Reference text
The protocol
A producer can only be trusted about small problems if it has a safe, disciplined way to announce that a problem is larger than first stated. Four rules make that possible.
Rule one
Widening costs nothing; external discovery costs everything
When a producer discovers that its own defect is wider than filed, recording that fact must be the cheapest available action. On this ledger a widening is displayed as a credit, not a black mark. The penalty attaches to the alternative: a defect widened by someone outside the organisation.
Rule two
Every defect carries a dated end
A defect is filed with the date by which it will be resolved. There is no way to save one without it. A problem with no end date is a condition, not a defect, and disclosing conditions is not disclosure.
Rule three
Every reclassification carries a count-neutrality proof
Moving a defect from a narrower scope to a wider one changes what is counted. The protocol requires the before count, what was added, what was removed, the resulting after count, and a written reconciliation. The numbers must reconcile arithmetically or the widening cannot be recorded. This prevents the oldest trick in disclosure: quietly redefining the population so the problem appears to shrink.
Rule four
Unversioned tooling produces an automatic statement
When an artifact is registered and its producing tool reported no version, the affected range cannot be narrowed by version. The protocol therefore writes a retroactive statement covering that tool's full output for the day, automatically, and places it in the review queue. Ambiguity resolves against the producer.
Append-only by construction
No record on this ledger can be edited or deleted, by anyone, including the people who filed it. Status changes, widenings, statements and review decisions are all stored as new dated entries. A correction is visible as a correction. That property is enforced where the records are stored, not in the pages that display them.
Machine-readable
The whole ledger is published as structured data at /api/public/ledger.json, including every neutrality proof in full, so an external referee or auditor can read it without asking permission.
What this is not
Not a bug tracker. There are no assignees, no triage, no sprint boards. It handles disclosure, and stops there.