KB-4BC4 rev 2

Codex FIX7 Control-Plane Immutability Design Plan - Corrected

1 min read Revision 2
QT001FIX7readmecorrectedzero-hardcode

Codex FIX7 Control-Plane Immutability Design Plan - Corrected

Design-only, no live mutation. Policy is never embedded as tier/gate/capability-specific CASE logic. Generic PG interpreters execute sealed typed policy rows; fact adapters return typed facts only. Manifest activation requires independently signed exact quorum and makes readiness fail until fresh evidence binds the new set.

Zero-hardcode boundary: business/control policy, required sets, principal classes, tier/reviewer requirements, hash components, measurements, thresholds, entrypoints, bypass vectors, and dependency roots are versioned SHA-256 exact-set manifest rows. Infrastructure bootstrap constants are allowed only inside the sealed bootstrap manifest/control-state hash.

Stage 2.6B remains blocked.

Back to Knowledge Hub knowledge/dev/reports/architecture/codex-fix7-control-plane-immutability-design-plan-2026-06-07/00-readme-first.md