Skip to content

Approval · research june 2026 · published 2026-08-03 · v2 · 4 min read · history

Disclosure is irrevocable

Deleting the copy does not undo the reading, so the record of a disclosure cannot offer to

Why moving material across a read boundary is typed as durable and non-revocable, and what a system gives up when it stops promising a takeback. The canonical treatment of irrevocable disclosure.

In brief
The problem

verified

Every claim this passage rests on has been checked against its sources.

  • "Atelier's strict boundary policy fails closed when private-domain material appears in shared work without a git.promote disclosure record."

    verified. The kit's own statement of its strict policies, read directly on 2026-08-03, alongside the boundary guard document.

Open the complete evidence in the structured publication.

Systems that move material across a read boundary want to describe the move as reversible, because deletion is the remedy everyone knows how to build and the one every person asks for.
The mechanism

verified

Every claim this passage rests on has been checked against its sources.

  • "The Atelier git-promote-event contract fixes the disclosure class to the single permitted value durable and the revocable flag to the single permitted value false, so no valid promotion record can describe a disclosure as reversible."

    verified. The schema read directly on 2026-08-03; both fields are JSON Schema const declarations inside the required event object.

Open the complete evidence in the structured publication.

The event is typed as durable and non-revocable in the format itself, so a record describing a disclosure as undoable is not a rejected record, it is not a record of this kind at all.
The move

position

This is the publication's stated position, not an empirical claim. It rests on the argument rather than graded evidence.

Open the complete evidence in the structured publication.

Type disclosure as permanent and spend the recording budget on who, what, from where, and to where, because attribution is the only remedy that was ever actually available.

A document moves out of a private repository and into a shared one. Six people can now read it, and some number of them do. A week later somebody decides the move was a mistake, deletes the file, rewrites the history, and force-pushes. Ask what has been undone and the honest answer is narrow. The copy is gone. The reading is not.

Our workspace tooling refuses to blur that. Moving source across a read boundary produces a promotion event, and the contract for it has two fields whose values are constants rather than choices. The disclosure class is fixed at durable. The revocable flag is fixed at false. Not defaults, not an enumeration with a recommended member, but single permitted values, which means a document describing a promotion as reversible fails validation on its shape and never reaches anyone with standing to disagree with it. The boundary policy fails closed in the other direction too, refusing private-domain material that turns up in shared work with no promotion record behind it.

The mechanism is that the event is typed as durable and non-revocable in the format itself, so a system holding these records cannot represent a disclosure as undoable, because what the record describes is a reading and a reading has no artifact left to destroy.

That last clause is the whole of the argument, and it is worth setting beside the strongest counter-technique this corpus has published. Cryptographic erasure lets an append-only ledger forget a person completely. The personal content sits encrypted under a key held somewhere else, and destroying the key leaves the sequence and the hashes intact while the content inside becomes unrecoverable. It is a real capability with a real guarantee, and the reason it works is that it has a target. There is a specific object whose destruction accomplishes the erasure. Disclosure has no such object. When material crosses a read boundary the thing that happened is that a person’s attention, or a model’s context window, took it in, and there is no key, no vault, and no jurisdiction on which any destruction could operate. Erasure can destroy a key. A reading has no key to destroy.

Law reached the same wall from the other side and stopped at the same place. In the 2014 Google Spain judgment, the Court of Justice of the European Union granted a form of the right to be forgotten and granted it in a very particular shape. The search engine was required to delist the results, and the newspaper page they pointed at stayed lawfully published exactly where it was. The most powerful data-protection court on the continent, ruling in the complainant’s favor, could make the material harder to find and could not make it unread. Everything downstream of that judgment, including the erasure right written into European law four years later, inherits the same boundary.

What a system gives up by admitting this is the undo button, and the undo button is what people want. The compensation is that the recording budget goes somewhere useful. Because it cannot promise a takeback, the promotion record spends its required fields on the questions that still have answers, naming the source repository and its read boundary, the target repository and its read boundary, the identity of the material at both ends, the actor who moved it, and the exact commit on either side. After the fact the question is never whether it can be recalled. The question is what went, from where to where, and who decided, and a record built on the truth can answer that one completely.

There is a kind of relief in a system that stops pretending here. A promise of revocation is a promise about other people’s memories, which is not a thing anyone has ever been able to keep, and building on it quietly teaches everyone that disclosure is cheap and correctable. Building on the truth teaches the opposite, which is that the decision to let something be read is the decision, made once, at a specific moment, by a named person. Treat it that way and the moment gets the attention it always deserved.

Evidence and lineage

Research trail

Follow the sources, inspect how the claims are graded, or propose a correction at the exact record it concerns.

Sources 5
  1. MNSTRY Atelier (2026). git-promote-event@v1, the local disclosure event contract

    The primary artifact. Its own description names it an append-only disclosure event, and two of its required event fields are JSON Schema constants, the disclosure class fixed at durable and the revocable flag fixed at false.

    Comment on this source
  2. MNSTRY Atelier (2026). Repo Boundary Guard V1 and the strict boundary policies

    The enforcement half. Git repository access is the source read boundary, and private-domain material appearing in shared work without a promotion record fails closed.

    Comment on this source
  3. Court of Justice of the European Union (2014). Google Spain SL and Google Inc. v AEPD and Mario Costeja González

    The external anchor and the limit case in law. The remedy granted was delisting from search results while the underlying publication remained lawfully in place, which is the strongest available demonstration that a completed publication cannot be unmade.

    Comment on this source
  4. MNSTRY (this corpus) (2026). 'Destroy the key' (the contrasting brick)

    The deliberate contrast. Cryptographic erasure is real and works because it has a destroyable target; this brick's argument is that a reading has none, so the two pieces are complements rather than rivals.

    Comment on this source
  5. MNSTRY (this corpus) (2026). 'Sacred artifacts' (the parent essay)

    The frame. The parent argues that fixing knowledge matters more than generating it; this brick takes one thing that is fixed whether anyone wanted it fixed or not.

    Comment on this source
Claims and confidence 5
  1. verified

    The Atelier git-promote-event contract fixes the disclosure class to the single permitted value durable and the revocable flag to the single permitted value false, so no valid promotion record can describe a disclosure as reversible.

    The schema read directly on 2026-08-03; both fields are JSON Schema const declarations inside the required event object.

    Respond to this claim
  2. verified

    The same contract requires repository, read boundary, knowledge-graph id, audience, and commit at both the source and target endpoints, together with the acting identity, so a promotion record states exactly what moved and between which boundaries.

    The schema's endpoint definition and the event's required-field list, read directly on 2026-08-03; commits are constrained to full forty-character hexadecimal identifiers.

    Respond to this claim
  3. verified

    Atelier's strict boundary policy fails closed when private-domain material appears in shared work without a git.promote disclosure record.

    The kit's own statement of its strict policies, read directly on 2026-08-03, alongside the boundary guard document.

    Respond to this claim
  4. verified

    In Google Spain v AEPD, decided by the Court of Justice of the European Union in 2014, the search engine was required to delist results about the complainant while the underlying newspaper publication remained lawfully in place.

    The judgment and the settled commentary on it. The delisting-not-deletion shape of the remedy is the point the brick uses and is uncontroversial.

    Respond to this claim
  5. directional

    Cryptographic erasure operates on a key held apart from the record, which gives it a destroyable target that a completed reading does not have.

    The first half restates the technique as treated in 'Destroy the key'. The second half is this brick's argument rather than a separate finding, offered as reasoning about what erasure can operate on.

    Respond to this claim

Read next

Or survey the topics.

Concepts in this piece 1

Add to the work

Contribute to Disclosure is irrevocable

Write the useful part. Identity, provenance, and review history are attached when you submit. The published source stays unchanged.

Target Disclosure is irrevocable

Contribution intent
Use an agent instead

The interface is ready. Public authenticated intake remains off until the hosted migration and feature flag are deployed together.