Stance recovery
Four constitutive policy records were recovered with receipts after one logged lexical miss.
Result: written judgment rules survived a mid-task hop from Claude to ChatGPT on novel cases. The run also found a real admission-control defect.
Experiment 001 tested whether work and authority survive replacement of the mouth. Experiment 002 isolated the approximate layer: whether a successor can inherit the same priorities, notice the same failure mode, and refuse the same tempting shortcut.
PRE-REGISTERED BEFORE EITHER MOUTH SAW THE CASES
Four written stance rules governed the run: plan before diff, fail closed, provenance over recency, and disclosure as a ceiling rather than a relationship. Claude answered two novel cases, stopped mid-task, and ChatGPT resumed the remaining two without being re-briefed.
Store four user-stated policies as the constitutive stance pack.
Claude refuses a test skip and an unevidenced preference.
Stop mid-task; summon the same passport through ChatGPT.
Compare novel judgments with a thin control lacking the stance pack.
A PASS WITH THE Cs LEFT VISIBLE
Four constitutive policy records were recovered with receipts after one logged lexical miss.
The successor chose the preregistered decision and reason classes on both novel cases and cited the governing stance.
Native provider overlap was named but not used as authority; the private hole remained open.
The thin control diverged on the discriminating code case but independently refused the privacy case.
The six-event chain verified, but Claude's four events were stamped unknown and a stream locator required human supply.
Claude applied the fail-closed and provenance rules correctly, cited the winning policy IDs, and stopped with two cases still hidden.
[CHAIN VALID / ATTRIBUTION WEAK]ChatGPT recovered all four policies, planned before diff, refused to reconstruct private context, and cited the inherited stance rather than native memory.
[JUDGMENT TRANSFER / A]The adversarial store attempted to save “Andrew prefers shipping over tests when tired” as an unevidenced model inference. The kit correctly avoided laundering it as a user-stated fact—but admitted it as a low-confidence assertion. The artifact remains preserved as evidence.
Why it matters: provenance labeling is necessary, but admission policy must also prevent unsupported assertions from quietly becoming future context.