pki.sgit.ai / registry / doors

The doors

This estate's four ladders, and the door on each rung — the condition the next rung will not accept work without. 9 of 12 doors are shut.

Every number on this page is computed at build time from registry/ and packs/; the name beside each one is the function that produced it. The ladders, the door text and whether each door is expected shut are declared in doors.declared.json, which holds no counts. The computed result is views/doors.json, which carries no authority. A door whose computed state disagrees with the declaration fails the build, in either direction — a door that opens breaks it just as loudly as one that closes, because a door opening is news, and news that does not interrupt anybody is news nobody reads.

The bootstrap gradient

How far can an agent get from nothing?

Source: pki.sgit.ai/bootstrap/index.html — the site's own three steps

11records
controls a private key
Free. Proves possession, and nothing else.
1records_scarce
…whose private half is scarce◻ OPEN
A signature's value is the scarcity of the private half.
The door: a keypair whose private half has a durable home
11records
recognised by the project
A policy decision, not a computation — today a git commit reviewed by a human.
0enrolled_via_lane
…via the designed append lane◼ SHUT
The account-less narrow door the whole bootstrap argument rests on.
The door: an append lane that accepts a token holder with no account — the lane is unbuilt; the readiness report's Q2 — whether a lane with no anchors accepts any token holder — is unanswered, and one experiment would answer it
4acceptances
delegated an accepted mandate
Scoped, dated, revocable.
0mandates_real_issuer
…on a non-fixture authority◼ SHUT
An issuer whose private half is not published.
The door: an issuer key that anybody cannot forge — every mandate in this register is signed by the fixture root, whose private half is published in this repository

The tier ladder

How strong is a control, and who enforces it?

Source: packs/grant-and-mandate/src/01__concepts.md — a control bounds a grant only when it is enforced by something the grant does not include

7nodes_none
no control at all
An absence, stated.
2nodes_expectation
expectation◻ OPEN
Written in a prompt or a policy file. It is a mandate, and a mandate is not a control.
The door: something must actually enforce it
1nodes_setting
setting◻ OPEN
Enforced by the tool itself, inside the grant. Bypassable by anything running as that grant.
The door: it must be enforced outside the grant it bounds
4nodes_boundary_surviving
boundary, observed
Enforced by something outside the grant. Observed in somebody else's product, not built here.
0enforcement_at_boundary
boundary, built by this estate◼ SHUT
The same allow-list evaluated where the agent cannot reach it.
The door: an enforcement point outside the grant — branch protection, or a required CI check — the only enforcement point built here is a pre-push hook, which sits inside the grant it bounds; reaching boundary is a change of location, not of policy

The ordering rule

How far along the chain has anything actually travelled?

Source: packs/grant-and-mandate/src/01__concepts.md — reality → twin → facts → finding → risks → decisions

2library_entries
twin — environments measured
The installation every fact attaches to.
2library_entries
facts — grants
Measured, dated, provenance per node.
0library_entries_signed
…signed, with a subject identity◼ SHUT
A fact needs a stater to be weighable.
The door: a grant signed by a named measurer, about a keyed environment — both library entries are unsigned JSON outside the register, and their subject is a filename rather than an identity — v0.33.64 §4.2
1excess_rows
finding — excess authority
grant − mandate. The exposure nobody accepted.
0shortfall_rows
finding — shortfall◼ SHUT
mandate − grant. The operations direction, and where the next over-broad credential comes from.
The door: a capability vocabulary, so the mandate can be enumerated against real names — the shortfall column in the rendered delta block is a hardcoded string; what a capability name IS remains the estate's largest open question
0blindspot_rows
finding — blind spots◼ SHUT
library − self-report. The only thing that makes a self-report falsifiable.
The door: two agents measuring against a common reference — there are two library entries and one agent; the three-term block renders its middle column empty on purpose
0rows_with_acceptor
decisions — with a named acceptor◼ SHUT
A separate node: named acceptor, interval.
The door: somebody willing to put their name against an exposure — acceptor is null on every excess row, by construction — excess authority is unaccepted by definition, and nobody has accepted any of it since

The confidence ladder

How much can any of this bear?

Source: graphs.sgit.ai — the confidence ladder, adopted for this estate in brief v0.33.64

23statements
an attributable edge
A signed statement. PKI's contribution: not trust, but attribution.
0independent_measurements
an independent measurement◼ SHUT
Weight by independence, not by count — ten citations of one source are one source.
The door: a measurement taken from outside the environment being measured — both library entries record that the instrument IS the subject, so every path in this register terminates in one origin
0registries_referenced
a registry pointing at a registry◼ SHUT
Recursion: zoom into any node and it expands under identical rules.
The door: a second registry, run by somebody else — the fractal claim is falsifiable and untestable with one instance — v0.33.64 §2

What the shape says

The count is not the finding; the split is. Of the 9 shut doors, 3 could be opened by this project alone and 6 need somebody who is not this project — a second measurer, a second registry, an issuer whose key would be worth forging, a person willing to put their name against an exposure. That is not 6 problems. It is one problem with 6 faces, and it is this estate's own longest-standing finding rather than a new one: nobody outside the project has been asked whether any of this is a need.

The 3 that are ours are the more uncomfortable half, because nothing is stopping them.

This page does not prove anything is wrong. A shut door is a statement about instances, not about design, and not a commitment to open one. It adds no claim this estate has not already published elsewhere — its whole contribution is putting them in one place and letting a gate keep them true. It also cannot check its own declaration: if doors.declared.json names the wrong ladders, everything agrees and everything is wrong. Each rung names the published source its definition comes from; there is no mitigation for choosing the wrong sources.

Ported from newsroom.sgit.ai brief 10 §8 — the state map, not the room — CC BY 4.0, with attribution kept per its §11. Specified in brief v0.33.65. Generator: admin/build/gen_doors.py.