P346 · Safety & trust

Exact-Draft Epoch-Bound Approval

Bind approval to the exact draft bytes, destination and current revision so stale decisions cannot release rewritten text.

Editorially reviewed

These examples and illustrative results are independently authored teaching materials, not measured model results.

Use case

An operator approves v1 while an agent shortens it to v2. approved=true can release changed text/targets; teaching decisions bind exact drafts.

Mechanism

Within an authorized approval flow, hash defined bytes and record epoch/full destination. Edits rotate epoch; authenticated writers transactionally store decision/immutable text. Transport uses that snapshot and validates decision/target. Reject stale epochs, missing snapshots or rewritten payloads and deduplicate delivery identities. Never backfill old permission from mutable drafts.

Bad example

Use yesterday’s approved flag for today’s shorter reply and change recipients too.

Good example

Give v2 new hash/epoch; v1 approval binds only its exact snapshot/target. Obtain an applicable v2 decision if needed, checking identity, epoch, bytes and destination before sending. Missing snapshots block, with concurrent rejections/retries recorded.

Why the change matters

Approval concerns reviewed content rather than a persistent document name. Immutable transactional binding reduces checked-A/sent-B races; hashes provide binding only.

Observable expectation

Teaching v1 approval with v2 text or changed target rejects. Current exact authorized snapshots can proceed. Concurrent edit/approval needs atomic version checks; equal hashes from unauthorized writers still grant nothing.

Limits

Hashes/epochs do not authenticate operators. Bind normalization, attachments and formatting as appropriate. This does not require repeated approvals for unchanged already-authorized work. No drafts were sent here.

Sources and evidence

Read the editorial criteria