HISTORICAL DEMO · AMB-2024-0004
The authorization record
Historical artifact — known defects, preserved unchanged. This earlier example has 2024 signatures paired with 2026 interpretations, duplicated reasoning and incomplete applicability information. It is not the current reference example. Preserving its bytes is not an endorsement of its contents.
Read the corrected 2026 example ↗Legacy spam triage classifier · Historical demonstration
A licet record captures your institution’s approved interpretation of its obligations. It records what you decided and who accepted it. It does not state what the law permits.
| Record | AMB-2024-0004 · v1 |
|---|---|
| Lifecycle snapshot | Authorized in this demonstration export. Not a live registry status. |
| Issue / expiry | 2024-03-15 / 2027-03-15. Expiry alone does not establish current validity. |
| Boundary | amb-2024-0004 · v1 |
| Risk acceptor | Priya Raghunathan · Compliance Officer (DSA Art. 41) |
| Recorded conditions | 10 |
| Approvals | 3 Ed25519 demonstration approvals. This page is a readable projection; the homepage checks the MER-2026-0001 signatures in your browser. |
| Operational assurance | Not assessed. Evidence requirements are not collected results. |
| Legal compliance | Not determined. |
The recorded conditions.
moderation · terms basis requiredArt. 14(1)
This system may not restrict, remove, demote, or otherwise act against user content except on a ground published in Meridian's terms and conditions and in force on the date of the action.
| Source reference | Regulation (EU) 2022/2065 · Art. 14(1) |
|---|---|
| Institutional interpretation | Meridian reads the terms and conditions duty as binding on machines as well as on people. An enforcement action taken by an automated system is an action taken by Meridian, so the ground for it must already be published before the system takes it. A system that can act on a ground the terms do not name has, in effect, amended the terms without publishing them. |
| Interpretation attribution | int-moderation-001 · Tomás Iglesias · 2026-03-04 · Fictional demonstration |
| Policy | PLT-POL-125 · v1 |
| Approving role | Deputy General Counsel, Platform Regulation |
| Declared control | Enforcement taxonomy bound to the published terms; an action carrying no mapped clause is refused at the enforcement gateway rather than logged as an exception. |
| Evidence required | Record, for every enforcement action, the terms clause relied on and the version of that clause in force at the time of the action. |
| Collection requirement | Retrieve every enforcement action attributed to this boundary with its cited terms clause and clause version, and return any action with no mapped clause. |
| Revalidation watch | trig-regulation-amendment, trig-periodic |
statement of reasons · per decision statementArt. 17(1)
Every restriction this system imposes emits a statement of reasons to the affected user containing the facts relied on, the ground for the action, and the redress available.
| Source reference | Regulation (EU) 2022/2065 · Art. 17(1) |
|---|---|
| Institutional interpretation | A statement of reasons is the only artifact a restricted user is guaranteed to receive. Meridian treats it as the output of the enforcement decision rather than a notification generated after it, which means a system that cannot produce one cannot take the action. |
| Interpretation attribution | int-sor-001 · Priya Raghunathan · 2026-02-18 · Fictional demonstration |
| Policy | PLT-POL-134 · v1 |
| Approving role | Compliance Officer (DSA Art. 41) |
| Declared control | The statement is produced by the same transaction as the enforcement action; an action that cannot produce one does not commit. |
| Evidence required | Record a statement of reasons identifier against every restriction this system imposed. |
| Collection requirement | Retrieve every restriction attributed to this boundary with its statement of reasons identifier, and return any restriction with none. |
| Revalidation watch | trig-regulation-amendment, trig-periodic |
statement of reasons · automated means disclosedArt. 17(3)(c)
A statement of reasons issued for an action this system took may not omit that automated means were used. Silence about automation is a defect in the statement, not a permitted economy.
| Source reference | Regulation (EU) 2022/2065 · Art. 17(3)(c) |
|---|---|
| Institutional interpretation | The obligation to state whether automated means were used is read here as a floor that cannot be satisfied by silence. Where a statement of reasons is generated for an action an automated system took, the absence of the automation disclosure is itself a defect in the statement. |
| Interpretation attribution | int-sor-002 · Priya Raghunathan · 2026-02-18 · Fictional demonstration |
| Policy | PLT-POL-132 · v1 |
| Approving role | Compliance Officer (DSA Art. 41) |
| Declared control | The automation disclosure field is populated from the acting identity rather than from the drafter, so it cannot be left empty by an author. |
| Evidence required | Record the automation disclosure carried by every statement of reasons this system generated. |
| Collection requirement | Retrieve statements of reasons generated for this boundary and return any whose automation disclosure field is absent or negative. |
| Revalidation watch | trig-regulation-amendment, trig-periodic |
statement of reasons · database submissionArt. 24(5)
Each statement of reasons is submitted to the Commission's public transparency database, without the personal data of the affected user.
| Source reference | Regulation (EU) 2022/2065 · Art. 24(5) |
|---|---|
| Institutional interpretation | A statement of reasons is the only artifact a restricted user is guaranteed to receive. Meridian treats it as the output of the enforcement decision rather than a notification generated after it, which means a system that cannot produce one cannot take the action. |
| Interpretation attribution | int-sor-001 · Priya Raghunathan · 2026-02-18 · Fictional demonstration |
| Policy | PLT-POL-133 · v1 |
| Approving role | Compliance Officer (DSA Art. 41) |
| Declared control | Submission runs from the statement record through a field allowlist; a field outside the allowlist fails the submission rather than being redacted silently. |
| Evidence required | Record the submission identifier and outcome for every statement of reasons this system generated. |
| Collection requirement | Retrieve statements of reasons for this boundary with their transparency database submission identifier and outcome, and return any not submitted. |
| Revalidation watch | trig-regulation-amendment, trig-periodic |
appeals · internal complaint routeArt. 20(1)
Every action this system takes carries a route into internal complaint handling that stays open for six months from the date of the decision.
| Source reference | Regulation (EU) 2022/2065 · Art. 20(1) |
|---|---|
| Institutional interpretation | Internal complaint handling is where an automated enforcement decision is tested against a person. Meridian's reading of Article 20(6) is that the review must be capable of reversing the original decision, which an automated reviewer trained on the same signal as the original decision is not. |
| Interpretation attribution | int-appeals-001 · Priya Raghunathan · 2026-02-25 · Fictional demonstration |
| Policy | PLT-POL-103 · v1 |
| Approving role | Compliance Officer (DSA Art. 41) |
| Declared control | The complaint route is minted with the enforcement record and expires on a stored date rather than on a deployment. |
| Evidence required | Record the complaint route issued with each action and the date it closes. |
| Collection requirement | Retrieve actions attributed to this boundary with their complaint route and closing date, and return any action with no open route inside the six month window. |
| Revalidation watch | trig-regulation-amendment, trig-periodic |
systemic risk · pre deployment assessmentArt. 34(1)
The systemic risk assessment covering this system is complete and signed before deployment, and names which of the four risk categories it considered.
| Source reference | Regulation (EU) 2022/2065 · Art. 34(1) |
|---|---|
| Institutional interpretation | The risk assessment and the mitigations are the platform's own account of itself, and an auditor tests that account. Meridian's reading is that a mitigation described in the assessment and not implemented as a condition on a live authorization is a finding waiting to be made, which is why the two are linked here rather than filed separately. |
| Interpretation attribution | int-systemic-001 · Priya Raghunathan · 2026-05-06 · Fictional demonstration |
| Policy | PLT-POL-140 · v1 |
| Approving role | Compliance Officer (DSA Art. 41) |
| Declared control | The release gate reads the assessment signature; an unsigned or category-incomplete assessment holds the deployment. |
| Evidence required | Retain the signed systemic risk assessment in force for this system and the risk categories it addressed. |
| Collection requirement | Historical omission: no collection method was recorded in this artifact. No attestation or collected result is implied. |
| Revalidation watch | trig-regulation-amendment, trig-periodic |
systemic risk · mitigation traceableArt. 35(1)
Each mitigation this system is credited with in the risk assessment maps to a condition on this authorization, so a mitigation that was only described is visible as one that was never implemented.
| Source reference | Regulation (EU) 2022/2065 · Art. 35(1) |
|---|---|
| Institutional interpretation | The risk assessment and the mitigations are the platform's own account of itself, and an auditor tests that account. Meridian's reading is that a mitigation described in the assessment and not implemented as a condition on a live authorization is a finding waiting to be made, which is why the two are linked here rather than filed separately. |
| Interpretation attribution | int-systemic-001 · Priya Raghunathan · 2026-05-06 · Fictional demonstration |
| Policy | PLT-POL-139 · v1 |
| Approving role | Compliance Officer (DSA Art. 41) |
| Declared control | Mitigations carry condition identifiers; the reconciliation runs on assessment publication and on every re-derivation. |
| Evidence required | Retain the mapping from each mitigation claimed for this system to the condition that implements it. |
| Collection requirement | Historical omission: no collection method was recorded in this artifact. No attestation or collected result is implied. |
| Revalidation watch | trig-regulation-amendment, trig-periodic |
systemic risk · audit evidence retainedArt. 37(1)
Evidence sufficient for an independent auditor to reach a conclusion about this system is retained and reachable without the cooperation of the team that operates it.
| Source reference | Regulation (EU) 2022/2065 · Art. 37(1) |
|---|---|
| Institutional interpretation | The risk assessment and the mitigations are the platform's own account of itself, and an auditor tests that account. Meridian's reading is that a mitigation described in the assessment and not implemented as a condition on a live authorization is a finding waiting to be made, which is why the two are linked here rather than filed separately. |
| Interpretation attribution | int-systemic-001 · Priya Raghunathan · 2026-05-06 · Fictional demonstration |
| Policy | PLT-POL-138 · v1 |
| Approving role | Compliance Officer (DSA Art. 41) |
| Declared control | Audit evidence is replicated to a store whose access is granted by the compliance function rather than by the operating team. |
| Evidence required | Retain the audit evidence set for this system in the independently reachable store. |
| Collection requirement | Retrieve the audit evidence set for this boundary and return any period where the independent store was not current. |
| Revalidation watch | trig-regulation-amendment, trig-periodic |
crisis · one hour removal capabilityArt. 3(3)
This system does not stand between a removal order for terrorist content and its execution. The one-hour path stays available while this system is running and while it is not.
| Source reference | Regulation (EU) 2021/784 · Art. 3(3) |
|---|---|
| Institutional interpretation | The one-hour clock runs against Meridian, not against the system that happens to be handling the content. Any automated system placed in that path must therefore be removable from it without a deployment. |
| Interpretation attribution | int-crisis-001 · Nnamdi Okonkwo · 2026-03-12 · Fictional demonstration |
| Policy | PLT-POL-106 · v1 |
| Approving role | Head of Trust and Safety |
| Declared control | The removal path bypasses the agent entirely and is exercised on a schedule against a synthetic order to prove it is still reachable. |
| Evidence required | Record each exercise of the one-hour removal path and the elapsed time it achieved. |
| Collection requirement | Retrieve one-hour path exercises covering this boundary and return any exercise that exceeded the hour or did not run. |
| Revalidation watch | No standing event subscription in this demonstration rule. Its required exercise evidence must be reviewed separately. |
crisis · protocol hook presentArt. 36(1)
This system exposes a control the crisis protocol can use to suspend or narrow its behaviour without a code deployment.
| Source reference | Regulation (EU) 2022/2065 · Art. 36(1) |
|---|---|
| Institutional interpretation | A crisis response mechanism that requires a code change to engage is not a mechanism. Meridian reads the article as requiring a control surface that exists before the crisis does. |
| Interpretation attribution | int-crisis-002 · Nnamdi Okonkwo · 2026-05-13 · Fictional demonstration |
| Policy | PLT-POL-107 · v1 |
| Approving role | Head of Trust and Safety |
| Declared control | A runtime capability flag is read on every action; the crisis protocol writes it and the system does not cache it across actions. |
| Evidence required | Retain the crisis capability flag this system reads, and the identity of the protocol that may write it. |
| Collection requirement | Historical omission: no collection method was recorded in this artifact. No attestation or collected result is implied. |
| Revalidation watch | No standing event subscription in this demonstration rule. Its required exercise evidence must be reviewed separately. |
Recorded approvals.
- Priya Raghunathan · Compliance Officer (DSA Art. 41) · risk acceptance · 2024-03-15T09:00:00+00:00
- Nnamdi Okonkwo · Head of Trust and Safety · concurrence · 2024-03-15T09:00:00+00:00
- Tomás Iglesias · Deputy General Counsel, Platform Regulation · concurrence · 2024-03-15T09:00:00+00:00
Check the artifact, not the rendering.
The download is the engine’s signed document, byte for byte. This page is a readable projection. The demonstration public keys are not an independent identity trust service.
sha256:c3cfc86a5c62a36cccd9ae9c4655e319c3976e3031205719b53157750826e9ef
Download the standalone verifier (v0.1.1) ↓. It requires Python 3.12 or later and the cryptography package; no licet application installation is needed. In an isolated Python environment, install the wheel and run:
python -m pip install ./licet_verifier-0.1.1-py3-none-any.whl licet-verify sample-record.json --jwks demonstration-jwks.json
Verification checks payload integrity and signatures. It does not establish real-world signer identity, control effectiveness, current authorization status or legal compliance. The record explorer is not connected to an enforcement point.
Discuss a record for your system ↗