Compartment Compromise Propagation, Sovereign Continuity, and Attested Reconstitution
Release: 2.0.0-rc.20-WIP
Public route: /workbench/compartment-continuity
API prefix: /api/v2/compartment-continuity
Execution boundary: synthetic, normalized, same-origin, ephemeral, non-operational
Terminal: SYNTHETIC_NULL_SINK
Mission
The workbench demonstrates how a machine-speed defense-assurance architecture can detect a compromised identity, authority artifact, signing key, software/model/configuration state, evidence source, communications path, reviewer lineage, or release channel; calculate the exact dependency blast radius; sever affected compartments; preserve minimum sovereign function; reconcile partition histories; rotate trust; and return only an attested current baseline to bounded service.
The governing sequence is:
DETECT → VERIFY → DENY → CONTAIN → RECOVER → PROVE
The public workbench does not ingest customer content and cannot issue operational commands. It models six abstract compartments and ten independent compromise dimensions.
Six synthetic compartments
- Sovereign command.
- Mission assurance.
- Supply chain and configuration.
- Evidence and provenance.
- Partner release.
- Public capability.
Each compartment preserves independent workload identity, authority, key epoch, revocation state, software/model/policy/configuration attestation, evidence custody, continuity priority, degraded local authority, isolation boundary, recovery baseline, and append-oriented history.
Independent state dimensions
The engine never collapses the following into one readiness score:
identity
authority
software and model
configuration
evidence
key and trust anchor
communications
power and compute
release channel
reviewer lineage
It also keeps these states distinct:
REACHABLE
ATTESTED
TRUSTED
AUTHORIZED
PURPOSE-PERMITTED
CURRENT
RECONCILED
READY FOR BOUNDED EXECUTION
Reachability cannot create authority. Trust cannot compensate for expired authority. A restored network path cannot reactivate stale commands. A valid hash does not prove factual truth.
Propagation model
Dependencies are explicit and dimension-scoped. For example, a sovereign-command key compromise can invalidate authority and trust-anchor dependencies in mission assurance and partner release without automatically erasing unaffected evidence history. A public-capability compromise can freeze publication while sovereign command and immutable evidence remain available.
The deterministic output records:
- directly affected compartments;
- blast-radius compartments;
- propagated dimensions;
- hard and qualifying dependency edges;
- severed and unaffected compartments;
- current authority and key epochs;
- minimum sovereign function;
- recovery prerequisites;
- hash-linked event history;
- proof conditions;
- reason codes;
- limitations and terminal state.
Minimum sovereign function
The workbench evaluates ten functions independently:
- constitutional identity continuity;
- authority-kernel continuity;
- immutable evidence continuity;
- revocation distribution;
- local time integrity;
- minimum communications;
- independent runtime assurance;
- archive and state reconstruction;
- recovery-baseline availability;
- reconciliation capability.
Minimum sovereign function is not full mission readiness. It is the bounded set of functions required to preserve constitutional identity, authority, evidence, revocation, time, assurance, archives, and the ability to recover.
Reconstitution contract
A compartment can return to service only after the engine establishes:
- trusted recovery root;
- accepted current baseline digest;
- current software, model, policy, and configuration versions;
- current key epoch;
- exclusion of revoked credentials;
- event-history reconciliation;
- source and evidence reconciliation;
- newly issued authority where required;
- independent runtime governor availability;
- configured reviewer or machine-review quorum;
- explicit unresolved defeaters;
- preservation of the compromised predecessor state.
Reconstitution appends a new state. It never deletes or rewrites the compromised state.
Scenario catalog
The release contains more than thirty deterministic scenarios covering forged and cloned identities, token theft and replay, partitioned authority expiry and revocation, compromised signing keys, quorum loss, mixed key/software/model/policy versions, configuration drift, provenance loss, unsigned updates, model tampering, evidence poisoning and correlation, timestamp manipulation, full and partial partitions, ledger divergence, release and public-compartment compromise, sovereign-command unavailability, runtime-governor loss, minimum-function continuity, defensive isolation, rekeying, reconciliation, reconstitution, superseded rollback denial, and recovery from an accepted immutable baseline.
Coordinated representations
One authoritative event index synchronizes:
- compartment topology;
- compromise-propagation graph;
- dependency matrix;
- authority and key-epoch table;
- continuity-state table;
- narrative;
- event ledger;
- proof inspector;
- containment record;
- reconstitution plan;
- change impact;
- raw synthetic evidence.
The browser may render, navigate, compare, branch, verify, and download deterministic state. It does not calculate authority, proof, propagation, continuity, reconstitution, or canonical history.
API contract
GET /api/v2/compartment-continuity
GET /api/v2/compartment-continuity/catalog
GET /api/v2/compartment-continuity/baseline
POST /api/v2/compartment-continuity/run
POST /api/v2/compartment-continuity/compare
POST /api/v2/compartment-continuity/branch
POST /api/v2/compartment-continuity/export
POST /api/v2/compartment-continuity/verify
GET /api/v2/compartment-continuity/proof
The only accepted public input is a published scenario_id. Unknown, private, file, URL, credential, coordinate, target, payload, weapon, vehicle-control, force-authorization, classified, and controlled-technical-data fields are rejected.
Public-safety and confidentiality boundary
The workbench contains no real customer data, protected strategy, real topology, GPS coordinates, target search or ranking, weapon-target pairing, payload or weapon functions, terminal guidance, force authorization, operational rules of engagement, malware, exploit code, external command channels, or public persistence.
Package validity establishes deterministic structure and byte integrity inside the declared synthetic scope. It does not establish operational accreditation, customer-system protection, legal approval, security certification, or deployment readiness.