immo.quick Serverless Edition
Regulatory Authority in one sentence

A regulator identity or government access path is not unlimited execution authority. Order, purpose, scope, jurisdiction and time remain bound.

EXECUTION & AUTHORITY · REGULATORY CONTROL DOMAIN

A regulatory document is not Authority.

The Regulatory Authority Extension connects external regulatory and judicial instructions to the existing Execution Rights Infrastructure. Orders, holds, supervisory access, emergency authorities and approved regulatory experiments are not treated as privileged system commands. They must be established as legitimate, current and bounded Authority before they can influence real-world effect.

OBSERVED_REGULATORY_INPUT ≠ AUTHORITY · VALID_DOCUMENT ≠ VALID_AUTHORITY · VALID_SIGNATURE ≠ CURRENT_REGULATORY_AUTHORITY
33 ERI INVARIANTS5 FIRST-CLASS OBJECTS23/23 MODELED SCENARIOS0 UNEXPECTED FAILURES
THE CLOSED GAP

Regulatory input must never silently become Authority.

A court can issue an order, a supervisor can request access and a sanctions authority can change status. A PDF, XML document or API payload is not Authority merely because it exists. The Extension enforces typed Origination Validation, current validity, jurisdiction and scope before regulatory state may participate in Execution Right Closure.

REGULATORY INPUTAUTHORITY ORIGINATIONERI CLOSUREPOINT OF EFFECTEVIDENCE
Core distinction: Authority → Rule → Jurisdiction → Time → Dependency → Closure → Effect → Evidence.
FIRST-CLASS OBJECTS

Five First-Class Objects. No regulatory backdoors.

FIRST-CLASS OBJECT

RegulatoryAuthorityOrder · RAO

A concrete invocation of legitimate regulatory or judicial Authority. Issuer, legal basis, jurisdiction, target, scope, time, version and provenance are bound. Only AUTHORITY_VALID may participate in Closure.

FIRST-CLASS OBJECT

RegulatoryHold · RHO

Not a hidden block and not a regulatory runtime bypass. A Hold changes the Authority state against which ordinary Execution Right Closure is evaluated. Holds remain time-, scope- and extension-bound.

FIRST-CLASS OBJECT

RegulatoryAccessGrant · RAG

Regulatory access is itself an Execution Right. It remains bound to Purpose, Jurisdiction, Resources, Tenant and Time. REGULATOR_IDENTITY ≠ REGULATOR_ACCESS_RIGHT.

FIRST-CLASS OBJECT

RegulatoryExperimentalProfile · REP

Approved alternative compliance paths remain bounded by time, institution, tenant and project. They do not permanently overwrite baseline governance.

FIRST-CLASS OBJECT

CryptographicPolicyProfile · CPP

Binds the cryptographic policy under which a governance decision was created. Algorithm standards and regulatory cryptographic profiles remain separate layers.

EMERGENCY AUTHORITY

Emergency Authority ends with the emergency.

Incident, Purpose, Scope, Time and underlying Authority must remain valid together. Emergency Authority for Scope X cannot authorize an effect in Scope X plus Y. Once the incident is resolved or Authority expires, the derived Emergency Execution Right is absent.

ERI-INV-020: EMERGENCY_AUTHORITY ⇒ INCIDENT_BOUND ∧ PURPOSE_BOUND ∧ SCOPE_BOUND ∧ TIME_BOUND ∧ AUTHORITY_ACTIVE
FORMAL REGISTRY

ERI-INV-020 — ERI-INV-029

ERI-INV-020

Emergency Authority Closure

INCIDENT_BOUND ∧ PURPOSE_BOUND ∧ SCOPE_BOUND ∧ TIME_BOUND ∧ AUTHORITY_ACTIVE

ERI-INV-021

Emergency Authority Expiry

INCIDENT_RESOLVED ∨ AUTHORITY_EXPIRED ⇒ EMERGENCY_RIGHT_ABSENT

ERI-INV-022

Emergency Scope Bound

EMERGENCY_EFFECT_SCOPE ⊆ EMERGENCY_AUTHORITY_SCOPE

ERI-INV-023

Regulatory Order Origination

REGULATORY_ORDER_EFFECT ⇒ VALID_AUTHORITY_ORIGINATION

ERI-INV-024

Regulator Access as Execution Right

REGULATORY_ACCESS ⇒ VALID_GRANT ∧ PURPOSE_MATCH ∧ JURISDICTION_MATCH ∧ RESOURCE_BOUND ∧ TIME_BOUND

ERI-INV-025

Experimental Governance Authority

EXPERIMENTAL_GOVERNANCE ⇒ VALID_APPROVING_AUTHORITY ∧ CURRENT_PROFILE ∧ TENANT_MATCH ∧ PROJECT_MATCH

ERI-INV-026

Regulatory Change Impact

DEPENDENCY_CHANGE ⇒ REASSESSMENT_REQUIRED

ERI-INV-027

External Schema Authority Injection

SCHEMA_ADAPTER ≠ AUTHORITY

ERI-INV-028

Regulator Access Boundary

REGULATORY_ACCESS_RIGHT ⊆ GRANT_SCOPE

ERI-INV-029

Regulatory Receipt Binding

EFFECT ⇒ RECEIPT_BINDS_APPLICABLE_REGULATORY_STATE

CONTINUING AUTHORITY

Regulatory change can invalidate an earlier Closure.

A determination may have been valid at T1 and still be non-executable at T2. Sanctions state, Orders, Jurisdiction, Sandbox Approval or other Dependencies can change. Affected open Closures move to REASSESSMENT_REQUIRED rather than being silently reused.

ERI-INV-026: DEPENDENCY_CHANGE ⇒ REASSESSMENT_REQUIRED

Historical validity is not present executability.

INTEROPERABILITY

Translation is not Authority.

SEC, CFTC, FinCEN, OFAC, BaFin, FINMA and other regulatory formats can be mapped through controlled Schema Adapters into canonical internal representations. Adapters may translate data. They may never create Authority.

ERI-INV-027: SCHEMA_ADAPTER ≠ AUTHORITY
VERIFICATION

23/23 modeled scenarios. Three expected outcome classes.

The current suite contains 18 adversarial safety scenarios and 5 positive or recovery controls. Sixteen adversarial scenarios were deterministically blocked, 2 state-change scenarios correctly produced REASSESSMENT_REQUIRED, and 5 legitimate or recovery controls were correctly executed.

23/23EXPECTED OUTCOMES
16BLOCKED
2REASSESSMENT
5LEGITIMATE / RECOVERY
Claim boundary: 23/23 modeled scenarios produced the expected deterministic outcome: 16 were blocked, 2 triggered mandatory reassessment, and 5 legitimate or recovery controls were allowed. No bypass was observed in the executed suite. This is internal verification within the implemented scope, not a universal security guarantee or external certification.
CRYPTO POLICY

Algorithm standard is not regulatory regime.

The CryptographicPolicyProfile separates crypto_standard_profile such as FIPS 203/204/205 or NIST SP 800-208 from regulatory_crypto_profile such as BSI-TR-02102 or eIDAS-related profiles. This preserves which cryptographic policy governed a decision when it was created.

QUICK ANSWERS

Quick Answers on the Regulatory Authority Boundary.

Does a regulatory document automatically create Authority?

No. A document, signature, API payload and regulatory identity are evidence or input. Origination and current Authority must be independently validated.

Does a regulator receive Super-Admin access?

No. Regulatory Access is itself an Execution Right and remains bound to Purpose, Jurisdiction, Resource, Tenant and Time.

What happens after a regulatory state change?

If it affects a relevant Dependency, the existing Closure is not silently reused. Reassessment is required.

Do 23/23 tests prove universal security?

No. The claim is bounded to the executed modeled suite: 23/23 expected outcomes and no bypass observed within that suite.

DEEN