The table
Actions resolving against grants and mandates, played as cards. Nothing on this table is synthetic: the scenario is this estate's own incident of 26 August 2026 — a push refused by a mandate, the mandate found to be wrong, the issuer amending it, the push landing — replayed from the artefacts it left behind. Every resolution below was re-run through the estate's own enforcement tool during the build; if the table claimed a refusal the tool does not reproduce, this page would not exist.
The players — the systems are players too
The deck — six suits, one card each, every field read from its source
A card is a rendering of a signed statement and nothing more — the one-envelope-two-genres model wearing table clothes. The resolution order is the ordering rule as game mechanics: a DOES resolves against CAN, then MAY, and its outcome mints an IS backed by a SHOWS. Blast radius is the CAN cards face-up on the table that no MAY card covers.
The play — forward: the simulation
The whodunnit — backward: the audit
The same cards, turned over in reverse: start from the consequence and ask because of what? Forward is the simulation; backward is the audit — they are the same cards in the same order, which is the register's was it valid last Tuesday? promise, as play.
- Turn 4 — the site deploys; tag v0.1.28 records it at 2026-08-26T15:14:16+00:00… because the resolution was PERMIT against current.json
- Turn 3 — a new MAY card enters play, citing the authorisation that actually existed and carrying an interval. The mandate was wro… because the issuer decided, citing the instruction the mandate itself quotes
- Turn 2 — the release carrying the hook's own documentation is blocked. CAN said yes; MAY said no; MAY won… because the resolution was REFUSED against mandate-v1.json
- Turn 1 — permitted — and the work crosses to the CI Runner, whose own CAN card reads: hosts reachable: github.com 200, pypi.org 2… because the resolution was PERMIT against mandate-v1.json
What this table does not claim. One scenario, four turns, one agent, one control — it demonstrates the mechanics, not coverage. A DOES card is not a receipt: nothing here is signed by the actor at the time of action; the table shows where receipts would sit, which is not the same as having them. And proposed-action simulation — playing a hypothetical card against the twin before reality sees it — is specified in brief v0.33.67 and deliberately not built here.
Generator admin/build/gen_table.py · gates: every resolution
re-run live through mandate.py check-branch; every reaction byte-checked against the
captured transcripts; every card field read from the source it links. Genre: tabletop grammar,
this estate's sentences.