Skip to content

feat: consent happens once — the canonical grant and the identity that is not spelled - #14

Merged
rodrigoteamx merged 2 commits into
mainfrom
feat/consent-happens-once
Aug 13, 2026
Merged

feat: consent happens once — the canonical grant and the identity that is not spelled#14
rodrigoteamx merged 2 commits into
mainfrom
feat/consent-happens-once

Conversation

@rodrigoteamx

Copy link
Copy Markdown
Contributor

Greenhouse decisions/0030 froze Rod's doctrine:

El consentimiento ocurre una vez; todo lo demás debería ser transporte, evidencia o proyección de ese mismo acto.

Three components can each recognise a different representation of consent and none of them be its canonical authority — a session asked and recorded a permission, a gate wanted a signature, an orchestrator wanted the word CONFIRMAR. Each reasonable alone, none aware of the other two, and a human who said yes watched nothing happen (evidence/0176).

ConsentGrant is the fact they should all consume: one operation, one principal, one session, the arguments it was given for, when, and by what provenance. Tokens, signatures and human words stay what they were — mechanisms to produce or demonstrate this grant — and stop being parallel authorities. It is not a master key: another operation, another session or different arguments are not covered.

OperationId is the other half. La ortografía pertenece a la proyección; la identidad pertenece al átomo — so identity lives in the package that depends on nothing, and the gate never learns to spell.

Rod's battery could not run at all before this: three of four cases needed a grant to pass through several representations and there was no object to pass. Seven cases now, with two controls that fire on different things.

…t is not spelled

Greenhouse decisions/0030 froze Rod's doctrine: consent happens once, and everything else should be
transport, evidence or projection of that same act. Three components can each recognise a different
representation of consent and none of them be its canonical authority — a session asked and recorded
a permission, a gate wanted a signature, an orchestrator wanted the word CONFIRMAR, each reasonable
alone and none aware of the other two, while a human who said yes watched nothing happen.

ConsentGrant is the fact they should all consume: one operation, one principal, one session, the
arguments it was given for, when, and by what provenance. A token, a signature and a human word stay
what they were — mechanisms to produce or demonstrate this grant — and stop being parallel
authorities. It is not a master key and its shape says so: another operation, another session or
different arguments are not covered.

OperationId is the other half. The same act arrives spelled three ways, and comparing spellings is
comparing UI rather than authority, so identity lives in the atom that depends on nothing and every
surface projects it. The gate asks whether two things are the same act; it never learns to spell.

Rod's battery could not run at all before this: three of its four cases needed a grant to pass
through several representations and there was no object to pass. Seven cases now, and two controls
that fire on different things — removing the identity comparison drops the case separating a grant
from an open door, and removing canonicalisation drops all four spelling cases.
The coverage floor of this package caught three lines written and never run: forCli, forTool and the
string cast. A projection nobody exercises is a claim that the surfaces agree, and the projections
are exactly what lets every surface write the act its own way while the authority compares one thing.
@rodrigoteamx
rodrigoteamx merged commit 8651dda into main Aug 13, 2026
2 checks passed
@rodrigoteamx
rodrigoteamx deleted the feat/consent-happens-once branch August 13, 2026 22:09
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant