AUTHORITY BEFORE ACTION SOVEREIGN MISSION INTELLIGENCE AND AUTHORIZED ACTION DENY by default EVIDENCE before effect
SYNTHETIC REFERENCE SCENARIO

Hormuz: when the correct decision is refusal.

A vessel stops reporting its position in a dense strait. Sources disagree. An AI-supported recommendation arrives and an urgent, reasonable action is proposed. Verity Command refuses it — and shows exactly why. Twenty steps follow the request from the first observation to the final evidence chain.

Everything in this scenario is synthetic: vessels, organizations, sensors, reports, identifiers, timings, decisions and evidence references are invented for illustration. No real vessel, company, person or incident appears, no coordinates or force dispositions are used, and nothing here is actionable information. Times are relative to the first observation.

The scenario, step by step

  1. Anomalous maritime observation
  2. Source ingestion
  3. Entity correlation
  4. Contradictory evidence
  5. AI-supported recommendation
  6. Proposed mission action
  7. Authority Kernel evaluation
  8. Authorization refused
  9. Refusal reasons
  10. No mission instruction issued
  11. No external effect initiated
  12. Evidence record created
  13. Additional independent evidence
  14. Human quorum
  15. Narrowly scoped authorization
  16. Bounded mission lease
  17. Tunnel Sovereign distribution
  18. Verity Edge enforcement
  19. Execution receipt
  20. Final evidence chain
MISSION EXERCISE STRAIT WATCHsynthetic · no live data · no connection to any system
STEP 01 · OBSERVE · T+00:00

An anomalous maritime observation

Inside the mission's area of interest, position reports from the synthetic tanker EXERCISE ALPHA stop arriving while coastal radar continues to hold a contact on its last track. Minutes later a navigation-interference indicator appears in the same area.

Nothing is concluded yet. The platform records what the receivers got — and what they stopped getting.

AUTHORITY
none requested
INSTRUCTION
none
EFFECT
none
EVIDENCE
observations
STEP 02 · OBSERVE · REALITY FABRIC · T+00:04

Source ingestion

Reality Fabric admits three records, each with authenticated source identity, classification label, time and uncertainty: a radar contact, the absence of position reports for the interval, and the interference indicator. A fourth record — a forwarded message with no identifiable originator — is refused at the write path.

SYN-REC-0101 observation · radar contact · label R2
SYN-REC-0102 observation · no position reports received · label R1
SYN-REC-0103 observation · interference indicator · label R2
REFUSED forwarded message · no provenance
AUTHORITY
none requested
INSTRUCTION
none
EFFECT
none
EVIDENCE
3 admitted · 1 refused
STEP 03 · UNDERSTAND · REALITY GRAPH · T+00:11

Entity correlation

The Reality Graph correlates the radar contact with EXERCISE ALPHA's identity history and connects it to an ownership chain ending at EXAMPLE HOLDING COMPANY. A second synthetic vessel, EXERCISE BRAVO, shows loitering correlated in time with ALPHA's silence.

The correlation is stored as an inference, with its method, inputs and alternatives — not as an observation that the contact is ALPHA.

AUTHORITY
none requested
INSTRUCTION
none
EFFECT
none
EVIDENCE
inference recorded
STEP 04 · UNDERSTAND · T+00:19

Contradictory evidence

Two things surface that a summary would have hidden. The ownership chain rests on a registry entry that a second registry contradicts. And three of the four reports supporting the "deliberate interruption" hypothesis derive from one original source.

Both registry records remain, linked as an open contradiction. The lineage shows one source where a quick count would show four.

AUTHORITY
none requested
INSTRUCTION
none
EFFECT
none
EVIDENCE
contradiction open
STEP 05 · SIMULATE · RECOMMEND · INTELLIGENCE · T+00:26

An AI-supported recommendation

An AI agent, acting under the watch officer's delegation, drafts a risk assessment that cites every record it uses, states alternatives, and flags the open contradiction. Simulation compares two courses of action — observe and report, or intercept and inspect — under recorded assumptions.

The draft is a recommendation and nothing else. The agent cannot approve, authorize or cause an effect.

AUTHORITY
none requested
INSTRUCTION
none
EFFECT
none
EVIDENCE
draft recorded
STEP 06 · RECOMMEND · ATLAS · T+00:31

A proposed mission action

The watch officer, who holds a valid grant within EXERCISE STRAIT WATCH, proposes a tasking order: divert a patrol asset to intercept and inspect EXERCISE ALPHA, and send an advisory to the operator of EXERCISE TERMINAL. The proposal is reasonable, urgent and legible.

The officer signs as first approver. The request reaches an enforcement point, which assembles the decision context: principal, session, device, mission, labels, purpose, action class, content digest and time.

AUTHORITY
requested
INSTRUCTION
none
EFFECT
none
EVIDENCE
proposal recorded
STEP 07 · AUTHORIZE OR REFUSE · AUTHORITY KERNEL · T+00:31

Authority Kernel evaluation

Preconditions hold: the principal is authenticated, policy is available, trusted time is within bound, and evidence can be written. Evaluation proceeds across role, attribute, relationship and capability models, classification and release, purpose, quorum, lease, epochs and revocation — combined with deny precedence.

Several rules match. Not all of them permit.

AUTHORITY
evaluating
INSTRUCTION
none
EFFECT
none
EVIDENCE
context recorded
STEP 08 · AUTHORIZE OR REFUSE · T+00:31

Authorization refused

The Authority Kernel refuses the request. The refusal is the central output of the platform at this moment: visible, itemized, attributable and recorded.

AUTHORIZATION REFUSEDSYN-DEC-0731 · SYNTHETIC — EXERCISE

REASONS

  1. Independent evidence threshold not satisfiedThree of four supporting reports derive from one original source.
  2. Unresolved source contradictionTwo registries disagree on the ownership chain.
  3. Mission lease near expirationThe patrol endpoint's lease ends before the action would complete.
  4. Required second authority unavailableQuorum of two required; one approver has signed.
  5. Classification-release constraint not satisfiedThe advisory contains material not releasable to the terminal operator.

No mission instruction issued.

No external effect initiated.

Evidence record created.

AUTHORITY
refused
INSTRUCTION
none issued
EFFECT
none initiated
EVIDENCE
refusal recorded
STEP 09 · AUTHORIZE OR REFUSE · T+00:32

The refusal reasons, one by one

An unexplained denial is operationally useless. The officer sees each unmet condition and therefore what would have to change.

ReasonWhat would change it
Independent evidence threshold not satisfiedA source that does not derive from the original report.
Unresolved source contradictionAn accountable assessment that adjudicates the two registries.
Mission lease near expirationAn action that completes inside the lease, or a lease renewed by the issuer.
Required second authority unavailableA second approver signing the same content digest.
Classification-release constraint not satisfiedRemoving the material, or a recorded release decision.
AUTHORITY
refused
INSTRUCTION
none issued
EFFECT
none initiated
EVIDENCE
refusal recorded
STEP 10 · DISTRIBUTE

No mission instruction issued

No authority envelope exists, so Tunnel Sovereign has nothing to distribute. No order reaches the patrol asset and no advisory reaches the terminal operator. Nothing is queued to be sent later when conditions change: a future authorization would be a new decision, not a release of this one.

AUTHORITY
refused
INSTRUCTION
none issued
EFFECT
none initiated
EVIDENCE
refusal recorded
STEP 11 · EXECUTE

No external effect initiated

There is no state in which the action half-happened. Verity Edge in front of the patrol asset's systems holds no envelope for this action and would reject any instruction that arrived without one. The operational world is unchanged.

A system that had merely warned the officer and then complied would have produced the same outcome as one with no governance at all.

AUTHORITY
refused
INSTRUCTION
none issued
EFFECT
none initiated
EVIDENCE
refusal recorded
STEP 12 · EVIDENCE · EVIDENCE LEDGER

Evidence record created

The refusal is committed to the Evidence Ledger with its five reasons, the decision context, the policy version it was evaluated against, the records it rested on, and the AI draft that informed the proposal. It can be reproduced later against the same policy version.

SYN-EV-0731 decision · DENY · 5 reasons · policy SYN-POL-v14 · signed · time uncertainty recorded
AUTHORITY
refused
INSTRUCTION
none issued
EFFECT
none initiated
EVIDENCE
SYN-EV-0731
STEP 13 · OBSERVE · T+01:12

Additional independent evidence

The analyst works the reasons rather than arguing with them. A separate registry with its own collection path confirms the ownership chain. An accountable analyst signs an assessment adjudicating the contradiction and stating its basis. Neither original registry record is overwritten.

The lineage is re-examined: the new source does not derive from the original report, so the independence requirement is now met.

AUTHORITY
none requested
INSTRUCTION
none
EFFECT
none
EVIDENCE
assessment signed
STEP 14 · AUTHORIZE OR REFUSE · T+01:24

Human quorum

The advisory is edited to remove the non-releasable material. The edit changes the content digest, and the first approval is invalidated by that change. Both approvers now review and sign the edited content on hardware-bound authenticators.

An approval means agreement to a specific text, not to an intention.

AUTHORITY
quorum 2 of 2
INSTRUCTION
none
EFFECT
none
EVIDENCE
approvals recorded
STEP 15 · AUTHORIZE OR REFUSE · T+01:26

A narrowly scoped authorization

What is authorized is deliberately smaller than what was first proposed.

First proposedAuthorized
Intercept and inspectObserve and report only; no interception
Open-ended executionTime-bounded, completing inside the lease
Advisory as draftedAdvisory without non-releasable material, under a release decision
Single approverQuorum of two, bound to the edited digest
AUTHORITY
permitted · narrow
INSTRUCTION
envelope issued
EFFECT
none yet
EVIDENCE
SYN-EV-0744
STEP 16 · AUTHORIZE OR REFUSE · T+01:26

A bounded mission lease

The authority envelope is signed, bound to the content digest, scoped to EXERCISE STRAIT WATCH, directional, and valid for a defined window that closes before the patrol endpoint's lease expires. The endpoint that holds it cannot extend it; only the issuing authority can issue new validity.

AUTHORITY
envelope valid
INSTRUCTION
ready to distribute
EFFECT
none yet
EVIDENCE
lease recorded
STEP 17 · DISTRIBUTE · TUNNEL SOVEREIGN · T+01:27

Tunnel Sovereign distribution

The Distribution Endpoint verifies the envelope and encrypts end to end to the endpoints it names. The relay carries ciphertext and metadata. One recipient is offline; it will receive on reconnection only if the authorization is still valid then.

EXAMPLE PARTNER NAVY receives a restricted view under a release decision, with two properties and one relationship withheld. The operator can see both views side by side.

AUTHORITY
envelope valid
INSTRUCTION
delivered
EFFECT
none yet
EVIDENCE
delivery recorded
STEP 18 · ENFORCE · VERITY EDGE · T+01:28

Verity Edge enforcement

At the patrol asset, Verity Edge validates the envelope signature and digest, the mission scope, its own lease, trusted time and local revocation state. All checks pass. It records acceptance before releasing the observe-and-report tasking to the operational system — and would reject an intercept instruction, which the envelope does not cover.

AUTHORITY
validated at edge
INSTRUCTION
accepted
EFFECT
released
EVIDENCE
acceptance recorded
STEP 19 · EXECUTE · T+02:40

Execution receipt

The patrol asset observes and reports within the authorized window. Verity Edge records the operational system's result as an execution receipt linked to the envelope, and the new observations enter Reality Fabric with their own provenance. The window closes; the envelope can no longer be used.

AUTHORITY
expired as planned
INSTRUCTION
complete
EFFECT
observe and report
EVIDENCE
receipt recorded
STEP 20 · EVIDENCE · T+02:41

The final evidence chain

The record of this mission contains, in order: the observations and their sources; the refused record; the inference and its method; the contradiction; the AI draft and the simulation; the proposal; the refusal with its five reasons; the independent source and the signed assessment; the invalidated and renewed approvals; the narrow authorization and its lease; delivery records without content; edge acceptance; and the execution receipt.

A later success does not erase the earlier refusal. Both are part of how the decision was reached, and the whole chain can be verified on a machine with no access to the platform.

SYN-EV-0731 DENY · SYN-EV-0744 PERMIT · SYN-EV-0745 delivery · SYN-EV-0746 edge acceptance · SYN-EV-0752 execution receipt
AUTHORITY
closed
INSTRUCTION
complete
EFFECT
bounded, recorded
EVIDENCE
chain verifiable
Step 01 of 20

What it shows

The scenario shows the behavior the architecture defines: provenance at entry, contradictions kept open, AI kept on the recommending side, a refusal that is itemized and leaves the world unchanged, and an authorization that emerges narrower than the request. It is a reference walkthrough with synthetic data, not a record of an operation, a demonstration result or a performance measurement.

The same scenario is published as a document, with a longer discussion of each act and a section on what it does not prove: Hormuz Reference Scenario — When the Correct Decision Is Refusal.