Protocol

Probe facts first. Ask for interpretation second.

01

Freeze

The supplied baseline snapshot artefact is fetched, canonicalized and digest-checked. SPACLY also independently probes the live baseline before freezing.

02

Bind candidate

The candidate must publish a same-origin /.well-known/spacly.json. Its release ref, route paths and exact response-body SHA-256 values become the generation identity.

03

Probe

HTTP status/body digest comes from web.get; HTML and readable text rendering provide bounded structural and semantic evidence. Leader and validator compare the full consequential probe payload.

04

Compare

Validators classify only the registered semantic rules. Findings and provenance are consensus-bound; bounded leader explanation prose is display-only and excluded from authorization commitments.

05

Challenge

Relevant retrieved challenge evidence is stored for audit and triggers a fresh independent candidate assessment. Its prose is never semantic-verdict input and cannot itself set BLOCKED or READY.

06

Derive & authorize

Contract code aggregates current-generation attempts. BLOCKED outranks INCONCLUSIVE; every route must be READY before review. Authorization rechecks each stored probe and commits route URLs, body hashes, assessment digests and candidate identity.

Fail closed: missing evidence, content-hash drift, manifest drift, cross-origin canonical substitution, malformed model output, unresolved challenge or stale generation cannot become authorized.