import type { AssuranceRecord, GateProvenance, Summary } from '@manehorizons/cadence-types'; /** * Phase 233 (T2): the per-AC result shape `deriveAssuranceRecord` consumes — * pinned to `Summary['acResults'][number]` (rather than a hand-rolled * subset) so this file breaks loudly at typecheck if `SummaryZ.acResults` * ever changes shape, instead of silently drifting from it. */ export type AssuranceAcResult = Summary['acResults'][number]; /** * Phase 233 (T2): derive one whole-run `AssuranceRecord` from a settle's * per-gate provenance array and per-AC evidence array — "how strongly was * this settle actually verified?", composed rather than gated. * * Pure function of its two arguments only — no I/O, no clock, no gate-name * special-casing (the AC-3 tripwire this task exists to test). Every gate * entry is treated uniformly by its `provider`/`model` fields alone: this * function never inspects `gate.gate`. Gates that carry no verifier * identity (everything except `code-review`/`security-audit` as of phase * 232) simply contribute nothing to `verifierRollup` — that is a property * of the input data, not a branch in this code. * * `overall` derivation rule (deterministic, documented here since the exact * thresholds are this function's own design call, per the phase-233 spec): * - `'unverified'`: no gate entry anywhere carried verifier identity AND * every AC's evidence class is `'unverified'` (nothing stronger, not * even `'mention'`, was ever recorded). Matches the `AssuranceRecordZ` * schema comment verbatim. * - `'strong'`: at least one gate entry carried a *real* (non-`'mock'`) * provider AND at least half of all ACs landed at `'ai-verified'` or * `'executed'` (the two strongest evidence classes). Mock-only * verification never earns `'strong'`, matching the phase-140/213 * mock-honesty precedent (a mock verdict is a placeholder, not * verification). * - `'mixed'`: some real verifier signal or some non-zero strong-evidence * ratio was present, but not enough to clear the `'strong'` bar. * - `'weak'`: everything else — e.g. mock-only (or no) verifier identity * with zero ACs at `'ai-verified'`/`'executed'`, but at least one AC * above bare `'unverified'` (otherwise it would already be * `'unverified'` above), or simply no ACs at all with no verifier * signal either. */ export declare function deriveAssuranceRecord(gates: readonly GateProvenance[], acResults: readonly AssuranceAcResult[]): AssuranceRecord; //# sourceMappingURL=assurance-record.d.ts.map