# Threat model
akicita sits between a self-acting system and its mutation surface. The
assumption is the acting component is *competent but not trusted*: it
generates proposals, the marshal decides whether they land.
## What akicita defends against
- **Runaway self-modification.** Blast-radius caps and rate limits bound
how much change one run can land, and how fast.
- **Constitutional damage.** Protected surfaces never auto-apply at any
level — the system cannot edit its own governor, policy engine, or
control files without a human.
- **Retry storms.** Fingerprint dedupe prevents a denied/held proposal
from being refiled until it falls out of the dedupe window.
- **Silent drift.** Every decision is journaled; an operator can replay
what was permitted, held, and denied, and why.
## What it does not defend against
- **A hostile proposal generator.** If the model proposing changes is
adversarial, akicita bounds its *rate and radius* but cannot judge
intent — pair it with a deliberation layer (e.g. `xipe`) for that.
- **Fingerprint gaming.** Dedupe hashes caller-provided fingerprint
material; a generator that rewrites equivalent patches trivially
defeats dedupe by construction. Dedupe is an ergonomics feature, not
a security boundary.
- **Level-file tampering.** The operator-controlled level file is a
trust boundary: whoever can write it sets autonomy. Protect it with
filesystem permissions, not with this crate.
- **Time-of-check races.** `check` and the caller's `apply` are two
steps; a concurrent mutation between them is out of scope.
## Design posture
Denials are cheap, holds are honest, and the record is append-only.
When in doubt the marshal holds — an oversize patch is escalated to a
human rather than rejected outright.