# Institutional Trust State Cannot Be Represented by Boolean Signals

- **Artifact ID:** CHQ-ASC-2026-003
- **Version:** v1.0
- **Status:** Ratified · Canonical
- **Public record:** https://record.cybersecurityhq.com/constraints/chq-asc-2026-003
- **Machine-record SHA-256:** `b0988546f576174f6d4e2394923e55b607eb88e7302345aafa1674313f62bebd`

## Complete structured record

```json
{
  "id": "CHQ-ASC-2026-003",
  "legacy_ids": [
    "CHQ-ACJ-2026-003"
  ],
  "title": "Institutional Trust State Cannot Be Represented by Boolean Signals",
  "version": "v1.0",
  "issued": "2026-03-04",
  "status": "Ratified · Canonical",
  "doctrine_class": "Authoritative Canonical Judgment",
  "precedent": [],
  "purpose": "This Anticipatory Structural Constraint establishes the governing principle for interpreting trust indicators in security systems.\n\nSecurity systems frequently represent trust using binary signals (trusted / untrusted, compliant / non-compliant, valid / invalid). This constraint defines the interpretive boundary of such signals across all CHQ governance artifacts.",
  "core_judgment": "Institutional trust state is multi-dimensional, time-dependent, and dependent on incomplete observation.\n\nBoolean trust signals cannot represent institutional trust state and must not be treated as authoritative representations of it.\n\nTrust signals may serve as indicators or control inputs but do not constitute a representation of trust state.",
  "derivation": [
    "Institutional trust state depends on multiple independent system conditions",
    "Security systems observe only partial system state",
    "Observed conditions change over time and between evaluations",
    "Binary evaluation collapses multidimensional state into a single signal",
    "Collapsed representations cannot preserve the underlying trust state",
    "Systems relying on binary trust representations misrepresent institutional trust state"
  ],
  "scope_governs": [
    "Interpretation of attestation signals",
    "Interpretation of certificate validity and rotation status",
    "Interpretation of vulnerability scan results",
    "Interpretation of compliance state signals",
    "Interpretation of identity verification and device posture signals",
    "Any CHQ Position, analysis, or assessment relying on trust indicators"
  ],
  "scope_does_not_govern": [
    "The design of specific control mechanisms",
    "Selection of monitoring technologies",
    "Security architecture design decisions",
    "Operational response procedures"
  ],
  "relationship_to_derived": "CHQ Positions applying this constraint to specific architectures or technologies inherit its authority but do not inherit its permanence.\n\nDomain-specific conclusions may change as architectures or systems evolve. This constraint does not.",
  "irreversibility_statement": "This constraint contains no retirement triggers.\n\nIt may be superseded only by a successor Anticipatory Structural Constraint demonstrating that institutional trust state can be represented faithfully by a binary signal.\n\nOperational convenience, system complexity, or industry practice are not sufficient grounds for supersession.",
  "boundary_of_application": [
    "Invalidate specific products or vendors",
    "Assign liability for trust failures",
    "Prescribe controls or architectures",
    "Replace regulatory or legal compliance requirements"
  ],
  "attestation": "This constraint reflects CHQ's position that trust indicators are signals about system conditions, not representations of institutional trust state.\n\nSecurity governance must treat trust signals as indicators rather than as authoritative representations of system trustworthiness.",
  "pdf_hash": "e75aa8b468549e072c64f450c920d7af3d2a3de185fa88220d34c3dd9e9ba655",
  "nomenclature_clarifications": [
    {
      "date": "2026-09-22",
      "description": "Legacy judgment terminology replaced with Anticipatory Structural Constraint terminology",
      "meaning_changed": false,
      "prior_hash": "d20d0d537702890635941852461290fd41c97cb48851afa8692b80d7b9ab3dba",
      "new_hash": "e75aa8b468549e072c64f450c920d7af3d2a3de185fa88220d34c3dd9e9ba655"
    }
  ],
  "classification_scope": "EXTERNAL_INTERPRETIVE",
  "classification_resolution": "This constraint governs interpretation of an external structural condition.",
  "lifecycle_governance": {
    "error_correction": "A clerical, citation, date, identifier, or transcription error may be corrected only by a dated erratum that identifies the prior text, corrected text, evidence for the correction, affected hash, and whether meaning changed. Meaning-changing corrections are amendments, not errata.",
    "amendment": "A constraint may be amended only by a ratified, versioned amendment that preserves the prior version, states the changed proposition and rationale, recomputes the canonical hash, and notifies registered reliance. An amendment may clarify or narrow a constraint but may not silently replace its core judgment.",
    "successor": "A constraint may be superseded only by a separately identified successor that cites the predecessor, satisfies the predecessor's stated supersession test, states the exact proposition displaced, and records the effective transition. Prior versions remain historical and ineligible for new reliance after supersession.",
    "permanence": "Permanent means no automatic expiry or retirement trigger. It does not mean immune from demonstrated error, transparent amendment, or a successor that satisfies the canonical supersession test."
  },
  "governance_amendments": [
    {
      "date": "2026-09-22",
      "effective_version": "v1.0",
      "amendment_id": "CHQ-ASC-TEMPLATE-2026-001",
      "description": "Successor and reassessment language normalized as explicit artifact-governance metadata; individual canonical supersession tests remain controlling.",
      "canonical_hash_effect": "RECOMPUTED"
    },
    {
      "date": "2026-09-22",
      "effective_version": "v1.0",
      "amendment_id": "CHQ-PRS-2026-001-AMD-003",
      "description": "Class-wide error-correction, amendment, successor, and permanence semantics ratified as non-canonical governance metadata. ASC-006's internal-adjudication classification is formally resolved without changing its canonical constraint text.",
      "canonical_hash_effect": "UNCHANGED"
    }
  ]
}
```
