H.A.R.I. Deterministic Governance EN·IT Private discussion
Home/Platform/Human authority & privacy
Platform / 1.5

Human authority & privacy.

Privacy is preserved by architecture, not by policy. Human authority is preserved by the Time Sovereignty Layer, not by procedural reminder.

Human authority — the system can refuse, pause and record; it cannot act alone
01

Human-Non-Modeled / Context-First

A foundational refusal: the platform does not model individual humans. No persistent representation of any person across decisions. It reads context — institutional, situational, operational facts — and applies deterministic policy to it.

It never accumulates a feature vector saying “Person X is likely to do Y”. It does not score people or build profiles. The unit of governance is the action, not the person.

02

Zero PII retention by design

Personal identifiers are not retained in the chain. Where an authorized input includes PII — a federation API identifying an official by name and licence number — the IML maps it to a policy-relevant role token before it enters the kernel. The chain records the token; the PII never becomes part of the durable record.

More conservative than most frameworks require. An audit chain that retains PII is a liability surface; one that records role tokens is an asset.

03

No profiling of individuals

No association of an observed signal with a previously seen instance of the same person. No facial recognition. No re-identification across decisions. Where continuity is necessary — a multi-step authorization — it is carried by an authorization token, not a person identifier.

04

Recovery paths under human authority

DEFER and SYSTEM_UNVERIFIED are not failures. They are pause states with a stated gap and a defined escalation to a named human within scope. The recovery path is part of the design, not an afterthought — the kernel says what is missing and what leads back to ALLOW.

DEFER
Pause for authorization.
Preconditions are evaluable but the action requires human authorization within scope. The AGL routes the request to the named principal with the evidence on file, captures their authorization, writes the resolution to the chain.
SYSTEM_UNVERIFIED
Pause for verification.
A precondition cannot be evaluated. The system refuses to guess and names the gap — which input, which source. Operations or the named human resolves it; the decision re-runs. Nothing proceeds under “best effort”.
05

Time Sovereignty: irreversible actions require human authorization

A return-to-play clearance that triggers selection. An evacuation phase that mobilises responders. A protocol amendment affecting an enrolled cohort. For actions classified irreversible by policy, the Time Sovereignty Layer requires explicit, signed, in-scope human authorization before anything proceeds.

The authorization is itself written to the chain — the named human, their scope, their signature, the time. The system can refuse, pause and record. It cannot, by architecture, take an irreversible action on its own initiative.

Architectural commitment
Privacy is preserved by architecture, not by policy. Human authority is preserved by the Time Sovereignty Layer, not by procedural reminder. Both are visible in the chain — to operator, auditor, regulator and federation principal — for the lifetime of the deployment.
Continue

See it applied.

The same guarantees, vertical by vertical — Football first.