Sovereign Relational Architecture · Model boundary
SRA Modeled-vs-Real Manifest
This inventory describes learning model 2026-09-12.1, developed alongside the September 12 working draft. The linked public preprint is a separate earlier release.
INTERACTIVE REFERENCE MODEL — SYNTHETIC FIXTURES ONLY. The artifact demonstrates mechanism and decision shape; it does not host, enforce, or protect real resources. All fixtures are synthetic, and no real protected information may be entered.
Signatures, identity and custody
Demonstrated for real
Warrant signing and gate verification. The page generates an ephemeral Web Crypto keypair, canonicalizes the immutable outward warrant payload, signs it, and verifies the signature against the known public key during gate step 4. The displayed prefix is
ed25519:orecdsa-p256:according to the algorithm actually used.JSON canonicalization. A faithful RFC 8785/JCS subset sorts object keys, preserves array order, rejects non-JSON values and invalid Unicode scalar sequences, and uses ECMAScript number serialization before signing and verification.
CSPRNG identifiers. Warrant, determination, gate-decision, contest, capability, public-statement, restricted-note, translation, issuer, profile, evidence, and resource identifiers use
crypto.getRandomValues; no public and hidden sequence is shared.
Modeled and labeled
Key custody. UI label: “Keys are generated in-page and ephemeral, demonstrating the signature/verification mechanism. Production requires key custody in an HSM/KMS under community control.”
Governance legitimacy. UI label: “A signature proves who signed bytes; it does not prove that the governance process was legitimate or that the claims are true.”
Principal authentication. Gate label: “Assume authenticated principal synthetic-principal. No identity provider is contacted, and authentication is not standing.”
Beyond this model
HSM/KMS custody, key rotation, and compromise runbooks. A public static page cannot provide community-controlled hardware custody, durable issuer operations, or incident response.
Authentication of governing authorities. The browser has no authoritative identity provider or community governance trust root. Signing a fixture cannot establish standing.
OIDC, institutional identity federation, and standing adjudication. Authentication can identify a principal; it cannot independently confer warrant-issuing authority.
Assessments and contested decisions
Demonstrated for real
DVA issuance without a computed verdict. The condition worksheet displays considerations without numbers or weights. Each proposed operation remains
PENDING_GOVERNANCEuntil governance enters its determination; no aggregate verdict is recorded. The browser validates proposal scope, configured profile/signing authority, issuance attestation, safe boundary/evidence rows, disclosure posture, supersession path and operation dependencies. Connected lessons derive only a permitted outward warrant from a signed authored determination. It never chooses a viability outcome; interpretive comparisons are labeled authored analyses.Operation-scoped contest behavior. A signed
ContestedDesignationcontains opaque identifiers, scope, interim rule, process reference, activation and review times, and state sequence. Other gate checks still run. Irreversible disputed disclosure fails closed; an uncontested storage operation may continue. Passingreview_afterrequires re-attestation and never becomes consent. Resolution requires a different, newly signed warrant and configured process scope. Closure by withdrawal is distinct from authorization to resume; future activation is not treated as a presently effective contest.
Modeled and labeled
Synthetic governance entry. UI label: “A governance determination has been entered under the synthetic profile's issuance rule.”
Recognized process. The fixture uses the synthetic governance profile as the recognized process boundary. An unverified outsider assertion is ignored and cannot freeze a resource.
Beyond this model
A real DVA convening process. The browser cannot determine who has standing, whose witnessing is required, how dissent is carried, or what must remain unnamed under community law.
Governance adjudication. The model protects the interval but cannot decide which witnessing is faithful, resolve disagreement, or make a captured process legitimate.
Recording, non-recording and refusal
Demonstrated for real
Distinct object stores.
DvaDetermination,GateDecision,ContestedDesignation,PublicRefusalStatement, andRestrictedGovernanceNoteoccupy separate in-memory structures. A gate denial and a non-viability determination write no refusal statement.NDE non-recording at the shared registry boundary. The NDE lesson creates no resource-specific shared handle, counter, object, registry entry or placeholder. A separately chosen internal continuity note stays in a distinct fictional community-held store; observer views are not access controls. The two external-query fixtures return identical status, body, headers, and byte length.
Deliberate refusal authorship. Public and restricted records require an explicit type, governance-authored text, profile scope, attestation, real signature, CSPRNG identifier, and idempotency key. No prose is generated from gate diagnostics, and an absent or invalid disclosure posture creates no record.
Modeled and labeled
Store separation. UI label: “This separate browser-memory structure demonstrates separation only. It is not access control or secure storage.”
NDE response shape only. UI label: “In a real deployment, equivalence across timing, caching, rate-limiting, logs, and backups must be measured under adversarial testing; it cannot be inferred from code. This model demonstrates the response shape only.”
Restricted visibility. The model labels the restricted store as an in-memory structural demonstration, not an externally enforced audience boundary.
Beyond this model
Separated production databases, service accounts, keys, and backups. In-memory maps demonstrate type and write-path separation, not operational isolation or authorization.
Statistical NDE timing-equivalence testing. Meaningful evidence requires a production-like service, caches, load balancers, logs, backups, rate limits, traffic generation, and adversarial measurement.
Secure restricted discovery and authorization. A public browser cannot provide partner authentication, authorization, compartmented queries, or durable retention controls.
Receiver compatibility
Demonstrated for real
Constraint-preserving receiver compatibility. Typed rules cover permissions, prohibitions, affirmative obligations, temporal conditions, audience boundaries, derivative rules, and retention/deletion. Exact preservation returns
COMPATIBLE; an exact signed translation bound to the configured originating process, warrant, policy version, hashes and validity interval can returnAUTHORIZED_TRANSLATION; unilateral weakening or tightening returnsINCOMPATIBLE; unknown terms returnINDETERMINATE.INDETERMINATEnever releases. A separate applicability check evaluates supported time, audience, permission/prohibition, derivative and retention rules for the request; matching declarations alone do not authorize it.
Modeled and labeled
Receiver declaration. The receiver profile is a synthetic declaration of accepted policy and supported obligations. A passing browser check does not show that an institution will obey after receiving plaintext.
Beyond this model
Receiver federation and attestation. The static model cannot establish institutional trust, inspect remote configuration, compel legal compliance, or prevent screenshots, copying, exfiltration, and bad-faith reuse.
Gates, obligations and one-time permissions
Demonstrated for real
Fail-closed gate order. The gate performs the twelve ordered checks: principal stub; opaque handle; supplied warrant state; real signature and trusted issuer; warrant state; operation-scoped contest; exact scope; receiver compatibility; community consult stub; obligations; capability; synthetic reveal. Unknown policy, malformed dates, stale revocation, unsupported obligations, and indeterminate compatibility deny.
Affirmative-obligation checks. Known obligation types are validated against receiver support. A due obligation must carry opaque evidence; a past-due obligation without evidence denies.
Capability lifecycle and scope. The model mints a real signed, short-lived capability only after the preceding checks pass. Consumption verifies signature, issuance and expiry, exact resource/action/audience/workflow/purpose, governing warrant/policy/profile binding, supplied current authorization state and an in-memory single-use set. Grant lifetime is capped to applicable authorization limits. The explicit simulation clock and current display distinguish ready, consumed and expired from a historical evaluation. Reuse has no second side effect. Only then is a synthetic payload revealed.
Modeled and labeled
Community-decision-service consult. A required synthetic decision is bound to action, resource, service, warrant/profile and validity interval. ALLOW, WITHHOLD and UNAVAILABLE remain distinct internal meanings. Remainder alone does not imply a synchronous service call; the authored determination states when one is required. No real service is contacted.
Evidence meaning. Opaque fixture references demonstrate the field and due-date rule, not the truth, sufficiency, or community acceptance of evidence.
Transport boundary. UI label: “Sender-constraining (mTLS/DPoP) and atomic key release require a real service; this model demonstrates the token lifecycle and scope-checking.”
Beyond this model
A real community decision service. Protected context, availability, authenticated requests, revocation, and community-controlled operations require a service outside the static page.
Audit and evidence verification. The browser has no trusted evidence store, reviewer process, or durable audit trail.
mTLS/DPoP, replay-resistant distributed consumption, and atomic key release. These require a sender, receiver, network protocol, durable atomic state, and protected key material.
Browser boundaries and accessibility
Demonstrated for real
Strict browser-side schemas and safer rendering. Unknown fields and enums fail closed in the decision model. User-entered text is rendered with DOM text nodes, not HTML parsing. The SRA routes use an external-script/external-style Content Security Policy without
unsafe-inline.No sensitive form persistence. Proposal and authorship drafts remain in memory, are never written to URLs or
localStorage, and are reset on page exit.
Modeled and labeled
Browser accessibility checks. Native controls, associated labels and fieldsets, keyboard navigation, visible focus, concise live status, reduced-motion handling, narrow-width reflow, a glossary and readable/printable lesson transcripts support access. Learner effectiveness and full assistive-technology conformance are not established by these mechanisms.
Status-banner preference. A session-only collapsed/expanded preference contains no form or protected state.
Beyond this model
Production security and full assistive-technology certification. A static review cannot substitute for independent penetration testing, multiple browser/AT combinations, organizational accessibility testing, or ongoing regression monitoring.
Storage of real protected data. Explicitly prohibited. This model is not a repository, record system, or secure processing environment.
Boundary statement
Narrative Summary
What the model now establishes is narrower and more useful than a claim of production readiness. It establishes that SRA's distinctions can be represented coherently: governance enters DVA outcomes rather than receiving them from arithmetic; warrants transmit bounded determinations without carrying protected standing; receiver compatibility prohibits unauthorized weakening and tightening; contests govern an operation without validating unrelated checks; NDE acts before shared recording; gate denial does not publish; and capability release occurs only after exact, ordered checks.
What remains outside the artifact is not a deployment backlog disguised as a feature list. It is the infrastructure and governance boundary the browser cannot honestly cross: real authority authentication, community-controlled key custody, protected decision services, isolated stores and backups, sender-constrained transport, receiver federation, deletion enforcement, adversarial NDE testing, and any handling of real protected information.
Canonical source: MODEL_MANIFEST.md