# Public Claims Audit

**Audit date:** 25 July 2026
**Artefact:** Living Stewardship Prototype
**Scope:** current worktree after the counter-reading slice
**Rule:** demonstrated fact, approved decision, working hypothesis, proposed
work and imaginative material remain distinct.

This audit supersedes the implementation-status findings in the historical
Day One receipt. It does not erase that earlier record.

## Current claims register

| Claim | Status | Repository evidence | Public limit |
|---|---|---|---|
| The baseline requires an explicit initial choice | Demonstrated | Disabled continuation and gate tests | Two authored scenarios |
| Each choice displays a different prewritten state | Demonstrated | Branch data and divergence tests | Text difference, not participant validation |
| Baseline receipts reconstruct the authored state | Demonstrated | Replay functions and tests | Not a signed or immutable event history |
| A browser model path generates a counter-reading through WebGPU | Demonstrated in a supported browser | Pinned runtime, generated output, model provenance, model module and request guard | Hardware, first asset load and output validation can force fallback |
| Unsupported or rejected generation is labelled scripted | Demonstrated in code and tests | Fallback provenance and interface copy | Scripted encounters are not model evidence |
| An overrule requires at least 40 written characters | Demonstrated | Pure validator, UI gate and tests | Length does not establish reason quality |
| Research receipts preserve generator provenance | Demonstrated | Schema builder and tests | Provenance does not validate output quality |
| Model assets are requested from one declared origin without participant-data bodies | Demonstrated in source and boundary tests | Request guard and technical note | Browser cache eviction can require another download |
| Offline key access creates no holder identity | Demonstrated in source and tests | Hash comparison, clearing and receipt checks | Public key proves mechanism, not secrecy |
| Overrule rate may describe deference behaviour | Proposed measure | Research plan and preregistration | No result or validated interpretation |
| Required friction may reduce excessive deference | Working hypothesis | Research question only | No participant or human-outcome evidence |
| The wider consequence infrastructure is not operational here | Demonstrated repository boundary | Source and documents | Says nothing about work outside this repository |

## Generator provenance rule

A completed counter-reading receipt is permitted only when provenance is one
of:

- `local-model` with model name, pinned version, runtime and `webgpu` device;
- `scripted-fallback` with null model fields, script name, script version and
  fallback reason.

The interface must use **Generated locally** only for the first form and
**Scripted fallback** for the second. Tests reject incomplete provenance.

## Network claim

The deterministic baseline contains no request API. The counter-reading model
module declares one remote origin and permits only `GET` or `HEAD` requests
under the pinned model path with no body. Same-origin scripts and runtime files
are relative and vendored. No analytics or telemetry mechanism is present.

## Language-order finding

Current public documents describe code behaviour before project terminology:

- requiring a choice before continuation precedes **ritual friction**;
- locally verifying a key without identity precedes **custodianship**;
- “materially different consequences” is not used as a current technical
  claim; the repository says **different prewritten states**.

Historical receipts retain their original language as evidence of chronology.

## Claims rejected or qualified

The current repository rejects affirmative claims about:

- flow detection or a working Flow-State Algorithm;
- physiological or cognitive measurement;
- validated autonomy effects or participant outcomes;
- connected wearables or hidden influence;
- a validated overrule measure;
- model-output quality;
- a physical edition currently available;
- an operational full Paradox Engine.

## Third-party boundary

No person, prospective partner, institution or endorsement is named. Exact
runtime and model identifiers appear only where required for technical
reproducibility and receipt provenance.

## Approval result

The code and research documents are candidate material pending Patrick's
approval. No participant study, public deployment or human-outcome claim is
approved by this audit.
