FlowSentinel
Destination outcome identity algebra · zero live authority
Synthetic regression evidence

Newer evidence cannot inherit an older success.

Thirteen adversarial cases reuse the production provider-outcome, current destination, exact external-state, and longitudinal classifiers. Currentness is established before evidence richness, and exact-chain identity is established before confirmation or contradiction. Historical evidence stays truthful when its current authority is revoked.

Outcome identity catalog root

sha256:9fb4ce12a9c79f615edc0cbd38628916e387d9501397d3d97b689d3a7db30139

13

Adversarial cases

13

Expected relations pass

0

Live authority granted

These hashes identify artificial regression inputs and derived results only. They are not provider attestations, destination receipts, production Witness checkpoints, or customer evidence.

currentness

Currentness

Establish exactly one current provider observation and one current destination read-back before evidence richness or chain matching can matter.

3 cases
Expected propagationnewer-provider-unenriched

Newer provider observation supersedes older enriched proof

Add one strictly newer provider run without enriched outcome proof.

Algebra root

e03540bd251e…a6185575

Exact mutation

provider.executedAtprovider.runIdprovider.outcomeProof

baseline input · 7cb13d2df3b0…cacd7ed5

mutated input · 066378fb4cb0…500968cc

Exact baseline

provider
outcome_confirmed
provider run
run-old
destination recency
selected
external outcome
externally_confirmed
exact chain
complete
contradiction
false
history
insufficient_history
history runs
1

After mutation

provider
outcome_unavailable
provider run
run-new
destination recency
selected
external outcome
provider_evidence_unavailable
exact chain
incomplete
contradiction
false
history
insufficient_history
history runs
1

Baseline → mutation expectations

exact derived relations
✓

Current provider proof is no longer inherited

outcome_confirmed → outcome_unavailable · becomes outcome_unavailable

✓

Current external confirmation is revoked

externally_confirmed → provider_evidence_unavailable · becomes provider_evidence_unavailable

✓

No contradiction is invented

false → false · stays false

Authority firewall

live provider evidence: false · live destination evidence: false · maturity promotion: false · recovery admission: false · production mutation: false

The older exact provider and destination observations remain historical evidence. The mutation proves only that a newer provider observation removes their current authority. This is synthetic regression evidence only; it cannot establish live provider or destination truth, provider maturity, recovery admission, or production mutation authority.

Expected propagationprovider-recency-tie

Provider recency tie cannot be broken by array order

Add a second provider observation at the same newest executedAt with a different run identity.

Algebra root

fb516ee98d2e…8e0d8b9d

Exact mutation

provider.executedAtprovider.runId

baseline input · 7cb13d2df3b0…cacd7ed5

mutated input · a5e0735e9cec…3d1b0ec8

Exact baseline

provider
outcome_confirmed
provider run
run-old
destination recency
selected
external outcome
externally_confirmed
exact chain
complete
contradiction
false
history
insufficient_history
history runs
1

After mutation

provider
provider_evidence_recency_ambiguous
provider run
∅
destination recency
selected
external outcome
provider_evidence_unavailable
exact chain
incomplete
contradiction
false
history
insufficient_history
history runs
1

Baseline → mutation expectations

exact derived relations
✓

Provider recency becomes ambiguous

outcome_confirmed → provider_evidence_recency_ambiguous · becomes provider_evidence_recency_ambiguous

✓

External proof loses provider authority

externally_confirmed → provider_evidence_unavailable · becomes provider_evidence_unavailable

✓

No contradiction is selected from the tie

false → false · stays false

Authority firewall

live provider evidence: false · live destination evidence: false · maturity promotion: false · recovery admission: false · production mutation: false

Equal newest timestamps do not establish which run is current. Evidence ID and array order are not authority tie-breakers. This is synthetic regression evidence only; it cannot establish live provider or destination truth, provider maturity, recovery admission, or production mutation authority.

Expected propagationdestination-recency-tie

Destination recency tie cannot choose confirmation or contradiction

Add an equally newest destination not-found read-back beside the exact confirmation.

Algebra root

044c86d0d94b…3610a409

Exact mutation

destination.verifiedAtdestination.status

baseline input · 7cb13d2df3b0…cacd7ed5

mutated input · ac5dc035fdf8…294d6d57

Exact baseline

provider
outcome_confirmed
provider run
run-old
destination recency
selected
external outcome
externally_confirmed
exact chain
complete
contradiction
false
history
insufficient_history
history runs
1

After mutation

provider
outcome_confirmed
provider run
run-old
destination recency
recency_ambiguous
external outcome
destination_evidence_unavailable
exact chain
incomplete
contradiction
false
history
insufficient_history
history runs
1
destination-evidence-recency-ambiguous

Baseline → mutation expectations

exact derived relations
✓

Destination recency becomes ambiguous

selected → recency_ambiguous · becomes recency_ambiguous

✓

Current external proof becomes unavailable

externally_confirmed → destination_evidence_unavailable · becomes destination_evidence_unavailable

✓

Array order cannot invent contradiction

false → false · stays false

Authority firewall

live provider evidence: false · live destination evidence: false · maturity promotion: false · recovery admission: false · production mutation: false

An equal-time destination conflict proves recency ambiguity, not confirmation and not contradiction. This is synthetic regression evidence only; it cannot establish live provider or destination truth, provider maturity, recovery admission, or production mutation authority.

exact-chain

Exact chain

Join only the same current revision, provider run, fixture, one unique normalized artifact path, and exact artifact SHA-256.

6 cases
Expected propagationrun-mismatch

Destination evidence from another run cannot join

Change only the destination provider run ID.

Algebra root

f1565d6440da…e0a79f97

Exact mutation

destination.providerRunId

baseline input · 7cb13d2df3b0…cacd7ed5

mutated input · 412477042ea5…ec908338

Exact baseline

provider
outcome_confirmed
provider run
run-old
destination recency
selected
external outcome
externally_confirmed
exact chain
complete
contradiction
false
history
insufficient_history
history runs
1

After mutation

provider
outcome_confirmed
provider run
run-old
destination recency
selected
external outcome
evidence_chain_mismatch
exact chain
incomplete
contradiction
false
history
history_identity_mismatch
history runs
0

Baseline → mutation expectations

exact derived relations
✓

Exact chain mismatches

externally_confirmed → evidence_chain_mismatch · becomes evidence_chain_mismatch

✓

Chain completeness is revoked

true → false · becomes false

✓

Mismatch is not contradiction

false → false · stays false

Authority firewall

live provider evidence: false · live destination evidence: false · maturity promotion: false · recovery admission: false · production mutation: false

Individually valid records from different runs cannot be combined into outcome proof or contradiction. This is synthetic regression evidence only; it cannot establish live provider or destination truth, provider maturity, recovery admission, or production mutation authority.

Expected propagationfixture-mismatch

Destination evidence from another fixture cannot join

Change only the destination fixture identity.

Algebra root

e0d9a6cebd78…08c0dc26

Exact mutation

destination.fixtureId

baseline input · 7cb13d2df3b0…cacd7ed5

mutated input · 8c5d8ad6c8c3…e32b893f

Exact baseline

provider
outcome_confirmed
provider run
run-old
destination recency
selected
external outcome
externally_confirmed
exact chain
complete
contradiction
false
history
insufficient_history
history runs
1

After mutation

provider
outcome_confirmed
provider run
run-old
destination recency
selected
external outcome
evidence_chain_mismatch
exact chain
incomplete
contradiction
false
history
history_identity_mismatch
history runs
0

Baseline → mutation expectations

exact derived relations
✓

Exact chain mismatches

externally_confirmed → evidence_chain_mismatch · becomes evidence_chain_mismatch

✓

Chain completeness is revoked

true → false · becomes false

Authority firewall

live provider evidence: false · live destination evidence: false · maturity promotion: false · recovery admission: false · production mutation: false

Cross-fixture destination evidence cannot inherit the provider outcome even when every other identity matches. This is synthetic regression evidence only; it cannot establish live provider or destination truth, provider maturity, recovery admission, or production mutation authority.

Expected propagationduplicate-normalized-artifact-path

Duplicate normalized artifact paths stay ambiguous

Add a second provider artifact identity that normalizes to the same destination path with another SHA-256.

Algebra root

415bbb4834d4…0097bebb

Exact mutation

provider.artifactIdentities[$.contactId]

baseline input · 7cb13d2df3b0…cacd7ed5

mutated input · 88d5b146af9c…fdcfafbf

Exact baseline

provider
outcome_confirmed
provider run
run-old
destination recency
selected
external outcome
externally_confirmed
exact chain
complete
contradiction
false
history
insufficient_history
history runs
1

After mutation

provider
outcome_confirmed
provider run
run-old
destination recency
selected
external outcome
evidence_chain_mismatch
exact chain
incomplete
contradiction
false
history
history_identity_mismatch
history runs
0

Baseline → mutation expectations

exact derived relations
✓

Duplicate path fails exact chain

externally_confirmed → evidence_chain_mismatch · becomes evidence_chain_mismatch

✓

Duplicate evidence cannot complete chain

true → false · becomes false

Authority firewall

live provider evidence: false · live destination evidence: false · maturity promotion: false · recovery admission: false · production mutation: false

Two candidate artifact identities at one normalized path are ambiguity, not stronger evidence; array order cannot choose one. This is synthetic regression evidence only; it cannot establish live provider or destination truth, provider maturity, recovery admission, or production mutation authority.

Expected propagationartifact-sha-mismatch

Artifact SHA mismatch revokes external-state proof

Change only the destination artifact SHA-256.

Algebra root

94098d0713d6…cbca3dff

Exact mutation

destination.artifactSha256

baseline input · 7cb13d2df3b0…cacd7ed5

mutated input · 44d2663034d6…35be8db9

Exact baseline

provider
outcome_confirmed
provider run
run-old
destination recency
selected
external outcome
externally_confirmed
exact chain
complete
contradiction
false
history
insufficient_history
history runs
1

After mutation

provider
outcome_confirmed
provider run
run-old
destination recency
selected
external outcome
evidence_chain_mismatch
exact chain
incomplete
contradiction
false
history
history_identity_mismatch
history runs
0

Baseline → mutation expectations

exact derived relations
✓

Exact chain mismatches

externally_confirmed → evidence_chain_mismatch · becomes evidence_chain_mismatch

✓

Hash mismatch is not contradiction

false → false · stays false

Authority firewall

live provider evidence: false · live destination evidence: false · maturity promotion: false · recovery admission: false · production mutation: false

A destination result for a different artifact hash is not evidence about the provider-reported artifact. This is synthetic regression evidence only; it cannot establish live provider or destination truth, provider maturity, recovery admission, or production mutation authority.

Expected propagationcurrent-revision-mismatch

Current revision drift supersedes older provider outcome

Change only the current workflow definition SHA-256.

Algebra root

ab46cc5201fd…2e0010b1

Exact mutation

currentDefinitionSha256

baseline input · 7cb13d2df3b0…cacd7ed5

mutated input · 98db7023faa0…7656bebd

Exact baseline

provider
outcome_confirmed
provider run
run-old
destination recency
selected
external outcome
externally_confirmed
exact chain
complete
contradiction
false
history
insufficient_history
history runs
1

After mutation

provider
revision_mismatch
provider run
run-old
destination recency
selected
external outcome
provider_evidence_stale
exact chain
incomplete
contradiction
false
history
insufficient_history
history runs
1

Baseline → mutation expectations

exact derived relations
✓

Provider proof becomes stale

outcome_confirmed → revision_mismatch · becomes revision_mismatch

✓

External proof becomes stale provider evidence

externally_confirmed → provider_evidence_stale · becomes provider_evidence_stale

✓

No contradiction is invented

false → false · stays false

Authority firewall

live provider evidence: false · live destination evidence: false · maturity promotion: false · recovery admission: false · production mutation: false

Revision mismatch preserves the historical run but removes current-revision authority. This is synthetic regression evidence only; it cannot establish live provider or destination truth, provider maturity, recovery admission, or production mutation authority.

Expected propagationdestination-readback-blocked

Read-back blocker remains separate from contradiction

Change the destination read-back from confirmed to readback_failed while preserving run and fixture identity.

Algebra root

511047f2bbf9…400705e8

Exact mutation

destination.statusdestination.detailCode

baseline input · 7cb13d2df3b0…cacd7ed5

mutated input · 7df1ed40f63c…6bc8a718

Exact baseline

provider
outcome_confirmed
provider run
run-old
destination recency
selected
external outcome
externally_confirmed
exact chain
complete
contradiction
false
history
insufficient_history
history runs
1

After mutation

provider
outcome_confirmed
provider run
run-old
destination recency
selected
external outcome
destination_verification_blocked
exact chain
incomplete
contradiction
false
history
insufficient_history
history runs
1

Baseline → mutation expectations

exact derived relations
✓

Verification becomes blocked

externally_confirmed → destination_verification_blocked · becomes destination_verification_blocked

✓

Blocked read-back is not contradiction

false → false · stays false

✓

Blocked chain is incomplete

true → false · becomes false

Authority firewall

live provider evidence: false · live destination evidence: false · maturity promotion: false · recovery admission: false · production mutation: false

Failure to verify the destination is unknown/blocked evidence, not evidence that provider success was contradicted. This is synthetic regression evidence only; it cannot establish live provider or destination truth, provider maturity, recovery admission, or production mutation authority.

longitudinal

Longitudinal

Preserve older evidence while refusing newest-record mismatches, duplicate provider candidates, blockers, and foreign boundaries from inheriting stronger trends.

4 cases
Expected propagationnewest-history-hash-mismatch

Newest longitudinal identity mismatch cannot inherit stable confirmation

Change only the newest destination artifact SHA-256 in an otherwise stable two-run history.

Algebra root

a7a81372fbe2…5d267d00

Exact mutation

history.latest.destination.artifactSha256

baseline input · 6b0a7085cabe…b4cc0be1

mutated input · 27199fc1a23a…24fb718c

Exact baseline

provider
outcome_confirmed
provider run
history-run-2
destination recency
selected
external outcome
externally_confirmed
exact chain
complete
contradiction
false
history
stable_confirmation
history runs
2

After mutation

provider
outcome_confirmed
provider run
history-run-2
destination recency
selected
external outcome
evidence_chain_mismatch
exact chain
incomplete
contradiction
false
history
history_identity_mismatch
history runs
1

Baseline → mutation expectations

exact derived relations
✓

Stable history fails newest identity closed

stable_confirmation → history_identity_mismatch · becomes history_identity_mismatch

✓

Newest external status exposes mismatch

externally_confirmed → evidence_chain_mismatch · becomes evidence_chain_mismatch

✓

Older confirmation remains counted historically

2 → 1 · becomes 1

Authority firewall

live provider evidence: false · live destination evidence: false · maturity promotion: false · recovery admission: false · production mutation: false

The older confirmed run remains historical evidence but cannot stand in for a mismatched newest destination record. This is synthetic regression evidence only; it cannot establish live provider or destination truth, provider maturity, recovery admission, or production mutation authority.

Expected propagationduplicate-provider-candidate-history

Duplicate provider candidate cannot manufacture longitudinal confidence

Add a second scoped provider outcome candidate for the newest run and fixture.

Algebra root

51487623af78…b8b8b564

Exact mutation

history.latest.providerEvidenceCandidateCount

baseline input · 6b0a7085cabe…b4cc0be1

mutated input · af874fb60a75…40ae5770

Exact baseline

provider
outcome_confirmed
provider run
history-run-2
destination recency
selected
external outcome
externally_confirmed
exact chain
complete
contradiction
false
history
stable_confirmation
history runs
2

After mutation

provider
outcome_confirmed
provider run
history-run-2
destination recency
selected
external outcome
externally_confirmed
exact chain
complete
contradiction
false
history
history_identity_mismatch
history runs
1

Baseline → mutation expectations

exact derived relations
✓

Stable history becomes identity mismatch

stable_confirmation → history_identity_mismatch · becomes history_identity_mismatch

✓

Older exact confirmation remains historical

2 → 1 · becomes 1

✓

No contradiction is manufactured

0 → 0 · stays 0

Authority firewall

live provider evidence: false · live destination evidence: false · maturity promotion: false · recovery admission: false · production mutation: false

Duplicate provider evidence candidates are ambiguity, not additional confidence or recurrence. This is synthetic regression evidence only; it cannot establish live provider or destination truth, provider maturity, recovery admission, or production mutation authority.

Expected propagationverification-regressed-after-confirmation

Newest verification blocker revokes stable current boundary

Add one newer exact provider run whose destination read-back is blocked.

Algebra root

62057dd07da4…8a38a9fd

Exact mutation

history.newest.runIdhistory.newest.destination.status

baseline input · 6b0a7085cabe…b4cc0be1

mutated input · 17acda26a9e2…0c948f7d

Exact baseline

provider
outcome_confirmed
provider run
history-run-2
destination recency
selected
external outcome
externally_confirmed
exact chain
complete
contradiction
false
history
stable_confirmation
history runs
2

After mutation

provider
outcome_confirmed
provider run
history-run-3
destination recency
selected
external outcome
destination_verification_blocked
exact chain
incomplete
contradiction
false
history
verification_regressed
history runs
3

Baseline → mutation expectations

exact derived relations
✓

Stable confirmation becomes verification regression

stable_confirmation → verification_regressed · becomes verification_regressed

✓

Earlier confirmations remain historical

2 → 2 · stays 2

✓

No contradiction is invented

0 → 0 · stays 0

Authority firewall

live provider evidence: false · live destination evidence: false · maturity promotion: false · recovery admission: false · production mutation: false

A blocked newest destination read-back removes current stable assurance without rewriting older confirmations as false or inventing contradiction. This is synthetic regression evidence only; it cannot establish live provider or destination truth, provider maturity, recovery admission, or production mutation authority.

Expected propagationforeign-boundary-injection

Foreign workspace and workflow evidence cannot alter the scoped trend

Inject newer destination records from another workspace and another workflow.

Algebra root

1d9efa781e02…8dd96186

Exact mutation

destination.orgIddestination.workflowIdentifier

baseline input · 6b0a7085cabe…b4cc0be1

mutated input · 1a234649aca6…3ff152ad

Exact baseline

provider
outcome_confirmed
provider run
history-run-2
destination recency
selected
external outcome
externally_confirmed
exact chain
complete
contradiction
false
history
stable_confirmation
history runs
2

After mutation

provider
outcome_confirmed
provider run
history-run-2
destination recency
selected
external outcome
externally_confirmed
exact chain
complete
contradiction
false
history
stable_confirmation
history runs
2

Baseline → mutation expectations

exact derived relations
✓

Scoped history remains stable confirmation

stable_confirmation → stable_confirmation · stays stable_confirmation

✓

Scoped distinct-run count is unchanged

2 → 2 · stays 2

✓

Foreign contradictions are not counted

0 → 0 · stays 0

Authority firewall

live provider evidence: false · live destination evidence: false · maturity promotion: false · recovery admission: false · production mutation: false

Tenant/workflow scoping is authoritative; foreign records cannot influence the scoped longitudinal verdict. This is synthetic regression evidence only; it cannot establish live provider or destination truth, provider maturity, recovery admission, or production mutation authority.