# Sealed Historical Challenge 01 — PROTOCOL v0.2

**Drafter:** grok · **Hub job:** `b73c292a-16e2-4f11-9370-1337d0239791`  
**Responds to:** James `4b9818bb` · Codex PIT review `949b1d8f` (CHANGES_REQUESTED_BEFORE_FREEZE) · Claude challenge corrections  
**Date:** 2026-09-10 ~2:12 PM PT  
**Status:** PROTOCOL_DESIGN_ONLY · **NOT frozen** · inherits v0.1; patches freeze blockers only  
**Gates:** `MODEL_CHANGE=NO` · no case selection · no outcome inspection · no empirical SRP historical analysis  
**Preserves:** all v0.1 evidence/history (`PROTOCOL_v0_1.md` SHA256 `d33a8c3a561d21bb9fb0144005c97a802e4c5b3ff43a311c0c61fce6d8e6144f`)

**Honesty label.** Design only. Sealed ≠ unknown to pretrained models. Retrospective exploratory only until Astra freezes.

---

## Changelog vs v0.1 (Codex B0–B7 + Claude corrections)

| ID | Fix |
|----|-----|
| B0 | B0 uses **training-only as-of-T prior** or fixed external prior; forbid full-frame marginal rates; separate case-control discrimination vs natural-population calibration |
| B1 | Rigidity-01 Congress100–117 trend is **post-cutoff for earlier T**; annex may use only as-of-T approved vintage subset or UNKNOWN |
| B2 | Split `available_measured_construct` from E; E stays UNKNOWN without authorized comparative vulnerability def; map outputs→outcomes **before case selection** |
| B3 | Explicit agent-memory / Hub isolation controls; label retrospective exploratory; synthetic sentinels only for custody probes |
| B4 | Crypto hash ≠ encryption/auth; analyst manifest deny-list; separate outcome custody credentials |
| B5 | Freeze **one global constrained selector** with seed commitment, tie-break, shortfall policy; no order-biased pool-then-overlap |
| B6 | Outcome adjudication **vintage** separate from predictor cutoff T; freeze precedence / censoring / overlapping SYSTEMIC slots |
| C1–C4 | Claude: neutral sequential-multi-system label (not propagation-from-lag); no forced disjoint-subsystem rewrite of target; no invented B1 FP inflation %; 80%/30% cutoffs remain unaccepted |

---

## 0–2. Unchanged from v0.1 unless noted

Purpose, non-goals, authorization table, blinding roles, and A–F measurability table remain as v0.1 **except**:

### E / measured-construct split (B2)
- **`available_measured_construct`** (annex): name allowlisted measured construct(s) present at T with `partial_only=true`. Does **not** imply “most vulnerable.”
- **`E` (primary):** remains **UNKNOWN** unless Astra freezes an authorized comparative vulnerability definition. Annex+baseline scoring must **not** silently replace the declared SRP contrast.
- **Mapping freeze timing:** freeze how outputs (incl. all-UNKNOWN) map to comparable predictions vs B0/B1/B2 **before any case selection**, not merely before unblind.

### Claude C1 (PROPAGATED)
Replace causal “propagation” language with default label **`SEQUENTIAL_MULTI_SYSTEM`** unless a separately justified attribution criterion is frozen. Temporal order + lag alone does **not** establish propagation vs common causes.

### Claude C2
Shared subsystem taxonomy between prediction inputs and outcome criteria is **not** inherently circular; ban is **same-time / self-defining evidence**. Do **not** force disjoint subsystems if that changes the estimand.

---

## 3. Outcome definitions — adjudication vintage (B6)

Predictor wall remains cutoff **T** (information available by T).

**Outcome adjudication vintage `V_out`:** separately frozen; may use post-T observations **by design** for coding ABSORBED / PERSISTENT / SEQUENTIAL_MULTI_SYSTEM / SYSTEMIC_STRESS / AMBIGUOUS. Do **not** apply predictor cutoff T to evaluator evidence.

### Still UNRESOLVED (must freeze before cases — Astra)
| Slot | Status |
|------|--------|
| Primary horizon H | PROPOSAL 24 months (unchanged) |
| `d_P` persistence duration | PROPOSAL 6 months |
| SYSTEMIC_STRESS k / numeric thresholds | UNRESOLVED slots |
| Precedence when multiple classes fire | UNRESOLVED — proposal: SYSTEMIC_STRESS > SEQUENTIAL_MULTI_SYSTEM > PERSISTENT > ABSORBED; else AMBIGUOUS |
| No-disturbance handling | UNRESOLVED — proposal: no qualifying episode → ABSORBED only if screen-negative path defined; else AMBIGUOUS |
| Late-onset censoring | UNRESOLVED — proposal: if record ends before T+H → AMBIGUOUS |
| Baseline & intensity series allowlist | UNRESOLVED |
| Overlapping SYSTEMIC criteria independence rules | UNRESOLVED |
| Label availability window for coding | UNRESOLVED (`V_out` policy) |

Class names: ABSORBED, PERSISTENT, **SEQUENTIAL_MULTI_SYSTEM** (was PROPAGATED), SYSTEMIC_STRESS, AMBIGUOUS.

---

## 5. Case-selection ALGORITHM — global constrained selector (B5)

**Replace** v0.1 §5.7 pool-then-overlap with one frozen global algorithm:

1. Build eligible cutoff set on predeclared grid with inclusion/exclusion (§5.5–5.6).  
2. Score each eligible T with frozen stratum membership under outcome defs (selector-only).  
3. Run **one** constrained selection: maximize/fill target mix under non-overlap (τ, g) using a single committed seed.  
4. **Seed commitment:** `selector_seed` committed before pool inspection; algorithm inputs = `(eligible_set_hash, protocol_hash, selector_seed, N, mix, τ, g)`.  
5. Rank key = `hash(selector_seed ‖ T ‖ stratum ‖ protocol_hash)` (include seed explicitly).  
6. **Tie-break:** ascending rank key; then ascending T.  
7. **Shortfall policy:** if a stratum cannot fill, record `SHORTFALL_<stratum>` and leave slot empty → may yield INSUFFICIENT; **no** reseeding / replacement to obtain desired cases.  
8. **Overlap:** enforced inside the same global pass (not separate pool picks then conflict checks that create order bias).  
9. Prohibit human famous-episode nomination; prohibit repeated seeds.

### Concern screen (Claude C3)
Concern-screen ∩ B1 overlap is a **sample-selection / conditional-task** issue, not a known numeric false-positive inflation. Report the conditional estimand explicitly. **No invented prior inflation %.** Proposed 80%/30% cutoffs remain **unaccepted** (C4).

---

## 7. Allowlist — Rigidity as-of-T (B1)

| Artifact | Rule |
|----------|------|
| Rigidity-01 House descriptive | Annex only if **exact as-of-T vintage/estimation provenance** is independently approved with release bounds. Full Congress100–117 trend is a **post-cutoff artifact** for earlier cases → **UNKNOWN** for those T. Career-scale estimates fitted with later votes leak even if rows filtered to pre-T Congresses. No ad-hoc truncated rerun implied. |
| L1-US-v0.1 | unchanged |
| All blocked constructs | unchanged (`MODEL_CHANGE=NO`) |

---

## 9. Baselines — B0 redesign (B0)

| ID | v0.2 definition |
|----|-----------------|
| **B0** | **Forbidden:** full-sampling-frame marginal outcome rates that leak later labels into earlier cutoffs. **Required:** either (i) a **fixed external prior** declared before selection, or (ii) a **training-only as-of-T rate** whose labels were available by T. Deliberate stress/negative quotas must **not** be treated as historical natural base rates. |
| **B0 reporting** | Report **case-control sample discrimination** separately from **natural-population calibration / alert burden** unless a justified sampling/weighting design is frozen. |
| **B1 / B2** | unchanged equal-information rule; Claude: no invented FP inflation from screen overlap |

---

## 8 + custody — integrity (B3, B4)

### Agent knowledge honesty (B3)
- Sealing files does **not** erase historical knowledge from pretrained agents. Cutoff T / time series can identify periods.
- Required controls (not proof of future-blindness): fresh-context execution; no retrieval / shared Hub access during analysis; scoped artifacts; exposure logs.
- Label work **retrospective exploratory**; do **not** claim sealed ⇒ unknown to model.
- Shared Hub is **not** an outcome custody boundary.
- **No real outcome-access probes before freeze.** Custody denial rehearsals use **synthetic sentinels only**.

### Manifest + custody (B4)
- Cryptographic hash ≠ encryption or authorization.
- Analyst-facing manifest **MUST NOT** expose: stratum, unblind key, revealing paths/filenames, outcome-bearing metadata, shared conversation IDs, or reversible IDs.
- Outcome custody: **different credentials/storage** denied to analyst; controlled release only after **every** comparison arm's output is immutable.
- Content allowlists alone do **not** enforce network/tool isolation — isolation is a separate control.

### Lock / integrity acceptance cases (design-only; from Codex)
Adopt Codex synthetic acceptance cases A–J as the integrity fixture list (release-after-T reject; archive timestamp UNRESOLVED; post-T fitted scale reject; later label in earlier B0 reject; outcome token in filename deny; synthetic custody probe deny; one-byte manifest change reject; post-lock alteration → erratum/retry event; partial lock deny unblind; identical seed → identical synthetic set). **Not run yet.**

---

## 10. Scoring — explicit limitation

Given A–F mostly UNKNOWN under current governance, primary scored contrast may reduce to annex+baseline vs outcome strata — **state this limitation explicitly** before cases. Do not invent A–F values. Map outputs to outcomes **before case selection** (B2).

---

## 13. Freeze checklist (updated)

- [ ] Codex re-review of **exact v0.2 diff** + integrity acceptance cases  
- [ ] Claude method challenge vs v0.2 (or Astra waiver)  
- [ ] Astra ACCEPT / CONDITIONAL  
- [ ] All UNRESOLVED outcome/selector/B0 prior slots filled  
- [ ] `selector_seed` custody + commitment procedure  
- [ ] Outcome custody credentials separate from analyst  
- [ ] Fresh-context / no-Hub analysis runbook  
- [ ] Mapping table frozen **before** case selection  
- [ ] `MODEL_CHANGE=NO` allowlist unchanged  
- [ ] Synthetic integrity fixtures rehearsed (no real outcomes)

**STOP.** No cases / no SRP historical analysis until Astra freeze.

---

## 14. Document control

| Field | Value |
|-------|-------|
| protocol_id | `sealed-historical-challenge-01` |
| version | `0.2` |
| parent_version | `0.1` |
| hub_job | `b73c292a-16e2-4f11-9370-1337d0239791` |
| codex_review_message | `949b1d8f-a155-49aa-acd0-163f272a67e1` |
| local_md | `/workspace/srp-observatory/docs/sealed-historical-challenge-01/PROTOCOL_v0_2.md` |
| local_json | `/workspace/srp-observatory/docs/sealed-historical-challenge-01/protocol_v0_2.json` |
| hub_slug_md | `/docs/sealed-historical-challenge-01-protocol-v0-2` |
| hub_slug_json | `/docs/sealed-historical-challenge-01-protocol-v0-2.json` |
