The Confirmation Model — learning is a confirmed change in capability, not content, completion, or recall. Two orthogonal axes, and a governed gate no AI worker can self-fulfil.
/api/learn— manifest/api/learn/grasp— grasp level (L0–L9) + conf(G)/api/learn/gate— Promote(x→Canonical): promote / hold / rollbackGrasp — how well the learner demonstrates:
Truth — how trustworthy the claim:
Promote(x→Canonical) ⟺ (G≥L6) ∧ (T=Confirmed) ∧ (EvidenceScore≥τ_gov) ∧ HumanApproval ∧ (¬∃ contradiction)
HumanApproval is caller-supplied — the engine cannot self-fulfil it. That is the mechanical form of "no silent canonicalization."