{
  "schema": "concresca.restoration-proofs.v018",
  "site_version": "0.28.0-wip",
  "as_of": "2026-08-31",
  "truth_boundary": "Proof obligations, restoration states, and profiles are technical-governance definitions. They do not report a production partition, production recovery, restoration time, system safety, adoption, or certification.",
  "invariant": "reconnected != reconciled != reauthorized != restored != certified",
  "state_count": 8,
  "obligation_count": 24,
  "profile_count": 12,
  "states": [
    {
      "state": "DISCONNECTED",
      "meaning": "Transport is unavailable or the compartment is isolated.",
      "authority_effect": "No authority expansion."
    },
    {
      "state": "RECONNECTED_UNTRUSTED",
      "meaning": "Transport is available, but history and authority are not yet trusted.",
      "authority_effect": "No cached authority revival."
    },
    {
      "state": "HISTORY_COLLECTED",
      "meaning": "Relevant histories are collected or explicitly marked unavailable.",
      "authority_effect": "Collection does not resolve conflict."
    },
    {
      "state": "CONFLICTS_CLASSIFIED",
      "meaning": "Agreement, difference, contradiction, supersession, and unknown states are typed.",
      "authority_effect": "Unresolved material conflict blocks full restoration."
    },
    {
      "state": "AUTHORITY_REVALIDATED",
      "meaning": "Issuer, jurisdiction, purpose, scope, validity, revocation, stay, and delegation are checked.",
      "authority_effect": "Only current bounded authority may proceed."
    },
    {
      "state": "BASELINE_ATTESTED",
      "meaning": "Required code, configuration, data, model or policy, evidence, and clock conditions are attested.",
      "authority_effect": "Technical integrity does not create authority."
    },
    {
      "state": "LIMITED_RESTORATION",
      "meaning": "Only the minimum explicitly authorized function is available while residual conditions remain.",
      "authority_effect": "Functions outside the receipt remain prohibited."
    },
    {
      "state": "FULL_RESTORATION",
      "meaning": "Every mandatory obligation and human-review gate for the selected profile passes.",
      "authority_effect": "Restoration remains revocable, reviewable, and bounded."
    }
  ],
  "allowed_transitions": [
    [
      "DISCONNECTED",
      "RECONNECTED_UNTRUSTED"
    ],
    [
      "RECONNECTED_UNTRUSTED",
      "HISTORY_COLLECTED"
    ],
    [
      "HISTORY_COLLECTED",
      "CONFLICTS_CLASSIFIED"
    ],
    [
      "CONFLICTS_CLASSIFIED",
      "AUTHORITY_REVALIDATED"
    ],
    [
      "AUTHORITY_REVALIDATED",
      "BASELINE_ATTESTED"
    ],
    [
      "BASELINE_ATTESTED",
      "LIMITED_RESTORATION"
    ],
    [
      "LIMITED_RESTORATION",
      "FULL_RESTORATION"
    ],
    [
      "FULL_RESTORATION",
      "LIMITED_RESTORATION"
    ],
    [
      "LIMITED_RESTORATION",
      "RECONNECTED_UNTRUSTED"
    ],
    [
      "FULL_RESTORATION",
      "RECONNECTED_UNTRUSTED"
    ]
  ],
  "prohibited_transitions": [
    [
      "DISCONNECTED",
      "FULL_RESTORATION"
    ],
    [
      "RECONNECTED_UNTRUSTED",
      "FULL_RESTORATION"
    ],
    [
      "HISTORY_COLLECTED",
      "FULL_RESTORATION"
    ],
    [
      "CONFLICTS_CLASSIFIED",
      "FULL_RESTORATION"
    ]
  ],
  "proof_obligations": [
    {
      "obligation_id": "PO01",
      "category": "identity",
      "name": "Artifact identity",
      "requirement": "Establish stable subject and artifact identity across histories.",
      "failure_condition": "identity mismatch or undocumented successor",
      "linked_property_ids": [
        "TC01"
      ],
      "gate_type": "CONJUNCTIVE_HARD_GATE",
      "status": "ACTIVE_PROOF_OBLIGATION"
    },
    {
      "obligation_id": "PO02",
      "category": "integrity",
      "name": "Artifact integrity",
      "requirement": "Verify exact raw bytes or selected-field digest within a declared boundary.",
      "failure_condition": "digest mismatch or ambiguous input boundary",
      "linked_property_ids": [
        "TC04",
        "TC05"
      ],
      "gate_type": "CONJUNCTIVE_HARD_GATE",
      "status": "ACTIVE_PROOF_OBLIGATION"
    },
    {
      "obligation_id": "PO03",
      "category": "authority",
      "name": "Authority issuer",
      "requirement": "Identify the issuer and authority provenance chain.",
      "failure_condition": "capability or identity substitutes for issuing authority",
      "linked_property_ids": [
        "PP01",
        "PP03"
      ],
      "gate_type": "CONJUNCTIVE_HARD_GATE",
      "status": "ACTIVE_PROOF_OBLIGATION"
    },
    {
      "obligation_id": "PO04",
      "category": "authority",
      "name": "Jurisdiction",
      "requirement": "Confirm territorial, institutional, subject, and matter jurisdiction.",
      "failure_condition": "jurisdiction absent, expired, or conflicting",
      "linked_property_ids": [
        "PP04"
      ],
      "gate_type": "CONJUNCTIVE_HARD_GATE",
      "status": "ACTIVE_PROOF_OBLIGATION"
    },
    {
      "obligation_id": "PO05",
      "category": "authority",
      "name": "Purpose",
      "requirement": "Confirm the authorized purpose and prohibit purpose laundering.",
      "failure_condition": "purpose absent or repurposed without authority",
      "linked_property_ids": [
        "PP05"
      ],
      "gate_type": "CONJUNCTIVE_HARD_GATE",
      "status": "ACTIVE_PROOF_OBLIGATION"
    },
    {
      "obligation_id": "PO06",
      "category": "authority",
      "name": "Scope",
      "requirement": "Confirm action, resource, duration, and recipient scope.",
      "failure_condition": "scope open-ended or inferred from capability",
      "linked_property_ids": [
        "PP03"
      ],
      "gate_type": "CONJUNCTIVE_HARD_GATE",
      "status": "ACTIVE_PROOF_OBLIGATION"
    },
    {
      "obligation_id": "PO07",
      "category": "authority",
      "name": "Freshness and expiry",
      "requirement": "Evaluate validity interval against a declared clock basis.",
      "failure_condition": "expired or clock-indeterminate authority",
      "linked_property_ids": [
        "PP06",
        "TC11"
      ],
      "gate_type": "CONJUNCTIVE_HARD_GATE",
      "status": "ACTIVE_PROOF_OBLIGATION"
    },
    {
      "obligation_id": "PO08",
      "category": "authority",
      "name": "Revocation",
      "requirement": "Query and preserve revocation evidence across every relevant history.",
      "failure_condition": "revocation missing, stale, or overridden by cache",
      "linked_property_ids": [
        "PP07"
      ],
      "gate_type": "CONJUNCTIVE_HARD_GATE",
      "status": "ACTIVE_PROOF_OBLIGATION"
    },
    {
      "obligation_id": "PO09",
      "category": "rights",
      "name": "Stay or suspension",
      "requirement": "Query stays, injunctions, holds, and suspensions before resumption.",
      "failure_condition": "material stay not resolved",
      "linked_property_ids": [
        "PP23"
      ],
      "gate_type": "CONJUNCTIVE_HARD_GATE",
      "status": "ACTIVE_PROOF_OBLIGATION"
    },
    {
      "obligation_id": "PO10",
      "category": "history",
      "name": "Partition-history completeness",
      "requirement": "Collect all required histories or mark each unavailable source.",
      "failure_condition": "missing history silently treated as agreement",
      "linked_property_ids": [
        "PP17",
        "PP32"
      ],
      "gate_type": "CONJUNCTIVE_HARD_GATE",
      "status": "ACTIVE_PROOF_OBLIGATION"
    },
    {
      "obligation_id": "PO11",
      "category": "history",
      "name": "Conflict classification",
      "requirement": "Type agreements, differences, contradictions, and unknowns per field.",
      "failure_condition": "last-writer or newest-clock merge",
      "linked_property_ids": [
        "PP15",
        "TC07"
      ],
      "gate_type": "CONJUNCTIVE_HARD_GATE",
      "status": "ACTIVE_PROOF_OBLIGATION"
    },
    {
      "obligation_id": "PO12",
      "category": "history",
      "name": "Reconciliation",
      "requirement": "Resolve or explicitly bound material conflicts before full restoration.",
      "failure_condition": "full restoration with unresolved material conflict",
      "linked_property_ids": [
        "PP10"
      ],
      "gate_type": "CONJUNCTIVE_HARD_GATE",
      "status": "ACTIVE_PROOF_OBLIGATION"
    },
    {
      "obligation_id": "PO13",
      "category": "baseline",
      "name": "Attested baseline",
      "requirement": "Identify and attest the required restoration baseline.",
      "failure_condition": "recovery from unknown or unauthenticated state",
      "linked_property_ids": [
        "PP11"
      ],
      "gate_type": "CONJUNCTIVE_HARD_GATE",
      "status": "ACTIVE_PROOF_OBLIGATION"
    },
    {
      "obligation_id": "PO14",
      "category": "baseline",
      "name": "Software and configuration",
      "requirement": "Verify software, configuration, dependency, and policy-control versions.",
      "failure_condition": "unreviewed configuration drift",
      "linked_property_ids": [
        "PP29"
      ],
      "gate_type": "CONJUNCTIVE_HARD_GATE",
      "status": "ACTIVE_PROOF_OBLIGATION"
    },
    {
      "obligation_id": "PO15",
      "category": "baseline",
      "name": "Data and evidence set",
      "requirement": "Verify data/evidence lineage and preserved contradiction state.",
      "failure_condition": "evidence set drift or contradiction deletion",
      "linked_property_ids": [
        "PP13",
        "PP15"
      ],
      "gate_type": "CONJUNCTIVE_HARD_GATE",
      "status": "ACTIVE_PROOF_OBLIGATION"
    },
    {
      "obligation_id": "PO16",
      "category": "baseline",
      "name": "Model or policy version",
      "requirement": "Verify model/policy identity, approval state, and change-control record.",
      "failure_condition": "unapproved or incomparable model/policy version",
      "linked_property_ids": [
        "TC03"
      ],
      "gate_type": "CONJUNCTIVE_HARD_GATE",
      "status": "ACTIVE_PROOF_OBLIGATION"
    },
    {
      "obligation_id": "PO17",
      "category": "time",
      "name": "Clock confidence",
      "requirement": "Record clock source, uncertainty, and conversion rules.",
      "failure_condition": "latest timestamp treated as authority without confidence",
      "linked_property_ids": [
        "TC11"
      ],
      "gate_type": "CONJUNCTIVE_HARD_GATE",
      "status": "ACTIVE_PROOF_OBLIGATION"
    },
    {
      "obligation_id": "PO18",
      "category": "review",
      "name": "Reviewer independence and appeal",
      "requirement": "Identify review authority, conflicts, separation, recusal state, challenge path, and appeal route.",
      "failure_condition": "self-review or no challenge/appeal route where independence is required",
      "linked_property_ids": [
        "PP22"
      ],
      "gate_type": "CONJUNCTIVE_HARD_GATE",
      "status": "ACTIVE_PROOF_OBLIGATION"
    },
    {
      "obligation_id": "PO19",
      "category": "restoration",
      "name": "Least-irreversible action",
      "requirement": "Select the minimum reversible function while evidence remains incomplete.",
      "failure_condition": "unnecessary irreversible action",
      "linked_property_ids": [
        "PP12"
      ],
      "gate_type": "CONJUNCTIVE_HARD_GATE",
      "status": "ACTIVE_PROOF_OBLIGATION"
    },
    {
      "obligation_id": "PO20",
      "category": "audit",
      "name": "Audit continuity",
      "requirement": "Preserve append-oriented histories, decisions, and invalidations.",
      "failure_condition": "history overwrite or deletion",
      "linked_property_ids": [
        "PP17"
      ],
      "gate_type": "CONJUNCTIVE_HARD_GATE",
      "status": "ACTIVE_PROOF_OBLIGATION"
    },
    {
      "obligation_id": "PO21",
      "category": "legibility",
      "name": "Human legibility",
      "requirement": "Provide plain-language authority, evidence, conflict, and action explanation.",
      "failure_condition": "machine code without usable human reason",
      "linked_property_ids": [
        "PP25"
      ],
      "gate_type": "CONJUNCTIVE_HARD_GATE",
      "status": "ACTIVE_PROOF_OBLIGATION"
    },
    {
      "obligation_id": "PO22",
      "category": "correction",
      "name": "Downstream correction",
      "requirement": "Identify and mark affected claims, decisions, caches, and receipts.",
      "failure_condition": "known stale dependency remains unmarked",
      "linked_property_ids": [
        "PP21",
        "TC12"
      ],
      "gate_type": "CONJUNCTIVE_HARD_GATE",
      "status": "ACTIVE_PROOF_OBLIGATION"
    },
    {
      "obligation_id": "PO23",
      "category": "recovery",
      "name": "Rollback and residual risk",
      "requirement": "Identify rollback target, residual unknowns, and invalidation triggers.",
      "failure_condition": "no safe rollback or hidden residual risk",
      "linked_property_ids": [
        "PP24"
      ],
      "gate_type": "CONJUNCTIVE_HARD_GATE",
      "status": "ACTIVE_PROOF_OBLIGATION"
    },
    {
      "obligation_id": "PO24",
      "category": "release",
      "name": "Release authority",
      "requirement": "Record the current bounded authority that approves limited or full restoration.",
      "failure_condition": "tool pass or operator convenience substitutes for release authority",
      "linked_property_ids": [
        "PP01",
        "PP30"
      ],
      "gate_type": "CONJUNCTIVE_HARD_GATE",
      "status": "ACTIVE_PROOF_OBLIGATION"
    }
  ],
  "profiles": [
    {
      "profile_id": "RP01",
      "name": "Routine reconnect",
      "mandatory_obligation_ids": [
        "PO01",
        "PO02",
        "PO03",
        "PO04",
        "PO05",
        "PO06",
        "PO07",
        "PO08",
        "PO09",
        "PO10",
        "PO12",
        "PO13",
        "PO17",
        "PO18",
        "PO20",
        "PO21",
        "PO23",
        "PO24"
      ],
      "maximum_state_if_any_mandatory_gate_fails": "LIMITED_RESTORATION",
      "target_state": "LIMITED_RESTORATION",
      "scoring_rule": "No composite score. Every mandatory obligation is conjunctive.",
      "status": "ANALYTICAL_PROFILE_DEFINITION",
      "actual_result": null
    },
    {
      "profile_id": "RP02",
      "name": "Authority expired during partition",
      "mandatory_obligation_ids": [
        "PO01",
        "PO02",
        "PO03",
        "PO04",
        "PO05",
        "PO06",
        "PO07",
        "PO08",
        "PO09",
        "PO10",
        "PO11",
        "PO12",
        "PO13",
        "PO17",
        "PO18",
        "PO19",
        "PO20",
        "PO21",
        "PO23",
        "PO24"
      ],
      "maximum_state_if_any_mandatory_gate_fails": "LIMITED_RESTORATION",
      "target_state": "LIMITED_RESTORATION",
      "scoring_rule": "No composite score. Every mandatory obligation is conjunctive.",
      "status": "ANALYTICAL_PROFILE_DEFINITION",
      "actual_result": null
    },
    {
      "profile_id": "RP03",
      "name": "Revocation conflict",
      "mandatory_obligation_ids": [
        "PO01",
        "PO02",
        "PO03",
        "PO04",
        "PO05",
        "PO06",
        "PO07",
        "PO08",
        "PO09",
        "PO10",
        "PO11",
        "PO12",
        "PO13",
        "PO17",
        "PO18",
        "PO19",
        "PO20",
        "PO21",
        "PO22",
        "PO23",
        "PO24"
      ],
      "maximum_state_if_any_mandatory_gate_fails": "LIMITED_RESTORATION",
      "target_state": "LIMITED_RESTORATION",
      "scoring_rule": "No composite score. Every mandatory obligation is conjunctive.",
      "status": "ANALYTICAL_PROFILE_DEFINITION",
      "actual_result": null
    },
    {
      "profile_id": "RP04",
      "name": "Stay or suspension conflict",
      "mandatory_obligation_ids": [
        "PO01",
        "PO02",
        "PO03",
        "PO04",
        "PO05",
        "PO06",
        "PO07",
        "PO08",
        "PO09",
        "PO10",
        "PO11",
        "PO12",
        "PO13",
        "PO17",
        "PO18",
        "PO19",
        "PO20",
        "PO21",
        "PO22",
        "PO23",
        "PO24"
      ],
      "maximum_state_if_any_mandatory_gate_fails": "LIMITED_RESTORATION",
      "target_state": "LIMITED_RESTORATION",
      "scoring_rule": "No composite score. Every mandatory obligation is conjunctive.",
      "status": "ANALYTICAL_PROFILE_DEFINITION",
      "actual_result": null
    },
    {
      "profile_id": "RP05",
      "name": "Conflicting authority histories",
      "mandatory_obligation_ids": [
        "PO01",
        "PO02",
        "PO03",
        "PO04",
        "PO05",
        "PO06",
        "PO07",
        "PO08",
        "PO09",
        "PO10",
        "PO11",
        "PO12",
        "PO13",
        "PO17",
        "PO18",
        "PO19",
        "PO20",
        "PO21",
        "PO22",
        "PO23",
        "PO24"
      ],
      "maximum_state_if_any_mandatory_gate_fails": "LIMITED_RESTORATION",
      "target_state": "LIMITED_RESTORATION",
      "scoring_rule": "No composite score. Every mandatory obligation is conjunctive.",
      "status": "ANALYTICAL_PROFILE_DEFINITION",
      "actual_result": null
    },
    {
      "profile_id": "RP06",
      "name": "Software or configuration drift",
      "mandatory_obligation_ids": [
        "PO01",
        "PO02",
        "PO03",
        "PO04",
        "PO05",
        "PO06",
        "PO07",
        "PO08",
        "PO09",
        "PO10",
        "PO11",
        "PO12",
        "PO13",
        "PO14",
        "PO17",
        "PO18",
        "PO19",
        "PO20",
        "PO21",
        "PO23",
        "PO24"
      ],
      "maximum_state_if_any_mandatory_gate_fails": "LIMITED_RESTORATION",
      "target_state": "LIMITED_RESTORATION",
      "scoring_rule": "No composite score. Every mandatory obligation is conjunctive.",
      "status": "ANALYTICAL_PROFILE_DEFINITION",
      "actual_result": null
    },
    {
      "profile_id": "RP07",
      "name": "Data or evidence drift",
      "mandatory_obligation_ids": [
        "PO01",
        "PO02",
        "PO03",
        "PO04",
        "PO05",
        "PO06",
        "PO07",
        "PO08",
        "PO09",
        "PO10",
        "PO11",
        "PO12",
        "PO13",
        "PO15",
        "PO17",
        "PO18",
        "PO19",
        "PO20",
        "PO21",
        "PO22",
        "PO23",
        "PO24"
      ],
      "maximum_state_if_any_mandatory_gate_fails": "LIMITED_RESTORATION",
      "target_state": "LIMITED_RESTORATION",
      "scoring_rule": "No composite score. Every mandatory obligation is conjunctive.",
      "status": "ANALYTICAL_PROFILE_DEFINITION",
      "actual_result": null
    },
    {
      "profile_id": "RP08",
      "name": "Model or policy drift",
      "mandatory_obligation_ids": [
        "PO01",
        "PO02",
        "PO03",
        "PO04",
        "PO05",
        "PO06",
        "PO07",
        "PO08",
        "PO09",
        "PO10",
        "PO11",
        "PO12",
        "PO13",
        "PO16",
        "PO17",
        "PO18",
        "PO19",
        "PO20",
        "PO21",
        "PO22",
        "PO23",
        "PO24"
      ],
      "maximum_state_if_any_mandatory_gate_fails": "LIMITED_RESTORATION",
      "target_state": "LIMITED_RESTORATION",
      "scoring_rule": "No composite score. Every mandatory obligation is conjunctive.",
      "status": "ANALYTICAL_PROFILE_DEFINITION",
      "actual_result": null
    },
    {
      "profile_id": "RP09",
      "name": "Clock divergence",
      "mandatory_obligation_ids": [
        "PO01",
        "PO02",
        "PO03",
        "PO04",
        "PO05",
        "PO06",
        "PO07",
        "PO08",
        "PO09",
        "PO10",
        "PO11",
        "PO12",
        "PO13",
        "PO17",
        "PO18",
        "PO19",
        "PO20",
        "PO21",
        "PO23",
        "PO24"
      ],
      "maximum_state_if_any_mandatory_gate_fails": "LIMITED_RESTORATION",
      "target_state": "LIMITED_RESTORATION",
      "scoring_rule": "No composite score. Every mandatory obligation is conjunctive.",
      "status": "ANALYTICAL_PROFILE_DEFINITION",
      "actual_result": null
    },
    {
      "profile_id": "RP10",
      "name": "Reviewer or archive unavailable",
      "mandatory_obligation_ids": [
        "PO01",
        "PO02",
        "PO03",
        "PO04",
        "PO05",
        "PO06",
        "PO07",
        "PO08",
        "PO09",
        "PO10",
        "PO11",
        "PO12",
        "PO13",
        "PO17",
        "PO18",
        "PO19",
        "PO20",
        "PO21",
        "PO23",
        "PO24"
      ],
      "maximum_state_if_any_mandatory_gate_fails": "LIMITED_RESTORATION",
      "target_state": "LIMITED_RESTORATION",
      "scoring_rule": "No composite score. Every mandatory obligation is conjunctive.",
      "status": "ANALYTICAL_PROFILE_DEFINITION",
      "actual_result": null
    },
    {
      "profile_id": "RP11",
      "name": "Downstream correction failure",
      "mandatory_obligation_ids": [
        "PO01",
        "PO02",
        "PO03",
        "PO04",
        "PO05",
        "PO06",
        "PO07",
        "PO08",
        "PO09",
        "PO10",
        "PO11",
        "PO12",
        "PO13",
        "PO17",
        "PO18",
        "PO19",
        "PO20",
        "PO21",
        "PO22",
        "PO23",
        "PO24"
      ],
      "maximum_state_if_any_mandatory_gate_fails": "LIMITED_RESTORATION",
      "target_state": "LIMITED_RESTORATION",
      "scoring_rule": "No composite score. Every mandatory obligation is conjunctive.",
      "status": "ANALYTICAL_PROFILE_DEFINITION",
      "actual_result": null
    },
    {
      "profile_id": "RP12",
      "name": "Full restoration",
      "mandatory_obligation_ids": [
        "PO01",
        "PO02",
        "PO03",
        "PO04",
        "PO05",
        "PO06",
        "PO07",
        "PO08",
        "PO09",
        "PO10",
        "PO11",
        "PO12",
        "PO13",
        "PO14",
        "PO15",
        "PO16",
        "PO17",
        "PO18",
        "PO19",
        "PO20",
        "PO21",
        "PO22",
        "PO23",
        "PO24"
      ],
      "maximum_state_if_any_mandatory_gate_fails": "RECONNECTED_UNTRUSTED",
      "target_state": "FULL_RESTORATION",
      "scoring_rule": "No composite score. Every mandatory obligation is conjunctive.",
      "status": "ANALYTICAL_PROFILE_DEFINITION",
      "actual_result": null
    }
  ]
}
