Probe facts first. Ask for interpretation second.
Freeze
The supplied baseline snapshot artefact is fetched, canonicalized and digest-checked. SPACLY also independently probes the live baseline before freezing.
Bind candidate
The candidate must publish a same-origin /.well-known/spacly.json. Its release ref, route paths and exact response-body SHA-256 values become the generation identity.
Probe
HTTP status/body digest comes from web.get; HTML and readable text rendering provide bounded structural and semantic evidence. Leader and validator compare the full consequential probe payload.
Compare
Validators classify only the registered semantic rules. Findings and provenance are consensus-bound; bounded leader explanation prose is display-only and excluded from authorization commitments.
Challenge
Relevant retrieved challenge evidence is stored for audit and triggers a fresh independent candidate assessment. Its prose is never semantic-verdict input and cannot itself set BLOCKED or READY.
Derive & authorize
Contract code aggregates current-generation attempts. BLOCKED outranks INCONCLUSIVE; every route must be READY before review. Authorization rechecks each stored probe and commits route URLs, body hashes, assessment digests and candidate identity.
Fail closed: missing evidence, content-hash drift, manifest drift, cross-origin canonical substitution, malformed model output, unresolved challenge or stale generation cannot become authorized.