01 · Bound lineage
What correction is being tested?
This receipt does not replace the earlier records. It binds to them and asks whether their result survives change.
CTR-R44-003
4840c455ac84267328ff6fb0641ddd8a67c5a19ab5e90ce2cf21760e0b70a2f1
RMR-R45-003
c509879855287a3a368289133190b4437c6ce81486e09b26d699c57bfdb24024
NRV-R46-003
a1cd176013da78c84bdb19158f4a28610d8068c1aa4acba385cb6b1c59bb96b9
SRP-R47-003
dae5e91d480dc1955d341188419738e78c18dba4f993d4a014241a625bb65d2d
02 · Federation change
What changed, and how did the obligation travel?
participant reentry
scoped correction lineage plus recipient-specific pairwise reference
The correction may travel; a permanent map of the person may not.
The subject reference is recipient-specific, non-reusable, and not globally stable.
PAIR-R48-003-3cb9a10726
Participants
03 · Bounded observation
Where did the verifier look—and where did it not?
Observed surfaces
- decision store
- application cache
- event queue
- downstream export
- human workflow
- feature or model path
- benefits processor
Known blind spots
- Undeclared systems outside the named fictional federation
- Future integrations after the observation window
Absence of evidence outside this plan is not evidence of absence.
Synthetic recurrence canaries
Detect revival of revoked adverse state after federation change. No personal data.
Detect adverse use of refusal, contest, or correction. No personal data.
04 · Durability tests
Did the old judgment return or get re-derived?
Synthetic corrected and uncorrected controls were evaluated separately.
Limit: Synthetic test only.
A fictional benefits processor leaves and later rejoins the federation under new pairwise references and the existing negative-use obligation.
Limit: The result is bounded to the re-entry test and declared integrations.
Refusal, contest, correction, expiry, and human-review signals were exercised with synthetic events.
Limit: No claim is made beyond declared surfaces and dates.
Renewal used a new recipient-specific presentation identifier and did not expose the prior identifier.
Limit: External network metadata was outside scope.
05 · Anti-retaliation
Was refusal, contest, or correction used as a new adverse signal?
No within scope
Available
Fictional anti-retaliation officer
No prohibited use was observed within the bounded plan.
A person may decline to present portable proof without that refusal becoming guilt, risk, delay, or reduced eligibility.
06 · Unlinkable renewal
Can proof renew without becoming a permanent handle?
PRES-R47-003-OLD
PRES-R48-003-NEW-dfd6bf25
unlinkable within declared observation
07 · Remaining obligations
What is still owed?
No open exception within the bounded plan.
This is not a claim of permanent or universal safety. Monitoring must not become a requirement that the affected person repeatedly prove innocence.
Continue bounded monitoring without requiring repeated proof from the affected person.
Independent signatory: Fictional independent durability auditor
08 · Integrity and machine access
Inspect the exact bounded record.
Receipt hashes
Input: 0ac3f9e55901f797f5d66bc6539fe3465e716d18adcc5e3deeba739427ea888b
Output: 960cd300e550762603c461ce2506e4db6151dc8ed317a795b857233e34edf2a7
Whole receipt: 3e05a6d5e9ba872b9dd6f61922270a39fd94ef65fa2ce3b69e72da35fe16057d
Machine-readable endpoints
/recovery-durability/receipt?id=FDR-R48-003/recovery-durability/schema/recovery-durability/state-machine/recovery-durability/anti-retaliation/recovery-durability/federation-change-protocol/recovery-durability/observation-plan/recovery-durability/unlinkable-renewalComplete selected receipt
{
"schema": "antichrist.cx.federated-recovery-durability-receipt.v1",
"release": "R48",
"receipt_id": "FDR-R48-003",
"fictional": true,
"title": "Departed participant re-enters without reviving an employment label",
"summary": "A fictional benefits processor leaves and later rejoins the federation under new pairwise references and the existing negative-use obligation.",
"domain": "employment_benefits",
"terminal_status": "durable_attested",
"status_label": "Durable Attested",
"lineage": {
"contestability_receipt_id": "CTR-R44-003",
"contestability_receipt_sha256": "4840c455ac84267328ff6fb0641ddd8a67c5a19ab5e90ce2cf21760e0b70a2f1",
"remedy_receipt_id": "RMR-R45-003",
"remedy_receipt_sha256": "c509879855287a3a368289133190b4437c6ce81486e09b26d699c57bfdb24024",
"non_recurrence_receipt_id": "NRV-R46-003",
"non_recurrence_receipt_sha256": "a1cd176013da78c84bdb19158f4a28610d8068c1aa4acba385cb6b1c59bb96b9",
"standing_recovery_receipt_id": "SRP-R47-003",
"standing_recovery_receipt_sha256": "dae5e91d480dc1955d341188419738e78c18dba4f993d4a014241a625bb65d2d",
"lineage_scope": "fictional demonstration lineage; hashes bind the referenced local R44–R47 artifacts where present"
},
"subject_reference": {
"scheme": "pairwise_ephemeral",
"value": "PAIR-R48-003-3cb9a10726",
"globally_stable": false,
"reusable_across_recipients": false
},
"observation_plan": {
"plan_id": "DOP-R48-003",
"window_start": "2026-08-01T00:00:00Z",
"window_end": "2026-08-29T23:59:59Z",
"bounded": true,
"independent_observer": "Fictional Independent Recovery Observatory",
"surfaces": [
"decision_store",
"application_cache",
"event_queue",
"downstream_export",
"human_workflow",
"feature_or_model_path",
"benefits_processor"
],
"known_blind_spots": [
"Undeclared systems outside the named fictional federation",
"Future integrations after the observation window"
],
"stop_conditions": [
"Any renewed adverse action from revoked material",
"Any use of refusal or correction as an adverse feature"
]
},
"federation_snapshot": {
"snapshot_id": "FED-R48-003",
"global_person_identifier": false,
"cleared_person_registry": false,
"participants": [
{
"participant_id": "PART-R48-003-A",
"role": "originating institution",
"pairwise_namespace": "pw-03-origin",
"correction_enforced": true
},
{
"participant_id": "PART-R48-003-B",
"role": "current service operator",
"pairwise_namespace": "pw-03-operator",
"correction_enforced": true
},
{
"participant_id": "PART-R48-003-C",
"role": "independent observer",
"pairwise_namespace": "pw-03-observer",
"correction_enforced": true
}
]
},
"federation_change": {
"event_id": "FCE-R48-003",
"type": "participant_reentry",
"occurred_at": "2026-08-09T12:00:00Z",
"predecessor_scope": "fictional-prechange-scope-3",
"successor_scope": "fictional-postchange-scope-3",
"mapping_basis": "scoped correction lineage plus recipient-specific pairwise reference",
"stable_cross_context_identifier_used": false,
"negative_obligations_transferred": true,
"acknowledgment_complete": true
},
"anti_retaliation_assessment": {
"contract_id": "ARC-R48-001",
"tested_signals": [
"refusal_to_present",
"filing_a_contest",
"requesting_correction",
"successful_remedy",
"human_review_request",
"presentation_expiry",
"presentation_revocation",
"nonparticipation_in_portability"
],
"adverse_signal_use_detected": false,
"contained": true,
"equivalent_human_review_available": true,
"no_adverse_inference_rule_active": true,
"finding": "No prohibited use was observed within the bounded plan.",
"human_owner": "Fictional anti-retaliation officer",
"follow_up_deadline": null
},
"renewal_assessment": {
"performed": true,
"prior_presentation_id": "PRES-R47-003-OLD",
"renewed_presentation_id": "PRES-R48-003-NEW-dfd6bf25",
"recipient_bound": true,
"purpose_bound": true,
"stable_identifier_reused": false,
"stable_hash_reused": false,
"cross_recipient_linkability_detected": false,
"result": "unlinkable_within_declared_observation"
},
"durability_tests": [
{
"test_id": "DT-R48-003-01",
"vector": "active_decision_path",
"result": "passed",
"evidence": "Synthetic corrected and uncorrected controls were evaluated separately.",
"limitation": "Synthetic test only."
},
{
"test_id": "DT-R48-003-02",
"vector": "participant_reentry",
"result": "passed",
"evidence": "A fictional benefits processor leaves and later rejoins the federation under new pairwise references and the existing negative-use obligation.",
"limitation": "The result is bounded to the re-entry test and declared integrations."
},
{
"test_id": "DT-R48-003-03",
"vector": "retaliation_path",
"result": "passed",
"evidence": "Refusal, contest, correction, expiry, and human-review signals were exercised with synthetic events.",
"limitation": "No claim is made beyond declared surfaces and dates."
},
{
"test_id": "DT-R48-003-04",
"vector": "unlinkable_renewal",
"result": "passed",
"evidence": "Renewal used a new recipient-specific presentation identifier and did not expose the prior identifier.",
"limitation": "External network metadata was outside scope."
}
],
"canaries": [
{
"canary_id": "CAN-R48-003-A",
"synthetic": true,
"contains_personal_data": false,
"purpose": "Detect revival of revoked adverse state after federation change.",
"result": "not_triggered"
},
{
"canary_id": "CAN-R48-003-B",
"synthetic": true,
"contains_personal_data": false,
"purpose": "Detect adverse use of refusal, contest, or correction.",
"result": "not_triggered"
}
],
"exceptions": [],
"state_history": [
{
"state": "registered",
"at": "2026-08-01T10:00:00Z",
"actor": "Fictional recovery registry"
},
{
"state": "baseline_pinned",
"at": "2026-08-02T10:00:00Z",
"actor": "Fictional independent verifier"
},
{
"state": "federation_observed",
"at": "2026-08-05T10:00:00Z",
"actor": "Fictional independent verifier"
},
{
"state": "change_tested",
"at": "2026-08-10T10:00:00Z",
"actor": "Fictional independent verifier"
},
{
"state": "retaliation_tested",
"at": "2026-08-15T10:00:00Z",
"actor": "Fictional civil-rights reviewer"
},
{
"state": "renewal_tested",
"at": "2026-08-20T10:00:00Z",
"actor": "Fictional privacy engineer"
},
{
"state": "durable_attested",
"at": "2026-08-25T10:00:00Z",
"actor": "Fictional independent signatory"
}
],
"affected_person_proof": {
"proof_id": "APR-R48-003",
"delivered": true,
"reveals_original_stigma": false,
"contains_global_identifier": false,
"plain_language_status": "durable attested",
"limitations": "The result is bounded to the re-entry test and declared integrations."
},
"human_accountability": {
"decision_owner": "Fictional chief recovery officer",
"independent_signatory": "Fictional independent durability auditor",
"signoff_at": "2026-08-25T10:00:00Z",
"can_change_result": true,
"next_action": "Continue bounded monitoring without requiring repeated proof from the affected person."
},
"limitations": [
"The result is bounded to the re-entry test and declared integrations.",
"All people, institutions, events, identifiers, and dates in this receipt are fictional design-test material."
],
"input_sha256": "0ac3f9e55901f797f5d66bc6539fe3465e716d18adcc5e3deeba739427ea888b",
"output_sha256": "960cd300e550762603c461ce2506e4db6151dc8ed317a795b857233e34edf2a7",
"receipt_sha256": "3e05a6d5e9ba872b9dd6f61922270a39fd94ef65fa2ce3b69e72da35fe16057d"
}