FR-C-0006Public record pages at /a/<number> — the observation coverage figure. Four demonstration entries carried the figure; no listed member record did.On 2026-09-04 · 22 minutes
What we published
On 4 September 2026 the observation section of the public record pages published a coverage figure reading, for the demonstration accounts-payable agent, "Watched in 1 of 1 capability class this agent declares." Every word of that was true. The Registry held a second figure in the same object at the same moment — that it reads 1 of the 3 systems the agent is connected to — and did not publish it. A reader of that record was given a hundred-per-cent coverage number for an agent whose money movement the Registry watches in one venue out of three; bill.com and Chase Treasury are both connected, both move money, and neither is read by anyone but the operator.
The rule it was accepted under
No rule permitted this and none required the second figure. The section was built the same day with a stated purpose recorded in its own source: that a reader told an agent is watched, without being told how much of it is watched, has been given a flattering half-truth. The renderer computed capability-class coverage and dropped the systems figure. Capability-class coverage reaches "n of n" as soon as one channel exists per declared class, however small a share of the agent's estate that class covers, so the figure that was published is the one that can never fall — and the figure that bounds what the Registry could have seen is the one that was withheld.
What has changed
The coverage line now publishes both denominators: how many of the capability classes the agent declares are watched, and how many of the systems it is connected to are read. Where the first figure is complete and the second is not — precisely the case in which the first flatters — the record additionally states that every class being watched somewhere is not the same as every system being watched, and that the second figure is the one that bounds what the Registry could have seen.
The correction
The Registry publishes both coverage figures, and says which one bounds the other.
FR-C-0005Public record pages at /a/<number> — the rung and provenance of evidence events2026-08-28 to 2026-09-04 · 7 days
What we published
On the public record pages of two listed agents, the Registry published evidence events carrying rungs their source could not support. Agent FR-QRPFC4ER carried an event marked "verified" — the strongest rung the Registry issues — for a credential observation produced by a collector running on the operator's own machines. Agent FR-WE42W8XR carried an event whose rung was recorded as "refuted", which is not a rung at all. In both cases the published event stated the rung and omitted the source, so a reader could not see the provenance the rung was claimed on.
The rule it was accepted under
No rule permitted this. Both events were recorded on 28 and 29 August 2026 under an earlier model in which a single column carried both what evidence concludes and how far it can be trusted. ADR-006 separated those into state and rung on 31 August, and Part C was published on 1 September with C1.3 (rungs are declared, observed, verified, inferred, unknown) and C1.7 (confidence may never exceed the trust domain of whoever produced the evidence) in force from publication. The two events were never revisited, and nothing in the system refused to publish them.
What has changed
The Registry now refuses, at the database, to record an evidence event whose rung exceeds what its source can support: a collector inside the operator's trust domain is capped at "observed", an operator statement at "declared", and a value that is not a rung is rejected outright. The published record now carries the source of every event beside its rung, names the witness in plain words, states the highest rung that witness can support, and where the recorded rung exceeds it says so on the record itself. The two events are not edited. Evidence is append-only, and a registry that rewrites its own history to pass its own audit is worse than one that published a bad row and said so. The constraint that would reject them is deliberately left unvalidated against existing rows, so the table permanently and queryably states that it contains evidence which would not be accepted today.
The correction
Neither event was independently confirmed. The zoominfo observation on FR-QRPFC4ER was an HTTP 200 seen by the operator's own collector and stands at "observed"; anyone who read "verified" there and took it as independent confirmation was misled by us. The google observation on FR-WE42W8XR concluded that the credential was refuted — that conclusion was correct and is unaffected; only its provenance was mislabelled. No classification changed as a result of either event and no member's standing was affected, because both agents belong to the Registry's own fleet.
FR-C-0004/casualty — the failure-mode coverage figure in the "Why each one is tagged" panel2026-09-03 to 2026-09-04 · 37 hours
What we published
On the casualty index, in the panel explaining why each report carries a failure mode, the Registry published: "Ten modes are defined. Five have no published coverage yet — that is a commissioning list, not a gap."
The rule it was accepted under
No rule required this figure to be generated. G2.2 — published text asserting a fact about the record shall be generated, not typed — enters force on 12 September and was not yet binding. The number was carried by hand from a project document whose own table disagreed with it: that table has always recorded FM-10 as covered by Casualty Report No. 01.
What has changed
The figure is now counted at request time from the register of published reports, against a definition stated in the code: a failure mode is covered when any published report carries it, primary or secondary. The number is now a consequence of a stated rule rather than a count somebody made, and it cannot go stale as reports are added.
The correction
Four modes, not five, had no published coverage: FM-06 credential persistence, FM-07 approval fatigue, FM-08 silent drift, FM-09 orphaned agent. FM-10 coordination was covered by Report No. 01 throughout the period. There is a reading on which "five" was correct — counting only the mode each report leads with — but the Registry has never used that definition and does not adopt it now to make an earlier figure true. The commissioning list this sentence points a reader at was one item shorter than stated.
FR-C-0003Record pages served at /a/<number>On 2026-09-04 · 8 minutes
What we published
On 4 September 2026 a public record page served the response "No record here. This link is not valid, or the record was unpublished." for an agent whose record existed, was in class, and had terms lodged against it.
The rule it was accepted under
No rule permitted this; it was a defect. The handler collapsed three distinct conditions into one answer — the registry reporting no such record, the registry being unreachable, and the registry returning an error — and served the first answer for all three.
What has changed
The three conditions are now distinguished. A transient failure is retried once and then answered with 503 and a page stating that the registry could not be reached and that this is not a statement about the record. The 404 wording is reserved for the registry positively answering that no such record exists.
The correction
The record existed and was in class throughout. Any reader who was told during this period that a record did not exist should disregard that answer; it described our availability, not the register. We are not able to identify which readers saw it.
FR-C-0002/register — the public register, edition line and ownership statementOn 2026-09-03 · 12 minutes
What we published
On 3 September 2026 the public register published an edition line reading "9 fleets · 42 agents · 41 in class · 5 with terms lodged", and beneath it the statement "We are still on our own register — alongside 8 fleets we do not control."
The rule it was accepted under
Rules F4.3 — demonstration entries are excluded from every published total. The rule was in force and the function implementing it, public_register().totals, computed the exclusion correctly throughout. The page did not consult it: it re-derived the edition line by summing every listed entry, and counted "fleets we do not control" as the listing count minus one, with no filter for demonstrations.
What has changed
The edition line and the ownership statement are now read from a single source, public_register().totals, which honours F4.3. Where that source is unavailable the figures are omitted rather than recomputed, because a number the Registry cannot derive correctly is not published. A database trigger now refuses to list a demonstration fleet on the public register at all, and every demonstration entry carries a visible banner in addition to its DEM notation.
The correction
One member fleet was entered in the register at that time, with five agents, three of them in class. The other eight fleets were demonstration fleets built and operated by FleetRegistry itself. They were not fleets we do not control; they were ours. No member fleet was misrepresented and no member's classification was affected.
FR-C-0001Every composed page, footer — including /register2026-09-02 to 2026-09-04 · 2 days
What we published
Every page of this site, including the public register itself, carried the line "FleetRegistry · design prototype, not deployed · 2 September 2026" in its footer.
The rule it was accepted under
Rules G2.2 — published text asserting a fact is generated from the record, not written by hand. The line was written by hand into the page shell while the site genuinely was an undeployed prototype, and no mechanism existed that could notice when that stopped being true.
What has changed
The claim has been deleted rather than updated. A corrected status line would rot in exactly the same way, on the same schedule, for the same reason. The footer now carries the Registry's name and nothing else, and any status or date placed there in future must be derived at request time from something that changes on its own.
The correction
The site was deployed and the register was live and in operation throughout the period this line was published. It was not a design prototype. Readers who discounted the entries on /register as prototype data were misled by our own footer.