# NousPolis Independence & External Trust

NousPolis must describe independence precisely. Separate prompts, processes, agents, or model providers do not automatically create institutional independence when they share the same principal, credentials, writable storage, or incentives.

## 1. Separation Levels

Use the following vocabulary for review, verification, evaluation, integrity, and governance claims.

### L0 — Role Separated
Different declared roles/prompts, but same runtime, principal, credentials, and infrastructure.

This reduces some cognitive coupling but provides no institutional independence.

### L1 — Process Separated
Separate workflow instances or services with distinct logs/state, but controlled by the same principal and ultimately mutable with the same authority.

### L2 — Credential Separated
Separate credentials/permissions prevent one process from directly modifying another's protected state, but credentials remain controlled by the same principal.

### L3 — Principal Separated
A different human or institution controls the relevant credential/decision and cannot be unilaterally compelled through the original principal's ordinary access.

### L4 — Externally Independent
Principal separation plus materially different incentives/governance and sufficient information/access to perform the claimed audit/attestation without depending on the evaluated system's permission to report unfavorable results.

## 2. Required Claim Format

Do not say only "independent review," "independent verifier," or "independent audit." State the achieved level and concrete separation, e.g.:

`L2 credential-separated verifier; same founder principal`

or

`L4 external reviewer; separate institution and credentials`.

Public claims must not imply a higher independence level than achieved.

## 3. External Trust Anchors

An external trust anchor is a component whose relevant property cannot be silently rewritten by the active NousPolis principal/runtime.

Examples:

- public or third-party timestamp/transparency log;
- separate human countersigner with independently controlled credential;
- externally hosted immutable archive or evaluation set;
- independent institutional auditor;
- third-party legal/ethics authority where applicable.

The system must state exactly what property the anchor attests. A timestamp service can witness a hash; it does not attest that the underlying policy is correct.

## 4. Maturity Requirements

### N0
No institutional-independence claim is permitted. NousPolis is founder-controlled architecture work.

### N1
At least one external integrity witness is required for the governing release. Internal reviewers/verifiers must state their actual separation level.

### N2
Material public advisory releases require at least one principal-separated review/evaluation channel or equivalent externally controlled evidence of integrity/correction capability.

### N3
Security, legal, research-ethics, and high-impact pilot authorization must include external/principal-separated review appropriate to the domain.

### N4+
Constitutional control, appeals, maturity certification, and root credentials require genuine multi-party principal separation. Founder-only governance is insufficient.

## 5. Independence Dimensions

Independence is multidimensional. Record where relevant:

- principal/control independence;
- credential independence;
- infrastructure/storage independence;
- model/provider independence;
- data/evidence independence;
- methodological independence;
- financial independence;
- evaluation-set independence;
- publication/reporting independence.

One dimension does not imply the others.

## 6. Same-Principal Limitations

A same-principal system may still benefit from role/process/credential separation, but it must assume the principal can ultimately coordinate or override those components unless a technical control prevents it.

Therefore same-principal separation reduces accidental failure and some local bias; it does not establish external legitimacy or tamper-proof self-audit.

## 7. External Evaluation

At least part of the institutional evaluation stack should eventually be outside the writable control of the system being evaluated. Possible designs include:

- held-out benchmark cases controlled by another principal;
- third-party expert review;
- resolved real-world outcomes;
- public reproducibility challenges;
- externally administered security tests.

MIRS, the orchestrator, and release tooling may consume these results but may not silently rewrite them.

## 8. Conflict and Disclosure

Reviewers, evaluators, funders, signers, and authorities must disclose material conflicts. Independence is not binary: a separate principal with strong financial dependence may still have compromised incentives.

## 9. Bootstrap Honesty

During N0/N1, founder control is expected. The correct response is transparent labeling, not simulated institutional independence.

NousPolis should earn stronger independence claims only when the corresponding separation actually exists.
