Correction requirements
A correction identifies the packet SHA-256, affected claim or field, requested change, reason, and at least one HTTPS evidence source. Do not include contact details, private ownership records, credentials, or documents without sharing authority.
Maintainers preserve the original packet and append the correction decision. Accepted changes create a new version and digest; they never silently rewrite the reviewed revision. Rejected and unresolved corrections retain a reason.
The machine-readable envelope schema resolves at
`/schemas/research-correction-envelope/v1`. An envelope targets one allowlisted
claim, contradiction, or alternative-hypothesis field and binds the proposal to
the exact original packet digest, evidence URLs, consented pseudonymous
contributor code, and its own canonical digest. Direct identifiers and
conclusive authentication, novelty, or legal language are rejected.
Researchers can assemble the same envelope entirely in their browser on
`/research/contribute`. No form value is transmitted or retained by Meta
Museum. The page requests only the packet digest, allowlisted target, proposed
value, reason, HTTPS evidence URLs, a pseudonymous code, attribution preference,
AI-assistance disclosure, and consent. The resulting JSON stays under the
researcher's custody unless they choose to share it.
Operators configure `config/research-correction-propagation.json` with the exact
original packet and correction-envelope files plus their raw-file SHA-256
receipts, then run `pnpm research:correction-propagate`. The command retains the
original packet and produces a distinct candidate digest with an appended
`pending-accountable-human-review` decision. It never overwrites the original
or marks the correction accepted.
The successful propagation artifact retains canonical base64 for both exact input
files, limited to 2 MB each, plus their raw SHA-256 receipts. Its verifier decodes and
rehashes both files, revalidates the finalized original and correction envelope,
reruns the allowlisted edit, and requires canonical equality for the complete signed
artifact. Editing the candidate, revision chain, publication flag, correction record,
or retained inputs and merely recomputing the outer digest does not pass. Because the
envelope may contain a pseudonymous contributor code, this operator artifact remains
under controlled local custody unless separately approved for disclosure.
Attribution
Contributors choose public name or researcher identifier, a pseudonymous reviewer code whose identity mapping is held privately, or anonymous public credit with an accountable maintainer retaining the approval record. Authorship, evidence contribution, correction, review, and editorial approval remain distinct. AI systems are disclosed as assistance and never treated as accountable authors or expert reviewers.
Evidence boundary
Acknowledgement is not acceptance. A correction counts as external-impact evidence only after it is independently attributable, evidence-backed, accepted, and bound to a released revision. Emails, issue creation, clicks, and automated suggestions do not count.
Synthetic sample packets are rejected from propagation. A generated correction
candidate is not external impact, a materially corrected investigation, or a
publication-ready release until an accountable independent human reproduces the
evidence and explicitly accepts the change through the separate validation and
publication controls.