§03-iv Minerva — Governed Production — Inspector verification (property table)
Mars® Spec › §03-iv Minerva — Governed Production › Inspector verification (property table)
5. Inspector verification (property table)
| Property | Observable condition |
|---|---|
| GP1 — Three-invariant generation witness | Generation trace, admissibility record, and coverage record are co-present in the recomputation witness for every governed data generation act; a witness omitting any invariant is structurally deficient |
| GP2 — Per-item content-hash tamper binding | Recomputing the content hash of each item in the corpus as received matches the per-item hash in the generation trace; a mismatch on any item is scoped to the affected item(s) and indicates alteration of the corpus or the witness |
| GP3 — Generation-time typing | Each generated item carries its domain aspect identifier, order type, generation specification version, and generation-act identifier assigned at generation time, not post-hoc; where a corpus spans multiple generation acts, each item carries its own generation specification version |
| GP4 — Generation specification amendment classified | An amendment to the generation specification is classified under the four-valued delta lifecycle; a scope-restricting amendment places affected certificates in conditionally-valid state and blocks downstream use pending a consistency determination |
| GP5 — Consistency determination witness | Carries the governing specification version at determination time, the prior and amended generation specification versions, the evaluated items by content hash, and per-item admissibility records including shim identity and version sub-records where a shim was applied |
| GP6 — Scope-breaking retirement | A scope-breaking generation specification amendment retires all prior-version items and invalidates affected certificates with no consistency-determination path; a new generation act is the only path to a new certificate |
| GP7 — Shim discipline | A generation specification shim is declared and registered before application, enrolled in the delta-attestation lifecycle, and its per-item application is recorded in the consistency determination witness; a shim-transformed item carries the amended version and a transformation record |
| GP8 — Cross-version certificate chain | Every re-issued governing-data-generation certificate carries the prior certificate identity, the triggering amendment, the consistency determination witness, and the outcome in Field 3; the full amendment and consistency chain is traversable by cross-version references |
| GP9 — Capsule completeness and self-containment | A produced generation environment capsule carries the artifact manifest, dynamic input record, generation model binding, environment timestamp, and generated corpus binding; its content hash covers all components; no component requires live network resolution; every input whose value depended on live infrastructure state at generation time is recorded |
| GP10 — Capsule status declared and re-use gated | Field 5 declares capsule status (produced or absent) on every governing-data-generation certificate; a capsule-absent certificate re-used in a capsule-required context is blocked until a capsule is produced, recorded as a Field 3 update |
| GP11 — Three-invariant benchmark witness | Derivation trace, coverage record, and falsifier record are co-present in the recomputation witness for every governed benchmark generation act |
| GP12 — Test-case structural completeness | Every test case carries case identity, content hash, aspect binding, order type, input, expected outcome, derivation record, and falsifier annotation; the benchmark aggregate hash is computed over lexicographically ordered case content hashes |
| GP13 — Specification-derived expected outcomes | Each test case’s expected outcome is re-derivable from the governing specification clause(s) named in its derivation record; a benchmark whose cases derive from empirical observation rather than specification clauses is not a governed benchmark |
| GP14 — Hash-scoped staleness | A scope-restricting or scope-breaking specification amendment flags stale only the test cases whose derivation records reference the amended clause(s); stale cases are excluded from evaluation until regenerated under the updated specification version |
| GP15 — Three-scenario mechanism invariance | New, modified, and external models are evaluated by the identical benchmark mechanism; only the certificate path differs across the three scenarios |
| GP16 — Declared modification record gate | A modified model without a declared modification record and registered modification artifact identity is treated as a new model and receives no delta classification; undeclared optimization cannot enter the delta path |
| GP17 — Model-evaluation witness | Evaluation trace, verdict derivation record, and benchmark version binding are co-present; per-case outcomes are drawn from the registered outcome vocabulary |
| GP18 — Modification delta cascade | A scope-restricting or scope-breaking modification delta triggers the delta-attestation cascade for downstream governed artifacts whose certificate path references the prior model version |
| GP19 — Consumer registration and output contract | Every benchmark consumer is registered with consumer identity, evaluation interface, input contract, output contract, and scope declaration; its verification result carries per-test-case outcomes, an aggregate verdict, and a recomputation witness sufficient for independent re-derivation |
| GP20 — Outcome vocabulary conformance | Per-case outcome classifications are drawn from the registered vocabulary {match, mismatch, partial-match, tolerance-boundary, indeterminate} or a registered extension; a consumer with a narrower vocabulary notes the narrowing in its scope declaration |
| GP21 — Multi-consumer non-merging | Where multiple consumers evaluate the same benchmark against the same model, their results are collected in a multi-consumer evaluation record without merging into a single verdict; each result is independently recomputable; the admissibility condition is a registered governing-specification parameter |
| GP22 — External documentation non-substitution | Vendor safety cards, published evaluation results, and model cards do not substitute for or supplement the benchmark-derived model-behavior certificate; an external model is evaluable only through the benchmark |
| GP23 — Train/evaluation disjointness | A model-behavior certificate is conforming only if the benchmark’s test cases and the model’s registered training corpus are disjoint under a declared similarity bound (content-hash intersection plus declared near-duplication threshold); contaminated cases narrow the certificate’s scope or, where pervasive, cause refusal; every certificate carries a benchmark-exposure record with the disjointness result; undeclared or external training history carries an honest exposure annotation and may not claim clean-disjointness |
| GP24 — Closed-loop separation | A generative-loop trajectory witness carries per-iteration train/benchmark disjointness results; a loop evaluating a candidate against a benchmark not disjoint from its own generated training partition under the declared similarity bound is producing overfitting-by-construction, not a governed evaluation, and is non-conforming |