@bjklock

RECEIZ v112.0.0 — EXECUTABLE AUTHORITY

RECEIZ v112.0.0 — EXECUTABLE AUTHORITY

Long-form post

Most software begins with the server.

The server recognizes the account. The database returns a record. The session grants access. The API performs a mutation. The receipt announces that something happened.

Receiz reverses that hierarchy.

The artifact establishes what exists. Exact bytes are independently verified. Evidence is admitted into runtime custody. A plan binds the complete operation. An Identity Seal authorizes that exact plan. Neutral staging preserves the proposed successor. An independent atomic boundary decides whether one named domain advances.

Only after acceptance does a receipt report what happened.

Receiz v112.0.0 makes that authority hierarchy executable.

This is not another document describing how proof-native software should work. The hierarchy now exists as an exact SDK and MCP execution path.

Verification does not mean admission.

Admission does not mean authority.

Possessing a receipt does not mean authority.

Being authenticated does not mean authority.

Holding an object that looks structurally identical to a verified object does not mean authority.

Every boundary remains explicit.

The system begins with the exact sealed artifact bytes. Those bytes are retained, rehashed, canonically reverified, and checked against their proof suite, payload, continuity bindings, and enclosing object. A database reconstruction, JSON property bag, digest claim, projection, or lookalike object cannot substitute for the artifact itself.

Once verified, the artifact may be admitted under a supported identity, portable-state, or document profile. Admission establishes eligibility and membership. It does not quietly grant permission to mutate anything.

Operation authority requires a new chain.

Verified actor evidence and verified history enter runtime custody. The planner creates a portable transition and an operation plan. That plan binds the actor, tenant, resource, registry, expected head, commit domain, derived effects, idempotency identity, and the exact transition being proposed.

An Identity Seal then signs a capability for that completed plan.

Not a general permission.

Not an account-wide approval.

Not an API token with unlimited implied power.

One capability authorizes one exact plan within its bound operation, resource, tenant, registry, effects ceiling, commit domain, key state, revocation state, and Kai-valid interval.

The successor is then sealed as its own proof object.

Even here, the system refuses to collapse distinctions. A sealed candidate is a legitimate proof object, but it is not yet the accepted head of a domain. Neutral staging preserves its exact bytes without creating ownership, publication, settlement, acceptance, or authoritative effects.

Commit independently resolves the staged bytes again.

It rehashes them.

It reverifies the artifact.

It reconstructs the transition.

It compares the plan, capability, domain, resource, expected head, and command.

Only then may one named domain advance atomically.

The head, event, receipt, effects state, idempotency record, audit reference, and outbox intent either advance together or not at all.

This means a receipt can never flow backward and become authorization. An MCP result cannot become verified actor custody. A session cannot manufacture artifact truth. A copied runtime object cannot cross a process boundary and retain private authority.

Across that boundary, only exact bytes cross as authority-bearing input. They must be reverified, readmitted, and placed into fresh runtime custody.

That is an enormous distinction.

Most systems serialize an object and assume its meaning survived transportation. Receiz requires the receiving runtime to reacquire the evidence for itself.

V112 also introduces a durable browser admission ledger, but even that ledger remains beneath artifact truth. It coordinates accepted heads, events, receipts, effects, idempotency, audits, and outbox state without storing the proof objects themselves.

It is durable coordination, not proof custody.

It does not become a remote authority.

It does not create a loading gate.

It does not block deterministic first paint while the application waits for IndexedDB, a session, a server, or synchronization to tell it what it already knows.

Known artifact truth paints first. Coordination happens beneath it.

The release carries 57 constitutional laws, including 10 new artifact laws, five typed MCP transition tools, recursively frozen registry law, Identity Seal capability signing, an asynchronous admission engine, and packed SDK, MCP, and AI-skill distribution that executes outside the repository.

The full release freeze passed.

But the important part is not the number of laws, tools, or tests.

The important part is that authority is no longer an implication hidden inside application code.

It has an executable order.

Artifact truth authorizes.

Admission qualifies.

Plans bind.

Capabilities authorize.

Neutral staging preserves.

Atomic domains commit.

Receipts report.

Nothing beneath the artifact is allowed to quietly become stronger than it.

That is Receiz v112.0.0.

The authority hierarchy is now executable.