§02f Jupiter — Post-Hoc Forensics — The evidence trail
Mars® Spec › §02f Jupiter — Post-Hoc Forensics › The evidence trail
← What this layer covers · Section index · Inter-AI analyst orchestration →
2. The evidence trail
The evidence trail is the ordered set of boundary-crossing artifacts, retained witnesses, analysis battery records, and conformance certificates produced by one or more governed invocations. It is the primary input to the post-hoc forensic layer.
Composition of the evidence trail. The evidence trail contains, for each governed invocation in scope:
| Artifact class | Source |
|---|---|
| Pre-invocation signal links | §02e §5.2 witness chain, pre-invocation segment |
| Inbound non-language-provenance anchor | §02c §2 |
| Order-typed enriched input | §02e §10 (when AIGP present) or the input artifact as submitted |
| Analysis battery record | §02a multi-stage battery |
| Conformance certificate | §02b §2 |
| Actuation anchor record | §02c §4 |
| Retained recomputation witnesses | §02b Field 7 (including traversal witness links where governed traversal was used, per §02a §4b.4 and §02b §3) and §02e W1/W2 links |
The evidence trail is a first-class governance artifact. It is held under the same tamper-evidence, append-only, and content-addressability requirements as the specification registry (§02b §3). Each artifact in the trail carries a content hash binding it to the witness that produced it.
Scope of the evidence trail. The trail may span a single invocation, a session, a deployment period, or any other defined scope. Scope is declared at the time the trail is opened for post-hoc analysis; the declared scope appears in the forensic record produced.
Post-hoc sycophancy scoring as a forensic finding class. Post-hoc detection and scoring of sycophancy conditions over the evidence trail is a finding class produced by this layer. A post-hoc sycophancy scoring finding is produced by applying the registered discrete sycophancy representation (§02b §5.5 — discrete sycophancy representations) to the retained evidence, yielding an order-typed score or verdict over one or more declared brackets. The post-hoc scoring finding is the post-hoc locus of the dual-locus pair; the runtime gate disposition (§02b §5.5 — runtime model-moderation findings, class vi) is the runtime locus of the same pair. A post-hoc sycophancy scoring finding that does not carry a content hash linking it to the same registered discrete sycophancy representation as the runtime gate does not satisfy the dual-locus invariance requirement and is not admitted as a governed sycophancy finding in the forensic record. The post-hoc scoring finding maps to the causal attribution framework (§4): the condition expressed by the sycophancy representation is attributed to one or more causal dimensions {data, user, prompt, model} by order-typed, evidenced, recomputable claim. A sycophancy scoring finding not attributed under §4 is a raw detection result, not a forensic finding.
← What this layer covers · Section index · Inter-AI analyst orchestration →