Sovereign Continuity Campaign Review, Baseline Promotion, and Readiness Evidence
Release: 2.0.0-rc.22-WIP
Source campaign release: 2.0.0-rc.21-WIP
Public route: /workbench/continuity-campaign-review
API root: /api/v2/continuity-campaign-review
Terminal boundary: SYNTHETIC_NULL_SINK
Mission
RC22 adds a deterministic review layer above the RC21 Sovereign Continuity Drill Orchestrator. The review layer does not rerun a campaign and does not rewrite its history. It verifies an exact campaign package, preserves the accepted baseline identity, exposes every changed and unresolved condition, records the observable review mode, and exports an append-oriented review artifact.
The governing rule is direct:
VERIFY THE CAMPAIGN BEFORE THE BASELINE MOVES.
A review may propose acceptance, qualification, deferral, rejection, suspension, withdrawal, or supersession. It never activates a baseline, writes production authority, or promotes a release automatically.
Verification before review
Review controls become meaningful only after the engine verifies:
- exact source release and engine identity;
- exact campaign and execution profile;
- current accepted-baseline identifier and digest;
- ordered drill membership and drill digests;
- predecessor/successor campaign ledger;
- per-drill event-chain integrity;
- proof-state completeness;
- newly introduced, resolved, and unchanged evidence differences;
- containment results;
- minimum sovereign function;
- rekeying, authority, and reconciliation state;
- reconstitution eligibility;
- controlled public/private boundary; and
SYNTHETIC_NULL_SINKtermination.
Review-state taxonomy
The workbench records these states independently:
ACKNOWLEDGEDMERITS_REVIEW_COMPLETEACCEPT_AS_CURRENT_SYNTHETIC_BASELINEACCEPT_WITH_QUALIFICATIONSDEFER_PENDING_EVIDENCEREJECT_FOR_CURRENT_SCOPESUSPEND_CURRENT_BASELINEWITHDRAW_CURRENT_BASELINESUPERSEDE_WITH_CANDIDATE
An acknowledgment is not a merits review. A machine report is not an independent machine review. A baseline-acceptance proposal is not baseline activation.
Mandatory inspection dimensions
Every merits-capable review records fourteen bounded inspections:
- exact accepted scope;
- newly introduced differences;
- resolved differences;
- unchanged evidence;
- failed or qualified proof conditions;
- containment results;
- minimum sovereign function;
- authority and key epoch;
- reconciliation state;
- reconstitution eligibility;
- unresolved defeaters;
- residual unknowns;
- changed assumptions; and
- public/private boundary integrity.
Reviewer modes
The platform preserves seven observable review modes:
- human click;
- procedural confirmation;
- merits review;
- declared independent judgment;
- machine report;
- independent machine review; and
- abstain/defer.
Independent machine review requires a separately identified implementation, distinct lineage, primary-evidence access, contrary-hypothesis review, abstention, implementation diversity, independent authority, and no shared unrecorded mutable state. These fields establish bounded technical separation; they do not establish consciousness, legal personhood, legal approval, or institutional legitimacy.
Readiness evidence
RC22 keeps eleven dimensions separate:
- package integrity;
- baseline identity;
- campaign reproducibility;
- containment;
- minimum sovereign function;
- rekey and revocation distribution;
- reconciliation;
- reconstitution;
- public/private boundary;
- reviewer completion; and
- deployment evidence.
There is no composite readiness score. A passing package-integrity check cannot compensate for missing deployment evidence, unresolved authority, failed containment, or incomplete review.
Lineage and immutability
Every review artifact records:
- source package digest;
- parent accepted-baseline identity;
- candidate baseline identity and digest;
- predecessor review digest where one exists;
- review sequence;
- review event chain;
- qualifications, defeaters, unknowns, effective conditions, and expiry;
- rollback baseline;
- review artifact digest; and
- lineage digest.
Comparison identifies the first review-state divergence and the lifecycle of introduced, resolved, unchanged, or reopened issues. Counterfactual reviews are labeled COUNTERFACTUAL REVIEW — NOT EXECUTED and cannot mutate parent campaign, baseline, or review history.
Controlled public boundary
The public workbench accepts published synthetic identifiers and bounded review metadata only. It accepts no customer content, files, arbitrary URLs, credentials, keys, private topology, real coordinates, targeting data, payload or weapon commands, vehicle commands, force authorization, or external command channel.
All public processing is ephemeral. The browser represents deterministic Python state and cannot create proof, authority, baseline activation, release promotion, or canonical history.
What this implementation establishes
Within the packaged synthetic scope, RC22 establishes deterministic source-package verification, bounded review-state behavior, reviewer-mode distinctions, append-oriented lineage, reproducible evidence export, comparison, counterfactual isolation, strict input rejection, and no automatic activation or promotion.
What it does not establish
This implementation does not establish production deployment, physical-system readiness, security accreditation, legal approval, procurement acceptance, customer-system protection, airworthiness, weapons review, certification, representative browser/device or assistive-technology acceptance, or operational authority.