Update log
- 7 September 2026 - Second edition. The programmes are now presented under their public names: the discipline described here is the working core of FxChain SAA - Sovereign Assurance & Attestation (internal reference Q372-SAA); the rooms and ledgers belong to FxChain Mission Control - Governed Operations & Evidence Custody. Internal references appear only as reference lines. See the three programmes.
- 7 September 2026 - First edition. An editorial account of the discipline applied on the development line, drawn from internal acceptance records, review transcripts and adjudication verdicts. It is a description of method, not an external audit, and it names no internal identifiers.
Short answer
A change to FxChain is not accepted because a test suite passed. It is accepted because a frozen candidate - a set of bytes named by its digest - has been rebuilt from those bytes, attacked by mutations aimed at the authority it claims to bound, reviewed in an isolated room by a reviewer who never received the builder's framing, and adjudicated against written law by a seat that was not the builder. Only then does the sealed line move, and later work may add witnesses to it but may never re-cut it.
The reason is simple and was learned the hard way: a run in which every conformance check passes can still leave the paths that grant or refuse authority untouched. Results were being verified; power was not. The discipline exists to verify power.
Two consequences follow. First, refusal is an outcome with the same standing as acceptance - a refused candidate is sealed with its reasons, and every record that cited it is reached by the supersession. Second, the instruments used to judge a candidate are themselves candidates: an instrument that cannot be parsed, reproduced or attacked has no authority to pass anything.
What is established, what is in development, what is not claimed
| Claim | Status | Basis | Limit |
|---|---|---|---|
| Builder and adjudicator are separate seats, never held by the same party for the same candidate | Proven today | Internal acceptance records on the development line | Internal practice, not an externally audited control |
| Candidates are frozen and named by digest before anything is judged | Proven today | Frozen-candidate manifests and verdicts | Applies to the examined candidates, not to every historical change |
| Reproduction from the frozen bytes precedes any mutation or verdict | Proven today | Reproduction-gate records | A reproduction proves the bytes build; it does not prove they are right |
| Authority paths are attacked with mutations, not only exercised by tests | Proven today | Mutation campaigns against accepted instruments | Coverage is what the campaign reached, not a universal guarantee |
| Cold review runs in isolated rooms with the reviewer's own instruments | Proven today | Room transcripts and recorder outputs | Isolation is checked by mechanism, not assumed; a subagent is not isolation |
| Refusals and publication failures are sealed with reasons and reached by supersession | Proven today | Sealed refusal records and recovery dossiers | Sealed history is preserved; it is not publicly reproducible |
| The discipline is described publicly at the level of method | In development | This dossier, FxChain Foundations and the programmes page | Public programme names are proposed; identifiers appear only as reference lines |
| Independent external audit of the discipline | Later gate | Not yet commissioned | No third party has certified the process |
| Public reproduction packages for acceptance records | Later gate | Not available | Records remain private |
| That the discipline is enforced by a running public network | Not claimed | No public deployment exists | Local development line only |
Why a green run is not enough
Most engineering organisations treat a fully green run as the end of the argument. On the development line it became the beginning of one. A candidate that passed every conformance check was submitted to a mutation campaign: small, deliberate corruptions of the code that decides who may cause what. A meaningful number of those mutations survived. The tests exercised what the code produced; they did not exercise whether the code was allowed to produce it.
conformance run: every check passes
+-----------------------------------------------------------+
| checks --> ok ok ok ok ok ok ok ok ok ok ok ok ok ok ok |
+-----------------------------------------------------------+
|
what the checks exercised what they never touched
+----------------------+ +----------------------+
| result paths | | authority paths |
| what happens | | who may cause it |
+----------------------+ +----------------------+
^
a mutation here survives a green run
Figure 1 - A green run verifies results. It says nothing about the paths that grant or refuse authority unless those paths are attacked directly.
This is the same distinction the protocol draws at runtime. FxChain judges a claim's admissibility before any power exists; the acceptance discipline judges a change's authority before it exists on the sealed line. The engineering process is held to the protocol's own axiom: proof before power.
Three rules follow from the lesson, and each one is applied literally.
- A claim of coverage must not exceed its mechanism. If a check claims to cover a boundary, the boundary is tested negatively: the check must fail when the boundary is broken. A check that cannot fail proves nothing.
- An empty success is not an answer. A tool that prints nothing and exits zero has not passed; it has been silent. Silence is treated as failure until the gated quantity is printed and read.
- A count carries its population. A number reported by an instrument is meaningless without the population it was counted over. Both are printed, always.
The roles: builder, cold reviewer, adjudicator, founder
The discipline is organised around seats rather than people. A seat is a role with a written law, an entry condition and an output that is sealed. The rule that gives the whole structure its force is that no seat may be held by the party that produced the thing the seat judges.
+----------+ +---------------+ +-------------+ +----------+
| builder | --> | cold reviewer | --> | adjudicator | --> | founder |
+----------+ +---------------+ +-------------+ +----------+
makes and examines, in weighs review ratifies,
freezes the isolation, the and attack amends or
candidate frozen bytes only against the law refuses
law: the reviewer never receives the builder's framing; the reviewer
fills in its own independence profile, which the builder may not
pre-fill; the adjudicator does not build.
Figure 2 - Four seats, four outputs, and a separation that is checked rather than trusted.
The builder produces the candidate and freezes it. From that moment the builder cannot touch the bytes under review. If the review finds a defect, the builder produces a new candidate; the old one is superseded, not edited.
The cold reviewer receives only the frozen candidate and the written law - not the builder's explanation, not the builder's environment, not the builder's history. The reviewer's first act is to state its own independence: what it has seen before, what it has not, and what it is therefore eligible to judge. A reviewer who helped conceive a plan is ineligible to review its execution, and says so.
The adjudicator weighs the review and the attack results against the law and issues one of three verdicts: pass, hold with a list of defects, or refuse with reasons. The adjudicator does not repair; it decides.
The founder ratifies, amends or refuses the adjudication. Ratification is a recorded, one-use act that binds a specific digest. A ratification that names no digest binds nothing.
Automated agents hold seats under the same law. An agent that built a candidate may not review it; an agent reviewing a candidate runs the law's probe, not its own. Internal reviews carried out by agents are counted for what they are - internal - and never presented as independent external audit.
The candidate lifecycle
Every candidate passes through the same gates in the same order. The order is not a convention; it is what makes each step's evidence mean something.
change
|
v
+---------------------+ freeze first: the bytes under review
| frozen candidate | never change again; they are named by
| digest + manifest | digest, not by path and not by time
+----------+----------+
v
+---------------------+ rebuild from the frozen bytes before
| reproduction gate | anything is judged; an empty success
+----------+----------+ is a failure, not a pass
v
+---------------------+ mutate authority, not only results; a
| attack | boundary that has not been attacked is
+----------+----------+ a claim, not a law
v
+---------------------+ isolated room, reviewer's own
| cold review | instruments, transcript recorded
+----------+----------+
v
+---------------------+ verdict against the written law:
| adjudication | PASS, HOLD or REFUSE, each sealed
+----------+----------+
v
+---------------------+ the sealed line moves; later work adds
| ratified and sealed | witnesses and never re-cuts history
+---------------------+
Figure 3 - The lifecycle of a candidate. Each gate consumes the output of the previous one and nothing else.
Freeze before verifying. The bytes under review are frozen and named by their digest before any verification starts. Verification of something that can still change is verification of nothing in particular. A frozen artifact also cannot see its producer: it carries no reference to the checkout, the machine or the session that made it, so a review cannot be steered by where the candidate came from.
Ordering is proven by digest containment, not by time. When the discipline needs to show that one artifact came after another, it shows that the later one contains the digest of the earlier one. File timestamps are not evidence; they can be set, copied and lost.
The reproduction gate comes before mutation. Before a candidate is attacked, it is rebuilt from its frozen bytes in a clean environment. If it does not rebuild, there is nothing to attack. If the rebuild produces different bytes, the candidate is not the candidate.
Attack before law. A boundary the candidate claims to enforce - "only this seat may cause that effect" - is attacked before it is accepted as law. Mutants that cross the boundary are counted, named and listed. A surviving mutant is a defect in the boundary or in the instrument that watches it, and the candidate does not pass until one of the two is fixed.
Cold rooms: isolation you can check
A cold review is only cold if the reviewer cannot reach the builder's world. This is not a matter of good faith; it is a matter of mechanism. The room is built so that the only thing inside it is the frozen candidate, the written law and the reviewer's own instruments, and the only thing that comes out is a transcript.
outside the room | inside the room
builder's checkout and caches | frozen candidate, by digest
builder's environment and history | the written law
builder's framing and explanations | the reviewer's own instruments
| a recorder, armed separately
------- no path in ------> x | transcript = the only output
Figure 4 - A cold room is defined by what cannot enter it. Its recorder is started by hand, on purpose: an unarmed recorder is a review that never happened.
Two lessons shaped the rooms. The first is that a subagent is not isolation: a helper process spawned from the builder's session inherits the builder's world, however carefully it is instructed. Isolation is a property of the environment, not of the prompt. The second is that the recorder is armed separately from the room. A review whose transcript was not recorded did not take place, whatever the reviewer remembers of it.
The reviewer's instruments deserve their own sentence. On the development line, defects in the instruments used to judge candidates have outnumbered defects in the candidates themselves. A probe that matches its own pattern, a scanner that counts the wrong population, a waiter that reports success when the thing it waits for never started - each of these was found by treating the instrument as a candidate: frozen, reproduced, attacked. An instrument that cannot be parsed has no authority to pass anything.
Evidence is admitted by law, not by assertion
The discipline keeps a ledger, and a row enters it only if the evidence behind it passes an admission test. The test does not ask whether the evidence is convincing. It asks whether the mechanism that produced it reaches the gate it names.
claim ----> evidence ----> admission test ----> ledger row
"X holds" digest of the does the mechanism status
bytes that reach the gate it basis
show it names? was the limit
negative case run?
a count carries its population . protected drift and canonical
drift are two counters, never summed . a digest identifies bytes,
it does not by itself prove that a process ran correctly
Figure 5 - From claim to ledger row. The admission test is applied to the mechanism, not to the claim.
Some of the admission rules read like tautologies until the day they are needed.
- A control must reach the gate it names. A rule that says "this cannot happen" is admitted only when the mechanism that prevents it has been shown to sit on the path where it would happen.
- Controls are added, never widened. A new control is a new, narrow mechanism. Widening an inherited permission to cover a new case is not a control; it is a hole with a name.
- A self-hash must name its preimage population. An artifact that carries its own digest must say exactly which bytes the digest covers. Otherwise the digest can be true of something else.
- Two drifts are two counters. Drift of protected files and drift of the canonical tree are counted separately and never added, because a change can be in one, the other, both or neither, and the sum hides which.
- Documentation is fact-checked against the check, not the grant. A document that says "the gate verifies X" is admitted only if the gate's code verifies X. What the design granted is not what the mechanism does.
Refusal is a first-class outcome
The protocol seals denials alongside results; the discipline does the same for candidates. An adjudication produces one of three verdicts, and all three are sealed.
+-- PASS ---> sealed and witnessed on the line
verdict -----+-- HOLD ---> defects listed; a new candidate is built;
| the held one is superseded, not edited
+-- REFUSE -> sealed refusal with reasons; supersession
reaches every record that cited it
Figure 6 - Three verdicts, three sealed outcomes. A supersession reaches every row it touches, or it is not a supersession.
A refused candidate is not deleted. Its refusal, with reasons, becomes part of the record that the next candidate must answer. When a publication act fails after a merge - an artifact that cannot be published exactly as sealed, a toolchain that no longer reproduces the bytes - the failure is itself recorded as an institution: a dossier states what was attempted, what was observed and what is required before another attempt. Erasing a failed attempt would be re-cutting history, which the line does not permit.
Two rules keep this honest. A supersession reaches every row it touches: when a candidate is superseded, every record that relied on it is marked, so that no downstream claim quietly rests on a withdrawn one. And refusal is not proof of unusability: a refused candidate is asked one more question - what is the minimal edit that removes the refusal? - because a refusal that cannot name its remedy is a refusal that cannot be checked.
What the discipline does not establish
- It does not establish that FxChain is secure, complete or ready for production. It establishes that each accepted change was frozen, reproduced, attacked, reviewed in isolation and adjudicated by a separate seat.
- It is internal. The reviewers, including automated ones, are not independent external auditors, and no third party has certified the process.
- Its coverage is what its campaigns reached. A mutation campaign lists the boundaries it attacked; it does not certify the boundaries it did not.
- Its records are private. The ledgers, transcripts and verdicts exist and are sealed; they are not published, and this dossier does not reproduce them.
- Instruments have defects. The discipline's answer is to treat instruments as candidates, not to claim they are correct.
Verdict
The acceptance discipline is the protocol's axiom applied to the protocol's own construction: nothing acquires authority on the sealed line before its truth has been frozen, reproduced, attacked and judged by a seat that did not produce it. Its most important property is not any single gate but the fact that the gates are ordered, that each consumes only the sealed output of the previous one, and that refusal leaves the same kind of record as acceptance.
What can be said publicly is that this discipline is practised, that its rules were learned from concrete failures rather than adopted from a manual, and that the failures themselves are on the record. What cannot be said is that anyone outside has verified it. That gate is later, and it is stated as such.
Frequently asked questions
Why is ordinary code review not enough?
Code review examines a diff a reviewer can see, in an environment the reviewer shares with the author. It does not freeze the bytes, does not rebuild them in isolation, and does not attack the authority they claim. It is a useful habit and a weak instrument. The discipline keeps review and adds the gates that review cannot provide.
Does an automated reviewer count as independent?
No. An automated agent holds a seat under the same law as a person - it may not review what it built, it runs the law's probe rather than its own, and its transcript is recorded - but it remains an internal reviewer. Nothing in the discipline presents an internal review, human or automated, as an external audit.
What happens when the instruments themselves are wrong?
They are treated as candidates. An instrument is frozen, reproduced and attacked like any other artifact, and a defective instrument's verdicts are withdrawn by supersession. On the development line, instrument defects have been more frequent than defects in the code the instruments judged.
Is any of this visible from outside?
This dossier and FxChain Foundations describe the method. The records are private. A public reproduction package and an external audit are later gates, listed above as such.
How does this relate to the protocol's own refusals?
Directly. The protocol seals a denial with its own root so that what it refused can be audited like what it did. The discipline seals a refused candidate with its reasons so that what the line rejected can be examined like what it accepted. The same idea, applied to two different objects.
Which programmes are behind this?
Two. The discipline is the working core of FxChain SAA - Sovereign Assurance & Attestation, whose future capability is to make verifiable the identity of a software version, the controls applied to it and the evidence that supports its qualification - while the admission decision stays with each organisation. The rooms, recorders and ledgers belong to FxChain Mission Control - Governed Operations & Evidence Custody. Both names are public presentation names; their internal references keep their historical meaning in the archives. The three programmes sets out the correspondence.
Sources and methodology
This dossier separates what the internal records establish from what they do not. Its statements about practice rest on frozen-candidate manifests, reproduction-gate records, mutation-campaign results, cold-room transcripts, adjudication verdicts and sealed refusal records on the development line. Statements about lessons rest on the incidents that produced them, which are on the same record.
None of these records are reproduced here, and none are publicly available. The reading is editorial: it describes mechanism and rule, and it withholds identifiers, counts and dates that belong to the records themselves. Figures shown anywhere on this portal come from a single dated snapshot; none are introduced by this dossier.
Related reading on this portal: The three programmes for the public names, internal references and statuses; FxChain Foundations for what the local foundations establish and what their evidence does not; Technology for the eight organs and the sequence a claim follows.