03 / proof

Governance receipts

Evidence survives the action.

Aetheria preserves why an effect was proposed, who held authority, what Gateway decided, what the rail reported, and what recovery followed.

Governance receiptObserved
Proposal
records.release.request
Actor
records.supervisor
Purpose
approved.publication
Authority
delegation.active
Policy decision
admit.scoped
Registered rail
records.publish
Dispatch
accepted
Effect state
observed
Recovery
available

Normalized evidence object

A decision record that extends through execution.

A governance receipt is more than an activity log. It binds the proposal and authority decision to the registered rail, dispatch state, observed outcome, and available recovery.

  1. 01
    Proposal identity
    The exact requested effect and its typed inputs remain bound to the record.
  2. 02
    Authority resolution
    The actor, delegation, purpose, scope, policy, and target establish why the decision was valid.
  3. 03
    Boundary decision
    Gateway records admission, denial, or deferment before any rail dispatch.
  4. 04
    Effect state
    Dispatch, observed success, failure, or unknown outcome remain separate facts.
  5. 05
    Recovery continuity
    Reconciliation, rollback, revocation, and corrective action link back to the originating decision.

Explicit outcomes

No synthetic certainty.

Each result carries different operational meaning and a different next control.

Observed

Effect confirmed

The rail reports the bounded result and the receipt binds it to the originating authority.

Denied

No dispatch

The boundary prevents execution and preserves the failed authority or policy condition.

Failed

Rail failure

The action was authorized, but the registered rail reports failure and exposes recovery.

Unknown

Reconcile first

Dispatch exists without confirmed effect. The system preserves uncertainty and opens reconciliation.

Unknown-state recovery

Uncertainty becomes governed work.

A timeout or broken connection does not prove that an external effect failed. Aetheria preserves the dispatch, blocks conflicting follow-on action, and drives reconciliation.

  1. 01Preserve the dispatch

    Keep the exact rail request and correlation evidence intact.

  2. 02Mark the effect unknown

    Prevent success language and dependent execution.

  3. 03Reconcile the external state

    Query the authoritative system or route the case to a responsible operator.

  4. 04Bind the resolution

    Attach the confirmed effect, corrective action, or recovery to the original receipt.

Independent assurance

StilleNacht tests the exact target.

StilleNacht remains outside Aetheria's installed execution authority. It evaluates the named build, environment, workflow, policy, and evidence boundary without converting internal test volume into a universal certification claim.

Target

Exact release

Assurance attaches to the build and configuration actually evaluated.

Method

Falsifiable controls

Denial, failure, unknown state, recovery, and boundary violations remain testable.

Boundary

Evidence, not theater

The record states what was proven and preserves what remains outside that proof.

Consequential action requires accountable authority.

Put a governed boundary between intent and effect.