pki.sgit.ai / documents / the-policy-as-a-statement

The Policy Is A Signed Statement, And The Relying Party Is The Boundary

TypeStrategy brief — memo 7 of 8 on the insurance pivot Versionv0.33.78 Date31 August 2026 AuthorDinis Cruz (project lead) and collaborators LicenceCC BY 4.0 Sourceraw markdown · view on GitHub

Summary

How the pivot works with primitives the estate already has — and it resolves a limit the pivot had recorded as hard. policy/v0 turns out to be a MANDATE-SHAPED statement issued by a rater rather than an operator: same five fields, same append-only record, same revocation-by-append, same verification walk, so the register needs no new machinery — one more statement type beside identity, mandate, acceptance, revocation and grant. A precision follows: a policy does not sign. A key signs, proving possession; the policy establishes what that signature is WORTH — which is exactly the 'afterwards' the corpus named on 19 August when it said a signature proves possession and proves nothing about trustworthiness. The consequential claim is structural: the handshake puts the check in the RELYING PARTY, who is by construction outside the requesting agent's grant — making it the first mechanism in this pivot that can reach tier boundary, and resolving memo 5's finding that a party outside the line can never be one. Also: trust as a path is a sentence the corpus published four days earlier, arrived at again from the insurance direction; the memo's ten-minute revocation is shown to be a CEILING bounded by relying-party check interval, with the handshake itself as the fix; and metering verification carries three hazards the observability brief anticipated, of which the quietest is that pricing a check discourages checking, raising the very latency the handshake exists to lower.

Key concepts

Key ideas

On this site

Adds insurance doctrine 07; proposes GM-D62 (policy/v0 as a mandate-shaped statement, answering GM-D36), GM-D63 (a policy does not sign), GM-D64 (the relying party is the boundary, resolving GM-D55's limit), GM-D65 (verification is not metered by the check) and GM-D66 (a revocation SLA states its check interval).

Read the document

📄 Original document · v0.33.78 · 31 August 2026 · rendered from the raw markdown (the source of truth)