Correction Principle
A Correction creates a new governed state without silently erasing the prior one.
Corrections define how Anchor repairs Anchor-owned errors while preserving the historical record of what was previously published, stored, or relied upon.
A Source Artifact change is not an Anchor Correction. Anchor corrects only information, provenance, integrity material, relationships, or metadata that Anchor itself recorded incorrectly.
A Correction creates a new governed state without silently erasing the prior one.
Source Institutions correct their own artifacts. Anchor corrects only Anchor-owned records and integrity metadata.
A revision, Correction, withdrawal, revocation, or new Version performed by the Source Institution under its own authority.
External AuthorityA governed repair to incorrect Anchor-owned information while preserving the prior production state.
Anchor AuthorityPreserves what was wrong, what changed, which Version carried the error, and which later Version or Integrity Reference resolves it.
RequiredAn error showing that the Integrity Reference was about the wrong integrity subject may require a new Integrity Reference rather than ordinary Versioning.
Material BoundaryExamples of Anchor-owned errors may include:
The following do not become Anchor Corrections merely because they affect what Anchor references:
Anchor may need Maintenance, Reverification, a new Anchor Version, or a new Integrity Reference—but the Source event remains Source authority.
Same subject + Anchor-owned error → Correction + new Anchor Version.
Wrong subject → new Integrity Reference, with lifecycle action on the flawed record.
The Anchor Identifier remains stable because the underlying integrity subject remains the same.
Some errors cannot be repaired as an ordinary Version because they invalidate the identity premise of the original Integrity Reference.
Normal response:
Every production Correction should preserve enough lineage to reconstruct:
Anchor may benefit from a separately identified Correction record if Corrections need durable citation independent of Version history.
Whether Correction Records receive their own permanent identifiers remains intentionally unfrozen until Procedures and first production use prove the need.
Correction Type is now proven to be a useful Controlled Value category.
Initial candidate categories include:
These remain provisional until the first real Corrections demonstrate which distinctions materially affect procedure and reporting.
Enumeration UnfrozenAnchor should not assume every Correction has the same operational impact.
Potential severity distinctions may eventually include:
No severity Controlled Value set is frozen yet. Production should prove whether severity adds durable value beyond Correction Type.
A typo in non-material notes is not equivalent to an incorrect digest.
Procedures may later allow different review thresholds while preserving the same correction lineage standard.
If Anchor stored the wrong Integrity Value for the correct Canonical Representation, the error is Anchor-owned.
The prior incorrect value must remain visible in preserved Version history.
Representation errors require the Versioning subject test.
If Anchor links the Integrity Reference to the wrong Source identifier, Correction, prior Version, superseding record, or commitment, that relationship error belongs to Anchor.
Corrected relationship lineage should preserve both the prior incorrect link and the corrected link through Version history or Correction records.
If Anchor records provenance incorrectly, Anchor may correct:
The Correction should distinguish inaccurate provenance from a later change in the actual process.
Verification may reveal an Anchor error.
A mismatch itself is not automatically a Correction.
Maintenance may identify:
Maintenance should route genuine Anchor errors into Correction rather than silently patching production records.
Correction does not automatically determine Lifecycle State.
The appropriate lifecycle consequence depends on whether the integrity subject remains valid and whether the defect is safely repairable.
Publication should make material Corrections visible.
A canonical public Integrity Reference should identify:
Publication must not create the appearance that the corrected value was always the value originally recorded.
Anchor should never repair a production error by deleting evidence of the erroneous state from institutional history.
Public presentation may emphasize the current corrected state while preserving access to historical Versions.
Later Validation architecture or Production Procedures should confirm:
Corrections should repair Anchor's present record without falsifying Anchor's past.