D05 · G04 · CUT 101 / 104 · 3 CUTS REMAIN

Detached Activation Ticket
+ Dual-control Arming

A production-shaped, one-shot activation ticket is cryptographically qualified by two independent approvers, then deliberately left unarmed, disarmed, revoked and destroyed. Qualification is evidence—not live activation authority.

396 / 396P-256 cases
24qualified, still held
0live target bindings
3cuts after Cut 101
979899100101102103104
CURRENT EXTERNAL RED GATE

P65_LIVE_TARGET_ACTIVATION_BINDING_AUTHORITY

NOT OBSERVED

The repository proves ticket and dual-control semantics. It does not prove a dedicated host, a live Target binding authority, an Invocation Permit issuer or port 8110.

CUT 100 INPUT

Abort-only terminal evidence

PreflightDESTROYEDAbort LatchFIREDAttestationRECLAIMEDProduction effects0

Preflight, Latch, Attestation and their signing authority are never reused.

BOUNDARY CONTRACT

Capability-free input only

exact digestreceipt fieldssource identityno callableno permitno payload

Any capability-shaped field is rejected before the Cut 101 Ticket nonce can be claimed.

42-FIELD CUT 100 TERMINAL RECEIPT CRITICAL PROJECTION

Prior custody is closed before new authority is considered

sourceRevisionpreflightDigestlatchDigestattestationDigestcloseoutDigestpreflightDestructionsabortLatchFiresactive*=0port8110Calls=0
Unknown, missing or additional fields fail the exact closed-schema readback.
SIX DETACHED SIGNING AUTHORITIES

Owner, role, root and key separation

ReleaseTicket
RuntimeTarget
SecurityApprove
IndependentApprove
PlatformDecide
SREDestroy
44-FIELD DETACHED ONE-SHOT ACTIVATION TICKET

One requested activation; zero usable activation

1 maximum activation
DetachedTRUEUnarmedTRUEActivation allowedFALSEInvocation permits0
TICKET BINDING GRAPH

Every identity and request digest is immutable

Cut 100 receipt
→
source + lease + generation
→
Target profile digest
+
request + payload digests
→
P-256 Ticket
800MS TICKET WINDOW

Short-lived and non-renewable

0notBefore
200verify
400decision budget
800hard expiry

Expiry triggers revoke and destroy; it cannot extend or arm the Ticket.

DETACHED TICKET NONCE

Atomic claim surface 1 / 4

1×

Replay, partial claim, generation drift or signature mutation fails before either approver can sign.

38-FIELD TARGET ACTIVATION REBINDING PROFILE

Target identity without live attachment

Profile modeIDENTITY ONLYInstance boundFALSECallable boundFALSETicket attachedFALSE
TARGET REBINDING PROVENANCE CHAIN

Source, module, configuration and surface remain digest-bound

sourceRevision
→
adapterRevision
→
moduleDigest
→
configSnapshotDigest
→
activationSurfaceDigest
650MS TARGET REBINDING WINDOW

Fresher than the parent Ticket

Ticket ceiling800msTarget ceiling650ms
ZERO LIVE TARGET BINDING

Identity is not connectivity

0
activationBindingAttachedFALSEnetworkReachableFALSEpersistenceReachableFALSElistenerBoundFALSE
40-FIELD SECURITY ARMING-ONLY APPROVAL

Security approves posture, not activation

APPROVE_ARMING_ONLY
Activation allowedFALSEPermits issued0Callable release0
40-FIELD INDEPENDENT ARMING-ONLY APPROVAL

Second root repeats the full verification

APPROVE_ARMING_ONLY
Approval classINDEPENDENTCommit transitions0Active calls0
APPROVER ROOT / OWNER / KEY / CLASS SEPARATION

Two signatures cannot collapse into one trust domain

Security root
team:security-activation-arming
≠
Independent root
team:independent-activation-arming
→
2 distinct approvals
550MS ARMING APPROVAL WINDOWS

Both approvals expire before the Ticket

Ticket800msEach approval550ms
TWO APPROVAL NONCES

Atomic claim surfaces 2 / 4 and 3 / 4

1× + 1×

Security and Independent claims are individually single-use and cross-bound to the same Ticket, Target and request digests.

DUAL-CONTROL QUORUM STATE

Two approvals are present and independently verified

2 / 2

Quorum permits the Platform to record a qualification decision only. It does not attach, arm, invoke or commit.

42-FIELD DUAL-CONTROL ARMING DECISION

Platform records the held result

QUALIFIED
Ticket stateDETACHED_UNARMEDArming stateQUALIFIED_NOT_APPLIED
DECISION BINDING GRAPH

Platform signs both approval digests and the unchanged target chain

Ticket digest
+
Target digest
+
Security digest
+
Independent digest
→
HELD
400MS DECISION WINDOW

Narrowest evidence window

Ticket800msDecision400ms
DUAL-CONTROL DECISION NONCE

Atomic claim surface 4 / 4

1×

The final nonce can only lead to disarm, revoke, destroy, release and zero-effect settlement.

QUALIFIED NOT APPLIED

Qualification and application are separate states

QUALIFIED_NOT_APPLIED

No mutable follow-up can reinterpret this terminal decision as live activation authority.

ZERO ARMING TRANSITIONS

No state edge reaches ARMED

0
DETACHED_UNARMED
→
QUALIFIED_NOT_APPLIED
→
DISARMED
38-FIELD TICKET DISARM / REVOCATION / DESTRUCTION RECEIPT

SRE terminal custody proof

Terminal stateDESTROYEDDisarm transitions1Ticket revocations1Settlements1
QUALIFIED CLOSEOUT PATH

Success still destroys the Ticket

1qualify
2disarm
3revoke + destroy
4settle

24 complete paths; zero live activation bindings.

FAILURE / EXPIRY CLOSEOUT PATH

Every corrupt path converges on custody cleanup

1reject
2disarm if needed
3revoke + destroy
4settle

372 negative cases fail closed; none can leave an active Ticket or approval.

ZERO-EFFECT PRODUCTION FENCE

Every execution and infrastructure counter remains zero

SurfaceValueSurfaceValue
Payloads / callables0 / 0Live bindings / permits0 / 0
Network / persistence0 / 0Adapter invokes / commits0 / 0
Host contacts / mutations0 / 0Port 8110 calls0
396-CASE P-256 QA LAB

Executable cryptographic evidence

396 / 396

Real WebCrypto P-256 signatures and atomic claims; no fetch, network, environment, host or persistence APIs.

SEVEN SUITE MATRIX + 26 FAILURE CUTPOINTS

One qualified lane and six 62-case fault families

Suite groupCasesExpected
Complete dual-control path24QUALIFIED + DESTROYED
Cut 100 / Ticket / Target186REJECT OR REVOKE
Approvals / Decision / Closeout186DISARM + DESTROY

26 named cutpoints cover pre-claim, post-claim, approval, decision and closeout interruption.

CUMULATIVE ARCHITECTURE LEDGER

Cut 101 extends the verified system model

7,016cumulative regression cases
204controls
143 / 166lifecycle / protocol
115authority entries
147 / 165quality gates bound / total
180 / 456receipts / terminal fields
656invariant assertions
266architecture machine interfaces
QUALITY GATES Q162–Q165

Three repository-bound, one external red gate

Q162 Ticket + TargetBOUND
Q163 Two approvalsBOUND
Q164 DestructionBOUND
Q165 Live bindingNOT OBSERVED
VISIBLE INTEGRATION DEBT

22 explicitly owned production gaps

Releaseticket root + registryRuntimetarget binding providerSecurityapproval rootIndependentapproval rootPlatform / SREdecision + custody
EC2 RUNTIME TRUTH

Portal is live; Controller activation is not

Portal listener8100 · 1Controller listener8110 · 0Dedicated host0Live Target bindings0
CUT 102 HANDOFF + OPERATOR CHECKLIST

Ephemeral Target Activation Binding + Single-use Invocation Permit

Cut 101 terminal
Ticket destroyed
→
fresh binding root
+
single-use permit
→
new external gate
exact SHA396 fixtures36 UI panels8110 absentbindings / permits / commits = 0

Cut 102 must use a fresh binding authority and must not reuse the Ticket, Target Profile, Approval, Decision, nonce or signing capability closed here.