{
  "id": "sample-audit-current@5",
  "schema": "woc.record.v1",
  "subject": "Word of Clout self-audit procedure — @5 evidence-class narrowing",
  "record_class": "self_audit",
  "material_class": "self_audit",
  "public_key": "-----BEGIN PUBLIC KEY-----\nMCowBQYDK2VwAyEAZAXc8TrIl05HTq4oDHbsc2Qf8SA6pydv3jbaUV4kSyA=\n-----END PUBLIC KEY-----",
  "propositions": [
    {
      "id": "self-audit:receipt_observable",
      "proposition": "The published receipt (sample-audit-n50-20260907T043637Z.out, sha256 4a763180b1aa2c92dc48cdd49f8016d0ac079846f8823e8f869aa5970497e83b) records 50 distinct verification ids: 42 board and 8 NPI. Under PROCEDURE-FAULT-1 v2 re-parse, 49 rows have expected == actual (agree); 1 row (row 13) carries a not-rederivable marker. Retained as published ledger extract at /verify/self-audit/2026-09-06T200705434Z/ledger/ (20/20 SHA256SUMS-verified) and /verify/self-audit/2026-09-07T043637637Z/ledger/ (50/50 SHA256SUMS-verified). Runner published at /verify/self-audit/observation-extract-runner.mjs re-derives 49/50 agree + 1 NOT-REDERIVED (ver:board:mo-dental:2025005314:address_of_record:2026-09-04@old, PROCEDURE-FAULT-1 v2 rule-short-circuit).",
      "evidence_class": "receipt_observable",
      "state": "VERIFIED",
      "authority": "operator run receipt",
      "verified_at": "2026-09-22T04:27:00.000Z",
      "method": "recount of the published receipt; ledger extract published at /verify/self-audit/2026-09-07T043637637Z/ledger/ with SHA256SUMS; re-derivation runner at /verify/self-audit/observation-extract-runner.mjs",
      "next_required_by": "2026-12-06T04:36:37.637Z",
      "decay_class": "unmeasured",
      "provenance": {
        "verified_at_source": "OBSERVED",
        "next_required_by_source": "POLICY"
      }
    },
    {
      "id": "self-audit:frame_unverifiable",
      "proposition": "The frame is every verification row recorded in the Word Of Clout published-records store at cutoff 2026-09-07T04:36:37.637Z. The frame row count is not recorded in the run receipt; the frame hash at the cutoff was not captured.",
      "evidence_class": "run_design",
      "state": "UNVERIFIABLE",
      "authority": "@4 narrowing (R15-2(d))",
      "method": "UNVERIFIABLE - missing precondition: frame count/hash at cutoff not recorded",
      "missing_precondition": "frame count/hash at cutoff not recorded",
      "next_admissible_step": "a successor run that records the frame row count and frame hash at the cutoff",
      "provenance": {
        "next_required_by_source": "N/A"
      }
    },
    {
      "id": "self-audit:draw_unverifiable",
      "proposition": "The draw used MongoDB's server-side $sample aggregate (sample_audit.js:91) against the frame. The sampler source that ran (sampler 51b81d94, sample_audit.js sha256 51fdb0dd3568cbe8faba3798a86428d341f66b052221fc9daf0075416333827d) is published at /verify/self-audit/sample_audit.js so the method can be inspected; no seed was recorded in the receipt, so the draw cannot be reproduced.",
      "evidence_class": "run_design",
      "state": "UNVERIFIABLE",
      "authority": "@4 narrowing (R15-2(d))",
      "method": "UNVERIFIABLE - missing precondition: no seed recorded; the draw cannot be reproduced (DRAW-REPRODUCIBLE-1 is the next admissible step)",
      "missing_precondition": "no seed recorded; the draw cannot be reproduced (DRAW-REPRODUCIBLE-1 is the next admissible step)",
      "next_admissible_step": "DRAW-REPRODUCIBLE-1 — a successor run that records the seed, the RNG, and the draw algorithm in the receipt",
      "provenance": {
        "next_required_by_source": "N/A"
      }
    },
    {
      "id": "self-audit:fault_classification",
      "proposition": "Row 13 (ver:board:mo-dental:2025005314:address_of_record:2026-09-04@old) fault class NOT-REDERIVED / sub-cause rule-short-circuit - this is a RETROSPECTIVE classification assigned from the receipt marker and the sampler source, not an emission of the run itself.",
      "evidence_class": "retrospective",
      "state": "VERIFIED",
      "authority": "@4 narrowing - the classification is a later labeling, not a run emission",
      "verified_at": "2026-09-22T04:27:00.000Z",
      "method": "retrospective classification under PROCEDURE-FAULT-1 v2",
      "next_required_by": "2026-12-06T04:36:37.637Z",
      "decay_class": "unmeasured",
      "provenance": {
        "verified_at_source": "OBSERVED",
        "next_required_by_source": "POLICY"
      }
    },
    {
      "id": "self-audit:bound_conditional",
      "proposition": "0 disagreements in 49 re-derived rows; the exact one-sided 95% binomial upper bound on the frame error rate among re-derivable verification rows is 1 - 0.05^(1/49) = 5.93% approx 5.9%, conditional on the run design above (the 50 rows are the ones in the receipt; the frame, the draw, and the re-derivation for the fault row cannot be independently established for this run). The retained re-derivable artifact is the ledger extract at /verify/self-audit/2026-09-07T043637637Z/ledger/ with SHA256SUMS and the observation-extract-runner.mjs published beside it.",
      "evidence_class": "receipt_observable",
      "state": "VERIFIED",
      "authority": "@4 narrowing",
      "verified_at": "2026-09-22T04:27:00.000Z",
      "method": "exact binomial one-sided 95% upper bound; ledger extract and runner at /verify/self-audit/ published as retained artifact",
      "next_required_by": "2026-12-06T04:36:37.637Z",
      "decay_class": "unmeasured",
      "provenance": {
        "verified_at_source": "OBSERVED",
        "next_required_by_source": "POLICY"
      }
    },
    {
      "id": "self-audit:run_inventory",
      "proposition": "2 published receipts: 951d0480bd92f162bf21986134e86f48ac3dbe47b37934b9a486042d50a0b776 published at /verify/self-audit/sample-audit-20260906T200704Z.out; 4a763180b1aa2c92dc48cdd49f8016d0ac079846f8823e8f869aa5970497e83b published at /verify/self-audit/sample-audit-n50-20260907T043637Z.out.",
      "evidence_class": "receipt_observable",
      "state": "VERIFIED",
      "authority": "@4 narrowing",
      "verified_at": "2026-09-22T04:27:00.000Z",
      "method": "published receipt catalogue",
      "next_required_by": "2026-12-06T04:36:37.637Z",
      "decay_class": "unmeasured",
      "provenance": {
        "verified_at_source": "OBSERVED",
        "next_required_by_source": "POLICY"
      }
    },
    {
      "id": "self-audit:run_completeness",
      "proposition": "The published run-inventory records 2 runs; run completeness rests on WoC host records — whether additional runs occurred is not independently verifiable from the published receipts alone.",
      "evidence_class": "run_design",
      "state": "UNVERIFIABLE",
      "authority": "@4 narrowing (R15-2(d))",
      "method": "UNVERIFIABLE - run completeness rests on WoC host records",
      "missing_precondition": "run completeness rests on WoC host records",
      "next_admissible_step": "RUN-LEDGER-1 — every run appends its receipt hash to the int1-signed host snapshot at run time",
      "provenance": {
        "next_required_by_source": "N/A"
      }
    }
  ],
  "dependency_manifest": {
    "ruleset_version": "woc.records.ruleset.self-audit.v1",
    "evaluation_cutoff": "2026-09-22T04:27:00.000Z",
    "receipt": {
      "name": "sample-audit-n50-20260907T043637Z.out",
      "sha256": "4a763180b1aa2c92dc48cdd49f8016d0ac079846f8823e8f869aa5970497e83b",
      "bytes": 14731,
      "citation": "/verify/self-audit/sample-audit-n50-20260907T043637Z.out"
    }
  },
  "dependency_manifest_sha256": "960f6729efc681ab82418bb42ef747b0bf33103eca51b3213cb1a8a5066923c0",
  "signed_scope_note": "The signature covers exactly: id, schema, subject, created_at (the EVIDENCE CUTOFF — the newest evidence timestamp in the derived snapshot, NOT the issuance time), issued_at (the issuance time of THIS record, distinct from the evidence cutoff — a record can never acquire an earlier issuance time because its evidence is older), public_key, propositions (four-state verdicts only, POLICY next_required_by = min(90d interval, authority-stated expiry at 00:00 America/Chicago)), candidate_relations (evidence joins carrying no verdict), dependency_manifest, dependency_manifest_sha256, signed_scope_note, supersedes — every field except signature, signing, and derivation. The derivation block (the queries that produced this record) is display metadata, excluded from signing. dependency_manifest_sha256 is the SHA-256 hex of the canonical form of dependency_manifest (key-sorted, no whitespace) — the same recipe as this record's own canonical form (equal manifest values hash equally regardless of stored key order). The field names in this note are the signed field names — machine-replayable values, labeled as such; the sentences around them state their meaning.",
  "issued_at": "2026-09-23T20:28:37.359Z",
  "supersedes": [
    "sample-audit-current@4"
  ],
  "signature": "3FoGMj7BJd4YawBhQNkwojOHV5HrmIPuHQrs4rulEYHQFn/IiTruc/2lallrq5fagmIUeRiuDntD+cWJ7ytLBA==",
  "signing": {
    "algorithm": "Ed25519",
    "hash": "SHA-256",
    "canonical_form": "canonical form (key-sorted, no whitespace; signature, signing, and derivation excluded)",
    "signed_at": "2026-09-23T20:28:37.793Z",
    "note": "Signed with the production signing key; the public key below is derived from it (SubjectPublicKeyInfo format, byte-identical under DER encoding) and matches the authority key embedded in the active crosswalk generation. The canonical-form recipe is published at /laws/canonicalization-v1.md."
  }
}