failure family
provenance and audit integrity
- Custody Without Account: A user who holds every byte locally and composes many services into a workflow has perfect custody and no answer to the question of what happened.
- Attribution Failure Dissolves Responsibility: Attribution failure dissolves responsibility into composition: where contribution cannot be traced, fault cannot be assigned, and no participant has a
- Unjoinable Audit Records: Chronicle entries at commit 2d920ce carry exactly five fields with no workflow identifier, parent-entry reference, principal identity, or correlation
- Uninstrumented Execution Path: At commit 2d920ce the built-in Gmail, Web3, and Vault modules and third-party MCP servers execute through the tool registry with no Chronicle instrume
- Unlogged Autonomous Payment: At commit 2d920ce the payment plugin moves real value autonomously while writing nothing into any Chronicle, so end-to-end provenance is not merely un
- Append-Only Without Tamper Evidence: The Chronicle at commit 2d920ce is append-only structurally but not tamper-evident: any process with filesystem access can rewrite or truncate history
- Silent Truncation Reports Clean History: Chronicle.read at commit 2d920ce skips malformed lines and silently truncates to a default limit, so the audit log reports a clean history in exactly