Execution Coverage Reconciliation: measuring the ungoverned surface when absence of bypass cannot be proved from inside
Abstract
A governance gate that commits a hash-chained receipt in the same transaction as its determination binds determination to evidence, but binds nothing to effect: the transition occurring in the world is a separate event on a separate system the governing runtime cannot observe. Absence of bypass therefore cannot be established from inside the governed path. This note proposes measuring the ungoverned surface instead of proving its absence. It sets out a bidirectional residual (G, E, M, Ue, Ug), three requirements — UNKNOWN as the initial rather than exception state, a closed classification vocabulary for Ug with UNCLASSIFIED preserved, and cross-window carry-forward bound into the reconciliation artifact — and a staged adoption path in which each stage is separately adoptable. Coverage is not attribution. Neither author has implemented the full model; this is a specification arrived at by argument, not a report of a running system. Section 13 records the corrections made between v0.1 and v0.2, including one that was wrong rather than merely improved.
// Source
Authors: Ishaan Ghosh, Tim Zlomke