Warden plan
tier: hermetic requires: []
Pending stub — GATED criterion. The precondition below is not built; this plan reports the criterion as pending (skip, never fail) until it lands. When it does, replace this stub with a real plan in the shape of
25-cr-18/26-cr-25/27-cr-20.
Register: ~/.studio/master.withrobin.ai/project/rfc.one/criteria-register.md (status there: PENDING OWNER ACCEPTANCE; accepted by the 2026-08-31 proxy screen).
### CR-07 — Retraction minimal-change check - Statement: Withdrawing Entries retracts exactly the Claims whose every justification depended on them, and restoring the Entries returns exactly those Claims to proposed. - Metric: Set equality in both directions (no extra retractions; exact restoration to proposed, never auto-accepted). - Dataset/inputs: Withdraw the Entries behind 20 accepted Claims per arm; restore them. - Threshold: Exact in both directions (construction guarantee). - Drop condition: None stated; a miss is a defect in the dependency network. - Source: Anchor §10.3. - Tier: gated — requires Claims layer and justification network.
Precondition: requires the Claims layer and the justification network. Not built at HEAD 7f379974 (verified 2026-08-31: no 'claims', 'dimensions', or 'initiatives' tables in server/src/db/schema.ts, and no conflicts_with edges anywhere in server/src or packages/). The justification network has no code marker to probe beyond the tables themselves.
set -uo pipefail
source "$WARDEN_LIB/assert.sh"
cd "${PROJECT_ROOT:-$(git rev-parse --show-toplevel)}"
SCHEMA=server/src/db/schema.ts
MISSING=""
grep -q "'claims'" "$SCHEMA" || MISSING="$MISSING claims-tables"
if [ -n "$MISSING" ]; then
warden_skip "CR-07 — Retraction minimal-change check" "pending: requires the Claims layer and the justification network — gated criterion, precondition not built (probes missing:$MISSING)"
else
warden_skip "CR-07 — Retraction minimal-change check" "schema probes now pass — upgrade this pending stub to a real plan before CR-07 can bind (probes are heuristic, not proof)"
fi
Pending stub, hermetic on purpose: the guard reads the checkout only and emits skip in every branch, so this plan can never red a run — the criterion surfaces in every summary as pending with its precondition named. The probes are heuristic activation bells, not proof: quoted table names (and conflicts_with where the contradiction check is a precondition) flip the detail text when the machinery lands. The real plan must quote the criterion verbatim, turn its thresholds into warden_pass/warden_fail gates, and follow the conventions the three runnable plans set: machine-local fixtures (25-cr-18), NLI probe and versioned judge prompts (26-cr-25), data-keyed guard activation (27-cr-20).