DETERMINISTIC RELEASE POLICY / RECEIPT-DERIVED
NOT RUNNOT RUN
Run a real release manifest to build the evidence graph.
AI AGENT / RECEIPT PROVENANCE
Artifact supplier, not decision authority
Run a real release to populate provider, artifact, retrieval, tool, and trace provenance.
Receipt-backed states: NOT_CONFIGURED · USED · ERROR · SKIPPED_ABLATION. Live status never claims an invocation before the receipt returns.
No receipt-backed agent invocation records.
The agent can supply an artifact, but Themis has not calculated a release decision without a receipt.
REPLAYPLAN / RECEIPT EVIDENCE
Why these cases ran
ReplayPlan appears only in an API receipt; no selection, order, or confidence is claimed.
Run a release to inspect the receipt-backed replay selection.
QUARANTINE / HUMAN-GATED REPAIR
Repair handoff
A QUARANTINE receipt is required before a repair handoff can be proposed.
The source receipt is immutable. Creating a proposal stores operator-supplied repair metadata only; a human must approve it, then the API must replay it. This workspace never claims repair verification before the API returns VERIFIED.
DATAHUB / WRITE-BACK RECEIPT
Durable status boundary
DataHub write-back appears only in an API receipt; no status is claimed before a run.
- API status
- —
- Verified
- —
- Receipt URN
- —