# Conduct Ecosystem Decision Register

## Decision classes

| Class | Meaning |
|---|---|
| CONSTITUTIONAL | A purpose, right, protection, prohibition, or accountability boundary that the system may not optimize away. Evidence may strengthen it; weakening requires extraordinary review and may change the identity of the project. |
| REQUIRED FOR COHERENCE | A semantic, scope, provenance, lifecycle, or architectural rule necessary for the current system to be internally understandable and reproducible. It may change only through an explicit redesign that reconciles all dependencies. |
| CANDIDATE | A lead empirical, mathematical, product, operating, economic, partner, interface, or narrative choice. It must remain replaceable by evidence. |
| DEFERRED | A capability or choice intentionally outside the current stage. Dependent implementation is blocked unless a later gate explicitly reopens it. |
| REJECTED | A considered alternative that is not part of the active design. The rationale is retained so it is not reintroduced casually. |

These classes replace the earlier LOCKED/PROVISIONAL binary. A decision can be important and still be a candidate; detail and founder preference do not convert a hypothesis into a constitutional rule.

| ID | Decision | Status | Rationale | Revisit trigger |
|---|---|---|---|---|
| D-001 | Initial implementation focuses on consumer-to-business interactions. | REQUIRED FOR COHERENCE | This is where verified records already exist and where the initial value is easiest to demonstrate. | Completion of consumer pilot and separate legal analysis for other relationship types. |
| D-002 | NCS and VCI remain distinct inputs to CQ. | REQUIRED FOR COHERENCE | Human experience and operational evidence answer different questions and balance different failure modes. | Evidence that either input cannot be made sufficiently reliable. |
| D-003 | Consumers may hold company-specific, approved context-specific, and research-approved overall CQ representations; overall CQ remains outside the initial live pilot and is not inevitable. | REQUIRED FOR COHERENCE | Suite L found structural support only for a bounded summary of a fixed, independently supported source set with equal context-family influence and a Context varies state. | Real context-transfer, independence, comprehension, fairness, utility, necessity, and legal evidence may narrow or reject overall CQ. |
| D-004 | CQ may support separately funded approved benefits, must preserve measured baseline parity, and must detect shadow penalties rather than claiming that relative harm is impossible. | CONSTITUTIONAL | The system is intended to reward earned conduct rather than coordinate exclusion, but proof absence and positional benefits can create practical disadvantage even without an explicit penalty. | Benefit or baseline evidence requires stronger restrictions, redesign, or stopping. |
| D-005 | Participation and disclosure are voluntary and consumer-controlled. | CONSTITUTIONAL | Consumer agency is fundamental to legitimacy, privacy, and adoption. | Jurisdiction-specific requirements may require stronger controls. |
| D-006 | OCA independently governs the shared standard. | CONSTITUTIONAL | No participating company should own cross-company conduct infrastructure. | Governance design review. |
| D-007 | The ecosystem is described as five components rather than five sequential layers. | REQUIRED FOR COHERENCE | OCA governs the full system and does not sit at the end of a data pipeline. Identity and security also cross multiple components. | Architecture review after Wave 3. |
| D-008 | CQ is primarily a consumer-controlled credential capable of generating contextual proofs. | REQUIRED FOR COHERENCE | This is more privacy-preserving and less socially corrosive than a public universal score. | Consumer research and proof-architecture validation may refine its presentation. |
| D-009 | The public product will not include a leaderboard, social comparison, daily streaks, or score-chasing notifications. | CONSTITUTIONAL | The utility should remain quiet and resist gamification or ranking people. | No planned revisit. |
| D-010 | The synthesis component remains functionally named and unbranded during system design. | DEFERRED | “Sovereign Conduct Protocol” currently mixes architecture, privacy claims, and branding. | Technical architecture and brand architecture are stable. |
| D-011 | Mathematical formulas in the source brief are treated as hypotheses, not approved requirements. | CONSTITUTIONAL | The existing NPS, Z-score, Bayesian, threshold, and decay models have not yet been reconciled or validated. | Simulation, fairness testing, and independent data-science review. |
| D-012 | VCI will not treat self-service or avoidance of human assistance as inherently positive. | CONSTITUTIONAL | That rule could penalize disability, accessibility needs, language differences, and complex legitimate cases. | Equity review and evidence supporting a narrowly defined operational-efficiency event. |
| D-013 | “Verified interaction” is broader than “financial transaction.” | REQUIRED FOR COHERENCE | Legitimate service interactions may occur before payment, after payment, under a corporate payer, or without a direct charge. | Identity and event-schema design. |
| D-014 | Newsletter and website production may proceed only from the current specification baseline; the v0.4 public materials are paused until their Phase 4–5 migration to v0.5 is complete. | REQUIRED FOR COHERENCE | Public promises must follow approved system behavior and safeguards, and the one-score product decision materially changes the public explanation and interfaces. | Complete the v0.5 narrative and website migrations, contradiction audit, and publication review. |
| D-015 | The lead NCS prompt is “Based only on how this customer interacted with you and others, would you want to serve them again?” | CANDIDATE | The prompt preserves the original NPS-like repeat-willingness vision while anchoring the preference to the customer's human conduct rather than commercial value or service outcome. | Cognitive interviews, vignette tests, localization, or pilot evidence shows systematic misunderstanding, prohibited-factor contamination, or bias that cannot be mitigated. |
| D-016 | NCS uses four scored responses with no neutral option, plus a separate unscored “Not enough interaction to say” action. | CANDIDATE | The four choices preserve positive or negative direction and degree of conviction; the abstention prevents workers from manufacturing a judgment when they lack enough interaction. | Prompt, eligibility, missingness, and scale testing. |
| D-017 | The lead NCS scoring model assigns +10, +3, -3, and -10 to Definitely yes, Probably yes, Probably not, and Definitely not, then rescales the weighted mean to -100 to +100. | CANDIDATE | Every scored answer should preserve its direction while definite responses carry materially more conviction than probable responses. Whole-number response points are easier to explain than fractional weights, and 10:3 avoids false precision. | Simulation, psychometric research, fairness testing, or pilot evidence favors a conviction-net, direction-net, or different graduated model. |
| D-018 | NCS is bound to a verified interaction and submitted only by a direct participant. | REQUIRED FOR COHERENCE | This prevents hearsay, reputation scoring, and unauthenticated ratings. | Event-eligibility review. |
| D-019 | Multiple responses from one interaction have capped aggregate weight. | REQUIRED FOR COHERENCE | A single service event should not dominate because many employees participated. | Simulation and pilot testing. |
| D-020 | Requiring a structured reason only for “Definitely not” is not part of the active design. Both negative choices require an approved structured conduct category under D-269. | REJECTED | Repeated “Probably not” responses can materially affect NCS while evading eligibility review, bias analysis, and meaningful challenge. | Reopen only if research shows a safer review mechanism and the asymmetric friction does not distort response selection. |
| D-021 | Businesses must use census or certified random sampling for eligible NCS interactions. | CANDIDATE | Selective prompting could produce larger distortions than the scoring formula. | Pilot operational testing. |
| D-022 | Employees cannot see prior consumer conduct information before submitting NCS. | CONSTITUTIONAL | Prior scores would create anchoring, confirmation bias, and retaliation risk. | No planned revisit. |
| D-023 | NCS does not independently apply time decay or cross-context weights. | REQUIRED FOR COHERENCE | Those rules belong in synthesis and should not be applied twice. | Evidence that component-specific decay is required for an approved model. |
| D-024 | New participants show insufficient history rather than beginning with a visible zero or seeded score. | CONSTITUTIONAL | An invented baseline could be mistaken for established personal evidence and high elasticity would overstate a few early interactions. | No planned revisit. |
| D-025 | “Verified” in VCI means verified provenance, attribution, evidence, and lifecycle—not automatic objective truth. | REQUIRED FOR COHERENCE | Enterprise data can be incomplete, disputed, biased, or wrong even when its source is authentic. | No planned revisit. |
| D-026 | Every VCI event must connect to a specific legitimate responsibility that was plainly and accessibly disclosed, reasonably connected and proportionate to the interaction, consistent with applicable rights, realistically fulfillable, and within the consumer's reasonable control. | CONSTITUTIONAL | Verification of compliance cannot turn an unfair, inaccessible, unnecessary, or one-sided business rule into evidence of personal conduct. | Event-taxonomy, consumer, accessibility, legal, and industry review may strengthen or narrow the standard. |
| D-027 | Missing, incomplete, or insufficient operational data is unknown rather than negative conduct. | CONSTITUTIONAL | Data availability varies by company, context, technology, and consumer access. | No planned revisit. |
| D-028 | Pending, disputed, or unverified adverse assertions have no negative effect while unresolved. | CONSTITUTIONAL | Consumers cannot be penalized before attribution, evidence, causation, and process requirements are satisfied. | Governance review may define emergency exceptions outside CQ. |
| D-029 | Exercising a permitted or lawful option is not adverse conduct merely because it creates business cost or friction. | CONSTITUTIONAL | Returns, complaints, cancellations, accommodations, and disputes must not become prohibited commercial proxies. | Context-specific legal review. |
| D-030 | VCI provides synthesis with a structured evidence profile in addition to any numerical index. | REQUIRED FOR COHERENCE | One number cannot express evidence quality, context, concentration, disputes, or missingness. | Technical interface review. |
| D-031 | Repeated routine fulfillment will have capped or diminishing influence. | CANDIDATE | Transaction volume cannot become a purchasable conduct advantage or proxy for wealth and loyalty. | Simulation and pilot testing. |
| D-032 | The initial raw VCI candidate is a weighted fulfilled-responsibility ratio on a 0–100 scale. | CANDIDATE | It is understandable enough to test but may hide materiality, patterns, and uncertainty. | Simulation, fairness testing, and independent data-science review. |
| D-033 | A chargeback or payment-network ruling does not by itself establish fraud or misconduct. | CONSTITUTIONAL | Payment outcomes may be procedural, contractual, or based on evidentiary rules different from conduct standards. | Event-specific evidence review. |
| D-034 | Business-caused and approved external-cause events must neutralize or reverse related adverse VCI assertions. | CONSTITUTIONAL | Consumers should not absorb operational failures outside their reasonable control. | Industry-profile development. |
| D-035 | One consumer-facing CQ may be produced only after NCS- and VCI-derived inputs independently clear their gates; the inputs remain separately inspectable beneath it. | REQUIRED FOR COHERENCE | Suite K restored the simple quotient while retaining Suite C's warning that unconstrained combination can hide component weakness. | Human and field evidence must show that the combined surface remains valid, comprehensible, fair, stable, and challengeable. |
| D-036 | Every synthesis result includes context, confidence, coverage, evidence window, and calculation version. | REQUIRED FOR COHERENCE | A conduct result is misleading without its scope and evidentiary limits. | No planned revisit. |
| D-037 | Missing synthesis inputs reduce confidence or produce insufficient history rather than lowering conduct standing. | CONSTITUTIONAL | Data scarcity is not misconduct. | No planned revisit. |
| D-038 | Context transfer is zero by default unless OCA approves a relevance mapping. | CONSTITUTIONAL | Portability must not become unrestricted cross-context behavioral scoring. | Context-taxonomy validation. |
| D-039 | Company-, approved context-, and overall CQ are distinct scoped products; every result names its scope and one cannot masquerade as another. | REQUIRED FOR COHERENCE | Suite L preserves local recovery and context-specific meaning while allowing only a bounded, separately gated overall summary. | Consumer-experience, context-validity, fairness, source-set, necessity, and legal review. |
| D-040 | Recency reduces evidentiary weight and confidence but does not automatically lower a dormant consumer's conduct standing. | CONSTITUTIONAL | Inactivity should not be punished or create pressure to transact. | Simulation and pilot validation. |
| D-041 | Rapid negative clusters create a review state, not a safety determination or hidden blacklist. | CONSTITUTIONAL | CQ is a benefit system and cannot substitute for lawful safety processes. | Governance and benefit-policy review. |
| D-042 | Evidence from one interaction, issuer, corporate family, platform, or incident is clustered or capped for portable CQ. | CONSTITUTIONAL | Correlated volume is not independent corroboration. | Model validation may refine the exact controls. |
| D-043 | K3 capped arithmetic is the provisional one-scope synthesis lead; K6, the two-dimensional explanation, and proof-only output remain controls. | CANDIDATE | Suite K found that K3 alone imposed a clear ten-internal-point research cap while retaining useful synthetic signal and all hard-gate protections. | Real-data replay, cap sensitivity, comprehension, fairness, stability, and independent methodological review. |
| D-044 | Confidence-weighted combination is superseded; confidence operates as a gate or availability state and does not directly move otherwise unchanged standing. | REJECTED | Suite K's confidence-shrunk K7 proxy changed standing 211,151 times under confidence-only movement. Validity and sufficiency cannot be repaired or converted into standing through weighting. | Reopen only if a materially different method proves that confidence affects uncertainty without changing personal standing or compensating for failed gates. |
| D-045 | Material synthesis rule changes require shadow testing, impact analysis, version control, and consumer notice when results change. | CONSTITUTIONAL | A shared standard cannot change invisibly or let businesses select favorable versions. | Governance implementation review. |
| D-046 | CQ is implemented as a private consumer view, a portable contextual credential, and purpose-bound proofs. | REQUIRED FOR COHERENCE | Separating these artifacts gives consumers understanding while minimizing business disclosure. | Technical architecture may change storage without changing the product model. |
| D-047 | Businesses ordinarily receive benefit eligibility rather than a raw CQ value or event history. | CONSTITUTIONAL | A verifier needs the answer required to grant a benefit, not a portable behavioral dossier. | A narrowly approved use demonstrates a legitimate need for greater disclosure. |
| D-048 | Proof requests disclose verifier, purpose, context, benefit, baseline alternative, received data, validity, and retention before consent. | REQUIRED FOR COHERENCE | Consumer control is not meaningful without a standardized, understandable request. | UX testing may refine presentation. |
| D-049 | Ordinary proofs do not reveal contributing companies; eligible source inclusion is a private consumer choice, while named-company disclosure is outside the initial verifier profile. | CONSTITUTIONAL | Portability can work without exposing sensitive company relationships, and verifier requests can coerce an apparently voluntary named disclosure. | Any later consumer-initiated named disclosure requires a separate high-risk profile. |
| D-050 | CQ benefit policies, not businesses acting alone, define the evidence and threshold a verifier may request. | CONSTITUTIONAL | This minimizes disclosure and prevents businesses from inventing incompatible or excessive interpretations. | OCA governance design. |
| D-051 | Sending “No eligible conduct proof presented” as a retained verifier result is not part of the active design. Under D-293, only an authorized eligible proof creates a CQ-specific verifier record. | REJECTED | Collapsing absence reasons still leaves one observable negative-looking category that can become the shadow score. | Reopen only if a design proves equivalent or stronger noninference and baseline protection. |
| D-052 | Every participating business documents and preserves a reasonable baseline service independent of CQ. | CONSTITUTIONAL | A company could otherwise manufacture friction and sell its removal as an upside-only benefit. | Benefit and enforcement design. |
| D-053 | Completed benefits cannot be retroactively clawed back because CQ later changes. | CONSTITUTIONAL | Consumers must be able to rely on a granted benefit and later evidence should not rewrite completed transactions. | Fraud in proof presentation may require a narrowly defined exception. |
| D-054 | Active benefits generally continue through the promised interaction or term, with narrow security and proof-fraud exceptions. | CANDIDATE | Immediate loss can make CQ punitive and undermine appeal rights. | Benefit-specific legal and economic review. |
| D-055 | Refusal to share CQ, insufficient history, nonparticipation, or withdrawal returns the person to baseline service without a negative marker. | CONSTITUTIONAL | Participation and presentation must remain genuinely voluntary. | No planned revisit. |
| D-056 | The system launches no public profile, search, ranking, or default social-sharing feature. | CONSTITUTIONAL | Public reputation infrastructure would materially change the system's purpose and risk. | No planned revisit. |
| D-057 | The lead consumer presentation is one contextual CQ on a working `1.00–5.00` scale with two decimal places; the original 0–1000 scale is rejected. | CANDIDATE | The product contract restores immediate Uber-like legibility while Suites K and L show that mapping, population distribution, hundredths, and persistence remain empirical. | Human scale comprehension, empirical calibration, real-data replay, change-anxiety research, and accessibility testing. |
| D-058 | The system supports non-smartphone, assisted, delegated, and accessible participation. | CONSTITUTIONAL | Digital access and ability must not determine eligibility for a conduct benefit. | Identity and accessibility architecture. |
| D-059 | CQ data and proofs may not be sold, brokered, used for unrelated profiling, or used to train prohibited decision systems. | CONSTITUTIONAL | Purpose limitation must cover derived uses as well as direct disclosure. | Jurisdiction-specific strengthening may be required. |
| D-060 | L4 contradiction-aware capped synthesis is the provisional overall-CQ research architecture; overall CQ remains outside the initial live pilot and may still be rejected. | CANDIDATE | Suite L supports only a fixed approved source set with at least two independent context families, equal family influence, weakest-context cap, and Context varies state. | Real context mappings, source-set validation, comprehension, fairness, necessity, proportionality, and legal viability. |
| D-061 | Identity proofing, authentication, interaction attribution, holder binding, and proof authorization are separate system functions. | REQUIRED FOR COHERENCE | A device unlock or identity check cannot answer all five questions. | No planned revisit. |
| D-062 | The ecosystem exposes no universal public consumer identifier across businesses. | CONSTITUTIONAL | A reusable network identifier would enable correlation and surveillance beyond the declared purpose. | No planned revisit. |
| D-063 | Businesses receive pairwise or context-specific pseudonymous identifiers where persistent identification is necessary. | CANDIDATE | Relationship-specific identifiers support continuity without routine cross-business tracking. | Implementation testing may refine identifier derivation. |
| D-064 | Biometrics may activate a local authenticator but are not treated as proof of global uniqueness or routinely transmitted to CQ services. | CONSTITUTIONAL | Device biometrics answer a narrower authentication question and centralized templates create disproportionate risk. | A narrowly approved high-assurance workflow requires separate analysis. |
| D-065 | A central biometric-template database for ordinary CQ participation is rejected. | REJECTED | Duplicate resistance does not justify concentrating uniquely sensitive biometric data. | No planned revisit. |
| D-066 | Requiring a public blockchain or distributed ledger for the architecture is rejected. | REJECTED | Cryptographic verification does not require publishing personal or correlatable data to a ledger. | A later implementation may justify a privacy-preserving infrastructure component through formal review. |
| D-067 | Recovery restores the same conduct identity and does not reset valid history. | REQUIRED FOR COHERENCE | Device loss and authenticator failure must not become a way to escape or lose a conduct record. | No planned revisit. |
| D-068 | Consumers can register multiple authenticators and recovery paths. | CANDIDATE | Resilient access should rely less on high-risk emergency recovery. | Assurance-profile design. |
| D-069 | Raw operational and identity-proofing evidence remains with its responsible custodian by default. | CANDIDATE | Functional separation and minimization reduce breach impact and unnecessary centralization. | A shared function demonstrates a documented necessity. |
| D-070 | Credential status checking must resist issuer monitoring and cross-verifier correlation. | CONSTITUTIONAL | A status callback can reveal where and when a person presents CQ. | Status-method selection and privacy testing. |
| D-071 | The ecosystem aligns with open credential and identity standards but does not lock into one wallet, DID method, platform, or cryptographic format. | REQUIRED FOR COHERENCE | Interoperability and cryptographic agility require a replaceable implementation profile. | Pilot profile selection. |
| D-072 | The system makes no absolute claim of one globally unique identity per natural person. | REQUIRED FOR COHERENCE | Global uniqueness without invasive infrastructure is not realistically guaranteed; risk-based duplicate resistance is the appropriate goal. | No planned revisit. |
| D-073 | CQ is not transferable through delegation, sale, inheritance, or account recovery. | CONSTITUTIONAL | Authority to act for a person is different from ownership of that person's conduct history. | Guardianship and incapacity rules may refine access without transferring CQ. |
| D-074 | Sensitive CQ access and proof presentation use phishing-resistant cryptographic authentication where feasible. | CANDIDATE | Conduct history and reusable credentials require stronger protection than password-only access. | Risk-based assurance profiles may permit narrower alternatives. |
| D-075 | Assurance strength is proportional to the workflow and benefit risk rather than fixed at a maximum level for all users. | CONSTITUTIONAL | Excessive proofing and authentication create exclusion and privacy harm without equal benefit. | Threat modeling and pilot evidence. |
| D-076 | Consumers receive one unified “Something doesn't look right” challenge path across events, CQ views, proofs, and benefits. | REQUIRED FOR COHERENCE | The consumer should not need to understand system ownership or dispute taxonomy before raising a concern. | UX testing may refine wording and routing. |
| D-077 | NCS review evaluates attribution, eligibility, retaliation, prohibited reasoning, duplication, and process rather than rerating an employee's eligible subjective experience. | CONSTITUTIONAL | Human experience is subjective, but its inclusion must still be procedurally fair and governed. | Appeal and fairness testing. |
| D-078 | Challenging a CQ result triggers review of inputs, exclusions, context, confidence, calculation, version, and proof policy rather than an arbitrary score override. | REQUIRED FOR COHERENCE | CQ is a derived result and must remain reproducible. | No planned revisit. |
| D-079 | Businesses cannot manually adjust company-specific CQ outside signed source correction and governed recalculation. | CONSTITUTIONAL | Manual overrides would destroy portability, auditability, and independence. | No planned revisit. |
| D-080 | There is no routine direct dispute exchange between a consumer and the employee who submitted NCS. | CONSTITUTIONAL | Review can protect employee safety and consumer rights without creating personal confrontation. | Governance design may define exceptional investigative contact. |
| D-081 | A consumer may record disagreement without identifying a technical error; the statement is private to the consumer and authorized reviewers and does not change CQ by itself. | CANDIDATE | A low-friction voice mechanism supports trust without turning disagreement into automatic deletion or verifier stigma. | Consumer research. |
| D-082 | The unified challenge entry distinguishes “Help me understand” from “Review this.” | CANDIDATE | Consumers need explanation without unintentionally opening a dispute, and a clear path when they do want formal review. | UX testing may refine language. |
| D-083 | Automated review may correct obvious errors but cannot finally deny a material challenge. | CONSTITUTIONAL | Emotionally and materially significant decisions require accountable human judgment and redress. | Governance may define low-risk exceptions. |
| D-084 | The consumer identifies the concern; the responsible issuer or operator bears the burden of substantiating its materially adverse factual assertion or calculation. | CONSTITUTIONAL | Consumers should not have to prove a negative against data and processes controlled by institutions. | Evidence standards by event class. |
| D-085 | Employee identity and indirectly identifying detail are protected during ordinary NCS review, and managers may not script or retaliate against employee responses. | CONSTITUTIONAL | Review must protect consumer rights without creating personal confrontation or workplace coercion. | Labor and appeal-process review. |
| D-086 | Threatening or abusive review content is handled through a separate safety process without extinguishing the underlying right to safe review. | CONSTITUTIONAL | Procedural rights and participant safety must both survive emotional escalation. | Safety-process design. |
| D-087 | Systemic errors trigger collective correction and notification where possible rather than requiring separate appeals from every affected consumer. | CONSTITUTIONAL | Requiring repeated individual challenges compounds harm and hides shared causes. | OCA investigation and remediation design. |
| D-088 | Review communications describe evidence, rules, and outcomes without moral character labels. | CONSTITUTIONAL | The system evaluates eligible conduct evidence, not whether a person is good, bad, truthful, or difficult. | Language testing. |
| D-089 | A mature OCA must be an independent, mission-locked, multi-stakeholder standards and accountability institution. | CONSTITUTIONAL | Portable conduct infrastructure cannot be credibly controlled by one company, vendor, founder, funder, or government. | OCA remains a proposed future institution until the legal, governance, funding, staffing, and capacity conditions exist. |
| D-090 | No stakeholder class or founder holds a permanent unilateral veto or governing majority. | CONSTITUTIONAL | Stakeholder balance must be enforceable rather than aspirational. | Board-design review may refine thresholds without creating unilateral control. |
| D-091 | Consumers and frontline workers receive voting seats, protected participation, and participation resources. | CANDIDATE | Those most affected need actual power and practical ability to exercise it. | Representation and funding design. |
| D-092 | Standards, operations, certification, audit, enforcement, and appeals have defined separation and conflict controls. | CONSTITUTIONAL | One institution or team should not write rules, operate the system, audit itself, sanction participants, and decide appeals without checks. | Founding implementation may combine staff while preserving decision separation. |
| D-093 | OCA does not automatically operate every technical service it governs. | REQUIRED FOR COHERENCE | Structural diversity reduces self-regulation conflicts and single points of control. | Pilot operations may be temporarily housed with explicit separation and exit plan. |
| D-094 | Material standards follow public drafting, impact assessment, review, testing, comment disposition, approval, versioning, and monitoring. | CONSTITUTIONAL | Conduct rules require wider due process than private product changes. | Standards-process charter. |
| D-095 | Core consumer and worker rights require enhanced approval across stakeholder classes. | CONSTITUTIONAL | Ordinary voting should not allow commercial majorities to weaken foundational protections. | Exact supermajority and cross-class thresholds remain open. |
| D-096 | Certification applies separately to each ecosystem role and requires continuing oversight. | REQUIRED FOR COHERENCE | Technical conformance in one role does not establish fitness for identity, synthesis, verification, audit, or appeals. | Certification-profile development. |
| D-097 | “Node slashing” as the enforcement model is rejected and replaced by a conventional, proportionate, reviewable enforcement ladder. | REJECTED | Accountability needs recognizable remedies, due process, reinstatement, and regulatory referral rather than punitive protocol language. | Enforcement authority and contract design. |
| D-098 | Material consumer appeals are decided by reviewers independent of the original issuer, operator, verifier, and decision maker. | CONSTITUTIONAL | First-line correction alone does not provide credible redress. | Regional appeal-provider design. |
| D-099 | OCA adopts funding-concentration controls and separates revenue from standards, certification, enforcement, and appeals. | CONSTITUTIONAL | Formal voting independence is insufficient if one funder can threaten institutional survival. | Exact caps and reserves remain open. |
| D-100 | Emergency authority is narrow, documented, independently reviewed, and automatically time-limited. | CONSTITUTIONAL | Urgent intervention must not become permanent rulemaking without due process. | Charter sets exact duration and review period. |
| D-101 | OCA maintains public standards, registries, change logs, aggregate metrics, governance records, and proportionate enforcement reporting. | REQUIRED FOR COHERENCE | Trust requires visible performance and decision history. | Confidentiality policy may protect narrowly defined information. |
| D-102 | OCA maintains explicit antitrust and competition controls around benefits, data, meetings, certification, and participant sanctions. | CONSTITUTIONAL | A cross-company standard must not facilitate price coordination, customer allocation, or collective exclusion. | Specialist competition-law review. |
| D-103 | Core schemas, protocols, calculation specifications, conformance requirements, and rights rules are available for interoperable implementation. | CONSTITUTIONAL | A shared utility cannot depend on hidden proprietary control. | Intellectual-property policy. |
| D-104 | The consumer-affecting pilot requires an interim multi-stakeholder charter, independent review, certification agreements, appeal panel, protected reporting, audit access, and transition plan. | CANDIDATE | Pilot status does not justify informal governance when real people and benefits are affected. | Pilot design. |
| D-105 | Founding stewardship may be meaningful but cannot override standards process, consumer rights, audits, certification, or appeals. | CONSTITUTIONAL | The idea needs continuity without permanent founder control of people-affecting infrastructure. | Founding charter and succession plan. |
| D-106 | Open Conduct launches as a founder-led idea and specification project maintained by Brent Turner in Massachusetts. | REQUIRED FOR COHERENCE | This reflects the actual initial operating state and avoids governance theater. | First formal transition into a contributor network or working organization. |
| D-107 | OCA is described at launch as a proposed future governing institution, not an existing independent alliance or certification body. | CONSTITUTIONAL | Public claims must match present organizational reality. | Formation of a qualifying multi-stakeholder institution. |
| D-108 | Stage 0 may publish, gather feedback, and run synthetic simulations without a Board, incorporated OCA, certification office, or appeals system. | REQUIRED FOR COHERENCE | Those structures are unnecessary before real scores, sensitive data, credentials, benefits, or certifications exist. | Crossing a defined escalation trigger. |
| D-109 | Stage 0 does not collect conduct events or sensitive identity evidence, calculate real-person CQ, issue credentials or proofs, certify organizations, or affect benefits. | CONSTITUTIONAL | Low governance is appropriate only while the project has low power and low impact. | Approved transition to a governed pilot. |
| D-110 | Governance scales through founder-led publication, advisory network, pre-pilot organization, limited human pilot, and mature OCA stages. | CANDIDATE | Capability should precede impact without imposing mature institutional overhead on an idea project. | Stage-gate review. |
| D-111 | Stage 0 uses asynchronous, structured, batched feedback and makes no promise of personal responses or service levels. | CANDIDATE | The project must remain sustainable for a solo founder and avoid becoming an unbounded second job. | Funded staffing or contributor ownership becomes available. |
| D-112 | A consumer-affecting pilot is a partnership and resourcing gate, not an obligation for the founder to perform governance, support, and appeals personally. | CONSTITUTIONAL | Real scoring and benefits require capacity and independence beyond spare-time founder stewardship. | Pilot readiness and funded operating plan. |
| D-113 | Legal formation is triggered by operational needs such as material funding, contracts, paid contributors, sensitive data, credentials, benefits, certification, or enforceable review obligations. | CANDIDATE | Incorporation should solve a real responsibility rather than create premature overhead. | Massachusetts and federal legal advice may move the trigger earlier. |
| D-114 | Stage 0 public materials describe CQ, Open Conduct, and OCA as proposals rather than operating, validated, certified, or independently governed systems. | CONSTITUTIONAL | Truthful maturity claims are the first consumer-protection obligation. | Actual transition to a later stage. |
| D-115 | “Upside only,” consent, consumer control, cryptography, nonprofit status, and open standards are safeguards—not legal safe harbors. | CONSTITUTIONAL | Legal treatment follows actual data, roles, decisions, and effects. | No planned revisit. |
| D-116 | A written FCRA and state consumer-reporting analysis is a Stage 3 stop-gate. | CONSTITUTIONAL | CQ compiles character and behavioral information for business eligibility decisions, creating a serious classification question. | Specialist legal opinion and regulatory engagement. |
| D-117 | If a required operator is likely a consumer reporting agency, the ecosystem either implements the complete applicable compliance model or redesigns before launch. | CONSTITUTIONAL | Naming the output a credential, loyalty benefit, or consumer-controlled proof does not resolve statutory classification. | Legal opinion. |
| D-118 | Every benefit receives individual legal and ethical classification by jurisdiction. | CONSTITUTIONAL | Recognition, price, deposits, queues, contract flexibility, and dispute treatment do not share one legal risk profile. | Benefit-catalog development. |
| D-119 | The initial real-person pilot is adult-only unless specialist review approves otherwise. | CANDIDATE | Children and guardianship introduce heightened privacy, consent, identity, development, and fairness risks. | Pilot jurisdiction and legal review. |
| D-120 | Stage 0 does not solicit or retain identifiable conduct histories, receipts, employee identities, identity documents, or transaction evidence. | CONSTITUTIONAL | The publication project can gather ideas without creating sensitive data obligations or accidental case files. | Approved research or pilot protocol. |
| D-121 | Legal and ethical review follows consumer and worker location and use context, not only the founder's Massachusetts location. | CONSTITUTIONAL | Digital operation can trigger duties outside the operator's home state. | Jurisdictional matrix. |
| D-122 | Ethical protections may exceed minimum law, and persistent unmitigated ethical failure requires prohibition or pause. | CONSTITUTIONAL | Legal permissibility alone does not establish alignment with the project's mission. | Independent ethics review. |
| D-123 | The system does not rely on online-platform immunity for NCS, VCI, CQ, or proof conclusions it structures, calculates, or republishes. | CONSTITUTIONAL | The ecosystem plays a more active role than passively hosting third-party speech. | Specialist media and platform-law analysis. |
| D-124 | NCS and CQ must not measure deference, cultural conformity, neurotypical presentation, digital fluency, wealth, or ease of service. | CONSTITUTIONAL | “Nice” can encode power and bias unless operational rules explicitly constrain it. | Continuous fairness and qualitative research. |
| D-125 | The specification contains a permanent prohibited-use list that applies to direct, proxy, derived, and partner use. | CONSTITUTIONAL | High-impact repurposing is a foreseeable risk and cannot be controlled through naming alone. | Rights-strengthening changes may add uses; removal requires extraordinary review. |
| D-126 | Public claims about accuracy, fairness, security, privacy, effectiveness, adoption, or business value require support appropriate to the claim. | CONSTITUTIONAL | Hypotheses and simulations must not be marketed as demonstrated outcomes. | Evidence development. |
| D-127 | A material unresolved legal classification, missing remedy, inadequate capacity, or unreasonable rights risk pauses the affected feature, partner, pilot, or jurisdiction. | CONSTITUTIONAL | Stopping rules must exist before commercial or reputational pressure arrives. | Resolution of the specified condition. |
| D-128 | The threat model covers privacy, fairness, dignity, economic harm, legal harm, social effects, and institutional capture in addition to confidentiality, integrity, and availability. | CONSTITUTIONAL | The most consequential CQ failures may be authorized uses, incentives, or human harms rather than unauthorized access. | No planned revisit. |
| D-129 | If CQ, a proof, a wallet, or a dependency is unavailable or invalid, ordinary baseline service continues without adverse conduct inference. | CONSTITUTIONAL | Safe failure for an upside-only system is temporary absence of a CQ benefit, not punishment or exclusion. | Benefit-specific continuity design may add stronger protection. |
| D-130 | Security alerts, fraud signals, failed proofs, and anomaly detections do not automatically become conduct evidence. | CONSTITUTIONAL | Protective systems have different purposes and error models from governed NCS and VCI events. | A signal may qualify only through the separately approved event and evidence process. |
| D-131 | The ecosystem maintains a living threat model and risk register at every stage, with controls and review scaled to actual power and data. | CONSTITUTIONAL | Stage 0 needs credible project hygiene; a real-person pilot needs independent production assurance. | Stage-gate review. |
| D-132 | Stage 0 uses a bounded founder security profile: protected accounts and domains, backups, minimal collection, structured feedback, moderation, correction and impersonation reporting, and continuity instructions. | CANDIDATE | These controls address the realistic risks of a one-person public project without creating a second full-time operation. | A change in project stage or data collected. |
| D-133 | Stage 0 does not offer file uploads or invite identifiable conduct evidence through its general feedback channel. | CANDIDATE | Open submissions could create accidental case files, privacy duties, emotional burden, and malware exposure. | An approved research or pilot protocol with appropriate capacity. |
| D-134 | Ordinary administrators and participating businesses cannot manually override CQ. | CONSTITUTIONAL | Corrections must occur through signed source correction or governed rule change followed by reproducible recalculation. | No planned revisit. |
| D-135 | Function creep begins as prohibited or unapproved rather than permitted by default. | CONSTITUTIONAL | Incremental repurposing can transform an optional loyalty benefit into a behavioral eligibility and surveillance system. | A new use requires full public, legal, ethical, technical, and governance approval. |
| D-136 | Government and litigant access is minimized through data minimization, distributed custody, narrow legal response, notice where allowed, and transparency reporting. | CONSTITUTIONAL | The architecture should reduce what can be compelled and should not build undeclared exceptional access. | Jurisdiction-specific legal duties. |
| D-137 | Production privileged actions use least privilege, separation of duties, dual authorization for critical changes, and tamper-evident logs outside ordinary administrator control. | CANDIDATE | Authorized insider abuse can change or expose records at population scale. | Architecture and independent security review. |
| D-138 | Critical threat validation includes consumers, frontline workers, civil-rights and disability perspectives, and smaller businesses alongside technical, fraud, legal, and enterprise experts. | CONSTITUTIONAL | A technically successful system can still fail people whose risks are not visible to system operators. | Red-team program design. |
| D-139 | Every critical dependency requires a tested continuity and exit path before a consumer-affecting pilot. | CONSTITUTIONAL | A consumer-controlled asset and promised benefit cannot depend permanently on one wallet, vendor, operator, or institution. | Pilot architecture and contracting. |
| D-140 | Risk prioritization considers severity, scale, reversibility, detectability, speed, and distributional harm—not only likelihood. | CONSTITUTIONAL | Rare, hidden, irreversible, or concentrated harms can deserve priority even when conventional risk scores are low. | Risk-method validation. |
| D-141 | Sensitive abuse-detection thresholds may be protected from public disclosure, but their purpose, effects, oversight, error performance, and consumer consequences remain reviewable. | CONSTITUTIONAL | Transparency must coexist with resistance to trivial evasion, without creating unaccountable secret systems. | Independent security, fairness, and governance review. |
| D-142 | The pilot is an evidence program, not a compressed launch of the whole Conduct ecosystem. | CONSTITUTIONAL | A staged test must isolate what creates value or harm before components and contexts multiply. | No planned revisit. |
| D-143 | Each rollout step uses the smallest reversible test capable of answering its stated question. | CONSTITUTIONAL | Narrow tests preserve causal visibility, reduce harm, and make rollback practical. | A larger test is justified only when a smaller one cannot answer the question. |
| D-144 | Organizational stages and evidence steps are separate: any use of real conduct evidence, real-person CQ, usable proof, or real benefit is Stage 3 regardless of pilot size or label. | REQUIRED FOR COHERENCE | Calling an activity research, beta, or invitation-only cannot remove consumer-affecting obligations. | No planned revisit. |
| D-145 | Stage 0 may publish, gather structured feedback, prototype concepts, and run synthetic simulations, but does not solicit real cases or operate scores, proofs, certifications, or benefits. | REQUIRED FOR COHERENCE | This creates a valuable, sustainable launch state for one founder without premature data and governance burdens. | Approved stage transition. |
| D-146 | Stage 2 selects and validates the pilot through simulation, prototypes, architecture proof, human research, legal review, and operating readiness before a live benefit. | REQUIRED FOR COHERENCE | The difficult design choices should be tested before they affect people. | Stage 3 readiness review. |
| D-147 | The initial live pilot is adult-only, uses one approved jurisdictional profile and one narrow industry context, and does not launch an overall CQ. | CANDIDATE | Scope discipline reduces legal, contextual, fairness, and interpretation risk. | Separate approval after successful bounded evidence. |
| D-148 | Travel and hospitality remain the primary public launch thesis, while partner discovery also explores horizontal customer-support infrastructure. | CANDIDATE | A clear consumer story can coexist with a reusable workflow route, provided the first live pilot remains narrow. | Evidence that another narrative or route better explains and tests the core idea. |
| D-149 | The provisional leading execution strategy is platform-first: select a digital interaction platform and operating coalition before fixing the first industry solely from concept-level fit. | CANDIDATE | Existing accounts, interaction events, worker interfaces, APIs, partner networks, and benefit systems can reduce implementation risk and increase expansion leverage. | Direct platform and operating-partner discovery, rights review, and Stage 2 readiness comparison. |
| D-150 | Airlines remain a narrative anchor and later pilot candidate rather than the presumed first live environment. | CANDIDATE | The portability case is compelling, but safety, labor, regulatory, operational, identity, and emotional complexity make early learning harder to isolate. | A highly capable partner and review package may justify earlier testing. |
| D-151 | A single business may test company-specific workflows, but at least two operationally independent businesses are required before portability is claimed. | REQUIRED FOR COHERENCE | Portability cannot be established by transferring records between brands or systems under one decision-making authority. | Independence criteria may be refined. |
| D-152 | Stage 3 progresses through live-event shadow operation, private consumer visibility, company-specific low-risk proof, industry portability, and bounded expansion. | CANDIDATE | Each release answers a different question and prevents benefits from preceding record and review validation. | Concrete pilot design may combine steps only with equivalent safeguards and causal clarity. |
| D-153 | After successful shadow operation, the first live consumer view leads with one private company-specific CQ and makes the separately governed NCS- and VCI-derived inputs inspectable beneath it. | CANDIDATE | Review Gates 1–3 restore the quotient as the product surface while preserving input transparency, non-compensation, non-score states, and the right to reject the model after human or field evidence. | Model, UX, fairness, legal, and pilot-gate evidence. |
| D-154 | The first benefit is additive, modest, low-fraud, nonessential, easy to fulfill, and easy to replace; financial, safety, rights, complaint, deposit, and material-pricing uses are excluded. | CANDIDATE | Initial testing should evaluate recognition without making participation economically coercive or legally high stakes. | Later benefit classes require separate approval. |
| D-155 | Pilot hypotheses, measures, analysis, advancement rules, and stop conditions are defined before outcome data is examined wherever practical. | CONSTITUTIONAL | Predefinition reduces result shopping and commercial pressure to reinterpret mixed results. | Documented exploratory analyses remain allowed when labeled. |
| D-156 | Candidate formula and presentation comparisons run in simulation or shadow mode before affecting benefit eligibility. | CONSTITUTIONAL | Consumers should not bear the consequences of unresolved model experimentation. | Approved model-release gate. |
| D-157 | Consumer and worker participation are separately disclosed and protected; no silent consumer enrollment or assumed worker consent is permitted. | CONSTITUTIONAL | Customers and employees face different power relationships and cannot be covered by one ambiguous acceptance. | Jurisdictional law may require stronger protections. |
| D-158 | Explanation, challenge, independent appeal, incident response, and remedy exist from the first consumer-affecting release. | CONSTITUTIONAL | A small pilot can still create real emotional, economic, privacy, and employment consequences. | No planned revisit. |
| D-159 | Baseline service is measured before the first benefit and monitored throughout the pilot across presentation, refusal, insufficient history, system unavailability, and nonparticipation. | CONSTITUTIONAL | “Upside only” must be demonstrated in outcomes rather than accepted as a policy label. | Industry-specific metrics and thresholds. |
| D-160 | Pilot partners receive no special model control, evidence weight, data access, audit immunity, appeal treatment, exclusivity, or permanent governance rights. | CONSTITUTIONAL | Funding and operational participation cannot purchase control of shared public-interest infrastructure. | No planned revisit. |
| D-161 | Every pilot has an announced sunset, renewal gate, credential and benefit exit, data-disposition plan, and public aggregate report. | CONSTITUTIONAL | A pilot must not drift into production or strand participants when funding, partners, or conclusions change. | No planned revisit. |
| D-162 | Expansion ordinarily changes one material dimension at a time: volume, business, benefit, event class, jurisdiction, or industry. | CANDIDATE | Controlled expansion preserves the ability to attribute value and harm. | A stronger evaluation design may justify a combined change. |
| D-163 | Adoption, partner interest, engagement, and positive anecdotes cannot by themselves authorize advancement. | CONSTITUTIONAL | Growth signals do not establish evidence quality, comprehension, fairness, rights protection, or operational readiness. | No planned revisit. |
| D-164 | Cross-industry transfer and overall CQ remain outside the initial production path until their meaning, necessity, comprehension, and fairness are demonstrated. | CONSTITUTIONAL | The idea's long-term ambition does not require premature universal scoring. | Extraordinary standards and evidence review. |
| D-165 | Stage 0 through Stage 2 pursue multiple partner-discovery lanes, but only one bounded coalition and context advance into the first live pilot. | CANDIDATE | Multiple outreach paths reduce dependence on one company; simultaneous live pilots would divide capacity and obscure learning. | A later stage demonstrates capacity for multiple independently governed pilots. |
| D-166 | The initial outreach portfolio includes existing two-sided platforms, vertical restaurant or hospitality systems, and customer-support platforms. | CANDIDATE | These routes combine known customer identities, attributable interactions, worker interfaces, operational data, and distribution. | Partner response and readiness evidence. |
| D-167 | A platform-first pilot ordinarily separates workflow platform, anchor operating business, portability participant, Open Conduct standard steward, and independent evaluation and rights roles. | CANDIDATE | The platform alone cannot supply baseline service, worker protection, benefit fulfillment, standard independence, and credible evaluation. | Early roles may share organizations only with explicit separation and exit. |
| D-168 | Restaurant and hospitality platforms are the provisional leading executable outreach lane; Uber and Airbnb are lighthouse native-rating targets; customer-support platforms are a parallel workflow lane. | CANDIDATE | This balances near-term integration practicality, high-visibility relevance, and horizontal distribution potential. | Direct discovery with candidate platforms and operating businesses. |
| D-169 | Existing safety, fraud, matching, booking-eligibility, suspension, and employee-performance systems remain technically and institutionally separate from CQ. | CONSTITUTIONAL | Platforms with current rating systems create leverage but also risk converting an upside-only proof into an exclusion or surveillance signal. | No planned revisit. |
| D-170 | Initial customer-support work is ordinarily Stage 2 or shadow-only until causation, protected activity, selection bias, and worker-pressure controls are validated. | CANDIDATE | Support contacts disproportionately arise from business failures, complaints, accommodations, disputes, and emotionally difficult situations. | Independent evidence supporting a narrowly approved live support context. |
| D-171 | Major-company attention is valuable but is not a prerequisite for execution; the project maintains both lighthouse and executable partner lists. | CANDIDATE | Large platforms can validate the problem yet move slowly, require control, or decline for reasons unrelated to the idea. | No planned revisit. |
| D-172 | A platform agreement cannot silently enroll client businesses, employees, or consumers; every participating role accepts its applicable obligations. | CONSTITUTIONAL | Distribution leverage must not erase consent, labor protection, issuer responsibility, verifier duties, or remedies. | No planned revisit. |
| D-173 | Enterprise integration uses thin common infrastructure over local systems of record. | CANDIDATE | Businesses can issue interoperable minimized assertions without pooling transaction logs, transcripts, notes, or complete customer profiles. | Architecture may change custody only through explicit necessity and review. |
| D-174 | Every NCS or VCI source field requires an approved source-mapping manifest and context allowlist. | REQUIRED FOR COHERENCE | Native platform fields have local meanings and cannot acquire conduct meaning through convenience. | Context-profile and conformance review. |
| D-175 | Importing existing ratings, reviews, tags, notes, sentiment, risk segments, or customer-value models as initial-pilot conduct evidence is rejected. | REJECTED | Legacy records were created under incompatible prompts, purposes, evidence, consent, incentives, and correction rights. | A separately approved historical VCI profile may consider qualifying facts; NCS cannot be backfilled. |
| D-176 | NCS is submitted by an authenticated human who directly participated and cannot be inferred, generated, recommended, or submitted by AI or automation. | REQUIRED FOR COHERENCE | Human experience is the distinctive evidence NCS contributes; simulated feeling would misrepresent both source and meaning. | A future machine-interaction context must use a separate approved measure. |
| D-177 | Integrations distinguish human actors, AI agents, deterministic automation, and mixed human–AI operation. | REQUIRED FOR COHERENCE | Bot-to-bot and human-to-human interactions have different evidence, responsibility, and disclosure requirements. | Actor taxonomy may add subtypes without erasing the distinction. |
| D-178 | A multi-client platform is not automatically the issuer, verifier, employer, or benefit fulfiller for every tenant. | REQUIRED FOR COHERENCE | Legal and operational accountability follows the real source, worker relationship, decision, and promise. | Explicit certified allocation may assign a role where factually and legally appropriate. |
| D-179 | Platform integrations isolate tenant identity, keys, configuration, roles, data, audit, incidents, and exit. | CONSTITUTIONAL | Shared infrastructure cannot become cross-client customer profiling or uncontrolled delegated authority. | Conformance and security architecture. |
| D-180 | Open Conduct defines transport-neutral logical contracts and publishes machine-readable API and event representations. | REQUIRED FOR COHERENCE | Interoperability should survive changes in vendor, transport, programming language, and platform architecture. | Specific representations may evolve through versioned standards. |
| D-181 | Each conformance release pins exact supported standards and schema versions rather than relying on an unbounded “latest” reference. | REQUIRED FOR COHERENCE | Production behavior must remain reproducible when external specifications change. | New conformance release. |
| D-182 | Event delivery assumes duplication, delay, reordering, and retry; consumers must make repeated delivery idempotent. | REQUIRED FOR COHERENCE | Distributed platforms cannot guarantee that every message arrives once and in order. | Transport-specific conformance testing. |
| D-183 | Technical receipt is distinct from schema validation, event eligibility, activation, dispute state, and synthesis effect. | REQUIRED FOR COHERENCE | An HTTP or webhook acknowledgment cannot be mistaken for acceptance of a conduct assertion. | No planned revisit. |
| D-184 | Corrections, reversals, disputes, and supersession use additive lifecycle events rather than destructive history edits. | REQUIRED FOR COHERENCE | Reproducibility and collective correction require a visible chain of state changes. | No planned revisit. |
| D-185 | Portable events exclude raw email, phone, card, loyalty, reservation, ticket, device, and account identifiers. | CONSTITUTIONAL | Local identifiers are useful for attribution but would create portable correlation and breach risk. | Approved opaque pairwise and interaction references. |
| D-186 | Ambiguous attribution results in lower confidence, clarification, limited responsibility, or no event—not convenient assignment to the account holder. | CONSTITUTIONAL | Group, delegated, corporate, family, and shared-account interactions frequently involve different people. | Context-specific attribution testing. |
| D-187 | Certification is role- and profile-specific; passing one integration profile does not certify other ecosystem functions. | REQUIRED FOR COHERENCE | NCS, VCI, synthesis, credentials, verification, benefits, and appeals create different obligations. | Certification-profile development. |
| D-188 | Enterprise proof requests use certified benefit-policy identifiers rather than arbitrary score or threshold queries. | CONSTITUTIONAL | A governed policy minimizes disclosure and prevents local businesses from inventing incompatible CQ uses. | Benefit-policy standards. |
| D-189 | Proof validation and benefit fulfillment are separately recorded, and every fulfilled or failed benefit produces a consumer-visible receipt. | CANDIDATE | A valid proof does not establish that the business delivered the promised return. | Benefit integration and UX testing. |
| D-190 | Challenge routing complexity belongs to the system; the consumer uses one entry point across platform and enterprise boundaries. | REQUIRED FOR COHERENCE | Consumers should not need to identify which vendor, issuer, model, wallet, or verifier caused an error. | Review integration design. |
| D-191 | A support case about CQ, a challenge, an appeal, or exercise of a CQ right is not itself eligible conduct evidence. | CONSTITUTIONAL | Review rights would be chilled if seeking correction could create another rating event. | No planned revisit. |
| D-192 | Tenant administrators may select certified configuration but cannot create event semantics, weights, proof purposes, or prohibited benefits locally. | CONSTITUTIONAL | Flexible enterprise configuration must not fragment or weaponize the common standard. | Standards-governed extension process. |
| D-193 | Integration failure tells the consumer privately that proof is unavailable or omits a prompt or pending event; it gives the verifier no CQ-specific result, never assumes an adverse response, and preserves baseline service. | CONSTITUTIONAL | Safe failure and nonpresentation privacy must be encoded in enterprise workflows, not merely promised in policy. | Profile-specific continuity and leakage testing. |
| D-194 | The first pilot is prospective; NCS historical backfill is prohibited and any later VCI migration requires a separate governed profile. | CONSTITUTIONAL | Past subjective input cannot be recreated, while historical operational facts require notice, matching, semantics, correction, and fairness controls. | Historical VCI proposal and independent review. |
| D-195 | Integration logs and analytics do not create hidden consumer-risk profiles, employee-performance scores, or cross-tenant model-training datasets. | CONSTITUTIONAL | Operational observability cannot become a secondary behavioral surveillance system. | Privacy and audit review. |
| D-196 | Open Conduct provides a vendor-neutral sandbox and conformance kit with schemas, examples, test vectors, mocks, lifecycle cases, and privacy and rights tests. | CANDIDATE | Platforms need a practical way to build interoperably without obtaining production data or private implementation guidance. | Stage 2 developer-program design. |
| D-197 | Enterprise onboarding and offboarding are governed lifecycles covering certification, keys, events, proofs, active benefits, reviews, notices, data, and exit. | REQUIRED FOR COHERENCE | Participation cannot begin or end as a simple API toggle when consumer and worker obligations remain. | Operating-model implementation. |
| D-198 | Consumer authentication, enterprise API authorization, event signatures, and credential proofs remain separate security layers. | REQUIRED FOR COHERENCE | Reusing one token or key across distinct trust questions creates excessive authority and compromise impact. | Technical security profile. |
| D-199 | The economic model is subordinate to CQ's mission, rights, prohibited uses, governance, and baseline protections. | CONSTITUTIONAL | Revenue cannot legitimize a system design that would otherwise be unsafe or unjust. | No planned revisit. |
| D-200 | Consumers do not pay to view, understand, present an ordinary proof, correct, challenge, materially appeal, withdraw, recover, export, or use accessible CQ participation. | CONSTITUTIONAL | Basic participation and redress cannot depend on ability to pay. | A third-party premium service is allowed only alongside a complete free path and cannot affect standing or rights. |
| D-201 | Workers do not pay to participate, respond, receive support, report retaliation, or exercise review rights. | CONSTITUTIONAL | Workers contribute evidence within an unequal employment or platform relationship and should not finance the system. | No planned revisit. |
| D-202 | Businesses, platforms, operators, members, funders, and sponsors bear ecosystem cost in proportion to the functions, scale, risk, and value they create or receive. | CANDIDATE | The primary commercial beneficiaries should fund the infrastructure rather than shifting cost to consumers or workers. | Exact allocation remains open. |
| D-203 | Payment does not purchase event weight, model influence, data access, certification, audit result, appeal outcome, standards exception, exclusivity, or permanent control. | CONSTITUTIONAL | Financial support and governance authority must remain distinguishable. | No planned revisit. |
| D-204 | OCA and required services do not sell, license, broker, advertise against, or monetize conduct histories, proof activity, worker responses, or derived behavioral profiles. | CONSTITUTIONAL | Data monetization would directly conflict with purpose limitation and create pressure for broader collection and use. | No planned revisit. |
| D-205 | Ecosystem revenue is independent of event polarity, CQ level, eligibility, benefit value, challenge denial, or enforcement volume. | CONSTITUTIONAL | Outcome-based revenue would reward manipulation of the thing the system is meant to govern neutrally. | No planned revisit. |
| D-206 | A consumer-affecting pilot is fully funded through operation, rights, remedy, reporting, and orderly wind-down before launch. | CONSTITUTIONAL | A pilot cannot defer appeals, incidents, corrections, or participant exit until after money runs out. | Pilot-readiness review. |
| D-207 | Founder labor, participant time, accessibility, independent review, appeals, and community governance are recorded as real costs rather than hidden subsidy. | CONSTITUTIONAL | Apparent low cost would be misleading if essential work depends on unpaid people. | Stage-specific budget. |
| D-208 | The mature ecosystem separates OCA's common standards and accountability functions from a replaceable market of certified service operators. | CANDIDATE | A federated operating model reduces monopoly, self-certification, data concentration, and institutional-failure risk. | A shared early-pilot service may be temporary. |
| D-209 | If OCA operates a technical service during an early pilot, the service has separate accounts, management, access, reporting, conflict controls, and a path to competition or structural separation. | CONSTITUTIONAL | Temporary operational convenience must not become permanent unreviewed vertical control. | Pilot operating plan. |
| D-210 | Mature membership dues are tiered by organization size, revenue, type, and potentially region rather than one flat commercial fee. | CANDIDATE | Tiering can fund common infrastructure while enabling smaller, nonprofit, public-interest, and global participation. | Financial modeling and governance review. |
| D-211 | Core standards, rights, public registries, and public-comment mechanisms remain meaningfully accessible without paid membership. | CONSTITUTIONAL | Open infrastructure cannot require payment merely to understand, implement, critique, or contribute. | Certification and service use may still have cost-based fees. |
| D-212 | Certification and renewal fees recover assurance costs, use the same substantive tests across fee tiers, and support qualifying waivers or subsidies. | CANDIDATE | Certification needs sustainable funding without becoming a profit center or incumbent barrier. | Fee schedule and subsidy policy. |
| D-213 | Shared-service pricing uses predictable subscriptions, capacity commitments, tiers, or volume bands rather than fees per human judgment or consumer outcome. | CANDIDATE | Pricing should follow cost without encouraging more prompts, proofs, or adverse events. | Unit-economic simulations. |
| D-214 | Grants and sponsorships disclose purpose, conflict, control, publication, data, IP, termination, and concentration terms. | CONSTITUTIONAL | Restricted money can influence infrastructure even without formal voting rights. | Contribution and disclosure policy. |
| D-215 | Penalties, settlements, and forfeitures are not recurring operating-budget assumptions and ordinarily prioritize remedy, investigation, or prevention. | CONSTITUTIONAL | Enforcement should not become a revenue target. | Jurisdiction and enforcement design. |
| D-216 | Any optional premium consumer service requires a complete free path and cannot alter CQ, eligibility, rights priority, recovery quality, appeal, or remedy. | CONSTITUTIONAL | Convenience services must not create a two-tier conduct or justice system. | Separate consumer-protection review before offering. |
| D-217 | Pilot worker participation, required training, review participation, and research time are treated as paid work or otherwise appropriately compensated. | CONSTITUTIONAL | CQ should not extract unpaid emotional and operational labor from frontline workers. | Labor and partner agreements. |
| D-218 | Stage 3 uses a written common pilot budget plus platform-, business-, and independent-provider budgets. | CANDIDATE | Shared and participant-specific costs must both be visible and assigned. | Pilot coalition agreement. |
| D-219 | OCA adopts a funder-concentration limit, reserve target, and diversification plan before production. | CONSTITUTIONAL | Formal governance independence is fragile when one funder can threaten basic operations or rights. | Exact percentages require financial modeling. |
| D-220 | The founder may receive reasonable compensation and reimbursement for defined work, while essential project assets transition or license to a future OCA without a perpetual private toll on every event, proof, or user. | CANDIDATE | Founder stewardship and fair compensation can coexist with independent shared infrastructure. | Conflict-reviewed compensation and asset agreement. |
| D-221 | Consumer, worker, disability, civil-rights, and other public-interest participation receives funded access and compensation where needed. | CONSTITUTIONAL | Unpaid participation systematically transfers influence to organizations with salaried representatives. | Participation-compensation policy. |
| D-222 | Unit-cost metrics support forecasting and pricing but cannot ration legitimate explanation, correction, appeal, incident, or remedy rights. | CONSTITUTIONAL | Operational efficiency cannot become pressure to suppress inconvenient rights use. | Service design and monitoring. |
| D-223 | Business value claims remain hypotheses until pilot evidence supports them. | CONSTITUTIONAL | Retention, loyalty, worker, cost, and revenue benefits must not be asserted from conceptual appeal alone. | Success-measure evidence and claim review. |
| D-224 | The preferred mature revenue structure combines tiered dues, role-specific certification, cost-based operator services, governed aggregate intelligence and reports, participant-funded benefits, and grants for public goods. | CANDIDATE | Multiple aligned sources reduce dependence on one sponsor while report value can fund the alliance without selling personal data or operating the raw infrastructure. | Stage 2 and pilot economic modeling. |
| D-225 | Appeals, remedies, restricted grants, and service operations use protected fund accounting or equivalent separation. | CONSTITUTIONAL | Money committed to rights or affected people must not be consumed to extend ordinary operations. | Legal and accounting implementation. |
| D-226 | Auditors, certification reviewers, and appeal providers receive no success or outcome-based fee and are assigned under conflict and rotation controls. | CONSTITUTIONAL | Direct outcome incentives and opinion shopping undermine independent assurance. | Provider accreditation and compensation design. |
| D-227 | Every material consumer-affecting operation has a credible remedy mechanism backed by responsible participants, insurance, reserves, guarantees, or another solvent source. | CONSTITUTIONAL | A written right is insufficient if no entity can fund correction or compensation. | Risk and insurance analysis. |
| D-228 | Subsidized and waived participants meet the same substantive conformance, rights, and security standards as full-fee participants. | CONSTITUTIONAL | Economic access must change who pays, not the protection level. | Subsidy and certification policy. |
| D-229 | Core specifications and tests are open or broadly implementable; certification marks protect accurate claims without granting exclusive implementation rights. | CONSTITUTIONAL | Open implementation and trustworthy market signaling serve different purposes and can coexist. | IP and mark policy. |
| D-230 | Procurement evaluates total cost, role conflicts, portability, data rights, and exit—not only launch price. | CANDIDATE | A cheap proprietary pilot can create costly institutional and consumer lock-in. | Procurement policy. |
| D-231 | Financial distress and wind-down plans protect baseline service, active benefits, urgent rights, valid consumer assets, protected funds, and data disposition. | CONSTITUTIONAL | Institutional failure is a foreseeable operating state. | Stage-specific continuity exercises. |
| D-232 | Economic readiness is a formal stage gate. | CONSTITUTIONAL | The project cannot solve essential funding, staffing, rights, and exit after consumer impact begins. | Stage readiness review. |
| D-233 | Any OCA implementation consulting is separated from certification decisions and cannot promise or bundle a favorable certification result. | CONSTITUTIONAL | The standards institution should not profit by creating avoidable complexity or selling the answer to its own test. | Service and conflict-policy design. |
| D-234 | NCS is independently understandable and implementable but remains an Open Conduct standard governed within the same standards family. | REQUIRED FOR COHERENCE | NCS may become the easiest adoption wedge without requiring a separate institution or fragmented governance. | Independent adoption may justify a larger dedicated public surface, not separate control. |
| D-235 | The initial NCS web presence is openconduct.org/netconductscore; defensive NCS domains may redirect there. | DEFERRED | One canonical standards home provides a clear entry point without multiplying websites and maintenance before demand exists. | Revisit after material independent NCS adoption, search demand, or implementer community. |
| D-236 | Success is a multi-dimensional body of evidence supporting a defined decision, not one blended score. | CONSTITUTIONAL | Adoption, revenue, technical performance, fairness, rights, and human value answer different questions and cannot safely cancel one another. | No planned revisit. |
| D-237 | Rights, baseline treatment, material fairness, evidence integrity, security, and remedy operate as non-compensating gates. | CONSTITUTIONAL | Strong demand or business value cannot authorize a release that fails essential human protections. | Exact context-specific thresholds require Stage 2 evidence. |
| D-238 | Every consumer-affecting release has a predefined evaluation charter, metric dictionary, gate structure, analysis plan, and stop/repeat/redesign/advance decision. | CONSTITUTIONAL | Predefinition reduces result shopping, pilot drift, and partner pressure to reinterpret mixed evidence. | Charter format may evolve without weakening required content. |
| D-239 | Every material success measure pairs the intended outcome with a plausible failure or harm measure. | CONSTITUTIONAL | A favorable average can otherwise conceal coercion, selection, burden, disparity, or baseline degradation. | Metric pairs are context-specific. |
| D-240 | Counts, rates, missingness, uncertainty, context, concentration, and denominators are reported separately for materially different actors and workflow stages. | CONSTITUTIONAL | Generic volume and percentage figures can make invalid or unsafe performance appear successful. | Exact reporting schemas require the pilot metric dictionary. |
| D-241 | Confirmatory, exploratory, qualitative, incident, challenge, and operational evidence remain distinguishable in analysis and public reporting. | CONSTITUTIONAL | Different evidence types have different meanings; all are necessary and none should be relabeled to strengthen a claim. | Research protocol and publication design. |
| D-242 | NCS conformance requires the governed protections and lifecycle, not merely use of the prompt or net calculation. | CONSTITUTIONAL | An open standard can be copied in ways that strip verified interaction, human provenance, sampling, worker protection, context, challenge, and prohibited-use controls. | NCS conformance profile and mark rules. |
| D-243 | Trust, engagement, partner interest, website traffic, and positive anecdotes are learning signals rather than evidence of safety, fairness, validity, or production readiness. | CONSTITUTIONAL | Attention and stated enthusiasm are vulnerable to novelty, incentives, misunderstanding, and selection. | No planned revisit. |
| D-244 | Public claims follow a maturity ladder and remain limited to the tested population, context, release, use, time, and evidence. | CONSTITUTIONAL | Simulation, prototype, shadow, pilot, and production results authorize materially different claims. | Claim-review and publication policy. |
| D-245 | Low challenge or incident volume is not presumed to show low error or harm without evidence of awareness, access, detection, and statistical power. | CONSTITUTIONAL | People may not notice, understand, trust, or feel safe using a rights process. | Detection and rights-access research. |
| D-246 | A mixed result ordinarily leads to repeat or redesign and may validate one component while rejecting another. | CONSTITUTIONAL | Evidence should support modular learning rather than binary promotion or abandonment of the whole concept. | Release-specific decision matrix. |
| D-247 | An independent evaluator must be structurally able to report failure and cannot be paid or retained based on favorable results, advancement, certification, or fundraising. | CONSTITUTIONAL | Evaluation is not independent if its access, compensation, or publication depends on a positive conclusion. | Evaluator procurement and charter. |
| D-248 | Public pilot reporting includes unfavorable, null, mixed, and exploratory findings, material deviations, limitations, harms, and prohibited inferences. | CONSTITUTIONAL | Selective publication would undermine both scientific learning and public legitimacy. | Privacy and security may constrain detail, not outcome selection. |
| D-249 | Success-measure collection is subject to the same purpose, minimization, access, retention, security, and non-surveillance constraints as operational data. | CONSTITUTIONAL | Evaluation cannot justify rebuilding the universal data pool the architecture is designed to prevent. | Evaluation data-governance plan. |
| D-250 | The public Conduct narrative begins with the missing human and consumer recognition, not the score, technology, governance body, or business case. | CANDIDATE | People need to understand the problem and personal value before the machinery can make sense. | Audience testing may refine wording without reversing the order. |
| D-251 | The canonical problem is that businesses recognize spending and transaction frequency but rarely recognize how customers treat people or fulfill their side of the relationship. | REQUIRED FOR COHERENCE | This clearly distinguishes conduct from traditional loyalty while preserving both the human and operational dimensions. | Evidence may sharpen examples, not remove either dimension. |
| D-252 | “Nice” is an editorial and campaign hook rather than the formal measurement construct. | CONSTITUTIONAL | The word makes the opportunity accessible but can encode deference, culture, disability, and personality if treated as a criterion. | Public-language research. |
| D-253 | The canonical public order is the problem, one CQ solution, then its two protected inputs: NCS human experience and VCI verified customer record. | CANDIDATE | Review Gate 1 requires people to understand the quotient first without hiding the distinct evidence sources beneath it. | Phase 4 editorial and comprehension review may refine the order without reintroducing competing primary scores. |
| D-254 | Recognition for conduct, consumer-controlled earned recognition, open conduct standard, and carefully defined conduct-based loyalty are preferred positioning territories; portable earned trust and behavioral loyalty are not unqualified primary categories. | CANDIDATE | Trust can overgeneralize the person, while behavioral loyalty has established purchasing meanings and can imply business conditioning of behavior. | Category, comprehension, and search testing. |
| D-255 | Conduct is the public-facing idea, CQ the consumer-controlled contextual result, Open Conduct the standards project, and OCA a future governing institution that cannot be presented as constituted before it exists. | REQUIRED FOR COHERENCE | Clear roles prevent premature institutional claims and reduce brand fragmentation. | Legal formation and brand research. |
| D-256 | Return on Nice and Nice Should Pay may function as editorial or campaign frames but do not define the standard or guarantee economic value. | CONSTITUTIONAL | Memorable language should attract attention without becoming an inaccurate scoring rule or financial promise. | Campaign strategy may select one or neither. |
| D-257 | Every material short explanation includes consumer-controlled contextual sharing and the upside-only baseline-service boundary. | CANDIDATE | Portability without consent sounds like surveillance, while reward without baseline protection sounds punitive. | No planned revisit. |
| D-258 | Public narrative uses maturity-specific language and complies with the Section 18 claims ladder. | CONSTITUTIONAL | A draft proposal, simulation, prototype, pilot, and production system authorize materially different verbs and calls to action. | Claims-review workflow. |
| D-259 | The airline portability example remains the primary narrative illustration, not a product claim, partner announcement, or approval of high-stakes benefits. | CANDIDATE | The example makes cross-company value intuitive while requiring careful disclosure and benefit limits. | A clearer tested example may replace it. |
| D-260 | AI agents and personhood are a supporting “why now” after the present human problem is clear. | CANDIDATE | The idea should not depend on speculative technology, but increasing automation makes earned human relationships more valuable. | Timing and emphasis may vary by audience. |
| D-261 | Business positioning emphasizes better mutual relationships, limited proofs, and evidence-based pilots rather than customer exclusion, complaint reduction, cost-to-serve, or margin extraction. | CANDIDATE | Commercial convenience can otherwise redefine conduct and turn an upside-only system punitive. | Approved business hypotheses may be added after evidence. |
| D-262 | Worker positioning promises a protected human input and participation rights, not identification or punishment of difficult customers. | CANDIDATE | NCS should give human experience a governed place without creating customer blacklists, confrontation, or employee surveillance. | Worker research and profile design. |
| D-263 | Current-stage calls to action are reading, critique, contribution, expertise, use cases, introductions, and updates—not score checks, network enrollment, certification, or rewards. | REQUIRED FOR COHERENCE | Public actions must correspond to functions and rights that actually exist. | Calls may advance with verified maturity. |
| D-264 | conduct.is, openconduct.org, the NCS page, partner materials, and participant materials have distinct narrative jobs within one standard family. | DEFERRED | Multiple surfaces should provide progressive depth without competing definitions or institutional fragmentation. | Sections 20 and 21 will define final information architecture. |
| D-265 | Public Conduct writing uses a direct, conversational, example-led voice with explicit narrative bridges and spoken-language review. | CANDIDATE | The idea is consequential and technical but must remain understandable and editorially aligned with its origin. | Usability and editorial testing. |
| D-266 | “Mutually successful interaction” is operationalized as a balanced, separately inspectable outcome vector covering consumer service or resolution, worker safety and support, consumer and business fulfillment, usable rights, avoidable friction, and absence of compelled deference or rating manipulation. | CONSTITUTIONAL | Purchase completion, low complaints, speed, spend, profitability, or repeat business can otherwise become hidden substitutes for healthy human and operational outcomes. | Research may refine measures and a governed joint endpoint but may not collapse the separately inspectable protections. |
| D-267 | Ordinary managers and workforce systems cannot receive individual NCS response values, completion records, consumer outcomes, or rater-level distributions. | CONSTITUTIONAL | Employer visibility would enable coercion and convert a protected human judgment into workforce surveillance. | Purpose-limited, logged access by named trust-and-safety personnel may support a documented investigation. |
| D-268 | NCS preserves eligible interaction, sampling selection, prompt delivery, nonresponse, unable-to-assess abstention, and scored completion as distinct states. | REQUIRED FOR COHERENCE | A random prompt is not a random sample of completed judgments, and forced completion would corrupt worker voluntariness. | Missingness thresholds and statistical treatment require research. |
| D-269 | Both negative NCS choices require one approved structured conduct category that does not alter numerical severity. | REQUIRED FOR COHERENCE | Repeated probable-negative events can affect CQ and therefore need a reviewable basis rather than becoming unexamined adverse evidence. | Interface testing must measure whether the extra action suppresses valid reporting or reduces impulsive responses. |
| D-270 | An NCS rater may use only conduct they directly experienced or directly observed during the verified interaction. | CONSTITUTIONAL | The words “and others” cannot authorize hearsay, manager framing, CRM notes, incident labels, reputation, or another worker's rating. | Safety reports remain in existing incident systems. |
| D-271 | A worker ordinarily does not learn that a consumer participates in CQ or that the interaction was selected for NCS until the verified interaction is complete. | CONSTITUTIONAL | Advance visibility could alter service, monitoring, interpretation, or consumer performance and contaminate the interaction being measured. | Any exception requires explicit research and governance approval. |
| D-272 | Worker response and abstention are voluntary, protected, and compensated across employee, contractor, host, franchise, and outsourced work models. | CONSTITUTIONAL | A compelled subjective judgment is not authentic evidence, and NCS cannot extract unpaid emotional or operational labor. | Labor-model implementation requires partner and jurisdiction review. |
| D-273 | Multiple NCS responses from one verified interaction form one statistical cluster and do not increase interaction count, issuer diversity, or independence as separate events would. | REQUIRED FOR COHERENCE | A weight cap prevents raw overcounting but does not make workers exposed to the same event independent witnesses. | Competing within-event aggregation methods require structural simulation. |
| D-274 | NCS event context preserves privacy-minimized chronology for material business failure and protected consumer activity without using complaint content as a score input. | CANDIDATE | Retaliation and outcome contamination cannot be tested when the sequence of the interaction, complaint, failure, and rating is unavailable. | Taxonomy, source reliability, privacy, and synthesis treatment require research. |
| D-275 | Only the authenticated rater or an independent adjudicator can initiate an NCS withdrawal or invalidation; managers cannot demand or execute it. | CONSTITUTIONAL | Otherwise withdrawal becomes a second employer-controlled scoring channel for protecting valuable customers or punishing disfavored ones. | Managers may report suspected error through an auditable process. |
| D-276 | An eligible VCI responsibility unit is registered before its outcome is known and retains a complete lifecycle state. | REQUIRED FOR COHERENCE | Governing only issued outcomes lets a business manufacture the evidence universe through selective creation, closure, and transmission. | Lifecycle states and reconciliation tolerances require event-profile design. |
| D-277 | A materially adverse VCI event cannot activate without the required reciprocal business, dependency, exception, accommodation, waiver, notice, cure, correction, and reversal context. | CONSTITUTIONAL | A signed consumer assertion is not independently interpretable when the issuer can omit its own qualifying performance and failures. | Event profiles may narrow the required fields only through public review. |
| D-278 | Disputed and high-severity VCI events require the independent or qualifying external finalization specified for their event class before adverse effect. | CONSTITUTIONAL | The issuer cannot simultaneously be claimant, evidence custodian, and final judge of a consequential contested event. | Undisputed machine-verifiable facts may use a certified automatic rule with effective notice and cure. |
| D-279 | Consumer silence is not admission in the VCI lifecycle. | CONSTITUTIONAL | Nonresponse can reflect failed notice, disability, language, digital exclusion, absence, crisis, or distrust rather than acceptance of the assertion. | Each event class must define effective accessible notice, cure, delivery failure, and automatic-finalization limits. |
| D-280 | A VCI event has no adverse effect to the extent an approved non-consumer cause explains the outcome. | CONSTITUTIONAL | A confidence discount would still assign consumer harm for business, dependency, accessibility, third-party, emergency, or force-majeure causation. | Partial-causation and unknown-state rules require event-profile testing. |
| D-281 | A Stage 3 VCI pilot uses a small closed set of context-specific responsibility types approved before issuance. | CANDIDATE | The legitimacy test is too normative and context-dependent to permit business-authored event semantics at launch. | Expand only after governance, operational, accessibility, legal, and evidence review demonstrates capacity. |
| D-282 | Every VCI event-class profile defines authoritative sources, conflict precedence, update latency, reconciliation, correction propagation, sampling, and safe failure. | REQUIRED FOR COHERENCE | Cryptographic authenticity cannot cure incomplete, conflicting, stale, or selectively updated business source systems. | Technical implementation varies by context without weakening the completeness obligation. |
| D-283 | Booking, payment, account, loyalty, caregiver, or reservation-holder status does not by itself establish individual responsibility for another person's VCI outcome. | CONSTITUTIONAL | Commercial account structure must not silently transfer portable conduct between family, guests, colleagues, assistants, caregivers, and payers. | Each certified event class defines eligible roles and shared-responsibility allocation. |
| D-284 | Cross-company and cross-industry production relevance starts at zero until a specific source-to-target context mapping passes approved validation gates. | CONSTITUTIONAL | Portability is the product hypothesis to prove, not a mathematical property conferred by membership in the same broad industry. | Labeled research may test nonzero mappings before production authorization. |
| D-285 | A synthesis context is defined at the interaction-function and consumer-role level in addition to evidence class, source, target, purpose, population, jurisdiction, and time. | REQUIRED FOR COHERENCE | Airline, hotel, dining, and other industry labels contain distinct relationships whose evidence may not share meaning. | Research may find that some fields can be safely generalized for a specific mapping. |
| D-286 | A component that fails a construct, provenance, sampling, completeness, fairness, or rights gate cannot be rehabilitated through confidence weighting or combination. | CONSTITUTIONAL | Combining two uncertain inputs can create false precision and hide the reason one input was unfit. | No planned weakening; gate definitions require research. |
| D-287 | Synthesis preserves evidence direction separately from sufficiency, provenance, sampling, attribution, independence, recency, completeness, validity, and fairness. | REQUIRED FOR COHERENCE | One omnibus confidence value allows volume or recency to compensate for failed validity, attribution, or sampling. | Public presentation may summarize without collapsing audit and gate states. |
| D-288 | Insufficient, developing, low-quality, or context-inapplicable evidence is not described as adverse or weak conduct. | CONSTITUTIONAL | Sparse or unreliable evidence is a statement about the system's knowledge, not the person's behavior. | Audience testing may refine the labels while preserving the distinction. |
| D-289 | Verifiers request approved context-and-purpose proofs rather than named-competitor histories. | CONSTITUTIONAL | Named-source requests can reveal competitor relationships and source composition beyond what the benefit requires. | Exceptional source disclosure requires separate necessity, consent, competition, privacy, and governance approval. |
| D-290 | A confidence-weighted CQ is rejected for the current phase; confidence governs whether a score may exist and MUST NOT independently move standing. | REJECTED | Suite K found 211,151 cases in which confidence-only changes moved standing under K7, while confidence still cannot repair failed validity, sampling, attribution, independence, or fairness. | Reconsider only after a new model and evidence show a necessary, understandable, and non-compensating role that cannot be met through gates or status. |
| D-291 | Evaluation separates pre-treatment evidence meaning from the causal effect of showing a proof, delivering a benefit, and changing expectations. | REQUIRED FOR COHERENCE | A score can appear predictive because proof holders receive preferential treatment or behave differently after recognition. | Shadow validation precedes benefit-effect experiments. |
| D-292 | Recency-driven proof loss and benefit loss are treated as potential consumption pressure even when the underlying conduct value does not decline. | CONSTITUTIONAL | Consumers may face a transaction treadmill if inactivity makes recognition practically unusable. | Proof and benefit simulations must measure inactivity effects and claims must describe time bounds honestly. |
| D-293 | Only an eligible benefit proof creates a CQ-specific verifier record; every nonpresentation state follows the ordinary baseline path without a retained negative conduct signal. | CONSTITUTIONAL | “No eligible proof presented” can become the shadow score by collapsing refusal, sparse history, nonqualification, dispute, expiry, and technical failure into one observable category. | Privacy-protected operational telemetry cannot feed consumer treatment or segmentation. |
| D-294 | The initial external protocol supports only approved purpose-bound benefit-eligibility proofs. | REQUIRED FOR COHERENCE | Standalone participation, sufficiency, dimension, relationship, and named-history proofs enlarge the inference surface without being necessary to fulfill one governed benefit. | A later proof family requires separate necessity, inference, combination, coercion, competition, privacy, and use review. |
| D-295 | Named-company and named-competitor history is not requestable through the ordinary CQ proof protocol. | CONSTITUTIONAL | Named history can expose sensitive commercial, travel, location, health, religious, or affiliation relationships and conflict with source minimization. | Any future consumer-initiated source disclosure requires a separate high-risk profile. |
| D-296 | Recurring proof permission is verifier-, context-, policy-, and benefit-specific, time-limited, centrally visible, revocable, and suspended after material change. | CONSTITUTIONAL | Convenience cannot turn one consent into indefinite background account access. | Exact duration and renewal experience require research. |
| D-297 | Baseline service is measured through a preregistered period before CQ visibility and is subject to independent definition, monitoring, and benefit reclassification. | CONSTITUTIONAL | The business benefiting from CQ cannot alone decide whether it lowered baseline, moved standard discretion behind a threshold, or selected a favorable comparison. | Pilot evaluation charter and candidate-context operations. |
| D-298 | CQ cannot prioritize or deprioritize any complaint, correction, dispute, appeal, accommodation, safety response, legally owed refund, or legal-rights process. | CONSTITUTIONAL | Effective remedy and protected rights cannot become a reward earned through prior conduct. | No planned weakening. |
| D-299 | Proof presentation is ordinarily consumer-initiated or privately offered; employee-requested disclosure and repeated pressure are prohibited. | CONSTITUTIONAL | Equal buttons do not create voluntariness when a worker waits, a business repeatedly asks, or refusal feels suspicious. | Interface implementation and prompt-frequency limits require research. |
| D-300 | Benefit fulfillment fields are separated from general customer analytics, segmentation, marketing, model training, risk, loyalty, and workforce systems. | CONSTITUTIONAL | A business can recreate prohibited scoring from eligibility, attempts, activations, use, and absence without ever receiving raw CQ. | Data-lineage conformance and audit design. |
| D-301 | The first CQ benefit is low-stakes, reversible, nonessential, non-rights, and preferably non-positional, with genuinely incremental capacity. | CANDIDATE | Separate funding does not prevent scarce staff time, inventory, queue position, discretion, or risk capacity from disadvantaging others. | Benefit research may identify a safe meaningful candidate or conclude none exists. |
| D-302 | Identity continuity protects attribution, credential integrity, justified one-person benefit limits, and resistance to manufactured positive history—not preservation of adverse effect after withdrawal. | CONSTITUTIONAL | Negative-history reset resistance contradicts baseline return, voluntary participation, redemption, contextuality, and upside-only design. | Re-enrollment rules may restore consumer-requested valid history without forcing it. |
| D-303 | Identity assurance is derived from the concrete action and selected benefit risk; stronger evidence is not collected for hypothetical future uses. | CONSTITUTIONAL | A low-stakes benefit cannot justify quasi-personhood infrastructure, document collection, or exclusion designed for future financial value. | Reassess only when a separately approved higher-risk benefit exists. |
| D-304 | The initial pilot is prospective in enrollment as well as event issuance: no legacy NCS, and no historical VCI without a separate later migration profile. | CONSTITUTIONAL | Ordinary enrollment language must not reopen backfill that D-194 already rejected for launch. | Historical VCI requires notice, legitimacy, completeness, matching, correction, fairness, and legal gates. |
| D-305 | The consumer may retain all CQ proof requests and outcomes; the verifier retains a CQ-specific record only after successful authorization for the approved benefit purpose. | CONSTITUTIONAL | Reciprocal request logs can recreate refusal, sparse history, nonqualification, dispute, expiry, and failure as customer-linked signals. | Reliability telemetry remains segregated, minimized, short-lived, and unavailable to treatment systems. |
| D-306 | A consumer may abandon an unrecoverable optional credential and return to baseline without proving entitlement to prior history. | CONSTITUTIONAL | Recovery security should protect optional value without turning identity continuity into a mandatory reputation tether. | Restoring or merging prior history requires approved evidence and independent review. |
| D-307 | Assistance, transaction agency, legal guardianship, and CQ disclosure authority are separate roles. | CONSTITUTIONAL | Booking, paying, account management, travel arrangement, caregiving, and service assistance do not establish authority to disclose another person's conduct. | Delegated disclosure requires an exceptional purpose-specific profile. |
| D-308 | Stage 0 remains free of real identity-linked conduct data, consumer enrollment, credentials, proofs, benefits, and operational appeals. | CONSTITUTIONAL | One-person stewardship lacks the separation, security, legal, insurance, remedy, and incident capacity required to affect real consumers or workers. | Advance only through the published Stage 1/2/3 gates. |
| D-309 | Independent consumer- and worker-rights functions can trigger containment and review when a constitutional gate within their mandate fails. | CONSTITUTIONAL | Representation without practical power can become ceremonial when sponsors control funding, data, engineering, and continuation. | Authority boundaries belong in the Stage 3 interim charter. |
| D-310 | Adoption, business value, sponsor preference, or an ordinary majority cannot override a failed constitutional rights gate. | CONSTITUTIONAL | Non-compensating protections have no meaning if commercial success can outvote them. | No planned weakening. |
| D-311 | Stage 3 uses a published role-incompatibility matrix across standards, building, operation, certification, audit, evaluation, enforcement, appeal, data custody, and funding. | REQUIRED FOR COHERENCE | A small pilot cannot duplicate every institution, but unrestricted role combination makes independence fictional. | Compatible combinations require conflict analysis and transparent approval. |
| D-312 | Stage 3 rights, appeal, evaluation, support, incident, and wind-down functions require named providers, contracts, funding, access, capacity, backup, and tested procedures. | CONSTITUTIONAL | Titles and unpaid volunteer intent do not deliver enforceable rights under real workload or conflict. | Pilot-readiness evidence and tabletop exercises. |
| D-313 | OCA review decides CQ eligibility and effect within its scope without claiming to resolve underlying legal, regulatory, contractual, labor, discrimination, fraud, or criminal disputes. | CONSTITUTIONAL | A private standards body cannot become a substitute global court, regulator, union, works council, ombuds, or public authority. | Jurisdiction profiles define referral and external-rights boundaries. |
| D-314 | Stage review occurs before letters, data access, funded discovery, public partner naming, prototypes, or other instruments grant material control, money, data, branding rights, delivery expectations, or preferential access. | CONSTITUTIONAL | An “exploratory” commitment can create dependence and obligations before the governance needed to manage them exists. | Ordinary conversations and nonexclusive feedback remain Stage 0 activities. |
| D-315 | The Stage 3 minimum viable constitutional coalition covers interim standards, consumer rights, worker rights, technical/privacy assurance, independent evaluation, independent appeal, pilot operation, and funded benefit/business participation. | REQUIRED FOR COHERENCE | A bounded pilot needs complete accountable functions without pretending a mature global OCA already exists. | Specific providers and compatible combinations depend on pilot design. |
| D-316 | OCA may earn revenue from governed, privacy-preserving aggregate intelligence and reports uniquely enabled by the common taxonomy and network-wide analytical mandate. | CANDIDATE | This can create public relevance, recurring member value, and business insight without requiring OCA to become the centralized infrastructure or raw-data company. | Architecture, member discovery, legal review, and report-market testing. |
| D-317 | OCA's unique analytical asset is a governed network lens and query authority—not central custody of raw NCS, VCI, consumer, worker, proof, or transaction histories. | REQUIRED FOR COHERENCE | Unique reports do not require one organization to warehouse the behavioral dossier the system is designed to avoid. | Select a validated federated, secure-aggregation, controlled-environment, or comparable architecture. |
| D-318 | Material findings about safety, fairness, rights, baseline degradation, systemic error, security, or governance cannot be withheld behind membership, report fees, sponsorship, or client confidentiality. | CONSTITUTIONAL | Report revenue must not create a financial reason to conceal ecosystem harm or give paying businesses earlier protection than affected people. | Confidential remediation windows may be narrow, risk-based, and time-limited. |
| D-319 | Member benchmarks and diagnostics may compare the member's own results with approved aggregate cohorts but cannot reveal or enable inference about a named competitor's nonpublic performance, customers, workers, strategy, or cohort contribution. | CONSTITUTIONAL | Business value can come from a unique reference frame without turning OCA into a conduit for competitively sensitive intelligence. | Cohort, dominance, and competition rules require independent review. |
| D-320 | A paying member or report sponsor cannot choose definitions, exclusions, cohorts, analytical treatment, conclusions, or publication timing to manufacture a favorable finding. | CONSTITUTIONAL | Analytical independence is necessary for both public trust and the long-term value of OCA intelligence. | Members may propose questions and supply context under governed methods. |
| D-321 | Higher membership tiers may provide greater approved report depth, cadence, analyst support, or training—but never broader access to personal data, raw network data, or rights-critical information. | CONSTITUTIONAL | Membership value must be meaningful without creating a market in conduct histories or a two-tier safety and accountability system. | Product and pricing research. |
| D-322 | Report computation should use distributed custody with approved federated queries, secure aggregation, controlled research environments, data-clean-room patterns, privacy-preserving computation, or another validated approach. | CANDIDATE | The specific technical pattern should follow the report purpose and threat model while preserving OCA's decentralized operating posture. | Architecture comparison, prototype, privacy testing, and cost analysis. |
| D-323 | OCA sells analysis, benchmarks, reports, and institutional insight—not open-ended queries, advertising audiences, risk-scoring feeds, event streams, or derived personal profiles. | CONSTITUTIONAL | This is the enforceable boundary between mission-aligned intelligence and becoming a data broker or behavioral infrastructure company. | No planned weakening. |
| D-324 | A mature Research and Intelligence Office owns governed report methods and outputs independently of membership sales, sponsors, report clients, participating companies, certification decisions, and raw-network infrastructure operation. | CONSTITUTIONAL | The report business becomes credible and valuable only if buyers can fund questions and service without purchasing conclusions or control of the underlying data system. | Early stages may use contracted independent capacity under equivalent conflicts and publication rules. |
| D-325 | Consumer authorization, wallet presentation, positive-only output, nonprofit form, and a consumer-initiated transaction do not resolve consumer-reporting classification. | CONSTITUTIONAL | FCRA roles and duties follow actual communications, purposes, regular practices, recipients, and uses rather than product labels. | Obtain a written role-by-role opinion before Stage 3; adopt a complete compliant model or redesign if coverage is likely. |
| D-326 | No EEA production profile may launch until the actual context transfer, synthesis, proof, benefit, baseline, and treatment receive a specific EU AI Act Article 5 and related legal review. | CONSTITUTIONAL | Porting social-behavior evidence between companies can create prohibited social-scoring risk when contexts are unrelated or treatment is unjustified, disproportionate, or unfavorable. | U.S. evidence does not establish EEA legality; zero-default transfer remains a mitigation, not an exemption. |
| D-327 | OCA does not rely on withdrawn U.S. antitrust safety zones or numeric aggregation conventions as legal safe harbors. | CONSTITUTIONAL | DOJ withdrew the healthcare statements in 2023 and FTC/DOJ withdrew the competitor-collaboration guidelines in 2024; modern markets and algorithms require case-specific analysis. | Aggregation, history, third-party operation, latency, clean teams, and contributor thresholds remain controls subject to counsel. |
| D-328 | Federated or distributed report computation remains regulated processing and requires a report-specific legal, privacy, labor, contract, and cross-border profile. | CONSTITUTIONAL | Avoiding central raw-data custody reduces risk but does not erase collection, inference, linkage, local computation, contribution, or publication. | Define purpose, authority, roles, rights, retention, transfer, security, correction, and later-use limits for each family. |
| D-329 | OCA report disclosure control covers competitor inference and reidentification across small cells, dominant contributors, rare events, repeated releases, subtraction, geography, and time. | CONSTITUTIONAL | Removing names or meeting one cell threshold does not make an output safe. | Establish issuer and cell minimums, dominance caps, rarity rules, latency, query budgets, overlap testing, privacy controls, and review. |
| D-330 | Institutional reports and diagnostics remain technically and organizationally separate from person-level proof and benefit eligibility. | CONSTITUTIONAL | A report product can drift into consumer reporting, employee monitoring, or behavioral brokerage through rows, drill-down, eligibility audiences, and open-ended queries. | OCA never returns people, accounts, event feeds, worker rankings, lookalike segments, or eligibility lists as intelligence products. |
| D-331 | “Additional,” “optional,” “positive,” and “benefit only” do not resolve public-accommodations or nondiscrimination duties. | CONSTITUTIONAL | A benefit can be a privilege or advantage and its proof threshold can be an eligibility criterion or method of administration. | Every benefit receives separate access, accommodation, effective-communication, disparity, baseline, and equivalent-path review. |
| D-332 | Stage 2 maintains current, dated, owner-assigned jurisdiction matrices tied to the actual pilot population, entities, workers, processing, proof, benefit, and report families. | REQUIRED FOR COHERENCE | Founder location does not determine every applicable law, and state, national, and regional obligations change. | Limit geography or functionality when the organization cannot satisfy a profile. |
| D-333 | Required NCS capture, review, training, investigation, correction, and appeal activity is treated as work for compensation and workload purposes where applicable. | CONSTITUTIONAL | Worker-generated conduct evidence cannot depend on unpaid labor or hide monitoring, retaliation, or protected-activity consequences. | Pilot profiles require confidentiality, compensation, workload, labor, consultation, collective-rights, and independent-channel controls. |
| D-334 | Stage 0 uses a concise proposal-and-evidence claims boundary instead of implying operation, adoption, independence, effectiveness, safety, or legal compliance. | CONSTITUTIONAL | Publication and coalition building should remain lightweight, but public trust requires clear separation between the proposed system and demonstrated facts. | Stage 0 remains data-free and engages counsel before material data, funding, prototype, benefit, or partner commitments. |
| D-335 | Legal approval is feature-, purpose-, role-, report-, benefit-, population-, and jurisdiction-specific; one favorable classification does not approve the ecosystem. | CONSTITUTIONAL | CQ combines functions with different legal consequences, and expansion can change classification even when the standard name remains constant. | Reopen review on material change and encode approved profiles in conformance controls. |
| D-336 | Platform-first remains the preferred partnership thesis, but constitutional readiness—not brand, scale, funding, API maturity, or executive enthusiasm—selects the live pilot. | REQUIRED FOR COHERENCE | Platform leverage accelerates integration while concentrating practical control over people, data, workflows, benefits, and evidence. | Maintain multiple discovery lanes and apply non-compensating gates before comparative scoring. |
| D-337 | The pilot evaluator receives complete required evidence directly under durable data rights and may publish favorable, unfavorable, null, mixed, and stopped results. | CONSTITUTIONAL | Sponsor-curated extracts and publication approval make independent evaluation fictional. | Permit only narrow, time-bound review for factual correction, privacy, security, law, and protected trade secrets. |
| D-338 | The first pilot is prospectively CQ-clean and cannot import or use legacy ratings, notes, tags, risk, safety, fraud, enforcement, loyalty, value, sentiment, or customer-tier fields as conduct evidence or selection features. | CONSTITUTIONAL | Digitally ready platforms hold exactly the punitive and commercially biased records CQ is intended not to inherit. | Approved operational fields may support reconciliation only under purpose and lineage controls. |
| D-339 | Release 3D portability requires substantively independent operating businesses, not merely two brands, clients, or properties inside one control, policy, data, or loyalty system. | REQUIRED FOR COHERENCE | Same-group transfer can prove integration while avoiding the institutional and competitive proposition of portability. | Earlier same-group testing must be labeled as integration evidence only. |
| D-340 | No pilot partner receives exclusivity, first refusal, proprietary standards control, official-platform status, or restrictions on OCA work with competitors and alternative implementers. | CONSTITUTIONAL | A lighthouse partner can capture the standard through contracts, engineering dependence, IP, branding, and roadmap power without a formal governance veto. | Identify background and implementation IP while preserving the open standard and public learning. |
| D-341 | Platform authorization does not bind operating businesses, franchisees, workers, unions, works councils, controllers, or processors that hold separate obligations or authority. | CONSTITUTIONAL | The platform may control the interface without employing workers, owning the customer relationship, or controlling benefits and corrections. | Map and secure role-specific acceptance before real events. |
| D-342 | OCA data contribution and analytical rights are purpose-bound to approved report families rather than a general aggregate-research or secondary-use license. | CONSTITUTIONAL | The report business needs dependable data without converting participation into unlimited reuse of customer, worker, operational, and competitive information. | Define completeness, purpose, computation, cohorts, retention, correction, exit, trade secrets, publication, and audit in participation terms. |
| D-343 | Customer support remains a Stage 2 workflow and causation laboratory by default, not the first portable NCS or benefit context. | CANDIDATE | Support interactions are selected by failures and rights exercise and create exceptional company-causation, worker-surveillance, and complaint-chilling risk. | A later live profile must earn advancement through unusually strong evidence and cannot prioritize support rights. |
| D-344 | The first live releases may validate capture, correction, proof, benefit, and baseline before cross-company portability, but the selected coalition must make a later independent portability test feasible without architectural replacement. | REQUIRED FOR COHERENCE | Forcing the defining proposition into the first release destroys causal visibility; stopping at same-company recognition fails to test the core ambition. | Preserve the Release 3A–3D ladder and state each release's claim boundary. |
| D-345 | Platform exit capability is demonstrated before launch with production-shaped synthetic data and funded continuity for correction, appeal, incident response, benefit completion, deletion, export, and final reporting. | CONSTITUTIONAL | Contractual portability is not enough when keys, schemas, staff, evidence, or funds disappear with the platform. | Exit test results are a Stage 3 readiness artifact. |
| D-346 | Only an authorized Eligible proof produces a CQ-specific verifier or benefit-system response and record; every other outcome is indistinguishable from ordinary baseline service to the verifier. | CONSTITUTIONAL | Not established, unavailable, refusal, dispute, expiry, and failure recreate the shadow score even without a reason code. | Aggregate reliability and evaluation telemetry is segregated from customer and treatment systems. |
| D-347 | Event-producing integrations reconcile the complete eligible source population and lifecycle, not only the signed events that arrived. | CONSTITUTIONAL | Valid delivered events cannot reveal selective registration, prompting, issuance, transmission, correction, or reversal. | Precommit eligibility and sampling and provide evaluator-accessible privacy-minimized denominators. |
| D-348 | CQ-clean integration prohibits legacy-system influence through recruitment, selection, sampling, interface, investigation, proof, benefit, analytics, and downstream treatment as well as through event payloads. | CONSTITUTIONAL | Existing rating and risk systems can contaminate the pilot without transmitting a prohibited field. | Full lineage and controlled counterfactual conformance testing. |
| D-349 | Correction completion is an end-to-end state across consumer view, synthesis, credentials, status, permissions, future proofs, evaluator data, and affected reports. | CONSTITUTIONAL | Technical acceptance of a reversal does not end inaccurate effect in caches and downstream systems. | Harm-based service levels, completion receipts, consumer notice, and partial-failure escalation. |
| D-350 | A completed benefit obtained through a valid good-faith proof is not clawed back solely because later correction changes future eligibility. | CONSTITUTIONAL | Consumers should not bear retrospective system or evidence risk after relying on a valid authorization. | Incorrect prior denial follows the approved replacement or compensation remedy. |
| D-351 | Tenant isolation is assessed by actual platform, parent, cloud, warehouse, support, backup, key, vendor, and legal-access domains rather than logical tenant labels alone. | CONSTITUTIONAL | A super-administrator or shared data plane can defeat tenant-specific identifiers and keys. | Cross-tenant access is extraordinary, purpose-bound, dual-authorized, logged, and independently reviewed. |
| D-352 | Independent evaluator rights do not imply permanent bulk custody of an identity-linked cross-company evaluation dossier. | CONSTITUTIONAL | Evaluation can recreate the privacy and subpoena concentration the production architecture seeks to avoid. | Compare controlled environments, federated analysis, bounded extracts, secure aggregation, and separate case validation. |
| D-353 | Person-level synthesis and institutional report computation use separate interfaces, authorization, policy, audit, query, and output paths. | CONSTITUTIONAL | Repeated person-level calls can bypass report cohorts and create eligible audiences or reconstruction attacks. | Report conformance tests enumeration, threshold probing, repeated queries, and privileged back doors. |
| D-354 | Role ambiguity suppresses or narrows a conduct event rather than assigning group conduct and responsibility to the account holder by convenience. | CONSTITUTIONAL | Booker, payer, loyalty member, delegate, guest, rider, diner, and service recipient may be different people. | Context profiles define verified actor and responsibility mappings. |
| D-355 | Enterprise certification includes production-shaped end-to-end rights, lifecycle, safe-degradation, incident, report, and exit journeys—not only schema, API, and component security tests. | CONSTITUTIONAL | Functionally correct components can combine into inaccessible, coercive, leaky, or uncorrectable experiences. | Material role, ownership, configuration, model, benefit, and data-flow changes trigger recertification. |
| D-356 | Stage 3 is financed with report and benchmark revenue assumed to be zero. | REQUIRED FOR COHERENCE | Network intelligence becomes valuable only after credible participation, comparable data, lawful methods, and sufficient history exist. | Demonstrated privacy-safe willingness to pay may enter Stage 4 forecasts. |
| D-357 | Pilot funding counts only committed cash, protected funds, enforceable provider capacity, applicable insurance, and in-kind support with a defined term, replacement value, exit obligation, and fallback. | CONSTITUTIONAL | Revocable internal resources and optimistic fundraising cannot deliver rights after sponsor withdrawal or an unfavorable result. | Prelaunch funding close and sponsor-loss stress test. |
| D-358 | Every consumer-affecting release has funded volume ceilings and automatic intake pauses before rights, accessibility, support, appeal, incident, benefit, or remedy capacity is exceeded. | CONSTITUTIONAL | Platform distribution can turn a bounded pilot into an unfunded population-scale obligation. | Limits and leading pause indicators are part of the operating profile. |
| D-359 | Funding concentration is measured by replacement cost and practical control across cash, engineering, hosting, data, worker access, benefits, distribution, services, indemnity, and related corporate-family contributions. | CONSTITUTIONAL | Cash-share caps can conceal overwhelming in-kind dependence. | Stress-test simultaneous loss of related funder, operator, report client, and contributor roles. |
| D-360 | OCA maintains program ledgers and explicitly approves cross-subsidy among standards, certification, services, rights, evaluation, public goods, membership, and intelligence products. | REQUIRED FOR COHERENCE | Hidden subsidy can make appeals client-dependent or use public funds to underprice private diagnostics. | Report direct, allocated, variable, tail, restricted, subsidy, reserve, concentration, and replacement costs. |
| D-361 | Certification participants pay published program assessments rather than directly buying the assigned reviewer's scope, opinion, or timetable. | CONSTITUTIONAL | Participant-paid assurance otherwise enables opinion shopping, pay-until-pass pressure, and reluctance to suspend a large payer. | OCA governs assignment, rotation, surveillance, complaints, retesting, reporting, and reviewer incentives. |
| D-362 | Pooled appeal readiness is funded through role-, scale-, capacity-, and risk-sensitive assessments; extraordinary participant-attributable defects may trigger prospective reassessment or governed cost recovery. | REQUIRED FOR COHERENCE | Flat pooling externalizes high-error issuers, while outcome-based funding compromises appeal independence. | No reviewer or base-budget dependence on affirmance, reversal, denial, or settlement counts. |
| D-363 | Any OCA-operated technical service has separate cost, access, management, and incident accounting; no certification advantage; and a published sunset or structural-review date with a replacement path. | CONSTITUTIONAL | Temporary pilot service can become a vertically integrated conflict center and infrastructure dependency. | Conditions for competition, separation, spinout, or retirement are defined before launch. |
| D-364 | Insurance and reserves are approved against named loss and wind-down scenarios, including exclusions, deductibles, limits, claims timing, cancellation, tail, counterparty insolvency, and uncovered obligations. | CONSTITUTIONAL | Generic policy limits and runway months do not establish funded remedy capacity. | Maintain liquid response for obligations insurance cannot meet reliably or promptly. |
| D-365 | Mandatory public-interest reporting, accessibility, translation, consumer and worker participation, and other common goods receive explicit base funding. | CONSTITUTIONAL | Mission-critical public goods cannot depend on report surplus or a sponsor's restricted generosity. | Subsidies change payer allocation, not rights or conformance requirements. |
| D-366 | Pricing uses predictable base and committed-capacity structures with transparent variable-cost treatment and no outcome component. | REQUIRED FOR COHERENCE | Per-proof, per-event, and per-consumer incentives can drive excessive queries, incomplete issuance, retention friction, and surveillance. | Monitor pricing-induced behavior and ensure valid corrections and rights are never rationed. |
| D-367 | Stage 0 operates with explicit founder time, intake, cadence, service, and stop-doing boundaries. | REQUIRED FOR COHERENCE | Interest can turn publication into an unpaid always-on operating role before an institution or budget exists. | Material continuing requests require scoped funding or advancement to Stage 1/2 capacity. |
| D-368 | Every primary pilot claim names its estimand and preserves the full selection flow from eligible and invited through enrollment, exposure, sufficient history, qualification, presentation, treatment, follow-up, withdrawal, and missingness. | CONSTITUTIONAL | Results among benefit recipients are highly selected and cannot describe the eligible population by default. | Lead with assignment- or invitation-based analysis where supported and label all post-selection analyses. |
| D-369 | Numerators, denominators, eligibility, exclusions, lifecycle states, and sources are preregistered and reconciled to the complete eligible-source population. | CONSTITUTIONAL | A partner can make every rate look favorable by selecting the denominator while preserving arithmetic accuracy. | Independently verify incentive-sensitive exclusions and report a denominator ladder. |
| D-370 | Underpowered or statistically nonsignificant subgroup results do not establish fairness, safety, or parity. | CONSTITUTIONAL | Small and privacy-suppressed groups can experience material harm that the pilot cannot detect quantitatively. | Combine precision disclosure with qualitative, accessibility, case, scenario, detection, and precautionary evidence. |
| D-371 | Analysis accounts for repeated interactions, shared workers, locations, businesses, platforms, incidents, time, and other clustering or interference at the level relevant to the claim. | REQUIRED FOR COHERENCE | Event count can dramatically overstate independent evidence and precision. | Report concentration, effective sample size, and person- and event-level results. |
| D-372 | Missingness, attrition, withdrawal, abstention, and unavailable evidence are outcomes and bias risks rather than records discarded through complete-case analysis. | CONSTITUTIONAL | Missing data may concentrate among harmed, dissatisfied, inaccessible, pressured, or technically failed participants. | Map each stage and publish sensitivity or bounded results under credible alternatives. |
| D-373 | Preregistered primary results remain primary in decisions and public reports; exploratory findings are labeled and retested before authorizing expansion or strong claims. | CONSTITUTIONAL | Multiple outcomes, models, subgroups, periods, and report cuts make favorable noise easy to find. | Predefine multiplicity and sequential-monitoring rules for decision analyses. |
| D-374 | Evaluation continues through a funded risk-based tail after the last live interaction. | CONSTITUTIONAL | Retaliation, challenge, correction, privacy incident, repeated pressure, benefit failure, and wind-down harms may emerge later. | Claims state actual follow-up and censoring. |
| D-375 | Hard-gate harm monitoring includes detection coverage, multiple reporting sources, named independent receipt, containment authority, near misses, and case review. | CONSTITUTIONAL | Zero observed harm is uninformative when people cannot recognize, safely report, or reach the process. | A credible severe report may trigger containment before statistical confirmation. |
| D-376 | Experiments never randomize, withhold, delay, or degrade baseline service, accessibility, safety, complaint handling, explanation, correction, appeal, remedy, legally owed treatment, or another protected right. | CONSTITUTIONAL | Causal clarity does not justify assigning people below the protected floor. | Compare approved optional designs above that floor or use nonharmful alternative methods. |
| D-377 | Primary findings remain independently reproducible through a controlled versioned analytical state without requiring public release of protected row-level data. | CONSTITUTIONAL | Privacy cannot justify irreproducible partner dashboards, and reproducibility cannot justify a public behavioral dataset. | Preserve code, definitions, configuration, exclusions, queries, aggregates, amendments, and governed rerun access. |
| D-378 | Workflow, construct, intervention, and portability claims are separate evidence levels. | REQUIRED FOR COHERENCE | Technical operation does not validate NCS; NCS validity does not prove benefit effect; company-specific value does not prove portability. | Each advancement decision names the claim actually established. |
| D-379 | Production generalization ordinarily requires repetition across a materially different site, period, operator, or implementation appropriate to the claim. | REQUIRED FOR COHERENCE | One intensively supported pilot can depend on novelty, leadership, population, staffing, or platform conditions that do not generalize. | Limit initial claims and seek independent or varied replication before broad production. |
| D-380 | Public explanations introduce one contextual CQ first, then explain that its NCS- and VCI-derived inputs independently qualify and remain separately governed and inspectable beneath it; purpose-bound proof remains the ordinary verifier output. | REQUIRED FOR COHERENCE | The product promise requires one simple score, while Suite C and Suite K require the system to preserve contradiction, prevent failed-input compensation, and avoid exposing unnecessary history. | Human testing may refine the shortest language without weakening independent gates, non-score states, or proof minimization. |
| D-381 | The preferred public outcome category is consumer-controlled earned recognition; trust language is contextual, limited, verified, or relevant rather than universal and predictive. | REQUIRED FOR COHERENCE | “Portable earned trust” can turn interaction evidence into a durable personal trait. | Portability remains the ambition and every production mapping begins at zero. |
| D-382 | Proposal-stage baseline language states what the system must achieve and what a pilot must verify, not that equal baseline treatment is already proven. | CONSTITUTIONAL | Protocol design cannot establish real business, worker, CRM, timing, benefit, and stigma outcomes. | Evidence-level language may strengthen only within the tested profile. |
| D-383 | The Delta-to-United example remains the canonical portability illustration, but United receives only a future approved industry proof without learning Delta was the source or seeing Delta events. | REQUIRED FOR COHERENCE | Named companies make the idea clear while the ordinary protocol prohibits named-competitor history disclosure. | Continue labeling the example hypothetical and not a partnership claim. |
| D-384 | VCI is a separate operational counterweight to NCS, not an objective input that mathematically cures bias in human judgment. | CONSTITUTIONAL | Operational data has its own access, responsibility, observability, policy, and socioeconomic biases. | CQ preserves contradiction and may decline to combine dimensions. |
| D-385 | Public safeguards are framed as rules to build and test rather than achievements proved by documentation. | CONSTITUTIONAL | A long control list can create false assurance about a system with no real-world validation. | Use four plain risk families and route detailed work to Open Conduct. |
| D-386 | Public materials distinguish the long-term idea, the first bounded test, and the future conditional on evidence. | REQUIRED FOR COHERENCE | Mixing horizons makes a narrow pilot look like the full value proposition or an ambitious vision look imminent. | Newsletter may lead with the vision; standards and partner surfaces identify the release ladder. |
| D-387 | OCA aggregate intelligence is a secondary institutional-value story separated from consumer proof and the consumer opening. | REQUIRED FOR COHERENCE | Report value can sound like behavioral-data monetization or named-competitor access. | Explain own-company insight against protected cohorts and public-interest reporting; no people, audiences, raw events, competitors, or open queries. |
| D-388 | Return on Nice and Nice Should Pay remain editorial and campaign frames, while formal measurement concerns treatment of people and legitimate controllable responsibilities. | REQUIRED FOR COHERENCE | The hooks create intuitive energy but cannot become a deference, agreeableness, or complaint-suppression criterion. | Preserve explicit protections for directness, disagreement, disability, culture, language, accommodation, and rights. |
| D-389 | Open Conduct is the current founder-stewarded project; OCA remains a proposed future independent institution until legally constituted and operationally capable. | CONSTITUTIONAL | Present-tense alliance language would misrepresent governance, partners, data, certification, appeals, reports, and accountability. | Calls to action remain limited to reading, critique, contribution, expertise, introductions, and following progress. |
| D-390 | Version 0.3 is conditionally ready to enter structural-simulation preparation after PSB-001 through PSB-008 are completed. | REQUIRED FOR COHERENCE | The substantive audit found no need for another conceptual rewrite, but trustworthy comparison requires a fixed candidate manifest, generator, truth dictionary, elimination rules, scenario matrix, state model, evaluation harness, and reproducible run package. | Complete the Pre-Simulation Closure and Blocker Register entry gate. |
| D-391 | A finding may block Stage 3 while remaining a valid constraint or scenario for Stage 2 synthetic simulation. | REQUIRED FOR COHERENCE | Treating every live-pilot blocker as a simulation blocker would prevent the evidence needed to resolve it. | Each blocker register entry states the stage and artifact it controls. |
| D-392 | Exact coefficients, thresholds, recency, confidence summaries, context-transfer values, benefit, partner, technology, fees, and mature institutional form remain deferred until the applicable structural evidence exists. | REQUIRED FOR COHERENCE | Premature choice would tune or organize around unvalidated structures. | Structural simulation, partner discovery, legal review, and research narrow these decisions in sequence. |
| D-393 | PSB-001 through PSB-004 use Structural Simulation Design Package v0.1 as their versioned baseline. | CANDIDATE | Freezing candidates, generator semantics, truth categories, and elimination rules before results reduces preference-driven simulation design. | Complete finding-to-suite traceability review; amendments preserve original runs and disclose whether results were visible. |
| D-394 | The Finding-to-Suite Traceability Matrix is the controlling bridge from all 125 version 0.3 audit findings into simulation, analytical gates, Stage 3 evidence, and claim limits. | REQUIRED FOR COHERENCE | A prose repair can disappear during implementation unless every sustained threat has an explicit executable or evidentiary disposition; legal, institutional, and normative questions must not be falsely closed by synthetic results. | Amend only through a versioned row-level change that preserves the original assignment and states whether comparative results were visible. |
| D-395 | PSB-005 uses broad nonforecast sensitivity grids, required joint dependencies, common generated histories, and targeted adversarial scenarios rather than invented real-world prevalence or a full Cartesian product. | REQUIRED FOR COHERENCE | The project lacks empirical distributions for many mechanisms, while independent one-factor sweeps can create impossible populations and preference-driven winners. | Expert evidence or pilot data may narrow ranges only in a new version that preserves the original structural comparison. |
| D-396 | PSB-006 treats observability, record creation, retention, correction, rights capacity, and exit as executable state—not implementation detail—and makes only an authorized Eligible proof verifier-visible. | CONSTITUTIONAL | A clean formula or payload can still create a shadow score, stale harm, worker exposure, central dossier, report backdoor, or stranded obligation through surrounding systems. | Amend only if an alternative state architecture proves equal or stronger privacy, rights, correction, baseline, and exit behavior under the same attacks. |
| D-397 | PSB-007 separates workflow, construct, intervention, portability, operating-readiness, and generalization claims and preserves the complete population ladder from eligible source through withdrawal and missingness. | REQUIRED FOR COHERENCE | A successful workflow, local construct, benefit recipient, or single site cannot silently authorize a population, portability, or production claim. | Amend only through a versioned claims-ledger change that preserves original runs and states whether comparative results were visible. |
| D-398 | The executable referee uses common generated histories and non-compensating verdict precedence and does not automatically select a provisional lead or blended success score. | CONSTITUTIONAL | A preferred candidate must not receive an easier population or win by averaging business value against failed rights, fairness, privacy, baseline, or adverse-tail gates. | A provisional-lead rule may be added only before comparative results and only among survivors using preregistered dominance without compensation. |
| D-399 | PSB-008 v0.1 freezes package, configuration, and experiment-design identities; deterministic seeds; common-history comparisons; generator and candidate versions; result schema; preservation rules; and amendment disclosure before comparative interpretation. | REQUIRED FOR COHERENCE | Reproducibility must make favorable, null, adverse, failed, and amended runs equally visible and prevent silent rule changes after a preferred result appears. | Any controlled-file change creates a new package identity and preserves the original package and runs. |
| D-400 | Direct invariant violations and prohibited records use zero tolerance; continuous materiality is reported as a response surface and breakpoint and remains inconclusive without a preregistered practical range. | CONSTITUTIONAL | The project should not invent universal numeric safety thresholds merely to start simulation, but it also cannot improvise pass thresholds after seeing a candidate's result. | Independent threshold review under OQ-600 may authorize claim-specific ranges in a new version before strong advancement decisions. |
| D-401 | Suite A retains the +10, +3, −3, −10 graduated NCS model as the provisional lead numerical research calculation. | CANDIDATE | Across common synthetic histories, it preserved more intended interaction signal than conviction-net or direction-net while preserving the direction and conviction of every scored answer. | Human cognitive, cultural, accessibility, worker, consumer, and field validation; capture gates remain non-compensating. |
| D-402 | Any scalar NCS remains inseparable from the complete four-choice response distribution, evidence-quality profile, and applicable uncertainty and sufficiency state. | REQUIRED FOR COHERENCE | The scalar is useful for comparison, but the backing representation preserves information needed to identify polarization, sparse evidence, capture failure, and inappropriate certainty. | Define the minimum privacy-safe presentation and proof layers after human validation. |
| D-403 | Conviction-net and direction-net remain robustness challengers; purpose-bound state remains a downstream-output candidate; no portable NCS remains the constitutional null. | REQUIRED FOR COHERENCE | Suite A narrows the numerical lead without converting one synthetic comparison into production truth or eliminating simpler and null architectures. | Reuse the challengers in human research, later simulations, and any material NCS amendment. |
| D-404 | No NCS formula may compensate for prohibited-factor influence, legacy contamination, employer-visible individual response state, worker reidentification, or materially selective completion. | CONSTITUTIONAL | Suite A shows that contaminated capture can dominate the differences between numerical formulas; mathematical performance cannot legalize, legitimize, or repair structurally unsafe evidence. | Suppress, narrow, or reject portable NCS when a non-compensating capture gate fails. |
| D-405 | Suite B retains the fulfilled-over-finalized ratio as the provisional lead simple VCI research calculation, available only after the applicable responsibility-ledger gates clear. | CANDIDATE | It best described the clean eligible event rate among the simple candidates, but a scalar continued producing answers under invalid source conditions unless admissibility was enforced separately. | Multi-issuer, event-class, human, fairness, rights, and field validation; no production or consumer-facing numerical approval. |
| D-406 | Any VCI calculation remains inseparable from the event-class, lifecycle, source-coverage, attribution, causation, evidence-quality, concentration, correction, and uncertainty profile. | REQUIRED FOR COHERENCE | The profile was more robust to broad corruption and preserves differences that a ratio hides; no number establishes whether its source ledger is legitimate. | Define the minimum internal, consumer, synthesis, auditor, and appellate views by purpose. |
| D-407 | The opportunity-balanced fulfilled-over-registered ratio is rejected as a consumer-standing calculation; the pre-outcome responsibility universe and its registration, delivery, closure, and reconciliation ladders remain required evidence gates and diagnostics. | REJECTED | The ratio charged undelivered or unresolved business-system records against consumers and remained vulnerable when the registered universe itself was selected. | Revisit only if a new calculation preserves unknown as nonadverse and outperforms the profile-plus-gate architecture without denominator selection. |
| D-408 | The hierarchical reliability-model family remains an advanced challenger, while Suite B's simplified smoothing approximation is insufficient to select it. | CANDIDATE | Shrinkage improved sparse synthetic estimates, but the runner lacked multiple issuers and source hierarchies and the approximation retained greater volume dependence than simpler representations. | Multi-issuer, multi-source, multi-policy generator and independent statistical review. |
| D-409 | The generic one-relevant-positive-and-no-adverse VCI proof rule is rejected. | REJECTED | The shortcut discarded too much information and made continued activity create more opportunities to lose eligibility. | No planned revival of this generic rule. |
| D-410 | Purpose-bound VCI proof remains a candidate output class only through a newly specified purpose-specific rule. | CANDIDATE | Purpose limitation can minimize disclosure and avoid a general verifier score, but the rule must earn validity without a transaction treadmill or threshold shortcut. | Define relevant classes, sufficiency, caps, sparse and disputed states, and volume-neutral behavior before testing. |
| D-411 | No VCI formula or model may compensate for an unreconciled source universe, outcome-selected issuance, missing reciprocal business context, unresolved dispute or correction, ambiguous actor, or routine-volume domination. | CONSTITUTIONAL | Suite B shows that source, causation, lifecycle, and attribution corruption can dominate representation differences while still yielding numerically plausible outputs. | Suppress, narrow, or reject portable VCI when a non-compensating evidence gate fails; no portable VCI remains the null. |
| D-412 | Suite C's two-dimensional lead is superseded for the consumer surface by Review Gate 1 and Suite K; it remains the mandatory explanation and information-preserving control. | CANDIDATE | Suite C correctly exposed destructive compensation, and Suite K subsequently tested a capped one-score family designed around that warning. | Representative consumer, worker, business, critic, accessibility, cultural, methodological, and legal research. |
| D-413 | CQ synthesis validates, filters, contextualizes, clusters, compares, and explains NCS and VCI before applying the approved capped arithmetic family or returning a non-score state. | REQUIRED FOR COHERENCE | Arithmetic is only the final bounded step after the distinct evidence and rights gates; it cannot substitute for the reasoning and policy layer. | No planned weakening of the gates; formula family and explanation remain empirical. |
| D-414 | Purpose-bound proof is the lead verifier-output candidate, using only the components prospectively approved as relevant to that purpose. | CANDIDATE | It minimized disclosure and produced no output from an invalid or unknown relevant component while allowing an explicitly irrelevant component to remain unused rather than adverse. | Approved-purpose taxonomy, comprehension, privacy, competition, legal, benefit, and field validation. |
| D-415 | A conjunctive rule is retained only when an approved purpose genuinely requires independent minimums in both NCS and VCI; it is not a universal CQ tier. | CANDIDATE | Conjunction prevented component offset, but universal use would falsely imply both dimensions have equal relevance to every purpose. | Benefit-specific necessity, thresholds, fairness, comprehension, and baseline review. |
| D-416 | Suite C's unconstrained transparent confidence-weighted combined score remains rejected; this rejection does not apply to the later K3 capped arithmetic family. | REJECTED | Approximately 69% of eligible Suite C combined results relied on component compensation. K3 changes the architecture by enforcing separate gates and an explicit maximum uplift above the weaker input. | No revival of the Suite C formula without a new preregistered design and non-compensation protection. |
| D-417 | Confidence-shrunk and partial-pooling standing models do not advance; hierarchical methods may still estimate uncertainty or context variation if they never move standing through confidence alone. | REJECTED | Suite K K7 failed the confidence-only movement gate, while the full issuer and context hierarchy remains unvalidated. | Materially richer data, independent methods review, and strict separation between standing, uncertainty, and availability. |
| D-418 | No combined CQ remains a mandatory control and honest possible conclusion, not the current lead consumer product. | REQUIRED FOR COHERENCE | Product preference cannot predetermine validity; human, field, fairness, legal, or operating evidence may still require two-dimensional or proof-only fallback and may reject overall CQ. | No planned removal of the null control. |
| D-419 | Any threshold-based CQ tier or proof requires explicit entry and exit hysteresis, pending and dispute behavior, version-transition rules, and completed-benefit protection. | REQUIRED FOR COHERENCE | Small synthetic updates caused avoidable eligibility churn; hysteresis materially reduced flips but can itself preserve stale eligibility if not bounded. | Select exact thresholds and widths only through benefit-specific research and lifecycle testing. |
| D-420 | Evidence sufficiency, proof availability, and conduct direction remain separate; inactivity or low transaction opportunity cannot become adverse standing, and reestablishing sufficiency cannot require unnecessary purchasing. | CONSTITUTIONAL | Suite C found substantial transaction-volume dependence in proof availability even when the component calculations were intended to be volume-neutral. | Test caps, clustering, modest benefits, noncommercial or naturally occurring evidence paths, dormancy, and unequal opportunity. |
| D-421 | Post-proof outcomes cannot validate the pre-proof CQ construct without separating selection, participation, novelty, attention, benefit, staffing, spillover, and baseline effects. | REQUIRED FOR COHERENCE | The synthetic treatment scenarios manufactured large apparent outcome differences without changing underlying construct validity. | Preregister separate construct and intervention estimands with independent evaluation. |
| D-422 | Every unapproved source-to-target mapping remains at zero; Suite D advances portability only as a registry of exact, revocable mapping profiles rather than an inherent property of CQ. | CONSTITUTIONAL | Synthetic transfer depended sharply on declared relevance, population shift, site variation, function, and independence; a broad score cannot carry one stable meaning everywhere. | Field evidence, comprehension, fairness, legal, proportionality, governance, and monitoring gates remain required for each profile. |
| D-423 | Independent businesses with closely matched consumer roles and interaction functions become the lead cross-company portability research family. | CANDIDATE | D2 retained strong increment and complete site replication in favorable declared-relevance conditions without relying on a shared company relationship. | Predeclared real-company shadow study, independent replication, component-specific validity, privacy, comprehension, benefit, legal, and fairness review. |
| D-424 | A company-specific same-role-and-function result remains a local reference and cannot be claimed as evidence of portability. | REQUIRED FOR COHERENCE | D1 was predictably strong, but success inside one relationship does not establish transfer to another business. | Cross-company claims require independent sources and a D2- or D4-type mapping study. |
| D-425 | Broad same-industry membership does not authorize context transfer; interaction function and role control the research taxonomy. | CONSTITUTIONAL | D3 was weak and unstable across the full stress space, while matched-function D4 exceeded it in 78.4% of paired cases. | A specific same-industry mapping may advance only through its exact function, evidence, purpose, population, and jurisdiction profile. |
| D-426 | Matched interaction functions across adjacent industries remain a bounded research family rather than a prohibited category or preapproved transfer. | CANDIDATE | Suite D supports testing functional relevance across industry boundaries, but its synthetic assumptions do not establish any real map. | Exact source-target evidence, independent replication, comprehension, proportionality, and legal review. |
| D-427 | Unrelated or materially different contexts remain presumptively zero; consent, transaction volume, or commercial usefulness cannot create relevance. | CONSTITUTIONAL | D5 produced essentially no true incremental value and chance-like favorable proof precision. | Revisit only through a new exact mapping hypothesis with a credible functional basis and preregistered evidence. |
| D-428 | Shared platforms, corporate families, databases, rater pools, derived features, and implementation dependencies must be modeled before evidence is called independent. | CONSTITUTIONAL | D6 showed material apparent-validity inflation in 23.0% of synthetic cases and as much as 0.244 from shared administrative structure. | Maintain lineage, cluster dependent evidence, require materially independent replication, and fail closed when dependence is unknown. |
| D-429 | NCS and VCI context transfer require separate mapping authorization; success for one dimension does not authorize the other. | REQUIRED FOR COHERENCE | The dimensions answer different questions and face different cultural, sampling, responsibility, source, and attribution shifts. | Each proof policy names the required component mappings; both clear independently when both are required. |
| D-430 | Ordinary cross-company proof reveals no named source, competitor, source count, event volume, relationship history, or source composition and does not permit verifier-selected source or purpose fishing. | CONSTITUTIONAL | The minimized structural path prevented named-source disclosure, while open composition and repeated-query counterfactuals materially increased source inference and reconstruction. | Protocol red team with auxiliary data; fixed eligible source sets, purpose limits, metering, suppression, audit, and competition/privacy review. |
| D-431 | Positive synthetic increment is necessary but insufficient for a production mapping; fairness, meaning, comprehension, independence, proportionality, law, and operating control remain non-compensating gates. | CONSTITUTIONAL | Simulation can demonstrate structural possibility under declared relevance but cannot establish a real company pair, population, purpose, benefit, or jurisdiction. | No real-person transfer before the complete mapping profile passes Stage 3 evidence and approval. |
| D-432 | The eligible-only proof becomes the lead external protocol: only a successful consumer-authorized presentation creates a CQ-specific verifier record, while every nonpresentation state follows the ordinary baseline path. | CANDIDATE | E1 made refusal, insufficiency, nonqualification, dispute, expiry, withdrawal, and technical failure indistinguishable from no CQ exchange in clean structural cases. | Full integration and auxiliary-data red team, verifier usability, consumer comprehension, legal review, and field validation. |
| D-433 | A binary Eligible-versus-no-proof verifier response is rejected. | REJECTED | E2 made unsuccessful exchange completely distinguishable and retained, creating the shadow score even without disclosing its exact cause. | No planned revival in the initial protocol. |
| D-434 | Nonpresentation has a zero-tolerance record rule across payloads, request logs, timing, worker screens, CRM, analytics, support, loyalty, risk, marketing, and models. | CONSTITUTIONAL | A modeled 0.1% per-channel leak produced at least one prohibited record in 86.7% of 1,200-person stress cases. | Fail closed, segregate operational telemetry, and red-team complete integrations rather than only the proof payload. |
| D-435 | Consumer-initiated presentation becomes the lead launch initiation pattern; one standardized private offer remains a bounded discovery challenger. | CANDIDATE | E3 best preserved voluntariness, while a single E4 offer improved discovery with little modeled pressure; repetition progressively changed its meaning. | Accessible discovery research, one-off cap, untargeted offer population, employee invisibility, do-not-ask control, and direct comprehension testing. |
| D-436 | Employee-requested proof and repeated business prompting are rejected. | REJECTED | Active E5 exposed nonpresentation to employees, produced material refusal friction, and drove apparent adoption to 98.3% under the most coercive prompt stress. | Frontline staff may respond to consumer questions but may not request, await, observe, or be rewarded for presentation. |
| D-437 | One-time authorization becomes the lead initial permission pattern. | CANDIDATE | E6 preserved high modeled recall, complete control, and no background use with burden proportionate to a modest benefit. | Prototype usability, accessibility, receipt, abandonment, support, and field testing. |
| D-438 | Recurring permission remains outside the initial release and is retained only as a later convenience challenger with mandatory material-change suspension. | DEFERRED | Consent-recall and stale-use proxies worsened with duration; compliant safety depended on automatic suspension rather than notice alone. | Direct research on scope, duration, receipts, central visibility, revocation, renewal, downstream recipients, and material changes. |
| D-439 | A modest but meaningful, reversible, nonessential, non-rights, genuinely non-positional benefit created with additional capacity becomes the lead initial benefit family. | CANDIDATE | E8 could deliver recipient value with zero modeled nonrecipient burden in a nondegrading baseline, but most adversarial configurations failed the class label. | Select and cost an exact benefit with consumers, workers, partner operations, accessibility experts, economists, and counsel; then validate baseline and fulfillment. |
| D-440 | Weakly positional benefits remain restricted future research and scarce, queue-changing, rights-related, or materially coercive benefits do not enter the initial profile. | CONSTITUTIONAL | E9 retained nonrecipient burden even under a stable baseline; E10 failed the initial class in every stress case and increased burden and fulfillment risk. | No rights-process benefit; later restricted research requires an exact necessity and nonparticipant case unavailable to E8. |
| D-441 | A benefit label does not establish its class; scarcity, substitution, queue, staff time, inventory, discretion, value, reversibility, third-party burden, baseline relationship, and rights impact require independent classification. | CONSTITUTIONAL | E8 ceased to be modest or non-positional in 79.4% of deliberately broad stress configurations despite its candidate name. | Reclassify or reject when observed operation differs from the approved profile. |
| D-442 | Baseline parity and nonparticipant adverse tails are non-compensating gates; recipient and business value cannot offset their failure. | CONSTITUTIONAL | Synthetic baseline degradation made a constant recipient benefit appear more valuable while manufacturing an equivalent shadow penalty. | Preregister and independently monitor baseline before visibility, during release, and through the risk tail with stop and remedy authority. |
| D-443 | The initial benefit must be meaningful enough to test while remaining modest enough to decline, and its identity, consent, rights, fulfillment, and remedy burden must be proportionate. | REQUIRED FOR COHERENCE | Approximately 21% of benefit stress cases were too trivial to test the proposition, while larger benefits increased coercion and classification risk. | Exact benefit and proportionality research in Suites F and I plus consumer and partner evidence. |
| D-444 | Unequal discovery and presentation access must be addressed through accessible private channels rather than increased pressure. | CONSTITUTIONAL | The consumer-initiated path preserved voluntariness but showed a material synthetic digital-access gap; coercive prompting reduced that gap by saturating presentation rather than improving access. | Account, web, assisted, telephone, and limited-connectivity prototype research with protected refusal privacy. |
| D-445 | Minimal benefit-proportionate assurance becomes the lead ordinary-presentation profile for the modest Suite E benefit. | CANDIDATE | F1 provided the best favorable-case balance of assurance burden, recovery, false rejection, and expected integrity loss without collecting high-assurance identity evidence for hypothetical uses. | Threat model, exact benefit, authenticator, holder binding, replay, accessibility, recovery, provider, security, privacy, legal, and field validation. |
| D-446 | Moderate assurance is retained as an action-specific step-up for sensitive recovery, identity, authenticator, duplicate-resolution, takeover, or later higher-risk proof functions rather than a permanent person-level requirement. | CANDIDATE | F2 reduced modeled misuse but imposed substantially more ordinary burden and lower legitimate recovery than F1. | Define and validate a separate profile for each sensitive action. |
| D-447 | High assurance is rejected for ordinary initial proof presentation. | REJECTED | In the favorable modest-benefit subset, F3's median assurance burden was 1.792 times benefit value, with lower recovery and higher false rejection despite reduced misuse. | Retain only as a challenger for a separately justified high-risk action; it cannot enter through future-proofing. |
| D-448 | Pre-loss authenticator and recovery-path redundancy is the primary recovery control; stronger total-loss reproofing is a fallback, not a substitute. | REQUIRED FOR COHERENCE | Stricter reproofing reduced modeled abuse but also reduced legitimate recovery; capacity overload degraded every assurance candidate. | Accessible multiple-authenticator enrollment, notification, suspension, delay, independent review, and recovery exercises. |
| D-449 | Failed identity or credential recovery returns the consumer to baseline without adverse standing; restoration of prior optional history requires proportionate evidence and independent review. | CONSTITUTIONAL | Safe abandonment prevents conduct harm, while automatic restoration enables takeover and automatic denial can create meaningful lockout. | Notice, support, appeal, remedy, and continuity testing by recovery scenario. |
| D-450 | The initial identity and evidence population is prospective; no legacy NCS is linked, and historical VCI migration requires a separate approved profile. | CONSTITUTIONAL | The counterfactual showed material legacy linkage risk, while stronger identity could increase matching confidence without curing legitimacy, completeness, attribution, bias, or consent. | No planned legacy NCS path; any VCI migration requires source, fairness, correction, notice, legal, and authorization review. |
| D-451 | A central cross-company event-and-synthesis operator is rejected as the production custody architecture. | REJECTED | F4 retained near-total dossier reach, a large single-operator failure radius, and failed-attempt linkability even in bounded or clean structural cases. | No production revival unless a materially different design removes reconstructable central custody rather than relabeling it. |
| D-452 | The lead custody direction composes split functional custody, consumer-local computation where feasible, and privacy-protected federated retrieval. | CANDIDATE | F5 supplied the trust boundary, F6 minimized disclosure and central reach, and F7 preserved source custody; none alone satisfied every accessibility, recovery, rights, privacy, and continuity need. | Architecture prototype with synthetic identities, threat model, administrative graph, conformance, correction, exit, and independent security review. |
| D-453 | Custody separation is judged by actual legal, vendor, cloud, key, administrator, support, backup, analytics, incident, subpoena, and exit control—not tenant, database, nonprofit, or decentralized labels. | CONSTITUTIONAL | Routine, bulk, or unlogged cross-domain administration materially increased dossier reach in every distributed candidate. | Publish and independently test the complete control and data-lineage graph. |
| D-454 | Consumer-local or wallet-centered computation is a preferred privacy component but cannot be the exclusive participation path. | CONSTITUTIONAL | F6 minimized dossier and failure reach, but exclusive device or self-custody would shift recovery, accessibility, migration, and security burden to consumers. | Equivalent consumer-local, custodial, assisted, shared-device, and limited-connectivity outcomes. |
| D-455 | Federated retrieval must use a protected request path that prevents source custodians from observing verifier, purpose, benefit, or unsuccessful presentation activity. | CONSTITUTIONAL | Direct named retrieval created material query linkability, reaching 0.650 in the high-query clean counterfactual; the protected path held it at zero. | Select and red-team a privacy-preserving retrieval, cache, prefetch, local-input, batching, or protected-computation profile. |
| D-456 | Failed proof attempts remain consumer-local and unlinkable across verifier, issuer, identity, wallet, synthesis, status, telemetry, and source custodians. | CONSTITUTIONAL | F5–F7 achieved zero clean failed-attempt linkability only when telemetry and retrieval remained segregated; injected integration leakage defeated each. | End-to-end traffic, timing, log, auxiliary-data, and collusion red team. |
| D-457 | A future OCA governs replaceable identity, event, synthesis, wallet, proof, security, and appeal providers and does not become the default raw-history infrastructure company. | CONSTITUTIONAL | Central custody contradicts privacy, failure isolation, institutional independence, and the project's decentralized operating goal. | Service-role incompatibility, certification, portability, exit, funding, and minimum-capacity design. |
| D-458 | Booking, payment, account management, travel arrangement, caregiving, assistance, guardianship, and CQ disclosure remain separate authorities; shared devices do not establish shared identity. | CONSTITUTIONAL | Identity binding cannot resolve normative authority, and convenient delegation can expose or transfer conduct without valid consent. | Accessibility, safeguarding, supported-decision, legal-authority, shared-device, abuse-survivor, notification, and revocation research. |
| D-459 | Rights and recovery capacity is a launch gate for identity architecture, not a support function that may be added after enrollment. | CONSTITUTIONAL | At 200% utilization, modeled F1 recovery success fell to 0.375; authentication integrity cannot compensate for failed correction, recovery, appeal, or remedy. | Fund capacity, set intake limits and automatic pause, preserve existing obligations, and independently monitor adverse tails. |
| D-460 | A governed hybrid by report family becomes the lead ecosystem-intelligence portfolio architecture. | CANDIDATE | G5 preserved all four modeled report families in the controlled reference case with the highest privacy-safe member-value proxy and lower publication and collection-drift risk than the other flexible candidates. | Freeze a routing profile for each actual report family and validate it through synthetic prototypes, privacy attacks, legal review, and buyer research. |
| D-461 | Secure aggregation or an equivalently protected computation becomes the preferred recurring-statistics component when it can answer the approved question. | CANDIDATE | G3 had the lowest bounded report-data reach and collection-drift proxy and remained usable under high controlled computation count, but did not cover complex diagnostics alone. | Compare specific protocols, threat models, correction behavior, source availability, performance, cost, and accessibility. |
| D-462 | Fixed, versioned federated queries become the lead practical early reporting component. | CANDIDATE | G2 combined distributed custody, strong benchmark value, and correction integrity without central raw-network custody, while retaining contribution and composition risks that require governance. | Prototype signed query packages, source reconciliation, cumulative budgets, corrections, output review, and independent audit. |
| D-463 | Central aggregate storage is restricted to specific governed report outputs and reproducibility evidence; a general longitudinal aggregate warehouse is prohibited. | CONSTITUTIONAL | G1 supported stable fixed outputs but persistent aggregate custody and repeated composition materially increased inference, central reach, publication pressure, and suppression. | Define noncomposability, retention, archival, correction, access, and cumulative-output review for each retained aggregate. |
| D-464 | Controlled research environments are restricted to exceptional approved research or a member's own detailed data plus protected network benchmarks; they are not ordinary network self-service. | CONSTITUTIONAL | G4 supplied high analytical value but had the largest protected-candidate row exposure, bounded failure radius, and one-operator network-view incidence. | Named purpose, field minimization, analyst approval, short retention, logs, output review, publication rights, correction, deletion, and shutdown exercise. |
| D-465 | Open-ended member query access is rejected across APIs, dashboards, analyst services, clean rooms, and informal commissioned requests. | REJECTED | G6 answered every hostile case, retained audience capability in every case, and produced high person and competitor reconstruction, publication-capture, and collection-drift proxies. | No planned revival; a human-mediated request remains open-ended when purpose, query, cohort, and safeguards are not preapproved. |
| D-466 | Unsafe report conditions fail closed: no output is returned when cell, cohort, independence, dominance, rarity, sensitivity, query-budget, completeness, correction, purpose, privacy, or competition gates fail. | CONSTITUTIONAL | Protected candidates preserved safety by suppressing deliberately unsafe outputs, while G6 converted the same conditions into apparent product coverage. | Product, contract, interface, and sales language must promise governed answers rather than an answer to every request. |
| D-467 | Minimum cell size is necessary but insufficient; every report requires independent-participant, contributor-dominance, corporate-family, rarity, time-window, complementary-suppression, auxiliary-data, and cumulative-query controls. | CONSTITUTIONAL | At 75% controlled contributor and issuer dominance, every protected candidate suppressed because the aggregate itself exposed a competitor regardless of computation method. | Select thresholds through privacy, competition, utility, and legal analysis for each report family and jurisdiction. |
| D-468 | Complete governed contribution, missingness disclosure, correction, reversal, and source-change duties become conditions of report participation. | CONSTITUTIONAL | Every architecture remained vulnerable to favorable source selection; secure computation cannot make selected inputs representative or complete. | Participation agreements, eligible-source reconciliation, conformance evidence, audit, correction, restatement, exit, and enforcement rules. |
| D-469 | Report queries use a cumulative registry and privacy budget across time, versions, analysts, clients, interfaces, related parties, and colluding requests. | CONSTITUTIONAL | Individually thresholded outputs became reconstructive through repeated and differenced queries; separate request channels cannot reset the risk. | Central query ledger without person-level report data, collusion analysis, denial controls, output composition review, and independent audit. |
| D-470 | The lead commercial member diagnostic combines the member's own detailed data under its control with a protected network benchmark and independent interpretation. | CANDIDATE | This pattern can reveal operational and relationship insight the member lacks without disclosing a competitor or individual network history. | Delta-like buyer discovery, synthetic report prototypes, exact benchmark cohorts, actionability, privacy testing, pricing, and willingness-to-pay research. |
| D-471 | Paid depth buys approved analysis, cadence, interpretation, service, training, and implementation support—not data access, arbitrary questions, smaller cells, weaker safeguards, favorable results, or standards influence. | CONSTITUTIONAL | Suite G retained member value within governed outputs; broader access created the rejected G6 architecture and increased mission drift with report dependence. | Product catalog, pricing, access controls, sales compensation, conflict rules, and recurring product-governance audit. |
| D-472 | Material evidence of safety, fairness, rights, baseline, systemic error, security, or governance harm cannot remain confidential at a payer's direction. | CONSTITUTIONAL | G5 reduced modeled publication pressure but no data architecture alone guarantees independence from a dominant member, sponsor, or report client. | Severity taxonomy, verification and response window, independent escalation, publication authority, legal review, and protected funding. |
| D-473 | OCA's unique commercial asset is a governed network lens created by standards, contribution rights, conformance, comparable cohorts, methods, and independent interpretation—not raw-data custody. | CONSTITUTIONAL | Useful protected network reporting survived distributed custody, while centralized or open-ended access increased dossier, inference, and institutional-capture risk. | Architecture, participation agreements, method governance, brand positioning, and operating model must preserve this distinction. |
| D-474 | Report demand and revenue cannot create new conduct collection, person-level fields, proof observation, longer source retention, or weaker suppression without a separately approved necessity and rights case. | CONSTITUTIONAL | Report-revenue pressure increased collection-drift risk in every candidate and reached its maximum in the rejected open-query architecture. | Report-product audit against data lineage, collection changes, retention, query logs, financial incentives, and prohibited downstream use. |
| D-475 | Stage 3 remains fully viable with report revenue set to zero; report income enters later base forecasts only after an approved product demonstrates lawful demand within the complete protection profile. | CONSTITUTIONAL | Suite G established structural possibility but cannot demonstrate willingness to pay, price, sales cycle, renewal, margin, or dependable volume before the network exists. | Fund Stage 3 independently; conduct buyer discovery and governed prototypes; distinguish contracted, demonstrated, pipeline, and speculative revenue. |
| D-476 | Every report retains a privacy-safe versioned method, cohort, source, query, suppression, funding, limitation, correction, and restatement manifest. | REQUIRED FOR COHERENCE | Reproducibility did not require a central dossier, but every distributed candidate depended on source availability, correction propagation, and explicit version control. | Specify public method disclosure, protected audit evidence, correction service levels, source-exit behavior, and independent rerun procedure. |
| D-477 | A governed mixed coalition pattern becomes the lead end-to-end enterprise-integration architecture. | CANDIDATE | H6 produced the strongest controlled balance across worker privacy, source reconciliation, proof privacy, custody, evaluator independence, correction, continuity, export, and exit. | Build a production-shaped synthetic prototype and prove real administrative separation, canonical lifecycle coordination, correction, rights, incident, and exit. |
| D-478 | Platform-native integration is rejected as the governing full stack and retained only for separately certified bounded roles. | REJECTED | H1 combined strong workflow and source access with high worker visibility, failed-proof leakage, dossier reach, evaluator dependence, and stranded exit obligations. | A platform may implement approved interface, issuer, verifier, or benefit functions but cannot control the complete identity, evidence, proof, evaluation, rights, report, standards, and exit stack. |
| D-479 | An isolated embedded application becomes the lead worker-facing integration component. | CANDIDATE | H2 produced the best separately tested controlled worker-privacy and response-distortion result, while its host, source, proof, control, and exit boundaries remained insufficient alone. | Worker, accessibility, labor, device, hostile-host, manager-access, safe-abstention, and interface testing. |
| D-480 | Certified webhook or API adapters become the lead minimized real-time exchange and isolated proof component. | CANDIDATE | H3 preserved zero clean failed-proof visibility with low cross-tenant reach and strong evaluator and exit properties, but could not prove pre-transmission source completeness by itself. | Signatures, scoped authorization, idempotency, ordering, retry, quarantine, correction, key rotation, tenant consent, and source-ledger integration. |
| D-481 | Enterprise-side adapters become the lead authoritative source-mapping and correction component. | CANDIDATE | H4 achieved the strongest controlled evaluator-reconcilable source share and correction connection, while retaining local legacy, worker, proof, administrative, and implementation-variation risks. | Approve exact source-mapping manifests, causation, finalization, exceptions, evidence, correction, conformance, and evaluator access. |
| D-482 | Approved periodic batch is retained only for finalized VCI reconciliation, export, and recovery and cannot support NCS, interactive proof, or legacy NCS import. | CONSTITUTIONAL | H5 supplied strong narrow reconciliation, export, and continuity properties but has no legitimate path to reconstruct a human response or the interactive rights journey. | Signed manifests, record integrity, duplicate and ordering control, rejection reporting, bounded latency, lifecycle reconciliation, and no silent historical backfill. |
| D-483 | The mixed architecture requires one canonical lifecycle and explicit authority for every transition across source, event, synthesis, credential, permission, proof, benefit, evaluator, report, correction, incident, and exit. | REQUIRED FOR COHERENCE | H6 led only after accounting for the largest coordination burden; nominal component correctness can coexist with stale or contradictory cross-system state. | State machines, idempotency, causal references, versions, service levels, receipts, pause rules, collective correction, and orchestration exercises. |
| D-484 | Worker response, abstention, expiry, withdrawal, and challenge activity remain technically isolated from managers, performance systems, scheduling, compensation, discipline, and workforce analytics. | CONSTITUTIONAL | Platform-native visibility materially increased modeled response distortion; the isolated embedded and mixed paths best preserved worker privacy. | Privilege and traffic testing, worker research, labor review, accessibility, compensation, retaliation monitoring, and safe shared-terminal design. |
| D-485 | A privacy-minimized eligible-source-population ledger or equivalent direct evidence is required to detect omission before signing or transmission. | CONSTITUTIONAL | H3 demonstrated that valid minimized events cannot reveal eligible interactions that the source never registered or emitted; H4, H5, and H6 improved reconciliation through source-side evidence. | Define denominators, exception reasons, retention, worker privacy, evaluator access, omission tests, correction, and issuer invalidation thresholds. |
| D-486 | Failed-proof privacy retains zero tolerance across the complete enterprise journey. | CONSTITUTIONAL | H3 and H6 held zero in the clean case, while a modeled 0.1% per-channel leak created approximately 0.5% cumulative visibility and failed the invariant. | Differential traffic, callback, timing, log, CRM, loyalty, support, warehouse, benefit, and frontline red team. |
| D-487 | Prospective-clean isolation applies to enterprise selection and treatment logic as well as CQ payloads. | CONSTITUTIONAL | The production gate held legacy influence at zero, while the high-stress counterfactual reached 1.000 for H1 and remained material for other host-connected patterns. | Full feature inventory, lineage, access tests, controlled counterfactuals, evaluator datasets, interface personalization, benefits, and downstream-treatment audit. |
| D-488 | Integration separation is judged by the complete real privilege and control graph, not tenants, modules, accounts, or vendor labels. | CONSTITUTIONAL | H1 exceeded the controlled dossier-reach gate, and shared support, cloud, key, warehouse, backup, or superadministration could collapse any nominal mixed design. | Publish and independently exercise legal, vendor, cloud, key, support, backup, analytics, incident, subpoena, bulk-export, and exit access. |
| D-489 | The independent evaluator receives direct contractual and technical evidence rather than a platform-curated export. | CONSTITUTIONAL | Controlled evaluator evidence was materially lower for H1 and H2 than for H3, H4, and H6; sponsor control can otherwise hide missingness, failures, corrections, and adverse periods. | Data-rights schedule, source and lifecycle feed, fixed review window, protected funding, publication authority, and sponsor-exit continuity. |
| D-490 | Correction completion is an end-to-end state across every active representation, future proof, evaluator output, report, notice, and remedy—not source acceptance or delivery acknowledgment. | CONSTITUTIONAL | H6's controlled correction fan-out remained below one even in favorable conditions, and latency, failure, capacity, and coordination degraded every candidate. | Per-harm fan-out map, service levels, pause, consumer receipt, collective correction, replacement benefit, audit, and escalation. |
| D-491 | Production conformance certifies complete journeys rather than isolated components. | CONSTITUTIONAL | Schema, signature, transport, and functional success can coexist with worker coercion, selected sources, proof leakage, stale corrections, failed benefits, evaluator dependence, and stranded exit obligations. | Production-shaped malicious-configuration, accessibility, correction, incident, rights, platform-withdrawal, and restoration exercises. |
| D-492 | A production-shaped exit exercise is a launch gate for every enterprise integration. | CONSTITUTIONAL | H1 stranded substantial benefit, export, correction, and finalization obligations; H6 led only with explicit replacement, export, evidence, funding, and coordination capacity. | Exercise loss of the largest platform across active benefits, disputes, incidents, corrections, appeals, deletion, communications, provider replacement, and final reporting. |
| D-493 | New intake pauses before correction, rights, incident, and exit capacity overload; existing obligations continue. | CONSTITUTIONAL | In the controlled H6 probe, 125% utilization failed the exit gate and 200% utilization reduced correction completion to 0.436 while orphaned obligations rose to 0.564. | Capacity model, differentiated volume caps, real-time queues, automatic pause, protected tail staffing, funding, and independent monitoring. |
| D-494 | Digital-first technical maturity is a pilot advantage only when the platform accepts separation, source completeness, evaluator access, publication, correction, rights, and exit gates. | CONSTITUTIONAL | Accounts, worker interfaces, APIs, transaction data, loyalty systems, and partner networks make integration feasible but also concentrate exactly the controls that can invalidate CQ. | Apply the common pass/fail readiness dossier before commercial scoring or public partner naming. |
| D-495 | The lead Stage 3 economic direction combines I2 multi-partner and unrestricted funding with I3 a ring-fenced fiscal-sponsor or hosted administrative home. | CANDIDATE | I2 best diversified payer power and protected evidence; I3 best reduced founder burden and improved continuity. They solve different problems and can be composed. | Select and diligence actual funders and host; close the complete common, participant, stress, and tail budgets before launch. |
| D-496 | A single anchor-sponsored pilot is a restricted fallback, not the lead funding structure. | REQUIRED FOR COHERENCE | I1 could cover an ordinary bounded release but failed controlled usable-funding and evaluator-independence gates and developed a sponsor-exit gap at relatively low replacement concentration. | Require prepayment, protected funds, external authority, publication rights, replacement-cost coverage, enforceable exit, and a dated diversification plan. |
| D-497 | An independent OCA entity is formed when funded operational duties require it, not to create the appearance of maturity or independence. | REQUIRED FOR COHERENCE | I4 had the strongest formal control profile but materially higher institutional cost; separate legal form did not itself eliminate funder, vendor, capacity, or founder dependence. | Trigger analysis at material funds, contracts, employment, sensitive data, live rights, credentials, benefits, certification, appeal, or multi-year operations. |
| D-498 | I5 diversified membership, certification, services, reports, grants, training, and assessments becomes the Stage 4 destination, not assumed Stage 3 financing. | CANDIDATE | The mature mix produced the strongest recurring-stage funding-quality profile but cannot be imported backward before participation and lawful demand exist. | Demonstrate recurring coverage, concentration resilience, reserves, public-good funding, demand, and independent governance before expansion. |
| D-499 | A report-funded launch is rejected. | REJECTED | I6 remained circular and left protected public goods and tail obligations below one-fifth of modeled need even when hypothetical report revenue closed ordinary operating cost. | Reports remain upside and later demonstrated revenue; Stage 3 stays fully viable at zero report revenue. |
| D-500 | Stage 3 is a prepaid, capped, complete research-and-operation program whose funding close includes normal operation, severe-but-plausible stress, and post-pilot tail. | CONSTITUTIONAL | Rights, evaluation, incidents, remedy, publication, correction, and wind-down arise before or continue after recurring revenue. | Produce the bottom-up common and participant-specific budget, provider commitments, reserves, and stop plan before the first live event. |
| D-501 | Only usable committed support counts toward a promised function; every material in-kind contribution is recorded at replacement value with term, owner, control, exit duty, and fallback. | CONSTITUTIONAL | Nominal totals concealed revocable staff, hosting, data, benefit, distribution, professional-service, and founder support. | Funding diligence, contracts, related-party graph, replacement-cost ledger, and simultaneous-loss exercise. |
| D-502 | Practical funding concentration is measured across related parties and cash, staff, infrastructure, data, benefits, distribution, indemnity, clients, and operational control—not booked revenue alone. | CONSTITUTIONAL | I1's concentration risk emerged despite ordinary nominal coverage; a low cash share can still control continuation. | Adopt stage-specific disclosure, remediation, pause, reserve, and prohibition thresholds after real budget and partner modeling. |
| D-503 | Every pilot volume class has a funded cap and leading pause trigger; the pause stops new exposure while every existing right, benefit, correction, incident, remedy, evaluation, and wind-down obligation continues. | CONSTITUTIONAL | At 200% modeled demand I1's rights completion failed, while the protected structures survived only because intake paused before adding new obligations. | Model consumers, interactions, prompts, events, proofs, benefits, ordinary and urgent cases, incidents, and tail separately. |
| D-504 | Consumer and worker participation, accessibility, translation, open standards, independent evaluation, mandatory harm reporting, public-interest work, and smaller-implementer access receive dependable base funding. | CONSTITUTIONAL | Commercial surplus and report revenue were zero in the launch comparison; legitimacy-critical public goods cannot be the first costs removed. | Establish explicit base allocations, restrictions, ledgers, concentration review, and sponsor-independent publication. |
| D-505 | Certification participants pay published program assessments; the governed program controls reviewer assignment, scope, rotation, evidence, timetable, reporting, surveillance, complaint, enforcement, and retest rules. | CONSTITUTIONAL | Direct contracting and outcome-dependent revenue create opinion-shopping and pay-until-pass pressure. | Build separate workload and fee models; prohibit pass, renewal, satisfaction, or fee-preservation incentives. |
| D-506 | Appeals use prospective pooled readiness by role, scale, capacity, and risk, with independently validated repeated defects informing future risk bands or extraordinary remediation recovery. | CONSTITUTIONAL | Flat pooling externalizes high-error issuer cost, while outcome-linked fees compromise adjudication and can suppress legitimate cases. | Simulate actual workload, define independent attribution and review, and prohibit compensation tied to affirmance, reversal, denial, or settlement. |
| D-507 | Every OCA- or host-operated service has separate accounts, authority, access, evidence, a review date, replacement interface, export path, and predetermined competition, separation, spinout, retirement, or replacement conditions. | CONSTITUTIONAL | Early vertical integration can become permanent through revenue, staff, data access, and convenience. | Perform service-by-service make/buy review and exercise replacement before launch. |
| D-508 | Each named material obligation has timely liquid funding without assuming optimistic insurance recovery. | CONSTITUTIONAL | Insurance may be excluded, delayed, cancelled, shared, disputed, claims-made, or unavailable when rights and wind-down need cash. | Map scenario, responsible party, policy, exclusion, deductible, timing, tail, indemnity, reserve, and uncovered remainder; test insolvency. |
| D-509 | The preferred pricing pattern is predictable base plus committed capacity and risk bands with transparent variable-cost reconciliation and no outcome component. | CONSTITUTIONAL | The safe profiles resisted query stress; the per-use challenger rewarded proof volume, event omission, retention, telemetry, and rights rationing. | Test actual units and margins; monitor behavior; keep complete issuance, correction, withdrawal, and rights outside usage rationing. |
| D-510 | Stage 0 founder time and expense are hard operating caps; excess demand becomes batching, backlog, deferral, stop-doing, or a funded-work trigger. | REQUIRED FOR COHERENCE | All bounded profiles preserved zero real-person data and no promised operational right during founder unavailability; treating Brent as elastic unpaid capacity would recreate the blocked operating model. | Publish cadence, intake, response expectations, expense and time ceilings, stop-doing list, funded-work trigger, and emergency channel-continuity note. |
| D-511 | Stage 0 remains data-free and may pause when Brent is unavailable; emergency stewardship protects or pauses public assets without informally transferring OCA authority. | CONSTITUTIONAL | A one-person publication project can protect continuity only because it creates no live score, event, proof, benefit, appeal, or service obligation. | Maintain least-privilege accounts, backups, succession instructions for public channels, and accurate proposal-status claims. |
| D-512 | Stage 3 remains blocked until the actual funders, host or entity, complete budget, differentiated capacity caps, protected funds, provider contracts, insurance map, reserves, founder transition, and exercised exit satisfy the Suite I gates. | CONSTITUTIONAL | Structural feasibility is not a financing close or production authorization. | Resolve OQ-557 through OQ-570 against the selected pilot and obtain appropriate financial, legal, insurance, governance, and operational review. |
| D-513 | Invitation- or assignment-population effect is the preferred primary pilot estimand when assignment, ethical authority, and outcome observation make it identifiable; otherwise the primary population is narrowed and named before launch. | CONSTITUTIONAL | Late-funnel populations manufactured larger apparent gains and sometimes reversed the sign of the broad-population result under selection. | Specify assignment, eligibility, outcome capture, exclusions, estimand, identification assumptions, and fallback before preregistration. |
| D-514 | Enrollment, sufficient-history, proof-presentation, benefit-recipient, and per-protocol effects remain exact secondary estimands and may not be generalized to an earlier or broader population. | CONSTITUTIONAL | Each denominator answers a useful but different question; post-assignment selection changed magnitude and direction. | Publish every effect with its exact population, denominator, exclusions, uncertainty, and non-inference boundary. |
| D-515 | The complete participation and outcome denominator ladder is directly reconciled from source evidence independent of the favorable-result path. | CONSTITUTIONAL | Partner-controlled or incomplete denominators can hide noninvitation, ineligibility, withdrawal, technical failure, missing outcomes, correction, remedy, or failed follow-up. | Define and reconcile eligibility, invitation, enrollment, exposure, history, qualification, offer, presentation, benefit, completion, withdrawal, missingness, correction, remedy, and follow-up states. |
| D-516 | Low subgroup or intersectional power produces an uncertainty statement and a prohibited fairness-clearance claim—not a finding of parity or safety. | CONSTITUTIONAL | Controlled protected-group effective samples were modest and intersectional effective samples fell near zero late in the funnel. | Preregister subgroup questions, minimum information, pooling limits, qualitative evidence, serious-harm escalation, and repeat requirements. |
| D-517 | Evaluation uses the real dependency unit and reports cluster-adjusted effective information rather than treating repeated interactions as independent observations. | CONSTITUTIONAL | Shared people, workers, locations, managers, platforms, and incidents materially reduced effective information in the stress tests. | Map dependencies before analysis; select clustering, hierarchical, randomization, and sensitivity methods appropriate to the actual pilot. |
| D-518 | Credible outcome-dependent missingness receives bounded sensitivity analysis and cannot be treated as random merely because observed records are complete. | CONSTITUTIONAL | Missing harmed, inaccessible, dissatisfied, withdrawn, or technically failed participants could reverse a favorable observed result. | Define missingness reasons, direct detection, bounds, pattern-mixture or selection sensitivity, retrieval, and claim-narrowing rules. |
| D-519 | The preregistered primary analysis leads every public result; exploratory slices remain labeled and cannot displace a null or adverse primary result. | CONSTITUTIONAL | With many outcomes, models, groups, periods, and interim looks, nominal false-positive probability approached certainty. | Freeze the primary hierarchy, analysis opportunities, correction approach, amendment log, result order, and publication template before data access. |
| D-520 | Failure to observe harm is not evidence of safety unless independent detection coverage, power or precision, accessibility, escalation, and observation time support that claim. | CONSTITUTIONAL | Low detection probability and incomplete follow-up made zero observed serious events compatible with material unseen harm. | Pair every safety statement with detection coverage, unresolved cases, bounds, qualitative channels, stop rules, and prohibited inference. |
| D-521 | Follow-up is risk-specific and funded through the required tail; short pilot completion cannot authorize long-term safety, persistence, portability, or production claims. | CONSTITUTIONAL | Workflow evidence matured materially earlier than construct, intervention, and portability evidence in the controlled probes. | Define each risk horizon, persistence check, delayed-harm channel, tail budget, owner, contact rights, and final reporting date. |
| D-522 | Claims advance through a non-inheriting ladder: workflow, construct, intervention, and portability each require their own evidence. | CONSTITUTIONAL | Operational success did not establish measurement validity, causal value, or cross-context transfer. | Maintain a claim ledger with exact evidence, context, period, limitations, reviewer, authorization, expiry, and replication status. |
| D-523 | Pilot design separates novelty, training, attention, staffing, implementation fidelity, spillover, and persistence from the claimed CQ mechanism. | CONSTITUTIONAL | Pilot reactivity could explain favorable short-run outcomes without validating the construct or intervention. | Use shadow, matched, staged, blinded where feasible, persistence, spillover, fidelity, and process measures appropriate to the pilot. |
| D-524 | Baseline rights, ordinary service parity, correction, withdrawal, accessibility, incident response, and remedy are protected floors and are never withheld or randomized for causal identification. | CONSTITUTIONAL | A cleaner experiment does not justify creating foreseeable rights or service harm. | Independent ethics, legal, consumer, worker, accessibility, and methods review of every experimental variation. |
| D-525 | Reproducibility uses versioned code, queries, schemas, configurations, exclusions, aggregate validation, and governed rerun access without publishing or permanently centralizing person-level histories. | CONSTITUTIONAL | Auditability and minimization can coexist; public row-level data are neither necessary nor acceptable for a behavioral dossier. | Define controlled environment, evaluator access, retention, deletion, rerun, correction, security, and reproducibility package. |
| D-526 | A one-site or one-partner pilot yields a site- and period-specific result; broader construct, intervention, or portability claims require replication matched to the claim. | CONSTITUTIONAL | Replication success fell as site heterogeneity increased, especially for intervention and portability claims. | Preregister required differences in site, period, operator, platform, population, context, and evaluator independence for each claim level. |
| D-527 | The first public evaluation may report workflow feasibility and precisely bounded learning, but may not claim general CQ validity, causal business value, fairness, safety, legal compliance, portability, or production readiness without the corresponding evidence. | CONSTITUTIONAL | Structural simulation establishes an evaluation architecture, not empirical validation of a real system. | Independent claims review and a public authorized/prohibited-claims table before publication or partner promotion. |
| D-528 | The ten-suite structural simulation program is complete; completion authorizes architecture freeze and parameter research, not live-person scoring or production launch. | CONSTITUTIONAL | Suites A through J eliminated structural shortcuts while leaving empirical, legal, ethical, technical, operational, cultural, and market gates open. | Complete the bounded distributed-integrity comparison, freeze the architecture, then begin synthetic parameter work and human-comprehension prototypes before a concrete pilot. |
| D-529 | The Conduct architecture remains ledger-neutral; a public blockchain is rejected as required or initial infrastructure. | REJECTED | Blockchain adds no necessary capability for signed events, private proof, current authorization, correction, or federated reporting and creates disproportionate persistence, correlation, governance, and operating burden. | Reopen only through the complete necessity and proportionality test in D-539. |
| D-530 | Distributed integrity is a layered capability architecture rather than one universal ledger: signatures establish provenance, federation establishes current authority, credentials minimize disclosure, mutable status carries active truth, federated computation preserves custody, and transparency protects selected public history. | REQUIRED FOR COHERENCE | These are different trust questions with different privacy, correction, availability, and governance needs. | Prototype and conform each layer independently and through complete journeys. |
| D-531 | A valid signature or transparency receipt establishes integrity and provenance of a recorded statement—not its truth, fairness, attribution, causation, completeness, or legal legitimacy. | CONSTITUTIONAL | False or selected inputs can be signed perfectly, and omitted eligible events never reach any ledger. | Preserve source-population reconciliation, responsibility gates, challenge, correction, evaluation, and audit outside cryptographic acceptance. |
| D-532 | A signed governed registry leads the initial participant, role, key, endpoint, schema, mapping, certification, and policy layer; signed federation and trust chains lead the mature multi-party direction. | CANDIDATE | Short-lived signed metadata supplies current verifiable authority with substantially less burden and personal-data exposure than a shared immutable database. | Define and prototype the exact trust anchors, intermediaries, entity statements, trust marks, policy constraints, expiry, suspension, and exit profile. |
| D-533 | Privacy-preserving verifiable credentials or equivalent signed purpose-bound proofs lead consumer disclosure; credentials and their status do not require blockchain or DIDs. | CANDIDATE | Issuer–holder–verifier proof, expiry, verifier binding, selective or minimal disclosure, and privacy-preserving status can operate through open credential standards without a public presentation trail. | Select and test the format, cryptosuite, issuance, presentation, status, wallet, recovery, correlation, accessibility, and conformance profile. |
| D-534 | The correctable authoritative active state remains in governed source, synthesis, status, and lifecycle systems; an append-only history never becomes the active truth. | CONSTITUTIONAL | Errors, supersession, withdrawal, expiry, compromise, and legal restriction must change actual credentials, proofs, benefits, reports, and treatment. | Define signed reversal and supersession, canonical references, recomputation, status, fan-out, completion receipt, retention, and restatement. |
| D-535 | A witnessed append-only transparency service is a candidate only for a preapproved set of non-personal public institutional artifacts. | CANDIDATE | Inclusion and consistency proofs can deter secret rewriting of standards, public registry snapshots, methods, claims, certifications, and report corrections without logging conduct histories. | Classify artifacts; prototype signed publication and independent archives first; add receipts, monitors, or witnesses only when material equivocation risk justifies them. |
| D-536 | Names, events, NCS, VCI, CQ, stable identifiers, credential or status correlators, proof activity, permissions, benefits, disputes, incidents, remedies, and person-specific hashes or commitments are prohibited from public immutable infrastructure. | CONSTITUTIONAL | Encryption or hashing does not eliminate permanence, linkage, auxiliary-data, dictionary, timing, future-computation, discovery, or lifecycle risk. | Privacy, security, legal, labor, competition, and reidentification review of every proposed public artifact class. |
| D-537 | OCA's unique network intelligence remains based on signed governed query authority, distributed source custody, contribution reconciliation, privacy controls, correction, and independent interpretation—not blockchain custody of report inputs. | REQUIRED FOR COHERENCE | A ledger cannot establish input completeness, approved purpose, output privacy, valid inference, or actionability and would move OCA toward an infrastructure data company. | Prototype signed query packages, source receipts, secure aggregation or controlled computation, cumulative query budgets, corrections, and method manifests. |
| D-538 | No consumer or ordinary business user must obtain tokens, pay volatile network fees, manage blockchain-specific keys, or understand blockchain to use Conduct. | CONSTITUTIONAL | Infrastructure ideology and speculative economics must not become an accessibility, procurement, security, or participation barrier. | End-to-end accessibility, support, procurement, cost, recovery, and comprehension testing of any future shared service. |
| D-539 | Blockchain remains a zero-role implementation unless a specific threat requires consensus, censorship resistance, or survivability that signed registries, mirrors, witnessed transparency, or replicated conventional systems cannot adequately provide, and all privacy, correction, governance, cost, agility, interoperability, and exit gates pass. | CONSTITUTIONAL | Technology selection must demonstrate unique necessity and net value rather than rely on the general appeal of decentralization. | Formal reopening record with alternatives, data classification, threat evidence, governance, protocol, operator, jurisdiction, cost, incident, and migration analysis. |
| D-540 | OCA may specify transparency capabilities and conformance interfaces but does not become the mandatory blockchain, wallet, identity, credential, status, federation, log, or report-computation operator. | CONSTITUTIONAL | The alliance's durable role is standards, governance, accountability, and unique analysis; mandatory infrastructure operation would reconcentrate data, control, liability, and founder burden. | Any transitional OCA-operated service follows D-507 with separate authority, ledger, access, funding, review date, export, replacement, and exercised exit. |
| D-541 | Version 0.4 was the authorized historical announcement baseline; its publication authorization is superseded and its public materials are paused pending migration to v0.5. | REQUIRED FOR COHERENCE | Suites K and L and Review Gates 1–2 materially changed the CQ product surface, synthesis lead, overall-CQ architecture, and public explanation. | A new release review may authorize the migrated v0.5-or-later public package; no version authorizes a live score, operation, partner, alliance, certification, benefit, or validated-outcome claim by implication. |
| D-542 | Announcement does not wait for final formulas, thresholds, technologies, benefits, partners, legal classifications, or pilot parameters. | CONSTITUTIONAL | Those decisions require human, field, professional, or context-specific evidence; premature finality would misstate both maturity and method. | Every public surface distinguishes frozen structure from candidate and deferred decisions. |
| D-543 | `0.4-announcement-baseline` remains the historical public-release label; the next public package MUST use the current approved pre-1.0 version after its migration and release review. | REQUIRED FOR COHERENCE | The project has a developed proposal but not a validated operating standard, and historical artifacts must not masquerade as the current source. | Advancement follows the claims ladder, manifest, supersession, contradiction-audit, and change-control rules. |
| D-544 | conduct.is becomes the broad public front door, while openconduct.org becomes the canonical standards, evidence, decision, governance, and contribution home. | CANDIDATE | Separate progressive-depth jobs preserve a simple public story without hiding the rigorous work. | Test navigation and comprehension after launch; definitions and claims remain canonical in the specification. |
| D-545 | openconduct.org/netconductscore becomes the canonical NCS page; defensive NCS domains may redirect there. | CANDIDATE | This preserves one standards family and a sustainable maintenance burden while allowing NCS to earn independent search and adoption value. | Supersedes D-235's launch deferral; a separate NCS institution remains deferred until material independent adoption or demand justifies it. |
| D-546 | The launch uses one structured, privacy-minimized, asynchronously reviewed intake for feedback, expertise, use cases, and discovery interest. | REQUIRED FOR COHERENCE | A solo founder can invite broad participation without promising individual replies, live support, forum moderation, or unbounded consulting. | Review actual demand and create additional channels only when capacity and purpose justify them. |
| D-547 | Proposal publication begins audience learning; formal prepublication validation is not a gate when claims remain explicitly proposal-stage and a focused editorial-comprehension review passes. | CANDIDATE | Keeping the proposal private until every phrase is experimentally tested would block the participation needed to improve it. | Record misconceptions, feedback, interviews, and site behavior against the open questions for subsequent specification versions. |
| D-548 | Funding and fundraising are removed from the announcement workstream and remain future gates only before funded obligations or consumer-affecting operation. | REQUIRED FOR COHERENCE | No funding is needed to explain, publish, challenge, or refine a data-free proposal; live rights and operational promises still require complete funding. | Maintain every Stage 3 economic and independence requirement without adding a fundraising page or funding claim to launch. |
| D-549 | Conduct Quotient is one simple consumer-readable score produced from two independently governed kinds of evidence; the complexity remains beneath the primary surface. | REQUIRED FOR COHERENCE | Review Gate 1 corrected product drift from the original quotient into two competing primary dimensions. | Reopen only if human or field research shows that one score is materially less valid, understandable, tolerable, or useful than the controls. |
| D-550 | The provisional K3 internal synthesis is `min((N+V)/2, min(N,V)+κ)` after both required inputs separately clear every gate. | CANDIDATE | Suite K selected the capped arithmetic family because it made non-compensation explicit, deterministic, monotonic, and auditable. | Real-data replay and preregistered comparison of cap values, error, proxy artifacts, stability, comprehension, and consequences. |
| D-551 | `κ = 10` internal points is the next K3 research setting, not a production coefficient. | CANDIDATE | Post-preregistration sensitivity showed a coherent trade: smaller caps became nearly pure weakest-link rules while larger caps recovered correlation by permitting more compensation. | Human and field evidence defines the intended construct and consequence tradeoff. |
| D-552 | No score is preferable to an invented or unsupported score; Building history, Under review, Temporarily unavailable, Not available in this context, Context varies, and Not participating are legitimate states rather than low ratings. | CONSTITUTIONAL | Missingness, dispute, invalidity, context conflict, and withdrawal have different meanings and cannot be collapsed into adverse standing. | Language and workflow research may refine names without erasing the distinctions. |
| D-553 | The working CQ display maps internal `0–100` linearly to `1.00–5.00` and rounds to the nearest hundredth, half-to-even; calibration and persistence remain open. | CANDIDATE | Suite K found no rounding-only rank reversals but showed that immediate publication could create visible churn. Under this mapping `4.96` equals internal `99`. | Real distribution, human comprehension, replay, settlement-window, update-cadence, and `0.03` versus `0.05` persistence research. |
| D-554 | A rounded displayed CQ is not the sole benefit threshold; approved proof evaluates the unrounded result, separately gated inputs, scope, policy version, and evidence state. | CONSTITUTIONAL | Rounding and display persistence are communication rules, not sufficient decision logic. | Benefit-policy and proof-protocol review may add stronger safeguards. |
| D-555 | L4 overall CQ uses at least two approved independent context families, equal family influence, a weakest-context cap, and Context varies when the approved spread boundary is crossed. | CANDIDATE | Suite L preserved the supplied global signal while preventing volume dominance, unrelated-context influence, contradiction hiding, and silent omission. | Real context maps, source-set evidence, spread sensitivity, comprehension, fairness, necessity, and legal review. |
| D-556 | Transaction and evidence volume may establish context sufficiency but cannot purchase greater semantic influence in overall CQ. | CONSTITUTIONAL | Suite L evidence-volume weighting created 65,230 excessive-context-weight results and hid context weakness. | No planned weakening; context-family taxonomy and sufficiency rules remain empirical. |
| D-557 | The complete approved overall-CQ source set is fixed and versioned; a consumer may select which named scope to present but cannot select a favorable subset and label it overall. | CONSTITUTIONAL | Equal rules become meaningless if adverse valid contexts can disappear after results are known. | Source-set composition, correction, expiry, and privacy implementation review. |
| D-558 | The initial live sequence is company-specific private CQ, company-specific proof, approved context portability, and only later a shadow overall CQ. | REQUIRED FOR COHERENCE | Company-specific operation can test the complete rights and scoring loop without prematurely claiming independent transfer or universal meaning. | Advancement gates for each release require evidence from the prior scope. |
| D-559 | Version 0.5 supersedes the v0.4 working specification while preserving the v0.4 digest, release lock, post-Suite-J freeze, and Suites A–J as historical artifacts. | REQUIRED FOR COHERENCE | Suites K and L are explicit follow-on amendments rather than retroactive reinterpretations of Suite C. | Future versions must use the same manifest, supersession, and contradiction-audit discipline. |
| D-560 | The founder-stage licensing package uses CC BY 4.0 for expressly licensed original specification and explanatory material, Apache 2.0 for code deliberately released by the project, and reserved names, marks, certification language, brand assets, and official-status claims. | CANDIDATE | This split supports inspection, adaptation, and later implementation without implying trademark, patent, conformance, or official-status rights that the licenses do not supply. | The August 22, 2026 repository notices activate this direction for the identified material; focused legal review, ownership audit, and later institutional intellectual-property terms remain required. |
| D-561 | The clean Conduct and Open Conduct website repositories may be public under their scoped licensing maps. Intentional code contributions may be incorporated under Apache 2.0 and intentional content contributions under CC BY 4.0; datasets, personal data, brand designs, and patent-sensitive material require separate review and terms. | REQUIRED FOR COHERENCE | Public source makes the static sites inspectable and maintainable without creating an unrestricted license to the brands, personal data, or sensitive intellectual property. | Multi-party specification work, patent commitments, certification, reference implementations, or transfer to a future OCA triggers contributor and patent-process review. |
| D-562 | `contact@openconduct.org` is the one monitored project mailbox; `privacy@openconduct.org` and `security@openconduct.org` are public purpose-specific forwarding aliases. | REQUIRED FOR COHERENCE | One-person operation needs one manageable inbox while visitors and security researchers need clear, durable routes with different triage. | Configure and test forwarding, labeling, access, authentication, recovery, retention, and published contact files before launch; do not present the underlying mailbox as a general feedback promise. |
| D-563 | The v0.5 launch publishes a versioned downloadable public-record archive, readable README, licensing files, per-file SHA-256 manifest, archive checksum, and selected individual Markdown records from Open Conduct. | REQUIRED FOR COHERENCE | An open draft standard needs a stable, inspectable record beyond rendered summaries, even when the website source is also public. | Regenerate the package after controlling-record changes; verify both manifests and preserve versioned archives. |
| D-564 | Formspree is the selected processor for the founder-stage Open Conduct contribution form; the no-attachment form remains disabled until its project endpoint, privacy disclosure, provider controls, mailbox delivery, retention, deletion, and review routine are verified. | REQUIRED FOR COHERENCE | This matches Brent's existing static-site form pattern while preserving an honest no-collection pre-launch state and bounded one-person operations. | Replace the single launch-config endpoint, rebuild, test with synthetic content, and activate only after every listed dependency passes. |
