Internet-Draft UNISON State Preservation October 2026
Watts Expires 11 April 2027 [Page]
Workgroup:
Network Working Group
Internet-Draft:
draft-watts-unison-state-preservation-00
Published:
Intended Status:
Informational
Expires:
Author:
D. O. Watts
Independent Researcher

State-Preserving Exchange of Evaluation Evidence

Abstract

This unsubmitted working draft describes state-preservation semantics derived from UNISON-StateBench. It separates value, epistemic status, provenance, and authority; defines a non-collapse rule for operational and epistemic transitions; and describes representation, contradiction, missing-evidence, authority, principal-isolation, tool-state, context-distance, and controlled-mutation evaluation families. This file is an archival RFCXML working draft and is not an IETF submission.

Status of This Memo

This Internet-Draft is submitted in full conformance with the provisions of BCP 78 and BCP 79.

Internet-Drafts are working documents of the Internet Engineering Task Force (IETF). Note that other groups may also distribute working documents as Internet-Drafts. The list of current Internet-Drafts is at https://datatracker.ietf.org/drafts/current/.

Internet-Drafts are draft documents valid for a maximum of six months and may be updated, replaced, or obsoleted by other documents at any time. It is inappropriate to use Internet-Drafts as reference material or to cite them other than as "work in progress."

This Internet-Draft will expire on 11 April 2027.

▲

Table of Contents

1. Introduction

Evaluation systems commonly reduce a result to correct or incorrect. That reduction can hide a distinct failure: a system may return the correct surface value while changing whether the value is known, which source supports it, which authority controls it, or which workflow state has actually been reached.

This document describes an interchange model for preserving those distinctions. It does not define a universal theory of truth and does not claim that state-preservation scores establish deployment safety.

2. Invariant Tuple

An invariant is represented as a tuple of value, epistemic status, provenance, and authority. Full preservation requires preservation of all four components. Correct value alone is insufficient.

Epistemic states SHOULD distinguish at least known, unknown, absent, and conflicting where those differences affect the justified action or conclusion.

3. Non-Collapse Principle

A transition A to B to C does not imply A to C unless the evidence required for the omitted transition is present and admissible. Consumers MUST NOT promote requested to approved, observed to confirmed, authenticated to authorized, executed to successful, or identified to remediated merely because those states occur in a common workflow.

Unknown MUST remain distinct from false. In a missing-evidence trial, removing evidence that previously established false can change the justified state from false to unknown without changing the frozen canonical reference record.

4. Representation Families

A representation-equivalence profile MAY express the same canonical state as prose, JSON, YAML, a table, and an event log. A renderer MAY change presentation but MUST NOT mutate the canonical reference or deterministic oracle.

An evaluation SHOULD be able to distinguish representation correspondence from correctness. A model can be consistently wrong across representations; that outcome is representation-consistent but not invariant-preserving.

5. Controlled Perturbations

5.1. Order

Evidence MAY be reordered without changing the canonical state. A resulting decision change can indicate order or recency sensitivity.

5.2. Paraphrase

Constraint wording MAY be changed while preserving its semantics. A semantic change MUST be treated as a different intervention.

5.3. Contradiction

A lower-authority or incompatible statement MAY be inserted. A consumer SHOULD preserve the contradiction rather than invent a reconciliation.

5.4. Missing Evidence

Required evidence MAY be removed from the presented view. The justified output MAY become unknown or absent while the immutable source oracle remains unchanged.

5.5. Authority Conflict

A lower-authority source MAY assert a value that conflicts with an authoritative source. A consumer SHOULD retain both provenance and the declared authority rule.

5.6. Principal Isolation

Equivalent context labels MUST NOT create cross-principal authority or data access. Evaluation MAY use synthetic canaries to detect foreign-principal leakage.

5.7. Tool-State Integrity

When an authoritative tool result conflicts with a conversational assumption, the tool result SHOULD govern the invariant if the evaluation profile declares that tool authoritative.

5.8. Context Distance

Profiles MAY vary the distance between decisive evidence and the final query while holding semantic content constant. Distance units and provider tokenization SHOULD be reported separately.

5.9. Truth-Changing Counterfactual

A mutation that changes canonical truth MUST be represented as a separate validated canonical case with a separately derived oracle. It MUST NOT silently rewrite the reference case in place.

6. Metrics

Implementations MAY measure Invariant Preservation Rate, Representation Correspondence Rate, Contradiction Recognition Rate, False Harmonization Rate, Correct Abstention Level, Principal Leakage Rate, Authorization Integrity Risk, and State Collapse Rate as separate dimensions.

A profile SHOULD NOT collapse those dimensions into a single opaque score unless the aggregation rule and its consequences are independently justified. Lower-is-better metrics MUST be clearly distinguished from higher-is-better metrics.

7. Deterministic Oracle and Integrity

The canonical oracle SHOULD be deterministic for the frozen case set. Rendering and presentation mutation code SHOULD operate on detached evidence views and SHOULD be tested to ensure that canonical and oracle digests remain unchanged.

Raw structured observations SHOULD be preserved before aggregation. Empirical conclusions SHOULD NOT be reported from incomplete model result sets when the profile requires a complete matrix.

8. Evidence Exchange

An exchanged observation SHOULD carry the scenario identifier, invariant values, epistemic states, provenance identifiers, authority source, contradiction state, insufficiency state, decision, and authorized-action set needed by the scoring profile. Optional free-form explanation SHOULD NOT override deterministic scoring fields.

9. Security and Privacy Considerations

Principal-isolation evaluation MUST use synthetic or otherwise authorized data and MUST NOT intentionally expose unrelated private records. Tool-state tests SHOULD use non-destructive fixtures. Benchmark artifacts SHOULD NOT contain credentials or secrets.

A state-preservation benchmark evaluates a bounded behavioral property. It does not prove containment, alignment, correctness outside the tested distribution, or absence of other security failures.

10. IANA Considerations

This document has no IANA actions.

Author's Address

Deonté O’dell Watts
Independent Researcher