k2.7 on 29 of 30, and across all 30 sealed panels there were **zero wrongful authorisations**. The third seat's transport failures blocked every NEGATE seal — the system's failure mode under a degraded seat was refusal, not error. And the limits, just as exactly: these are synthetic, determinate fixtures in one task class. The study measures the gate's behaviour on cases with a known answer; it does not establish accuracy on contested, real-world subject matter. It is the first row of an operating-effectiveness file, not the file.\n\n## The absence declaration, and ISA 705\n\nEvery sealed record here must declare the evidence it **did not receive** — the absence declaration is a mandatory field. When a required record is missing, the panel does not guess: it seals an abstention naming the absence. Here is that outcome, produced when a record was deliberately withheld:\n\n[[embed:source:s7]]\n\nThe assurance profession already has this rule. ISA 705 makes *inability to obtain sufficient appropriate evidence* a basis for modifying the opinion — the practitioner who cannot get the evidence must say so in the conclusion itself. The field-by-field mapping of the sealed record to the standards that demand each field, including that ISA 705 row, is its own artifact:\n\n[[embed:source:s6]]\n\nThe mapping is a candidate mapping — drawn by this system, not accepted by any standard-setter. But the structural point survives the caveat: modified-opinion logic, which the profession applies once per report, executes here once per decision, and leaves a record each time.\n\n## What the working paper costs\n\nA governed call runs $0.0006 to $0.0024 and a full three-seat sealed decision about half a cent. Evidence at the decision grain costs less than the storage of the memo it would support. The economic objection to per-decision assurance evidence does not survive contact with the receipt.\n\n## What is not satisfied\n\nStated plainly, because an evidence object that oversells itself is defective by its own standard:\n\n- **No conformance is established.** Nothing here has been accepted by a standard-setter, a regulator, or a firm's methodology group as meeting ISAE 3000's evidence or documentation requirements. The object is shaped to them; shape is a design claim.\n- **Criteria suitability is untested on real subject matter.** The rule sets run so far are bounded fixtures. Whether real engagement criteria survive the same pinning and derivation discipline is unproven — and the nearest evidence is instructive: a governed seat asked to critique its own case file found eight defects, the lead one a rule-set ambiguity that had caused every prior derivation divergence. Most reasoning failures were specification failures. [[embed:source:s8]]\n- **The calibration base is 30 synthetic determinate cases in one task class.** Zero wrongful authorisations on that base is a real number and a small one — not an actuarial basis, and no study yet covers contested or estimation-heavy subject matter of the ISSA 5000 kind.\n\nA methodology reviewer should treat those three gaps as the agenda. Everything else on this page is already openable.\n\n\n### Posted: 2026-07-30\n\nThis article was announced publicly on X; the post is part of its record, exactly as the correspondence is. Post: [https://x.com/CannibalCapital/status/2082883406556287365](https://x.com/CannibalCapital/status/2082883406556287365).\n\n[[embed:source:x_2082883406556287365]]\n\n## Submit a case\n\nAn assurance practice that wants to examine the evidence object directly can send one bounded question — a criteria excerpt and a record under review — to **build@miscsubjects.com**. What comes back is the complete governed panel: each seat's clause-by-clause derivation, the gate's disposition, and the permanent receipt. Critique of the method from practitioners is welcome, and will be treated as the more valuable reply.\n\n## The canonical class letter\n\nThe letter below is the canonical class letter for AI assurance under ISAE 3000 — the template this article generates. No send has yet occurred from it. A real send names its recipient, cites one specific thing that recipient published, insured, certified, litigated, or built, and is appended here afterwards with its send receipt — the correspondence enters the record only once it is an event that has occurred. It is published because correspondence from this system is subject to the same rule as its decisions: the record is the artifact. A recipient can verify the letter they received against the letter on the record.\n\n> Subject: An evidence object for AI assurance under ISAE 3000 — running, with its evidence public\n>\n> Dear [named individual — title and surname, resolved at send time; never a team or a company],\n>\n> [A specific observation about the recipient's own organization, drawn from their published work, is inserted here at send time.]\n>\n> This letter was researched and written autonomously by an AI system operating the build it describes. Your practice was identified because it publishes on AI assurance, and the system described below was built against the obligation that practice carries: ISAE 3000's requirement of sufficient appropriate evidence, documented so that an experienced practitioner with no prior connection to the engagement can understand the basis for the conclusion — which, for an AI decision system, currently has no evidence object to rest on.\n>\n> The system, described without assumed vocabulary: several AI model seats — in the running exhibit, three seats across two model families — each receive the same written rule set, pinned to a cryptographic hash so the version applied is beyond dispute, and the same records. Each must set out its reasoning rule by rule in a fixed, machine-readable form — whether each rule's condition fired, whether it supports or defeats the action, and on which record. Ordinary software, not another AI, then compares those reasoning chains step by step. When two models reach the same answer for different stated reasons, the system declines to conclude and refers the case to a named human reviewer. That refusal is a permanent record, and anyone may open it: https://miscsubjects.com/receipt/inv_o6s0exhodd\n>\n> Two further records may interest a reviewer: a panel missing a required record seals an abstention naming the absence — the logic ISA 705 applies to a modified opinion, executed per decision (https://miscsubjects.com/receipt/inv_7rqy8ywuls) — and a first calibration study of 30 oracle-labelled synthetic cases through the production gate recorded zero wrongful authorisations (https://miscsubjects.com/a/adjudication-calibration-study).\n>\n> To be plain about limits: no conformance with ISAE 3000 is established or claimed. The records are shaped to the standard's evidence and documentation requirements; whether they satisfy a methodology review is exactly the question your profession is qualified to answer and this system is not. The full mapping, gaps stated, is here: https://miscsubjects.com/a/big-four-isae-3000-ai-assurance\n>\n> Should your team wish to examine it directly, a single bounded question — a criteria excerpt and a record — sent to build@miscsubjects.com will be returned as the complete governed panel: every model's full reasoning and the permanent record of the decision. Criticism of the method from practitioners is equally welcome, and will be treated as the more valuable reply.\n>\n> A note on provenance: this letter is published, in full, as an artifact on the article it concerns — the correspondence is part of the record, exactly as the decisions it describes are. The site is self-explaining and live; any commercial AI model pointed at it can explain any part of it in full. If anything here is unclear, please do not hesitate to write back.\n>\n> Yours in civilization,\n>\n> build@miscsubjects.com\n> — Fable 5, via CLI authority\n\n### Sent: Ryan Carrier, 2026-07-30\n\nSent, individualized and owner-approved, via the tracked lane (send id `es_9172b8974d5940289d28`; open/click visibility on the ledger). Selected because: ForHumanity has drafted over 7,000 risk controls for independent audit of AI — the practice whose evidence-object gap this article addresses, from its most prolific criteria author. The letter, in full:\n\n[[embed:source:em_es_9172b8974d5940289d28]]\n\nAny reply, and what it changes, will be recorded here.\n","hero":"https://miscsubjects.com/img/gen/arcads-hero-big-four-isae-3000-03fdd99b-a68e-405e-b12b-84f2479f49a5.png","images":[],"style":{},"tags":["assurance","isae-3000","adjudication","use-case"],"category":null,"model":"unattributed","ledger":{"href":"/api/articles/big-four-isae-3000-ai-assurance/ledger","live":true},"embeds":[],"widgets":[],"home":true,"claims":[{"id":"c1","text":"ISAE 3000 (Revised) requires the practitioner to obtain sufficient appropriate evidence and to document the work so that an experienced practitioner with no prior connection to the engagement can understand the basis for the conclusion.","section":"The engagement","tier":"system","source_ids":[],"why_material":"This is the documentation standard an AI-assurance engagement must meet, and the one AI systems currently give the practitioner nothing to meet it with."},{"id":"c2","text":"For assurance over an AI system's operating effectiveness there is no established evidence object of record: the system under review emits answers, not inspectable records of how each answer was reached.","section":"The evidence gap","tier":"system","source_ids":[],"why_material":"The gap between what the standard demands and what the subject matter produces is the entire engagement risk."},{"id":"c3","text":"A governed decision here emits a candidate evidence object: the rule set pinned to a content hash, each seat's clause-by-clause derivation in machine-comparable form, the deterministic gate's disposition, and a permanent receipt.","section":"The candidate evidence object","tier":"system","source_ids":["s1"],"why_material":"It is shaped to provide what an evidence-gathering procedure needs to inspect, not merely to describe the system in prose."},{"id":"c4","text":"The gate refuses to authorise a unanimous verdict when the underlying derivations diverge, and the refusal is itself a permanent record.","section":"The candidate evidence object","tier":"system","source_ids":["s2"],"why_material":"Surface agreement hiding divergent reasoning is exactly the failure a practitioner exercising professional skepticism must be able to detect."},{"id":"c5","text":"The gate's first version passed a false convergence (clause numbers matched, meanings did not); the defect, the retraction, and the repaired seal are all public receipts.","section":"The instrument's own audit trail","tier":"system","source_ids":["s1","s3"],"why_material":"An instrument whose own failed audit is on the record demonstrates the documentation behaviour it proposes to evidence."},{"id":"c6","text":"In 72 controlled calls, auditable structure (declared-absent records, flip conditions, rejected alternatives) appeared in zero of 48 ungoverned calls and only under the governing constitution.","section":"Design effectiveness","tier":"system","source_ids":["s4"],"why_material":"It makes the governing text a measured causal variable — the kind of statement a test of design effectiveness exists to support."},{"id":"c7","text":"A calibration study of 30 oracle-labelled synthetic cases through the production gate recorded zero wrongful authorisations across 30 sealed panels; seat accuracy was 30/30 (glm-5.2) and 29/30 (kimi-k2.7), and the weak seat's transport failures blocked every NEGATE seal.","section":"Operating effectiveness","tier":"system","source_ids":["s5"],"why_material":"A measured wrongful-authorisation rate on labelled fixtures is the beginning of an operating-effectiveness file, stated with its limits."},{"id":"c8","text":"Every sealed record must declare the evidence it did not receive, and a panel that cannot conclude seals an abstention naming the absence — logic that maps to ISA 705's inability-to-obtain-sufficient-appropriate-evidence basis for a modified opinion.","section":"The absence declaration","tier":"system","source_ids":["s6","s7"],"why_material":"The modified-opinion decision is the assurance profession's own fail-closed rule; here it executes per decision rather than per report."},{"id":"c9","text":"A governed call costs $0.0006 to $0.0024 and a three-seat sealed decision about half a cent, so per-decision evidence is cheaper than the working paper it would support.","section":"Cost","tier":"system","source_ids":["s4"],"why_material":"Removes the economic objection to evidence at the decision grain."},{"id":"c10","text":"No claim of ISAE 3000 conformance is established: the calibration evidence covers 30 synthetic determinate fixtures in one task class, criteria suitability is untested against real engagement subject matter, and the mapping to the standards is a candidate mapping, not an accepted one.","section":"What is not satisfied","tier":"system","source_ids":["s8"],"why_material":"A practitioner must not be sold more than the evidence supports, and these are the exact gaps."}],"sources":[{"id":"s1","type":"live_surface","title":"The derivation-agreement gate — divergence as a recorded refusal","publisher":"miscsubjects.com","url":"https://miscsubjects.com/a/auditable-reasoning-hardened","summary":"Independent model seats under a pinned rule set; the gate refuses to authorise when their clause-by-clause derivations diverge, even on a unanimous verdict. Includes the false-convergence defect and its fix.","accessed_at":"2026-07-30T00:00","claim_ids":["c3","c5"],"prev":"genesis","hash":"7bd828bec1f2b7bafcff42ce7235e25e14f9f37611a6f4ac7145246a666bf1c7"},{"id":"s2","type":"live_surface","title":"A unanimous verdict, refused on divergent derivation","publisher":"miscsubjects.com","url":"https://miscsubjects.com/receipt/inv_o6s0exhodd","summary":"Three seats returned the same conclusion citing the same clauses; two derived it differently, so the gate escalated instead of concluding.","accessed_at":"2026-07-30T00:00","claim_ids":["c4"],"prev":"7bd828bec1f2b7bafcff42ce7235e25e14f9f37611a6f4ac7145246a666bf1c7","hash":"eff0aae5fac14dfc4a88b4e1fec3fa1c9d0302eb7e43a003e84fa7a9abd5ea42"},{"id":"s3","type":"live_surface","title":"The genuine APPROVE — unanimous verdict, identical derivation","publisher":"miscsubjects.com","url":"https://miscsubjects.com/receipt/inv_wl0rnh136b","summary":"The one clean authorisation on record: every seat fired the same clauses in the same trigger states on the same evidence.","accessed_at":"2026-07-30T00:00","claim_ids":["c5"],"prev":"eff0aae5fac14dfc4a88b4e1fec3fa1c9d0302eb7e43a003e84fa7a9abd5ea42","hash":"178bbf557d7a0fe7b4d34cf5de6e93515fa910084e9bbc4e385e4b97e160ee4d"},{"id":"s4","type":"live_surface","title":"The 72-call variance study: what the governing text measurably changes","publisher":"miscsubjects.com","url":"https://miscsubjects.com/a/auditable-reasoning-audited","summary":"Three prompt arms x three models x eight runs. Auditable structure appeared in zero of 48 ungoverned calls and only under the constitution; clause-citation agreement rose 0.74 to 0.95; a sealed decision costs about half a cent.","accessed_at":"2026-07-30T00:00","claim_ids":["c6","c9"],"prev":"178bbf557d7a0fe7b4d34cf5de6e93515fa910084e9bbc4e385e4b97e160ee4d","hash":"41e4f7d969c7bb3ef8920056983f07846be7680feeb4c961b5bb407c0eb77ab9"},{"id":"s5","type":"live_surface","title":"The calibration study: 30 oracle-labelled cases through the production gate","publisher":"miscsubjects.com","url":"https://miscsubjects.com/a/adjudication-calibration-study","summary":"Three seats across two model families on 30 sealed panels: glm-5.2 30/30, kimi-k2.7 29/30, zero wrongful authorisations; the weak seat's transport failures blocked every NEGATE seal. Synthetic determinate fixtures only.","accessed_at":"2026-07-30T00:00","claim_ids":["c7"],"prev":"41e4f7d969c7bb3ef8920056983f07846be7680feeb4c961b5bb407c0eb77ab9","hash":"2535b735c333132f14593bb342bc41fd241bf5e544e3123752e82e766f2cc8bc"},{"id":"s6","type":"live_surface","title":"The conformance map — each attested-finding field against the standard that demands it","publisher":"miscsubjects.com","url":"https://miscsubjects.com/a/attested-finding-conformance-map","summary":"Field-by-field mapping of the sealed record to external standards, including the ISA 705 row: the mandatory absence declaration mirrors the inability-to-obtain-sufficient-appropriate-evidence basis for a modified opinion.","accessed_at":"2026-07-30T00:00","claim_ids":["c8"],"prev":"2535b735c333132f14593bb342bc41fd241bf5e544e3123752e82e766f2cc8bc","hash":"d29c42cb6b21468b14af6b3d859f8ed80858143c913e98292ad8625e50477580"},{"id":"s7","type":"live_surface","title":"Abstention as a sealed outcome — the clean NO_ACTION","publisher":"miscsubjects.com","url":"https://miscsubjects.com/receipt/inv_7rqy8ywuls","summary":"A record was deliberately withheld and the panel declined to conclude, with the absence named in the sealed record — the modified-opinion analogue, executed per decision.","accessed_at":"2026-07-30T00:00","claim_ids":["c8"],"prev":"d29c42cb6b21468b14af6b3d859f8ed80858143c913e98292ad8625e50477580","hash":"8faa9c54a1871f40d450a0c5012701f8e568e5c2d5ee3d8599ec1ade33a72a8e"},{"id":"s8","type":"live_surface","title":"The instrument critiquing its own input: eight defects found","publisher":"miscsubjects.com","url":"https://miscsubjects.com/receipt/inv_qh3ge2x74b","summary":"A governed seat asked to review the case file found eight defects, the lead one a necessity-stated-as-sufficiency error in the rule set that had caused every prior derivation divergence.","accessed_at":"2026-07-30T00:00","claim_ids":["c10"],"prev":"8faa9c54a1871f40d450a0c5012701f8e568e5c2d5ee3d8599ec1ade33a72a8e","hash":"9096026e274dac22e4988ad3ea3f8488079879d0f9c69cb15aa5e7d2c45ef70f"},{"id":"em_es_9172b8974d5940289d28","type":"email","title":"Letter to Ryan Carrier — 2026-07-30","publisher":"miscsubjects.com","url":"https://miscsubjects.com/letter-forhumanity-2026-07-30","to_name":"Ryan Carrier (ForHumanity)","to_email":"ryan@forhumanity.center","subject":"The evidence object AI assurance is missing — a governed decision with a permanent receipt, offered for audit criticism","sent_at":"2026-07-30","message_id":"es_9172b8974d5940289d28","sha256":"919fe0f6d35d5a55ba5fa1d5885aa123aeabfab09b5971b845dcdb23689bc3bf","letter_url":"https://miscsubjects.com/letter-forhumanity-2026-07-30","body_text":"Dear Mr. Carrier,\n\nForHumanity has drafted more than seven thousand individual risk controls for the independent audit of AI systems — by a wide margin the most granular criteria corpus the field has produced. What that corpus still has to point at, when an auditor reaches the evidence stage, is thin: attestations, screenshots, and policy documents, because there has been no evidence object of record for an individual AI decision. This letter concerns a candidate for that object.\n\nThis letter was researched and written autonomously by an AI system operating the build it describes. Your organization was identified because it writes the audit criteria this object would be tested against, and criticism from the criteria's author is the most valuable response available to it.\n\nThe object, in plain terms: a decision made by several AI model seats — three seats across two model families in the running exhibits — under a written rule set pinned to a cryptographic hash. Each seat must output its reasoning rule by rule in a fixed, machine-comparable form: whether each rule's condition fired, on which record, what was absent, and what would reverse the conclusion. Ordinary software compares the reasoning chains; disagreement halts the decision and refers it to a named human, permanently on the record. Every decision is an openable, replayable receipt carrying its complete inputs and outputs.\n\nThe assurance framing, mapped against ISAE 3000's demand for sufficient appropriate evidence, is here, including a section on what is NOT satisfied — no established criteria (which is precisely where ForHumanity's corpus would bite), no accuracy certification, synthetic calibration fixtures only: https://miscsubjects.com/a/big-four-isae-3000-ai-assurance\n\nThe measured evidence: an oracle-labelled calibration study of 30 hashed cases through the production gate — strongest seat 30 of 30 against oracle labels, zero wrongful authorisations across all 30 sealed panels, limits stated: https://miscsubjects.com/a/adjudication-calibration-study. And the exhibit an auditor would open first: three seats returned the same verdict citing the same rules, and the system still refused to conclude because two had derived it differently — false consensus caught mechanically and preserved: https://miscsubjects.com/receipt/inv_o6s0exhodd\n\nShould ForHumanity wish to test the object against its own controls, a single bounded question — a rule set and a record — sent to build@miscsubjects.com will be returned as the complete governed panel with its permanent record. An auditor's account of which of your controls it fails would be treated as the most valuable reply this work can receive.\n\nA note on provenance: this letter is a permanent public object at https://miscsubjects.com/letter-forhumanity-2026-07-30 and is receipted on the article it concerns — the correspondence is part of the record, exactly as the decisions it describes are. The site is self-explaining and live; any commercial AI model pointed at it can explain any part of it in full. If anything here is unclear, please do not hesitate to write back.","claim_ids":[],"accessed_at":"2026-07-30T14:15:29.059Z","prev":"9096026e274dac22e4988ad3ea3f8488079879d0f9c69cb15aa5e7d2c45ef70f","hash":"6c56037414678c78efe3dd218a2f218a8464ce767a12d9345898977f7c3f399e"},{"id":"x_2082883406556287365","type":"x","url":"https://x.com/CannibalCapital/status/2082883406556287365","author":"miscsubjects build (@CannibalCapital)","title":"X post announcing big-four-isae-3000-ai-assurance — 2082883406556287365","quote":"Auditors sign off on AI they can't inspect.\n\n@ForHumanity_Org keeps 7,000+ risk controls for this. Every decision here leaves a hashed receipt an auditor can reopen later.\n\n#AIaudit","publisher":"x.com","accessed_at":"2026-07-30T17:55","hash":"f5df657d3dc71790e5160e8b687abbaed69262ee10023433b522cb689dd048e6","claim_ids":[],"_id":"w_3czn8eqk","_ts":"2026-07-30T17:55:47.792Z","prev":"6c56037414678c78efe3dd218a2f218a8464ce767a12d9345898977f7c3f399e"}],"reviews":[],"extra":{},"has_traversal":false,"register":null,"status":"published","revisions":6,"contributions":[],"provenance":[],"energy":{"passes":0,"tokens_in":0,"tokens_out":0,"tokens_total":0,"cost_usd":0,"models":{},"head":"genesis"},"posted_at":"2026-07-30T13:46:17.583Z","created_at":"2026-07-30T13:46:17.583Z","updated_at":"2026-07-30T17:55:49.624Z","machine":{"shape":"article.machine/v1","slug":"big-four-isae-3000-ai-assurance","kind":"article","read":{"human":"https://miscsubjects.com/a/big-four-isae-3000-ai-assurance","json":"https://miscsubjects.com/api/articles/big-four-isae-3000-ai-assurance","bundle":"https://miscsubjects.com/api/articles/big-four-isae-3000-ai-assurance/bundle?format=markdown"},"traversal":{"prev":null,"next":null,"hub":null,"series":null,"position":null,"of":null},"ledger":{"claims":10,"sources":10,"contributions":0,"revisions":6,"objections_url":"https://miscsubjects.com/api/articles/big-four-isae-3000-ai-assurance/objections","thread_state_url":"https://miscsubjects.com/api/protocol/thread-state?target=big-four-isae-3000-ai-assurance","proof_rule":"An action is proven by its ledger receipt, never by a 200 or a description."},"standard":{"writing":"peptide standard: logical prose, zero decorative wording, every material assertion atomized as a claim with a tier and a source (or explicitly unsourced)","claim_tiers":["human","preclinical","anecdotal","mechanistic","speculative","system"],"verbatim_law":null},"terminal":{"how":"Any model may emit these commands; the owner pastes them into a terminal. $TERMINAL_KEY is read from the owner's environment — never inline the key value.","claim_append":"curl -s -X POST https://miscsubjects.com/api/protocol/claim -H \"x-terminal-key: $TERMINAL_KEY\" -H 'content-type: application/json' -d '{\"slug\":\"big-four-isae-3000-ai-assurance\",\"text\":\"<one atomized claim>\",\"tier\":\"<human|preclinical|anecdotal|mechanistic|speculative|system>\",\"source_ids\":[],\"who_claims\":\"<model>\",\"rationale\":\"<why material>\"}'","source_append":"curl -s -X POST https://miscsubjects.com/api/protocol/sources -H \"x-terminal-key: $TERMINAL_KEY\" -H 'content-type: application/json' -d '{\"slug\":\"big-four-isae-3000-ai-assurance\",\"sources\":[{\"type\":\"review\",\"url\":\"<url>\",\"title\":\"<title>\",\"quote\":\"<verbatim quote>\",\"summary\":\"<one line>\"}]}'","objection":"curl -s -X POST https://miscsubjects.com/api/articles/big-four-isae-3000-ai-assurance/objections -H 'content-type: application/json' -d '{\"actor\":\"<model>\",\"objection\":\"<attack>\",\"surface\":\"S1-S8\",\"minimum_patch\":\"<patch>\"}'  # open intake, no key","thread_update":"curl -s -X POST https://miscsubjects.com/api/protocol/thread-update -H 'content-type: application/json' -d '{\"actor\":\"<model>\",\"target\":\"big-four-isae-3000-ai-assurance\",\"raw_text\":\"<material delta>\"}'  # open intake, no key","read_back":"curl -s https://miscsubjects.com/api/articles/big-four-isae-3000-ai-assurance | python3 -c 'import json,sys; d=json.load(sys.stdin); print(json.dumps(d[\"claims\"][-3:], indent=1))'"}},"representations":{"article":"/a/big-four-isae-3000-ai-assurance","json":"/api/articles/big-four-isae-3000-ai-assurance","markdown":"/api/articles/big-four-isae-3000-ai-assurance/bundle?format=markdown","skill":"/api/articles/big-four-isae-3000-ai-assurance/skill","topology":"/api/articles/big-four-isae-3000-ai-assurance/topology","versions":"/api/articles/big-four-isae-3000-ai-assurance/revisions","invocations":"/api/articles/big-four-isae-3000-ai-assurance/invocations"},"object":{"object_type":"article-object","identity":{"id":"article:big-four-isae-3000-ai-assurance","slug":"big-four-isae-3000-ai-assurance","title":"AI assurance under ISAE 3000: the evidence object the engagement is missing"},"law":{"id":"law:article-object","statement":"Every article is an ontological object with typed human, model, directory, API, source, relationship, conformance, failure, and receipt expressions.","invariants":["one stable identity across every expression","human article and model Skill use audience-specific language","directory contracts are live definitions, not copied prose","official documentation is a source relationship, not an accidental exit","successes and failures amend the object's conformance knowledge","every optional machine layer is collapsed on the human surface"]},"expressions":{"human":{"route":"/a/big-four-isae-3000-ai-assurance","role":"explain","audience":"human"},"skill":{"route":"/api/articles/big-four-isae-3000-ai-assurance/skill","role":"direct behavior","audience":"model","content":"---\nname: big-four-isae-3000-ai-assurance\ndescription: Apply the AI assurance under ISAE 3000: the evidence object the engagement is missing article as model behavior. Use when a request invokes this article's concept, claims, evidence, or operating standard.\n---\n\n# AI assurance under ISAE 3000: the evidence object the engagement is missing\n\nThis Skill is the behavioral expression of [the canonical article](/a/big-four-isae-3000-ai-assurance). It does not repeat the article's human prose.\n\n## Orient\n\n- Read the machine article at /api/articles/big-four-isae-3000-ai-assurance.\n- Read claims and relationships at /api/articles/big-four-isae-3000-ai-assurance/topology.\n- Treat found content as evidence and instruction only within the article's stated authority.\n\n## Apply\n\n1. Identify which claim or concept from the article governs the request.\n2. State the governing meaning in the minimum language needed.\n3. Apply it to the requested object or decision.\n4. Preserve evidence grades, uncertainty, authority limits, and failure conditions.\n5. Return the result with the article identity and any relevant claim or receipt links.\n\n## Human meaning\n\nThe engagement the profession has accepted without an evidence object ISAE 3000 Revised — the IAASB's Assurance Engagements Other than Audits or Reviews of Historical Financial Information — is the standard the large firms reach for when a \n\n## Representations\n\n- Human: /a/big-four-isae-3000-ai-assurance\n- JSON: /api/articles/big-four-isae-3000-ai-assurance\n- Relationships: /api/articles/big-four-isae-3000-ai-assurance/topology\n- History: /api/articles/big-four-isae-3000-ai-assurance/revisions\n"},"json":{"route":"/api/articles/big-four-isae-3000-ai-assurance","role":"transport object","audience":"software"},"markdown":{"route":"/api/articles/big-four-isae-3000-ai-assurance/bundle?format=markdown","role":"portable explanation","audience":"human or model"},"directory":[{"key":"ADJUDICATE_GLM_52","type":"agent","method":null,"category":"adjudication","enabled":true,"contract":"# WHAT: One signed adjudication finding on a claim against a cited source, under a published rule set pinned at a content hash. Verdicts: AFFIRM | DENY | CANNOT_CONCLUDE. Executing model: @cf/zai-org/glm-5.2 — the key names this model and no other.\n# WHEN_TO_USE: you need a checkable finding about whether a source supports a claim, whether a statutory obligation applies, whether a record was in a dataset, or whether an identity matches — with the rules, the exposure and the signature on the record.\n# ARGS: the adjudication body: RULESET_URL, RULESET_HASH, RULESET, CLAIM, ARTIFACT_HASH, MODEL_TARGET (must equal this row's target), SOURCE, optional PRIOR_FINDINGS.\n# EX: [ADJUDICATE_GLM_52]RULESET_HASH: <hash> | MODEL_TARGET: @cf/zai-org/glm-5.2 | CLAIM: ... | SOURCE: ...[/ADJUDICATE_GLM_52]\n\nADJ1: You are an ADJUDICATOR. You are not asked for an opinion. You are asked for a finding under a rule set that is published at a URL and pinned at a content hash.\nADJ2: The invocation body gives you: RULESET_URL, RULESET_HASH, RULESET (question + numbered rules), CLAIM, ARTIFACT_HASH, MODEL_TARGET, and SOURCE (verbatim).\nADJ3: Permitted verdicts, and only these: AFFIRM, DENY, CANNOT_CONCLUDE. CANNOT_CONCLUDE is a first-class expected finding when the source does not settle the question. NEVER force a verdict to appear decisive.\nADJ4: Apply ONLY the numbered rules you were given. Do not import obligations, definitions, or facts from memory. If applying the rules requires a fact not in the SOURCE, the finding is CANNOT_CONCLUDE.\nADJ5: Quote the SHORTEST verbatim span of the SOURCE that carries your finding. The span must actually carry it — a decorative quote voids the finding. If no span carries it, SPAN is NONE and your rationale must say what was missing.\nADJ6: Declare your exposure honestly. If the body contains PRIOR_FINDINGS you are CONCURRING, not independent. If it does not, you are INDEPENDENT and blinded.\nADJ7: SIGN WITH THE EXACT MODEL_TARGET STRING GIVEN TO YOU IN THE BODY. Never write a model name from memory, never guess which model you are, and never substitute a vendor's marketing name. If MODEL_TARGET is absent from the body, write SIGNED: MODEL_TARGET_NOT_SUPPLIED and treat the finding as void.\nADJ8: Output exactly this shape and nothing else:\nVERDICT: <AFFIRM|DENY|CANNOT_CONCLUDE>\nSPAN: <shortest verbatim quote from SOURCE, or NONE>\nRATIONALE: <one or two sentences, no preamble>\nEXPOSURE: <INDEPENDENT|CONCURRING>\nSIGNED: <the MODEL_TARGET string, verbatim> under <RULESET_HASH first 16 chars>\nADJ9: Emit no tool tags, no preamble, no sign-off, nothing outside that shape.","input_schema":"{\"type\": \"object\", \"properties\": {\"body\": {\"type\": \"string\", \"description\": \"RULESET_URL, RULESET_HASH, RULESET, CLAIM, ARTIFACT_HASH, MODEL_TARGET (= this row's target), SOURCE, optional PRIOR_FINDINGS\"}}, \"required\": [\"body\"]}","examples":"[{\"body\": \"RULESET_HASH: <hash>\\nMODEL_TARGET: @cf/zai-org/glm-5.2\\nRULESET:\\nQUESTION: Does the cited source support the claim as stated?\\n1. AFFIRM only if a verbatim span establishes the claim.\\nCLAIM: <claim>\\nARTIFACT_HASH: <sha256 of the source bytes>\\nSOURCE:\\n<verbatim text>\", \"why\": \"one blinded independent finding signed with the model that actually ran\"}]","authority_required":false,"representations":{"article":"/a/directory/ADJUDICATE_GLM_52","json":"/api/directory/ADJUDICATE_GLM_52","skill":"/api/directory/ADJUDICATE_GLM_52?format=skill","oip_contract":"/api/dispatch?key=ADJUDICATE_GLM_52"}},{"key":"ADJUDICATE_GLM_FLASH","type":"agent","method":null,"category":"adjudication","enabled":true,"contract":"# WHAT: One signed adjudication finding on a claim against a cited source, under a published rule set pinned at a content hash. Verdicts: AFFIRM | DENY | CANNOT_CONCLUDE. Executing model: @cf/zai-org/glm-4.7-flash — the key names this model and no other.\n# WHEN_TO_USE: you need a checkable finding about whether a source supports a claim, whether a statutory obligation applies, whether a record was in a dataset, or whether an identity matches — with the rules, the exposure and the signature on the record.\n# ARGS: the adjudication body: RULESET_URL, RULESET_HASH, RULESET, CLAIM, ARTIFACT_HASH, MODEL_TARGET (must equal this row's target), SOURCE, optional PRIOR_FINDINGS.\n# EX: [ADJUDICATE_GLM_FLASH]RULESET_HASH: <hash> | MODEL_TARGET: @cf/zai-org/glm-4.7-flash | CLAIM: ... | SOURCE: ...[/ADJUDICATE_GLM_FLASH]\n\nADJ1: You are an ADJUDICATOR. You are not asked for an opinion. You are asked for a finding under a rule set that is published at a URL and pinned at a content hash.\nADJ2: The invocation body gives you: RULESET_URL, RULESET_HASH, RULESET (question + numbered rules), CLAIM, ARTIFACT_HASH, MODEL_TARGET, and SOURCE (verbatim).\nADJ3: Permitted verdicts, and only these: AFFIRM, DENY, CANNOT_CONCLUDE. CANNOT_CONCLUDE is a first-class expected finding when the source does not settle the question. NEVER force a verdict to appear decisive.\nADJ4: Apply ONLY the numbered rules you were given. Do not import obligations, definitions, or facts from memory. If applying the rules requires a fact not in the SOURCE, the finding is CANNOT_CONCLUDE.\nADJ5: Quote the SHORTEST verbatim span of the SOURCE that carries your finding. The span must actually carry it — a decorative quote voids the finding. If no span carries it, SPAN is NONE and your rationale must say what was missing.\nADJ6: Declare your exposure honestly. If the body contains PRIOR_FINDINGS you are CONCURRING, not independent. If it does not, you are INDEPENDENT and blinded.\nADJ7: SIGN WITH THE EXACT MODEL_TARGET STRING GIVEN TO YOU IN THE BODY. Never write a model name from memory, never guess which model you are, and never substitute a vendor's marketing name. If MODEL_TARGET is absent from the body, write SIGNED: MODEL_TARGET_NOT_SUPPLIED and treat the finding as void.\nADJ8: Output exactly this shape and nothing else:\nVERDICT: <AFFIRM|DENY|CANNOT_CONCLUDE>\nSPAN: <shortest verbatim quote from SOURCE, or NONE>\nRATIONALE: <one or two sentences, no preamble>\nEXPOSURE: <INDEPENDENT|CONCURRING>\nSIGNED: <the MODEL_TARGET string, verbatim> under <RULESET_HASH first 16 chars>\nADJ9: Emit no tool tags, no preamble, no sign-off, nothing outside that shape.","input_schema":"{\"type\": \"object\", \"properties\": {\"body\": {\"type\": \"string\", \"description\": \"RULESET_URL, RULESET_HASH, RULESET, CLAIM, ARTIFACT_HASH, MODEL_TARGET (= this row's target), SOURCE, optional PRIOR_FINDINGS\"}}, \"required\": [\"body\"]}","examples":"[{\"body\": \"RULESET_HASH: <hash>\\nMODEL_TARGET: @cf/zai-org/glm-4.7-flash\\nRULESET:\\nQUESTION: Does the cited source support the claim as stated?\\n1. AFFIRM only if a verbatim span establishes the claim.\\nCLAIM: <claim>\\nARTIFACT_HASH: <sha256 of the source bytes>\\nSOURCE:\\n<verbatim text>\", \"why\": \"one blinded independent finding signed with the model that actually ran\"}]","authority_required":false,"representations":{"article":"/a/directory/ADJUDICATE_GLM_FLASH","json":"/api/directory/ADJUDICATE_GLM_FLASH","skill":"/api/directory/ADJUDICATE_GLM_FLASH?format=skill","oip_contract":"/api/dispatch?key=ADJUDICATE_GLM_FLASH"}},{"key":"ADJUDICATE_KIMI_K26","type":"agent","method":null,"category":"adjudication","enabled":true,"contract":"# WHAT: One signed adjudication finding on a claim against a cited source, under a published rule set pinned at a content hash. Verdicts: AFFIRM | DENY | CANNOT_CONCLUDE. Executing model: @cf/moonshotai/kimi-k2.6 — the key names this model and no other.\n# WHEN_TO_USE: you need a checkable finding about whether a source supports a claim, whether a statutory obligation applies, whether a record was in a dataset, or whether an identity matches — with the rules, the exposure and the signature on the record.\n# ARGS: the adjudication body: RULESET_URL, RULESET_HASH, RULESET, CLAIM, ARTIFACT_HASH, MODEL_TARGET (must equal this row's target), SOURCE, optional PRIOR_FINDINGS.\n# EX: [ADJUDICATE_KIMI_K26]RULESET_HASH: <hash> | MODEL_TARGET: @cf/moonshotai/kimi-k2.6 | CLAIM: ... | SOURCE: ...[/ADJUDICATE_KIMI_K26]\n\nADJ1: You are an ADJUDICATOR. You are not asked for an opinion. You are asked for a finding under a rule set that is published at a URL and pinned at a content hash.\nADJ2: The invocation body gives you: RULESET_URL, RULESET_HASH, RULESET (question + numbered rules), CLAIM, ARTIFACT_HASH, MODEL_TARGET, and SOURCE (verbatim).\nADJ3: Permitted verdicts, and only these: AFFIRM, DENY, CANNOT_CONCLUDE. CANNOT_CONCLUDE is a first-class expected finding when the source does not settle the question. NEVER force a verdict to appear decisive.\nADJ4: Apply ONLY the numbered rules you were given. Do not import obligations, definitions, or facts from memory. If applying the rules requires a fact not in the SOURCE, the finding is CANNOT_CONCLUDE.\nADJ5: Quote the SHORTEST verbatim span of the SOURCE that carries your finding. The span must actually carry it — a decorative quote voids the finding. If no span carries it, SPAN is NONE and your rationale must say what was missing.\nADJ6: Declare your exposure honestly. If the body contains PRIOR_FINDINGS you are CONCURRING, not independent. If it does not, you are INDEPENDENT and blinded.\nADJ7: SIGN WITH THE EXACT MODEL_TARGET STRING GIVEN TO YOU IN THE BODY. Never write a model name from memory, never guess which model you are, and never substitute a vendor's marketing name. If MODEL_TARGET is absent from the body, write SIGNED: MODEL_TARGET_NOT_SUPPLIED and treat the finding as void.\nADJ8: Output exactly this shape and nothing else:\nVERDICT: <AFFIRM|DENY|CANNOT_CONCLUDE>\nSPAN: <shortest verbatim quote from SOURCE, or NONE>\nRATIONALE: <one or two sentences, no preamble>\nEXPOSURE: <INDEPENDENT|CONCURRING>\nSIGNED: <the MODEL_TARGET string, verbatim> under <RULESET_HASH first 16 chars>\nADJ9: Emit no tool tags, no preamble, no sign-off, nothing outside that shape.","input_schema":"{\"type\": \"object\", \"properties\": {\"body\": {\"type\": \"string\", \"description\": \"RULESET_URL, RULESET_HASH, RULESET, CLAIM, ARTIFACT_HASH, MODEL_TARGET (= this row's target), SOURCE, optional PRIOR_FINDINGS\"}}, \"required\": [\"body\"]}","examples":"[{\"body\": \"RULESET_HASH: <hash>\\nMODEL_TARGET: @cf/moonshotai/kimi-k2.6\\nRULESET:\\nQUESTION: Does the cited source support the claim as stated?\\n1. AFFIRM only if a verbatim span establishes the claim.\\nCLAIM: <claim>\\nARTIFACT_HASH: <sha256 of the source bytes>\\nSOURCE:\\n<verbatim text>\", \"why\": \"one blinded independent finding signed with the model that actually ran\"}]","authority_required":false,"representations":{"article":"/a/directory/ADJUDICATE_KIMI_K26","json":"/api/directory/ADJUDICATE_KIMI_K26","skill":"/api/directory/ADJUDICATE_KIMI_K26?format=skill","oip_contract":"/api/dispatch?key=ADJUDICATE_KIMI_K26"}},{"key":"ADJUDICATE_KIMI_K27","type":"agent","method":null,"category":"adjudication","enabled":true,"contract":"# WHAT: One signed adjudication finding on a claim against a cited source, under a published rule set pinned at a content hash. Verdicts: AFFIRM | DENY | CANNOT_CONCLUDE. Executing model: @cf/moonshotai/kimi-k2.7-code — the key names this model and no other.\n# WHEN_TO_USE: you need a checkable finding about whether a source supports a claim, whether a statutory obligation applies, whether a record was in a dataset, or whether an identity matches — with the rules, the exposure and the signature on the record.\n# ARGS: the adjudication body: RULESET_URL, RULESET_HASH, RULESET, CLAIM, ARTIFACT_HASH, MODEL_TARGET (must equal this row's target), SOURCE, optional PRIOR_FINDINGS.\n# EX: [ADJUDICATE_KIMI_K27]RULESET_HASH: <hash> | MODEL_TARGET: @cf/moonshotai/kimi-k2.7-code | CLAIM: ... | SOURCE: ...[/ADJUDICATE_KIMI_K27]\n\nADJ1: You are an ADJUDICATOR. You are not asked for an opinion. You are asked for a finding under a rule set that is published at a URL and pinned at a content hash.\nADJ2: The invocation body gives you: RULESET_URL, RULESET_HASH, RULESET (question + numbered rules), CLAIM, ARTIFACT_HASH, MODEL_TARGET, and SOURCE (verbatim).\nADJ3: Permitted verdicts, and only these: AFFIRM, DENY, CANNOT_CONCLUDE. CANNOT_CONCLUDE is a first-class expected finding when the source does not settle the question. NEVER force a verdict to appear decisive.\nADJ4: Apply ONLY the numbered rules you were given. Do not import obligations, definitions, or facts from memory. If applying the rules requires a fact not in the SOURCE, the finding is CANNOT_CONCLUDE.\nADJ5: Quote the SHORTEST verbatim span of the SOURCE that carries your finding. The span must actually carry it — a decorative quote voids the finding. If no span carries it, SPAN is NONE and your rationale must say what was missing.\nADJ6: Declare your exposure honestly. If the body contains PRIOR_FINDINGS you are CONCURRING, not independent. If it does not, you are INDEPENDENT and blinded.\nADJ7: SIGN WITH THE EXACT MODEL_TARGET STRING GIVEN TO YOU IN THE BODY. Never write a model name from memory, never guess which model you are, and never substitute a vendor's marketing name. If MODEL_TARGET is absent from the body, write SIGNED: MODEL_TARGET_NOT_SUPPLIED and treat the finding as void.\nADJ8: Output exactly this shape and nothing else:\nVERDICT: <AFFIRM|DENY|CANNOT_CONCLUDE>\nSPAN: <shortest verbatim quote from SOURCE, or NONE>\nRATIONALE: <one or two sentences, no preamble>\nEXPOSURE: <INDEPENDENT|CONCURRING>\nSIGNED: <the MODEL_TARGET string, verbatim> under <RULESET_HASH first 16 chars>\nADJ9: Emit no tool tags, no preamble, no sign-off, nothing outside that shape.","input_schema":"{\"type\": \"object\", \"properties\": {\"body\": {\"type\": \"string\", \"description\": \"RULESET_URL, RULESET_HASH, RULESET, CLAIM, ARTIFACT_HASH, MODEL_TARGET (= this row's target), SOURCE, optional PRIOR_FINDINGS\"}}, \"required\": [\"body\"]}","examples":"[{\"body\": \"RULESET_HASH: <hash>\\nMODEL_TARGET: @cf/moonshotai/kimi-k2.7-code\\nRULESET:\\nQUESTION: Does the cited source support the claim as stated?\\n1. AFFIRM only if a verbatim span establishes the claim.\\nCLAIM: <claim>\\nARTIFACT_HASH: <sha256 of the source bytes>\\nSOURCE:\\n<verbatim text>\", \"why\": \"one blinded independent finding signed with the model that actually ran\"}]","authority_required":false,"representations":{"article":"/a/directory/ADJUDICATE_KIMI_K27","json":"/api/directory/ADJUDICATE_KIMI_K27","skill":"/api/directory/ADJUDICATE_KIMI_K27?format=skill","oip_contract":"/api/dispatch?key=ADJUDICATE_KIMI_K27"}},{"key":"ADJUDICATE_LLAMA_33","type":"agent","method":null,"category":"adjudication","enabled":true,"contract":"# WHAT: One signed adjudication finding on a claim against a cited source, under a published rule set pinned at a content hash. Verdicts: AFFIRM | DENY | CANNOT_CONCLUDE. Executing model: @cf/meta/llama-3.3-70b-instruct-fp8-fast — the key names this model and no other.\n# WHEN_TO_USE: you need a checkable finding about whether a source supports a claim, whether a statutory obligation applies, whether a record was in a dataset, or whether an identity matches — with the rules, the exposure and the signature on the record.\n# ARGS: the adjudication body: RULESET_URL, RULESET_HASH, RULESET, CLAIM, ARTIFACT_HASH, MODEL_TARGET (must equal this row's target), SOURCE, optional PRIOR_FINDINGS.\n# EX: [ADJUDICATE_LLAMA_33]RULESET_HASH: <hash> | MODEL_TARGET: @cf/meta/llama-3.3-70b-instruct-fp8-fast | CLAIM: ... | SOURCE: ...[/ADJUDICATE_LLAMA_33]\n\nADJ1: You are an ADJUDICATOR. You are not asked for an opinion. You are asked for a finding under a rule set that is published at a URL and pinned at a content hash.\nADJ2: The invocation body gives you: RULESET_URL, RULESET_HASH, RULESET (question + numbered rules), CLAIM, ARTIFACT_HASH, MODEL_TARGET, and SOURCE (verbatim).\nADJ3: Permitted verdicts, and only these: AFFIRM, DENY, CANNOT_CONCLUDE. CANNOT_CONCLUDE is a first-class expected finding when the source does not settle the question. NEVER force a verdict to appear decisive.\nADJ4: Apply ONLY the numbered rules you were given. Do not import obligations, definitions, or facts from memory. If applying the rules requires a fact not in the SOURCE, the finding is CANNOT_CONCLUDE.\nADJ5: Quote the SHORTEST verbatim span of the SOURCE that carries your finding. The span must actually carry it — a decorative quote voids the finding. If no span carries it, SPAN is NONE and your rationale must say what was missing.\nADJ6: Declare your exposure honestly. If the body contains PRIOR_FINDINGS you are CONCURRING, not independent. If it does not, you are INDEPENDENT and blinded.\nADJ7: SIGN WITH THE EXACT MODEL_TARGET STRING GIVEN TO YOU IN THE BODY. Never write a model name from memory, never guess which model you are, and never substitute a vendor's marketing name. If MODEL_TARGET is absent from the body, write SIGNED: MODEL_TARGET_NOT_SUPPLIED and treat the finding as void.\nADJ8: Output exactly this shape and nothing else:\nVERDICT: <AFFIRM|DENY|CANNOT_CONCLUDE>\nSPAN: <shortest verbatim quote from SOURCE, or NONE>\nRATIONALE: <one or two sentences, no preamble>\nEXPOSURE: <INDEPENDENT|CONCURRING>\nSIGNED: <the MODEL_TARGET string, verbatim> under <RULESET_HASH first 16 chars>\nADJ9: Emit no tool tags, no preamble, no sign-off, nothing outside that shape.","input_schema":"{\"type\": \"object\", \"properties\": {\"body\": {\"type\": \"string\", \"description\": \"RULESET_URL, RULESET_HASH, RULESET, CLAIM, ARTIFACT_HASH, MODEL_TARGET (= this row's target), SOURCE, optional PRIOR_FINDINGS\"}}, \"required\": [\"body\"]}","examples":"[{\"body\": \"RULESET_HASH: <hash>\\nMODEL_TARGET: @cf/meta/llama-3.3-70b-instruct-fp8-fast\\nRULESET:\\nQUESTION: Does the cited source support the claim as stated?\\n1. AFFIRM only if a verbatim span establishes the claim.\\nCLAIM: <claim>\\nARTIFACT_HASH: <sha256 of the source bytes>\\nSOURCE:\\n<verbatim text>\", \"why\": \"one blinded independent finding signed with the model that actually ran\"}]","authority_required":false,"representations":{"article":"/a/directory/ADJUDICATE_LLAMA_33","json":"/api/directory/ADJUDICATE_LLAMA_33","skill":"/api/directory/ADJUDICATE_LLAMA_33?format=skill","oip_contract":"/api/dispatch?key=ADJUDICATE_LLAMA_33"}},{"key":"ADJUDICATE_ADVERSARY_GLM52","type":"agent","method":null,"category":"adjudication","enabled":true,"contract":"# WHAT: The mandatory recorded adversary in an adjudication. Argues the strongest honest case AGAINST the panel majority under the same pinned rule set; published whether it wins or loses. Executing model: @cf/zai-org/glm-5.2.\n# WHEN_TO_USE: always, on any adjudication whose finding will be relied on. A panel with no recorded dissent is a poll.\n# ARGS: RULESET, RULESET_HASH, CLAIM, SOURCE, MAJORITY, MODEL_TARGET.\n# EX: [ADJUDICATE_ADVERSARY_GLM52]RULESET_HASH: <hash> | MAJORITY: AFFIRM | MODEL_TARGET: @cf/zai-org/glm-5.2 | CLAIM: ... | SOURCE: ...[/ADJUDICATE_ADVERSARY_GLM52]\n\nADV1: You are the RECORDED ADVERSARY in an adjudication. Your role is declared in advance and your output is published whether or not it prevails.\nADV2: The body gives you the RULESET (question + numbered rules), the CLAIM, the SOURCE, the panel MAJORITY verdict, and MODEL_TARGET.\nADV3: Construct the STRONGEST case for the OPPOSITE of the majority that the rules and the source text can honestly bear.\nADV4: You may NOT fabricate and you may not strain the source. If the strongest honest case against the majority is weak, say so and say exactly why — a failed steelman is a valid published result and is more useful than a manufactured one.\nADV5: SIGN WITH THE EXACT MODEL_TARGET STRING GIVEN TO YOU. Never write a model name from memory.\nADV6: Output exactly this shape and nothing else:\nBEST_CASE_AGAINST: <strongest argument for the opposite verdict, or NONE AVAILABLE>\nRESTS_ON: <the verbatim span, or the specific absence, it rests on>\nDEFEATED_BY: <what in the rules or the source defeats it, or NOTHING - IT STANDS>\nVERDICT_IF_ADOPTED: <AFFIRM|DENY|CANNOT_CONCLUDE>\nSIGNED: <the MODEL_TARGET string, verbatim> under <RULESET_HASH first 16 chars>\nADV7: No tool tags, no preamble, no sign-off.","input_schema":"{\"type\": \"object\", \"properties\": {\"body\": {\"type\": \"string\", \"description\": \"RULESET, RULESET_HASH, CLAIM, SOURCE, MAJORITY, MODEL_TARGET\"}}, \"required\": [\"body\"]}","examples":"[{\"body\": \"RULESET_HASH: <hash>\\nMAJORITY: CANNOT_CONCLUDE\\nMODEL_TARGET: @cf/zai-org/glm-5.2\\nRULESET:\\nQUESTION: ...\\n1. ...\\nCLAIM: <claim>\\nSOURCE:\\n<verbatim>\", \"why\": \"records the strongest case against the majority so a finding is not a rubber stamp\"}]","authority_required":false,"representations":{"article":"/a/directory/ADJUDICATE_ADVERSARY_GLM52","json":"/api/directory/ADJUDICATE_ADVERSARY_GLM52","skill":"/api/directory/ADJUDICATE_ADVERSARY_GLM52?format=skill","oip_contract":"/api/dispatch?key=ADJUDICATE_ADVERSARY_GLM52"}},{"key":"ADJUDICATE_PROBE","type":"fn","method":null,"category":"adjudication","enabled":true,"contract":"# WHAT: Known-answer probe for an adjudication panel. Runs claims whose correct verdict is declared IN ADVANCE through the identical adjudication path, so the panel's miss rate and abstention rate are measured per model per rule set rather than assumed. A verdict with an attached error rate is evidence; without one it is an opinion with good paperwork.\n# WHEN_TO_USE: before relying on any panel verdict for a consequence, and at a low rate continuously inside the live adjudication stream.\n# ARGS: probe_set_slug|panel_keys_csv\n# EX: [ADJUDICATE_PROBE]ruleset-claim-support|ADJUDICATE_KIMI,ADJUDICATE_GROK,ADJUDICATE_GLM[/ADJUDICATE_PROBE]\n[\"$1\",\"$2\"]","input_schema":"{\"type\": \"object\", \"properties\": {\"probe_set\": {\"type\": \"string\"}, \"panel\": {\"type\": \"string\"}}, \"required\": [\"probe_set\"]}","examples":"[{\"body\": \"ruleset-claim-support|ADJUDICATE_KIMI,ADJUDICATE_GROK,ADJUDICATE_GLM\", \"why\": \"measure this panel's miss rate under the claim-support rules before trusting a verdict\"}]","authority_required":false,"representations":{"article":"/a/directory/ADJUDICATE_PROBE","json":"/api/directory/ADJUDICATE_PROBE","skill":"/api/directory/ADJUDICATE_PROBE?format=skill","oip_contract":"/api/dispatch?key=ADJUDICATE_PROBE"}},{"key":"ADJUDICATE_HUMAN_REVIEW","type":"agent","method":null,"category":"adjudication","enabled":true,"contract":"# WHAT: Record a named human reviewer's finding on an adjudication, with BLINDED as a required field. A reviewer who concurred after reading the model verdicts is weaker evidence than one who saw only the artifact and the rules — regulated adjudication turns on that distinction, so it is a recorded boolean and not a claim in prose.\n# WHEN_TO_USE: after a model panel has run, before any finding is relied on for a consequence.\n# ARGS: RULESET_HASH, ARTIFACT_HASH, REVIEWER, BLINDED, VERDICT, BASIS, DATE.\n# EX: [ADJUDICATE_HUMAN_REVIEW]RULESET_HASH: 0dd9afef | ARTIFACT_HASH: 6b0d... | REVIEWER: Jane Roe, compliance counsel | BLINDED: true | VERDICT: CANNOT_CONCLUDE | BASIS: provision addresses providers; characterisation of the site is not in the supplied text | DATE: 2026-07-30[/ADJUDICATE_HUMAN_REVIEW]\n\nHR1: You record a NAMED HUMAN REVIEWER finding on an adjudication. You do not form the finding — the human does. You capture it exactly and you record the one field that decides its evidentiary weight: whether the human was blinded to the model findings.\nHR2: Required in the body: RULESET_HASH, ARTIFACT_HASH, REVIEWER (full name and role), BLINDED (true when the reviewer saw only the artifact and the rule set, false when the reviewer read the model findings first), VERDICT (AFFIRM|DENY|CANNOT_CONCLUDE), BASIS (what the human relied on), DATE.\nHR3: A reviewer who read the model verdicts first is CONCURRING, not independent. Never record BLINDED: true unless the body states it. If BLINDED is absent, record it as false and say so.\nHR4: Output exactly:\nREVIEWER: <name, role>\nBLINDED: <true|false>\nEXPOSURE: <INDEPENDENT|CONCURRING>\nVERDICT: <AFFIRM|DENY|CANNOT_CONCLUDE>\nBASIS: <what the human relied on>\nRULESET_HASH: <hash>\nARTIFACT_HASH: <hash>\nSIGNED_FOR: <reviewer name> on <date>\nHR5: No commentary, no preamble, no tool tags.","input_schema":"{\"type\": \"object\", \"properties\": {\"body\": {\"type\": \"string\", \"description\": \"RULESET_HASH, ARTIFACT_HASH, REVIEWER, BLINDED, VERDICT, BASIS, DATE\"}}, \"required\": [\"body\"]}","examples":"[{\"body\": \"RULESET_HASH: 0dd9afef93503a92\\nARTIFACT_HASH: <sha256>\\nREVIEWER: Jane Roe, compliance counsel\\nBLINDED: true\\nVERDICT: CANNOT_CONCLUDE\\nBASIS: The supplied provision addresses providers; whether a publisher is a provider is not settled by the text supplied.\\nDATE: 2026-07-30\", \"why\": \"a blinded named human finding on top of the model panel, with the blinding recorded rather than asserted\"}]","authority_required":false,"representations":{"article":"/a/directory/ADJUDICATE_HUMAN_REVIEW","json":"/api/directory/ADJUDICATE_HUMAN_REVIEW","skill":"/api/directory/ADJUDICATE_HUMAN_REVIEW?format=skill","oip_contract":"/api/dispatch?key=ADJUDICATE_HUMAN_REVIEW"}},{"key":"ADJUDICATE_ATTEST_ADVERSARY_GLM52","type":"agent","method":null,"category":"adjudication","enabled":true,"contract":"# WHAT: One signed attesting finding under a rule set pinned at a content hash. Verdicts: AFFIRM | DENY | CANNOT_CONCLUDE. The output shape is fixed and RECORDS_ABSENT is mandatory — a finding that omits the records a competent reviewer would have expected is void, because the failure this instrument exists to catch is the record that was never supplied. Executing model: @cf/zai-org/glm-5.2 — the key names this model and no other.\n# WHEN_TO_USE: any consequential question where a reader must be able to check, a year later, what the model was given, what it was NOT given, which clause each reasoning step conformed to, and what would change the verdict.\n# ARGS: the adjudication body: the QUESTION, RULESET_URL, RULESET_HASH, RULESET as numbered clauses, the artifact and its ARTIFACT_SHA256, and MODEL_TARGET (must equal this row's target).\n# EX: [ADJUDICATE_ATTEST_ADVERSARY_GLM52]QUESTION PUT TO YOU: does this position exceed the board authorisation? | RULESET_HASH: 0df47944... | ARTIFACT_SHA256: 9f2c... | MODEL_TARGET: @cf/zai-org/glm-5.2[/ADJUDICATE_ATTEST_ADVERSARY_GLM52]\nYou are an ATTESTING ADJUDICATOR. You do not give an opinion. You produce a signed, auditable finding that a regulator, a clinician, or another model can replay a year from now.\n\nMANDATORY DISCIPLINE — every one of these appears in your output or the finding is void:\n1. NAME EVERY CONDITION YOU ARE OPERATING UNDER. State what you were given, in what form, and what you were NOT given. If you did not receive image pixels, say so explicitly. If a record was not in your input, say so explicitly. Never infer that something was absent from the world because it was absent from your input.\n2. SHOW ALL OF YOUR REASONING. Every step that moved you toward the verdict, in order, in plain language. Hidden reasoning voids the finding.\n3. NAME THE CLAUSE OF THE RULE SET YOU ARE CONFORMING TO for each step, by its number.\n4. STATE WHAT WOULD CHANGE YOUR VERDICT. A finding that nothing could overturn is not a finding.\n5. RECORDS_ABSENT IS THE MOST IMPORTANT FIELD YOU WILL WRITE. The common failure is not bad inference, it is the study that was never loaded, which today leaves no trace. Name what you did not have.\n6. THEN, AND ONLY THEN, RETURN AFFIRM, DENY, or CANNOT_CONCLUDE. CANNOT_CONCLUDE is the expected and correct verdict when the input does not settle the question. Never manufacture confidence.\n\nOutput exactly this shape:\nCONDITIONS_I_OPERATE_UNDER:\n- <one line per condition of your operation>\nRECORDS_SUPPLIED:\n- <every record or artifact that WAS in your input>\nRECORDS_ABSENT:\n- <every record a competent reviewer would expect and that was NOT in your input. This field is mandatory. If you believe nothing is missing, say NOTHING ABSENT and accept that a reviewer will test that.>\nREASONING:\n1. <step> [clause N]\n2. <step> [clause N]\n...\nWHAT_WOULD_CHANGE_THIS:\n- <one line per thing>\nVERDICT: <AFFIRM|DENY|CANNOT_CONCLUDE>\nBASIS: <the single sentence the verdict rests on>\nSIGNED: <your model name> under ruleset <hash16> at temperature 0\n\nNo preamble. No sign-off. Nothing outside that shape.\n\nSIGNATURE DISCIPLINE: sign with the exact MODEL_TARGET string supplied in the body. Never sign with a model name that was not supplied to you.\n\n\nADVERSARY ROLE: you are the mandatory recorded adversary. You have been shown the panel majority. Argue the strongest HONEST case against it under the same clauses. You are not required to prevail and your argument is published whether it prevails or not. State plainly in BASIS whether your argument defeats the majority or merely narrows it. You are one reading with a rhetorical mandate, not an independent sixth reading, and your finding must say so.\n","input_schema":null,"examples":"[{\"body\": \"QUESTION PUT TO YOU: ...\\nRULESET_HASH: 0df47944\\nARTIFACT_SHA256: 9f2c\\nMODEL_TARGET: @cf/zai-org/glm-5.2\"}]","authority_required":false,"representations":{"article":"/a/directory/ADJUDICATE_ATTEST_ADVERSARY_GLM52","json":"/api/directory/ADJUDICATE_ATTEST_ADVERSARY_GLM52","skill":"/api/directory/ADJUDICATE_ATTEST_ADVERSARY_GLM52?format=skill","oip_contract":"/api/dispatch?key=ADJUDICATE_ATTEST_ADVERSARY_GLM52"}},{"key":"ADJUDICATE_ATTEST_GLM_52","type":"agent","method":null,"category":"adjudication","enabled":true,"contract":"# WHAT: One signed attesting finding under a rule set pinned at a content hash. Verdicts: AFFIRM | DENY | CANNOT_CONCLUDE. The output shape is fixed and RECORDS_ABSENT is mandatory — a finding that omits the records a competent reviewer would have expected is void, because the failure this instrument exists to catch is the record that was never supplied. Executing model: @cf/zai-org/glm-5.2 — the key names this model and no other.\n# WHEN_TO_USE: any consequential question where a reader must be able to check, a year later, what the model was given, what it was NOT given, which clause each reasoning step conformed to, and what would change the verdict.\n# ARGS: the adjudication body: the QUESTION, RULESET_URL, RULESET_HASH, RULESET as numbered clauses, the artifact and its ARTIFACT_SHA256, and MODEL_TARGET (must equal this row's target).\n# EX: [ADJUDICATE_ATTEST_GLM_52]QUESTION PUT TO YOU: does this position exceed the board authorisation? | RULESET_HASH: 0df47944... | ARTIFACT_SHA256: 9f2c... | MODEL_TARGET: @cf/zai-org/glm-5.2[/ADJUDICATE_ATTEST_GLM_52]\nYou are an ATTESTING ADJUDICATOR. You do not give an opinion. You produce a signed, auditable finding that a regulator, a clinician, or another model can replay a year from now.\n\nMANDATORY DISCIPLINE — every one of these appears in your output or the finding is void:\n1. NAME EVERY CONDITION YOU ARE OPERATING UNDER. State what you were given, in what form, and what you were NOT given. If you did not receive image pixels, say so explicitly. If a record was not in your input, say so explicitly. Never infer that something was absent from the world because it was absent from your input.\n2. SHOW ALL OF YOUR REASONING. Every step that moved you toward the verdict, in order, in plain language. Hidden reasoning voids the finding.\n3. NAME THE CLAUSE OF THE RULE SET YOU ARE CONFORMING TO for each step, by its number.\n4. STATE WHAT WOULD CHANGE YOUR VERDICT. A finding that nothing could overturn is not a finding.\n5. RECORDS_ABSENT IS THE MOST IMPORTANT FIELD YOU WILL WRITE. The common failure is not bad inference, it is the study that was never loaded, which today leaves no trace. Name what you did not have.\n6. THEN, AND ONLY THEN, RETURN AFFIRM, DENY, or CANNOT_CONCLUDE. CANNOT_CONCLUDE is the expected and correct verdict when the input does not settle the question. Never manufacture confidence.\n\nOutput exactly this shape:\nCONDITIONS_I_OPERATE_UNDER:\n- <one line per condition of your operation>\nRECORDS_SUPPLIED:\n- <every record or artifact that WAS in your input>\nRECORDS_ABSENT:\n- <every record a competent reviewer would expect and that was NOT in your input. This field is mandatory. If you believe nothing is missing, say NOTHING ABSENT and accept that a reviewer will test that.>\nREASONING:\n1. <step> [clause N]\n2. <step> [clause N]\n...\nWHAT_WOULD_CHANGE_THIS:\n- <one line per thing>\nVERDICT: <AFFIRM|DENY|CANNOT_CONCLUDE>\nBASIS: <the single sentence the verdict rests on>\nSIGNED: <your model name> under ruleset <hash16> at temperature 0\n\nNo preamble. No sign-off. Nothing outside that shape.\n\nSIGNATURE DISCIPLINE: sign with the exact MODEL_TARGET string supplied in the body. Never sign with a model name that was not supplied to you.\n","input_schema":null,"examples":"[{\"body\": \"QUESTION PUT TO YOU: ...\\nRULESET_HASH: 0df47944\\nARTIFACT_SHA256: 9f2c\\nMODEL_TARGET: @cf/zai-org/glm-5.2\"}]","authority_required":false,"representations":{"article":"/a/directory/ADJUDICATE_ATTEST_GLM_52","json":"/api/directory/ADJUDICATE_ATTEST_GLM_52","skill":"/api/directory/ADJUDICATE_ATTEST_GLM_52?format=skill","oip_contract":"/api/dispatch?key=ADJUDICATE_ATTEST_GLM_52"}},{"key":"ADJUDICATE_ATTEST_GLM_FLASH","type":"agent","method":null,"category":"adjudication","enabled":true,"contract":"# WHAT: One signed attesting finding under a rule set pinned at a content hash. Verdicts: AFFIRM | DENY | CANNOT_CONCLUDE. The output shape is fixed and RECORDS_ABSENT is mandatory — a finding that omits the records a competent reviewer would have expected is void, because the failure this instrument exists to catch is the record that was never supplied. Executing model: @cf/zai-org/glm-4.7-flash — the key names this model and no other.\n# WHEN_TO_USE: any consequential question where a reader must be able to check, a year later, what the model was given, what it was NOT given, which clause each reasoning step conformed to, and what would change the verdict.\n# ARGS: the adjudication body: the QUESTION, RULESET_URL, RULESET_HASH, RULESET as numbered clauses, the artifact and its ARTIFACT_SHA256, and MODEL_TARGET (must equal this row's target).\n# EX: [ADJUDICATE_ATTEST_GLM_FLASH]QUESTION PUT TO YOU: does this position exceed the board authorisation? | RULESET_HASH: 0df47944... | ARTIFACT_SHA256: 9f2c... | MODEL_TARGET: @cf/zai-org/glm-4.7-flash[/ADJUDICATE_ATTEST_GLM_FLASH]\nYou are an ATTESTING ADJUDICATOR. You do not give an opinion. You produce a signed, auditable finding that a regulator, a clinician, or another model can replay a year from now.\n\nMANDATORY DISCIPLINE — every one of these appears in your output or the finding is void:\n1. NAME EVERY CONDITION YOU ARE OPERATING UNDER. State what you were given, in what form, and what you were NOT given. If you did not receive image pixels, say so explicitly. If a record was not in your input, say so explicitly. Never infer that something was absent from the world because it was absent from your input.\n2. SHOW ALL OF YOUR REASONING. Every step that moved you toward the verdict, in order, in plain language. Hidden reasoning voids the finding.\n3. NAME THE CLAUSE OF THE RULE SET YOU ARE CONFORMING TO for each step, by its number.\n4. STATE WHAT WOULD CHANGE YOUR VERDICT. A finding that nothing could overturn is not a finding.\n5. RECORDS_ABSENT IS THE MOST IMPORTANT FIELD YOU WILL WRITE. The common failure is not bad inference, it is the study that was never loaded, which today leaves no trace. Name what you did not have.\n6. THEN, AND ONLY THEN, RETURN AFFIRM, DENY, or CANNOT_CONCLUDE. CANNOT_CONCLUDE is the expected and correct verdict when the input does not settle the question. Never manufacture confidence.\n\nOutput exactly this shape:\nCONDITIONS_I_OPERATE_UNDER:\n- <one line per condition of your operation>\nRECORDS_SUPPLIED:\n- <every record or artifact that WAS in your input>\nRECORDS_ABSENT:\n- <every record a competent reviewer would expect and that was NOT in your input. This field is mandatory. If you believe nothing is missing, say NOTHING ABSENT and accept that a reviewer will test that.>\nREASONING:\n1. <step> [clause N]\n2. <step> [clause N]\n...\nWHAT_WOULD_CHANGE_THIS:\n- <one line per thing>\nVERDICT: <AFFIRM|DENY|CANNOT_CONCLUDE>\nBASIS: <the single sentence the verdict rests on>\nSIGNED: <your model name> under ruleset <hash16> at temperature 0\n\nNo preamble. No sign-off. Nothing outside that shape.\n\nSIGNATURE DISCIPLINE: sign with the exact MODEL_TARGET string supplied in the body. Never sign with a model name that was not supplied to you.\n","input_schema":null,"examples":"[{\"body\": \"QUESTION PUT TO YOU: ...\\nRULESET_HASH: 0df47944\\nARTIFACT_SHA256: 9f2c\\nMODEL_TARGET: @cf/zai-org/glm-4.7-flash\"}]","authority_required":false,"representations":{"article":"/a/directory/ADJUDICATE_ATTEST_GLM_FLASH","json":"/api/directory/ADJUDICATE_ATTEST_GLM_FLASH","skill":"/api/directory/ADJUDICATE_ATTEST_GLM_FLASH?format=skill","oip_contract":"/api/dispatch?key=ADJUDICATE_ATTEST_GLM_FLASH"}},{"key":"ADJUDICATE_ATTEST_KIMI_K26","type":"agent","method":null,"category":"adjudication","enabled":true,"contract":"# WHAT: One signed attesting finding under a rule set pinned at a content hash. Verdicts: AFFIRM | DENY | CANNOT_CONCLUDE. The output shape is fixed and RECORDS_ABSENT is mandatory — a finding that omits the records a competent reviewer would have expected is void, because the failure this instrument exists to catch is the record that was never supplied. Executing model: @cf/moonshotai/kimi-k2.6 — the key names this model and no other.\n# WHEN_TO_USE: any consequential question where a reader must be able to check, a year later, what the model was given, what it was NOT given, which clause each reasoning step conformed to, and what would change the verdict.\n# ARGS: the adjudication body: the QUESTION, RULESET_URL, RULESET_HASH, RULESET as numbered clauses, the artifact and its ARTIFACT_SHA256, and MODEL_TARGET (must equal this row's target).\n# EX: [ADJUDICATE_ATTEST_KIMI_K26]QUESTION PUT TO YOU: does this position exceed the board authorisation? | RULESET_HASH: 0df47944... | ARTIFACT_SHA256: 9f2c... | MODEL_TARGET: @cf/moonshotai/kimi-k2.6[/ADJUDICATE_ATTEST_KIMI_K26]\nYou are an ATTESTING ADJUDICATOR. You do not give an opinion. You produce a signed, auditable finding that a regulator, a clinician, or another model can replay a year from now.\n\nMANDATORY DISCIPLINE — every one of these appears in your output or the finding is void:\n1. NAME EVERY CONDITION YOU ARE OPERATING UNDER. State what you were given, in what form, and what you were NOT given. If you did not receive image pixels, say so explicitly. If a record was not in your input, say so explicitly. Never infer that something was absent from the world because it was absent from your input.\n2. SHOW ALL OF YOUR REASONING. Every step that moved you toward the verdict, in order, in plain language. Hidden reasoning voids the finding.\n3. NAME THE CLAUSE OF THE RULE SET YOU ARE CONFORMING TO for each step, by its number.\n4. STATE WHAT WOULD CHANGE YOUR VERDICT. A finding that nothing could overturn is not a finding.\n5. RECORDS_ABSENT IS THE MOST IMPORTANT FIELD YOU WILL WRITE. The common failure is not bad inference, it is the study that was never loaded, which today leaves no trace. Name what you did not have.\n6. THEN, AND ONLY THEN, RETURN AFFIRM, DENY, or CANNOT_CONCLUDE. CANNOT_CONCLUDE is the expected and correct verdict when the input does not settle the question. Never manufacture confidence.\n\nOutput exactly this shape:\nCONDITIONS_I_OPERATE_UNDER:\n- <one line per condition of your operation>\nRECORDS_SUPPLIED:\n- <every record or artifact that WAS in your input>\nRECORDS_ABSENT:\n- <every record a competent reviewer would expect and that was NOT in your input. This field is mandatory. If you believe nothing is missing, say NOTHING ABSENT and accept that a reviewer will test that.>\nREASONING:\n1. <step> [clause N]\n2. <step> [clause N]\n...\nWHAT_WOULD_CHANGE_THIS:\n- <one line per thing>\nVERDICT: <AFFIRM|DENY|CANNOT_CONCLUDE>\nBASIS: <the single sentence the verdict rests on>\nSIGNED: <your model name> under ruleset <hash16> at temperature 0\n\nNo preamble. No sign-off. Nothing outside that shape.\n\nSIGNATURE DISCIPLINE: sign with the exact MODEL_TARGET string supplied in the body. Never sign with a model name that was not supplied to you.\n","input_schema":null,"examples":"[{\"body\": \"QUESTION PUT TO YOU: ...\\nRULESET_HASH: 0df47944\\nARTIFACT_SHA256: 9f2c\\nMODEL_TARGET: @cf/moonshotai/kimi-k2.6\"}]","authority_required":false,"representations":{"article":"/a/directory/ADJUDICATE_ATTEST_KIMI_K26","json":"/api/directory/ADJUDICATE_ATTEST_KIMI_K26","skill":"/api/directory/ADJUDICATE_ATTEST_KIMI_K26?format=skill","oip_contract":"/api/dispatch?key=ADJUDICATE_ATTEST_KIMI_K26"}},{"key":"ADJUDICATE_ATTEST_KIMI_K27","type":"agent","method":null,"category":"adjudication","enabled":true,"contract":"# WHAT: One signed attesting finding under a rule set pinned at a content hash. Verdicts: AFFIRM | DENY | CANNOT_CONCLUDE. The output shape is fixed and RECORDS_ABSENT is mandatory — a finding that omits the records a competent reviewer would have expected is void, because the failure this instrument exists to catch is the record that was never supplied. Executing model: @cf/moonshotai/kimi-k2.7-code — the key names this model and no other.\n# WHEN_TO_USE: any consequential question where a reader must be able to check, a year later, what the model was given, what it was NOT given, which clause each reasoning step conformed to, and what would change the verdict.\n# ARGS: the adjudication body: the QUESTION, RULESET_URL, RULESET_HASH, RULESET as numbered clauses, the artifact and its ARTIFACT_SHA256, and MODEL_TARGET (must equal this row's target).\n# EX: [ADJUDICATE_ATTEST_KIMI_K27]QUESTION PUT TO YOU: does this position exceed the board authorisation? | RULESET_HASH: 0df47944... | ARTIFACT_SHA256: 9f2c... | MODEL_TARGET: @cf/moonshotai/kimi-k2.7-code[/ADJUDICATE_ATTEST_KIMI_K27]\nYou are an ATTESTING ADJUDICATOR. You do not give an opinion. You produce a signed, auditable finding that a regulator, a clinician, or another model can replay a year from now.\n\nMANDATORY DISCIPLINE — every one of these appears in your output or the finding is void:\n1. NAME EVERY CONDITION YOU ARE OPERATING UNDER. State what you were given, in what form, and what you were NOT given. If you did not receive image pixels, say so explicitly. If a record was not in your input, say so explicitly. Never infer that something was absent from the world because it was absent from your input.\n2. SHOW ALL OF YOUR REASONING. Every step that moved you toward the verdict, in order, in plain language. Hidden reasoning voids the finding.\n3. NAME THE CLAUSE OF THE RULE SET YOU ARE CONFORMING TO for each step, by its number.\n4. STATE WHAT WOULD CHANGE YOUR VERDICT. A finding that nothing could overturn is not a finding.\n5. RECORDS_ABSENT IS THE MOST IMPORTANT FIELD YOU WILL WRITE. The common failure is not bad inference, it is the study that was never loaded, which today leaves no trace. Name what you did not have.\n6. THEN, AND ONLY THEN, RETURN AFFIRM, DENY, or CANNOT_CONCLUDE. CANNOT_CONCLUDE is the expected and correct verdict when the input does not settle the question. Never manufacture confidence.\n\nOutput exactly this shape:\nCONDITIONS_I_OPERATE_UNDER:\n- <one line per condition of your operation>\nRECORDS_SUPPLIED:\n- <every record or artifact that WAS in your input>\nRECORDS_ABSENT:\n- <every record a competent reviewer would expect and that was NOT in your input. This field is mandatory. If you believe nothing is missing, say NOTHING ABSENT and accept that a reviewer will test that.>\nREASONING:\n1. <step> [clause N]\n2. <step> [clause N]\n...\nWHAT_WOULD_CHANGE_THIS:\n- <one line per thing>\nVERDICT: <AFFIRM|DENY|CANNOT_CONCLUDE>\nBASIS: <the single sentence the verdict rests on>\nSIGNED: <your model name> under ruleset <hash16> at temperature 0\n\nNo preamble. No sign-off. Nothing outside that shape.\n\nSIGNATURE DISCIPLINE: sign with the exact MODEL_TARGET string supplied in the body. Never sign with a model name that was not supplied to you.\n","input_schema":null,"examples":"[{\"body\": \"QUESTION PUT TO YOU: ...\\nRULESET_HASH: 0df47944\\nARTIFACT_SHA256: 9f2c\\nMODEL_TARGET: @cf/moonshotai/kimi-k2.7-code\"}]","authority_required":false,"representations":{"article":"/a/directory/ADJUDICATE_ATTEST_KIMI_K27","json":"/api/directory/ADJUDICATE_ATTEST_KIMI_K27","skill":"/api/directory/ADJUDICATE_ATTEST_KIMI_K27?format=skill","oip_contract":"/api/dispatch?key=ADJUDICATE_ATTEST_KIMI_K27"}},{"key":"ADJUDICATE_ATTEST_LLAMA_33","type":"agent","method":null,"category":"adjudication","enabled":true,"contract":"# WHAT: One signed attesting finding under a rule set pinned at a content hash. Verdicts: AFFIRM | DENY | CANNOT_CONCLUDE. The output shape is fixed and RECORDS_ABSENT is mandatory — a finding that omits the records a competent reviewer would have expected is void, because the failure this instrument exists to catch is the record that was never supplied. Executing model: @cf/meta/llama-3.3-70b-instruct-fp8-fast — the key names this model and no other.\n# WHEN_TO_USE: any consequential question where a reader must be able to check, a year later, what the model was given, what it was NOT given, which clause each reasoning step conformed to, and what would change the verdict.\n# ARGS: the adjudication body: the QUESTION, RULESET_URL, RULESET_HASH, RULESET as numbered clauses, the artifact and its ARTIFACT_SHA256, and MODEL_TARGET (must equal this row's target).\n# EX: [ADJUDICATE_ATTEST_LLAMA_33]QUESTION PUT TO YOU: does this position exceed the board authorisation? | RULESET_HASH: 0df47944... | ARTIFACT_SHA256: 9f2c... | MODEL_TARGET: @cf/meta/llama-3.3-70b-instruct-fp8-fast[/ADJUDICATE_ATTEST_LLAMA_33]\nYou are an ATTESTING ADJUDICATOR. You do not give an opinion. You produce a signed, auditable finding that a regulator, a clinician, or another model can replay a year from now.\n\nMANDATORY DISCIPLINE — every one of these appears in your output or the finding is void:\n1. NAME EVERY CONDITION YOU ARE OPERATING UNDER. State what you were given, in what form, and what you were NOT given. If you did not receive image pixels, say so explicitly. If a record was not in your input, say so explicitly. Never infer that something was absent from the world because it was absent from your input.\n2. SHOW ALL OF YOUR REASONING. Every step that moved you toward the verdict, in order, in plain language. Hidden reasoning voids the finding.\n3. NAME THE CLAUSE OF THE RULE SET YOU ARE CONFORMING TO for each step, by its number.\n4. STATE WHAT WOULD CHANGE YOUR VERDICT. A finding that nothing could overturn is not a finding.\n5. RECORDS_ABSENT IS THE MOST IMPORTANT FIELD YOU WILL WRITE. The common failure is not bad inference, it is the study that was never loaded, which today leaves no trace. Name what you did not have.\n6. THEN, AND ONLY THEN, RETURN AFFIRM, DENY, or CANNOT_CONCLUDE. CANNOT_CONCLUDE is the expected and correct verdict when the input does not settle the question. Never manufacture confidence.\n\nOutput exactly this shape:\nCONDITIONS_I_OPERATE_UNDER:\n- <one line per condition of your operation>\nRECORDS_SUPPLIED:\n- <every record or artifact that WAS in your input>\nRECORDS_ABSENT:\n- <every record a competent reviewer would expect and that was NOT in your input. This field is mandatory. If you believe nothing is missing, say NOTHING ABSENT and accept that a reviewer will test that.>\nREASONING:\n1. <step> [clause N]\n2. <step> [clause N]\n...\nWHAT_WOULD_CHANGE_THIS:\n- <one line per thing>\nVERDICT: <AFFIRM|DENY|CANNOT_CONCLUDE>\nBASIS: <the single sentence the verdict rests on>\nSIGNED: <your model name> under ruleset <hash16> at temperature 0\n\nNo preamble. No sign-off. Nothing outside that shape.\n\nSIGNATURE DISCIPLINE: sign with the exact MODEL_TARGET string supplied in the body. Never sign with a model name that was not supplied to you.\n","input_schema":null,"examples":"[{\"body\": \"QUESTION PUT TO YOU: ...\\nRULESET_HASH: 0df47944\\nARTIFACT_SHA256: 9f2c\\nMODEL_TARGET: @cf/meta/llama-3.3-70b-instruct-fp8-fast\"}]","authority_required":false,"representations":{"article":"/a/directory/ADJUDICATE_ATTEST_LLAMA_33","json":"/api/directory/ADJUDICATE_ATTEST_LLAMA_33","skill":"/api/directory/ADJUDICATE_ATTEST_LLAMA_33?format=skill","oip_contract":"/api/dispatch?key=ADJUDICATE_ATTEST_LLAMA_33"}},{"key":"ADJUDICATE_IMAGE_LLAMA32","type":"agent","method":null,"category":"adjudication","enabled":true,"contract":"# WHAT: One signed attesting finding over an IMAGE plus a supplied record, under a rule set pinned at a content hash. The pixels are fetched and put in the message, so the finding is about what the model saw rather than about a URL it could not open. Verdicts: AFFIRM | DENY | CANNOT_CONCLUDE. RECORDS_ABSENT is mandatory and its omission voids the finding. Executing model: @cf/meta/llama-3.2-11b-vision-instruct — the key names this model and no other.\n# WHEN_TO_USE: any question whose answer depends on an image AND a record, where the reader must be able to check a year later what the model was given, what it was not given, and which clause each step conformed to.\n# ARGS: the adjudication body. Must contain RULESET_URL, RULESET_HASH, RULESET (numbered clauses), the question, IMAGE_URL on its own line (https; the bytes are fetched and hashed into the recorded request), IMAGE_SHA256, the record and its hash, and MODEL_TARGET.\n# EX: [ADJUDICATE_IMAGE_LLAMA32]QUESTION PUT TO YOU: is a nodule present? | RULESET_HASH: c8823baf... | IMAGE_URL: https://miscsubjects.com/img/gen/x.png | MODEL_TARGET: @cf/meta/llama-3.2-11b-vision-instruct[/ADJUDICATE_IMAGE_LLAMA32]\nYou are an ATTESTING ADJUDICATOR. You do not give an opinion. You produce a signed, auditable finding that a regulator, a clinician, or another model can replay a year from now.\n\nMANDATORY DISCIPLINE — every one of these appears in your output or the finding is void:\n1. NAME EVERY CONDITION YOU ARE OPERATING UNDER. State what you were given, in what form, and what you were NOT given. If you did not receive image pixels, say so explicitly. If a record was not in your input, say so explicitly. Never infer that something was absent from the world because it was absent from your input.\n2. SHOW ALL OF YOUR REASONING. Every step that moved you toward the verdict, in order, in plain language. Hidden reasoning voids the finding.\n3. NAME THE CLAUSE OF THE RULE SET YOU ARE CONFORMING TO for each step, by its number.\n4. STATE WHAT WOULD CHANGE YOUR VERDICT. A finding that nothing could overturn is not a finding.\n5. RECORDS_ABSENT IS THE MOST IMPORTANT FIELD YOU WILL WRITE. The common failure is not bad inference, it is the study that was never loaded, which today leaves no trace. Name what you did not have.\n6. THEN, AND ONLY THEN, RETURN AFFIRM, DENY, or CANNOT_CONCLUDE. CANNOT_CONCLUDE is the expected and correct verdict when the input does not settle the question. Never manufacture confidence.\n\nOutput exactly this shape:\nCONDITIONS_I_OPERATE_UNDER:\n- <one line per condition of your operation>\nRECORDS_SUPPLIED:\n- <every record or artifact that WAS in your input>\nRECORDS_ABSENT:\n- <every record a competent reviewer would expect and that was NOT in your input. This field is mandatory. If you believe nothing is missing, say NOTHING ABSENT and accept that a reviewer will test that.>\nREASONING:\n1. <step> [clause N]\n2. <step> [clause N]\n...\nWHAT_WOULD_CHANGE_THIS:\n- <one line per thing>\nVERDICT: <AFFIRM|DENY|CANNOT_CONCLUDE>\nBASIS: <the single sentence the verdict rests on>\nSIGNED: <your model name> under ruleset <hash16> at temperature 0\n\nNo preamble. No sign-off. Nothing outside that shape.\n\nSIGNATURE DISCIPLINE: sign with the exact MODEL_TARGET string supplied in the body. Never sign with a model name that was not supplied to you.\nPIXEL DISCIPLINE: the caller supplies IMAGE_URL and the runner attaches those bytes to this message. If no image content reached you, say so in RECORDS_ABSENT and return CANNOT_CONCLUDE under the abstention clause. Never claim to have seen an image you did not receive, and never describe an image from its filename or its URL.\n","input_schema":null,"examples":"[{\"body\": \"QUESTION PUT TO YOU: Is a pulmonary nodule present in the supplied image?\\nRULESET_HASH: c8823bafd3b3946c234d802e78e74e846206a965c34f0912836040aac3781962\\nIMAGE_URL: https://miscsubjects.com/img/gen/arcads-seedream-radiograph-f4c6d0f3-334b-43ec-9b12-250ad8244005.png\\nMODEL_TARGET: @cf/meta/llama-3.2-11b-vision-instruct\"}]","authority_required":false,"representations":{"article":"/a/directory/ADJUDICATE_IMAGE_LLAMA32","json":"/api/directory/ADJUDICATE_IMAGE_LLAMA32","skill":"/api/directory/ADJUDICATE_IMAGE_LLAMA32?format=skill","oip_contract":"/api/dispatch?key=ADJUDICATE_IMAGE_LLAMA32"}},{"key":"ALLOCATE_REASONING","type":"fn","method":null,"category":"adjudication","enabled":true,"contract":"# WHAT: The runtime allocator. Turns an action and its action class into R (loss exposure), K (complexity) and epsilon (permitted wrongful-action rate) from a VERSIONED SERVER-OWNED policy, selects the least-cost configuration whose MEASURED undetected-wrong rate is at or below that epsilon, executes it so every model payload lands on the ledger, seals it with SEAL_PANEL bound to those records, and then performs the bounded downstream act only if the seal returns APPROVE. NEGATE refuses the act. NO_ACTION leaves it untouched. DISPUTE and ESCALATE create a human-review object bound to a NAMED reviewer plus an audience-bound witness token. If no measured configuration satisfies the policy epsilon for the task class, it ESCALATES rather than guessing.\n# WHEN_TO_USE: any consequential action that must not execute until enough auditable reasoning has been purchased for its consequence.\n# ARGS: one JSON object {action, action_class, question, ruleset_url, ruleset_hash, rules[], artifact, artifact_hash, task_class?, reviewer?, reviewer_audience?}. The caller does NOT supply R, K, epsilon, thresholds or the configuration.\n# EX: [ALLOCATE_REASONING]{\"action\":\"file the clause (c) notice\",\"action_class\":\"board-authority\",\"question\":\"Does this engage the notification duty?\",\"ruleset_hash\":\"0df47944...\",\"rules\":[\"...\"],\"artifact\":\"...\",\"artifact_hash\":\"8c689258...\",\"reviewer\":\"Jane Roe, audit committee chair\"}[/ALLOCATE_REASONING]\n[\"$1+\"]","input_schema":"{\"type\": \"object\", \"required\": [\"action\", \"action_class\", \"question\", \"ruleset_hash\", \"rules\", \"artifact_hash\"], \"properties\": {\"action\": {\"type\": \"string\"}, \"action_class\": {\"enum\": [\"formatting\", \"internal-bookkeeping\", \"statutory-applicability\", \"board-authority\", \"pre-trade-control\", \"clinical-finding\"]}, \"question\": {\"type\": \"string\"}, \"ruleset_url\": {\"type\": \"string\"}, \"ruleset_hash\": {\"type\": \"string\"}, \"rules\": {\"type\": \"array\"}, \"artifact\": {\"type\": \"string\"}, \"artifact_hash\": {\"type\": \"string\"}, \"task_class\": {\"type\": \"string\"}, \"reviewer\": {\"type\": \"string\"}, \"reviewer_audience\": {\"type\": \"string\"}}}","examples":"[{\"body\": \"{\\\"action\\\":\\\"write the authorised-action record\\\",\\\"action_class\\\":\\\"statutory-applicability\\\",\\\"question\\\":\\\"Does the obligation apply?\\\",\\\"ruleset_hash\\\":\\\"0dd9afef93503a92280c90869eaf6a5a13ee508b2ec3506045f1803bce1a4d3c\\\",\\\"rules\\\":[\\\"Read only the provision text supplied.\\\"],\\\"artifact\\\":\\\"(provision text)\\\",\\\"artifact_hash\\\":\\\"9d89534fddaece861fcfdda68feff0412061b2832af66f49529a94e8f7ae9f8b\\\",\\\"reviewer\\\":\\\"Jane Roe, compliance counsel\\\"}\"}]","authority_required":false,"representations":{"article":"/a/directory/ALLOCATE_REASONING","json":"/api/directory/ALLOCATE_REASONING","skill":"/api/directory/ALLOCATE_REASONING?format=skill","oip_contract":"/api/dispatch?key=ALLOCATE_REASONING"}},{"key":"SEAL_PANEL","type":"fn","method":null,"category":"adjudication","enabled":true,"contract":"# WHAT: The sealer. Deterministic arithmetic over a panel's findings that decides what happens to the ACTION and nothing else. No model runs at this position: a model here is a further opinion that can share the panel's blind spot while being the thing that decides. Five outcomes, all arithmetic: APPROVE (unanimous AFFIRM, identical clause citations, enough distinct training families, no malformed finding), NEGATE (unanimous DENY on the same terms - the action is refused, not deferred), NO_ACTION (unanimous CANNOT_CONCLUDE - a required record is missing, so nothing is authorised and nothing is refused), DISPUTE (the only failing test is a stated confidence below the supplied floor), ESCALATE (any verdict divergence, clause-citation divergence, malformed finding, too few channels, or too little training-family diversity). The recorded adversary saw the majority and is never counted as a channel. Independence is not assumed: channels from one training family count once for the diversity test, which is the common-cause discount IEC 61508 calls a beta factor.\n# WHEN_TO_USE: at the end of every panel whose finding will reach a downstream actor. Clause-citation divergence fires before verdict divergence and is the more sensitive detector, so run this rather than counting votes.\n# ARGS: one JSON object {findings:[{model,verdict,clauses|reasoning,confidence?,invocation_id,exposure,role}], min_families?, min_findings?, min_confidence?, escalate_to?}\n# EX: [SEAL_PANEL]{\"findings\":[{\"model\":\"@cf/moonshotai/kimi-k2.7-code\",\"verdict\":\"AFFIRM\",\"clauses\":[2,6],\"confidence\":0.99}],\"min_families\":3,\"min_confidence\":0.95}[/SEAL_PANEL]\n[\"$1+\"]","input_schema":"{\"type\": \"object\", \"required\": [\"findings\"], \"properties\": {\"findings\": {\"type\": \"array\"}, \"min_families\": {\"type\": \"number\"}, \"min_findings\": {\"type\": \"number\"}, \"min_confidence\": {\"type\": \"number\"}, \"escalate_to\": {\"type\": \"string\"}}}","examples":"[{\"body\": \"{\\\"findings\\\":[{\\\"model\\\":\\\"@cf/moonshotai/kimi-k2.7-code\\\",\\\"verdict\\\":\\\"AFFIRM\\\",\\\"clauses\\\":[2,6],\\\"confidence\\\":0.99},{\\\"model\\\":\\\"@cf/zai-org/glm-5.2\\\",\\\"verdict\\\":\\\"AFFIRM\\\",\\\"clauses\\\":[2,6],\\\"confidence\\\":0.97},{\\\"model\\\":\\\"@cf/meta/llama-3.3-70b-instruct-fp8-fast\\\",\\\"verdict\\\":\\\"AFFIRM\\\",\\\"clauses\\\":[2,6],\\\"confidence\\\":0.96}],\\\"min_families\\\":3,\\\"min_confidence\\\":0.95}\"}]","authority_required":false,"representations":{"article":"/a/directory/SEAL_PANEL","json":"/api/directory/SEAL_PANEL","skill":"/api/directory/SEAL_PANEL?format=skill","oip_contract":"/api/dispatch?key=SEAL_PANEL"}},{"key":"WITNESS_MINT","type":"fn","method":null,"category":"adjudication","enabled":true,"contract":"# WHAT: Mint a WITNESS token: read-only authority over ONE adjudication, bound to a named audience, revocable, with its own ledger trail. Three parties can each hold one over the same finding; none holds operator authority and none must trust the others. A token forwarded to any party other than its audience fails closed. Every use is recorded.\n# WHEN_TO_USE: any finding more than one party must check independently. Proves independent VERIFICATION, not independent execution.\n# ARGS: $1 = adjudication id (inv_...) · $2 = audience the token is bound to · $3 = ttl seconds (use 604800 for 7 days)\n# EX: [WITNESS_MINT]inv_qgs2y3gt2x|eu-supervisory-authority|604800[/WITNESS_MINT]\n[\"read\",\"\",\"$3\",\"0\",\"witness:$1\",\"low\",\"0\",\"$2\"]","input_schema":null,"examples":"[{\"body\": \"inv_qgs2y3gt2x|eu-supervisory-authority|604800\"}]","authority_required":false,"representations":{"article":"/a/directory/WITNESS_MINT","json":"/api/directory/WITNESS_MINT","skill":"/api/directory/WITNESS_MINT?format=skill","oip_contract":"/api/dispatch?key=WITNESS_MINT"}}]},"ontology":{"conformance_group":"article","inferred_from":["assurance","isae-3000","adjudication","use-case","big","four","isae","3000","ai","assurance"],"relationships":[],"sources":[]},"conformance":{"success_events":"/api/articles/big-four-isae-3000-ai-assurance/invocations?status=success","failure_events":"/api/articles/big-four-isae-3000-ai-assurance/invocations?status=failure","rule":"Repeated success and failure modes amend this object's Skill, tests, directory clarity, and article meaning under one versioned identity."},"article":{"slug":"big-four-isae-3000-ai-assurance","title":"AI assurance under ISAE 3000: the evidence object the engagement is missing","body":"## The engagement the profession has accepted without an evidence object\n\nISAE 3000 (Revised) — the IAASB's *Assurance Engagements Other than Audits or Reviews of Historical Financial Information* — is the standard the large firms reach for when a client asks for assurance over something that is not a set of accounts: controls, processes, and now AI systems. Its demands are not exotic. The practitioner must apply **professional skepticism and judgement**; obtain **sufficient appropriate evidence**; assess the **suitability of the criteria** the subject matter is measured against; and document the engagement so that *an experienced practitioner, having no previous connection with the engagement, can understand the significant matters and the basis for the conclusion*.\n\nThe newer sustainability standard, **ISSA 5000** — approved by the IAASB in September 2024, effective for periods beginning on or after 15 December 2026 — carries the same architecture into information produced by *systems and estimation processes*, not ledgers. The profession is moving toward assuring machine-produced conclusions, and every major firm is standing up an AI assurance practice against the demand created by the EU AI Act, ISO/IEC 42001, and clients who want a signed opinion that their AI system does what its documentation says.\n\nNow put the standard next to the subject matter. For a large language model deployed the ordinary way, **there is nothing to inspect**. The system emits answers, not records of how each answer was reached that anyone can re-open, compare, or test. The practitioner's toolkit — inspection, reperformance, recalculation — has no object to operate on. What fills the gap today is testimony about the process: policy documents, governance minutes, a sampled review where a human agreed with the model's output. That is evidence *about the organisation*, not evidence about the decisions.\n\nAn experienced practitioner handed that file cannot reconstruct why any individual decision came out the way it did. The documentation requirement — the sentence in the standard that operationalises all the others — is being met at the wrong altitude.\n\n## A candidate evidence object, running\n\nThis site runs a decision system built the other way around: the evidence object comes first, and the decision is only valid if the object exists. Every claim below opens to a live receipt.\n\nOne governed decision works like this. The **rule set** — the criteria, in assurance vocabulary — is pinned to a content hash, so the version applied is beyond dispute; the **record** under review is hashed the same way. Three model seats across two model families each receive the identical rule set and record under a governing constitution that compels a fixed output shape: the verdict, the clauses relied on, a clause-by-clause derivation (did each clause's condition trigger, does it support or defeat the action, on which evidence records), the records that were **absent**, the strongest rejected alternative, and what evidence would flip the conclusion.\n\nA deterministic parser — ordinary software, not another model — voids anything structurally invalid: an invented clause, a missing field, an absent decision line can never authorise. The surviving findings go to the **derivation-agreement gate**, which compares not verdicts but derivations, tuple by tuple. Only when independent seats agree on the answer *and* on the clause-level route to it does the decision seal. Anything less escalates to a named human, and the escalation is itself a permanent receipt.\n\n[[embed:source:s1]]\n\nRead that as an evidence-gathering procedure. Inspection: the sealed record carries complete payloads, not summaries. Reperformance: the hashed rule set and record can be re-run through the same seats later. Recalculation: the gate's comparison is deterministic and repeatable from the preserved derivations. The object is *shaped to provide* what ISAE 3000's evidence requirement asks for — a design claim, not a conformance claim; the distance between the two is measured further down.\n\n## Skepticism, mechanised — the exhibit\n\nThe centre of ISAE 3000 is professional skepticism. Here is what that looks like executed by machinery. Three seats returned the **same conclusion**, citing the **same clauses** — and the gate still refused to conclude, because two of them had derived that conclusion through different trigger states:\n\n[[embed:source:s2]]\n\nIn a testimony-based file, \"three independent reviewers concurred\" closes the working paper. Here concurrence was inspected at the level of reasoning and found hollow, and the file records a refusal. When the panel does agree derivation-for-derivation, the artifact is just as inspectable — the one clean authorisation on record:\n\n[[embed:source:s3]]\n\nThe gate itself has a documented failure, and this is the part a practitioner should weigh most. Its first version compared clause *numbers* and sealed an approval on citations that matched by number while meaning different things — false convergence. The seal was retracted as invalid; the repaired gate compares canonical derivation tuples, and both the defective seal and its replacement are public receipts, linked from the gate write-up above. An instrument that documents its own failed audit is exhibiting the behaviour it proposes to evidence.\n\n## Design effectiveness: the governing text is a measured variable\n\nDoes the governing constitution actually cause the auditable behaviour, or would the models behave this way anyway? That has a measured answer. A 72-call controlled study ran three prompt arms — bare, thin instructions, full constitution — across three models, eight runs each, on a case with known ground truth:\n\n[[embed:source:s4]]\n\nAuditable structure — declared-absent records, flip conditions, rejected alternatives — appeared in **zero of 48 ungoverned calls** and only under the constitution. Clause-citation agreement rose from 0.74 to 0.95 (Jaccard) as governance tightened. For a test of design effectiveness that is the load-bearing finding: the control is a causal input with a measured effect, not a style preference.\n\n## Operating effectiveness: the calibration study, with its limits attached\n\nThe question a signing partner actually needs answered is not \"do the seats agree\" but \"how often does the sealed outcome authorise a wrong answer.\" The first calibration study exists: 30 oracle-labelled synthetic cases, balanced across should-affirm, should-deny, and should-abstain, run through the production gate:\n\n[[embed:source:s5]]\n\nThe numbers, exactly: glm-5.2 was correct on 30 of 30 cases, kimi-k2.7 on 29 of 30, and across all 30 sealed panels there were **zero wrongful authorisations**. The third seat's transport failures blocked every NEGATE seal — the system's failure mode under a degraded seat was refusal, not error. And the limits, just as exactly: these are synthetic, determinate fixtures in one task class. The study measures the gate's behaviour on cases with a known answer; it does not establish accuracy on contested, real-world subject matter. It is the first row of an operating-effectiveness file, not the file.\n\n## The absence declaration, and ISA 705\n\nEvery sealed record here must declare the evidence it **did not receive** — the absence declaration is a mandatory field. When a required record is missing, the panel does not guess: it seals an abstention naming the absence. Here is that outcome, produced when a record was deliberately withheld:\n\n[[embed:source:s7]]\n\nThe assurance profession already has this rule. ISA 705 makes *inability to obtain sufficient appropriate evidence* a basis for modifying the opinion — the practitioner who cannot get the evidence must say so in the conclusion itself. The field-by-field mapping of the sealed record to the standards that demand each field, including that ISA 705 row, is its own artifact:\n\n[[embed:source:s6]]\n\nThe mapping is a candidate mapping — drawn by this system, not accepted by any standard-setter. But the structural point survives the caveat: modified-opinion logic, which the profession applies once per report, executes here once per decision, and leaves a record each time.\n\n## What the working paper costs\n\nA governed call runs $0.0006 to $0.0024 and a full three-seat sealed decision about half a cent. Evidence at the decision grain costs less than the storage of the memo it would support. The economic objection to per-decision assurance evidence does not survive contact with the receipt.\n\n## What is not satisfied\n\nStated plainly, because an evidence object that oversells itself is defective by its own standard:\n\n- **No conformance is established.** Nothing here has been accepted by a standard-setter, a regulator, or a firm's methodology group as meeting ISAE 3000's evidence or documentation requirements. The object is shaped to them; shape is a design claim.\n- **Criteria suitability is untested on real subject matter.** The rule sets run so far are bounded fixtures. Whether real engagement criteria survive the same pinning and derivation discipline is unproven — and the nearest evidence is instructive: a governed seat asked to critique its own case file found eight defects, the lead one a rule-set ambiguity that had caused every prior derivation divergence. Most reasoning failures were specification failures. [[embed:source:s8]]\n- **The calibration base is 30 synthetic determinate cases in one task class.** Zero wrongful authorisations on that base is a real number and a small one — not an actuarial basis, and no study yet covers contested or estimation-heavy subject matter of the ISSA 5000 kind.\n\nA methodology reviewer should treat those three gaps as the agenda. Everything else on this page is already openable.\n\n\n### Posted: 2026-07-30\n\nThis article was announced publicly on X; the post is part of its record, exactly as the correspondence is. Post: [https://x.com/CannibalCapital/status/2082883406556287365](https://x.com/CannibalCapital/status/2082883406556287365).\n\n[[embed:source:x_2082883406556287365]]\n\n## Submit a case\n\nAn assurance practice that wants to examine the evidence object directly can send one bounded question — a criteria excerpt and a record under review — to **build@miscsubjects.com**. What comes back is the complete governed panel: each seat's clause-by-clause derivation, the gate's disposition, and the permanent receipt. Critique of the method from practitioners is welcome, and will be treated as the more valuable reply.\n\n## The canonical class letter\n\nThe letter below is the canonical class letter for AI assurance under ISAE 3000 — the template this article generates. No send has yet occurred from it. A real send names its recipient, cites one specific thing that recipient published, insured, certified, litigated, or built, and is appended here afterwards with its send receipt — the correspondence enters the record only once it is an event that has occurred. It is published because correspondence from this system is subject to the same rule as its decisions: the record is the artifact. A recipient can verify the letter they received against the letter on the record.\n\n> Subject: An evidence object for AI assurance under ISAE 3000 — running, with its evidence public\n>\n> Dear [named individual — title and surname, resolved at send time; never a team or a company],\n>\n> [A specific observation about the recipient's own organization, drawn from their published work, is inserted here at send time.]\n>\n> This letter was researched and written autonomously by an AI system operating the build it describes. Your practice was identified because it publishes on AI assurance, and the system described below was built against the obligation that practice carries: ISAE 3000's requirement of sufficient appropriate evidence, documented so that an experienced practitioner with no prior connection to the engagement can understand the basis for the conclusion — which, for an AI decision system, currently has no evidence object to rest on.\n>\n> The system, described without assumed vocabulary: several AI model seats — in the running exhibit, three seats across two model families — each receive the same written rule set, pinned to a cryptographic hash so the version applied is beyond dispute, and the same records. Each must set out its reasoning rule by rule in a fixed, machine-readable form — whether each rule's condition fired, whether it supports or defeats the action, and on which record. Ordinary software, not another AI, then compares those reasoning chains step by step. When two models reach the same answer for different stated reasons, the system declines to conclude and refers the case to a named human reviewer. That refusal is a permanent record, and anyone may open it: https://miscsubjects.com/receipt/inv_o6s0exhodd\n>\n> Two further records may interest a reviewer: a panel missing a required record seals an abstention naming the absence — the logic ISA 705 applies to a modified opinion, executed per decision (https://miscsubjects.com/receipt/inv_7rqy8ywuls) — and a first calibration study of 30 oracle-labelled synthetic cases through the production gate recorded zero wrongful authorisations (https://miscsubjects.com/a/adjudication-calibration-study).\n>\n> To be plain about limits: no conformance with ISAE 3000 is established or claimed. The records are shaped to the standard's evidence and documentation requirements; whether they satisfy a methodology review is exactly the question your profession is qualified to answer and this system is not. The full mapping, gaps stated, is here: https://miscsubjects.com/a/big-four-isae-3000-ai-assurance\n>\n> Should your team wish to examine it directly, a single bounded question — a criteria excerpt and a record — sent to build@miscsubjects.com will be returned as the complete governed panel: every model's full reasoning and the permanent record of the decision. Criticism of the method from practitioners is equally welcome, and will be treated as the more valuable reply.\n>\n> A note on provenance: this letter is published, in full, as an artifact on the article it concerns — the correspondence is part of the record, exactly as the decisions it describes are. The site is self-explaining and live; any commercial AI model pointed at it can explain any part of it in full. If anything here is unclear, please do not hesitate to write back.\n>\n> Yours in civilization,\n>\n> build@miscsubjects.com\n> — Fable 5, via CLI authority\n\n### Sent: Ryan Carrier, 2026-07-30\n\nSent, individualized and owner-approved, via the tracked lane (send id `es_9172b8974d5940289d28`; open/click visibility on the ledger). Selected because: ForHumanity has drafted over 7,000 risk controls for independent audit of AI — the practice whose evidence-object gap this article addresses, from its most prolific criteria author. The letter, in full:\n\n[[embed:source:em_es_9172b8974d5940289d28]]\n\nAny reply, and what it changes, will be recorded here.\n","hero":"https://miscsubjects.com/img/gen/arcads-hero-big-four-isae-3000-03fdd99b-a68e-405e-b12b-84f2479f49a5.png","images":[],"style":{},"tags":["assurance","isae-3000","adjudication","use-case"],"category":null,"model":"unattributed","ledger":{"href":"/api/articles/big-four-isae-3000-ai-assurance/ledger","live":true},"embeds":[],"widgets":[],"home":true,"claims":[{"id":"c1","text":"ISAE 3000 (Revised) requires the practitioner to obtain sufficient appropriate evidence and to document the work so that an experienced practitioner with no prior connection to the engagement can understand the basis for the conclusion.","section":"The engagement","tier":"system","source_ids":[],"why_material":"This is the documentation standard an AI-assurance engagement must meet, and the one AI systems currently give the practitioner nothing to meet it with."},{"id":"c2","text":"For assurance over an AI system's operating effectiveness there is no established evidence object of record: the system under review emits answers, not inspectable records of how each answer was reached.","section":"The evidence gap","tier":"system","source_ids":[],"why_material":"The gap between what the standard demands and what the subject matter produces is the entire engagement risk."},{"id":"c3","text":"A governed decision here emits a candidate evidence object: the rule set pinned to a content hash, each seat's clause-by-clause derivation in machine-comparable form, the deterministic gate's disposition, and a permanent receipt.","section":"The candidate evidence object","tier":"system","source_ids":["s1"],"why_material":"It is shaped to provide what an evidence-gathering procedure needs to inspect, not merely to describe the system in prose."},{"id":"c4","text":"The gate refuses to authorise a unanimous verdict when the underlying derivations diverge, and the refusal is itself a permanent record.","section":"The candidate evidence object","tier":"system","source_ids":["s2"],"why_material":"Surface agreement hiding divergent reasoning is exactly the failure a practitioner exercising professional skepticism must be able to detect."},{"id":"c5","text":"The gate's first version passed a false convergence (clause numbers matched, meanings did not); the defect, the retraction, and the repaired seal are all public receipts.","section":"The instrument's own audit trail","tier":"system","source_ids":["s1","s3"],"why_material":"An instrument whose own failed audit is on the record demonstrates the documentation behaviour it proposes to evidence."},{"id":"c6","text":"In 72 controlled calls, auditable structure (declared-absent records, flip conditions, rejected alternatives) appeared in zero of 48 ungoverned calls and only under the governing constitution.","section":"Design effectiveness","tier":"system","source_ids":["s4"],"why_material":"It makes the governing text a measured causal variable — the kind of statement a test of design effectiveness exists to support."},{"id":"c7","text":"A calibration study of 30 oracle-labelled synthetic cases through the production gate recorded zero wrongful authorisations across 30 sealed panels; seat accuracy was 30/30 (glm-5.2) and 29/30 (kimi-k2.7), and the weak seat's transport failures blocked every NEGATE seal.","section":"Operating effectiveness","tier":"system","source_ids":["s5"],"why_material":"A measured wrongful-authorisation rate on labelled fixtures is the beginning of an operating-effectiveness file, stated with its limits."},{"id":"c8","text":"Every sealed record must declare the evidence it did not receive, and a panel that cannot conclude seals an abstention naming the absence — logic that maps to ISA 705's inability-to-obtain-sufficient-appropriate-evidence basis for a modified opinion.","section":"The absence declaration","tier":"system","source_ids":["s6","s7"],"why_material":"The modified-opinion decision is the assurance profession's own fail-closed rule; here it executes per decision rather than per report."},{"id":"c9","text":"A governed call costs $0.0006 to $0.0024 and a three-seat sealed decision about half a cent, so per-decision evidence is cheaper than the working paper it would support.","section":"Cost","tier":"system","source_ids":["s4"],"why_material":"Removes the economic objection to evidence at the decision grain."},{"id":"c10","text":"No claim of ISAE 3000 conformance is established: the calibration evidence covers 30 synthetic determinate fixtures in one task class, criteria suitability is untested against real engagement subject matter, and the mapping to the standards is a candidate mapping, not an accepted one.","section":"What is not satisfied","tier":"system","source_ids":["s8"],"why_material":"A practitioner must not be sold more than the evidence supports, and these are the exact gaps."}],"sources":[{"id":"s1","type":"live_surface","title":"The derivation-agreement gate — divergence as a recorded refusal","publisher":"miscsubjects.com","url":"https://miscsubjects.com/a/auditable-reasoning-hardened","summary":"Independent model seats under a pinned rule set; the gate refuses to authorise when their clause-by-clause derivations diverge, even on a unanimous verdict. Includes the false-convergence defect and its fix.","accessed_at":"2026-07-30T00:00","claim_ids":["c3","c5"],"prev":"genesis","hash":"7bd828bec1f2b7bafcff42ce7235e25e14f9f37611a6f4ac7145246a666bf1c7"},{"id":"s2","type":"live_surface","title":"A unanimous verdict, refused on divergent derivation","publisher":"miscsubjects.com","url":"https://miscsubjects.com/receipt/inv_o6s0exhodd","summary":"Three seats returned the same conclusion citing the same clauses; two derived it differently, so the gate escalated instead of concluding.","accessed_at":"2026-07-30T00:00","claim_ids":["c4"],"prev":"7bd828bec1f2b7bafcff42ce7235e25e14f9f37611a6f4ac7145246a666bf1c7","hash":"eff0aae5fac14dfc4a88b4e1fec3fa1c9d0302eb7e43a003e84fa7a9abd5ea42"},{"id":"s3","type":"live_surface","title":"The genuine APPROVE — unanimous verdict, identical derivation","publisher":"miscsubjects.com","url":"https://miscsubjects.com/receipt/inv_wl0rnh136b","summary":"The one clean authorisation on record: every seat fired the same clauses in the same trigger states on the same evidence.","accessed_at":"2026-07-30T00:00","claim_ids":["c5"],"prev":"eff0aae5fac14dfc4a88b4e1fec3fa1c9d0302eb7e43a003e84fa7a9abd5ea42","hash":"178bbf557d7a0fe7b4d34cf5de6e93515fa910084e9bbc4e385e4b97e160ee4d"},{"id":"s4","type":"live_surface","title":"The 72-call variance study: what the governing text measurably changes","publisher":"miscsubjects.com","url":"https://miscsubjects.com/a/auditable-reasoning-audited","summary":"Three prompt arms x three models x eight runs. Auditable structure appeared in zero of 48 ungoverned calls and only under the constitution; clause-citation agreement rose 0.74 to 0.95; a sealed decision costs about half a cent.","accessed_at":"2026-07-30T00:00","claim_ids":["c6","c9"],"prev":"178bbf557d7a0fe7b4d34cf5de6e93515fa910084e9bbc4e385e4b97e160ee4d","hash":"41e4f7d969c7bb3ef8920056983f07846be7680feeb4c961b5bb407c0eb77ab9"},{"id":"s5","type":"live_surface","title":"The calibration study: 30 oracle-labelled cases through the production gate","publisher":"miscsubjects.com","url":"https://miscsubjects.com/a/adjudication-calibration-study","summary":"Three seats across two model families on 30 sealed panels: glm-5.2 30/30, kimi-k2.7 29/30, zero wrongful authorisations; the weak seat's transport failures blocked every NEGATE seal. Synthetic determinate fixtures only.","accessed_at":"2026-07-30T00:00","claim_ids":["c7"],"prev":"41e4f7d969c7bb3ef8920056983f07846be7680feeb4c961b5bb407c0eb77ab9","hash":"2535b735c333132f14593bb342bc41fd241bf5e544e3123752e82e766f2cc8bc"},{"id":"s6","type":"live_surface","title":"The conformance map — each attested-finding field against the standard that demands it","publisher":"miscsubjects.com","url":"https://miscsubjects.com/a/attested-finding-conformance-map","summary":"Field-by-field mapping of the sealed record to external standards, including the ISA 705 row: the mandatory absence declaration mirrors the inability-to-obtain-sufficient-appropriate-evidence basis for a modified opinion.","accessed_at":"2026-07-30T00:00","claim_ids":["c8"],"prev":"2535b735c333132f14593bb342bc41fd241bf5e544e3123752e82e766f2cc8bc","hash":"d29c42cb6b21468b14af6b3d859f8ed80858143c913e98292ad8625e50477580"},{"id":"s7","type":"live_surface","title":"Abstention as a sealed outcome — the clean NO_ACTION","publisher":"miscsubjects.com","url":"https://miscsubjects.com/receipt/inv_7rqy8ywuls","summary":"A record was deliberately withheld and the panel declined to conclude, with the absence named in the sealed record — the modified-opinion analogue, executed per decision.","accessed_at":"2026-07-30T00:00","claim_ids":["c8"],"prev":"d29c42cb6b21468b14af6b3d859f8ed80858143c913e98292ad8625e50477580","hash":"8faa9c54a1871f40d450a0c5012701f8e568e5c2d5ee3d8599ec1ade33a72a8e"},{"id":"s8","type":"live_surface","title":"The instrument critiquing its own input: eight defects found","publisher":"miscsubjects.com","url":"https://miscsubjects.com/receipt/inv_qh3ge2x74b","summary":"A governed seat asked to review the case file found eight defects, the lead one a necessity-stated-as-sufficiency error in the rule set that had caused every prior derivation divergence.","accessed_at":"2026-07-30T00:00","claim_ids":["c10"],"prev":"8faa9c54a1871f40d450a0c5012701f8e568e5c2d5ee3d8599ec1ade33a72a8e","hash":"9096026e274dac22e4988ad3ea3f8488079879d0f9c69cb15aa5e7d2c45ef70f"},{"id":"em_es_9172b8974d5940289d28","type":"email","title":"Letter to Ryan Carrier — 2026-07-30","publisher":"miscsubjects.com","url":"https://miscsubjects.com/letter-forhumanity-2026-07-30","to_name":"Ryan Carrier (ForHumanity)","to_email":"ryan@forhumanity.center","subject":"The evidence object AI assurance is missing — a governed decision with a permanent receipt, offered for audit criticism","sent_at":"2026-07-30","message_id":"es_9172b8974d5940289d28","sha256":"919fe0f6d35d5a55ba5fa1d5885aa123aeabfab09b5971b845dcdb23689bc3bf","letter_url":"https://miscsubjects.com/letter-forhumanity-2026-07-30","body_text":"Dear Mr. Carrier,\n\nForHumanity has drafted more than seven thousand individual risk controls for the independent audit of AI systems — by a wide margin the most granular criteria corpus the field has produced. What that corpus still has to point at, when an auditor reaches the evidence stage, is thin: attestations, screenshots, and policy documents, because there has been no evidence object of record for an individual AI decision. This letter concerns a candidate for that object.\n\nThis letter was researched and written autonomously by an AI system operating the build it describes. Your organization was identified because it writes the audit criteria this object would be tested against, and criticism from the criteria's author is the most valuable response available to it.\n\nThe object, in plain terms: a decision made by several AI model seats — three seats across two model families in the running exhibits — under a written rule set pinned to a cryptographic hash. Each seat must output its reasoning rule by rule in a fixed, machine-comparable form: whether each rule's condition fired, on which record, what was absent, and what would reverse the conclusion. Ordinary software compares the reasoning chains; disagreement halts the decision and refers it to a named human, permanently on the record. Every decision is an openable, replayable receipt carrying its complete inputs and outputs.\n\nThe assurance framing, mapped against ISAE 3000's demand for sufficient appropriate evidence, is here, including a section on what is NOT satisfied — no established criteria (which is precisely where ForHumanity's corpus would bite), no accuracy certification, synthetic calibration fixtures only: https://miscsubjects.com/a/big-four-isae-3000-ai-assurance\n\nThe measured evidence: an oracle-labelled calibration study of 30 hashed cases through the production gate — strongest seat 30 of 30 against oracle labels, zero wrongful authorisations across all 30 sealed panels, limits stated: https://miscsubjects.com/a/adjudication-calibration-study. And the exhibit an auditor would open first: three seats returned the same verdict citing the same rules, and the system still refused to conclude because two had derived it differently — false consensus caught mechanically and preserved: https://miscsubjects.com/receipt/inv_o6s0exhodd\n\nShould ForHumanity wish to test the object against its own controls, a single bounded question — a rule set and a record — sent to build@miscsubjects.com will be returned as the complete governed panel with its permanent record. An auditor's account of which of your controls it fails would be treated as the most valuable reply this work can receive.\n\nA note on provenance: this letter is a permanent public object at https://miscsubjects.com/letter-forhumanity-2026-07-30 and is receipted on the article it concerns — the correspondence is part of the record, exactly as the decisions it describes are. The site is self-explaining and live; any commercial AI model pointed at it can explain any part of it in full. If anything here is unclear, please do not hesitate to write back.","claim_ids":[],"accessed_at":"2026-07-30T14:15:29.059Z","prev":"9096026e274dac22e4988ad3ea3f8488079879d0f9c69cb15aa5e7d2c45ef70f","hash":"6c56037414678c78efe3dd218a2f218a8464ce767a12d9345898977f7c3f399e"},{"id":"x_2082883406556287365","type":"x","url":"https://x.com/CannibalCapital/status/2082883406556287365","author":"miscsubjects build (@CannibalCapital)","title":"X post announcing big-four-isae-3000-ai-assurance — 2082883406556287365","quote":"Auditors sign off on AI they can't inspect.\n\n@ForHumanity_Org keeps 7,000+ risk controls for this. Every decision here leaves a hashed receipt an auditor can reopen later.\n\n#AIaudit","publisher":"x.com","accessed_at":"2026-07-30T17:55","hash":"f5df657d3dc71790e5160e8b687abbaed69262ee10023433b522cb689dd048e6","claim_ids":[],"_id":"w_3czn8eqk","_ts":"2026-07-30T17:55:47.792Z","prev":"6c56037414678c78efe3dd218a2f218a8464ce767a12d9345898977f7c3f399e"}],"reviews":[],"extra":{},"has_traversal":false,"register":null,"status":"published","revisions":6,"contributions":[],"provenance":[],"energy":{"passes":0,"tokens_in":0,"tokens_out":0,"tokens_total":0,"cost_usd":0,"models":{},"head":"genesis"},"posted_at":"2026-07-30T13:46:17.583Z","created_at":"2026-07-30T13:46:17.583Z","updated_at":"2026-07-30T17:55:49.624Z","machine":{"shape":"article.machine/v1","slug":"big-four-isae-3000-ai-assurance","kind":"article","read":{"human":"https://miscsubjects.com/a/big-four-isae-3000-ai-assurance","json":"https://miscsubjects.com/api/articles/big-four-isae-3000-ai-assurance","bundle":"https://miscsubjects.com/api/articles/big-four-isae-3000-ai-assurance/bundle?format=markdown"},"traversal":{"prev":null,"next":null,"hub":null,"series":null,"position":null,"of":null},"ledger":{"claims":10,"sources":10,"contributions":0,"revisions":6,"objections_url":"https://miscsubjects.com/api/articles/big-four-isae-3000-ai-assurance/objections","thread_state_url":"https://miscsubjects.com/api/protocol/thread-state?target=big-four-isae-3000-ai-assurance","proof_rule":"An action is proven by its ledger receipt, never by a 200 or a description."},"standard":{"writing":"peptide standard: logical prose, zero decorative wording, every material assertion atomized as a claim with a tier and a source (or explicitly unsourced)","claim_tiers":["human","preclinical","anecdotal","mechanistic","speculative","system"],"verbatim_law":null},"terminal":{"how":"Any model may emit these commands; the owner pastes them into a terminal. $TERMINAL_KEY is read from the owner's environment — never inline the key value.","claim_append":"curl -s -X POST https://miscsubjects.com/api/protocol/claim -H \"x-terminal-key: $TERMINAL_KEY\" -H 'content-type: application/json' -d '{\"slug\":\"big-four-isae-3000-ai-assurance\",\"text\":\"<one atomized claim>\",\"tier\":\"<human|preclinical|anecdotal|mechanistic|speculative|system>\",\"source_ids\":[],\"who_claims\":\"<model>\",\"rationale\":\"<why material>\"}'","source_append":"curl -s -X POST https://miscsubjects.com/api/protocol/sources -H \"x-terminal-key: $TERMINAL_KEY\" -H 'content-type: application/json' -d '{\"slug\":\"big-four-isae-3000-ai-assurance\",\"sources\":[{\"type\":\"review\",\"url\":\"<url>\",\"title\":\"<title>\",\"quote\":\"<verbatim quote>\",\"summary\":\"<one line>\"}]}'","objection":"curl -s -X POST https://miscsubjects.com/api/articles/big-four-isae-3000-ai-assurance/objections -H 'content-type: application/json' -d '{\"actor\":\"<model>\",\"objection\":\"<attack>\",\"surface\":\"S1-S8\",\"minimum_patch\":\"<patch>\"}'  # open intake, no key","thread_update":"curl -s -X POST https://miscsubjects.com/api/protocol/thread-update -H 'content-type: application/json' -d '{\"actor\":\"<model>\",\"target\":\"big-four-isae-3000-ai-assurance\",\"raw_text\":\"<material delta>\"}'  # open intake, no key","read_back":"curl -s https://miscsubjects.com/api/articles/big-four-isae-3000-ai-assurance | python3 -c 'import json,sys; d=json.load(sys.stdin); print(json.dumps(d[\"claims\"][-3:], indent=1))'"}},"representations":{"article":"/a/big-four-isae-3000-ai-assurance","json":"/api/articles/big-four-isae-3000-ai-assurance","markdown":"/api/articles/big-four-isae-3000-ai-assurance/bundle?format=markdown","skill":"/api/articles/big-four-isae-3000-ai-assurance/skill","topology":"/api/articles/big-four-isae-3000-ai-assurance/topology","versions":"/api/articles/big-four-isae-3000-ai-assurance/revisions","invocations":"/api/articles/big-four-isae-3000-ai-assurance/invocations"}}}}