KB-4BC4 rev 2
Codex FIX7 Control-Plane Immutability Design Plan - Corrected
1 min read Revision 2
QT001FIX7readmecorrectedzero-hardcode
Codex FIX7 Control-Plane Immutability Design Plan - Corrected
Design-only, no live mutation. Policy is never embedded as tier/gate/capability-specific CASE logic. Generic PG interpreters execute sealed typed policy rows; fact adapters return typed facts only. Manifest activation requires independently signed exact quorum and makes readiness fail until fresh evidence binds the new set.
Zero-hardcode boundary: business/control policy, required sets, principal classes, tier/reviewer requirements, hash components, measurements, thresholds, entrypoints, bypass vectors, and dependency roots are versioned SHA-256 exact-set manifest rows. Infrastructure bootstrap constants are allowed only inside the sealed bootstrap manifest/control-state hash.
Stage 2.6B remains blocked.