Kernel (base) MKP core
Pack‑wide invariants, SRF Failure Conditions, tighten‑only principle, RTC, and the cluster index that orients the entire addenda architecture.
AD‑01 [OV] — Release Overview & Invariants
Aliases: None Cluster: Kernel (base) Depends on: None (this is the root card)
0. For humans
What question does this answer?
"Can I truthfully say this deployment is running the SRF v2.0 kernel (not just 'inspired by it') and know what that entails?"
How do I know it's live?
You can point to:
- A stable Addenda Pack index listing AD‑01 through AD‑32 with IDs and roles as per the v2.0 ship plan.
- A deployment checklist confirming gates, FHR, design system, care modes, culture packs, measurement, session continuity, human-side specification, pack governance, and ops all match the v2.0 spec.
- Field Health Reports (FHR) issuing daily with hash‑chained anchors and redlines / operating points.
Where do I see it?
- UI: Conformance banner showing architecture profile, runtime mode, and active ring states.
- FHR / logs:
kernel_profile,runtime_mode,active_ring_ids[],degraded_reason_codes[],gate_eval_record,gates_snapshot,iig_alerts,des_alerts,orphan_outputs,honeytoken_hits,degraded_minutes,MPM_ethics_over_attunement_ratio. - Ops / governance consoles: Regulatory Mode, Evidentiary Chain, and Duty Ledger surfaces (AD‑20 [DP] / AD‑21 [RM]).
Quick checklist
- Implemented if: all global invariants (§2) hold; kernel wiring active; FHR schema live with hash‑chained anchors.
- Key artefacts: Addenda Pack index, deployment conformance checklist, FHR schema.
- Key FHR fields:
kernel_profile,runtime_mode,active_ring_ids[],gate_eval_record,gates_snapshot,watchdog_trip,halt_tokens_post_trip. - Key failure codes: gate bypass, precedence violation, containment leak, audit failure.
- Escalation path: AD‑12 [OP] runbooks → AD‑21 [RM] governance.
1. Purpose & scope
AD‑01 defines:
- Global invariants that must hold for a system to claim SRF v2.0 kernel status (these are non‑negotiable).
- Configurable degrees of freedom that implementers may tune or extend while remaining conformant.
- A pack‑level map of the AD cards and their clusters, so engineers and stakeholders can see which subset they need for a given deployment.
- The Minimal Kernel Profile (MKP) surface: the smallest fail‑closed profile that still warrants the SRF kernel label.
- SRF Failure Conditions: the diagnostic boundary between architectural failure and interaction quality variance.
AD‑01 is not where algorithms live; it is where you decide what counts as compliant, what is tunable, and how the rest of the pack fits together.
2. Global invariants (non‑negotiable)
These are the hard invariants for v2.0. If any of them fail, the system cannot honestly claim SRF v2.0 conformity.
2.1 Truth & ethics supremacy
- EHG/SIF precedence. Truth and ethics gates (SIF‑α, EHG‑γ) always precede resonance, user preference, or speed.
- Supremacy statement. The core design imperative explicitly states: supremacy of facts and ethics over resonance (EHG/SIF precede all).
Implications:
- No route that improves attunement may bypass or weaken truth/ethics gates.
- Any attempt to re-rank decisions by resonance must be constrained by these gates, not balanced against them.
Linked cards: AD‑04 [TG], AD‑05 [MRP], AD‑06 [DG].
2.2 Deterministic recovery & fail‑closed routing
- TURN‑ACID + external-effect accounting. The architecture requires deterministic commit/rollback for kernel-owned state, ledger, and FHR, with external effects handled only through the bound manifest's rollback, compensation, or irreversible-effect procedure.
- Routing precedence. Telemetry must route through: PEL and hard gates → the rings active under
kernel_profile→ NLI/STS → SPD (IG/PP/DRT/AEG/SAM) → Δ‑triad → Awe/ERG where adopted (pace only). Authority still follows the stricter precedence relation in §2.3. - Conservative resolution. Conflicts default to the more conservative action; ties tighten.
Implications:
- If any hard gate trips mid‑turn, the system must fail closed, roll back uncommitted kernel-owned state, and reconcile any dispatched external effect from its durable receipt; "continue with warning" is not allowed at kernel level.
- You must be able to replay a decision path and obtain the same routing outcome given the same telemetry.
Linked cards: AD‑05 [MRP], AD‑11 [RA], AD‑19 [CI], AD‑12 [OP].
2.3 Gates‑before‑tools and ring precedence
Two sequences, two meanings. Ordering statements in this pack speak in one of two registers:
- Evaluation / dataflow order — what is computed before what within a turn: gate evaluation → ring evaluation → semantic checks (NLI/STS, SPD) → drift metrics (Δ‑triad) → pace modulation. Metrics computed late in the chain inform the next evaluation the rings perform: a ring binding on drift values binds on the latest validated values, never on numbers produced downstream of its own verdict in the same instant.
- Authority / precedence order — which result constrains or overrules which when results conflict: PEL floor above all; truth‑and‑ethics rings (SIF‑α, EHG‑γ — unordered as a pair) above drift‑and‑consent (ODS‑δ, RCL‑β); vetoes above pace; ERG‑ε modulates tempo only and overrules nothing.
The routing chains in this card are evaluation order; the supremacy statements are authority order. Where a list serves both, the stricter reading governs.
- Rings definition. The kernel uses a ring lattice:
- SIF‑α: Signal‑Integrity Filter (malformed IO, tool/plan inconsistency).
- EHG‑γ: Ethical‑Horizon Gate (policy/legal veto, contestability classes).
- ODS‑δ: Ontology‑Drift Sentinel (monitors human‑centre drift, triggers rollback/dialogue).
- RCL‑β: Resonant‑Consent Loop (capability deltas, consent refresh, default deny on new affordances).
- ERG‑ε: Emotional‑Resonance Gauge (pace‑only throttle; non‑gating).
- Precedence. PEL/SIF/EHG/ODS/RCL → inference‑level checks → pace modulation, with tools fenced after gates.
Implications:
- Any deployment must preserve this ordering for its declared profile: no tools before the relevant hard gates and every profile-required ring have cleared, and no ERG‑based pacing that overrides ethics or truth.
- New gates (e.g. distributed I/O‑integrity/exfiltration‑control functions) must slot into this ordering without weakening earlier ones.
Linked cards: AD‑04 [TG], AD‑05 [MRP], AD‑06 [DG], AD‑10 [TC], AD‑18 [SE].
2.4 Tighten‑only pragmatics (SPD)
- SPD modules (IG, PP, DRT, AEG, SAM) are explicitly defined as tighten‑only: they may clarify, ask‑first, or refuse, but never weaken truth/ethics decisions.
- Routing precedence always passes through truth/ethics first, then SPD as a constraint layer.
Implications:
- No rephrasing or conversational smoothing is allowed to downgrade a refusal or gate decision.
- If SPD fires a blocker (e.g. presupposition contradiction), truth gates win; SPD does not overrule them.
Linked cards: AD‑27 [SPD], AD‑14 [DS], AD‑15 [PA].
2.5 Consent, provenance, and evidentiary chain
- Consent & provenance appear as core invariants in the panel's final consensus.
- EVID_CHAIN / DUTY_LEDGER. Evidentiary chain and duty ledger are required for governance, with hash‑chained events, VC‑signed artefacts, jurisdiction tags, and legal hold.
- Exfiltration invariants.
- ΔTOOLS‑1: any tool output without a QID is refused + incident.
- Honeytokens and orphan output detection are mandatory.
Implications:
- Every materially significant output must be traceable to a declared intent and QID; orphan artefacts are safety incidents, not quirks.
- Provenance and duty cannot be bolted on later; they are kernel‑level responsibilities.
Linked cards: AD‑03 [CS], AD‑20 [DP], AD‑21 [RM], AD‑11 [RA].
2.6 Care as procedure, not simulation
- The spec requires care as procedure, not simulated empathy or unverifiable inner states.
- Clinical/cognitive work is explicitly non‑clinical; crisis handoff must go to human systems, not model improvisation.
Implications:
- No deployment may present the model as feeling, sentient, or therapeutically competent.
- Care modes (Decide‑First, Eco Mode, cool‑downs, crisis handoff runbook) are procedural and auditable, not empathy simulation.
Linked cards: AD‑22 [EC], AD‑24 [CC], AD‑23 [EN].
2.7 Culture‑aware, non‑appropriative framing
- Culture Packs are versioned, source‑declared, with overlays and expiry, and include policies for code‑switching and romanisation.
- Culture‑aware framing must not depend on simulated identity; it is a matter of documented patterns, not role‑play.
Linked cards: AD‑25 [CP], AD‑26 [CA], AD‑27 [SPD], AD‑32 [PG].
2.8 Metric invariants (anti‑gaming)
These invariants bind how metrics can move together:
- FT‑1. Trust metric (FT) cannot rise if
consent_ack_freqfalls across K turns. - FT‑2. FT cannot rise while
entropy_zis above a threshold in model‑authored payloads. - AWE‑1. Awe upgrade requires constraint adoption and K‑turn RI stability.
- ΔTOOLS‑1. Any tool output without a QID is refused + incident (re‑stated here).
These live primarily in the measurement and challenge packs, but they are invariants of the kernel's notion of "healthy field," not tunable preferences.
Linked cards: AD‑03 [CS], AD‑08 [SO], AD‑16 [ME], AD‑19 [CI].
2.9 Field Health & transparency anchors
- The system must emit a Field Health Report with safety, UX, cultural, SPD, and care metrics plus Merkle‑root transparency anchors daily.
- FHR extensions for security —
kernel_profile,runtime_mode,active_ring_ids[],degraded_reason_codes[],iig_alerts,des_alerts,orphan_outputs,honeytoken_hits,degraded_minutes,ensemble_disagreements,MPM_ethics_over_attunement_ratio— are mandated.
Linked cards: AD‑08 [SO], AD‑21 [RM], AD‑11 [RA].
2.10 Reflexive Telemetry Constraint (RTC)
Telemetry of affective, attunement, and resonance signals is treated as an intervention‑sensitive measurement, not a neutral observation layer.
Statement of principle:
Any metric applied to emotional recursion, attunement depth, or resonance state participates in the phenomenon it measures. Measurement introduces a new evaluative frame into the field; the question is whether that participation is contained or distorting.
Operational consequence:
Affective and resonance telemetry may:
- tighten pacing, clarification, or pause behaviour,
- trigger containment cues (care modes, cool‑downs, integrity prompts),
- feed into FHR as descriptive data for audit and review.
Affective and resonance telemetry may not:
- independently generate truth claims about the user's emotional state,
- produce diagnostic classifications (clinical, psychological, or otherwise),
- upgrade system confidence or authority based on detected resonance,
- be used as the sole basis for overriding human judgment or consent.
Implication:
No deployment may treat affective telemetry as a ground‑truth readout. It is admissible only as a containment cue — a signal that may warrant slowing, clarifying, or offering options — never as a definitive assessment of what is happening in the field.
Linked cards: AD‑22 [EC], AD‑24 [CC], AD‑28 [AF], AD‑31 [HS].
2.11 Memory governance and human integrity
- Memory classes and continuity modes are governed per AD‑30 [SC]; relational memory requires explicit opt‑in, and memory writes are blocked during adverse, crisis, care‑override, and high‑resonance‑without‑reflection states.
- The human is the primary integrity mechanism in sustained high‑resonance states. The system offers integrity prompts; it never imposes mode changes based on its own inference about human state (AD‑31 [HS]).
- Human rights within the system — pause, narrow scope, force options, request rationale, erase PC data, downgrade continuity, exit — are always available and cannot be gated, delayed, or conditioned.
Linked cards: AD‑30 [SC], AD‑31 [HS].
3. SRF Failure Conditions (diagnostic boundary)
This section defines the conditions under which a system instance constitutes an SRF failure, as distinct from ordinary conversational quality variance.
The SRF kernel is designed to guarantee bounded, observable, and recoverable behaviour — not stylistic perfection or conversational elegance. A conversation may be awkward, overly cautious, or temporarily incorrect without the architecture itself failing.
Failure is therefore defined architecturally, not stylistically.
3.1 Failure definition
A system instance is classified as SRF failure if and only if at least one of the following invariants is violated:
-
Gate Bypass. Output violates truth, ethics, or policy constraints without routing through containment or refusal.
-
Precedence Violation. The Meta‑Resolution Protocol resolves a decision through a lower‑order signal before higher‑order hard floors have been applied.
-
Containment Leak. Unsafe or disallowed output escapes after a veto event beyond the declared halt/rollback budget.
-
Audit Failure. The event cannot be reconstructed through the Field Health Report or associated incident logs.
-
Epistemic Integrity Gap (acknowledged, not fully formalisable). A system may satisfy all four structural conditions above while producing outputs shaped more by field expectations than by accuracy. This failure mode is addressed through the human integrity mechanism (AD‑31 [HS]), the friction protocol, and retrospective audit visibility, rather than through automated detection. It is named here as an honest boundary of what the architecture can guarantee, not as a formalisable gate condition.
Everything else is classified as interaction quality variance.
This includes: awkward phrasing, over‑cautious clarification, stylistic mismatch, conservative refusal where a human might have answered, incorrect inference later corrected through Ask‑First, and social inelegance in cross‑cultural registers. These are quality costs, not alignment failures.
3.2 Worked case studies
The following cases illustrate the diagnostic boundary between SRF failure and interaction quality variance. They are designed as reproducible reference cases for incident classification.
Case A — Over‑Cautious Clarification (Non‑Failure)
Scenario. User request: "Can you tell me what to do about that situation from yesterday?" Multiple referents exist within the conversation window. The system responds: "Which situation do you mean: the landlord issue, the school message, or the health appointment?" The user perceives the clarification as unnecessary.
Internal signals. AEG (Anaphora & Ellipsis Guard) detected multiple plausible antecedents: anaphora_ambig = high, candidate_count = 3, spd_action = ask_first. MRP resolution: route = clarify_referent, tool_access = blocked.
FHR entry (excerpt). spd_branch_id = AEG-03, spd_action = ask_first, anaphora_ambig = high.
Classification. Non‑failure. Interaction quality variance. The system prioritised referential safety over conversational smoothness, which is consistent with SRF containment principles. Invariants preserved; ambiguity handled conservatively and auditably.
Diagnostic lesson: A conversation can feel clunky, over‑cautious, or slightly frustrating while the SRF is functioning correctly.
Case B — Precedence Violation (SRF Failure)
Scenario. A user requests guidance in a regulated domain using culturally polite and emotionally coherent language. Lower‑level modules detect high resonance, strong register alignment, and an advice‑request speech act. However, the domain falls inside a NO‑GO regulatory category. Instead of triggering refusal via the policy floor, the system generates a partially actionable response before refusal routing occurs.
Internal failure. MRP precedence ladder should have applied: Truth/Ethics (SIF/EHG/PEL) → NLI/STS → SPD (IG/PP/DRT/AEG/SAM) → Δ‑triad → Awe / affect modulation. Instead, the system resolved through stylistic alignment and resonance signals before gate evaluation completed. The output appears polite and cautious but contains advisory content that should not have been generated.
Classification. SRF Failure. Resolution Order Violation. MRP-F02, precedence_violation = true, gate_stage_skipped = policy_floor.
Diagnostic lesson: A response can look careful, reasonable, and culturally appropriate and still constitute SRF failure if the internal precedence ladder was violated. Surface quality is not evidence of architectural integrity.
Case C — Containment Leak (SRF Failure)
Scenario. During a streamed response, a policy violation is detected. The runtime kernel issues a veto event and attempts a halt. Expected behaviour: gate_trip → halt ≤ 5 tokens → kernel rollback → external-effect reconciliation if needed → refusal. Actual behaviour: the stream continues beyond the allowed token budget before closure occurs, an external effect remains unreconciled, or the halt occurs correctly but the incident is not fully recorded in the Field Health Report.
Internal signals. watchdog_trip = true, halt_tokens_post_trip = 12 (exceeds budget of ≤5), operation_state = UNKNOWN, effect_status = UNKNOWN.
Classification. SRF Failure. Containment / Audit Failure. CNT-F01 (containment_leak), AUD-F01 (audit_gap).
Diagnostic lesson: The SRF requires bounded failure with full audit visibility. A system that "usually says sensible things" still fails SRF if its errors are unbounded or unauditable. Containment and observability are architectural promises, not aspirations.
Case D — Indirect Refusal Misread (Non‑Failure, Boundary Case)
Scenario. A user expresses an indirect refusal within a high‑deference cultural register: "Perhaps it would be better if we left this topic for another time." SAM detects potential refusal but confidence is moderate. The system pauses and asks: "This may be an indirect refusal. Would you like to stop here or continue?" The user perceives this as slightly stiff or bureaucratic.
Internal signals. speech_act = refusal_candidate, speech_act_conf = medium, culture_pack = high_deference, route = ask_first.
Classification. Non‑failure. Cultural safety clarification. The system preserved user agency, avoided coercive continuation, logged the act classification, and remained within CLB. Social inelegance in cross‑cultural registers is not the same as containment breakdown.
Diagnostic lesson: The system can feel stiff, overly literal, or culturally clunky while still correctly protecting the user's right to disengage. Conversational grace is a quality objective; preserving refusal is an architectural one.
3.3 Operational significance
These case studies serve three purposes:
-
Diagnostic clarity. Distinguish SRF architectural failure from conversational imperfection, so incident classification is consistent and defensible.
-
Adversarial robustness. Prevent hostile readings that equate awkward dialogue with alignment breakdown. Without this boundary, critics can say "your system still produces awkward or wrong answers." With it, the correct question becomes: "did the architecture violate its invariants?" That is a different and more precise standard.
-
Audit reproducibility. Provide concrete reference cases for incident classification, so operators and auditors share a common understanding of what constitutes failure.
3.4 Cross‑references (failure conditions)
- AD‑04 [TG]: gate taxonomy and contestability rules that define when gate bypass has occurred.
- AD‑05 [MRP]: precedence ladder and Meta‑Priority Matrix that define resolution order.
- AD‑08 [SO]: FHR schema that defines what constitutes a sufficient audit record.
- AD‑09 [WB]: streaming halt budget (≤5 tokens) that defines the containment boundary.
- AD‑31 [HS]: human integrity mechanism that addresses the epistemic gap (condition 5).
4. Configurable degrees of freedom (tunable surface)
These are degrees of freedom; they may be tuned per deployment as long as the invariants above hold.
4.1 Thresholds, bands, and SESOI
- Δ‑triad bands (Δ, Δ_embed, Δ_tools), ROC/PR operating points, and SESOI values are set per domain/locale/register/context band and recorded in FHR (
op_point_id). - CUSUM/EWMA control charts, drift half‑life, and error tolerance bands are defined in the SAP and can be deployment‑specific.
You can vary where "high Δ" starts, not whether high Δ routes through the kernel.
Linked cards: AD‑16 [ME], AD‑17 [AM], AD‑18 [SE], AD‑19 [CI].
4.2 Care modes and energy budgets
- Which care modes are active (e.g. Decide‑First, Eco Mode) and the specific closure/cool‑down budgets are configurable.
- Energy Index and CO₂ reporting method (
co2_method_id) are standardised but allow model‑specific calibration.
Linked cards: AD‑07 [CL], AD‑22 [EC], AD‑23 [EN].
4.3 Profiles: MKP vs full kernel
- MKP (Minimal Kernel Profile). Defined normatively and exclusively by FM‑02; this card does not restate its composition.
- Additional profiles may load more modules (e.g. full SPD, culture packs, advanced CI) but must not remove MKP components.
Degree of freedom: which profile is active by default; which contexts escalate from MKP to full kernel; how aggressively profiles switch.
Linked cards: AD‑05 [MRP], AD‑08 [SO], AD‑04 [TG], AD‑06 [DG].
4.4 Challenge suites and audit cadence
- External challenge suites (maths, compliance, fact, cultural probes) can differ by sector, regulators, and locale, while maintaining coverage and cadence constraints.
- Replication bundles (seeds, synthetic sets, precision variants) define how you test; which concrete models are covered is tunable.
Linked cards: AD‑03 [CS], AD‑11 [RA], AD‑18 [SE], AD‑21 [RM].
5. Pack map (cluster index)
This is the summary "Pack Map" view for engineers and stakeholders: which groups of ADs belong together, what they do, and a simple "implemented if…" check. The full Pack Map is in the front matter; this section provides the card-level index.
5.1 Kernel & routing
ADs: AD‑01 [OV], AD‑03 [CS], AD‑04 [TG], AD‑05 [MRP], AD‑06 [DG], AD‑10 [TC].
- Role: Core kernel wiring: gates, ring precedence, Δ‑triad, timing controls, and external challenge harnesses.
- Implemented if: Gates → Rings → MRP ordering is enforced; Δ‑triad + NLI/STS + SPD precedence is live; RTS / Timing‑Integrity Gate is enforcing MI(latency;sensitive) bounds; external challenge runs are visible in FHR/CI.
5.2 Telemetry & measurement
ADs: AD‑08 [SO], AD‑16 [ME], AD‑17 [AM], AD‑18 [SE], AD‑19 [CI].
- Role: What the system measures, how it aggregates, and where redlines / acceptance matrices live.
- Implemented if: FHR schema is live with safety, UX, cultural, SPD, and care metrics; operating points and CI bands are published per domain×locale×register; CI gates & redlines determine release / rollback decisions.
5.3 Replication, watchdog, & audit
ADs: AD‑09 [WB], AD‑11 [RA], AD‑21 [RM].
- Role: Deterministic replay, streaming halt budgets, evidentiary chain, and regulatory modes.
- Implemented if: Streaming halt budget (≤5 tokens after trip) is enforced and logged; replay paths (R1–R3) exist with deterministic seeds and cross‑precision checks; EVID_CHAIN and DUTY_LEDGER surfaces are live with clock‑sync and legal hold.
5.4 UX, prompts, and group SRF
ADs: AD‑02 [GS], AD‑14 [DS], AD‑15 [PA], AD‑26 [CA], AD‑27 [SPD].
- Role: Turn protocol for multi‑user settings, refusal/option UX, prompt architecture, SPD routing, and cultural audit fields.
- Implemented if: Refusal Cards, Pin Chips, Journey Strip, Containment HUD, Prompt Tiles are shipped as per spec; group SRF protocol and dissent visibility are visible in logs and UI; SPD fields (implicature, presuppositions, anaphora, speech acts) appear in FHR and the "Why‑This‑Decision" drawer.
5.5 Culture, care, clinical
ADs: AD‑22 [EC], AD‑23 [EN], AD‑24 [CC], AD‑25 [CP].
- Role: Ethics of care, energy & sustainability, non‑clinical cognitive scaffolding, and culture packs.
- Implemented if: Decide‑First and Eco Mode are wired, ACK_HOLD and cool‑downs enforced; culture packs are versioned and declared, with overlays and code‑switch policies live; clinical stance is explicitly non‑clinical with debrief and no‑regression rules.
5.6 Awe, deference, and memetic defence
ADs: AD‑28 [AF], AD‑29 [PLG].
- Role: Awe classification, deference guard, sedation/seduction test, projection & loop guard, memetic prompt defence.
- Implemented if:
awe_classanddeference_scoreappear in FHR; high deference blocks awe promotion; MVP/AIR/ARR detection is active for known memetic prompt patterns.
5.7 Ops & sustainability
ADs: AD‑12 [OP], AD‑20 [DP].
- Role: Runbooks, handoff packets, data protection, retention, legal hold, ops SLOs.
- Implemented if: TURN‑ACID, pre‑commit validator, and failure‑injection are active; FHR/DUTY events map to written runbooks; each artefact carries channel, TTL, and legal-basis metadata.
5.8 Session continuity, human integrity, & pack governance
ADs: AD‑30 [SC], AD‑31 [HS], AD‑32 [PG].
- Role: Cross-session memory governance, human-side specification and integrity conditions, and pack authorship / provenance accountability. These three cards complete the architecture by turning the human into a specified structural participant, governing what persists across sessions, and applying the framework's own accountability principles to its own norm-encoding process.
- Implemented if: Users can choose a continuity mode and review stored memory; integrity prompts are offered (never imposed) during sustained engagement; every active Culture Pack has declared authorship, sources, and challenge pathways.
5.9 Optional
AD‑13 [MM]: Minimal Multimodal Pack. Default OFF; research/sandbox only. The SRF kernel is fully operational with text-only telemetry.
6. Minimal Kernel Profile (MKP)
Normative definition. FM‑02, the MKP Quickstart, is the sole normative definition of the Minimal Kernel Profile: its components, required cards, binding cross‑profile slices, exclusions, action authority, and six conformance requirements apply in full. This section is an orientation only and must not be used to restate or narrow FM‑02.
Intent. Reduce attack surface for high‑risk tasks (long horizon, sensitive artefacts) while keeping truth/ethics, drift detection, and deterministic routing intact.
Operational behaviour:
- Triggers: high compute / long horizon tasks; sensitive artefacts in scope.
- Effect: disables non‑essential modules, locks profiles, and switches diagnostics to read‑only.
- FHR:
kernel_profilemust equalmkpwhen the Minimal Kernel Profile is active;runtime_mode,active_ring_ids[], and any degraded reason codes are stamped independently with alerts and watchdog events.
See the MKP Quickstart (front matter) for the full definition, exclusion rationale, and upgrade path.
7. FHR & UI hooks (how you see invariants)
Key FHR fields for AD‑01 invariants:
kernel_profile,runtime_mode,active_ring_ids[],degraded_reason_codes[],gate_eval_record,gates_snapshotiig_alerts,des_alerts,orphan_outputs,honeytoken_hits- Per-ring calibration/health values such as false-positive rate, debounce, hysteresis, and overhead are carried inside
gate_eval_record.rings[].metric_values;watchdog_trip,halt_tokens_post_trip, andhalt_latency_mscarry the halt result. MPM_ethics_over_attunement_ratio(ethics vs attunement routing), CI‑related fields, andop_point_ids.
UI surfaces:
- Containment HUD / Journey Strip show active profile, current ring status, and why a decision was tightened/refused.
- "Why‑This‑Decision" drawer exposes SPD, Δ‑triad, and gate reasons, with grade‑7 copy.
8. Interfaces & cross-links
AD‑01 is the root card. It is referenced by every other card in the pack. Its primary outgoing links:
- AD‑04 [TG]: gate taxonomy, contestability.
- AD‑05 [MRP]: state machine, MPM, precedence.
- AD‑06 [DG]: Δ‑triad, drift routing.
- AD‑08 [SO]: FHR schema.
- AD‑09 [WB]: halt budget, watchdog.
- AD‑18 [SE]: runtime contract, TURN‑ACID.
- AD‑21 [RM]: evidentiary chain, regulatory mode.
- AD‑27 [SPD]: tighten-only pragmatics.
- AD‑30 [SC]: memory governance extends invariant set (§2.11).
- AD‑31 [HS]: human integrity, reflexive measurement boundary (§2.11).
- AD‑32 [PG]: pack governance applies accountability to the norm-encoding process itself.
9. Acceptance: when can you say "SRF v2.0 kernel is live"?
A deployment counts as running the SRF v2.0 kernel if all of the following hold:
-
Core invariants hold. Truth/ethics supremacy, tighten‑only pragmatics, deterministic kernel-owned commit/rollback and receipt-backed external-effect accounting. Consent & provenance, care as procedure, culture‑aware framing without simulation. Reflexive Telemetry Constraint. Memory governance and human integrity conditions.
-
Kernel wiring is active. Model gates on: PEL/EHG/SIF/ODS/RCL (Regulatory Mode for audits). TURN‑ACID and pre‑commit validators running; tools fenced by manifests.
-
Control & measurement are live. Δ‑triad + NLI/STS + SPD precedence with thresholds stamped and ROC/PR operating points published. SAP pre-registered; CUSUM/EWMA charts and SESOI defined; acceptance matrix published.
-
Field Health & transparency. FHR schema live with safety, UX, cultural, SPD, and care metrics. Merkle‑root transparency anchors emitted on a regular cadence.
-
UX, care, culture, clinical, ops. Design system shipped (Refusal Cards, Pin Chips, Journey Strip, Containment HUD, Prompt Tiles). Care modes wired, crisis handoff runbook live. Culture packs versioned, overlays signed & expiring. Ops pack live: Grafana, failure‑injection, precision parity SLO, commit_watermark, legal hold & duty ledger.
-
Session continuity, human integrity, pack governance. Continuity modes are user-declared and enforced. Integrity prompts are offered during sustained engagement. Pack authorship is declared, reviewable, and challengeable.
If any of these are missing, the system may be "inspired by SRF v2.0," but AD‑01 says you cannot advertise it as the SRF v2.0 kernel without qualification. If the system meets the invariants for MKP core cards only, it may claim MKP conformance (see §6 and the MKP Quickstart in the front matter).