SubstrateX Aperture™ Runtime Evidence Authority
From Computed Material to Qualified Runtime Evidence
SubstrateX Aperture™ can ingest a source, reconstruct a runtime, compute behavioral telemetry, establish temporal and stability postures, and issue bounded Instrument Findings. None of those operations makes every resulting value, marker, interpretation, or interface statement qualified Runtime Evidence by default.
Computed material becomes Runtime Evidence only when Aperture can establish what record was examined, how it was transformed, which methods and versions were applied, what evidence supports each claim, which limitations remain, and whether the resulting record conforms to its declared authority boundary.
The Runtime Evidence Authority governs that transition.
Runtime Evidence Authority is the versioned governance architecture through which SubstrateX Aperture™ binds computed material to a qualified source, canonical runtime, run identity, evidence lineage, legitimacy state, disclosure posture, claim boundary, and preservation record before it can be issued as Runtime Evidence.
The term authority refers to computational authority within Aperture. It does not imply legal authority, regulatory approval, institutional accreditation, or independent scientific certification.
Its governing rule is:
Computation produces results. Evidence authority determines what those results are permitted to establish.
Computed Material Is Not Automatically Runtime Evidence
A deterministic value may be reproducible and still lack a sufficient source basis. A marker may exist but remain only a candidate. A metric may be correctly computed while functioning only as a proxy. An interpretation may be internally consistent while exceeding the available record. An export may contain many fields while failing to preserve their lineage.
Runtime Evidence therefore requires more than successful computation.
It requires:
a qualified and identified source;
a canonical runtime whose relationship to that source is inspectable;
a declared computational run and version context;
registered measurements with known legitimacy and computability;
evidence coverage sufficient for the claim being made;
source-linked claim lineage;
explicit disclosure and missingness states;
evidence-authority conformance;
a bounded certification scope;
an integrity seal over the declared evidence-bearing core; and
an export and preservation path that does not enlarge the evidence.
The distinction can be stated compactly:
Computed does not mean qualified.
Deterministic does not mean scientifically validated.
Issued does not mean universally certified.
Exported does not mean preserved.
Position Within the Engineering Architecture
Runtime Evidence Authority performs a responsibility distinct from the other major engineering layers.
Engineering layerGoverning responsibility
Runtime Blackbox
Controls the computation boundary: source loaded, readiness established, computation initiated, and issuance state resolved.
Runtime Reconstruction Architecture
Constructs the inspectable longitudinal record: canonical runtime spine, event ledger, coordinates, worldline, regimes, markers, replay frames, and source links.
Behavioral Telemetry and Instrumentation
Computes registered signals and permits contract-governed instruments to project bounded findings over the reconstructed runtime.
Runtime Evidence Authority
Determines which resulting material is qualified, legitimate, sufficiently supported, conformant, claim-bounded, sealable, exportable, and preservable as Runtime Evidence.
The governing distinction is:
The Blackbox governs computation. Runtime Reconstruction constructs the record. Telemetry and instruments measure it. Runtime Evidence Authority governs what the resulting record is permitted to establish.
The Authority Path
The evidence-authority path is:
Qualified source and source identity
↓
Canonical runtime and canonical identity
↓
Versioned computation and run identity
↓
Current Evidence Run
↓
Evidence-authority conformance
↓
Metric legitimacy, coverage, sufficiency, disclosure, and claim lineage
↓
Runtime Evidence Record
↓
Runtime Evidence Passport, certification scope, and Evidence Seal
↓
Artifact identity and Export Authority
↓
Preservation readiness and Evidence Commons handoff
Each stage answers a different question. Together they prevent a computed output, visual surface, explanatory statement, or exported package from acquiring authority that the underlying record does not possess.
The Current Evidence Run
The Current Evidence Run is the active run-wide authority context within Aperture.
It binds the qualified source and canonical runtime to the computational objects produced during one declared run. Depending on the available evidence and applicable versions, it may govern:
source identity and provenance;
canonical runtime structures;
runtime frames and event ledger;
role and interaction topology;
coordinate and temporal systems;
registered telemetry and measurements;
detector outputs and regime structures;
authoritative and candidate markers;
Instrument Findings;
evaluation and synthesis state;
REIM classification and routing;
Human Read and Evidence Brief projections;
evidence availability and missingness;
claim boundaries;
Passport state;
export authority; and
preservation readiness.
The Current Evidence Run prevents the observatory's surfaces from becoming independent sources of truth. Reconstruction, instruments, REIM, Human Read, investigation, export, and preservation must all resolve to the same governing run.
The Current Evidence Run is active and computational. It may acquire additional authorized outputs as the run progresses, but those outputs may not rewrite the source, canonical runtime, or prior authority state without a versioned recomputation.
One current run. One evidence authority. Multiple bounded computations.
From Current Evidence Run to Runtime Evidence Record
The Runtime Evidence Record is the structured evidence-bearing representation assembled from the Current Evidence Run.
It is not a screenshot, interface state, summary report, or collection of unrelated outputs. It is the machine-readable record that preserves the relationship among:
the source supplied;
the transformations applied;
the canonical runtime constructed;
the measurements computed;
the temporal and stability authorities used;
the Instrument Findings issued;
the interpretations and synthesis objects formed;
the evidence that supports each material claim;
the evidence that was missing or insufficient;
the versions that governed computation; and
the boundaries limiting what the record can establish.
When the record satisfies the applicable issuance and conformance requirements, Aperture may issue it as a Certified Runtime Evidence Record.
Certification is scoped. It means that the record passed the declared Aperture checks for identity, integrity, lineage, versioning, disclosure, authority conformance, and claim boundaries. It does not certify that every interpretation is objectively true or scientifically validated.
The Four Identities
Runtime Evidence Authority distinguishes four related identities. They must not be collapsed into one identifier.
Source identity
The supplied source record or declared source collection before Aperture-derived computation.
A change to source bytes, source membership, source ordering where material, or the declared source boundary.
Canonical identity
The normalized, role-aware, event-bearing runtime representation produced through the declared ingestion and canonicalization methods.A source change or a change to the adapter, normalization, schema, role mapping, event extraction, or canonicalization version.
Run identity
One computation over the canonical runtime under a declared configuration, registry set, method set, and software version.A change to computational configuration, registered methods, thresholds, code version, or another run-governing input.
Artifact identity
A specific exported or preserved package containing the evidence record and its declared envelope.A change to package composition, manifest, export format, included attachments, issuance metadata, or preservation envelope.
These identities make several important distinctions possible.
The same source may produce a different canonical identity when the canonicalization method changes. The same canonical runtime may be recomputed under a later measurement version and therefore receive a different run identity. The same evidence-bearing core may be packaged into more than one artifact format without pretending that every packaging difference changed the underlying source.
Identity separation also protects determinism. Operator-added notes, export timestamps, destination metadata, and presentation choices should not silently alter the identity of the deterministic evidentiary core unless the applicable artifact contract explicitly includes them.
Evidence-Authority Conformance
Evidence-authority conformance determines whether the material attached to the run remains aligned with the governing evidence architecture.
Conformance is not a judgment that every scientific construct is valid. It is a structural and semantic check that the system has respected its own declared authorities.
Identity conformance
Every material output resolves to the correct source, canonical, run, and—where applicable—artifact identity.
Provenance conformance
Derived objects retain their source objects, transformations, method versions, and supporting source spans.
Coordinate conformance
Frames, events, findings, markers, replay structures, and claims use declared and reconcilable coordinate systems.
Temporal conformance
Temporal claims resolve through the applicable temporal authority and remain within the eligible evidence horizon.
Signal conformance
Metrics use registered definitions, inputs, versions, availability states, and legitimacy classes.
Marker conformance
Candidate, confirmed, source-supplied, and computed markers retain their distinct authority and status.
Instrument conformance
Instruments read authorized evidence, honor dependencies, issue only permitted findings, and do not mutate governing evidence.
Interpretation conformance
Runtime Evidence Interpretation Matrix (REIM), synthesis, and Human Read remain subordinate to authorized evidence and preserve missingness, alternatives, and claim limits.
Claim conformance
Every material claim remains within its evidence basis, certification scope, and explicit non-certifications.
Preservation conformance
Exported artifacts retain identity, manifest, integrity references, versions, lineage, disclosures, and claim boundaries.
A run may compute successfully and still fail evidence-authority conformance. In that case, the system may preserve the failed or partial state for debugging and validation, but it must not present the affected material as fully qualified Runtime Evidence.
The Metric-Legitimacy Matrix
The metric-legitimacy matrix governs whether a computed value is authorized for use and what it is permitted to mean.
The existence of a number is not sufficient. A metric must disclose its relationship to the source and the claim for which it is being used.
For each registered metric or signal, the matrix may identify:
metric and registry identity;
definition and computational method;
method and schema version;
eligible source objects;
source basis and provenance path;
coordinate domain and evidence horizon;
computability and sufficiency requirements;
availability and missingness state;
authority class;
eligible instrument or downstream consumer;
uncertainty, coverage, or confidence posture where applicable;
permitted interpretations; and
prohibited claims.
The principal authority classes are:
Direct
The value or event is present in the qualified source record, subject to source integrity and interpretation limits.
Derived
The value is reproducibly computed from eligible source or canonical evidence through a declared method.
Proxy
The value is an indirect indicator of a property and cannot be treated as the property itself without separate calibration.
Interpretive
The value or label organizes authorized evidence through a declared heuristic or classification method.
Experimental
The construct is implemented for investigation but remains explicitly availability-gated, calibration-limited, or research-facing.
Legitimacy is claim-specific. A metric may be legitimate for describing relative change across a runtime while remaining illegitimate as a calibrated probability, causal estimate, or universal diagnostic.
The matrix therefore answers two different questions:
Can this value be computed from the available record?
If it can, what is it permitted to establish?
Evidence Coverage and Sufficiency
Evidence coverage and evidence sufficiency are related but distinct.
Coverage describes what portion and which dimensions of the relevant record are available. It may concern:
source-span coverage;
event and frame coverage;
role coverage;
temporal coverage;
marker coverage;
telemetry coverage;
instrument dependency coverage;
replay coverage; and
disclosure coverage.
Sufficiency describes whether the available evidence satisfies the requirements of a particular measurement, finding, classification, or claim.
A run may have broad coverage and still be insufficient for formal lead time because no observable failure marker was supplied. A partial record may be sufficient for the narrow claim that a particular tool error occurred while remaining insufficient for a trajectory-level recovery claim.
Coverage is therefore not a universal percentage of truth, and sufficiency is never global.
The evidence record must preserve meaningful distinctions among:
available;
observed;
not observed;
not supplied;
partial;
candidate only;
proxy-only;
unsupported;
not computable; and
unavailable.
Absence must not be replaced by zero, a default marker, an inferred event, or a convenient narrative conclusion.
Evidence sufficiency belongs to the claim, not merely to the run.
Claim Lineage
Runtime Evidence Authority requires every material claim to retain a path back to the evidence that authorizes it.
The claim-lineage path is:
Source evidence or declared context
↓
Canonical event, frame, role, or source span
↓
Registered measurement, marker, or regime state
↓
Instrument Finding or evaluation state
↓
REIM, synthesis, or Human Read statement
↓
Preserved claim and artifact reference
Not every claim requires every layer, but no material claim may lose the relationships applicable to it.
A claim-lineage record may retain:
claim identity and type;
run and Passport references;
source and canonical references;
runtime coordinates and eligible horizon;
contributing measurements and findings;
method, registry, and schema versions;
evidence-basis and availability state;
confidence or uncertainty posture where applicable;
supporting and contradictory evidence;
admissible interpretation;
explicit non-claims; and
preserved artifact location.
Claim lineage makes the result challengeable. A reviewer can move from a readable statement to the computation that produced it, inspect the supporting source, determine whether the method was admissible, and identify where the authority of the claim ends.
Disclosure State
Runtime Evidence is only as accountable as its disclosed evidence conditions.
The disclosure state records what is known, what was supplied, what was transformed, and what remains absent. Depending on the source and operational environment, it may include:
source family, format, and collection boundary;
source-supplied and normalized roles;
adapter and transformation versions;
timestamp and ordering availability;
model, provider, or system identity when supplied;
operational environment and operator-declared context;
observable failure or consequence markers;
optional embedding, trace, benchmark, or external telemetry availability;
redaction, truncation, filtering, or sampling state;
known gaps and unsupported fields;
privacy or sensitivity flags where implemented; and
the distinction between source evidence and operator declaration.
Not every disclosure is required for every claim. The authority requirement is that absence remains explicit and that a missing disclosure cannot be silently treated as present.
Operator-declared context may assist interpretation. It does not become a source-observed fact merely because it appears in the record.
Certification Scope
Certification within Aperture is deliberately narrow.
When a Runtime Evidence Record is issued as certified, the certification may establish that:
the record has identified source, canonical, and run relationships;
the declared computation completed under known versions;
evidence-authority conformance checks were applied;
registered measurements retain their legitimacy states;
material claims retain evidence lineage;
missingness and disclosures were preserved;
the claim boundary and non-certifications are explicit;
the evidence-bearing core has an integrity reference or seal; and
the record is eligible for the declared export or preservation operation.
Certification does not establish:
that the supplied source is complete, authentic, or free from omission beyond the checks performed;
that every measurement is scientifically validated;
that an interpretation is objectively true;
hidden model state, private reasoning, intent, consciousness, cognition, agency, or identity;
root cause or universal causation;
human or organizational responsibility, blame, competence, or legal liability;
universal safety, alignment, deployment readiness, or regulatory compliance;
calibrated probability without applicable calibration;
guaranteed future failure or recovery;
provider-controlled internals; or
required operational action.
Certification establishes the integrity and scope of the evidence process—not the universal truth of the conclusion.
The Runtime Evidence Passport
The Runtime Evidence Passport is the operator-facing identity and authority surface for the issued record.
It may disclose:
source, canonical, run, record, and artifact identities where applicable;
source and transformation provenance;
computational, registry, schema, and method versions;
evidence coverage and sufficiency posture;
metric-legitimacy and conformance status;
temporal and marker availability;
disclosure and missingness state;
certification scope;
explicit non-certifications;
Evidence Seal;
export authority;
preservation readiness; and
claim boundary.
The Passport does not create the Runtime Evidence Record and does not perform analysis. It identifies the record, states how it was formed, exposes its limits, and provides the reference through which reconstruction, investigation, export, and preservation remain connected to the same evidence object.
A Passport can be issued only to the extent that its fields are supported. Missing identity, disclosure, or conformance information must remain visible rather than being replaced by a completed-looking presentation.
The Evidence Seal
The Evidence Seal is the integrity reference for the declared evidence-bearing core.
It binds the issued record to the content and versions included within the seal contract. Depending on the implementation version, the sealed core may include:
source and canonical identities;
run identity;
canonical runtime structures;
registered measurements and markers;
evidence-authority and metric-legitimacy state;
claim lineage and boundaries;
Passport evidence fields;
applicable schemas, registries, and method versions; and
manifest references required for reconstruction or preservation.
If material within the sealed core changes, the seal must no longer be represented as the same seal.
The Evidence Seal is not, by itself, an external notarization, digital-signature guarantee, proof of source authenticity, or certification of scientific validity. It establishes integrity relative to the declared Aperture sealing method and payload.
The distinction among identities remains important. A later export may add packaging metadata or an issuance timestamp and therefore receive a new artifact identity without changing the deterministic evidence core. Conversely, a change to the canonical runtime, registered method, or evidence-bearing finding requires a new run or seal as governed by the applicable contract.
Export Authority
Export Authority determines what material may leave the active run as an evidence-bearing artifact and under which identity, manifest, and claim boundary.
It governs matters such as:
whether the record has reached an exportable state;
which evidence objects are authorized for inclusion;
which attachments are canonical, optional, contextual, or excluded;
which manifest and integrity references apply;
whether replay and reconstruction dependencies are present;
which disclosures and limitations must accompany the artifact;
which portions belong to the deterministic evidence core;
which portions belong to the export envelope; and
whether the artifact is suitable for preservation handoff.
The distinction between core and envelope is essential.
Artifact layerTypical contentsAuthorityDeterministic evidence coreCanonical identities, evidence record, runtime structures, measurements, markers, findings, claim lineage, method versions, boundaries, and Evidence Seal.Recomputable or verifiable under the declared evidence contract.Export envelopeArtifact format, package manifest, issuance timestamp, destination information, operator-declared notes, and other packaging context.Contextual to the export and prohibited from rewriting the deterministic core.
Export Authority is not permission to disclose confidential, personal, regulated, or proprietary information. Legal, privacy, security, organizational, and consent requirements remain external responsibilities unless a specific control is explicitly implemented and declared.
Preservation Readiness
Preservation readiness describes whether the evidence record can be handed off without losing the information required for later inspection, recomputation, comparison, or challenge.
A preservation-ready record should retain, where applicable:
stable source, canonical, run, record, and artifact identities;
a declared manifest and artifact composition;
the Evidence Seal and integrity references;
source and transformation provenance;
schemas, registries, methods, and versions;
canonical runtime, reconstruction, and replay structures;
measurements, markers, Instrument Findings, and interpretation objects;
evidence coverage, sufficiency, and missingness;
claim lineage and source paths;
disclosure state;
certification scope and explicit non-certifications;
the Runtime Evidence Passport; and
the requirements for future reconstruction or verification.
Preservation readiness is not the same as preservation. It means that the record has the identity, integrity, lineage, composition, and boundaries required for a preservation operation under the declared contract.
A record may be preserved in a partial or failed state when that state is itself important evidence. In such cases, the artifact must identify the failure, missing components, and limits rather than presenting itself as a fully issued record.
Evidence Commons Handoff
Evidence Commons receives the preservable artifact produced through Runtime Evidence Authority.
The handoff may include:
the Runtime Evidence Record;
Runtime Evidence Passport;
source, canonical, run, and artifact identities;
manifest and Evidence Seal;
canonical runtime and reconstruction structures;
replay frames and event ledger;
registered measurements, markers, and Instrument Findings;
REIM, synthesis, Human Read, and investigation state where included;
claim lineage and source references;
disclosure, missingness, and uncertainty states;
schemas, registries, computational methods, and versions;
certification scope and explicit non-certifications; and
preservation and comparison metadata.
Evidence Commons does not enlarge the authority of the record. It preserves the record together with the information required to understand what was computed, what was claimed, what remained absent, and how the artifact can be inspected or challenged later.
Preservation carries authority forward. It does not create additional authority.
Failure and Partial-Issuance States
Evidence authority must remain meaningful when computation is incomplete or conformance fails.
A run may be unable to issue a fully certified record because:
source qualification failed;
canonicalization was incomplete;
identity relationships could not be resolved;
required methods or registry versions were unavailable;
evidence-authority conformance failed;
a material metric lacked legitimacy;
required source spans or lineage were missing;
disclosure state was insufficient for the requested claim;
the seal could not be formed or verified; or
the intended export lacked required manifest or preservation components.
These conditions should not disappear behind a generic error. Where safe and technically possible, Aperture may preserve the partial state as a validation, debugging, or accountability artifact.
The artifact must state what completed, what failed, which outputs remain usable, which claims are prohibited, and whether recomputation is required.
The Claim Boundary
Runtime Evidence Authority governs the qualification, identity, integrity, lineage, and bounded issuance of observable runtime evidence.
It does not transform Aperture into an oracle. It does not make implementation equivalent to scientific proof. It does not allow a seal, Passport, certification label, export, or preservation artifact to exceed the evidence from which it was formed.
Its authority ends where the source, declared computation, coverage, sufficiency, calibration, disclosure, and claim boundary end.
This produces a strict hierarchy:
Source evidence constrains canonicalization.
Canonicalization constrains computation.
Computation constrains findings.
Findings constrain interpretation.
Interpretation constrains Human Read.
The complete lineage constrains certification, export, and preservation.
No downstream layer may silently reverse that hierarchy.
The Engineering Contribution
Hashes, manifests, provenance records, certificates, and export bundles are not individually new. The engineering contribution is their integration into a runtime evidence architecture in which identity, measurement legitimacy, claim lineage, disclosure, interpretation, certification scope, and preservation remain governed by one run-wide authority.
Within SubstrateX Aperture™:
computed material is not automatically treated as evidence;
four distinct identities prevent source, computation, and packaging from being conflated;
the Current Evidence Run provides one active authority root;
evidence-authority conformance aligns the observatory's outputs;
the metric-legitimacy matrix governs what values are permitted to mean;
coverage and sufficiency remain claim-specific;
material claims retain source-linked lineage;
missingness and disclosure persist into operator-facing surfaces;
certification remains explicit and narrow;
the Passport exposes identity, formation, integrity, and limits;
the Evidence Seal protects the declared evidence-bearing core;
Export Authority preserves the distinction between core evidence and packaging context; and
Evidence Commons receives a bounded, inspectable, and challengeable artifact.
This is the architecture that allows Aperture to produce Runtime Evidence rather than merely analytical output.
The Governing Definition
Runtime Evidence Authority is the versioned governance architecture through which SubstrateX Aperture™ qualifies computed runtime material, binds it to source, canonical, run, and artifact identities, verifies its legitimacy and lineage, declares its coverage and certification limits, seals the evidence-bearing core, and authorizes bounded export and preservation as Runtime Evidence.
SubstrateX Aperture™ does not establish Runtime Evidence by declaration. It establishes the identity, provenance, computation, legitimacy, sufficiency, lineage, disclosure, conformance, and preservation conditions under which a runtime record can be issued and examined as evidence.
