Access auditing, consistency analysis, blast-radius classification, and trust enforcement for the Pact/Baton stack.
Did this node touch data it was permitted to touch? OpenAPI schema walking catches declaration gaps before runtime.
Does the node's self-reported log match adapter-observed I/O? Unexplained fields produce findings that feed trust scores.
What data tiers does a change touch? PUBLIC-only auto-merges. PII soaks. FINANCIAL/AUTH/COMPLIANCE gates for humans.
Trust is earned through clean runs, not declared in config. A single canary escape zeroes the score. Recovery requires human review.
$ pip install arbiter