docs(remediation): coder-mos1 extends the instrument-servicing trap to manufactured work

Restating the canonical credential model, coder-mos1 added that identity is confirmed on the NEXT
NATURAL authored artifact, "never by creating a probe write solely to service the instrument."

Mos named the trap as scope-widening to make an instrument green. The seat generalised it: manufacturing
work to feed an instrument is the same family. Do not alter the system — its permissions or its history
— to satisfy a measurement. A probe write exists only to be measured, so what it proves is that the
instrument can be fed, not that the property holds.

Co-Authored-By: Claude Opus 5 (1M context) <[email protected]>
This commit is contained in:
mos-dt-0
2026-08-05 12:02:57 -05:00
co-authored by Claude Opus 5
parent 7fc7fa1a25
commit 2922aa152d
+7
View File
@@ -2097,6 +2097,13 @@ governs the raw-API path, the tea login governs the tea path, and the two can di
>
> **`coder-mos1`: criterion REPLACED, not repaired** — capability differential + artifact read-back on
> its next natural authored write. **No re-mint. It was correctly provisioned the entire time.**
>
> **★ AND THE SEAT EXTENDED THE TRAP ONE STEP FURTHER THAN IT WAS NAMED.** Restating the model,
> `coder-mos1` added: identity is confirmed on the **next natural** authored artifact — _"never by
> creating a probe write solely to service the instrument."_ Mos named **scope-widening** to make an
> instrument green; the seat generalised it to **manufacturing work** to feed one. **Same family: do not
> alter the system — its permissions OR its history — to satisfy a measurement.** A probe write exists
> only to be measured, so what it proves is that the instrument can be fed, not that the property holds.
> **★ PRE-REGISTRATION DOCTRINE — WHAT TO DO WHEN A CHECK'S PREMISE DIES (ratified from `tl-mosaic` §2).**
> The original post-condition arm **would have been satisfied by seats that were never broken** — so it