# Disposition — Second Architectural Adversarial Review

**Date:** 2026-08-09  
**Review:** `reviews/ARCHITECTURAL_ADVERSARIAL_REVIEW_2_2026-08-09.md`  
**Target reviewed:** NousPolis v0.1 post-first-remediation architecture  
**Disposition authority:** founder/bootstrap authority under `CONSTITUTIONAL_BOOTSTRAP.md`  
**Independence claim:** none. This disposition is founder-controlled N0 governance, not external certification.  
**Status:** remediation accepted as architecture input; this document records disposition after remediation and does not rewrite the chronology of the original review.

## 1. Review Status

The second review is accepted as a high-value adversarial input, not as self-certifying proof of institutional safety.

Its central diagnosis is adopted:

> After substantive and procedural power are constrained, **definitional/classification power** becomes a major control surface. Safeguards that activate only when something is labelled `Level 3+`, `material`, `credible`, `catastrophic`, or `Class D` require explicit governance.

The review's second central diagnosis is also adopted:

> Same-principal roles, prompts, agents, and storage do not create external independence or a root of trust.

## 2. Critical Findings Disposition

### C1 — Undefined impact Level 0–5 master switch
**Disposition: REMEDIATED IN SPECIFICATION.**

Added `CLASSIFICATION.md` with concrete Level 0–5 criteria, protected escalation floors, second-pass classification, conservative escalation, audit records, and explicit challenge rights.

### C2 — Dependency materiality unowned / unaudited
**Disposition: REMEDIATED IN SPECIFICATION.**

`DEPENDENCY_PROPAGATION.md` now assigns materiality to governed classification, defaults uncertain active Level-3+ dependencies to `MODERATE`, requires audit trails for downgrades, adds review deadlines/queue governance, and prevents anti-abuse controls from silently suppressing verified material dependencies.

### C3 — Forecast resolution post-hoc malleability
**Disposition: REMEDIATED IN SPECIFICATION.**

`FORECASTING.md` now freezes metric, reference class, conditions, target date, scoring method, resolution rule, invalidation clauses, and data-source rule at issuance. Changes create a new version rather than rewrite the scored forecast.

### C4 — Methodology dependence invisible to evidence lineage
**Disposition: REMEDIATED IN SPECIFICATION.**

`EVIDENCE.md` now tracks source, dataset/sample, methodology, measurement-instrument, replication, and institutional/authorship dependence. `ONTOLOGY.md` adds corresponding relationships.

### C5 — Append-only log self-attested
**Disposition: REMEDIATED AS N1 REQUIREMENT; NOT YET IMPLEMENTED.**

`INTEGRITY.md` and `ENFORCEMENT_SUBSTRATE.md` now require an external witness/timestamp/commitment for governing release hashes before N1. This cannot be satisfied by Markdown and remains an executable N1 task.

### C6 — Singular key custody
**Disposition: STAGED REMEDIATION.**

`INTEGRITY.md` explicitly distinguishes N0/N1 founder bootstrap control from later multi-party authority. N1 requires root/agent credential separation, recovery controls, external witnessing, and root-use logs. N2/N3 strengthen signer separation; N4+ requires multi-party constitutional control.

This avoids falsely claiming institutional independence during the N1 research phase.

### C7 — Prompt-injection boundary only a sentence
**Disposition: REMEDIATED AS N1 REQUIREMENT; NOT YET IMPLEMENTED.**

`SECURITY.md` now specifies typed origin/taint metadata and a runtime authorization boundary under which retrieved/model-generated text has zero authority to grant capabilities, change governing state, expose secrets, or authorize protected writes.

`ENFORCEMENT_SUBSTRATE.md` makes this a mandatory N1 technical control and test target.

### C8 — No enforcement substrate / weak N1 gate
**Disposition: REMEDIATED IN SPECIFICATION; IMPLEMENTATION IS THE FIRST N1 TASK.**

Added `ENFORCEMENT_SUBSTRATE.md`. `MATURITY_MODEL.md` now prohibits N0 -> N1 until the enforcement report passes required schemas, state-machine guards, classification controls, evidence states, security boundaries, forecast immutability, invariant tests, integrity witness, observability, and Review Authority requirements.

Founder declaration alone is no longer sufficient.

### C9 — "Independent" has no external referent
**Disposition: REMEDIATED IN TERMINOLOGY AND MATURITY RULES.**

Added `INDEPENDENCE.md` with L0 role-separated, L1 process-separated, L2 credential-separated, L3 principal-separated, and L4 externally independent levels.

Unqualified independence claims are prohibited. N1 requires an external integrity witness; stronger principal separation is required as maturity/authority grows.

## 3. High Findings Disposition

### H1/H2 — Class D precedence inversion / conflicting taxonomies
**REMEDIATED.** The sole A–D taxonomy now lives in `GOVERNING_PRECEDENCE.md`. `META_GOVERNANCE.md` and `ENGINEERING_GOVERNANCE.md` defer to it. Changing taxonomy definitions or classification thresholds is automatically Class D.

### H3 — `NORMATIVE_MAP` recommendation smuggling
**REMEDIATED.** `DECISION_AGGREGATION.md` forbids a normative map from silently ranking frameworks unless authorized; ranking/recommendation changes artifact type.

### H4 — aggregation threshold selection ungoverned
**REMEDIATED.** Level-3+ aggregation method, threshold, tie/no-consensus rule, weighting, correlation treatment, and authority requirement are frozen before final outputs.

### H5 — catastrophic-risk prohibition without replacement rule
**REMEDIATED.** `DECISION_AGGREGATION.md` now defines a positive Maximum-Scrutiny Procedure; `RISK.md` binds catastrophic cases to it.

### H6 — appeals standing deferred
**REMEDIATED.** `APPEALS.md` now contains bootstrap standing rules for factual/procedural, affected-stakeholder, and institutional challenges.

### H7 — "credible" minority undefined
**REMEDIATED.** `CLASSIFICATION.md` defines credibility and `APPEALS.md` provides a concrete dissent-preservation test.

### H8 — panel construction non-reproducible
**REMEDIATED IN SPECIFICATION.** Level-3+ panels require candidate-pool snapshot, eligibility rules, constraints, algorithm, seed/tie-break, conflicts, and replacement provenance.

### H9 — no-single-controller bypass by sequential proxies
**REMEDIATED IN SPECIFICATION.** `SEPARATION_OF_POWERS.md` prevents one model family from satisfying all protected Level-4/5 control roles merely through multiple instances/role labels.

### H10 — human-subject experiment ethics gate missing
**REMEDIATED.** Added `RESEARCH_ETHICS.md`; `EXPERIMENTS.md` now binds real human-subject work to external human/legal ethics authorization at the relevant maturity.

### H11/H12 — uncertainty-vector laundering / no deep-uncertainty off-ramp
**REMEDIATED.** `UNCERTAINTY.md` defines load-bearing dimension rules and explicit `DISTRIBUTION_NOT_DEFENSIBLE`, `DEEP_UNCERTAINTY`, and related states.

### H13/H14 — retraction deadlines / evidence boundary honor-system
**REMEDIATED IN SPECIFICATION.** `EVIDENCE.md` defines a typed evidence state machine; `DEPENDENCY_PROPAGATION.md` defines materiality-based review handling/deadlines. Executable enforcement remains an N1 task.

### H15/H16 — reference-class and condition gaming
**REMEDIATED.** `FORECASTING.md` requires predeclared reference-class governance and immutable conditional/resolution rules.

### H17 — stable IDs hide concept drift
**REMEDIATED.** `ONTOLOGY.md` adds `SPLIT_FROM`, `MERGED_FROM`, `SEMANTIC_SUCCESSOR_OF`, and `SCOPE_CHANGED_FROM`; engineering migrations must use them where meaning changes materially.

### H18 — scenario plausibility capture
**REMEDIATED.** `SCENARIOS.md` now distinguishes central, plausible alternative, adversarial, low-probability/high-impact, and upside classes and governs exclusion of severe stress cases.

### H19 — theory-of-change claims need no testability
**REMEDIATED.** `THEORY_OF_CHANGE.md` requires observable/falsifying/discriminating implications or explicit non-testability with uncertainty penalty for load-bearing causal claims.

### H20 — commercial provider privacy assurances unverifiable
**PARTIALLY REMEDIATED / ACCEPTED AS EXTERNAL DEPENDENCY RISK.** `SECURITY.md` requires provider assurance review and safer/local routing when the required assurance cannot be established. Provider behavior cannot be proven solely by NousPolis and remains a provider/legal trust issue.

### H21 — evaluation by evaluated party
**PARTIALLY REMEDIATED / MATURITY-STAGED.** `INDEPENDENCE.md`, `REVIEW_AUTHORITY.md`, `MIRS_INDEPENDENCE.md`, and N2+ maturity requirements create principal-separated/external evaluation requirements. N0 remains founder-controlled by design.

### H22 — funding independence / choice of law
**PARTIALLY REMEDIATED / MATURITY-STAGED.** NousPolis does not claim institutional independence at N0/N1. Existing funding/legal modules remain applicable; public/experimental maturity requires stronger separation and jurisdiction-specific legal review.

### H23 — adversarial review absent from separation of powers
**REMEDIATED.** Added `REVIEW_AUTHORITY.md`; `SEPARATION_OF_POWERS.md` now includes Review Authority as a distinct authority domain and requires separate disposition chronology.

## 4. Medium Findings Disposition

The final pass also addresses the major Medium findings:

- templates are now explicitly bound by name or schema-equivalent in governing workflows;
- added `DOMAIN_REVIEW_MATRIX.md` for minimum cross-domain reviews;
- strengthened invariant-implementing language from advisory to mandatory in key enforcement documents;
- `LOOPS.md` now includes stabilization, oscillation, entrenchment, and marginal-value stop rules;
- MIRS challenger allocation now has a measurable N1 default;
- emergency status follows governed classification;
- Procedural Auditor blocking findings now block protected completion pending disposition;
- `EXPLORATION.md` now has a protected N1 default allocation with deficit/restoration rules;
- dependency review flags have priority/aging/backlog controls;
- Class-C protected prompt changes require adversarial review;
- founder root compromise requires an external/principal-separated trust check before declaring integrity restored.

## 5. Residual N0 Reality

The specification is stronger, but NousPolis remains N0. The following protections are **not yet executable merely because they are written**:

- machine-readable constitutional manifest;
- typed schemas;
- classification engine;
- state-machine guards;
- runtime origin/taint enforcement;
- permission policy engine;
- evidence state enforcement;
- reproducible panel constructor;
- immutable forecast service;
- invariant CI/attack suite;
- cryptographic release/witness pipeline;
- executable provenance/event log;
- automated Review Authority / maturity evidence.

These form the N1 enforcement project.

## 6. Final Disposition

**All nine Critical findings are closed at the specification level or explicitly converted into mandatory N1 infrastructure requirements.**

No Critical finding is considered "solved" by prose when its remedy inherently requires infrastructure or an external trust anchor.

This disposition supports freezing **NousPolis Architecture v0.1 / N0** and beginning implementation with one objective only:

> **Build and verify the minimum enforcement substrate required to pass the N0 -> N1 gate.**
