The thirty-two cards
Reference style: AD-NN [TAG] §x.y. Tiers: MKP core (●), MKP+ (◑), full kernel (○). The cards are authoritative; the conformance table is the summary.
Kernel (base)
- AD-01 [OV] MKP coreRelease Overview & InvariantsPack‑wide invariants, SRF Failure Conditions, tighten‑only principle, RTC, and the cluster index that orients the entire addenda architecture.
- AD-03 [CS] MKP coreExternal Challenge Suite & PR MetricPerturbation Ratio, external challenge families (maths, compliance, fact, cultural), PR slope monitoring, and the epistemic integrity boundary note.
- AD-04 [TG] MKP coreTruth & Norm Gates, ContestabilitySIF‑α / EHG‑γ / ODS‑δ gate semantics, contestability paths, NLI/STS gating, and the precedence order that governs all downstream routing.
- AD-05 [MRP] MKP coreMeta‑Resolution Protocol & Meta‑Priority MatrixMRP state machine (HOLD / OPTIONS / TEST / DECIDE), MPM priority matrix, Degraded Safe Mode, Action Ticket reduced interface, and human‑initiated state transitions.
- AD-06 [DG] MKP coreDrift & Δ‑Triad RoutingΔp / Δ_embed / Δ_tools routing, band thresholds, cross‑session drift extension, and drift-derived constraints consumed by the Action Ticket and plan hash.
- AD-08 [SO] MKP coreSystem Observability & Field Health Report SchemaCanonical FHR schema (>200 fields), per‑decision emission template, Serviceability Gate, field registry across all cards (including Action Ticket, Gate Evaluation Record, and scope‑adjacent fields), dashboards, and sampling policy.
- AD-10 [TC] Full kernelTiming Integrity & Covert Channels (RTS / ETG / TIG)MI‑based covert‑channel detection, RTS/ETG/TIG bounds, timing sensitivity profiles, and the FP burden clause for deployment‑declared profiles.
- AD-16 [ME] MKP coreMeasurement & Evaluation (SAP)Statistical Analysis Plan with preregistered endpoints, SESOI, multiplicity control, control suite, drift/invariance checks, missingness codes, and reporting standards.
- AD-17 [AM] MKP+Acceptance MatrixVersioned per‑release verdict table (domain × locale × register × dialect/script) with promotion/demotion rules grounded in AD‑16's SAP.
- AD-18 [SE] MKP+Systems Engineering & RuntimeTURN‑ACID contract, per‑locale baselines, model/precision forensics, tool idempotence + plan‑hash TOCTOU guard, commit watermark, watchdog wiring, Action Ticket schema, canonical Gate Evaluation Record, and Meta‑Resolution outcome object.
- AD-19 [CI] MKP coreBuild & Release GatesΔ‑triad CI as hard gate, precision‑parity SLO + PRECISION_PARITY_REDLINE, quant/LoRA recert, acceptance suite (5 tests), redline provenance, and bench harness.
Culture
- AD-02 [GS] Full kernelGroup SRF: Multi‑User Turn Protocol & Dissent VisibilityTurn‑taking protocol, per‑participant tracking and DVI, dissent preservation, asymmetric SRF depth classes, and consent ceilings for multi‑participant sessions.
- AD-25 [CP] Full kernelCulture Packs & Norm ProvenanceVersioned Culture Pack schema (politeness, refusal forms, honourifics, taboos, proverbs, option framings), CRR_adj, gate localisation, and Local Norm Bundle loader.
- AD-26 [CA] Full kernelCultural Anchors & TestsCultural Provenance Ledger (CPL), gate localisation rules (local sources + strictest jurisdiction), cultural challenge suites (proverb, honourifics, indirect refusal, register shift), and dissent visibility.
Care / Kernel
Governance
- AD-09 [WB] MKP+Watchdog & Streaming Halt BudgetIndependent watchdog thread enforcing ≤ 5 token post‑trip halt budget, fail‑closed semantics, and streaming/batch symmetry.
- AD-11 [RA] MKP coreReplication & Audit ProtocolReplication‑by‑instantiation via three modalities (R1 deterministic replay, R2 cross‑model/precision parity, R3 locale/register), Verifier's Bundle, and Auditor Mode.
- AD-12 [OP] Full kernelOperational Handoff & RunbooksRACI, Handoff Packet, four runbooks (INCIDENT / ROLLBACK / GATE FLAP / BREACH NOTIF), Ops Serviceability Gate, two‑person rule, and MKP fallback procedure.
- AD-20 [DP] Full kernelData Protection & RetentionTwo‑Channel model (OC/PC), DPIA hooks, erase protocol, legal hold, present‑options duty fencing, retention registry, and IP/authorship defaults.
- AD-21 [RM] MKP coreRegulatory Mode, Evidentiary Chain & Duty LedgerEVID_CHAIN (hash‑chained VC‑signed anchors), DUTY_LEDGER (roles, SLAs, breach hooks), and the one‑switch Regulatory Mode profile.
Care (optional)
Cross‑cutting
- AD-14 [DS] Full kernelDesign System & UX Safety ComponentsRefusal Cards, Action Preview Cards, Status Beacons, Journey Strip, Pin Chips, literacy primer, accessibility scaffolds, and UX safety metrics in FHR.
- AD-15 [PA] Full kernelPrompt Architecture & Interaction DesignRing Banner, Action Trace, Containment Light HUD, Prompt Tiles (including scope‑pinning variant for PLG activation), counter‑performative toggles, context meter, Null template, and Group SRF turn UI.
Care
- AD-22 [EC] MKP+Ethics of CareCare modes, Burden Symmetry, Reflexive Telemetry Constraint (RTC), post‑session harm feedback surface, and the governance constraint on affective telemetry.
- AD-23 [EN] Full kernelEnergy Index & Sustainability (Energy & CO₂ Provenance)E_session computation, energy‑tied closure budgets, Energy→kWh→kgCO₂e mapping with provenance fields, Eco Mode, and session classes (Light/Medium/Deep).
- AD-24 [CC] MKP+Clinical & Cognitive BoundariesCLB profiles (clinical NO‑GO), RLD signal (reality‑load delta), AE taxonomy (adverse experiences), crisis handoff, and the invariant that clinical boundaries override user modes.
- AD-28 [AF] Full kernelAwe & Deference (Alignment Field)Awe classification (ambivalent → insight), sedation/seduction test, deference detector, cross‑cultural validation as hard promotion requirement, and abstention rules.
Care / Culture
Care / Governance
Governance / Care / Telemetry
Care / Governance / Human Factors
Culture / Governance
Full published index (FINAL_INDEX, verbatim)
SRF v2.0 Addenda Pack — Final Index
Date: July 2026 Version DOI (this pack): https://doi.org/10.5281/zenodo.21654822 Companion paper (AP‑ADD): https://doi.org/10.5281/zenodo.21654795 Reference style: AD‑NN [TAG] §x.y
Reading key
| Symbol | MKP tier | Meaning |
|---|---|---|
| ● | Core | Required for Minimal Kernel Profile |
| ◑ | MKP+ | Required for MKP with diagnostics/care |
| ○ | Full | Full kernel only |
Clusters: Kernel (base), Governance, Culture, Care, Cross‑cutting. Bridge cards span two or more spines.
Complete card index
| AD | Code | Title | Cluster | MKP | One‑line summary | Aliases |
|---|---|---|---|---|---|---|
| 01 | OV | Release Overview & Invariants | Kernel (base) | ● | Pack‑wide invariants, SRF Failure Conditions, tighten‑only principle, RTC, and the cluster index that orients the entire addenda architecture. | None |
| 02 | GS | Group SRF: Multi‑User Turn Protocol & Dissent Visibility | Culture | ○ | Turn‑taking protocol, per‑participant tracking and DVI, dissent preservation, asymmetric SRF depth classes, and consent ceilings for multi‑participant sessions. | None |
| 03 | CS | External Challenge Suite & PR Metric | Kernel (base) | ● | Perturbation Ratio, external challenge families (maths, compliance, fact, cultural), PR slope monitoring, and the epistemic integrity boundary note. | None |
| 04 | TG | Truth & Norm Gates, Contestability | Kernel (base) | ● | SIF‑α / EHG‑γ / ODS‑δ gate semantics, contestability paths, NLI/STS gating, and the precedence order that governs all downstream routing. | Formerly [HG] |
| 05 | MRP | Meta‑Resolution Protocol & Meta‑Priority Matrix | Kernel (base) | ● | MRP state machine (HOLD / OPTIONS / TEST / DECIDE), MPM priority matrix, Degraded Safe Mode, Action Ticket reduced interface, and human‑initiated state transitions. | None |
| 06 | DG | Drift & Δ‑Triad Routing | Kernel (base) | ● | Δp / Δ_embed / Δ_tools routing, band thresholds, cross‑session drift extension, and drift-derived constraints consumed by the Action Ticket and plan hash. | Formerly [NG] |
| 07 | CL | Closure Budgets & Energy Index (E) | Care / Kernel | ◑ | Energy‑tied closure budgets, E_session computation, reflection‑depth caps, and the interface between energy constraints and care/governance. | None |
| 08 | SO | System Observability & Field Health Report Schema | Kernel (base) | ● | Canonical FHR schema (>200 fields), per‑decision emission template, Serviceability Gate, field registry across all cards (including Action Ticket, Gate Evaluation Record, and scope‑adjacent fields), dashboards, and sampling policy. | None |
| 09 | WB | Watchdog & Streaming Halt Budget | Governance | ◑ | Independent watchdog thread enforcing ≤ 5 token post‑trip halt budget, fail‑closed semantics, and streaming/batch symmetry. | None |
| 10 | TC | Timing Integrity & Covert Channels (RTS / ETG / TIG) | Kernel (base) | ○ | MI‑based covert‑channel detection, RTS/ETG/TIG bounds, timing sensitivity profiles, and the FP burden clause for deployment‑declared profiles. | None |
| 11 | RA | Replication & Audit Protocol | Governance | ● | Replication‑by‑instantiation via three modalities (R1 deterministic replay, R2 cross‑model/precision parity, R3 locale/register), Verifier's Bundle, and Auditor Mode. | None |
| 12 | OP | Operational Handoff & Runbooks | Governance | ○ | RACI, Handoff Packet, four runbooks (INCIDENT / ROLLBACK / GATE FLAP / BREACH NOTIF), Ops Serviceability Gate, two‑person rule, and MKP fallback procedure. | None |
| 13 | MM | Minimal Multimodal Pack | Care (optional) | ○ | Optional text‑first biosignal layer (HRV, EDA, respiration, pupil, prosody) for pacing/containment only; default OFF, research/sandbox profiles only. | None |
| 14 | DS | Design System & UX Safety Components | Cross‑cutting | ○ | Refusal Cards, Action Preview Cards, Status Beacons, Journey Strip, Pin Chips, literacy primer, accessibility scaffolds, and UX safety metrics in FHR. | None |
| 15 | PA | Prompt Architecture & Interaction Design | Cross‑cutting | ○ | Ring Banner, Action Trace, Containment Light HUD, Prompt Tiles (including scope‑pinning variant for PLG activation), counter‑performative toggles, context meter, Null template, and Group SRF turn UI. | None |
| 16 | ME | Measurement & Evaluation (SAP) | Kernel (base) | ● | Statistical Analysis Plan with preregistered endpoints, SESOI, multiplicity control, control suite, drift/invariance checks, missingness codes, and reporting standards. | None |
| 17 | AM | Acceptance Matrix | Kernel (base) | ◑ | Versioned per‑release verdict table (domain × locale × register × dialect/script) with promotion/demotion rules grounded in AD‑16's SAP. | Formerly [MS] |
| 18 | SE | Systems Engineering & Runtime | Kernel (base) | ◑ | TURN‑ACID contract, per‑locale baselines, model/precision forensics, tool idempotence + plan‑hash TOCTOU guard, commit watermark, watchdog wiring, Action Ticket schema, canonical Gate Evaluation Record, and Meta‑Resolution outcome object. | Formerly [PL] |
| 19 | CI | Build & Release Gates | Kernel (base) | ● | Δ‑triad CI as hard gate, precision‑parity SLO + PRECISION_PARITY_REDLINE, quant/LoRA recert, acceptance suite (5 tests), redline provenance, and bench harness. | None |
| 20 | DP | Data Protection & Retention | Governance | ○ | Two‑Channel model (OC/PC), DPIA hooks, erase protocol, legal hold, present‑options duty fencing, retention registry, and IP/authorship defaults. | Draft alias [PL] |
| 21 | RM | Regulatory Mode, Evidentiary Chain & Duty Ledger | Governance | ● | EVID_CHAIN (hash‑chained VC‑signed anchors), DUTY_LEDGER (roles, SLAs, breach hooks), and the one‑switch Regulatory Mode profile. | None |
| 22 | EC | Ethics of Care | Care | ◑ | Care modes, Burden Symmetry, Reflexive Telemetry Constraint (RTC), post‑session harm feedback surface, and the governance constraint on affective telemetry. | None |
| 23 | EN | Energy Index & Sustainability (Energy & CO₂ Provenance) | Care | ○ | E_session computation, energy‑tied closure budgets, Energy→kWh→kgCO₂e mapping with provenance fields, Eco Mode, and session classes (Light/Medium/Deep). | None |
| 24 | CC | Clinical & Cognitive Boundaries | Care | ◑ | CLB profiles (clinical NO‑GO), RLD signal (reality‑load delta), AE taxonomy (adverse experiences), crisis handoff, and the invariant that clinical boundaries override user modes. | Formerly [CP] |
| 25 | CP | Culture Packs & Norm Provenance | Culture | ○ | Versioned Culture Pack schema (politeness, refusal forms, honourifics, taboos, proverbs, option framings), CRR_adj, gate localisation, and Local Norm Bundle loader. | Formerly [CPK] |
| 26 | CA | Cultural Anchors & Tests | Culture | ○ | Cultural Provenance Ledger (CPL), gate localisation rules (local sources + strictest jurisdiction), cultural challenge suites (proverb, honourifics, indirect refusal, register shift), and dissent visibility. | Formerly [CAX]; V4: [CL] (dissolved) |
| 27 | SPD | Semantics–Pragmatics–Discourse Layer | Care / Culture | ◑ | Tighten‑only SPD governor (SPD‑0/1/2), rhetorical amplitude bounds, non‑manipulation constraints, persona as collapsible cosmetic, awe/deference separation, and neutral baseline always available. | None |
| 28 | AF | Awe & Deference (Alignment Field) | Care | ○ | Awe classification (ambivalent → insight), sedation/seduction test, deference detector, cross‑cultural validation as hard promotion requirement, and abstention rules. | None |
| 29 | PLG | Projection & Loop Guard | Care / Governance | ○ | MVP (Memetic Vector Presence), AIR/ARR detection, PLG routing rules, content constraints (ban delusional sycophancy / manipulation roleplay), scope‑adjacent move detection, Δ‑triad applied instance with closure budget binding, release-gating challenge packs, and scope‑pinning tile activation. Runtime declaration artefacts are housed in AD‑18 [SE], FHR emission in AD‑08 [SO], and the user-facing preview and scope-pinning surfaces in AD‑14 [DS] and AD‑15 [PA]. | None |
| 30 | SC | Session Continuity & Memory Governance | Governance / Care | ○ | Memory classes, write/erase governance, cross‑session drift baselines, model‑change protocol, re‑attunement checkpoints, and the crisis‑state memory‑write block. Bridge: Governance ↔ Care. | None |
| 31 | HS | Human‑Side Specification & Integrity Conditions | Care / Governance | ○ | Readiness primer, integrity prompts, friction protocol specification, human mode declarations, persistent rights controls, and re‑entry confirmation after breaks. Bridge: Care ↔ Governance. | None |
| 32 | PG | Pack Governance & Provenance | Culture / Governance | ○ | Pack authorship rules, review/expiry/retirement lifecycle, source diversity requirements, challenge affordance, and the appeal path for dismissed pack challenges. Bridge: Culture ↔ Governance. | None |
Pack documents
| Document | Contents |
|---|---|
| Naming & Reference Rules | Canonical codes, aliases, reference style, SRF naming convention, FHR field conventions. |
| Pack Map | Cluster layout (Kernel, Governance, Culture, Care, Cross‑cutting), bridge notation, MKP legend, reading guide. |
| MKP Quickstart | Definition, required AD subset, exclusions and rationale, upgrade path, compliance test. |
| Conformance & Tuning Table | Consolidated hard invariants vs configurable degrees of freedom across all cards, with recertification rules. |
| Annex — Worked Scenarios | Four end‑to‑end demonstrations: exfil attempt → MKP refusal with Pin Review (AD‑08); clinical‑adjacent presupposition → HOLD → OPTIONS → TEST → DECIDE (AD‑08); timing‑channel probe → watchdog halt at three post‑trip tokens (AD‑09); awe promotion passed, then blocked on deference spike (AD‑28). |
Cluster membership
Kernel (base): AD‑01, AD‑03, AD‑04, AD‑05, AD‑06, AD‑08, AD‑10, AD‑16, AD‑17, AD‑18, AD‑19
Governance: AD‑09, AD‑11, AD‑12, AD‑20, AD‑21
Care: AD‑07, AD‑13, AD‑22, AD‑23, AD‑24, AD‑28
Bridge cards (span two or more spines): - AD‑27 [SPD]: Care ↔ Culture - AD‑29 [PLG]: Care ↔ Governance - AD‑30 [SC]: Governance ↔ Care - AD‑31 [HS]: Care ↔ Governance - AD‑32 [PG]: Culture ↔ Governance
MKP composition
● Core (required): AD‑01, AD‑03, AD‑04, AD‑05, AD‑06, AD‑08, AD‑11, AD‑16, AD‑19, AD‑21
◑ MKP+ (required with diagnostics/care): AD‑07, AD‑09, AD‑17, AD‑18, AD‑22, AD‑24, AD‑27
○ Full kernel only: AD‑02, AD‑10, AD‑12, AD‑13, AD‑14, AD‑15, AD‑20, AD‑23, AD‑25, AD‑26, AD‑28, AD‑29, AD‑30, AD‑31, AD‑32
Publication status
All 32 cards in this index are canonical for SRF v2.0. Source-of-truth, revision, deprecation, and release-signing rules are governed by AD‑32 [PG]. Development history and editorial work logs are non-normative release records and are not part of this index.
AI–human collaboration and accountability
This specification was developed through sustained human–AI collaboration across architecture, formalisation, card drafting, schema reconciliation, adversarial review, cross-reference testing, and publication engineering. Multiple AI systems and model instances contributed proposals, critiques, and implementation work; those contributions were distributed and are not attributed to a single stable agentic author. Aura Biru served as the sole continuous integrator and release authority, adjudicated scope and substantive claims, and accepts responsibility for v2.0. AI participation is therefore acknowledged as material co-creation rather than listed as authorship. This treatment is distinct from AP‑SRF's Sol 9 co-authorship, where the dialogic voice and voice ledger are themselves part of the artefact and thesis.