Files

23 lines
1.2 KiB
Markdown

# GovOPlaN Voting
`govoplan-voting` owns governed ballot definitions, frozen electorate
snapshots, ballot casting and replacement, deterministic tallying, result
certification, challenges, annulment, and provider evidence.
The native `recorded` assurance profile is auditable but not secret: active
ballots are stored so that a result can be reconstructed. Confidential,
secret, and externally certified profiles fail closed unless an explicit
`voting.provider.<provider>` capability is installed. Providers return only
aggregate results and evidence through the public Voting boundary. The bundled
`local_confidential` provider stores cast selections only as Encryption-owned
server-envelope ciphertext in provider-specific shared SQL tables. It is
confidential at rest, but it is not anonymous, secret, coercion-resistant, or
externally certified.
Committee and other modules retain their deliberation or business context and
refer to Voting ballots through the `voting.ballots` capability. Informal
preference and availability collection remains in `govoplan-poll`.
See [the domain and assurance boundary](docs/VOTING_DOMAIN.md) for operations,
security, recovery, and integration details.