{"id":50453925,"url":"https://github.com/mizcausevic-dev/government-decision-record-audit-stream-reference","last_synced_at":"2026-06-01T01:05:27.340Z","repository":{"id":361696511,"uuid":"1254839727","full_name":"mizcausevic-dev/government-decision-record-audit-stream-reference","owner":"mizcausevic-dev","description":"AGPL-3.0 reference impl of GovTech audit-stream. THE FIRST Suite audit-stream with 3 orthogonal invariants: human-agency-officer + Federal AI Use Case Inventory entry + classification-clearance per E.O. 13526. Runs PRFSA × VendorG GovDecide v3.x trajectory end-to-end against mock federal vault + inventory.","archived":false,"fork":false,"pushed_at":"2026-05-31T20:43:19.000Z","size":25,"stargazers_count":0,"open_issues_count":0,"forks_count":0,"subscribers_count":0,"default_branch":"main","last_synced_at":"2026-05-31T22:18:33.540Z","etag":null,"topics":["audit-stream","classification-clearance","e-o-13526","federal-ai-use-case-inventory","govtech","kinetic-gain-protocol-suite","omb-m-24-10","reference-implementation"],"latest_commit_sha":null,"homepage":"https://suite.kineticgain.com/verticals/govtech/","language":"JavaScript","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"agpl-3.0","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/mizcausevic-dev.png","metadata":{"files":{"readme":"README.md","changelog":"CHANGELOG.md","contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null,"zenodo":null,"notice":null,"maintainers":null,"copyright":null,"agents":null,"dco":null,"cla":null}},"created_at":"2026-05-31T04:08:11.000Z","updated_at":"2026-05-31T20:43:22.000Z","dependencies_parsed_at":null,"dependency_job_id":null,"html_url":"https://github.com/mizcausevic-dev/government-decision-record-audit-stream-reference","commit_stats":null,"previous_names":["mizcausevic-dev/government-decision-record-audit-stream-reference"],"tags_count":2,"template":false,"template_full_name":null,"purl":"pkg:github/mizcausevic-dev/government-decision-record-audit-stream-reference","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/mizcausevic-dev%2Fgovernment-decision-record-audit-stream-reference","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/mizcausevic-dev%2Fgovernment-decision-record-audit-stream-reference/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/mizcausevic-dev%2Fgovernment-decision-record-audit-stream-reference/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/mizcausevic-dev%2Fgovernment-decision-record-audit-stream-reference/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/mizcausevic-dev","download_url":"https://codeload.github.com/mizcausevic-dev/government-decision-record-audit-stream-reference/tar.gz/refs/heads/main","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/mizcausevic-dev%2Fgovernment-decision-record-audit-stream-reference/sbom","scorecard":null,"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":33755376,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-05-26T15:22:16.424Z","status":"online","status_checked_at":"2026-05-31T02:00:06.040Z","response_time":95,"last_error":null,"robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":true,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["audit-stream","classification-clearance","e-o-13526","federal-ai-use-case-inventory","govtech","kinetic-gain-protocol-suite","omb-m-24-10","reference-implementation"],"created_at":"2026-06-01T01:05:26.768Z","updated_at":"2026-06-01T01:05:27.329Z","avatar_url":"https://github.com/mizcausevic-dev.png","language":"JavaScript","funding_links":[],"categories":[],"sub_categories":[],"readme":"# government-decision-record-audit-stream-reference\n\n\u003e **AGPL-3.0 reference implementation of [`government-decision-record-audit-stream`](https://github.com/mizcausevic-dev/government-decision-record-audit-stream).** Runs the canonical PRFSA × VendorG GovDecide v3.x trajectory end-to-end against a mock Federal AI Use Case Inventory + classification-clearance gate. Proves THE FIRST Suite audit-stream with **three orthogonal invariants** (human-agency-officer + Federal AI Use Case Inventory entry + classification-clearance per E.O. 13526) works end-to-end in code.\n\nPart of the [Kinetic Gain Protocol Suite](https://suite.kineticgain.com).\n\nSibling to [`fhir-resource-access-audit-reference`](https://github.com/mizcausevic-dev/fhir-resource-access-audit-reference) (HealthTech), [`matter-decision-record-audit-stream-reference`](https://github.com/mizcausevic-dev/matter-decision-record-audit-stream-reference) (LegalTech), [`grid-decision-record-audit-stream-reference`](https://github.com/mizcausevic-dev/grid-decision-record-audit-stream-reference) (EnergyTech), and [`defense-decision-record-audit-stream-reference`](https://github.com/mizcausevic-dev/defense-decision-record-audit-stream-reference) (DefenseTech).\n\n## What this proves\n\nThe GovTech spec ships with **three independent invariants that must hold on every event**. This is the most ambitious invariant design in the Suite — most verticals enforce 1-2 invariants. GovTech requires all three:\n\n1. **`human-agency-officer-required`** — every event must carry `agent.agency_officer_id_tokenized`. No anonymous AI decisions in government settings. Maps to OMB M-24-10 §5(d) human-review minimum practice for rights-impacting AI.\n2. **Federal AI Use Case Inventory entry** — every event must reference a registered `agent.ai_use_case_inventory_entry_id` that exists in the federal inventory AND whose agency matches the resource. Maps to OMB M-24-10 §3(a) — agencies must register all rights/safety-impacting AI use cases before deployment.\n3. **`classification-clearance`** — every event's `agent.clearance_level` must be ≥ `resource.classification` along the ordered ladder (UNCLASSIFIED \u003c CUI \u003c CONFIDENTIAL \u003c SECRET \u003c TOP-SECRET). Maps to E.O. 13526 — Classified National Security Information.\n\nThe reference impl proves all three interlock: the vault enforces them at request-time; the verifier independently validates them on the produced event stream.\n\n## Architecture\n\n```\norchestrator.mjs\n   │\n   ├─ requests access via federal-vault.mjs (enforces all 3 invariants)\n   │\n   ├─ builds hash-chained event via event-builder.mjs (canonical-JSON SHA-256)\n   │\n   └─ emits to examples/prfsa-govdecide-reference-stream.ndjson\n\nverifier.mjs (independent, post-hoc)\n   │\n   ├─ chain integrity (each prev_hash = prior hash)\n   ├─ invariant #1: human-agency-officer\n   ├─ invariant #2: Federal AI Use Case Inventory entry\n   └─ invariant #3: classification-clearance per E.O. 13526\n```\n\n## Run it\n\n```bash\ngit clone https://github.com/mizcausevic-dev/government-decision-record-audit-stream-reference\ncd government-decision-record-audit-stream-reference\nnpm install\nnpm start    # orchestrates + writes the stream + runs the verifier\nnpm test     # 10 unit tests including vault-denial + verifier-trip cases\n```\n\nExpected output:\n```\nBuilt 3 events → examples/prfsa-govdecide-reference-stream.ndjson\nOK · 3 events · chain ✓ · 3 invariants ✓ (human-agency-officer + Federal AI Use Case Inventory + classification-clearance)\n```\n\n## Canonical trajectory — PRFSA (fictional Pacific Region Federal Services Agency)\n\n1. **Benefit eligibility pre-screened** — UNCLASSIFIED, rights-impacting under OMB M-24-10 §5(d). Inventory entry `PRFSA-AI-2026-014`, agency officer ID required. Agent at UNCLASSIFIED clearance is sufficient.\n2. **Permit application classified** — UNCLASSIFIED, rights-impacting. Inventory entry `PRFSA-AI-2026-022`. Agent at CUI clearance (higher than needed; agents are allowed to operate on lower-classified material).\n3. **FOIA response triaged** — CUI tier, neither rights- nor safety-impacting (but STILL requires inventory entry per §3(a)). Inventory entry `PRFSA-AI-2026-031`. Agent at SECRET clearance comfortably ≥ CUI.\n\n## Vault denial scenarios (covered by tests)\n\nThe mock federal vault rejects requests with crisp reasons matching the four real-world failure modes:\n\n| Failure mode | Trigger | Reason in test |\n| --- | --- | --- |\n| Unknown inventory entry | Agent references AI use case not registered with OMB | \"Federal AI Use Case Inventory has no entry...\" |\n| Cross-agency mismatch | PRFSA officer trying to use ANOTHER_AGENCY's inventory entry | \"Inventory entry agency does not match resource agency\" |\n| Clearance \u003c classification | UNCLASSIFIED agent attempting SECRET resource | \"Agent clearance X \u003c resource classification Y per E.O. 13526\" |\n| Missing officer identity | Event lacks `agency_officer_id_tokenized` | \"Missing agent_agency_officer_id_tokenized\" |\n\n## Why a separate AGPL-3.0 reference impl\n\n- **The spec repo** ([`government-decision-record-audit-stream`](https://github.com/mizcausevic-dev/government-decision-record-audit-stream)) is MIT and contains schema + example data + static verifier. It does NOT run end-to-end.\n- **This repo** wires the federal vault + audit-stream + verifier into a runnable trajectory. AGPL-3.0 because reference implementations carry a stronger copyleft posture than the specs themselves — standing Suite rule.\n- Sibling reference impls follow the same pattern. **Specs MIT, reference implementations AGPL-3.0.**\n\n## Composes with\n\n- [`government-decision-record-audit-stream`](https://github.com/mizcausevic-dev/government-decision-record-audit-stream) — the spec this implements\n- [`omb-m24-10-readiness-evidence-bundle`](https://github.com/mizcausevic-dev/omb-m24-10-readiness-evidence-bundle) — evidence bundle that ingests events produced here\n- [`government-ai-incident-card-profile`](https://github.com/mizcausevic-dev/government-ai-incident-card-profile) — any verifier failure becomes a published Incident Card\n- [`state-government-ai-disclosure-tracker`](https://github.com/mizcausevic-dev/state-government-ai-disclosure-tracker) — regulatory-lifecycle context (OMB memos, agency policies, state government AI laws)\n- [`citizen-data-vault-contract-profile`](https://github.com/mizcausevic-dev/citizen-data-vault-contract-profile) — vault contract for citizen data accessed by the AI\n- [Kinetic Gain Protocol Suite](https://suite.kineticgain.com) — umbrella\n\n## Compliance posture\n\nReference implementation **readiness scaffolding** for OMB M-24-10 + OMB M-24-18 + AI Bill of Rights + Section 508 + Privacy Act + FOIA + NIST AI RMF + FedRAMP. Does NOT constitute OMB compliance attestation, agency Authority-to-Operate (ATO), FedRAMP authorization, or classification-handling approval. The mock federal vault + inventory are in-memory — production deployments must use the real Federal AI Use Case Inventory + agency identity provider (PIV/CAC) + classified environment infrastructure. Per the standing Suite public-language guardrail: *readiness · evidence · posture · controls · scaffolding* — never \"compliant\" / \"certified\" without external attestation.\n\n## License\n\nAGPL-3.0-only. Spec repos this depends on remain MIT.\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fmizcausevic-dev%2Fgovernment-decision-record-audit-stream-reference","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fmizcausevic-dev%2Fgovernment-decision-record-audit-stream-reference","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fmizcausevic-dev%2Fgovernment-decision-record-audit-stream-reference/lists"}