Overview
Guardstation V2 implements expiring session identity, roles and groups, workspace grants and explicit denies, read-only linked-source boundaries, exact-source approval, immutable policy versions, governed provider routing, bounded context planning, document revision and review gates, controlled research intake, budget reservation, and local audit and usage evidence.
Approval follows the exact source bytes reviewed. Changed bytes lose current approval before later governed use. Document edits similarly break the reviewed-revision relationship; publication creates a separate source that must be governed on its own.
Implemented and documented scope
The reviewed native .NET 8 WPF/SQLite candidate records 109 service checks, 68 native WPF checks, and one synthetic loopback local-provider trial. In the tested path:
- actor, permission, source state, and approved bytes are revalidated before governed model use;
- external access begins off, local loopback research is separately labeled, and there is no silent external-provider fallback;
- human review binds a specific document revision, while decisions, actions, usage, and cost are recorded locally for later inspection;
- one synthetic loopback trial exercised the governed local-provider path against an approved source and returned the recorded citation; it does not establish general model quality or legal reliability.
Project architecture and governance invariants are documented. A master order references a provisional specification, but that authority was not staged with the recovered implementation, so filing scope and status are not asserted.
Limits and open work
The candidate remains unsigned and local, formal local review was pending, and ten V1 parity areas remained unknown or unverified in the recovered record. Validation is predominantly synthetic: only one local model/runtime was exercised live, external providers were mock-tested, and public browsing was not physically validated.
- OCR, encrypted PDFs, and complex Word round trips are unsupported.
- Retrieval, citation checking, and secret detection are not presented as infallible.
- Application controls do not protect against an administrator who controls the Windows account or disk; the local hash chain is application-level tamper evidence, not external notarization.
- The record does not establish production readiness, legal accuracy, regulatory compliance, generalized model quality, or absolute security.
Broader claims require additional providers, public browsing, non-synthetic material, and environments beyond the present local trust boundary. Detection rules, enforcement internals, credential handling, bypass analysis, and exact audit mechanics remain withheld.