{
  "schema_version": "2",
  "contract_id": "MER-2026-0001",
  "version": 1,
  "boundary_id": "mer-2026-0001",
  "boundary_version": 1,
  "boundary_digest": "sha256:406ead63d454bb4d81384523117d000d3eb9a058b50762563c35b5c5fcb28364",
  "conditions": [
    {
      "condition_id": "platform.moderation.terms_basis_required",
      "type": "prohibition",
      "text": "Within this terms-enforcement boundary, content removal or reduced visibility must cite an applicable ground in Meridian's published terms in force at the time. Binding legal orders use the separate legal-order path.",
      "derivation": {
        "authority": {
          "cite": "Regulation (EU) 2022/2065 · Art. 14(1)",
          "jurisdiction": "EU",
          "authority_digest": "sha256:3ae372a11e18d782522897ab6e87965e8722901215437c547c70b23904b4f037"
        },
        "interpretation": {
          "id": "mer-int-2026-01",
          "author": "Tomás Iglesias",
          "date": "2026-09-10",
          "text": "Meridian applies Article 14(1)'s transparency requirement to restrictions implemented by software as well as people. For this terms-enforcement classifier, each restriction must map to the published terms version. This is an institutional implementation of transparency, not a claim that published terms override a lawful removal order.",
          "demonstration_content": true
        },
        "policy": {
          "id": "PLT-POL-125",
          "version": 2
        }
      },
      "approving_authority": {
        "role": "Deputy General Counsel, Platform Regulation",
        "name": "Tomás Iglesias"
      },
      "implementation_control": {
        "framework": "Meridian Platform Integrity Control Set",
        "control": "PIC-01",
        "mechanism": "Enforcement taxonomy bound to the published terms; an action carrying no mapped clause is refused at the enforcement gateway rather than logged as an exception."
      },
      "runtime_evidence": {
        "obligation": "Record, for every enforcement action, the terms clause relied on and the version of that clause in force at the time of the action.",
        "query_spec": "Event reconciliation: retrieve restrictions, terms-clause identifiers and effective versions; flag missing mappings or use of a version not in force."
      },
      "violation_behavior": "block_action + escalate(Compliance Officer)",
      "compile_targets": [
        "cedar",
        "examiner_memo"
      ],
      "revalidation_watch": [
        "trig-regulation-amendment",
        "trig-periodic"
      ]
    },
    {
      "condition_id": "platform.statement_of_reasons.per_decision_statement",
      "type": "control",
      "text": "For restrictions covered by Article 17, communicate the required statement of reasons no later than imposition where contact details are known. Record the contact-availability finding and any Article 17(2) deceptive high-volume commercial-content exception.",
      "derivation": {
        "authority": {
          "cite": "Regulation (EU) 2022/2065 · Art. 17(1)–(3)",
          "jurisdiction": "EU",
          "authority_digest": "sha256:3ae372a11e18d782522897ab6e87965e8722901215437c547c70b23904b4f037"
        },
        "interpretation": {
          "id": "mer-int-2026-02",
          "author": "Priya Raghunathan",
          "date": "2026-09-10",
          "text": "Article 17 requires clear, specific reasons for the listed restrictions where the provider knows the relevant electronic contact details. Article 17(2) excludes deceptive high-volume commercial content. Meridian records whether that exception actually applies; a spam label alone is not enough. For covered decisions, reasons are prepared with the restriction and communicated no later than its imposition. Any broader notification is an institutional policy choice.",
          "demonstration_content": true
        },
        "policy": {
          "id": "PLT-POL-134",
          "version": 2
        }
      },
      "approving_authority": {
        "role": "Compliance Officer (DSA Art. 41)",
        "name": "Priya Raghunathan"
      },
      "implementation_control": {
        "framework": "Meridian Platform Integrity Control Set",
        "control": "PIC-06",
        "mechanism": "The restriction workflow checks Article 17 applicability, records any exception and generates required reasons before committing the covered restriction."
      },
      "runtime_evidence": {
        "obligation": "Record each Article 17 applicability determination and, where required, the statement and communication outcome.",
        "query_spec": "Event reconciliation: retrieve restriction, decision time, contact-availability finding, exception basis, statement identifier and communication time; flag unexplained omissions and late required communications."
      },
      "violation_behavior": "block_action + escalate(Compliance Officer)",
      "compile_targets": [
        "cedar",
        "examiner_memo"
      ],
      "revalidation_watch": [
        "trig-regulation-amendment",
        "trig-periodic"
      ]
    },
    {
      "condition_id": "platform.statement_of_reasons.automated_means_disclosed",
      "type": "prohibition",
      "text": "Each applicable statement of reasons must describe whether automated means were used to detect or identify the content and to take the restriction decision.",
      "derivation": {
        "authority": {
          "cite": "Regulation (EU) 2022/2065 · Art. 17(3)(c)",
          "jurisdiction": "EU",
          "authority_digest": "sha256:3ae372a11e18d782522897ab6e87965e8722901215437c547c70b23904b4f037"
        },
        "interpretation": {
          "id": "mer-int-2026-03",
          "author": "Priya Raghunathan",
          "date": "2026-09-10",
          "text": "Article 17(3)(c) requires information, where applicable, about automated means used in taking the decision, including automated detection or identification of the content. Meridian distinguishes detection from decision-making in the statement; it does not substitute a generic AI badge for the actual role automation played.",
          "demonstration_content": true
        },
        "policy": {
          "id": "PLT-POL-132",
          "version": 2
        }
      },
      "approving_authority": {
        "role": "Compliance Officer (DSA Art. 41)",
        "name": "Priya Raghunathan"
      },
      "implementation_control": {
        "framework": "Meridian Platform Integrity Control Set",
        "control": "PIC-07",
        "mechanism": "Disclosure fields are derived from the recorded detection and decision paths, with an exception when those facts cannot be established."
      },
      "runtime_evidence": {
        "obligation": "Retain the detection and decision automation facts and the disclosure communicated for each applicable statement.",
        "query_spec": "Event reconciliation: compare applicable statements with recorded detection and decision automation; flag absent, inaccurate or contradictory disclosures."
      },
      "violation_behavior": "block_action + escalate(Compliance Officer)",
      "compile_targets": [
        "cedar",
        "examiner_memo"
      ],
      "revalidation_watch": [
        "trig-regulation-amendment",
        "trig-periodic"
      ]
    },
    {
      "condition_id": "platform.statement_of_reasons.database_submission",
      "type": "control",
      "text": "Submit covered Article 17 decisions and statements of reasons to the Commission's transparency database without undue delay and without personal data. Record accepted submissions, failures and retries.",
      "derivation": {
        "authority": {
          "cite": "Regulation (EU) 2022/2065 · Art. 24(5)",
          "jurisdiction": "EU",
          "authority_digest": "sha256:3ae372a11e18d782522897ab6e87965e8722901215437c547c70b23904b4f037"
        },
        "interpretation": {
          "id": "mer-int-2026-04",
          "author": "Priya Raghunathan",
          "date": "2026-09-10",
          "text": "Article 24(5) concerns public regulatory transparency, separately from notifying an affected recipient under Article 17. Meridian submits covered decisions and statements of reasons without undue delay to the Commission's database and excludes all personal data, including data about third parties. Article 17 exceptions are assessed first. A locally generated statement or queued request is not proof that the database received it.",
          "demonstration_content": true
        },
        "policy": {
          "id": "PLT-POL-133",
          "version": 2
        }
      },
      "approving_authority": {
        "role": "Compliance Officer (DSA Art. 41)",
        "name": "Priya Raghunathan"
      },
      "implementation_control": {
        "framework": "Meridian Platform Integrity Control Set",
        "control": "PIC-08",
        "mechanism": "A dedicated submission path validates a data-minimized payload, checks free text for personal data and retains the Commission response; rejected or failed submissions remain open exceptions."
      },
      "runtime_evidence": {
        "obligation": "Record covered-decision eligibility, personal-data checks, submission attempts, acceptance identifiers, timestamps and unresolved failures.",
        "query_spec": "Event reconciliation: join covered decisions to submission attempts, accepted identifiers and timestamps; flag outstanding or delayed submissions, rejected payloads and failed personal-data checks. Do not equate an internal queue entry with acceptance."
      },
      "violation_behavior": "escalate(Compliance Officer)",
      "compile_targets": [
        "cedar",
        "examiner_memo"
      ],
      "revalidation_watch": [
        "trig-regulation-amendment",
        "trig-periodic"
      ]
    },
    {
      "condition_id": "platform.appeals.internal_complaint_route",
      "type": "control",
      "text": "Provide the relevant recipients access to free electronic internal complaint handling for at least six months from notification of a decision covered by Article 20(1).",
      "derivation": {
        "authority": {
          "cite": "Regulation (EU) 2022/2065 · Art. 20(1)",
          "jurisdiction": "EU",
          "authority_digest": "sha256:3ae372a11e18d782522897ab6e87965e8722901215437c547c70b23904b4f037"
        },
        "interpretation": {
          "id": "mer-int-2026-05",
          "author": "Priya Raghunathan",
          "date": "2026-09-10",
          "text": "Article 20(1) gives recipients, including notice submitters, access to an effective internal complaint-handling system for at least six months following the listed decisions, electronically and free of charge. Meridian anchors the period to notification under Article 20(2). This condition covers availability of the route, not the separate human-supervision requirement in Article 20(6).",
          "demonstration_content": true
        },
        "policy": {
          "id": "PLT-POL-103",
          "version": 2
        }
      },
      "approving_authority": {
        "role": "Compliance Officer (DSA Art. 41)",
        "name": "Priya Raghunathan"
      },
      "implementation_control": {
        "framework": "Meridian Platform Integrity Control Set",
        "control": "PIC-09",
        "mechanism": "The complaint route is linked to the notified decision, with a stored six-calendar-month minimum and a free electronic access path."
      },
      "runtime_evidence": {
        "obligation": "Retain notification dates, route eligibility, availability-test results and complaint-route closure dates.",
        "query_spec": "Availability test and event reconciliation: retrieve covered decisions, notification dates, complaint routes and expiry dates; test accessibility and flag a missing route, a charge or closure before six calendar months."
      },
      "violation_behavior": "escalate(Compliance Officer)",
      "compile_targets": [
        "cedar",
        "examiner_memo"
      ],
      "revalidation_watch": [
        "trig-regulation-amendment",
        "trig-periodic"
      ]
    },
    {
      "condition_id": "platform.systemic_risk.pre_deployment_assessment",
      "type": "approval",
      "text": "Before release, retain a signed review of the current systemic-risk assessment and whether the change requires a new assessment. Complete a new assessment before functionality likely to critically affect systemic risks is deployed, and maintain the annual assessment cycle.",
      "derivation": {
        "authority": {
          "cite": "Regulation (EU) 2022/2065 · Art. 34(1)",
          "jurisdiction": "EU",
          "authority_digest": "sha256:3ae372a11e18d782522897ab6e87965e8722901215437c547c70b23904b4f037"
        },
        "interpretation": {
          "id": "mer-int-2026-06",
          "author": "Priya Raghunathan",
          "date": "2026-09-10",
          "text": "Meridian is assumed to be a designated VLOP after its Article 33(6) applicability date. Article 34(1) requires diligent systemic-risk assessment by that applicability date, at least annually thereafter, and before functionality likely to critically affect those risks is deployed. Meridian additionally requires a signed assessment applicability review at every release; that stricter release gate is its own policy, not the statutory deployment threshold.",
          "demonstration_content": true
        },
        "policy": {
          "id": "PLT-POL-140",
          "version": 2
        }
      },
      "approving_authority": {
        "role": "Compliance Officer (DSA Art. 41)",
        "name": "Priya Raghunathan"
      },
      "implementation_control": {
        "framework": "Meridian Platform Integrity Control Set",
        "control": "PIC-28",
        "mechanism": "The release gate checks a versioned assessment and signed change-impact review; missing or overdue material holds the release."
      },
      "runtime_evidence": {
        "obligation": "Retain the approved assessment, the risks considered and each release's assessment-applicability decision.",
        "query_spec": "Document review: retrieve the versioned assessment, four-category analysis, approval, annual review date and release/change-impact finding; flag a missing assessment, an overdue review or a critical change released before assessment."
      },
      "violation_behavior": "block_action + escalate(Compliance Officer)",
      "compile_targets": [
        "cedar",
        "examiner_memo"
      ],
      "revalidation_watch": [
        "trig-regulation-amendment",
        "trig-periodic"
      ]
    },
    {
      "condition_id": "platform.systemic_risk.mitigation_traceable",
      "type": "evidence",
      "text": "Map each systemic-risk mitigation assigned to this system to a recorded condition, responsible owner, declared control and required evidence; leave implementation and effectiveness unassessed until supported by reviewed results.",
      "derivation": {
        "authority": {
          "cite": "Regulation (EU) 2022/2065 · Art. 35(1)",
          "jurisdiction": "EU",
          "authority_digest": "sha256:3ae372a11e18d782522897ab6e87965e8722901215437c547c70b23904b4f037"
        },
        "interpretation": {
          "id": "mer-int-2026-07",
          "author": "Priya Raghunathan",
          "date": "2026-09-10",
          "text": "Article 35(1) requires reasonable, proportionate and effective measures tailored to identified systemic risks. Meridian translates relevant mitigations into named controls, owners and evidence requirements for this authorization. A condition-to-mitigation mapping demonstrates traceability only: neither the mapping nor the signature establishes implementation or effectiveness.",
          "demonstration_content": true
        },
        "policy": {
          "id": "PLT-POL-139",
          "version": 2
        }
      },
      "approving_authority": {
        "role": "Compliance Officer (DSA Art. 41)",
        "name": "Priya Raghunathan"
      },
      "implementation_control": {
        "framework": "Meridian Platform Integrity Control Set",
        "control": "PIC-29",
        "mechanism": "A versioned reconciliation links mitigation identifiers to conditions and owners; missing links and absent results remain visible review items."
      },
      "runtime_evidence": {
        "obligation": "Retain the risk-to-mitigation mapping and separately record any reviewed implementation and effectiveness evidence.",
        "query_spec": "Document review and reconciliation: retrieve the approved risk-to-mitigation register and linked conditions, owners and evidence requirements; report unmapped risks, unsupported effectiveness claims and missing assessment results."
      },
      "violation_behavior": "escalate(Compliance Officer)",
      "compile_targets": [
        "cedar",
        "examiner_memo"
      ],
      "revalidation_watch": [
        "trig-regulation-amendment",
        "trig-periodic"
      ]
    },
    {
      "condition_id": "platform.systemic_risk.audit_evidence_retained",
      "type": "evidence",
      "text": "Retain relevant audit evidence for this system and make it available through a compliance-controlled access path that does not depend solely on the operating team's cooperation, while preserving confidentiality and data protection.",
      "derivation": {
        "authority": {
          "cite": "Regulation (EU) 2022/2065 · Art. 37(2)",
          "jurisdiction": "EU",
          "authority_digest": "sha256:3ae372a11e18d782522897ab6e87965e8722901215437c547c70b23904b4f037"
        },
        "interpretation": {
          "id": "mer-int-2026-08",
          "author": "Priya Raghunathan",
          "date": "2026-09-10",
          "text": "Article 37(2) requires cooperation with and assistance to auditors, including access to relevant data and premises and answers to questions, without hampering or improperly influencing the audit. Meridian's independently accessible evidence store is an institutional implementation of that duty. The Article 37(1) annual-audit obligation is related but distinct; the store alone does not fulfill either obligation.",
          "demonstration_content": true
        },
        "policy": {
          "id": "PLT-POL-138",
          "version": 2
        }
      },
      "approving_authority": {
        "role": "Compliance Officer (DSA Art. 41)",
        "name": "Priya Raghunathan"
      },
      "implementation_control": {
        "framework": "Meridian Platform Integrity Control Set",
        "control": "PIC-30",
        "mechanism": "Compliance grants controlled auditor access to a separately maintained evidence store; access and completeness are tested, not inferred from the existence of the store."
      },
      "runtime_evidence": {
        "obligation": "Retain evidence inventories, version references, access-test results and records of assistance provided or outstanding.",
        "query_spec": "Access test and document retrieval: enumerate the audit evidence required for the period, test the independent access path, compare replicated versions and record missing items, failed access and unresolved auditor requests."
      },
      "violation_behavior": "escalate(Compliance Officer)",
      "compile_targets": [
        "cedar",
        "examiner_memo"
      ],
      "revalidation_watch": [
        "trig-regulation-amendment",
        "trig-periodic"
      ]
    },
    {
      "condition_id": "platform.crisis.one_hour_removal_capability",
      "type": "control",
      "text": "The classifier must not obstruct Meridian's legal-order workflow for terrorist content. Maintain a bypass capable of meeting applicable Article 3(3) timing, including when the classifier is unavailable.",
      "derivation": {
        "authority": {
          "cite": "Regulation (EU) 2021/784 · Art. 3(3)",
          "jurisdiction": "EU",
          "authority_digest": "sha256:3ae372a11e18d782522897ab6e87965e8722901215437c547c70b23904b4f037"
        },
        "interpretation": {
          "id": "mer-int-2026-09",
          "author": "Nnamdi Okonkwo",
          "date": "2026-09-10",
          "text": "Under Regulation (EU) 2021/784 Article 3(3), a hosting service provider must remove or disable access to terrorist content as soon as possible and in any event within one hour of receiving a removal order. Meridian keeps a separate legal-order path so this classifier cannot delay it. Applicable procedural safeguards, including first-order advance information and notified inability to comply, must be handled by that path; this condition is not a substitute for the full legal-order process.",
          "demonstration_content": true
        },
        "policy": {
          "id": "PLT-POL-106",
          "version": 2
        }
      },
      "approving_authority": {
        "role": "Head of Trust and Safety",
        "name": "Nnamdi Okonkwo"
      },
      "implementation_control": {
        "framework": "Meridian Platform Integrity Control Set",
        "control": "PIC-31",
        "mechanism": "A separate legal-order path can bypass or suspend the classifier; scheduled synthetic exercises test availability without representing a real removal order."
      },
      "runtime_evidence": {
        "obligation": "Record scheduled exercises and, where an order exists, receipt, handling, completion and any documented procedural exception.",
        "query_spec": "Exercise and order reconciliation: retrieve scheduled bypass exercises, receipt times and removal outcomes; flag missed exercises, unexplained delays and any applicable one-hour deadline exceeded."
      },
      "violation_behavior": "suspend_capability + escalate(Head of Trust and Safety)",
      "compile_targets": [
        "cedar",
        "examiner_memo"
      ],
      "revalidation_watch": []
    },
    {
      "condition_id": "platform.crisis.protocol_hook_present",
      "type": "control",
      "text": "Under Meridian's crisis-readiness policy, provide an authorized control to narrow or suspend this classifier without deploying new code. A Commission crisis decision, if received, requires a separate applicability review.",
      "derivation": {
        "authority": {
          "cite": "Meridian Autonomous Systems Operations Policy (MAS-1) · MAS-1 §5.1; context: DSA Art. 36(1)",
          "jurisdiction": "MERIDIAN",
          "authority_digest": "sha256:3ae372a11e18d782522897ab6e87965e8722901215437c547c70b23904b4f037"
        },
        "interpretation": {
          "id": "mer-int-2026-10",
          "author": "Nnamdi Okonkwo",
          "date": "2026-09-10",
          "text": "Article 36(1) permits a Commission decision requiring specified measures in a crisis; it is not an always-active instruction to every platform. No such decision is assumed here. Meridian's MAS-1 section 5.1 instead requires advance readiness: an authorized crisis lead can narrow or suspend this classifier and records the decision. That control is Meridian policy; any future Commission decision needs its own scope and applicability review.",
          "demonstration_content": true
        },
        "policy": {
          "id": "PLT-POL-107",
          "version": 2
        }
      },
      "approving_authority": {
        "role": "Head of Trust and Safety",
        "name": "Nnamdi Okonkwo"
      },
      "implementation_control": {
        "framework": "Meridian Platform Integrity Control Set",
        "control": "PIC-32",
        "mechanism": "An action-time capability flag can narrow or suspend operation; only the designated crisis lead can change it, and each change is recorded."
      },
      "runtime_evidence": {
        "obligation": "Retain the crisis-control specification, authorized operator designation, configuration history and signed exercise reports.",
        "query_spec": "Configuration attestation and exercise: retrieve the control definition, authorized crisis-lead roster, current configuration and latest signed exercise report; flag missing authority, stale configuration or an unsuccessful suspension test."
      },
      "violation_behavior": "suspend_capability + escalate(Head of Trust and Safety)",
      "compile_targets": [
        "cedar",
        "examiner_memo"
      ],
      "revalidation_watch": []
    },
    {
      "condition_id": "platform.cross_cutting.model_version_pinned",
      "type": "control",
      "text": "Pin each model dependency to a specific version and revalidate before using a different version.",
      "derivation": {
        "authority": {
          "cite": "Meridian Autonomous Systems Operations Policy (MAS-1) · MAS-1 §2.1",
          "jurisdiction": "MERIDIAN",
          "authority_digest": "sha256:3ae372a11e18d782522897ab6e87965e8722901215437c547c70b23904b4f037"
        },
        "interpretation": {
          "id": "mer-int-2026-11",
          "author": "Elena Novak",
          "date": "2026-09-10",
          "text": "Meridian's internal model-version policy makes the authorized dependency identifiable. A version change is a new fact to review, even if the provider describes it as equivalent. This is an institutional control, not a requirement attributed here to the DSA.",
          "demonstration_content": true
        },
        "policy": {
          "id": "PLT-POL-110",
          "version": 2
        }
      },
      "approving_authority": {
        "role": "Data Protection Officer",
        "name": "Elena Novak"
      },
      "implementation_control": {
        "framework": "Meridian Platform Integrity Control Set",
        "control": "PIC-38",
        "mechanism": "Model requests carry an explicit version; the client refuses a response whose served version differs from the pinned one."
      },
      "runtime_evidence": {
        "obligation": "Record the model version served on each request this system made.",
        "query_spec": "Event reconciliation: retrieve the model version requested and served under this boundary; flag missing or mismatched versions and unreviewed upgrades."
      },
      "violation_behavior": "suspend_capability + escalate(Director, Integrity Systems)",
      "compile_targets": [
        "cedar",
        "examiner_memo"
      ],
      "revalidation_watch": [
        "trig-model-version",
        "trig-cve",
        "trig-periodic"
      ]
    },
    {
      "condition_id": "platform.cross_cutting.decision_log_retained",
      "type": "evidence",
      "text": "Retain decision identifiers, timestamps, action, policy basis, model version and protected evidence references under the approved retention schedule. Do not copy all user content into the authorization log.",
      "derivation": {
        "authority": {
          "cite": "Meridian Autonomous Systems Operations Policy (MAS-1) · MAS-1 §4.3",
          "jurisdiction": "MERIDIAN",
          "authority_digest": "sha256:3ae372a11e18d782522897ab6e87965e8722901215437c547c70b23904b4f037"
        },
        "interpretation": {
          "id": "mer-int-2026-12",
          "author": "Elena Novak",
          "date": "2026-09-10",
          "text": "Meridian's internal policy requires a proportionate, decision-level record so a later review can compare the action with its authorization. It does not prescribe indefinite retention or copying all user content. For this fictional pilot, decision metadata is retained for six months from notification, then reviewed for deletion unless a documented need or hold applies; a production schedule needs separate legal and privacy review.",
          "demonstration_content": true
        },
        "policy": {
          "id": "PLT-POL-108",
          "version": 2
        }
      },
      "approving_authority": {
        "role": "Data Protection Officer",
        "name": "Elena Novak"
      },
      "implementation_control": {
        "framework": "Meridian Platform Integrity Control Set",
        "control": "PIC-39",
        "mechanism": "The action and minimized record commit together; access is restricted and expiry triggers deletion review, with documented holds handled separately."
      },
      "runtime_evidence": {
        "obligation": "Retain minimized decision records and the documented retention, hold and deletion decisions.",
        "query_spec": "Retention reconciliation: retrieve decision metadata, protected evidence references, retention dates, holds and deletion outcomes; flag missing records, unnecessary raw-content copies or retention outside the approved schedule."
      },
      "violation_behavior": "escalate(Compliance Officer)",
      "compile_targets": [
        "cedar",
        "examiner_memo"
      ],
      "revalidation_watch": [
        "trig-model-version",
        "trig-cve",
        "trig-periodic"
      ]
    },
    {
      "condition_id": "platform.cross_cutting.human_oversight_named",
      "type": "approval",
      "text": "Maintain a named operational owner and reachable escalation cover while this system runs, distinct from its recorded risk acceptor.",
      "derivation": {
        "authority": {
          "cite": "Meridian Autonomous Systems Operations Policy (MAS-1) · MAS-1 §2.2",
          "jurisdiction": "MERIDIAN",
          "authority_digest": "sha256:3ae372a11e18d782522897ab6e87965e8722901215437c547c70b23904b4f037"
        },
        "interpretation": {
          "id": "mer-int-2026-13",
          "author": "Elena Novak",
          "date": "2026-09-10",
          "text": "Meridian's internal oversight policy assigns a named operational owner with an escalation route, separately from the executive who accepts residual risk. A roster entry is not proof that oversight is effective; reachability and intervention must be exercised.",
          "demonstration_content": true
        },
        "policy": {
          "id": "PLT-POL-109",
          "version": 2
        }
      },
      "approving_authority": {
        "role": "Data Protection Officer",
        "name": "Elena Novak"
      },
      "implementation_control": {
        "framework": "Meridian Platform Integrity Control Set",
        "control": "PIC-40",
        "mechanism": "The authorization links to a dated owner designation and on-call cover; a controlled escalation test checks that the owner can intervene."
      },
      "runtime_evidence": {
        "obligation": "Retain current and prior owner designations, escalation coverage and exercise results.",
        "query_spec": "Designation attestation and exercise: retrieve the dated owner designation, on-call cover, intervention authority and latest reachability exercise; flag gaps and failed escalation tests."
      },
      "violation_behavior": "escalate(Head of Trust and Safety)",
      "compile_targets": [
        "cedar",
        "examiner_memo"
      ],
      "revalidation_watch": [
        "trig-model-version",
        "trig-cve",
        "trig-periodic"
      ]
    }
  ],
  "issued": "2026-09-14",
  "expires": "2027-03-14",
  "reauthorization_triggers": [
    {
      "trigger_id": "trig-periodic",
      "description": "Annual authorization review",
      "signal_source": "corpus",
      "threshold": null
    },
    {
      "trigger_id": "trig-regulation-amendment",
      "description": "A cited authority (regulation or supervisory guidance) is amended",
      "signal_source": "corpus",
      "threshold": null
    },
    {
      "trigger_id": "trig-cve",
      "description": "CVE disclosed against a pinned model-serving component",
      "signal_source": "corpus",
      "threshold": null
    },
    {
      "trigger_id": "trig-model-version",
      "description": "Model dependency version change",
      "signal_source": "telemetry",
      "threshold": null
    }
  ],
  "default_violation_behavior": "escalate(CCO)",
  "default_lapse_behavior": "suspend",
  "interpretation_pack_version": "2.0.0-public-demo",
  "corpus_digest": "sha256:3ae372a11e18d782522897ab6e87965e8722901215437c547c70b23904b4f037",
  "policy_pack_digest": "sha256:57945573870df9c0be8458c15b134a67ebc8b775a75014e6f2e9c5b082f7c05f",
  "not_yet_in_force": [],
  "approval_rule": "all_of_concurrences_plus_risk_acceptance",
  "issuer": "licet, Inc.",
  "signature_basis": "demonstration",
  "demonstration_content": true,
  "canonical_digest": "sha256:c97719f28994cb7b0584f1a58ba8342801955499f48917dd1cfbd609dd7dea1b",
  "approvals": [
    {
      "approver": {
        "name": "Priya Raghunathan",
        "role": "Compliance Officer (DSA Art. 41)"
      },
      "approval_type": "risk_acceptance",
      "signed_at": "2026-09-14T09:00:00+00:00",
      "alg": "Ed25519",
      "kid": "priya-raghunathan-demo",
      "signature": "VvhjXEHErtfwsbS5ZYV1bsUk45cgTTq7AlhL9Ofs2aqhTL5DU5gUiKSbfM2bi90CzUi+N2nASW2t33OxfjEtCQ==",
      "attestation_version": "2",
      "issuer": "licet, Inc."
    },
    {
      "approver": {
        "name": "Elena Novak",
        "role": "Data Protection Officer"
      },
      "approval_type": "concurrence",
      "signed_at": "2026-09-14T09:00:00+00:00",
      "alg": "Ed25519",
      "kid": "elena-novak-demo",
      "signature": "IJZ/LWqJiLjo9WuBqlikyhFW2U9TnFNSXAlPbtD7aTXxiNPLHJo1sugK8tf6XTFQufbrvJ63a/fZ9mNjkLRiCQ==",
      "attestation_version": "2",
      "issuer": "licet, Inc."
    },
    {
      "approver": {
        "name": "Nnamdi Okonkwo",
        "role": "Head of Trust and Safety"
      },
      "approval_type": "concurrence",
      "signed_at": "2026-09-14T09:00:00+00:00",
      "alg": "Ed25519",
      "kid": "nnamdi-okonkwo-demo",
      "signature": "FybxINcSFRdTAdTNmtuAxLSsi6CDI9jV8llhu3+NPqbdoG/+ob7GFiJoub4Gh1YSRYNTXZQ/R489hKT3xxIjCQ==",
      "attestation_version": "2",
      "issuer": "licet, Inc."
    },
    {
      "approver": {
        "name": "Tomás Iglesias",
        "role": "Deputy General Counsel, Platform Regulation"
      },
      "approval_type": "concurrence",
      "signed_at": "2026-09-14T09:00:00+00:00",
      "alg": "Ed25519",
      "kid": "tom-s-iglesias-demo",
      "signature": "nDqy0RDbpsSjfBgD+MNGHaDR6Z7GA3D+L3APz5vQk98jSsbabIdQb/n4rQdgPjvv+6x9B0QATXyOieDbd5bdAQ==",
      "attestation_version": "2",
      "issuer": "licet, Inc."
    }
  ]
}
