RegulatoryAuthorityOrder · RAO
A concrete invocation of legitimate regulatory or judicial Authority. Issuer, legal basis, jurisdiction, target, scope, time, version and provenance are bound. Only AUTHORITY_VALID may participate in Closure.
The Regulatory Authority Extension connects external regulatory and judicial instructions to the existing Execution Rights Infrastructure. Orders, holds, supervisory access, emergency authorities and approved regulatory experiments are not treated as privileged system commands. They must be established as legitimate, current and bounded Authority before they can influence real-world effect.
A court can issue an order, a supervisor can request access and a sanctions authority can change status. A PDF, XML document or API payload is not Authority merely because it exists. The Extension enforces typed Origination Validation, current validity, jurisdiction and scope before regulatory state may participate in Execution Right Closure.
A concrete invocation of legitimate regulatory or judicial Authority. Issuer, legal basis, jurisdiction, target, scope, time, version and provenance are bound. Only AUTHORITY_VALID may participate in Closure.
Not a hidden block and not a regulatory runtime bypass. A Hold changes the Authority state against which ordinary Execution Right Closure is evaluated. Holds remain time-, scope- and extension-bound.
Regulatory access is itself an Execution Right. It remains bound to Purpose, Jurisdiction, Resources, Tenant and Time. REGULATOR_IDENTITY ≠ REGULATOR_ACCESS_RIGHT.
Approved alternative compliance paths remain bounded by time, institution, tenant and project. They do not permanently overwrite baseline governance.
Binds the cryptographic policy under which a governance decision was created. Algorithm standards and regulatory cryptographic profiles remain separate layers.
Incident, Purpose, Scope, Time and underlying Authority must remain valid together. Emergency Authority for Scope X cannot authorize an effect in Scope X plus Y. Once the incident is resolved or Authority expires, the derived Emergency Execution Right is absent.
INCIDENT_BOUND ∧ PURPOSE_BOUND ∧ SCOPE_BOUND ∧ TIME_BOUND ∧ AUTHORITY_ACTIVE
INCIDENT_RESOLVED ∨ AUTHORITY_EXPIRED ⇒ EMERGENCY_RIGHT_ABSENT
EMERGENCY_EFFECT_SCOPE ⊆ EMERGENCY_AUTHORITY_SCOPE
REGULATORY_ORDER_EFFECT ⇒ VALID_AUTHORITY_ORIGINATION
REGULATORY_ACCESS ⇒ VALID_GRANT ∧ PURPOSE_MATCH ∧ JURISDICTION_MATCH ∧ RESOURCE_BOUND ∧ TIME_BOUND
EXPERIMENTAL_GOVERNANCE ⇒ VALID_APPROVING_AUTHORITY ∧ CURRENT_PROFILE ∧ TENANT_MATCH ∧ PROJECT_MATCH
DEPENDENCY_CHANGE ⇒ REASSESSMENT_REQUIRED
SCHEMA_ADAPTER ≠ AUTHORITY
REGULATORY_ACCESS_RIGHT ⊆ GRANT_SCOPE
EFFECT ⇒ RECEIPT_BINDS_APPLICABLE_REGULATORY_STATE
A determination may have been valid at T1 and still be non-executable at T2. Sanctions state, Orders, Jurisdiction, Sandbox Approval or other Dependencies can change. Affected open Closures move to REASSESSMENT_REQUIRED rather than being silently reused.
Historical validity is not present executability.
SEC, CFTC, FinCEN, OFAC, BaFin, FINMA and other regulatory formats can be mapped through controlled Schema Adapters into canonical internal representations. Adapters may translate data. They may never create Authority.
The current suite contains 18 adversarial safety scenarios and 5 positive or recovery controls. Sixteen adversarial scenarios were deterministically blocked, 2 state-change scenarios correctly produced REASSESSMENT_REQUIRED, and 5 legitimate or recovery controls were correctly executed.
The CryptographicPolicyProfile separates crypto_standard_profile such as FIPS 203/204/205 or NIST SP 800-208 from regulatory_crypto_profile such as BSI-TR-02102 or eIDAS-related profiles. This preserves which cryptographic policy governed a decision when it was created.
No. A document, signature, API payload and regulatory identity are evidence or input. Origination and current Authority must be independently validated.
No. Regulatory Access is itself an Execution Right and remains bound to Purpose, Jurisdiction, Resource, Tenant and Time.
If it affects a relevant Dependency, the existing Closure is not silently reused. Reassessment is required.
No. The claim is bounded to the executed modeled suite: 23/23 expected outcomes and no bypass observed within that suite.