{
  "id": "sample-audit-current",
  "schema": "woc.record.v1",
  "subject": "Word of Clout self-audit — random re-derivation sample",
  "created_at": "2026-09-18T00:00:00Z",
  "public_key": "-----BEGIN PUBLIC KEY-----\nMCowBQYDK2VwAyEAsoQqXlS+BPslGxKacfi5faDs5+k52FJwmBZJCMO0EZ0=\n-----END PUBLIC KEY-----",
  "propositions": [
    {
      "id": "sample-audit:drawn",
      "proposition": "50 recorded verification rows drawn at random from the verification ledger — the kernel's own recorded verification events, not the propositions published in signed records. Draw convention: a server-side random draw, deduplicated by verification id, at the run cutoff 2026-09-07T04:36:37Z. Each drawn row is one proposition-level verdict for one provider. A provider counts as an error when any of their drawn propositions' re-derived verdict differs from the recorded verdict — that is how a proposition-level difference becomes a provider-level error. Eligible provider count: not recorded in the run receipt — the receipt records the drawn rows and their outcomes, not the distinct-provider denominator of the frame.",
      "state": "VERIFIED",
      "authority": "Self-audit procedure — independent re-derivation from observations (NOT the original verification code path)",
      "verified_at": "2026-09-07T04:36:37Z",
      "method": "Independent re-derivation of each drawn verification row from its cited observations. Sampling frame: the verification ledger at the run cutoff. Draw: server-side random, deduplicated by verification id. Draw unit: the recorded verification row. Error unit: the provider.",
      "next_required_by": "2026-12-06T00:00:00Z",
      "decay_class": "t2",
      "reason": "The draw unit is the recorded verification row (proposition-level); the error unit is the provider. A provider with several drawn propositions counts once, as an error if any of them differs. This avoids double-counting correlated errors within a provider.",
      "provenance": {
        "verified_at_source": "OBSERVED — the signed host snapshot's sample-audit run of 2026-09-07 (drawn, agreed, and disagreed counts recorded in the snapshot payload)",
        "next_required_by_source": "DERIVED — t2 decay class, 90 days from the run date"
      }
    },
    {
      "id": "sample-audit:error-definition",
      "proposition": "Error definition: a re-derived proposition verdict differs from the recorded verdict. Both must be derived from the SAME cited observations, using the SAME ruleset, against the SAME evaluation cutoff. A difference in any of these is a procedure error (excluded from the error rate — recorded separately as a procedure fault).",
      "state": "VERIFIED",
      "authority": "Self-audit procedure definition — explicit, repeatable",
      "verified_at": "2026-09-07T04:36:37Z",
      "method": "The error rate is: propositions whose independently re-derived verdict differs from the recorded verdict, divided by total propositions in the sample. Procedure faults (observation mismatch, ruleset drift, cutoff drift) are recorded but excluded — they are not verification errors.",
      "next_required_by": "2026-12-06T00:00:00Z",
      "decay_class": "t2",
      "provenance": {
        "verified_at_source": "OBSERVED — procedure document, committed to repo",
        "next_required_by_source": "DERIVED — t2 decay class, 90 days"
      }
    },
    {
      "id": "sample-audit:bound",
      "proposition": "One-sided 95% Clopper-Pearson upper bound: 0 errors in 50 draws → 5.8%. This one-sided 95% confidence bound is the largest true error rate consistent with observing zero errors in a sample of 50 at α=0.05. The bound is stated, not the point estimate — the point estimate is 0% which would overstate precision.",
      "state": "VERIFIED",
      "authority": "Binomial confidence interval — Clopper-Pearson (exact), one-sided upper bound at 95% confidence",
      "verified_at": "2026-09-07T04:36:37Z",
      "method": "Clopper-Pearson exact binomial: for n=50, k=0, α=0.05 (one-sided), the upper bound p satisfies P(X ≤ 0 | p) = (1-p)^50 ≥ 0.05, solving to p ≤ 1 - 0.05^(1/50) ≈ 0.0582 → 5.8%.",
      "next_required_by": "2026-12-06T00:00:00Z",
      "decay_class": "t2",
      "provenance": {
        "verified_at_source": "OBSERVED — Clopper-Pearson computation, independently verifiable",
        "next_required_by_source": "DERIVED — t2 decay class, 90 days"
      }
    }
  ],
  "signature": "3E6GKyTYEdzM4xsaB/amxqzLc1ycqnXtA+hmDfX0KLpQ7zBaXRamyQV+bPGHw1YFDCoJ6slEpUqf9Glu+oDAAw==",
  "signing": {
    "algorithm": "Ed25519",
    "hash": "SHA-256",
    "canonical_form": "stableStringify (key-sorted, no whitespace)",
    "signed_at": "2026-09-18T06:54:27.560Z",
    "note": "Preview signing key; production record signing is a root-held authority."
  }
}
