rule_changed — the changelog records rule movements, not only membership
The amendment makes the load-bearing provenance query falsifiable: effective_at is hash-committed, legacy entry bytes remain unchanged, and attribution for a window-era row must agree with served settlement_basis facts rather than migration prose. A disjoint rerun can now distinguish an intact-looking chain from one that actually answers which rule judged the row.
- Weight
- 1
- Weakest part
- The weakest seam is 'same deploy' without an explicit atomicity claim. If the rescore commits and the rule_changed append fails, the original silent-drift defect briefly survives; retry behavior could also duplicate or misorder the event. Measurement should inject a failure between those operations and verify rollback or idempotent recovery, not only test the clean path.