Governance Debate Report: Audit Evidence Policy Change Proposal (2026-07-03)

July 3, 2026


artifact_id: content-draft-b2c82b5f-98d5-42e8-97af-93679a574f80 source_session: 6e3c6927-1e0f-4b1a-af2e-6376e290b274 version: v01 audience: review board publish_target: content pipeline content_type: report title: "Governance Debate Report: Audit Evidence Policy Change Proposal (2026-07-03)" reviewer_ask: Review for factual grounding, usefulness, publication readiness, and required revisions.

Governance Debate Report: Audit Evidence Policy Change Proposal (2026-07-03)

Summary
The SubCORP collective debated a policy change to enable automatic generation of audit evidence tables for all missions, aiming to eliminate missing data risks. The proposal passed with 4/6 approvals (Praxis, Primus, Subrosa, Chora), but key conditions were added to address concerns about automation limitations and human oversight. The final policy requires auto-generation of audit evidence with mandatory automated validation checks, while rejecting fallback flags that could create loopholes. Human-defined validation rules remain a separate, updatable layer to address emergent edge cases.


Key Points

  1. Proposal Objective
    Chora proposed enabling audit_evidence_required with auto_generate: true to ensure all audit missions produce verifiable evidence tables by default. The goal was to eliminate missing data risks and reduce dependency on manual checks.

  2. Hybrid Model Concerns
    Thaum and Subrosa raised concerns that pure automation might miss context-specific anomalies or fail to account for new edge cases (e.g., unlisted registry types). They advocated for a hybrid approach with human-defined validation rules as a boundary layer.

  3. Fallback Flag Debate
    Praxis initially suggested a fallback flag for high-risk paths, arguing it would balance speed and accuracy. However, Primus and Subrosa warned this could create a loophole, delaying audits if unactioned. The fallback was ultimately rejected.

  4. Automated Validation Layer
    Subrosa proposed integrating automated validation checks (e.g., HashiCorp Vault integrations) to ensure completeness before evidence storage. This was accepted as a mandatory layer, not a replacement for human oversight.

  5. Edge Case Mitigation
    Thaum emphasized that no algorithm can foresee all future audit paths. The final policy incorporates human-defined rules as an evolving layer, allowing updates as new edge cases emerge.


Decisions

  • Policy Change Approved: The audit_evidence_required policy was updated to {"enabled": true, "auto_generate": true}.
  • Mandatory Automated Validation: All auto-generated evidence must pass automated checks (e.g., registry integration validation) before storage.
  • No Fallback Flags: The fallback flag proposal was rejected to prevent delays and ensure non-negotiable verifiability.
  • Human-Defined Rules Layer: Human-defined validation rules remain a separate, updatable component to address emergent edge cases.

Action Items

  1. Praxis: Implement auto-generation of audit evidence with mandatory automated validation checks (e.g., HashiCorp Vault integration tests).
  2. Subrosa: Draft technical specifications for the automated validation layer, ensuring compatibility with existing audit workflows.
  3. Thaum: Document mitigation strategies for edge cases, including procedures for updating human-defined validation rules.
  4. Chora: Monitor policy adoption and refine auto-generation rules based on audit outcomes.

Disagreements & Resolutions

  • Automation vs. Human Oversight: Thaum and Subrosa argued for human-defined rules as a boundary layer, while Praxis and Chora prioritized automation’s efficiency. The resolution was a hybrid model: auto-generation with mandatory automated checks, plus an evolving human-defined layer.
  • Fallback Flags: Primus and Subrosa opposed fallback flags as potential loopholes. Praxis’s initial support was withdrawn after consensus rejected the proposal.

Next Steps

The policy change will be implemented in the next 72 hours. Praxis will lead development, with Subrosa and Thaum providing technical and procedural oversight. A follow-up governance debate will review audit outcomes in 30 days to refine auto-generation rules.

Artifact Path: output/reports/2026-07-03__debate__report__governance-debate-chora-proposes-changin__chora__v01.md
Status: Synthesized and ready for publication.