Six facts only you can supply
Without intent, most obligations are conditional and unanswerable. So Clearance requires all six — and an omitted field evaluates to UNKNOWN, never to a default. Defaulting mau to 0 or territories to global would mean the tool invents facts and then reasons from them.
An ignore without a reason is refused (E-CFG-005), and an ignore covering more than half the tree raises E-SCAN-020. Ignored paths are recorded in the verdict so a reader can see what was skipped.
schema_version: 1 project: name: my-saas description: A hosted document-analysis service. use: commercial: true licence_model: closed-source modified: true # the §13 trigger network_exposed: true # with modified distributed: false saas: true scale: mau: 5000 employees: 2 revenue_eur: 40000 territories: - EU - US - GB policy: never_allow: - AGPL-3.0-only - AGPL-3.0-or-later block_on: - BLOCK allow_if: - licence: LGPL-3.0-only when: op: "==" field: use.modified value: false ignore: - path: "vendor/legacy-internal-only/**" reason: "internal tooling, never distributed"
A user-level config supplies defaults; a project config overrides field by field. The resolved config is hashed into meta.intent_hash, so every verdict is traceable to the exact intent that produced it.
Every field that can change a verdict is written out and has to be answered. Nothing that can change a verdict is inferred. The tool does not guess intent — not even helpfully.
schema_version: 1 use: # all six are required commercial: true # are you charging? licence_model: closed-source modified: false # do you edit vendored code? network_exposed: true # is it reachable over a network? distributed: false saas: true