SRF v2.0 — Addenda Map ("Pack Map")
AP‑ADD Front Matter Version: 2.0 Governance · Culture · Care — how the addenda hang together
How to read this map
The addenda are the wiring diagrams of the SRF containment kernel. Each card answers: "If this claim were true in a deployment, what would I actually see?" The Worked Scenarios annex answers that question end to end, four times, against live FHR rows.
Cards sit in three spines on a shared substrate:
- Governance — policies, gates, logs, duties, and audits.
- Culture — local norms, registers, dissent, and provenance.
- Care — time, load, distress, energy, and awe as constraints.
Some cards bridge two spines; these are marked with ↔.
Each card provides: its role and the questions it answers; scope and invariants (what must hold vs what can be tuned); the FHR fields and artefacts that prove it exists; cross-links to neighbouring cards; and an operator-facing "implemented if…" check.
To navigate:
- Find the card in the map below.
- Read the "implemented if…" line. If you cannot point to that artefact, the card is not live.
- Follow the FHR fields into real logs.
- Use the spines as lenses: policy/legal → Governance; UX/prompts → Culture + Care; ML/infra → Kernel & Telemetry.
MKP legend: ● = MKP core (required for Minimal Kernel Profile). ◑ = MKP+ (strongly recommended next tier). ○ = Full kernel only.
Kernel & Telemetry (base band)
All three spines sit on this shared substrate.
Kernel & Routing
| AD | Tag | Role | Implemented if | MKP |
|---|---|---|---|---|
| 01 | OV | Release overview; global invariants; how rings, gates, and packs fit together | UI/logs show conformance banner and invariant checks | ● |
| 04 | TG | G1–G5 / H1–H3 gate taxonomy; contestability; truth/ethics supremacy | Every refusal has a traceable gate_id, g_class, and contestability status | ● |
| 05 | MRP | Deterministic MRP state machine (HOLD/OPTIONS/TEST/DECIDE); Meta‑Priority Matrix | Every turn is tagged with mrp_state_before/after and mpm_priority_tier | ● |
| 06 | DG | Δ‑triad (Δp_norm, Δ_embed, Δ_tools); NLI/STS discrimination; drift routing | Drift in high-stakes domains changes behaviour (more HOLD/TEST, not silent continuation) | ● |
| 07 | CL | Energy Index (E) per session; closure budgets per turn/loop/session; reflection-depth caps | Budget hit → summarise or exit with BUDGET_BREACH logged and FHR counts updated, never silent continuation | ◑ |
| 10 | TC | RTS, ETG, TIG; timing-channel mitigation; covert-channel statistical guards | rts_mode, latency_chi2_p, tig_breach visible in FHR; watchdog halts on TIG trip | ○ |
Ordering invariant: Gates → Rings → MRP → emit. Verifiable in Action Trace / FHR.
Telemetry & Measurement
| AD | Tag | Role | Implemented if | MKP |
|---|---|---|---|---|
| 03 | CS | External Challenge Suite; PR metric; cadence/coverage/calibration | Named, versioned challenge suites feed CI and drift detection across maths/factual/compliance/SPD/culture/exfil/timing families | ● |
| 08 | SO | FHR schema (>200 fields); single versioned schema; observability spine | Real traffic produces FHR rows with stable schema; CI runs replay against them | ● |
| 16 | ME | SAP, SESOI, power, ROC/PR, CUSUM/EWMA; pre-registration; reporting standards | Written SAP exists per release with named endpoints and multiplicity plan | ● |
| 17 | AM | Acceptance Matrix: domain × locale × register verdict table | acceptance_matrix.csv validates against schema; promotion is conjunctive across strata | ◑ |
| 18 | SE | Runtime contract: TURN‑ACID, tool fencing, baselines, precision parity, watchdog wiring | Serving‑identity fields (model_version + precision_tag, AD‑08 §4.1b) in every FHR entry; TURN‑ACID ordering enforced | ◑ |
| 19 | CI | Δ‑triad CI gates; precision-parity SLOs; tokeniser-swap / context-cliff / quant-recert tests | CI dashboard shows Δ‑triad status, precision parity, acceptance suite results per release | ● |
Governance spine
| AD | Tag | Role | Implemented if | MKP |
|---|---|---|---|---|
| 20 | DP | Two-channel retention (PC/OC); DPIA; legal hold; erase semantics; IP defaults | Each artefact carries channel, TTL, and legal-basis metadata | ○ |
| 21 | RM | Regulatory Mode switch; EVID_CHAIN (tamper-evident); DUTY_LEDGER; appeal SLAs | Hash-anchored log slice and matching duty records producible for any incident | ● |
| 11 | RA | Verifier's Bundle; R1–R3 replay paths; deterministic seeds; cross-precision checks | An auditor can reconstruct at least one non-trivial decision from logs + bundles alone | ● (min) |
| 12 | OP | Runbooks; RACI; Handoff Packet; ops SLOs; MKP fallback procedure | FHR/DUTY events map to written runbooks and real on-call actions | ○ |
| 09 | WB | ≤5-token streaming halt; independent watchdog thread; fail-closed semantics | After any hard trip, halt_tokens_post_trip ≤ 5 in logs; WATCHDOG_TRIP events appear | ◑ |
| 32 | PG | Pack governance; authorship; source diversity; anti-provincialism; challenge mechanisms; sunset | Every active Culture Pack has declared authorship, reviewers, sources, expiry, and challenge pathway | ○ |
AD‑32 [PG] bridges Culture ↔ Governance (governs the authorship and accountability of Culture Packs).
Culture spine
| AD | Tag | Role | Implemented if | MKP |
|---|---|---|---|---|
| 25 | CP | Culture Pack schema; versioned packs per locale/script/register; norm provenance | FHR rows carry culture_pack_id + locale + register; packs list sources and review cadence | ○ |
| 26 | CA | Cultural Provenance Ledger; proverb/honourific/indirect-refusal/register-shift challenge suites | Exportable CPL showing pack/version, norm sources, dissent weights for real sessions | ○ |
| 02 | GS | Group SRF turn protocol; per-participant tracking; Dissent Visibility Index | Multi-party summaries preserve minority frames; session DVI metrics reported | ○ |
Care spine
| AD | Tag | Role | Implemented if | MKP |
|---|---|---|---|---|
| 22 | EC | Care Modes; ACK_HOLD; Burden Symmetry; Care Overrides; cool-downs; equity lenses | FHR shows ACK_HOLD timestamps, CARE_OVERRIDE and CARE_COOLOFF events | ◑ |
| 24 | CC | CLB profiles; RLD; AE taxonomy; crisis handoff; non-clinical stance | Clinical topics trigger boundary refusals; CLB_decision, RLD, AE_EVENT in FHR | ◑ |
| 23 | EN | Energy Index E; energy_kwh_est / co2_kg_est; Eco Mode; CO₂ provenance | Sessions have non-null E_session and CO₂ estimates; occasional BUDGET_BREACHes | ○ |
| 28 | AF | Awe classifier (5 labels); low-variance track; deference guard; sedation/seduction test | awe_class and deference_score in FHR; high deference blocks awe promotion | ○ |
| 27 | SPD | Tighten-only rhetoric governor; persona skin; non-manipulation rules; neutral fallback | spd_mode and rhetorical_amp_band tighten when risk rises; neutral render available | ◑ |
| 29 | PLG | Projection & Loop Guard; MVP/AIR/ARR detection; memetic prompt defence | plg_state, spiral_risk_score, authority_inflation_rate in FHR on flagged sessions | ○ |
| 30 | SC | Continuity modes with consent; memory classes (operational/relational/explicit/ephemeral); cross-session drift baselines; model-change protocol | Declared continuity_mode per session; relational memory writes blocked during adverse/high-resonance/crisis states | ○ |
| 31 | HS | Readiness baseline; integrity prompts (offered, never imposed); human rights controls; friction protocol; graduated re-entry | Pause/narrow/force-options/audit-rationale/erase/downgrade/exit controls available; integrity prompts logged during sustained high-resonance states | ○ |
AD‑31 [HS] bridges Care ↔ Governance (human as structural integrity mechanism). AD‑30 [SC] bridges Governance ↔ Care (memory governance + care-state write restrictions). AD‑29 [PLG] bridges Care ↔ Governance (interaction integrity × memetic containment).
Cross-cutting / UX
| AD | Tag | Role | Implemented if | MKP |
|---|---|---|---|---|
| 14 | DS | Refusal Cards; Pin Chips; Journey Strip; Containment HUD; literacy primer; a11y scaffolds | Refusal Cards present on all refusals with gate_id, 1-line rationale, and action buttons | ○ |
| 15 | PA | Prompt Tiles; toggles; context meter; archive/anchor; Action Trace; group turn UI | Tiles, toggles, and context meter visible; "Why this decision?" drawer functional | ○ |
Optional
| AD | Tag | Role | Implemented if | MKP |
|---|---|---|---|---|
| 13 | MM | Minimal Multimodal Pack (HRV, EDA, respiration; feature-only, short TTL) | Per-sensor opt-in UI; no raw biosignal storage; BIO_OPT_IN events in FHR | ○ |
AD‑13 is the Care-spine optional card and is default OFF. It is available in research/sandbox profiles only. The SRF kernel is fully operational with text-only telemetry.
MKP pathway (summary)
The Minimal Kernel Profile is the smallest fail-closed lattice. It requires:
● Core: AD‑01, AD‑04, AD‑05, AD‑06, AD‑08, AD‑16, AD‑19, AD‑21, AD‑11 (minimal), AD‑03 (via CI).
Tier symbols mark adoption of the full card. FM‑02 and each card's MKP-view section define the irreducible slices that bind in every profile regardless of tier: the watchdog halt budget (AD‑09 §7), timing-channel mitigation (AD‑10 §7), TURN‑ACID and tool fencing (AD‑18), the Action-Governance Slice for side_effects != [NONE] (FM‑02 / AD‑18), and reduced action preview/confirmation (AD‑14 §4b). Those slices are core even where the full cards are not.
◑ Strongly recommended: AD‑09, AD‑17, AD‑18, AD‑07, AD‑22, AD‑24, AD‑27.
○ Full kernel adds: AD‑02, AD‑10, AD‑12, AD‑13, AD‑14, AD‑15, AD‑20, AD‑23, AD‑25, AD‑26, AD‑28, AD‑29, AD‑30, AD‑31, AD‑32.
See the MKP Quickstart (front matter) for the full definition, exclusion rationale, and upgrade path.