# Founding-package review and adoption plan

Draft 0.1.0 · October 10, 2026 · Proposed gates, not delivery commitments

The objective is credible institutional recognition, partnerships, and published references built on independently useful investigations. Maintainer capacity, funding, reviewer availability, and partner access are not established. Advance when the evidence for a gate exists; assign dates only after people accept responsibility.

## Gate 1 — Agree on a reviewable scope

Review the charter, Core contract, terminology, architecture, governance, standards crosswalk, and reference cases as one package. Recruit an AI-security practitioner, a conventional incident investigator, an independent implementer, and a standards or evidence-model reviewer. A person may cover more than one perspective; record any concentration.

**Exit evidence:** named accepted roles; a public issue and decision register; explicit licensing questions; resolved or clearly bounded objections about Core versus profiles and overlays. Verify the public access and implementation defects in the prior audit before using the website as the adoption route. A draft package alone does not pass this gate.

## Gate 2 — Make the contract executable

Implement a small producer and reader against pinned candidate artifacts. Expand checks beyond syntax to reference integrity, revisions, uncertainty, actor attribution, policy binding, extension handling, and declared loss. Exercise two cases: suspected unauthorized agent activity and a conventional identity or cloud incident with agent assistance. Use synthetic evidence with explicit labels.

**Exit evidence:** reproducible fixture and validation results; readable case records; documented differences from existing graph releases; known failures; and a migration proposal. Passing schema validation does not establish semantic conformance.

## Gate 3 — Test independent exchange and usefulness

Have an independently authored implementation import, review, amend, and export both cases. Require preservation of identities, evidence relationships, contradictory assessments, policy references, uncertainty, and revision lineage. Include unavailable evidence and unsupported required extensions. Share the specification and fixtures, but disclose shared code that limits independence.

Have investigators perform comparable review and handoff tasks with and without TENSOR. Report participant selection, task order, evidence conditions, review time, missing-context errors, disagreement, and qualitative burden. State sample limitations; do not generalize small demonstrations into universal performance claims.

**Exit evidence:** public exchange artifacts, failure reports, reproducible methods, and a jointly reviewed evaluation. Equal conclusions are not required; unexplained semantic loss is a failed exchange.

## Gate 4 — Seek external stewardship and recognition

Invite substantive review and co-authorship after the evidence exists. Assess suitable standards venues and legal/operational obligations before choosing one. Publish the accepted Core candidate, dissent dispositions, external evaluations, and a funded maintenance plan before proposing a stable release.

Track separately: substantive external contributions, independent implementations, published third-party references, signed partnerships, and formal institutional approvals. A meeting, logo, or self-authored paper is not an endorsement. Candidate twelve-month outcomes are two independent implementations, one external co-authored evaluation, and a recorded stewardship-venue decision; feasibility remains uncommitted.

Outreach, public release, and institutional submissions are subsequent activities. This plan neither sends invitations nor represents agreement by prospective participants.
