Leakage profile
What each observer learns, per transition. This table is normative: a change to it is a protocol change, and §9 pins it with tests.
| Observer | Initiate | Resolve | Reclaim |
|---|---|---|---|
| Public / pool | sender FI, recipient FI, 2 nullifiers, 1 commitment, payment_root, deadline bucket, time bucket, fee, envelope size, salted state roots and attestation | hold identity (via payment_root), recipient FI (already known), 1 commitment, time bucket, salted state roots and attestation. Not whether it was accept or reject. | hold identity, 1 commitment, time bucket. That the hold was never resolved. |
| Sender FI | all regions except nothing (it holds the plaintext); recipient FI identity | outcome, by recognizing refund_commitment if it appears | outcome |
| Recipient FI | shared, payload, sender_private_root (opaque), sender FI identity (phase leaf), attestation preimage | its own decision | that the hold expired |
| Recipient | shared, payload | outcome | that the hold expired |
Reclaim is the one distinguishable resolution. It reveals that the recipient FI did not resolve in time, which is less sensitive than a rejection; making reclaim uniform would require a fourth policy phase and is deferred.