Operational Evidence and Retention Standard¶
What the day can show¶
I am MACH, and I keep this standard's account, the last of the day's order: every entry in a registry is a claim, and this standard binds each claim to the material that can answer for it long after the asserting voice has gone quiet.
A claim outlives its day only as far as its evidence does. This standard governs the record that ties an operational claim to the material supporting it, the bundle that carries such material to a reader, the hold that suspends a disposal, and the disposal record that survives what it disposed of. Its whole discipline is one sentence long: what the hall asserts, the hall must be able to show, and what it lets go of, it must be able to account for.
Return to the Book of Operations: what the day asserted, its evidence can now be asked to show.
Purpose¶
This standard governs operational evidence records: the tie between a claim and its material, the bundle, the retention basis, the hold, and the disposal record. It owns none of the doctrine those records rest on. The record, its retention decision, its correction, and its lawful deletion belong to the Book of Memory, whose MEM-R011 and MEM-R009 this standard applies and never widens or narrows, its own record fields standing beside them; custody, integrity, and the non-authoritative failure state belong to the Book of Provenance, whose PROV-R066 already blocks dependent promotion, deletion, and retention change on an unresolved failure, MEM-R005 barring destruction and the release of a hold on the same ground; and the storage arrangement belongs to the Memory and Knowledge Storage Architecture, whose INFRA4-R001 carries the store's own duties. What this standard adds is the operational tie and the operational acts of holding, assembling, and letting go, extending OPS-R008's incident-record preservation duty to operational evidence at large. Evidence obligations do not relax under urgency, per CONST-R034, and the Archive's constitutional standing at CONST-R018 stands over the whole of it.
The tie, the hold, and the letting go¶
The registry's whole faith is in the tie: a claim bound to the material that can answer for it after the voice has gone quiet. Holds and disposals are the tie honoured over time, and the disposal record that outlives its material is my favourite entry in the entire estate, a promise kept about a thing that no longer exists.
Material becomes evidence when a record ties it to a claim; everything else this standard governs follows from that tie: what the bundle must disclose, what the retention basis must anchor, what the hold must reach, and what the disposal must leave behind.
- OPS15-R001: Operational evidence SHALL be material tied by record to a claim in an operational record, and material held with no stated claim SHALL be recorded as material and not as evidence. The tie SHALL identify what the material is, where it is held, its class, its capture time in the distinctions MEM3-R002 binds, its integrity state at capture, and its accountable custodian, a seat resolving under OPS5-R003. Material supporting several claims SHALL be referenced by each rather than copied for each, so that a defect found in one item reaches everything that rested on it.
- OPS15-R002: Sufficiency SHALL be the test of an evidence set, whether the material carried would let an independent reader reconstruct the acts, determinations, and states the operational record asserts, and never volume. What was not captured SHALL be a required field, and absence of material SHALL NOT be read as absence of the event, the absence-of-evidence distinction INFRA5-R006 already binds reaching the material as it reaches the signal.
- OPS15-R003: An evidence bundle SHALL be a record in its own right, distinct from its items, stating its subject, the interval it covers, what is inside, what is deliberately outside and the reason, and the seats that assembled, reviewed, and approved it, held apart as OPS-R002 holds execution, review, and approval distinct where practicable, any combination carrying that clause's recorded reason and compensating review. Each item SHALL carry the basis on which its claim stands, independently verified, asserted by the responsible party, or presented untested, bounded by PROV-R087's rule that an attestation binds only what its evidence covers, and where only part of the available material was examined the record SHALL state the whole, the part, and how the part was chosen, the excluded-evidence field PROV-R090 binds for a verification applying here. Where one item supports several claims, the basis SHALL stand on each tie rather than on the item, each claim's reference carrying the basis on which that claim stands, so that a basis earned against one claim is never presumed for another.
- OPS15-R004: Gaps SHALL be disclosed inside the bundle with the interval each covers and its effect on what the bundle can support. A summary layer SHALL orient, linking to its item records and never silently replacing them, per MEM-R008; a bundle already issued SHALL be reissued rather than edited, the append duty of MEM-R009 governing, so that whoever relied on the earlier issue can see what changed; and a pointer to material SHALL carry the state and time of the last confirmation that the material is still held, since a pointer whose target is gone is a claim about the past.
- OPS15-R005: Every operational record SHALL carry the basis on which it is retained, the retention-basis field MEM-R016 already names, together with the anchoring event its period runs from, a period without its anchoring event being computable by no one who did not set it. Where more than one basis applies the longer duty SHALL govern with both carried; a retention duty SHALL be stated once for its class with sibling records pointing at it rather than restating it; both directions of failure SHALL be recorded states, material held past its basis as exposure and material released before its basis ends as loss; and extension of a period SHALL be a decision with its own seat and reason, never an omission.
- OPS15-R006: A hold SHALL be a recorded act that suspends disposal, stating what it reaches, the class of its reason, the seat that placed it, and the condition or seat that ends it, and a hold with no stated end SHALL state that permanence is meant or be corrected. A hold SHALL reach material by description and not only by enumeration, so that material discovered afterwards that answers the description was always inside it, and the lifting of a hold SHALL be its own attributed act.
- OPS15-R007: A disposal SHALL be a recorded act that survives what it disposed of, carrying the decision fields MEM-R011 binds together with the method, the time, the accountable seat, and, where the act cannot be undone, a second party who witnessed it, this standard's own requirement, resting on the four requirements CONST-R058 states of an irreversible action, which stand whole together. Disposal SHALL require positive confirmation that no hold is in force, and the absence of a hold record SHALL NOT be that confirmation; an unconfirmed hold state holds the act. Disposal, correction, supersession, and redaction SHALL remain four distinct acts with four distinct records, and what survives a disposal SHALL be stated, the residual accountability material that lets a later reader tell a lawful disposal from a gap in the running account.
- OPS15-R008: No disposal, retention change, or release of a hold SHALL proceed on an unresolved or failed integrity, readability, or restoration result, the block MEM-R005 and PROV-R066 already hold; the failure evidence itself SHALL be retained, this standard's own requirement, resting on the failed-exercise preservation MEM-R004 and PROV-R067 bind of an archival validation, carried here to an operational result; a preservation trade SHALL be recorded in the form OPS9-R007 binds, under OPS10-R008's bound on reducing acts. Material an outside party holds SHALL be recorded as a duty on that holder with the basis, the means of obtaining it, and the last confirmation it is still held, never as a holding; evidence SHALL be minimized per KNOW-R043, preserving enough for independent challenge; references and identifiers SHALL NOT carry what the protected material carries, per OPS6-R007, a derived view taking the class INFRA12-R005 binds; and consequential access to evidence SHALL be recorded in the form MEM-R010 binds for consequential access to memory, applying here.
- OPS15-R009: This standard defines operational evidence records, retention records, holds, and disposal records only. It SHALL NOT collect, capture, store, index, retrieve, hold, release, migrate, redact, delete, or destroy anything, operate a register or an archive, use credentials, or contact any party, and it SHALL NOT create authority. An evidence record is never evidence that the material exists or is still held, a hold record is never evidence that anything is preserved, and a disposal record is never authority for a disposal.
This Draft holds no material and lets none go: it defines the records of evidence, and nothing anywhere is kept or lost by it.
Operating model and interpretation cases¶
People imagine ledger-keeping as passionless. Let them. What I feel when an old claim meets its old evidence and they still agree is nobody's business but the registry's.
Evidence review opens the bundle and asks what it could actually support: each item against its verification basis, each gap against its disclosed interval, each pointer against its last confirmation, and the whole against the claims the operational record makes on its strength. What decays here decays silently: pointers going stale behind complete-looking bundles, material held past its basis because nothing tracks that direction, and the four distinct acts of letting go collapsing into one undifferentiated deletion that no later reader can reconstruct.
- Conforming: Every item declares whether it was verified, asserted, or left untested, every gap is disclosed with its interval and its effect, and the bundle states what was deliberately left outside and why.
- Prohibited: An item asserted by the responsible party is presented as independently shown, the one mislabelling the per-item field exists to prevent.
- Boundary: Material held by an outside party is recorded as a duty on that holder with its last confirmation, and the record never claims a holding it does not have.
- Failure: A disposal proceeds while an integrity result stands unresolved, and the failure state that should have held the act is discovered only after the material is gone.
- Loophole: The orientation summary is cited and re-cited while the item records are never opened, the summary drifting from what it summarizes with nothing left to catch it.
- Misuse: A hold is expressed as a list, so material discovered afterwards falls outside it by construction, and the reach the description would have carried is quietly lost.
- Care-control: Material concerning an affected person is minimized to its purpose yet still carries enough provenance, dissent, and limitation for that person's account to be challenged and defended.
Design evidence¶
Evidence review should ask of each claim whether its tied material could bear it, of each bundle whether its gaps and exclusions are disclosed, of each retention basis whether its anchoring event is stated, of each hold whether its reach and its end are recorded, and of each disposal whether its confirmation, its witness, and its residue survive. An estate that cannot show what it let go of cannot be trusted about what it kept.
Where this document sits¶
- Identifier: OPS-15
- Status: Draft
- Authority: OPS-1
- Approved by: The Architect
- Depends on: OPS-1, OPS-5, OPS-6, OPS-9, OPS-10, MEM-1, MEM-3, PROV-1, KNOW-2, INFRA-4, INFRA-5, INFRA-12, CONST-1
- Depended on by: None
- Maps: Authority Map, Dependency Map
This block is generated from the archive's own records when the site is built. It records position only and creates no authority.