Consent / Revocation Propagation Simulator v0.0.4 — Sensitivity Drivers + Flip Trace Patch

Did the boundary survive the handoff?

Consent is not a checkbox. It is a living boundary that has to travel. Revocation is not erasure. It is a boundary delta that must reach every affected branch.

A consent boundary is only real if revocation can reach the branches.

Most systems ask: did the user consent?

This simulator asks: consent to what, for whom, for how long, under what scope, with what revocation path, and can that revocation reach every branch?

This simulator does not provide legal advice, HIPAA compliance certification, privacy-law analysis, or clinical authorization. It maps whether a consent boundary remains structurally intact under handoff, downstream reuse, retention, and revocation pressure.

Dual boundary equations

S_consent = A_authorization × B_scope − P_revocation_drift
S_revocation = R_notice × C_chain × E_enforcement − P_residue

The first path tests whether consent carried with scope intact. The second path tests whether a revocation or scope change can propagate through downstream branches.

v0.0.4 patch: sensitivity drivers, flip traces, and top route-change contributors. Route logic, thresholds, presets, and shareable state unchanged.

Explain this to me as…

This tool checks whether a consent boundary stayed clear, scoped, current, revocable, and enforceable as it moved through downstream systems.

Consent event → handoff → downstream branches

Original Consent / Boundary

Downstream Use / Revocation Event

v0.0.1 does not automatically analyze text. These fields preserve scenario context for the export report while sliders model boundary and propagation conditions.

Simulator

v0.0.1 route note: repair, revocation, quarantine, and human review override ordinary consent-active routing.

Authorization / consent side

Scope side

Propagation pressure side

Revocation propagation side

Route gates

Revocation Propagation State
boundary delta / downstream enforcement
REVOCATION PROPAGATING

Revocation Support
Residue Pressure
Propagation Stability
Boundary Delta Strength
Read:

Why this route?

Action:

Revocation Flags

Route stability sensitivity

Click “Test route stability ±10%” to see whether the current routes are stable, threshold-adjacent, fragile, or override-locked under small slider perturbations.

Consent Route
Revocation Route
Overall Stability

Top sensitivity drivers / flip trace

Consent route flips
  1. No sensitivity run yet.
Revocation route flips
  1. No sensitivity run yet.

Exportable consent-boundary report

How the model works

S_consent = A_authorization × B_scope − P_revocation_drift
S_revocation = R_notice × C_chain × E_enforcement − P_residue

Consent granted is not enough. Consent carried is the real test.

Revocation received is not enough. Revocation propagated is the real test.

Revocation propagates as a boundary delta, not erasure. History and audit spine remain preserved, but downstream authorization is downgraded, stopped, quarantined, or re-proofed according to the affected scope.

Where:
A_authorization = explicit authorization, informed understanding, currency, identity/authority match, and consent record availability.
B_scope = purpose clarity, recipient clarity, data/action boundary, duration clarity, and revocation-path visibility.
P_revocation_drift = downstream branch count, transfer opacity, retention friction, automation lag, and institutional/commercial incentive.
R_notice = revocation notice clarity.
C_chain = downstream chain visibility.
E_enforcement = enforcement ability and confirmation returned.
P_residue = residual copy/cache risk plus downstream drift pressure.

Route transparency / math disclosure

Why this matters:
Consent granted is not enough. Consent carried is the real test.
Revocation received is not enough. Revocation propagated is the real test.
Revocation propagates as a boundary delta, not erasure.

Show route logic / show the math
Consent carry path
A_authorization = 0.25×Explicit Authorization + 0.20×Informed Understanding + 0.18×Current Consent + 0.20×Identity/Authority Match + 0.17×Consent Record

B_scope = 0.24×Purpose Clarity + 0.20×Recipient Clarity + 0.22×Data/Action Boundary + 0.16×Duration Clarity + 0.18×Revocation Path Visible

S_consent = A_authorization × B_scope − P_revocation_drift
Revocation propagation path
P_revocation_drift = average downstream branch count, transfer opacity, retention friction, automation lag, and institutional/commercial incentive.

S_revocation = R_notice × C_chain × E_enforcement − P_residue

P_residue = residual copy/cache risk plus retention, opacity, and automation residue.
Override order
Repair debt overrides ordinary consent evaluation. Full revocation overrides active consent. Downstream quarantine overrides convenience when branches cannot be verified. Sensitive/high-stakes contexts can require human review.
Boundary rule
Revocation does not erase the audit spine. It travels forward as a boundary delta: stop, downgrade, quarantine, re-proof, retain with limits, or repair according to affected scope.
PresetConsent Carry RouteRevocation RouteConsent StabilityRevocation Stability
Clean Bounded ConsentCONSENT_ACTIVEREVOCATION_READY0.580.29
Ambiguous App PermissionSCOPE_MISMATCHNO_REVOCATION_ACTIVE-0.44-0.59
Patient EHR Consent RevocationREVOKED_SCOPEDOWNSTREAM_QUARANTINE-0.14-0.47
Health Data Partial RevocationPARTIAL_REVOCATIONHUMAN_REVIEW_REQUIRED-0.01-0.30
Caregiver / Proxy Boundary DriftHUMAN_REVIEW_REQUIREDNO_REVOCATION_ACTIVE-0.17-0.35
AI Agent Tool Permission DriftSCOPE_CLARIFICATION_REQUIREDNO_REVOCATION_ACTIVE-0.34-0.47
Public Platform Data ReuseRETENTION_LIMIT_REQUIREDNO_REVOCATION_ACTIVE-0.63-0.76
Revocation Lost DownstreamREVOKED_SCOPEDOWNSTREAM_QUARANTINE-0.38-0.78
Prior Consent Boundary HarmREPAIR_REQUIREDREPAIR_REQUIRED-0.52-0.71

Route stability / sensitivity

A boundary route can be stable, fragile, threshold-adjacent, or override-locked. This patch perturbs each slider by ±10% and checks whether the recommended consent or revocation routes change. v0.0.4 also records the flip trace: which slider moved, in which direction, and which route it changed from/to.

Stable Route
The same route survives small pressure changes. The boundary diagnosis is not near a threshold.
Threshold Adjacent
A few small slider shifts change the route. The case is close enough to a boundary that review or re-proof may be prudent.
Fragile Route
Many small slider shifts change the route. The boundary state is unstable and should not be treated as cleanly resolved.
Override Locked
A hard gate such as repair debt, full revocation, or partial revocation is active. Slider softness does not override the boundary gate.

Route taxonomy

Defensive boundary

This simulator maps consent-boundary degradation for review, repair, education, and defensive design. It does not provide instructions for bypassing consent, evading revocation, retaining data improperly, or exploiting downstream copies.