GCL Controlled Epistemic Interface
Independent intelligence intake without institutional assimilation
| Status field | Current state |
|---|---|
| Result status | audited operational doctrine over a protected interface |
| Conditional on | Protected MATHSOLVE dispatch/intake records, the active controller contract, and the ordinary MATHSOLVE/MATHCERT governance routes remaining authoritative |
| Strongest supported claim | GCL can receive one bounded contribution from independent intelligence, preserve its exact returned evidence and provenance, and adjudicate it separately without granting the contributor institutional authority |
| Not claimed | Mathematical correctness, statistical or cryptographic independence, novelty, certification, claim promotion, merge authority, publication authority, or MATHCERT effect |
| Support-route class | regression audit of protected implementation and pilot evidence; mathematical claims carried through the interface retain their own support classes |
| Foundational profile | Not applicable to this governance interface; any mathematical contribution retains the foundation profile of its own campaign |
| Certification state | Documentary and operational state protected; no mathematical certification is created by this page |
| First executable step | Before the next CEI dispatch, compare the dispatch contract, RESULT/1 grammar, controller machine contract, workflow wake paths, and claim boundaries; complete when all five agree on protected state |
Control surface: GCL-CEI-001
Documentary lifecycle: active
Documentary role: governed human-readable operational description of the protected independent-intelligence intake path
Initial protected admission: MATH-PROGRAMME PR #1041, merge 598a13d8a390fcab722b84b4a494921fc50d0e56
Controller: MP-EXTERNAL-INTAKE-PR-CONTROLLER-001, machine status ACTIVE
1. Plain object
The object is a controlled boundary between outside reasoning and inside governed knowledge.
GCL gives an independent reasoner one complete, bounded problem description. The reasoner returns one bounded result. GitHub preserves exactly what was returned. Only after preservation does GCL decide what, if anything, the result earns.
In compact form:
GCL supplies the problem world.
Independent intelligence supplies one bounded thought.
GitHub preserves the thought.
GCL tests the thought.
Protected knowledge changes only through the existing governed route.
The governing sentence is:
GCL defines the whole problem world. Independent intelligence reasons inside that bounded world. Only the returned contribution crosses the boundary. GCL then preserves, falsifies, adjudicates, and, if warranted, routes the result through existing protected knowledge controls.
This is a contribution interface, not an authority interface.
2. Exact obstruction
Two tempting designs fail for exact reasons.
Failure A — open-ended assimilation
A contributor is told to read the repository, absorb prior discussion, inspect campaign history, and then help.
That may produce useful work, but it destroys the property this interface needs: the returned reasoning is no longer independent of GCL's accumulated local framing.
The failure is not philosophical. It is operational:
repository immersion
-> institutional context acquisition
-> local framing enters the reasoning path
-> zero-context contribution claim no longer holds
Failure B — direct admission
A contributor returns a plausible proof or counterexample and the institution treats the result as accepted because the contributor appears capable.
That collapses generation into adjudication:
returned result
-> assumed correctness
-> claim promotion
The controlled interface forbids that collapse. Its semantic sequence is:
receive
!=
believe
!=
admit
!=
certify
The exact obstruction is therefore a trust-boundary problem: GCL needs epistemic separation without losing provenance, and provenance without converting receipt into authority.
3. Working model
The smallest useful model is:
one dispatch
->
one bounded reasoning task
->
one RESULT/1
->
one immutable evidence object
->
separate adjudication
Contrast that with the failure mode:
open-ended conversation
->
many partially authoritative artifacts
->
ambiguous provenance
->
unclear claim effect
The protected NS-CI pilot instantiated the first model. The UC-001/WP08-D004 tranche is the first reuse of the same controlled interface outside that pilot, with no expansion of token scope or claim authority. A zero-context bootstrap defined the entire work-set, a contributor returned one GCL-CONTRIBUTION-RESULT/1, intake preserved the raw result and receipt, and GCL adjudicated the mathematics separately.
4. Restricted claim
The interface supports this restricted operational claim:
Given a complete bounded dispatch and a contract-valid RESULT/1 return, GCL can preserve the returned contribution with provenance, keep it non-authoritative on receipt, and route subsequent adjudication through existing protected controls.
The interface does not establish:
- that the contribution is mathematically correct;
- that the contributor is statistically, cryptographically, or philosophically independent;
- that common pretraining or shared background knowledge is absent;
- that a preserved result is admitted;
- that an admitted result is certified;
- that MATHSOLVE evidence has MATHCERT effect;
- that the contributor acquires merge, publication, campaign, or claim-promotion authority.
For a zero-context dispatch, independence is a work-context property:
A valid contribution must be understandable and executable as intellectual work from the dispatch itself.
5. Governance-spine location
The CEI sits between problem dispatch and institutional adjudication. It does not replace either side.
+------------------------------+
| GCL DISPATCH |
| defines the whole problem |
| world and return contract |
+--------------+---------------+
|
v
+------------------------------+
| INDEPENDENT INTELLIGENCE |
| reasons without repository |
| or institutional assimilation|
+--------------+---------------+
|
v
+------------------------------+
| RESULT/1 |
| one bounded contribution |
+--------------+---------------+
|
v
+------------------------------+
| GITHUB INTAKE |
| authenticate · validate |
| hash · preserve |
+--------------+---------------+
|
v
+------------------------------+
| MATHSOLVE EVIDENCE |
| immutable raw result |
| + machine receipt |
+--------------+---------------+
|
v
+------------------------------+
| GCL ADJUDICATION |
| compare · falsify · narrow |
| synthesize · admit/reject |
+--------------+---------------+
|
v
+------------------------------+
| MATHCERT / PROTECTED STATE |
| only through pre-existing |
| governed routes |
+------------------------------+
The implementation contains one additional control-plane hop:
validated intake branch
|
v
bounded Release Trust controller
|
v
ordinary MATHSOLVE evidence PR
That controller may validate and open the PR. It may not adjudicate, approve, merge, certify, promote, publish, or mutate campaign state.
6. Dispatch contract
A dispatch defines the complete bounded work-set.
It should contain, as applicable:
- the mathematical target;
- definitions and notation;
- exact assumptions;
- imported lemmas or facts the contributor may use;
- excluded assumptions;
- the permitted contribution class;
- falsification or rejection conditions;
- resource or time bounds;
- authority and claim boundaries;
- the exact return grammar;
- the exact place where the result must be returned.
The dispatch should make “read the repository first” unnecessary.
For the protected NS-CI pilot, the bootstrap explicitly states that the document is the entire work-set and binds the contributor to one bounded response object.
7. RESULT/1: the narrow crossing
The contributor returns exactly one object under the GCL-CONTRIBUTION-RESULT/1 grammar.
The narrow return surface prevents an informal cloud of attachments, private notes, side files, hidden calculations, or supplementary artifacts from becoming ambiguous evidence.
The one-result rule improves:
- provenance;
- hashing;
- replay;
- first-result locking;
- adversarial review;
- separation between contribution and institutional interpretation.
8. Support route: intake and preservation
The intake layer does not decide whether the mathematics is correct.
Its role is mechanical and evidentiary:
- authenticate the GitHub actor and source comment;
- bind the result to the exact registered dispatch;
- validate the RESULT/1 grammar and field order;
- reject unsupported links, attachments, or additional contribution objects;
- enforce the first-valid-result lock;
- preserve the raw returned bytes;
- compute and retain the raw result digest;
- emit a machine receipt;
- mark the object
received_unadjudicated; - retain
canonical_claim_effect=false.
The intake must not execute contributor-supplied material.
A syntactically valid result is therefore evidence received, not mathematics accepted.
Evidence shape
The durable MATHSOLVE intake result has two primary objects:
raw result snapshot
machine receipt
The receipt binds the contribution to the dispatch identity, source issue/comment identity, contributor actor, bootstrap or handoff identities, raw-result digest, schema state, and non-adjudicated claim state.
A later reviewer should be able to determine exactly what was returned, who returned it through GitHub, what dispatch it answered, and whether the preserved bytes changed.
The receipt is provenance. It is not a proof certificate.
9. Bounded Release Trust controller
The active machine contract is:
governance/ns_ci_intake_pr_controller.json
with control ID:
MP-NSCI-INTAKE-PR-CONTROLLER-001.
Its protected authority is intentionally small. The controller now uses an explicit finite profile registry: the original NS-CI-001 pilot profile and the UC-001/WP08-D004 incidence-interface profile. A campaign not named in that registry is rejected rather than inferred.
Its protected authority is intentionally small:
- read protected MATHSOLVE dispatch records for an explicitly registered CEI profile;
- read an already-created registered intake branch;
- compare raw result and receipt against protected requirements;
- open an ordinary pull request from that existing validated branch.
It may not:
- write repository contents;
- create or alter intake evidence branches;
- merge or approve pull requests;
- modify protected main;
- modify campaign state;
- perform mathematical adjudication;
- certify or promote claims;
- acquire Actions-write, workflow-write, checks-write, or administration authority.
The controller closes an automation gap without collapsing intake, adjudication, and acceptance into one actor.
Wake and persistence
Protected workflow behavior has three wake paths:
- scheduled reconciliation every ten minutes;
- manual replay;
- a success-gated
workflow_runwake after the Administrative maintenance dispatcher completes.
PR #1039 admitted the third path at merge commit:
536e377529dd6a313e79c2f91c1dc2567ad924a5.
The wake changes latency and persistence only. It does not change credential scope or claim authority.
10. Adjudication is a separate action
GCL adjudication occurs only after raw preservation.
The preserved result is not rewritten into the form GCL wishes the contributor had supplied. Adjudication may instead:
- verify a derivation;
- identify a useful lemma inside an overclaim;
- construct counterexamples;
- compare the result with internal evidence;
- narrow a statement;
- reject unsupported implications;
- preserve negative information;
- admit only the fragment that survives scrutiny.
This is the semantic bridge between outside contribution and inside claim state. The bridge is governed review, not contributor identity and not intake success.
11. Protected pilot evidence
The interface has been exercised on real mathematical content.
Cooperative mathematical contribution
The NS-CI contribution from issue #426 / comment 5768723180 was adjudicated in MATHSOLVE PR #436.
Protected merge:
b9e41f38a438fd3e039cf55fb59d7cd1ae0d1bc8.
The adjudication admitted only a reduced theorem and rejected stronger unsupported packet-realizability and necessity/sufficiency claims.
This is a concrete negative-control result: the interface preserved useful mathematics without preserving the contributor's strongest claim as institutional truth.
Release Trust qualification
The bounded Release Trust controller revalidated adversarial fixture dispatch NSCI-C2-B-ADV-999 and opened MATHSOLVE PR #445 as gcl-release-trust[bot].
That PR preserved exactly the raw result and machine receipt and merged at:
78c31d50671ad98305062c7104ed1e3c1812fc0c.
Its body records that it does not adjudicate mathematics, infer independence, certify a claim, or alter campaign state.
Together, the two pilot cases exercise:
outside mathematical contribution
+
trusted mechanical preservation
+
separate institutional adjudication
12. Debt and claim boundary
What is established
- the protected intake path exists;
- the controller is
ACTIVE; - one-result preservation and receipt generation have been exercised;
- the Release Trust controller can open an ordinary evidence PR from a valid intake branch;
- the cooperative pilot demonstrates that adjudication can narrow an external result instead of accepting it wholesale;
- the controller's wake metadata and protected workflow are aligned.
What remains outside this claim
- mathematical correctness of any future contribution;
- statistical or cryptographic independence;
- universal sufficiency of the RESULT/1 schema;
- MATHCERT certification;
- theorem promotion;
- publication or commercial authority.
Documentary debt
The continuing debt is synchronization, not missing mathematical proof: the human-readable page, controller contract, workflow, dispatch grammar, and protected evidence path must remain mutually consistent as the interface evolves.
Any material mismatch is a governance defect and should fail closed before a new dispatch relies on the changed surface.
13. Failure semantics
The interface fails closed by layer.
Dispatch failure
If the problem cannot be specified without hidden institutional context, it is not ready for zero-context dispatch.
Contributor return failure
Malformed, multi-object, out-of-contract, attachment-dependent, or otherwise invalid return material is not silently normalized into a valid RESULT/1.
Intake failure
If actor identity, dispatch binding, grammar, digest, receipt, or first-result-lock conditions fail, no trusted evidence PR should be created.
Preservation failure
An unprotected branch or issue comment is not canonical mathematical evidence merely because it exists.
Adjudication failure
If the mathematics cannot be justified, the contribution remains evidence of an attempted route, not an admitted theorem.
Certification boundary
MATHSOLVE evidence and GCL adjudication do not create MATHCERT certification by implication. Certification, when applicable, must traverse the existing MATHCERT route.
14. Operational recipe
For a new controlled independent contribution:
- identify one bounded contribution worth externalizing;
- write a complete zero-context dispatch/bootstrap;
- bind exact assumptions, exclusions, output grammar, and authority boundary;
- publish the dispatch through the governed route;
- provide the bootstrap to the independent reasoner;
- require one RESULT/1 through the declared GitHub comment surface;
- let intake authenticate, validate, hash, and preserve the result;
- let the bounded Release Trust controller open the ordinary evidence PR when the intake branch is valid;
- protect the raw evidence through ordinary repository controls;
- adjudicate the mathematics separately;
- admit, narrow, reject, or retain negative knowledge according to evidence;
- use MATHCERT only through its existing independent route where certification is required.
Do not merge these stages for convenience.
15. Trust quartet
What is proved? No new mathematical theorem is proved by this governance page.
What is checked? The protected interface topology, authority boundary, pilot evidence, controller contract, and wake behavior are represented by protected repository artifacts and regression/governance checks.
What remains open? The correctness and value of each future contribution remain open until separately adjudicated.
What requires external verification? Any mathematical statement that depends on external sources, independent replay, or MATHCERT review retains those obligations in its own campaign.
16. Source-of-truth surfaces
| Function | Protected surface |
|---|---|
| Controller machine contract | governance/ns_ci_intake_pr_controller.json |
| Controller implementation | ci/ns_ci_intake_pr_controller.py (historical filename; active controller is profile-registered and covers NS-CI plus UC-WP08-D004) |
| Persistent controller workflow | .github/workflows/ns-ci-intake-pr-controller.yml |
| GH-OS workflow registry | .ghos-routing/workflows.json |
| Execution/recovery doctrine | docs/governance/EXECUTION_RECOVERY_OPERATING_GUIDE.md |
| Routing-control doctrine | docs/governance/GHOS_ROUTING_CONTROL_RUNBOOK.md |
| Institutional authority doctrine | docs/governance/GCL_TRUTH_SPINE.md |
| Cooperative adjudication evidence | MATHSOLVE PR #436 |
| Release Trust qualification evidence | MATHSOLVE PR #445 |
| Deterministic wake admission | MATH-PROGRAMME PR #1039 |
| ACTIVE lifecycle reconciliation | MATH-PROGRAMME PR #1040 |
| Initial CEI documentary admission | MATH-PROGRAMME PR #1041 |
The raw contribution and receipt remain MATHSOLVE evidence. This document explains the interface and its invariants; it does not replace those evidence objects.
17. Historical housekeeping evidence
PR #1040 changed the controller lifecycle metadata from:
CANDIDATE -> ACTIVE
without changing token scope, permitted action, prohibited action, validation rule, first-result lock, or claim boundary.
The protected merge establishing that closure was:
01b334c14dec59b49cca3cc014acafd0870d7011.
That SHA is historical closure evidence, not a statement about the repository's current head. Current controller state is read from the protected machine contract.
Earlier documentary drift between the public page and machine wake contract was repaired through PR #1062 and protected at:
ab13f94e37d493212468664e620746dd7c023a23.
18. First executable step
Before issuing the next CEI dispatch, perform one bounded conformance audit.
Input: the candidate dispatch/bootstrap, RESULT/1 grammar, governance/ns_ci_intake_pr_controller.json, .github/workflows/ns-ci-intake-pr-controller.yml, and this page.
Action: compare dispatch identity rules, return grammar, first-result locking, wake behavior, controller permissions, prohibited actions, and claim boundaries across those surfaces.
Output: one pass/fail record naming every inspected protected artifact and exact SHA.
Completion test: PASS only if the human-readable description, machine contract, workflow, and dispatch all describe the same authority and evidence path with no unresolved drift.
The architectural lesson remains:
Outside intelligence is allowed to be intellectually foreign. Inside governance remains responsible for what becomes institutional knowledge.
That separation is the feature.