the error register
NIKA-SEC-014
the affirmative-consent law — a confirm-mode human gate (invoke: nika:prompt · mode absent or confirm) reaches an egress-capable task over a route no affirmative gate closes: a REFUSED confirm settles success with value false, so a bare after: { gate: success } edge, a when: that never reads the answer, and a when: provably true on the refusal all let the effect through · the gate is credited only when every route consumes the answer and proves false on it (the Kleene-falsifiable when: · when: false · a closer confirm gate owns its closure) · an undecidable gate (a nested binding · a non-fragment expression) defers to the advisory hint, never a refusal (NEP-0020 · P0-2 of the 2026-07-30 audit). A typed refusal, one of 103 the registry names: stable code, spec category, the transient flag the retry machinery reads. The engine stamps this page's address on the finding itself. Route on the code, never on prose. Machines read the catalog.
- security_errorcategorya security policy refused the effect
- stablea retry cannot helpfix the file, not the timing
- 14of 14 in NIKA-SECprev / next walk the registry
- 103registered codesthe normative floor · versioned
hear it from the binary
nika explain NIKA-SEC-014 answers offline with the failure, the fix shape and this page's address: the same text the check finding carries. A code is a contract: never renamed, never repurposed, safe to route on in on_codes and retry policy.
cross-references
the family it sits in
the NIKA-SEC codes
14 codesBreak a file on purpose in the playground and watch the code arrive typed. The boundary teaches the security family. Read the spec →