Every deployable artifact has one digest, one parent, build provenance, and a release manifest.
Let it improve.
Keep the robot identifiable.
A 10,000-hour robot should learn and receive fixes. Profile 0.2-U1 makes every operator-deployed model, planner, controller, and configuration artifact reconstructible—without confusing personalization with a silent replacement.
Updates are expected.
Substitution is not.
The policy clock assigns every resident second to exactly one immutable artifact. Signed telemetry boundaries connect that clock to the exposure ledger.
Current-cohort outcomes and task logs cannot inform a release decision.
Transitions follow a frozen global or staged schedule, never participant-specific targeting.
Capability-changing exposure cannot be blended into the same ranked claim.
Frozen algorithm.
Evolving state.
On-device personalization stays inside one artifact only when its learning algorithm, inputs, update rule, and permitted state are frozen in the baseline digest. Operator-deployed weights, prompts, planners, controllers, or configurations are updates.
Measured separately by profile 0.2-LG1.
New digest, release manifest, rollout, and exposure segment.
Never commingled with the existing ranked cohort claim.
Trace every release.
Rebuild every hour.
The verifier checks artifact lineage, prospective decisions, bounded rollout, signed boundaries, exact policy-specific exposure, target coverage, and independent evidence bindings locally.
Policy evolution is disclosed context. It cannot change W, offset a safety failure, or break a leaderboard tie.
OPEN CERTIFICATION MATRIX ->