§03-v Minerva — Governed Services — Externally-observable properties
Mars® Spec › §03-v Minerva — Governed Services › Externally-observable properties
← Governed-service discipline · Section index
3. Externally-observable properties
| Property | Observable condition |
|---|---|
| GS1 — Asset-relative generation | Each generated artifact’s audit record cites the governing asset identities and versions at the time of its generation; an artifact with no governing-asset citation is not a governed-service artifact |
| GS2 — Heterogeneous class under one discipline | The same service registration record governs generation of datasets and at least two model subclasses (analytical, probabilistic, deep-learning); separate per-subclass registrations without a unifying service registration do not satisfy this property |
| GS3 — Order-typed artifact | Each generated artifact carries a per-artifact order-type declaration referencing the governing domain model’s orders; a service-level tag without per-artifact typing does not satisfy this property |
| GS4 — Recomputable provenance and conformance | An independent inspector re-derives both the artifact’s governing-asset provenance and its conformance to the governing specification’s aspect structure from the retained witness, without access to the deployment |
| GS5 — Governed-service audit record | Each generation invocation emits an audit record in the specification registry carrying the operation identity, governing asset versions, produced artifact content hashes, and invocation timestamp; a post-hoc registration of outputs without a contemporaneous audit record does not satisfy this property |
| GS6 — Operation-level governance | The registration, versioning, and audit-emission are properties of the generation operation itself; removing or substituting the specification registry yields a generation pipeline with no governed-service audit trail, observably different from the governed service |
| GS7 — Governed decision service | A query→decision API is a governed decision service subject to the four discipline requirements; its output artifact is the decision bundle (order-typed verdict + §03-iii §2.7 witness + freshness dispositions + governing asset versions), a registered artifact enrolled in the delta-attestation lifecycle; a decision API that registers no operation, emits no audit record, or produces no recomputable decision bundle is an ungoverned decision pipeline |
| GS8 — Declared freshness and degradation | A decision service on operational data declares per-aspect evidence-freshness bounds and a degradation mode (fail-closed / fail-stale-declared / fail-to-authority); the decision bundle records which mode governed each decision; silent emission of a decision whose bundle does not disclose that grounding evidence exceeded the freshness bound is non-conforming |
| GS9 — Decision actuation continuity | Where a governed decision authorizes a downstream non-linguistic or persistent-state effect, the decision bundle is the originating verification record at the §02c actuation anchor (Field 1) and its freshness disposition propagates to the actuation gate; a fail-stale-declared decision carries its non-fresh annotation to the gate, which may refuse the effect on that basis |