Skip to content

§03-v Minerva — Governed Services — Externally-observable properties

Mars® Spec§03-v Minerva — Governed Services › Externally-observable properties

← Governed-service discipline · Section index

3. Externally-observable properties

Property Observable condition
GS1 — Asset-relative generation Each generated artifact’s audit record cites the governing asset identities and versions at the time of its generation; an artifact with no governing-asset citation is not a governed-service artifact
GS2 — Heterogeneous class under one discipline The same service registration record governs generation of datasets and at least two model subclasses (analytical, probabilistic, deep-learning); separate per-subclass registrations without a unifying service registration do not satisfy this property
GS3 — Order-typed artifact Each generated artifact carries a per-artifact order-type declaration referencing the governing domain model’s orders; a service-level tag without per-artifact typing does not satisfy this property
GS4 — Recomputable provenance and conformance An independent inspector re-derives both the artifact’s governing-asset provenance and its conformance to the governing specification’s aspect structure from the retained witness, without access to the deployment
GS5 — Governed-service audit record Each generation invocation emits an audit record in the specification registry carrying the operation identity, governing asset versions, produced artifact content hashes, and invocation timestamp; a post-hoc registration of outputs without a contemporaneous audit record does not satisfy this property
GS6 — Operation-level governance The registration, versioning, and audit-emission are properties of the generation operation itself; removing or substituting the specification registry yields a generation pipeline with no governed-service audit trail, observably different from the governed service
GS7 — Governed decision service A query→decision API is a governed decision service subject to the four discipline requirements; its output artifact is the decision bundle (order-typed verdict + §03-iii §2.7 witness + freshness dispositions + governing asset versions), a registered artifact enrolled in the delta-attestation lifecycle; a decision API that registers no operation, emits no audit record, or produces no recomputable decision bundle is an ungoverned decision pipeline
GS8 — Declared freshness and degradation A decision service on operational data declares per-aspect evidence-freshness bounds and a degradation mode (fail-closed / fail-stale-declared / fail-to-authority); the decision bundle records which mode governed each decision; silent emission of a decision whose bundle does not disclose that grounding evidence exceeded the freshness bound is non-conforming
GS9 — Decision actuation continuity Where a governed decision authorizes a downstream non-linguistic or persistent-state effect, the decision bundle is the originating verification record at the §02c actuation anchor (Field 1) and its freshness disposition propagates to the actuation gate; a fail-stale-declared decision carries its non-fresh annotation to the gate, which may refuse the effect on that basis

← Governed-service discipline · Section index