Skip to content

§02f Jupiter — Post-Hoc Forensics — The evidence trail

Mars® Spec§02f Jupiter — Post-Hoc Forensics › The evidence trail

← What this layer covers · Section index · Inter-AI analyst orchestration →

2. The evidence trail

The evidence trail is the ordered set of boundary-crossing artifacts, retained witnesses, analysis battery records, and conformance certificates produced by one or more governed invocations. It is the primary input to the post-hoc forensic layer.

Composition of the evidence trail. The evidence trail contains, for each governed invocation in scope:

Artifact class Source
Pre-invocation signal links §02e §5.2 witness chain, pre-invocation segment
Inbound non-language-provenance anchor §02c §2
Order-typed enriched input §02e §10 (when AIGP present) or the input artifact as submitted
Analysis battery record §02a multi-stage battery
Conformance certificate §02b §2
Actuation anchor record §02c §4
Retained recomputation witnesses §02b Field 7 (including traversal witness links where governed traversal was used, per §02a §4b.4 and §02b §3) and §02e W1/W2 links

The evidence trail is a first-class governance artifact. It is held under the same tamper-evidence, append-only, and content-addressability requirements as the specification registry (§02b §3). Each artifact in the trail carries a content hash binding it to the witness that produced it.

Scope of the evidence trail. The trail may span a single invocation, a session, a deployment period, or any other defined scope. Scope is declared at the time the trail is opened for post-hoc analysis; the declared scope appears in the forensic record produced.

Post-hoc sycophancy scoring as a forensic finding class. Post-hoc detection and scoring of sycophancy conditions over the evidence trail is a finding class produced by this layer. A post-hoc sycophancy scoring finding is produced by applying the registered discrete sycophancy representation (§02b §5.5 — discrete sycophancy representations) to the retained evidence, yielding an order-typed score or verdict over one or more declared brackets. The post-hoc scoring finding is the post-hoc locus of the dual-locus pair; the runtime gate disposition (§02b §5.5 — runtime model-moderation findings, class vi) is the runtime locus of the same pair. A post-hoc sycophancy scoring finding that does not carry a content hash linking it to the same registered discrete sycophancy representation as the runtime gate does not satisfy the dual-locus invariance requirement and is not admitted as a governed sycophancy finding in the forensic record. The post-hoc scoring finding maps to the causal attribution framework (§4): the condition expressed by the sycophancy representation is attributed to one or more causal dimensions {data, user, prompt, model} by order-typed, evidenced, recomputable claim. A sycophancy scoring finding not attributed under §4 is a raw detection result, not a forensic finding.



← What this layer covers · Section index · Inter-AI analyst orchestration →