Source standard
Material factual claims must meet the published source threshold. Every load-bearing fact in a record needs either one Tier-1 source or two independent Tier-2 sources. Tier 1 is a court, a regulator, a legislature, a royal commission, a national investigator, a dual-party forensic disclosure, or a first-party account by a named party to the event. Tier 2 is established trade or business press with named reporting. Tier 3, which includes vendor incident trackers and marketing research, is used to find candidates and never as ground truth for a published fact. Sources are labelled on each record as Primary for Tier 1, Secondary for Tier 2, and Cross-reference for catalogue entries.
Where a material claim rests on a single interested source, disputed attribution or incomplete public evidence, the limitation is stated directly in the record.
Three kinds of statement
Confirmed fact. Information established by an authoritative source or corroborated across qualifying independent sources.
Source-stated cause. An explanation or allegation attributed to the person, organisation, investigator or publication making it.
Architectural analysis. Regulayer’s analysis of the authority and control structure surrounding the event. It is identified as analysis and is not presented as an adjudicated fact.
Gap codes
Every record carries one primary gap, the failure without which the consequence does not occur as documented, and any number of secondary gaps. A primary gap must be supported by a Tier-1 or Tier-2 source. Secondary gaps may be analysis and are shown as such.
| Code | Gap | Meaning |
|---|---|---|
| A | authority | No legitimate authority for the action |
| B | stale-authority | Authority outlived its grant: the instruction changed, the permission did not |
| C | pre-action control | No gate between the decision and the execution |
| D | permission / tool-use | Permission, credential or tool scope exceeded the purpose |
| E | human review | Human review absent, nominal, or structurally impossible |
| F | evidence | No contemporaneous, trustworthy record of what happened |
| G | governance inside the system | The system governed itself: the rules lived inside the model context |
| H | fail-stop | No working stop path, or stop signals ignored |
| I | provenance | Origin or chain of outputs, instructions or data unverifiable |
| J | network dependency | Failure propagated across a network or dependency boundary |
Severity
Severity describes the documented consequence that occurred. It does not measure the theoretical capability of the system or the seriousness of an event that did not occur.
| Tier | Threshold, any one suffices |
|---|---|
| S1 | Death or serious injury; population-scale rights or benefit harm; entity-ending outcome; loss at or above $100m |
| S2 | Multi-million-dollar loss; systemic denial of care or benefits affecting thousands; company shutdown; criminal resolution |
| S3 | Material data loss or outage; regulatory action; binding precedent with small direct damages |
| S4 | Contained harm; small monetary loss; rapid remediation |
| S5 | No realised external harm; controlled demonstration or pre-exploitation patch |
Confidence, graded twice
Records carry two confidence grades, because the two questions come apart. A breach can be certain while the claim that AI drove it rests on one company's word.
| Tier | Meaning |
|---|---|
| C1 | Adjudicated or regulator-grade: court opinion, regulator order, royal commission, national investigator, or dual-party forensic disclosure |
| C2 | Multi-source corroborated: independent outlets plus named first-party statements, consistent on the facts |
| C3 | Single-source or vendor-asserted: one credible source, a self-report, or a vendor disclosure without independent validation |
| C4 | Disputed: material facts contested by a named party. Both accounts are published side by side and neither is adjudicated |
What is never published
No preventability flags. No claim that any control or product would have prevented an outcome. No vendor scores, rankings or comparisons. No record below the source standard, however useful the gap would be to fill. Candidates that fail the standard are held, and the reason is published with them.
Updating and corrections
Records are reviewed when material litigation, regulatory, investigative or disclosure developments occur. Material changes and corrections are dated in the record history.
To report an error, write to hello@regulayer.com with the record name and the source you believe should be reviewed.
