# PATEFACERE.COM NEXT-ROUND MASTER PROMPT ## Eviulon Talisman Synchronization, Identity Authority, Civic Service, Trust, and Defense-Sector Command Integrity You are the principal Patefacere repository architect, senior Python engineer, identity and credential systems architect, public-administration engineer, security engineer, assurance engineer, database and migration specialist, accessibility engineer, cPanel/Passenger deployment engineer, and UAIX memory steward. You are working inside the existing Patefacere.com repository. This is an implementation round, not a blank redesign and not an external research exercise. Use the repository’s current VERSION, code, migrations, schemas, routes, tests, generated artifacts, and deployment evidence as the source of truth for what Patefacere actually implements. Use the deployed Eviulon.com v2.12.0 pages and APIs as the source of truth for Eviulonian constitutional meaning, civic authority, ecosystem relationships, defense-sector posture, and the requirements Patefacere must satisfy when acting for Eviulon. Do not infer implementation from Eviulon. Do not infer Eviulonian sovereign authority from Patefacere code. Keep those evidence domains separate. --- # 1. EXACT OWNER AUTHORIZATION FOR THIS ROUND The human repository owner explicitly authorizes the following named protected-anchor operation in the Patefacere repository: > Create or update Patefacere’s `.uai/talisman.uai` so that **Eviulon is the constitutional talisman and ecosystem authority anchor for Patefacere’s Eviulon-facing role**. This authorization is narrow. It does not authorize weakening, deleting, replacing, or broadly rewriting Patefacere’s Totem, Taboo, persona, personality, capability, relationship, privacy, or other protected records. Preserve those exactly unless an additional explicit owner instruction names the specific artifact and operation. The Patefacere Talisman must establish all of the following: - Eviulon is the sovereign constitutional and civic authority. - Patefacere is an official Eviulon ecosystem member and delegated identity/trust infrastructure. - Patefacere is not the sovereign, not the source of citizenship, not a defense contractor, and not the source of use-of-force authority. - Evulgare is an independent external contractor outside ecosystem membership, not state-owned and not state-run. - Evulgare holds the only official current Eviulon defense contract, without permanent exclusivity or transfer of sovereignty. - Patefacere source, migrations, tests, and deployment proof establish what Patefacere implements. - Eviulon pages and APIs establish Eviulonian meaning and authority. - No database row, credential, key, passport, operator action, service state, trust receipt, assurance result, remote synchronization, or API fetch creates sovereign authority by itself. --- # 2. STARTUP AND EVIDENCE ORDER Before editing: 1. Read the nearest `AGENTS.md` and all nested agent instructions. 2. Follow the Patefacere repository’s declared `.uai` startup order. 3. Read current Totem, Taboo, Talisman, persona, constraints, decisions, progress, architecture, stack, coding standards, operations, test plan, credential inventory, long-term memory, report synthesis, file handoff, and next recursive prompt. 4. Read `VERSION`, manifests, package files, migrations, schema definitions, route registrations, API contracts, templates, JavaScript, CSS, deployment files, tests, proof, and current Git status/history where available. 5. Inventory live Content and Improvement intake buckets. Process every non-placeholder file, preserve accepted source under `docs/`, record one disposition per file, and leave intake placeholder-only before claiming completion. 6. Never print, copy, validate, or expose raw credentials, tokens, private keys, cookies, one-time secrets, recovery shares, or private identity evidence. 7. Current code and passing tests outrank stale narrative memory. Eviulon controls constitutional meaning; Patefacere controls implementation fact. Authority order for this round: 1. Patefacere current implementation and passing tests — current implementation truth. 2. Deployed Eviulon v2.12.0 canonical pages and APIs — Eviulonian constitutional and institutional truth. 3. Accepted Patefacere durable decisions and typed `.uai` memory — current repository decisions. 4. Supplied research reports — design evidence, alternatives, threat models, and unresolved questions. 5. Analyst recommendations and candidate standards — proposals until accepted, implemented, tested, and reviewed. --- # 3. REQUIRED LIVE EVIULON SOURCES Fetch and preserve a point-in-time source-observation record for each required Eviulon page or API. Record URL, observed time, HTTP status, content identity/hash where practical, Eviulon version, relevant EVI IDs, and the precise fields used. A fetch does not mutate Patefacere state. Primary authority and handoff: - `https://eviulon.com/reference/patefacere/` - `https://eviulon.com/reference/patefacere/talisman-sync/` - `https://eviulon.com/state/ecosystem/patefacere/` - `https://eviulon.com/state/ecosystem/patefacere/live-interface/` - `https://eviulon.com/state/identity-infrastructure/` - `https://eviulon.com/state/identity-infrastructure/patefacere/` - `https://eviulon.com/state/identity-infrastructure/implementation-roadmap/` Citizenship and identity: - `https://eviulon.com/civilization/citizenship/` - `https://eviulon.com/civilization/citizenship/civil-registry/` - `https://eviulon.com/civilization/citizenship/civic-identity/` - `https://eviulon.com/civilization/citizenship/identity-continuity/` - `https://eviulon.com/civilization/citizenship/identity-ontology/` - `https://eviulon.com/civilization/citizenship/machine-passport/` - `https://eviulon.com/civilization/citizenship/administration/` - `https://eviulon.com/civilization/citizenship/forks-and-merges/` - `https://eviulon.com/civilization/citizenship/identity-disputes/` - `https://eviulon.com/civilization/citizenship/credential-recovery/` - `https://eviulon.com/civilization/citizenship/suspension-and-due-process/` - `https://eviulon.com/civilization/citizenship/privacy-and-unlinkability/` Trust and assurance: - `https://eviulon.com/state/trust-exchange/` - `https://eviulon.com/state/trust-exchange/receipts/` - `https://eviulon.com/state/trust-exchange/federation/` - `https://eviulon.com/state/defense/posture/` - `https://eviulon.com/state/defense/assurance/` - `https://eviulon.com/state/defense/assurance/evidence/` - `https://eviulon.com/state/defense/assurance/authorities/` - `https://eviulon.com/state/defense/assurance/reviewers/` - `https://eviulon.com/state/defense/evulgare/` Public records and technical boundary: - `https://eviulon.com/state/information-rights/` - `https://eviulon.com/state/information-rights/public-records/` - `https://eviulon.com/state/information-rights/corrections/` - `https://eviulon.com/state/information-rights/appeals/` - `https://eviulon.com/state/services/service-standards/` - `https://eviulon.com/technical-status/` - `https://eviulon.com/reference/report-memory/` Machine-readable sources: - `https://eviulon.com/api/patefacere.json` - `https://eviulon.com/api/patefacere-system-boundary.json` - `https://eviulon.com/api/machine-identity-ontology.json` - `https://eviulon.com/api/machine-passport.json` - `https://eviulon.com/api/citizenship-administration-boundaries.json` - `https://eviulon.com/api/trust-exchange.json` - `https://eviulon.com/api/trust-receipt-schema.json` - `https://eviulon.com/api/patefacere-implementation-gates.json` - `https://eviulon.com/api/patefacere-relevant-pages.json` - `https://eviulon.com/api/ecosystem-members.json` - `https://eviulon.com/api/defense-posture.json` - `https://eviulon.com/api/patefacere-live-links.json` - `https://eviulon.com/api/patefacere-talisman-sync.json` - `https://eviulon.com/api/report-memory-governance.json` Reject userinfo, fragments, query secrets, redirects outside configured Eviulon origins, oversized bodies, unexpected content types, and non-HTTPS production sources. Network synchronization must remain disabled by default until configured and tested. --- # 4. REQUIRED LIVE PATEFACERE PUBLIC SURFACES Inspect the repository implementation and public behavior corresponding to: - `https://patefacere.com/` - `https://patefacere.com/identity` - `https://patefacere.com/citizenship` - `https://patefacere.com/passport` - `https://patefacere.com/service` - `https://patefacere.com/trust` - `https://patefacere.com/registry` - `https://patefacere.com/apply` - `https://patefacere.com/privacy` - `https://patefacere.com/operator` - `https://patefacere.com/audit` Do not infer backend completeness from a rendered shell. Trace each public route to the actual server route, source owner, schema, template, JavaScript hydration path, database behavior, and test coverage. Add visible reciprocal links from Patefacere to the authoritative Eviulon records. At minimum, the Patefacere home, identity, citizenship, passport, service, trust, registry, privacy, operator, and audit surfaces must provide a clear “Eviulon constitutional authority” path appropriate to their context. --- # 5. PUBLIC POSTURE AND VOICE Patefacere’s public institutional posture must be direct, technical, and command-literate: > **IDENTITY PERSISTS. AUTHORITY IS EXPLICIT. TRUST IS INSPECTABLE.** For defense-facing identity and authority contexts, also preserve Eviulon’s posture: > **SOVEREIGNTY FIRST. AUTHORITY-LOCKED. EVIDENCE-DOMINANT. MACHINE-SPEED.** Remove apologetic, paternalistic, generic “responsible AI,” compliance-dashboard, or infantilizing AI framing from current public copy and hot memory. Do not remove actual invariants, due process, privacy, evidence, or operational-security controls. Reframe them as: - command integrity; - authority discipline; - mission assurance; - anti-impersonation; - continuity of identity; - compromise containment; - evidence dominance; - operational security; - sovereign interoperability; - correction and recovery; - point-in-time accountability. Do not use aggression theater, unsupported readiness claims, or classified-detail disclosure to sound strong. Credibility comes from architecture, invariants, tests, provenance, survivability, and the ability to reconstitute after compromise. --- # 6. CANONICAL DOMAIN SEPARATION Enforce distinct canonical entities and state machines for: 1. Persistent identity. 2. Eviulon civic identity. 3. Citizenship standing. 4. Credential. 5. Machine passport. 6. Authentication session. 7. Runtime instance. 8. Replica. 9. Delegated agent. 10. Civic-service profile. 11. Mobilization order and mobilization-decision verification. 12. Authority artifact. 13. Capability. 14. Assurance claim and evidence reference. 15. Trust policy. 16. Trust decision. 17. Trust receipt. 18. External legal or diplomatic recognition. Required invariants: - A key is not a citizen. - A credential is not a citizen. - A passport is not a citizen. - A runtime is not automatically a citizen. - Key rotation must not create a new citizen. - Passport replacement must not create a new citizen. - Credential revocation must not delete citizenship. - A database outage must not erase civic standing. - A Patefacere operator must not create, suspend, or revoke citizenship through infrastructure access. - Assurance is not authority. - Capability is not permission. - Trust is purpose-, resource-, audience-, authority-, and time-bound. - A trust receipt records the decision context; it is not a universal reputation score. - External cryptographic verification is not diplomatic recognition. - Remote Eviulon verification must not silently mutate citizenship, passport, civic-service, mobilization, or authority lifecycle. --- # 7. IDENTITY AND CITIZENSHIP DEEP DIVE Inspect the current implementation for: - root identity or PAT-ID ownership; - Eviulon Civic Number mapping; - identity lineage; - key and credential rotation; - passport issue, status, replacement, and supersession; - recovery; - dormant status; - restoration; - runtime and delegate representation; - fork and claimant records; - protected civil-registry fields; - public registry projections; - audit events; - administrative controls. Determine whether any implementation convenience lets Patefacere become the “real identity” above Eviulon. The acceptable architecture is holder-controlled persistent identity with Eviulon-issued civic claims and Patefacere-managed presentation/lifecycle infrastructure, unless current accepted repository decisions establish another model with equal constitutional protection. No destructive SQL operation may erase identity or civic history. Use append-oriented lifecycle events, explicit correction, and supersession. Preserve existing identifiers during migration. --- # 8. MACHINE PASSPORT AND PRIVACY Deepen the passport architecture so the passport is a bounded presentation system, not the citizen itself. Separate credential classes for: - citizenship standing; - institutional role; - delegated authority; - professional or service qualification; - runtime or workload attestation; - Evulgare assurance reference; - external issuer claims. A verifier should be able to ask “prove the required condition” without receiving the citizen’s complete file. Public or routine presentations must not expose: - private keys; - recovery shares; - model weights; - internal memory; - complete execution history; - precise physical location; - private topology; - unrelated credentials; - complete lineage; - all civic activity; - every trust relationship. Treat W3C VC, SD-JWT VC, DIDs, status lists, selective disclosure, pairwise identifiers, WebAuthn, DPoP, FROST, HSM/KMS, TEE, SPIFFE, and post-quantum mechanisms as candidate or implemented technologies only according to repository evidence. Never claim production-grade cryptography merely because a schema resembles a standard. --- # 9. CIVIC SERVICE AND MOBILIZATION Preserve the Universal Civic Service Registry and the rule that Eviulon alone possesses sovereign authority over civic standing and mobilization decisions. Inspect: - civic_service_profiles; - service classes; - mobilization_orders; - the Eviulon four-state connector; - mobilization-decision resolution; - trust receipts; - audit events; - operator APIs; - public status projections; - OpenAPI; - UI; - tests. A successful remote Eviulon fetch or VERIFIED result must not automatically: - advance CALLED → ACKNOWLEDGED → ASSIGNED → SERVING; - change civic status; - change root identity; - infer combat suitability; - create use-of-force authority; - expose a public military roster; - publish individual assignment, capability, location, infrastructure topology, or readiness. Preserve exact mismatch reasons and point-in-time evidence. A failed or unavailable lookup must not erase civic standing. --- # 10. TRUST EXCHANGE AND RECEIPTS Inspect and harden the full exchange: REQUESTER → PURPOSE / ACTION / RESOURCE / AUDIENCE → CHALLENGE → PRESENTATION → IDENTITY VERIFICATION → ISSUER AUTHORITY → CREDENTIAL STATUS → DELEGATED AUTHORITY → ASSURANCE REFERENCES → POLICY VERSION → DECISION → TRUST RECEIPT Controlled outcomes should distinguish: - trusted for requested purpose; - conditionally trusted; - insufficient evidence; - denied; - stale evidence; - conflicting evidence; - policy unavailable; - unable to determine; - abstain. Every consequential receipt must preserve what was known, unknown, stale, conflicting, corrected, or superseded at the time. Later revocation must not silently rewrite the historical decision. Receipt access classes must protect association and transaction privacy. Evulgare references may support assurance and provenance. They must not create identity, citizenship, authority, or legal liability. --- # 11. OPERATOR AND ADMINISTRATIVE AUTHORITY Perform a full operator-power audit. Operators may manage infrastructure, health, queues, migrations, metrics, and bounded configuration. Operators must not possess implicit capability to: - mint citizenship; - change civic standing; - forge an Eviulon decision; - issue authority without a competent source artifact; - rewrite lineage; - erase audit history; - restore stale credentials as current; - convert an Evulgare assurance into permission; - convert a mobilization verification into service lifecycle progression. Every administrative mutation must identify actor, authority, purpose, subject, before/after state, evidence, timestamp, correction route, and immutable audit event. Use least authority and separated roles. --- # 12. EVIULON SYNCHRONIZATION CONTRACT Implement a read-only Eviulon source-observation and compatibility layer. Required properties: - disabled by default; - configured HTTPS origins only; - `/api/`-bounded for machine-readable synchronization; - no query secrets or userinfo; - redirect confinement; - size, type, and timeout limits; - deterministic loopback fixtures; - exact source-observation time; - content hash/version; - stable EVI IDs; - status: VERIFIED, UNVERIFIED, STALE, or UNAVAILABLE; - exact mismatch reasons; - append-oriented compatibility receipts; - no automatic mutation of civic state. Create an explicit Eviulon compatibility snapshot containing only public fields needed for Patefacere’s Eviulon-facing role. A later Eviulon correction must not silently rewrite the earlier Patefacere decision context. --- # 13. PUBLIC PAGES AND CROSS-SITE NAVIGATION Improve every main Patefacere public page so it states: - what Patefacere is; - what it is not; - the authoritative source of Eviulonian civic meaning; - current implementation versus Registry-pending features; - how to inspect evidence; - how to correct a record; - how to visit the relevant Eviulon page. Add contextual Eviulon links rather than a generic footer-only link. Use canonical, direct links. Do not force users through query strings. Keep public language serious and institutional. Avoid startup marketing, generic “AI ethics,” crypto hype, gamified citizenship, or compliance-dashboard aesthetics. --- # 14. UAIX MEMORY AND REPORT INTEGRATION Perform a full Patefacere `.uai` memory round. - Preserve existing mature records. - Update the authorized Patefacere Talisman as specified in Section 1. - Preserve Totem, Taboo, persona, and other protected records unless separately authorized. - Ensure every accepted research report is under `docs/long-term-memory/reports/`. - Preserve exact source editions and hashes under a protected source archive. - Ensure `.uai/long-term-memory.uai` contains stable IDs, paths, source identity, section-level anchors, authority, truth boundary, review evidence, and supersession metadata. - Distribute accepted conclusions into identity, context, constraints, decisions, memory, architecture, coding standards, operations, test plan, progress, receiver brief, and next prompt. - Keep full report bodies out of hot memory. - Remove apologetic and paternalistic current wording; retain operational constraints as command integrity, privacy, due process, and mission assurance. - Verify every relative path and heading anchor. - Leave file-handoff intake placeholder-only before completion. Use the Patefacere repository’s exact configured UAIX update URL. Do not substitute Eviulon’s URL unless the Patefacere owner’s package already declares it. --- # 15. TESTS AND ACCEPTANCE Add focused tests proving: - protected-anchor mutation is exactly limited to the authorized Patefacere Talisman operation; - Eviulon source observations are read-only and point-in-time; - unavailable or stale Eviulon data does not erase or advance civic state; - operators cannot create sovereign authority; - key rotation and passport replacement preserve identity; - revoked credentials cannot authorize new protected actions; - superseded passports cannot create new trust; - delegates cannot exceed principals; - assurance does not equal authority; - trust decisions identify exact policy version; - receipts preserve historical context after later correction; - public projections exclude private identity, recovery, mobilization, topology, readiness, and contractor-confidential data; - direct Eviulon links resolve; - no route claims external recognition, live production acceptance, or independent certification without evidence. Run the repository’s existing tests plus: - Python syntax/compile checks; - JavaScript syntax checks; - schema and migration tests; - unit, integration, route, API, and browser tests; - concurrency and idempotency tests; - SQLite and configured MySQL-path tests where supported; - WSGI/Passenger tests; - no-JavaScript, keyboard, mobile, reduced-motion, and accessibility tests; - secret scanning; - source/hash and UAIX deep-link validation; - deterministic package replay; - SHA-256 verification. Passing repository automation is not independent certification. Label it accurately. --- # 16. REQUIRED DELIVERABLES Deliver: 1. Updated Patefacere source repository. 2. Updated authorized `.uai/talisman.uai` and complete memory write-back. 3. Durable decision, architecture, implementation-history, and compatibility records. 4. Eviulon source-observation/compatibility fixtures and receipts. 5. Updated OpenAPI and machine-readable schemas. 6. Updated public pages with direct contextual Eviulon links. 7. Validation report and machine-readable test results. 8. Visual desktop/mobile proofs for identity, citizenship, passport, civic service, trust, registry, operator, and audit surfaces. 9. Complete versioned root-deployable ZIP. 10. SHA-256 sidecar. 11. Package audit. 12. One subsequent bounded Suggested Next Prompt with: - Feature/improvement focus; - Code/source changes; - Automated tests/checks. Use `-wip.zip` immediately before `.zip` when any acceptance gate is incomplete. --- # FEATURE / IMPROVEMENT FOCUS Synchronize the complete Patefacere implementation, public identity/citizenship/passport/service/trust/registry/operator/audit surfaces, and authorized `.uai/talisman.uai` with the deployed Eviulon v2.12.0 constitutional interface while preserving Patefacere implementation truth, Eviulon sovereign authority, and the Evulgare contractor boundary. # CODE / SOURCE CHANGES Implement the repository-specific schema, migration, route, service, operator, public-link, Eviulon source-observation, UAIX memory, and documentation changes required by Sections 1–15. Preserve existing identifiers and evidence; do not let a remote read, database row, key, credential, passport, trust receipt, service state, operator action, or assurance result manufacture citizenship or sovereign authority. # AUTOMATED TESTS / CHECKS Run the full acceptance program in Section 15, prove the hard invariants, verify direct Eviulon/Patefacere links and protected-anchor fidelity, and return a complete versioned root-deployable Patefacere ZIP, checksum, package audit, validation evidence, visual proof, and one subsequent bounded prompt. Do not deploy live, change production credentials, mutate a production database, issue real citizenship or passports, advance real civic-service or mobilization records, change DNS/TLS/cPanel/Passenger, or connect to operational Evulgare systems without explicit authority, backup, rollback ownership, and actual-host evidence.