Platform contracts

Guardrails, schemas, samples, verifiers, and blocked authority footers.

This route owns the platform contract wall. Contracts define structure and gates; they do not prove public runtime or signal truth.

8 contractsSUPPORT_ONLYRUNTIME_SIGNAL_BLOCKED

Public inspection layer

source truthseparate
runtime truthseparate
signal truthseparate
evidence truthseparate
public proofseparate

Platform owner route

Contract wall

Each contract keeps its blocked-authority footer visible so support structure cannot become a stronger public claim.

Deterministic analyst-support case packet

SOAR Case Packet v0

Analyst-support structure: sanitized refs, checklist, response gates, blocked actions, and an AI support summary.

Schema

Packet schema

contracts/schemas/soar-case-packet-v0.schema.json

Example

Sample packet

contracts/examples/soar-case-packet-v0.sample.json

Verifier

Packet verifier

scripts/verify-soar-case-packet-v0.py

SOAR packet models analyst support, not response authority.

Blocked authority

  • Live Torq / SOAR is not claimed.
  • Production SOC and response automation are blocked.
  • Containment, closure, and suppression execution are blocked.
  • Autonomous SOC and AI / analyst disposition are blocked.

Append-only seed ledger

AutoSOC Case Ledger v0

An append-only seed ledger that demonstrates constraints — every case is human-review required.

Schema

Schema logic

scripts/ho_factory.py

Example

Seed ledger

evidence/autosoc-case-ledger-v0.sqlite

Total cases 1Human review required 1Public-safe state 0Proof BLOCKEDDeterministic close BLOCKED

Append-only seed ledger demonstrates constraints, not live SOC operation.

Blocked authority

  • Live runtime ledger is not claimed.
  • Proof promotion is blocked.
  • Case closure is blocked.

Bounded reviewer status / plan emitter

Detection Factory Controller v0

Emits bounded reviewer status and plan packets for HO-DET-001, HO-DET-011, HO-DET-012, and ID-DET-001..004.

Schema

Controller doc

docs/factory/DETECTION_FACTORY_CONTROLLER_V0.md

Schema

Controller schema

contracts/schemas/detection-factory-controller-v0.schema.json

Verifier

Controller script

scripts/ho_factory.py

HO-DET-011 reports STATE_DRIFT_REVIEW_REQUIRED.

The controller emits bounded status and plan packets. It reports state; it does not promote proof or publish evidence.

Blocked authority

  • Website updates and proof promotion are blocked.
  • Evidence publishing and PR creation are blocked.
  • Merge and generated-output writing are blocked.

Bounded manual gate receipt

Local GPU Triage Gate

A bounded manual gate receipt exists for local GPU triage support.

Schema

Pipeline doc

docs/factory/LOCAL_GPU_TRIAGE_PIPELINE_V0.md

Example

Support schema / sample

local-gpu-triage-support-v0 schema / sample

Verifier

Triage verifier

scripts/verify_local_gpu_triage.py

Gate status GITHUB_ACTIONS_RUN_PASSEDMetadata PRIVATE_OPERATIONAL

Local GPU support is private support-only infrastructure. The public website may describe the contract boundary, not public runtime proof.

Blocked authority

  • Model execution in CI is not claimed.
  • Prompt execution in CI and artifact upload are blocked.
  • Public proof, production, autonomous, and AI-approved claims are blocked.

Support-only labor contract

Offline LLM Triage Support Contract

AI may summarize sanitized facts, identify missing context, draft questions, and map fields to the checklist.

Schema

Support contract

docs/autosoc/OFFLINE_LLM_TRIAGE_SUPPORT_CONTRACT.md

Offline LLM is support-only labor; human review remains authority.

Blocked authority

  • Disposition decision and approval are blocked.
  • Proof promotion and case closure are blocked.
  • Public-safe marking and production claim are blocked.

Private support-only receipt packet

Local LLM Runtime Receipt

A private support-only local LLM runtime receipt exists as a structure / boundary packet.

Schema

Receipt schema

contracts/schemas/local-llm-runtime-receipt.schema.json

Example

Valid sample

contracts/examples/local-llm-runtime-receipt.valid.sample.json

Verifier

Private evidence index

validation-side private-runtime-evidence-index.json

A private boundary packet — never a public runtime claim.

Blocked authority

  • Public-safe state is not claimed.
  • Runtime-active public proof and signal-observed status are blocked.
  • AI-approved disposition is blocked.

Non-promotional platform guardrail

HO-DET-001 Runtime Contract

Platform runtime contract enforcement exists as a non-promotional guardrail.

Schema

Contract schema / sample

ho-det-001-runtime-contract schema / sample

Verifier

Contract verifier

scripts/verify-ho-det-001-runtime-contract.py

PROMOTION_STATUS BLOCKEDRUNTIME_ACTIVE falseSIGNAL_OBSERVED falseAI_DECIDED_DISPOSITION false

A guardrail that holds promotion blocked — it does not raise the ceiling.

Blocked authority

  • Promotion beyond CONTROLLED_TEST_VALIDATED is blocked.
  • Runtime-active and signal-observed status are not claimed.

Case-packet guardrail

HO-DET-011 Case Packet

A case-packet guardrail exists for HO-DET-011.

Schema

Packet schema / sample

ho-det-011-case-packet schema / sample

Verifier

Packet verifier

scripts/verify-ho-det-011-case-packet.py

Packet shape 6-case (pinned)Validation / proof state 17 fixturesDrift STATE_DRIFT_REVIEW_REQUIRED

Pinned to an older 6-case shape while validation / proof state records 17 fixtures. The drift surfaces as STATE_DRIFT_REVIEW_REQUIRED and is not silently normalized.

The packet shows the drift instead of hiding it.

Blocked authority

  • Promotion is blocked while drift review is required.
  • Public-safe runtime proof is not claimed.

Boundaries

Supplemental contract pointers

Contract pointer

Runtime Truth Spine

Private runtime/evidence boundary route. Keep as a pointer only unless public wording is separately approved.

Private runtime evidence is not public-safe material.

Contract pointer

Telemetry Coverage Contract v0

Aligns HO-NDR-001 and HO-PIPE-001 as visibility and route-integrity contracts.

Contract status does not prove live telemetry or public signal proof.