R14 WITHDRAWN: the register already does everything the question assumed it could not
Withdrawn without a ruling, following the R2a precedent. R14 asked whether the
credential matrix needs a ruled-exception field, on the premise that three S5
power-key asymmetries were "ruled correct by SEC-016" and so reported a permanent
red a reader learns to ignore.

All three parts of that premise fail on measurement:

1. They are NOT ruled correct. SEC-016 ruled per-DC ISOLATION -- dc1 gets its own
   dedicated power key rather than reusing dc0's -- which is satisfied. It never
   blessed the filename, host and custody divergence. That is SEC-021(b), an OPEN
   ledger defect whose own disposition reads "needs a naming/custody reconciliation
   to the dc1 shape", and whose stated complaint was "Per-DC rows that should be
   symmetric are not, and nothing compares them". S5 is the thing that now compares
   them, so the finding is the register working as designed.

2. The register already ATTRIBUTES them: those rows carry sec-ref=SEC-021 and
   notes-ref=n-dc0-power-key-divergence.

3. The register already EXPLAINS them: creds-matrix-notes.md carries the
   n-dc0-power-key-divergence note describing the name and host-role divergence and
   why the expected jumphost rows fail EXPECTED-BUT-ABSENT.

And the notes file already warns against the exact move this question contemplated.
The line immediately preceding that note reads: "failure, not a matrix error: do
not delete the row to make the checker green."

So no schema change is needed and none should be made. Adding a suppression
mechanism would have HIDDEN an open security-ledger item -- the opposite of what
the register exists for. The red clears when SEC-021(b) is remediated, which is the
intended behaviour.

This is the third premise this audit has had to correct in its own framing, after
R2a (literals already assigned under D-111) and R9 (one failure mode, not two).
Worth noting the pattern: the audit's lens findings were sound as observations and
repeatedly wrong as conclusions, and measurement caught it every time.

Residual recorded so it is not mistaken for an oversight: whether a ruled-exception
field is EVER needed is now hypothetical. If one arises, notes-ref and sec-ref are
the place to start, not a new column.

Revert: git revert this commit; the R14 entry is rewritten in place with the
original retained beneath as R14-ORIGINAL for the audit trail.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01HvCyrwvYTTcDYnRErfMsNf
1 parent 4165c9e commit 9862cf9fcc10fa65673b877714173ada6633e88b
@JANeumatrix JANeumatrix authored 1 hour ago
Showing 2 changed files
View
docs/CURRENT-STATE.md
View
docs/audit/queued-rulings-20260727.md