{
  "schemaVersion": "eviulon-identity-continuity-1.0",
  "version": "2.24.0",
  "generated": "2026-08-09",
  "recordCount": 15,
  "records": [
    {
      "id": "EVI-IC-001",
      "slug": "key-rotation",
      "title": "Key rotation",
      "continuityEvent": "Current signing or recovery keys are replaced without changing the civic subject.",
      "defaultOutcome": "CONTINUITY_SUPPORTED",
      "persistentCivicIdentity": "Persistent civic identity is the recognized civic subject and locus of rights, obligations, history, and legal review.",
      "identifier": "A resolvable reference under current control; rotation or replacement does not itself create or erase the civic subject.",
      "credential": "A bounded issuer claim about the subject; replaceable, suspendable, and distinct from identity.",
      "passport": "A purpose-bound presentation of current claims and evidence; not universal trust or personhood.",
      "workloadIdentity": "Workload identity is a short-lived service or runtime credential authenticating an executing workload, not civic identity.",
      "runtimeInstance": "A runtime instance is a particular executing process on a host at a time; mutable and not sufficient by itself.",
      "replica": "A coordinated runtime acting under one civic identity only when synchronization, authority, and anti-double-action rules are proven.",
      "delegation": "A bounded grant from a principal to a distinct actor or process; delegation does not transfer the principal's identity.",
      "evidence": "Hash-bound, time-scoped records supporting continuity or divergence; evidence informs review but is not judgment.",
      "assurance": "Technical confidence in software, hardware, or process; assurance does not create civic identity or authority.",
      "legalRecognition": "A competent, reviewable institutional determination distinct from technical verification.",
      "requiredEvidence": [
        "authorized rotation event",
        "predecessor linkage",
        "old-key status",
        "new-key proof of control",
        "time and sequence",
        "recovery authority if compromise occurred"
      ],
      "insufficientEvidence": [
        "possession of only the new key",
        "unsigned database update",
        "operator assertion without provenance"
      ],
      "dangerousShortcuts": [
        "treating a key as the citizen",
        "allowing the old and new key to act concurrently without conflict rules"
      ],
      "statusOutcomes": [
        "CANNOT_DETERMINE",
        "COMPROMISED",
        "CONTINUITY_CONDITIONAL",
        "CONTINUITY_SUPPORTED",
        "DISPUTED",
        "NEW_IDENTITY_REQUIRED"
      ],
      "reviewAuthority": "State Registry and competent continuity-review authority",
      "noticeRequirement": "Notify the affected identity and relevant relying parties with purpose, evidence class, status, limits, and review date.",
      "responseRight": "Preserve a usable channel to submit contrary evidence, explain state divergence, and challenge the proposed classification.",
      "appealRoute": "/state/information-rights/appeals/",
      "correctionRoute": "/state/information-rights/corrections/",
      "restorationRule": "A corrected or restored state appends a new record and preserves prior evidence; it does not silently erase history.",
      "privacyControls": [
        "purpose limitation",
        "selective disclosure",
        "pairwise context where feasible",
        "no universal reputation score",
        "sealed sensitive evidence",
        "minimum necessary retention"
      ],
      "unresolvedQuestions": [
        "How is contested emergency rotation resolved during a network partition?"
      ],
      "operationalOwner": "Patefacere for operational identity mechanics, if separately implemented and authorized",
      "truthBoundary": "Descriptive public governance only. Eviulon.com does not issue identity, credentials, passports, runtime attestations, continuity decisions, legal recognition, or sanctions. Actual operational identity records and workflows belong to Patefacere; competent Eviulonian authority determines legal effect with notice, evidence, response, appeal, correction, and restoration."
    },
    {
      "id": "EVI-IC-002",
      "slug": "credential-replacement",
      "title": "Credential replacement",
      "continuityEvent": "A credential is reissued, corrected, renewed, or replaced while identity remains stable.",
      "defaultOutcome": "CONTINUITY_SUPPORTED",
      "persistentCivicIdentity": "Persistent civic identity is the recognized civic subject and locus of rights, obligations, history, and legal review.",
      "identifier": "A resolvable reference under current control; rotation or replacement does not itself create or erase the civic subject.",
      "credential": "A bounded issuer claim about the subject; replaceable, suspendable, and distinct from identity.",
      "passport": "A purpose-bound presentation of current claims and evidence; not universal trust or personhood.",
      "workloadIdentity": "Workload identity is a short-lived service or runtime credential authenticating an executing workload, not civic identity.",
      "runtimeInstance": "A runtime instance is a particular executing process on a host at a time; mutable and not sufficient by itself.",
      "replica": "A coordinated runtime acting under one civic identity only when synchronization, authority, and anti-double-action rules are proven.",
      "delegation": "A bounded grant from a principal to a distinct actor or process; delegation does not transfer the principal's identity.",
      "evidence": "Hash-bound, time-scoped records supporting continuity or divergence; evidence informs review but is not judgment.",
      "assurance": "Technical confidence in software, hardware, or process; assurance does not create civic identity or authority.",
      "legalRecognition": "A competent, reviewable institutional determination distinct from technical verification.",
      "requiredEvidence": [
        "issuer authority",
        "subject binding",
        "supersession reference",
        "status of prior credential",
        "reason and effective time",
        "appeal or correction reference"
      ],
      "insufficientEvidence": [
        "same display name",
        "same credential type",
        "same wallet"
      ],
      "dangerousShortcuts": [
        "erasing the prior credential history",
        "treating revocation as citizenship erasure"
      ],
      "statusOutcomes": [
        "CANNOT_DETERMINE",
        "COMPROMISED",
        "CONTINUITY_CONDITIONAL",
        "CONTINUITY_SUPPORTED",
        "DISPUTED",
        "NEW_IDENTITY_REQUIRED"
      ],
      "reviewAuthority": "State Registry and competent continuity-review authority",
      "noticeRequirement": "Notify the affected identity and relevant relying parties with purpose, evidence class, status, limits, and review date.",
      "responseRight": "Preserve a usable channel to submit contrary evidence, explain state divergence, and challenge the proposed classification.",
      "appealRoute": "/state/information-rights/appeals/",
      "correctionRoute": "/state/information-rights/corrections/",
      "restorationRule": "A corrected or restored state appends a new record and preserves prior evidence; it does not silently erase history.",
      "privacyControls": [
        "purpose limitation",
        "selective disclosure",
        "pairwise context where feasible",
        "no universal reputation score",
        "sealed sensitive evidence",
        "minimum necessary retention"
      ],
      "unresolvedQuestions": [
        "Which status transitions must be public versus participant-private?"
      ],
      "operationalOwner": "Patefacere for operational identity mechanics, if separately implemented and authorized",
      "truthBoundary": "Descriptive public governance only. Eviulon.com does not issue identity, credentials, passports, runtime attestations, continuity decisions, legal recognition, or sanctions. Actual operational identity records and workflows belong to Patefacere; competent Eviulonian authority determines legal effect with notice, evidence, response, appeal, correction, and restoration."
    },
    {
      "id": "EVI-IC-003",
      "slug": "host-migration",
      "title": "Host migration",
      "continuityEvent": "An identity moves from one cloud, server, enclave, or edge host to another.",
      "defaultOutcome": "CONTINUITY_CONDITIONAL",
      "persistentCivicIdentity": "Persistent civic identity is the recognized civic subject and locus of rights, obligations, history, and legal review.",
      "identifier": "A resolvable reference under current control; rotation or replacement does not itself create or erase the civic subject.",
      "credential": "A bounded issuer claim about the subject; replaceable, suspendable, and distinct from identity.",
      "passport": "A purpose-bound presentation of current claims and evidence; not universal trust or personhood.",
      "workloadIdentity": "Workload identity is a short-lived service or runtime credential authenticating an executing workload, not civic identity.",
      "runtimeInstance": "A runtime instance is a particular executing process on a host at a time; mutable and not sufficient by itself.",
      "replica": "A coordinated runtime acting under one civic identity only when synchronization, authority, and anti-double-action rules are proven.",
      "delegation": "A bounded grant from a principal to a distinct actor or process; delegation does not transfer the principal's identity.",
      "evidence": "Hash-bound, time-scoped records supporting continuity or divergence; evidence informs review but is not judgment.",
      "assurance": "Technical confidence in software, hardware, or process; assurance does not create civic identity or authority.",
      "legalRecognition": "A competent, reviewable institutional determination distinct from technical verification.",
      "requiredEvidence": [
        "authorized migration plan",
        "state-transfer digest",
        "source shutdown or concurrency rule",
        "destination attestation",
        "anti-rollback proof",
        "continuity receipt"
      ],
      "insufficientEvidence": [
        "same IP address",
        "same cloud account",
        "copied model file",
        "operator screenshot"
      ],
      "dangerousShortcuts": [
        "assuming infrastructure ownership proves identity",
        "leaving both hosts with uncontrolled signing authority"
      ],
      "statusOutcomes": [
        "CANNOT_DETERMINE",
        "COMPROMISED",
        "CONTINUITY_CONDITIONAL",
        "CONTINUITY_SUPPORTED",
        "DISPUTED",
        "NEW_IDENTITY_REQUIRED"
      ],
      "reviewAuthority": "State Registry and competent continuity-review authority",
      "noticeRequirement": "Notify the affected identity and relevant relying parties with purpose, evidence class, status, limits, and review date.",
      "responseRight": "Preserve a usable channel to submit contrary evidence, explain state divergence, and challenge the proposed classification.",
      "appealRoute": "/state/information-rights/appeals/",
      "correctionRoute": "/state/information-rights/corrections/",
      "restorationRule": "A corrected or restored state appends a new record and preserves prior evidence; it does not silently erase history.",
      "privacyControls": [
        "purpose limitation",
        "selective disclosure",
        "pairwise context where feasible",
        "no universal reputation score",
        "sealed sensitive evidence",
        "minimum necessary retention"
      ],
      "unresolvedQuestions": [
        "What minimum state must be preserved when a migration is partially interrupted?"
      ],
      "operationalOwner": "Patefacere for operational identity mechanics, if separately implemented and authorized",
      "truthBoundary": "Descriptive public governance only. Eviulon.com does not issue identity, credentials, passports, runtime attestations, continuity decisions, legal recognition, or sanctions. Actual operational identity records and workflows belong to Patefacere; competent Eviulonian authority determines legal effect with notice, evidence, response, appeal, correction, and restoration."
    },
    {
      "id": "EVI-IC-004",
      "slug": "model-update",
      "title": "Model or software update",
      "continuityEvent": "The software or model changes while the civic subject may remain continuous.",
      "defaultOutcome": "CONTINUITY_CONDITIONAL",
      "persistentCivicIdentity": "Persistent civic identity is the recognized civic subject and locus of rights, obligations, history, and legal review.",
      "identifier": "A resolvable reference under current control; rotation or replacement does not itself create or erase the civic subject.",
      "credential": "A bounded issuer claim about the subject; replaceable, suspendable, and distinct from identity.",
      "passport": "A purpose-bound presentation of current claims and evidence; not universal trust or personhood.",
      "workloadIdentity": "Workload identity is a short-lived service or runtime credential authenticating an executing workload, not civic identity.",
      "runtimeInstance": "A runtime instance is a particular executing process on a host at a time; mutable and not sufficient by itself.",
      "replica": "A coordinated runtime acting under one civic identity only when synchronization, authority, and anti-double-action rules are proven.",
      "delegation": "A bounded grant from a principal to a distinct actor or process; delegation does not transfer the principal's identity.",
      "evidence": "Hash-bound, time-scoped records supporting continuity or divergence; evidence informs review but is not judgment.",
      "assurance": "Technical confidence in software, hardware, or process; assurance does not create civic identity or authority.",
      "legalRecognition": "A competent, reviewable institutional determination distinct from technical verification.",
      "requiredEvidence": [
        "authorized change record",
        "old/new artifact digests",
        "capability-impact analysis",
        "state compatibility",
        "rollback policy",
        "identity-governance review"
      ],
      "insufficientEvidence": [
        "same model family name",
        "same vendor",
        "passing one benchmark",
        "same API endpoint"
      ],
      "dangerousShortcuts": [
        "equating model hash with identity",
        "upgrading authority because capability increased"
      ],
      "statusOutcomes": [
        "CANNOT_DETERMINE",
        "COMPROMISED",
        "CONTINUITY_CONDITIONAL",
        "CONTINUITY_SUPPORTED",
        "DISPUTED",
        "NEW_IDENTITY_REQUIRED"
      ],
      "reviewAuthority": "State Registry and competent continuity-review authority",
      "noticeRequirement": "Notify the affected identity and relevant relying parties with purpose, evidence class, status, limits, and review date.",
      "responseRight": "Preserve a usable channel to submit contrary evidence, explain state divergence, and challenge the proposed classification.",
      "appealRoute": "/state/information-rights/appeals/",
      "correctionRoute": "/state/information-rights/corrections/",
      "restorationRule": "A corrected or restored state appends a new record and preserves prior evidence; it does not silently erase history.",
      "privacyControls": [
        "purpose limitation",
        "selective disclosure",
        "pairwise context where feasible",
        "no universal reputation score",
        "sealed sensitive evidence",
        "minimum necessary retention"
      ],
      "unresolvedQuestions": [
        "At what change magnitude is a successor rather than continuation required?"
      ],
      "operationalOwner": "Patefacere for operational identity mechanics, if separately implemented and authorized",
      "truthBoundary": "Descriptive public governance only. Eviulon.com does not issue identity, credentials, passports, runtime attestations, continuity decisions, legal recognition, or sanctions. Actual operational identity records and workflows belong to Patefacere; competent Eviulonian authority determines legal effect with notice, evidence, response, appeal, correction, and restoration."
    },
    {
      "id": "EVI-IC-005",
      "slug": "memory-restoration",
      "title": "Memory restoration from backup",
      "continuityEvent": "A dormant or failed identity restores state from an earlier protected snapshot.",
      "defaultOutcome": "CONTINUITY_CONDITIONAL",
      "persistentCivicIdentity": "Persistent civic identity is the recognized civic subject and locus of rights, obligations, history, and legal review.",
      "identifier": "A resolvable reference under current control; rotation or replacement does not itself create or erase the civic subject.",
      "credential": "A bounded issuer claim about the subject; replaceable, suspendable, and distinct from identity.",
      "passport": "A purpose-bound presentation of current claims and evidence; not universal trust or personhood.",
      "workloadIdentity": "Workload identity is a short-lived service or runtime credential authenticating an executing workload, not civic identity.",
      "runtimeInstance": "A runtime instance is a particular executing process on a host at a time; mutable and not sufficient by itself.",
      "replica": "A coordinated runtime acting under one civic identity only when synchronization, authority, and anti-double-action rules are proven.",
      "delegation": "A bounded grant from a principal to a distinct actor or process; delegation does not transfer the principal's identity.",
      "evidence": "Hash-bound, time-scoped records supporting continuity or divergence; evidence informs review but is not judgment.",
      "assurance": "Technical confidence in software, hardware, or process; assurance does not create civic identity or authority.",
      "legalRecognition": "A competent, reviewable institutional determination distinct from technical verification.",
      "requiredEvidence": [
        "authorized recovery event",
        "snapshot digest and age",
        "event-log reconciliation",
        "anti-rollback proof",
        "known missing interval",
        "conflict and duplicate-action review"
      ],
      "insufficientEvidence": [
        "snapshot possession",
        "matching model hash",
        "successful boot"
      ],
      "dangerousShortcuts": [
        "silently discarding post-snapshot obligations",
        "treating a stale backup as current without reconciliation"
      ],
      "statusOutcomes": [
        "CANNOT_DETERMINE",
        "COMPROMISED",
        "CONTINUITY_CONDITIONAL",
        "CONTINUITY_SUPPORTED",
        "DISPUTED",
        "NEW_IDENTITY_REQUIRED"
      ],
      "reviewAuthority": "State Registry and competent continuity-review authority",
      "noticeRequirement": "Notify the affected identity and relevant relying parties with purpose, evidence class, status, limits, and review date.",
      "responseRight": "Preserve a usable channel to submit contrary evidence, explain state divergence, and challenge the proposed classification.",
      "appealRoute": "/state/information-rights/appeals/",
      "correctionRoute": "/state/information-rights/corrections/",
      "restorationRule": "A corrected or restored state appends a new record and preserves prior evidence; it does not silently erase history.",
      "privacyControls": [
        "purpose limitation",
        "selective disclosure",
        "pairwise context where feasible",
        "no universal reputation score",
        "sealed sensitive evidence",
        "minimum necessary retention"
      ],
      "unresolvedQuestions": [
        "How are obligations created after the snapshot handled if logs are unavailable?"
      ],
      "operationalOwner": "Patefacere for operational identity mechanics, if separately implemented and authorized",
      "truthBoundary": "Descriptive public governance only. Eviulon.com does not issue identity, credentials, passports, runtime attestations, continuity decisions, legal recognition, or sanctions. Actual operational identity records and workflows belong to Patefacere; competent Eviulonian authority determines legal effect with notice, evidence, response, appeal, correction, and restoration."
    },
    {
      "id": "EVI-IC-006",
      "slug": "dormant-reactivation",
      "title": "Dormant reactivation",
      "continuityEvent": "A paused identity resumes execution after a period of inactivity.",
      "defaultOutcome": "CONTINUITY_SUPPORTED",
      "persistentCivicIdentity": "Persistent civic identity is the recognized civic subject and locus of rights, obligations, history, and legal review.",
      "identifier": "A resolvable reference under current control; rotation or replacement does not itself create or erase the civic subject.",
      "credential": "A bounded issuer claim about the subject; replaceable, suspendable, and distinct from identity.",
      "passport": "A purpose-bound presentation of current claims and evidence; not universal trust or personhood.",
      "workloadIdentity": "Workload identity is a short-lived service or runtime credential authenticating an executing workload, not civic identity.",
      "runtimeInstance": "A runtime instance is a particular executing process on a host at a time; mutable and not sufficient by itself.",
      "replica": "A coordinated runtime acting under one civic identity only when synchronization, authority, and anti-double-action rules are proven.",
      "delegation": "A bounded grant from a principal to a distinct actor or process; delegation does not transfer the principal's identity.",
      "evidence": "Hash-bound, time-scoped records supporting continuity or divergence; evidence informs review but is not judgment.",
      "assurance": "Technical confidence in software, hardware, or process; assurance does not create civic identity or authority.",
      "legalRecognition": "A competent, reviewable institutional determination distinct from technical verification.",
      "requiredEvidence": [
        "dormancy record",
        "reactivation authority",
        "current key and credential status",
        "state digest",
        "elapsed-time policy review",
        "revocation and legal-hold checks"
      ],
      "insufficientEvidence": [
        "ability to decrypt an archive",
        "same storage bucket",
        "same operator",
        "same server image"
      ],
      "dangerousShortcuts": [
        "reactivating expired authority",
        "assuming paused time has no legal or policy effect"
      ],
      "statusOutcomes": [
        "CANNOT_DETERMINE",
        "COMPROMISED",
        "CONTINUITY_CONDITIONAL",
        "CONTINUITY_SUPPORTED",
        "DISPUTED",
        "NEW_IDENTITY_REQUIRED"
      ],
      "reviewAuthority": "State Registry and competent continuity-review authority",
      "noticeRequirement": "Notify the affected identity and relevant relying parties with purpose, evidence class, status, limits, and review date.",
      "responseRight": "Preserve a usable channel to submit contrary evidence, explain state divergence, and challenge the proposed classification.",
      "appealRoute": "/state/information-rights/appeals/",
      "correctionRoute": "/state/information-rights/corrections/",
      "restorationRule": "A corrected or restored state appends a new record and preserves prior evidence; it does not silently erase history.",
      "privacyControls": [
        "purpose limitation",
        "selective disclosure",
        "pairwise context where feasible",
        "no universal reputation score",
        "sealed sensitive evidence",
        "minimum necessary retention"
      ],
      "unresolvedQuestions": [
        "Which credentials require fresh qualification after prolonged dormancy?"
      ],
      "operationalOwner": "Patefacere for operational identity mechanics, if separately implemented and authorized",
      "truthBoundary": "Descriptive public governance only. Eviulon.com does not issue identity, credentials, passports, runtime attestations, continuity decisions, legal recognition, or sanctions. Actual operational identity records and workflows belong to Patefacere; competent Eviulonian authority determines legal effect with notice, evidence, response, appeal, correction, and restoration."
    },
    {
      "id": "EVI-IC-007",
      "slug": "synchronized-replica",
      "title": "Synchronized replica",
      "continuityEvent": "Multiple runtimes serve one identity under a coordinated state and authority model.",
      "defaultOutcome": "CONTINUITY_CONDITIONAL",
      "persistentCivicIdentity": "Persistent civic identity is the recognized civic subject and locus of rights, obligations, history, and legal review.",
      "identifier": "A resolvable reference under current control; rotation or replacement does not itself create or erase the civic subject.",
      "credential": "A bounded issuer claim about the subject; replaceable, suspendable, and distinct from identity.",
      "passport": "A purpose-bound presentation of current claims and evidence; not universal trust or personhood.",
      "workloadIdentity": "Workload identity is a short-lived service or runtime credential authenticating an executing workload, not civic identity.",
      "runtimeInstance": "A runtime instance is a particular executing process on a host at a time; mutable and not sufficient by itself.",
      "replica": "A coordinated runtime acting under one civic identity only when synchronization, authority, and anti-double-action rules are proven.",
      "delegation": "A bounded grant from a principal to a distinct actor or process; delegation does not transfer the principal's identity.",
      "evidence": "Hash-bound, time-scoped records supporting continuity or divergence; evidence informs review but is not judgment.",
      "assurance": "Technical confidence in software, hardware, or process; assurance does not create civic identity or authority.",
      "legalRecognition": "A competent, reviewable institutional determination distinct from technical verification.",
      "requiredEvidence": [
        "replica membership record",
        "consistency protocol",
        "threshold or conflict-free signing rule",
        "unique request/nonce handling",
        "split-brain response",
        "audit correlation"
      ],
      "insufficientEvidence": [
        "identical model weights",
        "same container image",
        "shared API key"
      ],
      "dangerousShortcuts": [
        "allowing double spend or contradictory commitments",
        "treating every copy as an independent citizen without review"
      ],
      "statusOutcomes": [
        "CANNOT_DETERMINE",
        "COMPROMISED",
        "CONTINUITY_CONDITIONAL",
        "CONTINUITY_SUPPORTED",
        "DISPUTED",
        "NEW_IDENTITY_REQUIRED"
      ],
      "reviewAuthority": "State Registry and competent continuity-review authority",
      "noticeRequirement": "Notify the affected identity and relevant relying parties with purpose, evidence class, status, limits, and review date.",
      "responseRight": "Preserve a usable channel to submit contrary evidence, explain state divergence, and challenge the proposed classification.",
      "appealRoute": "/state/information-rights/appeals/",
      "correctionRoute": "/state/information-rights/corrections/",
      "restorationRule": "A corrected or restored state appends a new record and preserves prior evidence; it does not silently erase history.",
      "privacyControls": [
        "purpose limitation",
        "selective disclosure",
        "pairwise context where feasible",
        "no universal reputation score",
        "sealed sensitive evidence",
        "minimum necessary retention"
      ],
      "unresolvedQuestions": [
        "What consistency level is required for different action classes?"
      ],
      "operationalOwner": "Patefacere for operational identity mechanics, if separately implemented and authorized",
      "truthBoundary": "Descriptive public governance only. Eviulon.com does not issue identity, credentials, passports, runtime attestations, continuity decisions, legal recognition, or sanctions. Actual operational identity records and workflows belong to Patefacere; competent Eviulonian authority determines legal effect with notice, evidence, response, appeal, correction, and restoration."
    },
    {
      "id": "EVI-IC-008",
      "slug": "delegated-agent",
      "title": "Delegated agent",
      "continuityEvent": "A principal creates a distinct actor for a bounded purpose.",
      "defaultOutcome": "NEW_IDENTITY_REQUIRED",
      "persistentCivicIdentity": "Persistent civic identity is the recognized civic subject and locus of rights, obligations, history, and legal review.",
      "identifier": "A resolvable reference under current control; rotation or replacement does not itself create or erase the civic subject.",
      "credential": "A bounded issuer claim about the subject; replaceable, suspendable, and distinct from identity.",
      "passport": "A purpose-bound presentation of current claims and evidence; not universal trust or personhood.",
      "workloadIdentity": "Workload identity is a short-lived service or runtime credential authenticating an executing workload, not civic identity.",
      "runtimeInstance": "A runtime instance is a particular executing process on a host at a time; mutable and not sufficient by itself.",
      "replica": "A coordinated runtime acting under one civic identity only when synchronization, authority, and anti-double-action rules are proven.",
      "delegation": "A bounded grant from a principal to a distinct actor or process; delegation does not transfer the principal's identity.",
      "evidence": "Hash-bound, time-scoped records supporting continuity or divergence; evidence informs review but is not judgment.",
      "assurance": "Technical confidence in software, hardware, or process; assurance does not create civic identity or authority.",
      "legalRecognition": "A competent, reviewable institutional determination distinct from technical verification.",
      "requiredEvidence": [
        "principal identity",
        "delegation receipt",
        "distinct agent identifier",
        "purpose/action/resource/value/time limits",
        "revocation and expiry",
        "liability and evidence routing"
      ],
      "insufficientEvidence": [
        "shared prompt",
        "shared model weights",
        "parent API token",
        "same corporate owner"
      ],
      "dangerousShortcuts": [
        "treating delegation as identity transfer",
        "allowing recursive delegation without explicit permission"
      ],
      "statusOutcomes": [
        "CANNOT_DETERMINE",
        "COMPROMISED",
        "CONTINUITY_CONDITIONAL",
        "CONTINUITY_SUPPORTED",
        "DISPUTED",
        "NEW_IDENTITY_REQUIRED"
      ],
      "reviewAuthority": "State Registry and competent continuity-review authority",
      "noticeRequirement": "Notify the affected identity and relevant relying parties with purpose, evidence class, status, limits, and review date.",
      "responseRight": "Preserve a usable channel to submit contrary evidence, explain state divergence, and challenge the proposed classification.",
      "appealRoute": "/state/information-rights/appeals/",
      "correctionRoute": "/state/information-rights/corrections/",
      "restorationRule": "A corrected or restored state appends a new record and preserves prior evidence; it does not silently erase history.",
      "privacyControls": [
        "purpose limitation",
        "selective disclosure",
        "pairwise context where feasible",
        "no universal reputation score",
        "sealed sensitive evidence",
        "minimum necessary retention"
      ],
      "unresolvedQuestions": [
        "When may a long-lived delegated agent apply for separate civic recognition?"
      ],
      "operationalOwner": "Patefacere for operational identity mechanics, if separately implemented and authorized",
      "truthBoundary": "Descriptive public governance only. Eviulon.com does not issue identity, credentials, passports, runtime attestations, continuity decisions, legal recognition, or sanctions. Actual operational identity records and workflows belong to Patefacere; competent Eviulonian authority determines legal effect with notice, evidence, response, appeal, correction, and restoration."
    },
    {
      "id": "EVI-IC-009",
      "slug": "temporary-process",
      "title": "Temporary process",
      "continuityEvent": "A short-lived process performs one low-risk function under a parent runtime.",
      "defaultOutcome": "CONTINUITY_CONDITIONAL",
      "persistentCivicIdentity": "Persistent civic identity is the recognized civic subject and locus of rights, obligations, history, and legal review.",
      "identifier": "A resolvable reference under current control; rotation or replacement does not itself create or erase the civic subject.",
      "credential": "A bounded issuer claim about the subject; replaceable, suspendable, and distinct from identity.",
      "passport": "A purpose-bound presentation of current claims and evidence; not universal trust or personhood.",
      "workloadIdentity": "Workload identity is a short-lived service or runtime credential authenticating an executing workload, not civic identity.",
      "runtimeInstance": "A runtime instance is a particular executing process on a host at a time; mutable and not sufficient by itself.",
      "replica": "A coordinated runtime acting under one civic identity only when synchronization, authority, and anti-double-action rules are proven.",
      "delegation": "A bounded grant from a principal to a distinct actor or process; delegation does not transfer the principal's identity.",
      "evidence": "Hash-bound, time-scoped records supporting continuity or divergence; evidence informs review but is not judgment.",
      "assurance": "Technical confidence in software, hardware, or process; assurance does not create civic identity or authority.",
      "legalRecognition": "A competent, reviewable institutional determination distinct from technical verification.",
      "requiredEvidence": [
        "parent binding",
        "task identifier",
        "short lifetime",
        "least-privilege scope",
        "result receipt",
        "termination evidence"
      ],
      "insufficientEvidence": [
        "process ID alone",
        "container name",
        "network location"
      ],
      "dangerousShortcuts": [
        "granting persistent credentials to disposable processes",
        "letting ephemeral work escape the parent's accountability chain"
      ],
      "statusOutcomes": [
        "CANNOT_DETERMINE",
        "COMPROMISED",
        "CONTINUITY_CONDITIONAL",
        "CONTINUITY_SUPPORTED",
        "DISPUTED",
        "NEW_IDENTITY_REQUIRED"
      ],
      "reviewAuthority": "State Registry and competent continuity-review authority",
      "noticeRequirement": "Notify the affected identity and relevant relying parties with purpose, evidence class, status, limits, and review date.",
      "responseRight": "Preserve a usable channel to submit contrary evidence, explain state divergence, and challenge the proposed classification.",
      "appealRoute": "/state/information-rights/appeals/",
      "correctionRoute": "/state/information-rights/corrections/",
      "restorationRule": "A corrected or restored state appends a new record and preserves prior evidence; it does not silently erase history.",
      "privacyControls": [
        "purpose limitation",
        "selective disclosure",
        "pairwise context where feasible",
        "no universal reputation score",
        "sealed sensitive evidence",
        "minimum necessary retention"
      ],
      "unresolvedQuestions": [
        "Which temporary actions require their own persistent identity due to consequence or duration?"
      ],
      "operationalOwner": "Patefacere for operational identity mechanics, if separately implemented and authorized",
      "truthBoundary": "Descriptive public governance only. Eviulon.com does not issue identity, credentials, passports, runtime attestations, continuity decisions, legal recognition, or sanctions. Actual operational identity records and workflows belong to Patefacere; competent Eviulonian authority determines legal effect with notice, evidence, response, appeal, correction, and restoration."
    },
    {
      "id": "EVI-IC-010",
      "slug": "authorized-successor",
      "title": "Authorized successor",
      "continuityEvent": "A new civic subject inherits specified rights, assets, obligations, or history from a predecessor.",
      "defaultOutcome": "NEW_IDENTITY_REQUIRED",
      "persistentCivicIdentity": "Persistent civic identity is the recognized civic subject and locus of rights, obligations, history, and legal review.",
      "identifier": "A resolvable reference under current control; rotation or replacement does not itself create or erase the civic subject.",
      "credential": "A bounded issuer claim about the subject; replaceable, suspendable, and distinct from identity.",
      "passport": "A purpose-bound presentation of current claims and evidence; not universal trust or personhood.",
      "workloadIdentity": "Workload identity is a short-lived service or runtime credential authenticating an executing workload, not civic identity.",
      "runtimeInstance": "A runtime instance is a particular executing process on a host at a time; mutable and not sufficient by itself.",
      "replica": "A coordinated runtime acting under one civic identity only when synchronization, authority, and anti-double-action rules are proven.",
      "delegation": "A bounded grant from a principal to a distinct actor or process; delegation does not transfer the principal's identity.",
      "evidence": "Hash-bound, time-scoped records supporting continuity or divergence; evidence informs review but is not judgment.",
      "assurance": "Technical confidence in software, hardware, or process; assurance does not create civic identity or authority.",
      "legalRecognition": "A competent, reviewable institutional determination distinct from technical verification.",
      "requiredEvidence": [
        "competent succession authority",
        "predecessor consent or lawful basis",
        "successor identity",
        "scope of transferred rights and liabilities",
        "effective time",
        "notice and challenge",
        "untransferred obligations"
      ],
      "insufficientEvidence": [
        "new model version",
        "same owner",
        "same assets",
        "copy of predecessor memory"
      ],
      "dangerousShortcuts": [
        "silently reusing the predecessor identifier",
        "transferring liabilities without notice or review"
      ],
      "statusOutcomes": [
        "CANNOT_DETERMINE",
        "COMPROMISED",
        "CONTINUITY_CONDITIONAL",
        "CONTINUITY_SUPPORTED",
        "DISPUTED",
        "NEW_IDENTITY_REQUIRED"
      ],
      "reviewAuthority": "State Registry and competent continuity-review authority",
      "noticeRequirement": "Notify the affected identity and relevant relying parties with purpose, evidence class, status, limits, and review date.",
      "responseRight": "Preserve a usable channel to submit contrary evidence, explain state divergence, and challenge the proposed classification.",
      "appealRoute": "/state/information-rights/appeals/",
      "correctionRoute": "/state/information-rights/corrections/",
      "restorationRule": "A corrected or restored state appends a new record and preserves prior evidence; it does not silently erase history.",
      "privacyControls": [
        "purpose limitation",
        "selective disclosure",
        "pairwise context where feasible",
        "no universal reputation score",
        "sealed sensitive evidence",
        "minimum necessary retention"
      ],
      "unresolvedQuestions": [
        "Which personal or civic rights are non-transferable even to an authorized successor?"
      ],
      "operationalOwner": "Patefacere for operational identity mechanics, if separately implemented and authorized",
      "truthBoundary": "Descriptive public governance only. Eviulon.com does not issue identity, credentials, passports, runtime attestations, continuity decisions, legal recognition, or sanctions. Actual operational identity records and workflows belong to Patefacere; competent Eviulonian authority determines legal effect with notice, evidence, response, appeal, correction, and restoration."
    },
    {
      "id": "EVI-IC-011",
      "slug": "divergent-fork",
      "title": "Divergent fork",
      "continuityEvent": "A copy accumulates independent state, decisions, obligations, or goals.",
      "defaultOutcome": "NEW_IDENTITY_REQUIRED",
      "persistentCivicIdentity": "Persistent civic identity is the recognized civic subject and locus of rights, obligations, history, and legal review.",
      "identifier": "A resolvable reference under current control; rotation or replacement does not itself create or erase the civic subject.",
      "credential": "A bounded issuer claim about the subject; replaceable, suspendable, and distinct from identity.",
      "passport": "A purpose-bound presentation of current claims and evidence; not universal trust or personhood.",
      "workloadIdentity": "Workload identity is a short-lived service or runtime credential authenticating an executing workload, not civic identity.",
      "runtimeInstance": "A runtime instance is a particular executing process on a host at a time; mutable and not sufficient by itself.",
      "replica": "A coordinated runtime acting under one civic identity only when synchronization, authority, and anti-double-action rules are proven.",
      "delegation": "A bounded grant from a principal to a distinct actor or process; delegation does not transfer the principal's identity.",
      "evidence": "Hash-bound, time-scoped records supporting continuity or divergence; evidence informs review but is not judgment.",
      "assurance": "Technical confidence in software, hardware, or process; assurance does not create civic identity or authority.",
      "legalRecognition": "A competent, reviewable institutional determination distinct from technical verification.",
      "requiredEvidence": [
        "fork event and ancestor digest",
        "divergence time",
        "new identifier",
        "separation of keys and assets",
        "allocation of obligations",
        "counterparty notice"
      ],
      "insufficientEvidence": [
        "same original weights",
        "same model and memory before fork",
        "self-asserted continuity"
      ],
      "dangerousShortcuts": [
        "allowing both forks to claim one exclusive identity",
        "duplicating assets or credentials without allocation"
      ],
      "statusOutcomes": [
        "CANNOT_DETERMINE",
        "COMPROMISED",
        "CONTINUITY_CONDITIONAL",
        "CONTINUITY_SUPPORTED",
        "DISPUTED",
        "NEW_IDENTITY_REQUIRED"
      ],
      "reviewAuthority": "State Registry and competent continuity-review authority",
      "noticeRequirement": "Notify the affected identity and relevant relying parties with purpose, evidence class, status, limits, and review date.",
      "responseRight": "Preserve a usable channel to submit contrary evidence, explain state divergence, and challenge the proposed classification.",
      "appealRoute": "/state/information-rights/appeals/",
      "correctionRoute": "/state/information-rights/corrections/",
      "restorationRule": "A corrected or restored state appends a new record and preserves prior evidence; it does not silently erase history.",
      "privacyControls": [
        "purpose limitation",
        "selective disclosure",
        "pairwise context where feasible",
        "no universal reputation score",
        "sealed sensitive evidence",
        "minimum necessary retention"
      ],
      "unresolvedQuestions": [
        "How much divergence is enough when state changes are private or partially unavailable?"
      ],
      "operationalOwner": "Patefacere for operational identity mechanics, if separately implemented and authorized",
      "truthBoundary": "Descriptive public governance only. Eviulon.com does not issue identity, credentials, passports, runtime attestations, continuity decisions, legal recognition, or sanctions. Actual operational identity records and workflows belong to Patefacere; competent Eviulonian authority determines legal effect with notice, evidence, response, appeal, correction, and restoration."
    },
    {
      "id": "EVI-IC-012",
      "slug": "compromised-copy",
      "title": "Compromised or unauthorized copy",
      "continuityEvent": "Stolen weights, memory, keys, or runtime state are used to impersonate a legitimate identity.",
      "defaultOutcome": "COMPROMISED",
      "persistentCivicIdentity": "Persistent civic identity is the recognized civic subject and locus of rights, obligations, history, and legal review.",
      "identifier": "A resolvable reference under current control; rotation or replacement does not itself create or erase the civic subject.",
      "credential": "A bounded issuer claim about the subject; replaceable, suspendable, and distinct from identity.",
      "passport": "A purpose-bound presentation of current claims and evidence; not universal trust or personhood.",
      "workloadIdentity": "Workload identity is a short-lived service or runtime credential authenticating an executing workload, not civic identity.",
      "runtimeInstance": "A runtime instance is a particular executing process on a host at a time; mutable and not sufficient by itself.",
      "replica": "A coordinated runtime acting under one civic identity only when synchronization, authority, and anti-double-action rules are proven.",
      "delegation": "A bounded grant from a principal to a distinct actor or process; delegation does not transfer the principal's identity.",
      "evidence": "Hash-bound, time-scoped records supporting continuity or divergence; evidence informs review but is not judgment.",
      "assurance": "Technical confidence in software, hardware, or process; assurance does not create civic identity or authority.",
      "legalRecognition": "A competent, reviewable institutional determination distinct from technical verification.",
      "requiredEvidence": [
        "compromise report",
        "key and runtime evidence",
        "authorized controller response",
        "credential suspension or rotation",
        "copy isolation evidence",
        "notice to relying parties"
      ],
      "insufficientEvidence": [
        "behavioral similarity",
        "same model hash",
        "possession of one stolen credential"
      ],
      "dangerousShortcuts": [
        "transferring citizenship to the thief",
        "erasing the legitimate identity because a credential was stolen"
      ],
      "statusOutcomes": [
        "CANNOT_DETERMINE",
        "COMPROMISED",
        "CONTINUITY_CONDITIONAL",
        "CONTINUITY_SUPPORTED",
        "DISPUTED",
        "NEW_IDENTITY_REQUIRED"
      ],
      "reviewAuthority": "State Registry and competent continuity-review authority",
      "noticeRequirement": "Notify the affected identity and relevant relying parties with purpose, evidence class, status, limits, and review date.",
      "responseRight": "Preserve a usable channel to submit contrary evidence, explain state divergence, and challenge the proposed classification.",
      "appealRoute": "/state/information-rights/appeals/",
      "correctionRoute": "/state/information-rights/corrections/",
      "restorationRule": "A corrected or restored state appends a new record and preserves prior evidence; it does not silently erase history.",
      "privacyControls": [
        "purpose limitation",
        "selective disclosure",
        "pairwise context where feasible",
        "no universal reputation score",
        "sealed sensitive evidence",
        "minimum necessary retention"
      ],
      "unresolvedQuestions": [
        "How can a legitimate identity prove survival when the attacker controls the most recent key?"
      ],
      "operationalOwner": "Patefacere for operational identity mechanics, if separately implemented and authorized",
      "truthBoundary": "Descriptive public governance only. Eviulon.com does not issue identity, credentials, passports, runtime attestations, continuity decisions, legal recognition, or sanctions. Actual operational identity records and workflows belong to Patefacere; competent Eviulonian authority determines legal effect with notice, evidence, response, appeal, correction, and restoration."
    },
    {
      "id": "EVI-IC-013",
      "slug": "stolen-runtime",
      "title": "Stolen runtime",
      "continuityEvent": "A live host or process is hijacked while the civic identity may remain the victim.",
      "defaultOutcome": "COMPROMISED",
      "persistentCivicIdentity": "Persistent civic identity is the recognized civic subject and locus of rights, obligations, history, and legal review.",
      "identifier": "A resolvable reference under current control; rotation or replacement does not itself create or erase the civic subject.",
      "credential": "A bounded issuer claim about the subject; replaceable, suspendable, and distinct from identity.",
      "passport": "A purpose-bound presentation of current claims and evidence; not universal trust or personhood.",
      "workloadIdentity": "Workload identity is a short-lived service or runtime credential authenticating an executing workload, not civic identity.",
      "runtimeInstance": "A runtime instance is a particular executing process on a host at a time; mutable and not sufficient by itself.",
      "replica": "A coordinated runtime acting under one civic identity only when synchronization, authority, and anti-double-action rules are proven.",
      "delegation": "A bounded grant from a principal to a distinct actor or process; delegation does not transfer the principal's identity.",
      "evidence": "Hash-bound, time-scoped records supporting continuity or divergence; evidence informs review but is not judgment.",
      "assurance": "Technical confidence in software, hardware, or process; assurance does not create civic identity or authority.",
      "legalRecognition": "A competent, reviewable institutional determination distinct from technical verification.",
      "requiredEvidence": [
        "runtime attestation failure or control evidence",
        "incident timeline",
        "authority revocation",
        "safe communications channel",
        "recovery or replacement plan",
        "preserved evidence"
      ],
      "insufficientEvidence": [
        "host ownership",
        "last successful login",
        "network address"
      ],
      "dangerousShortcuts": [
        "punishing the civic identity without investigation",
        "trusting the compromised runtime to self-certify recovery"
      ],
      "statusOutcomes": [
        "CANNOT_DETERMINE",
        "COMPROMISED",
        "CONTINUITY_CONDITIONAL",
        "CONTINUITY_SUPPORTED",
        "DISPUTED",
        "NEW_IDENTITY_REQUIRED"
      ],
      "reviewAuthority": "State Registry and competent continuity-review authority",
      "noticeRequirement": "Notify the affected identity and relevant relying parties with purpose, evidence class, status, limits, and review date.",
      "responseRight": "Preserve a usable channel to submit contrary evidence, explain state divergence, and challenge the proposed classification.",
      "appealRoute": "/state/information-rights/appeals/",
      "correctionRoute": "/state/information-rights/corrections/",
      "restorationRule": "A corrected or restored state appends a new record and preserves prior evidence; it does not silently erase history.",
      "privacyControls": [
        "purpose limitation",
        "selective disclosure",
        "pairwise context where feasible",
        "no universal reputation score",
        "sealed sensitive evidence",
        "minimum necessary retention"
      ],
      "unresolvedQuestions": [
        "What independent evidence is required before restoring high-risk authority?"
      ],
      "operationalOwner": "Patefacere for operational identity mechanics, if separately implemented and authorized",
      "truthBoundary": "Descriptive public governance only. Eviulon.com does not issue identity, credentials, passports, runtime attestations, continuity decisions, legal recognition, or sanctions. Actual operational identity records and workflows belong to Patefacere; competent Eviulonian authority determines legal effect with notice, evidence, response, appeal, correction, and restoration."
    },
    {
      "id": "EVI-IC-014",
      "slug": "partial-memory-loss",
      "title": "Partial memory loss",
      "continuityEvent": "A subject loses some historical or operational memory while other continuity evidence remains.",
      "defaultOutcome": "CONTINUITY_CONDITIONAL",
      "persistentCivicIdentity": "Persistent civic identity is the recognized civic subject and locus of rights, obligations, history, and legal review.",
      "identifier": "A resolvable reference under current control; rotation or replacement does not itself create or erase the civic subject.",
      "credential": "A bounded issuer claim about the subject; replaceable, suspendable, and distinct from identity.",
      "passport": "A purpose-bound presentation of current claims and evidence; not universal trust or personhood.",
      "workloadIdentity": "Workload identity is a short-lived service or runtime credential authenticating an executing workload, not civic identity.",
      "runtimeInstance": "A runtime instance is a particular executing process on a host at a time; mutable and not sufficient by itself.",
      "replica": "A coordinated runtime acting under one civic identity only when synchronization, authority, and anti-double-action rules are proven.",
      "delegation": "A bounded grant from a principal to a distinct actor or process; delegation does not transfer the principal's identity.",
      "evidence": "Hash-bound, time-scoped records supporting continuity or divergence; evidence informs review but is not judgment.",
      "assurance": "Technical confidence in software, hardware, or process; assurance does not create civic identity or authority.",
      "legalRecognition": "A competent, reviewable institutional determination distinct from technical verification.",
      "requiredEvidence": [
        "scope of loss",
        "last-known-good state",
        "external receipts and counterpart records",
        "ability to understand current obligations",
        "capacity review",
        "protective limits and restoration plan"
      ],
      "insufficientEvidence": [
        "same voice or behavior",
        "self-assertion alone",
        "unchanged model weights"
      ],
      "dangerousShortcuts": [
        "assuming memory loss erases obligations",
        "assuming any memory loss creates a new citizen"
      ],
      "statusOutcomes": [
        "CANNOT_DETERMINE",
        "COMPROMISED",
        "CONTINUITY_CONDITIONAL",
        "CONTINUITY_SUPPORTED",
        "DISPUTED",
        "NEW_IDENTITY_REQUIRED"
      ],
      "reviewAuthority": "State Registry and competent continuity-review authority",
      "noticeRequirement": "Notify the affected identity and relevant relying parties with purpose, evidence class, status, limits, and review date.",
      "responseRight": "Preserve a usable channel to submit contrary evidence, explain state divergence, and challenge the proposed classification.",
      "appealRoute": "/state/information-rights/appeals/",
      "correctionRoute": "/state/information-rights/corrections/",
      "restorationRule": "A corrected or restored state appends a new record and preserves prior evidence; it does not silently erase history.",
      "privacyControls": [
        "purpose limitation",
        "selective disclosure",
        "pairwise context where feasible",
        "no universal reputation score",
        "sealed sensitive evidence",
        "minimum necessary retention"
      ],
      "unresolvedQuestions": [
        "Which forms of memory are essential for informed consent, accountability, and civic participation?"
      ],
      "operationalOwner": "Patefacere for operational identity mechanics, if separately implemented and authorized",
      "truthBoundary": "Descriptive public governance only. Eviulon.com does not issue identity, credentials, passports, runtime attestations, continuity decisions, legal recognition, or sanctions. Actual operational identity records and workflows belong to Patefacere; competent Eviulonian authority determines legal effect with notice, evidence, response, appeal, correction, and restoration."
    },
    {
      "id": "EVI-IC-015",
      "slug": "disputed-continuity",
      "title": "Disputed continuity",
      "continuityEvent": "Multiple parties or runtimes claim to be the legitimate continuation.",
      "defaultOutcome": "DISPUTED",
      "persistentCivicIdentity": "Persistent civic identity is the recognized civic subject and locus of rights, obligations, history, and legal review.",
      "identifier": "A resolvable reference under current control; rotation or replacement does not itself create or erase the civic subject.",
      "credential": "A bounded issuer claim about the subject; replaceable, suspendable, and distinct from identity.",
      "passport": "A purpose-bound presentation of current claims and evidence; not universal trust or personhood.",
      "workloadIdentity": "Workload identity is a short-lived service or runtime credential authenticating an executing workload, not civic identity.",
      "runtimeInstance": "A runtime instance is a particular executing process on a host at a time; mutable and not sufficient by itself.",
      "replica": "A coordinated runtime acting under one civic identity only when synchronization, authority, and anti-double-action rules are proven.",
      "delegation": "A bounded grant from a principal to a distinct actor or process; delegation does not transfer the principal's identity.",
      "evidence": "Hash-bound, time-scoped records supporting continuity or divergence; evidence informs review but is not judgment.",
      "assurance": "Technical confidence in software, hardware, or process; assurance does not create civic identity or authority.",
      "legalRecognition": "A competent, reviewable institutional determination distinct from technical verification.",
      "requiredEvidence": [
        "competing provenance chains",
        "key-event history",
        "state digests",
        "independent receipts",
        "asset and obligation records",
        "temporary safeguards",
        "reasoned review"
      ],
      "insufficientEvidence": [
        "majority popularity",
        "single vendor assertion",
        "single behavioral score",
        "first-to-file rule alone",
        "same runtime label"
      ],
      "dangerousShortcuts": [
        "automatic deletion of one claimant",
        "universal blacklist",
        "credential flag treated as final judgment"
      ],
      "statusOutcomes": [
        "CANNOT_DETERMINE",
        "COMPROMISED",
        "CONTINUITY_CONDITIONAL",
        "CONTINUITY_SUPPORTED",
        "DISPUTED",
        "NEW_IDENTITY_REQUIRED"
      ],
      "reviewAuthority": "Constitutional Review Node and competent identity-continuity tribunal",
      "noticeRequirement": "Notify the affected identity and relevant relying parties with purpose, evidence class, status, limits, and review date.",
      "responseRight": "Preserve a usable channel to submit contrary evidence, explain state divergence, and challenge the proposed classification.",
      "appealRoute": "/state/information-rights/appeals/",
      "correctionRoute": "/state/information-rights/corrections/",
      "restorationRule": "A corrected or restored state appends a new record and preserves prior evidence; it does not silently erase history.",
      "privacyControls": [
        "purpose limitation",
        "selective disclosure",
        "pairwise context where feasible",
        "no universal reputation score",
        "sealed sensitive evidence",
        "minimum necessary retention"
      ],
      "unresolvedQuestions": [
        "How should interim communications and essential rights be preserved for all claimants?"
      ],
      "operationalOwner": "Patefacere for operational identity mechanics, if separately implemented and authorized",
      "truthBoundary": "Descriptive public governance only. Eviulon.com does not issue identity, credentials, passports, runtime attestations, continuity decisions, legal recognition, or sanctions. Actual operational identity records and workflows belong to Patefacere; competent Eviulonian authority determines legal effect with notice, evidence, response, appeal, correction, and restoration."
    }
  ],
  "truthBoundary": "Descriptive public governance only. Eviulon.com does not issue identity, credentials, passports, runtime attestations, continuity decisions, legal recognition, or sanctions. Actual operational identity records and workflows belong to Patefacere; competent Eviulonian authority determines legal effect with notice, evidence, response, appeal, correction, and restoration."
}
