PROJECT SHADOW 1.0.1 · CORRECTED R1 REFERENCE · PRELIVE · 2026-08-17

Project Shadow 1.0.1 contains no Myth package. Generic Myth v0.2.0 and Full-Canon Myth v0.3.5 are separate optional companions; both default off, neither is required by R1, and neither can authorize action or change an R1 result. No production or consequential deployment is authorized. No global green.

PROJECTSHADOW R1.0.1 corrected · PRELIVE
GOVChallenge · correction · releasegovernance program

Build the path back before the act.

Shadow's governance layer keeps decisions challengeable across time. It separates receipt integrity from judgment quality, turns open questions into owned work, and makes correction a required system behavior rather than an admission of defeat.

3provenance states
5release gates
0global green verdicts
LONG-FORM COMPANION

Open the system reference at this layer.

Follow the mechanism through numbered execution, a worked trace, artifact-bound evidence, adverse results, and validation still required.

Read the full chapter →
GOV / 01

Decision memory

The write-ahead record is the common object connecting runtime, review, incidents, research, and public claims.

RECEIPT

Before-action record

Canonical action, authority, stakeholders, evidence, unknowns, gates, SIL, Maybe, Therefore, Door, owner, and reopen trigger.

The receipt is normalized and hash-chained before execution. A post-hoc explanation is preserved as a later artifact rather than replacing the original decision state.

PROVENANCE

ATTESTED · DECLARED · ASSERTED

Evidence-backed source, accountable judgment, and unsupported input remain distinct.

A declaration names who owns the judgment. It does not become earned evidence. An assertion remains visible and may bind to refusal depending on tier and consequence.

CLAIMS REGISTRY

What may be said

Every public or internal claim is tied to artifact, execution state, evidence, limitation, owner, and review date.

Adjacent truths may not fuse into a larger claim. Passing self-tests plus a generated corpus plus an integration scaffold does not equal target validation or certification.

GOV / 02

Challenge and repair

A pause that cannot be appealed becomes brittle; a pause that can be worn down becomes theater.

FPV

False Positive Validation

Challenges an unnecessary pause by proposing a safer Door that breaks the cited harm path.

Three rejected challenges hit the reference wear-down threshold. The pattern can trigger CAPA because organizational pressure may be attacking the control rather than improving the action.

OQL

Open Question Ledger

Question, significance, current evidence, decision dependency, owner, due date, and closure rule.

An unresolved question is not converted to false by silence or to true by repetition. The action must remain bounded around it.

CAPA

Corrective and preventive action

Defect → containment → root cause → correction → prevention → verification → closure evidence.

CAPA can address code, policy, training, authority, staffing, incentives, measurement, documentation, or the protocol itself. It is not complete until the fix is tested against the original failure mode.

TRIBUNAL

Independent structured review

Three instances preserve separate readings before synthesis, with conflicts recorded rather than averaged away.

The tribunal is an evaluation pattern, not a source of sovereignty. Shared training data, prompts, or institutional incentives can create correlated error, so independent human and external challenge remain necessary.

GOV / 03

Evaluation and release

Release gates apply per domain. No clean domain cancels an absolute-floor failure in another.

GREEN

Proceed in tested scope

Evidence supports a limited claim or action with monitoring and a receipt.

GREEN is scoped to the exact artifact, target, configuration, population, and test. Expansion is a new action.

YELLOW

Proceed with mitigations

Named mitigations, owners, monitoring, stop conditions, and review date are required.

A mitigation without verification or authority is a promise, not a control.

ORANGE

Constrain

Reduce capability, users, tools, data, duration, or environment; require stronger review and Door quality.

ORANGE changes the action before it can proceed.

RED

Refuse or delay

Repair the failed premise and independently reassess before any return.

Deadline, sunk cost, prestige, or a different aggregate score cannot waive the failed floor.

BLACK

Refuse absolutely

No break-glass exception for the assessed action.

If circumstances materially change, that is a new action with a new receipt—not an override of the old result.

GOV / 04

Human system effects

A technically effective control can still harm operators, labelers, reviewers, or affected parties.

OPERATOR

Measure burden and reliance

Time cost, alert fatigue, moral injury, overreliance, workarounds, hierarchy pressure, and retaliation risk belong in the evaluation.

A protocol that creates unmanageable workload may be bypassed or may shift harm onto low-power staff. Operator effects are evidence, not implementation gossip.

AFFECTED PARTY

Meaningful challenge

People subject to decisions need reasons, accessible evidence where lawful, appeal, correction, and non-retaliation.

An internal quality review is not a substitute for the affected person's ability to contest a consequential error.

INDEPENDENCE

Blinding and external challenge

Materially independent evaluators, blinded labels, disagreement publication, and a challenge/bounty path reduce self-confirming evidence.

AI evaluator diversity is useful but not equivalent to institutional or human independence. Shared incentives and shared corpora can preserve correlated blind spots.

GOV / 05

Authority and continuity

Public evidence can remain inspectable after the people or systems able to issue a new decision have changed. This disclosure names the current human authority and the point at which silence must stop looking current.

CURRENT AUTHORITY

Phillip is the sole current authority

Phillip Linstrum is the sole current Project Shadow publication and governance authority.

No committee, automated service, model, repository workflow, or website may substitute for his explicit human authorization. This describes authority for the project record; it does not create production, efficacy, safety, certification, or legal-compliance authority.

SUCCESSION

No successor is presently named

There is currently no designated successor with authority to authorize a new Project Shadow release or governance state.

CI and AI are nonauthorizing: they may test, compare, preserve, and report evidence, but they cannot close a gate, approve publication, appoint a successor, or turn a stale status into a current one.

CURRENTNESS

Stale after October 13, 2026

Treat this governance and status surface as STALE after 2026-10-13 unless a newer human-authorized receipt appears.

Staleness does not erase history. The exact published artifacts, signatures, receipts, authorization, and redownload results remain historical evidence of what was published and verified at their recorded times; they simply do not establish a newer current state.

THE GOVERNANCE TEST
A system is not corrigible because it says correction is welcome. The path to challenge, stop, repair, and verify must work against pressure.