{
  "repo_root": "/home/runner/work/app/app",
  "taken_at": "2026-10-08T04:38:41.126Z",
  "engine_version": "0.1.0",
  "constitution_version": "1.1",
  "documents": [
    {
      "number": "00",
      "filename": "00-INDEX.md",
      "title": "KYE Protocol™ — Constitution Index",
      "status": "Adopted 2026-05-29",
      "section_count": 7,
      "sha256": "626cbaabd09613fb535fc30fb2725c7afeb3985e90111da7d42c7d3ca5159feb"
    },
    {
      "number": "01",
      "filename": "01-NAMING.md",
      "title": "KYE Protocol™ — Naming, Rails & Surfaces Lock (v1.0)",
      "status": "locked",
      "section_count": 20,
      "sha256": "614cf4e9e06e24200c3ff5c0898428dcce29db362d177440b382f946deba4945"
    },
    {
      "number": "02",
      "filename": "02-INFORMATION-ARCHITECTURE.md",
      "title": "KYE™ Information Architecture (v1.0 — locked blueprint)",
      "status": "locked",
      "section_count": 15,
      "sha256": "8842f04f8550af7c71da2b74c31aa96af1af8d482cb46179ffae860c511a7adb"
    },
    {
      "number": "03",
      "filename": "03-DESIGN-MIGRATION.md",
      "title": "KYE™ Design-System Migration — multi-week plan",
      "status": "locked",
      "section_count": 4,
      "sha256": "cbeaa7f8cce982992e23d5614957c09d5f17dd5aa05875f79abddcd38fd59911"
    },
    {
      "number": "04",
      "filename": "04-DESIGN-SYSTEM.md",
      "title": "KYE™ Design System Reference — Portable Kit",
      "status": "locked",
      "section_count": 14,
      "sha256": "adf99813315a1aec4659c7ff9e652bf5f2683073ebd4c616c0bac8c0a2b22b14"
    },
    {
      "number": "05",
      "filename": "05-GITHUB.md",
      "title": "GitHub Constitution",
      "status": "locked",
      "section_count": 12,
      "sha256": "f26155047315f317b9b7adb3e8e4f2ba7da739f995e46195bd38b1cd2333b481"
    },
    {
      "number": "06",
      "filename": "06-WEBSITE.md",
      "title": "Website Constitution",
      "status": "locked",
      "section_count": 14,
      "sha256": "e73e626896c2de8e51dcb94b75e3d99725508c5e4fdb6eddb533c7ae64fa8f1b"
    },
    {
      "number": "07",
      "filename": "07-SUBDOMAIN.md",
      "title": "Subdomain Constitution",
      "status": "locked",
      "section_count": 12,
      "sha256": "03160eb6693c839c8794dbc37f7405d1dda662227bb090ee7e5a07713ddcfe02"
    },
    {
      "number": "08",
      "filename": "08-APPS-DASHBOARDS.md",
      "title": "Apps & Dashboards Constitution",
      "status": "locked",
      "section_count": 13,
      "sha256": "1d1e549996f09bd7cb60469d75a2678f932abc5f6c5ba08b75ae6568640bc1b0"
    },
    {
      "number": "09",
      "filename": "09-WIDGETS.md",
      "title": "Widgets Constitution",
      "status": "locked",
      "section_count": 11,
      "sha256": "c57f50682404eb8bbfa98a448730d8f0898a9b3371b1fdf363ad077e8c9676cc"
    },
    {
      "number": "10",
      "filename": "10-PARTNER.md",
      "title": "Partner Constitution",
      "status": "locked",
      "section_count": 11,
      "sha256": "e3f42d9013cf469de80cf8a657b9d18c2bdcf5745ea260c60e128d91d3103df4"
    },
    {
      "number": "11",
      "filename": "11-CONTENT.md",
      "title": "Content Constitution",
      "status": "locked",
      "section_count": 13,
      "sha256": "cf076cec34584a693ad8aa532404dbb254b81390012dcfc9cb0891ae8eeda542"
    },
    {
      "number": "12",
      "filename": "12-PURPOSE-PERMISSION.md",
      "title": "KYE Protocol™ — Purpose & Scope Rail · Purpose Permission™ (v1.0)",
      "status": "locked",
      "section_count": 11,
      "sha256": "bb0c24e311fdad66449192aa93d181f1d36c467ecf614e2dc69aab80c5c56f4c"
    },
    {
      "number": "13",
      "filename": "13-RESILIENCE-LOOP.md",
      "title": "KYE Protocol™ — Evidence & Replay Rail · Resilience Loop™ (v1.0)",
      "status": "locked",
      "section_count": 17,
      "sha256": "4ffaa9a9399f704520ea41d7cb2f7a52d17934a71f85bed7fba7e2a210b2bd76"
    },
    {
      "number": "14",
      "filename": "14-AGENTS-AND-ENGINES.md",
      "title": "KYE Protocol™ — Agents & Engines (v1.0)",
      "status": "locked",
      "section_count": 12,
      "sha256": "6eff21cae90627bec0c6c8c3a4b2d19dbfb58e4278e6b0e7b817f5acba4a747e"
    },
    {
      "number": "15",
      "filename": "15-MCP-AND-SDK.md",
      "title": "KYE Protocol™ — Developer Surface · KYE™ MCP Server / KYE™ MCP Gateway / KYE SDK™ / KYE Conformance Pack™ (v1.0)",
      "status": "locked",
      "section_count": 19,
      "sha256": "faa5a44f4938ce78c7d65df2f512b9954de8ef01615e43836943a3eb3c932923"
    },
    {
      "number": "16",
      "filename": "16-EDGE-RUNTIME.md",
      "title": "KYE Protocol™ — Edge Runtime · Cloudflare-Native Topology (v1.0)",
      "status": "locked",
      "section_count": 14,
      "sha256": "fb62046177db59f6775bca46d5035552b3b7ba7baf7b8cb851f2138c5c704098"
    },
    {
      "number": "17",
      "filename": "17-DIRECTORY-SEARCH.md",
      "title": "KYE Protocol™ — Directory Rail · Directory Search™ (v1.0)",
      "status": "locked",
      "section_count": 12,
      "sha256": "204d6347d8fee35f5826b9586fc2a78257536e6426adba2e37df63c73a22df6e"
    },
    {
      "number": "18",
      "filename": "18-OPERATING-MODEL.md",
      "title": "KYE Protocol™ — Operating Model Rail · Operating Model™ (v1.0)",
      "status": "locked",
      "section_count": 14,
      "sha256": "e5182ca81eeabc65fca3582783183852fa714e0be5ce967cf9743931b7358ddb"
    },
    {
      "number": "19",
      "filename": "19-WIDGETS-EXPANDED.md",
      "title": "KYE Protocol™ — KYE Partner Widgets™ Catalogue (v1.2)",
      "status": "locked",
      "section_count": 10,
      "sha256": "54b39ed0dab20ef7b298c5ad97a5ee3279897fddd45d43e76b34436991de4da6"
    },
    {
      "number": "20",
      "filename": "20-ANALYTICS-PLANE.md",
      "title": "KYE Protocol™ — Analytics Plane Lock (v1.0)",
      "status": "locked",
      "section_count": 15,
      "sha256": "0c2517d453ed9376b988649cd359b421aa0376c21db2c6b9f33944373822451d"
    },
    {
      "number": "21",
      "filename": "21-DELEGATED-AUDITABILITY.md",
      "title": "KYE Protocol™ — Delegated Auditability Rail · Audit Pilot™ (v1.0)",
      "status": "locked",
      "section_count": 16,
      "sha256": "18a81d74939deb1513cfd8982b41e029dd95107142265a06d9ace2d794b57dec"
    },
    {
      "number": "22",
      "filename": "22-ONBOARDING.md",
      "title": "KYE Protocol™ — Onboarding Rail · KYE Onboarding Agent™ (v1.0)",
      "status": "locked",
      "section_count": 15,
      "sha256": "dc679fca58e2aea668d2cab7769c67c5dc3b4ed12268be39f831e99818d1df33"
    },
    {
      "number": "23",
      "filename": "23-BILLING-METERING.md",
      "title": "KYE Protocol™ — Billing & Metering Rail · KYE Billing Meters™ (v1.0)",
      "status": "locked",
      "section_count": 15,
      "sha256": "8aa0a5369b1ada55dbafdba36c28dec43e0c46071d5c23e48bda2b321fcfebcc"
    },
    {
      "number": "24",
      "filename": "24-DESIGN-DICTIONARY.md",
      "title": "Constitution §24 — Design Dictionary",
      "status": "locked",
      "section_count": 17,
      "sha256": "6df4a4862d488020fd481bb37837b53e7fed138379c4a5151df12aa7b3383550"
    },
    {
      "number": "25",
      "filename": "25-EDGE-GOVERNANCE.md",
      "title": "Constitution §25 — KYE Edge Governance™ Rail",
      "status": "locked",
      "section_count": 11,
      "sha256": "5896f8e56f75a96ca418be7b143ea99e4af1e52d43e7fd47e8e8a0dbd5e0f867"
    },
    {
      "number": "26",
      "filename": "26-COMMERCIAL.md",
      "title": "Constitution §26 — Commercial Rail (SKU catalogue + closed-registration disclosure)",
      "status": "locked",
      "section_count": 14,
      "sha256": "8ee35bb38971be9b96eec32e1a65f9cc44c8d85d27ab9cfd49fd2a0de54316b7"
    },
    {
      "number": "27",
      "filename": "27-COMMERCIAL-LIFECYCLE.md",
      "title": "Constitution §27 — Commercial Lifecycle + Dual-Channel Admin + Payment-Gate",
      "status": "locked",
      "section_count": 15,
      "sha256": "8d9541448d2f81c97f83090582c872b8ff3211616e9ea8d7742aed6ef08e1bea"
    },
    {
      "number": "28",
      "filename": "28-CKAN-OPEN-DATA.md",
      "title": "Constitution §28 — CKAN connector + Open Data Portal Rail",
      "status": "locked",
      "section_count": 15,
      "sha256": "eede51c234166977233c99d68a742a9e7234ee80b1e5becb8c9ae0811390ba79"
    },
    {
      "number": "29",
      "filename": "29-PROFILES-LITE.md",
      "title": "Constitution §29 — Profiles-Lite + Rule Packs + Dictionaries + Rules Gateway",
      "status": "locked",
      "section_count": 12,
      "sha256": "cb600cfebf5eeaf62de1e00d7959ed29e523907114c0ecb1d65fe8d546328e61"
    },
    {
      "number": "30",
      "filename": "30-AUDIT-WORM-RETENTION.md",
      "title": "Constitution §30 — Audit WORM + Retention",
      "status": "locked",
      "section_count": 10,
      "sha256": "a3f35723177838f6e65afd0875eece4b3513a7f9ec841d807e7707b172140cfa"
    },
    {
      "number": "31",
      "filename": "31-DATA-GOVERNANCE-PACK.md",
      "title": "Constitution §31 — KYE Data Governance Pack™",
      "status": "locked",
      "section_count": 11,
      "sha256": "daaf041500c9e6417755c73519e3e6e40dc735015decd82a3695b337b9927cd9"
    },
    {
      "number": "32",
      "filename": "32-AGENT-DEV-KIT.md",
      "title": "Constitution §32 — KYE Agent Dev Kit™",
      "status": "locked",
      "section_count": 9,
      "sha256": "a7a8bc80126f8ca1adca79e407b2233fd66678e635944f69192bd7487eef7993"
    },
    {
      "number": "33",
      "filename": "33-IP-OSS-LINE.md",
      "title": "Constitution §33 — IP/OSS Line (the patent-safety / open-source split)",
      "status": "locked",
      "section_count": 10,
      "sha256": "38ce3125cf28063cf2ccfea3eeec4287cbdede1e13e569a4e2a8b85353bf197c"
    },
    {
      "number": "34",
      "filename": "34-RECONCILIATION-ENGINE.md",
      "title": "Reconciliation Engine™",
      "status": "locked",
      "section_count": 16,
      "sha256": "c4b0e5a41390ddbf5f4a0993de557d7669b05c7f4a649a7b3b42ca21caabd815"
    },
    {
      "number": "35",
      "filename": "35-STREAMING-LOGS.md",
      "title": "Streaming Logs Contract™",
      "status": "locked",
      "section_count": 6,
      "sha256": "d6684be97a826cb7565f91bc64b6a5964febbf02c5bcbf962288344528ce8bd4"
    },
    {
      "number": "36",
      "filename": "36-GOVERNEDUI.md",
      "title": "KYE GovernedUI™",
      "status": "locked",
      "section_count": 12,
      "sha256": "18df5eaf8b06cf4aa1d1ecdde5587b370b6de8d4dd96be55964bd46b91debb6b"
    },
    {
      "number": "37",
      "filename": "37-EVENT-ENGINE.md",
      "title": "37 — KYE Event Engine™",
      "status": "locked",
      "section_count": 11,
      "sha256": "0996e42bfd1cb5ebddc6d74d485fbacc8f97f88f10f90d626d00b46c18d89516"
    },
    {
      "number": "38",
      "filename": "38-COMMS-RAIL.md",
      "title": "38 — Comms Rail · KYE Comms Engine™",
      "status": "locked",
      "section_count": 16,
      "sha256": "9aa93cd5466fa7664c131cef8167aecef3b506894aefb32cd3cb477953d1579c"
    },
    {
      "number": "39",
      "filename": "39-LEARN-RAIL.md",
      "title": "39 — Learn Rail · KYE Learn™",
      "status": "locked",
      "section_count": 8,
      "sha256": "f69724cc6ffcda4cd1ac8c37daa206aa032db46ccca73a29c1f5f9c255a4f9eb"
    },
    {
      "number": "40",
      "filename": "40-IMPLEMENTATION-CANONICAL.md",
      "title": "40 — Implementation Canonical · KYE Implementation Registry™",
      "status": "locked",
      "section_count": 10,
      "sha256": "fc978ac0b49d9fb2e60a95ac34c13102877ad336102a7079987608e5b43fc059"
    },
    {
      "number": "41",
      "filename": "41-ERROR-HORIZONS.md",
      "title": "41 — Error Horizons · push, then convert-to-rule",
      "status": "locked",
      "section_count": 9,
      "sha256": "ae6b76ef4070c1a65a8f907de1c940b51ab6f5e862c6731b1039380255d7b322"
    },
    {
      "number": "42",
      "filename": "42-CONSTITUTION-KIT.md",
      "title": "42 — Constitution Kit · the enforcement toolkit of software/constitution™",
      "status": "locked",
      "section_count": 12,
      "sha256": "f149ac158ea9f25fa521d8eafbded09ed04938fd925f93739e62ff95d9eb976a"
    },
    {
      "number": "43",
      "filename": "43-MACHINE-READABLE-BY-DEFAULT.md",
      "title": "43 — Machine-Readable by Default",
      "status": "locked",
      "section_count": 11,
      "sha256": "e738e5844736c97484b5de14fd28f8ed260bb3b53206b9339f25b43b1c976afe"
    },
    {
      "number": "44",
      "filename": "44-LIVENESS-ENGINE.md",
      "title": "44 — KYE Liveness Engine™ · functional-liveness verification",
      "status": "locked",
      "section_count": 10,
      "sha256": "099d2770db7ed7c37f5ad3811b855daec05af6d4946255faaef4291761c11c2a"
    },
    {
      "number": "45",
      "filename": "45-SELF-DESCRIPTION-GATE.md",
      "title": "45 — The Self-Description Gate",
      "status": "locked",
      "section_count": 11,
      "sha256": "007c4c823913cec2a0697c0d9a50960de85ac3ab99400ea94e74aadea80070f0"
    },
    {
      "number": "46",
      "filename": "46-FLOW-CONTRACTS.md",
      "title": "46 — Flow Contracts",
      "status": "locked",
      "section_count": 10,
      "sha256": "1016ffcda6fce7cee990f6e1a0a6ac163588f77aac195d656bb95cd76e17943f"
    },
    {
      "number": "47",
      "filename": "47-CANONICAL-EVERYTHING.md",
      "title": "Canonical Everything — every concept has manifest + dictionary + schema (v1.0)",
      "status": "locked",
      "section_count": 6,
      "sha256": "d9f1ea888968b3a8c8055f127155f88600ead6ea3151e04f7f9e24ac05f22a30"
    },
    {
      "number": "48",
      "filename": "48-SIGNAL-INGEST-CONTRACT.md",
      "title": "48 — Signal Ingest Contract · the wake-up half of §41",
      "status": "locked",
      "section_count": 7,
      "sha256": "b3e37d4d390552329cbb1f53e7e353833e37e627be2c76f54e18e31b933cd42c"
    },
    {
      "number": "49",
      "filename": "49-UNIVERSAL-ENGAGEMENT-RAIL.md",
      "title": "49 — Universal Engagement Rail · one canonical surface for every external party",
      "status": "locked",
      "section_count": 14,
      "sha256": "64eec23827d187f44bbf45193167ede83e03a5694f831586a42b811d237965c9"
    },
    {
      "number": "50",
      "filename": "50-CONTENT-GRAPH-DISCOVERABILITY.md",
      "title": "50 — Canonical Content Graph + Derived Discoverability",
      "status": "locked",
      "section_count": 7,
      "sha256": "69eb8f85b5a52a6366b27addc334cdc1eb60ede0699aa77ffd472c8808edbe8f"
    },
    {
      "number": "51",
      "filename": "51-NO-SPOF.md",
      "title": "51 — No Single Point of Failure · the operational counterpart of §0",
      "status": "locked",
      "section_count": 11,
      "sha256": "a71ff8d623c6f6aa7369ea31145ceee4e4602071218cb0af0e9cf77b4f2a751e"
    },
    {
      "number": "52",
      "filename": "52-DELEGATED-AGENT-BINDING.md",
      "title": "52 — Constitutional Binding of Delegated Agents · subagents · MCP servers · external tool calls",
      "status": "locked",
      "section_count": 17,
      "sha256": "800d46a4bec78af1d82ec400509018d079b440509e6db2a0f0b7015d80934d69"
    },
    {
      "number": "53",
      "filename": "53-COHESION-CASCADE.md",
      "title": "53 — Cohesion Cascade · the repo is a single coherent state, every change ripples coherently throughout",
      "status": "locked",
      "section_count": 15,
      "sha256": "ac56ed3c837c2d0940125c924955a64bfed17120a874a9aa06018cb6e719f437"
    },
    {
      "number": "54",
      "filename": "54-SECTOR-PACK-FOUNDRY.md",
      "title": "54 — KYE Sector Pack Foundry™ · productisation rail for expert governance frameworks",
      "status": "locked",
      "section_count": 16,
      "sha256": "ca058db08075273af3f10aa4bc309d46460e5b880ddece38cd59395c40822f31"
    },
    {
      "number": "55",
      "filename": "55-EXECUTION-LAYERS-ARCHITECTURE.md",
      "title": "§55 — Execution Layers Architecture (KYE State Engine™ + 10-Layer Stack)",
      "status": "locked",
      "section_count": 10,
      "sha256": "48aabbcf0999a40941dea0ae84f072ce80f05e0df3a1ffd2a54c7eddb266a5ff"
    },
    {
      "number": "56",
      "filename": "56-N-M-RELATIONSHIPS.md",
      "title": "56 — Canonical N:M Relationships · the relationship root, many projections",
      "status": "locked",
      "section_count": 8,
      "sha256": "290f033b0431b938b5dad15970dd9ac044b740db46b18da216f7f4e766b65569"
    },
    {
      "number": "57",
      "filename": "57-CROSS-JURISDICTION-HANDOFF.md",
      "title": "57 — Cross-Jurisdiction Handoff Rail · regulatory acts that cross borders",
      "status": "locked",
      "section_count": 8,
      "sha256": "607a6209c7d2fdd983acdec53f11aa492a83e1b14a853072b30ffe8b4eae4649"
    },
    {
      "number": "58",
      "filename": "58-GOVERNED-PROMPTS.md",
      "title": "58 — KYE Governed Prompts™ · the prompt is an authority act",
      "status": "locked",
      "section_count": 8,
      "sha256": "39a878e33e63c66fc88be8b2b4f87c2c8d9b149ead269b00041560f6974950b1"
    },
    {
      "number": "59",
      "filename": "59-FRAMEWORK-INGESTION.md",
      "title": "59 — KYE Framework Ingestion Engine · deterministic, no-LLM, replay-proof",
      "status": "locked",
      "section_count": 8,
      "sha256": "e048bb7eb4252bb5289caf8d31dd15ce6e34bd5ff2b40aac4be09fdef58f3e6e"
    },
    {
      "number": "60",
      "filename": "60-AUTHORITY-AS-CODE.md",
      "title": "60 — KYE Authority-as-Code™ + Authority Harness™ · programmable primitives, deterministic finality",
      "status": "locked",
      "section_count": 9,
      "sha256": "9b80ef293b00a24fc6e42adba9dc03fc1e445c54c005cc6e169b8ffa5e0af13a"
    },
    {
      "number": "61",
      "filename": "61-RIGHTS-DISPUTES-DISCLOSURE-RAIL.md",
      "title": "61 — KYE Rights, Disputes & Disclosure Rail™",
      "status": "locked",
      "section_count": 8,
      "sha256": "5854f9fa9663b1bb4ec1d616f77fbf324ddd2b99dbaecc6d4a77d6fa182bd21b"
    },
    {
      "number": "62",
      "filename": "62-GOVERNED-RESEARCH-RAIL.md",
      "title": "62 — KYE Governed Research Rail™ · publisher of authority and authority for publishing",
      "status": "locked",
      "section_count": 16,
      "sha256": "cdcc9d2630fb3c8168463098ff1cf1bbec0ffbdb47cd378fd22e01b8bb837dd6"
    },
    {
      "number": "63",
      "filename": "63-MEMORY-AUTHORITY-RAIL.md",
      "title": "63 — KYE Memory Authority Rail™ · agent memory as authority-bearing state",
      "status": "locked",
      "section_count": 12,
      "sha256": "695b1ccbf769fb2926f6816d94700cecc89b78ce189d017333ab249e71fc7035"
    },
    {
      "number": "64",
      "filename": "64-OBLIGATION-AUTHORITY-RAIL.md",
      "title": "64 — KYE Obligation Authority Rail™ · obligations as the governed spine",
      "status": "locked",
      "section_count": 7,
      "sha256": "e759bca5bb306650b1b26e1028a35eeb1196e6ae6da6ebb3f35c9980a40d54aa"
    },
    {
      "number": "65",
      "filename": "65-UPDATES-RAIL.md",
      "title": "65 — KYE Updates Rail™ · one feed, the bell, and every announcement",
      "status": "locked",
      "section_count": 8,
      "sha256": "39f2dd70459b2d6b55213325b55ec7a651c2d0fd0c4e176d50d61d5147882cfa"
    },
    {
      "number": "66",
      "filename": "66-CERTIFICATES-RAIL.md",
      "title": "66 — KYE Certificates Rail™ · the catalog of certificate programs",
      "status": "locked",
      "section_count": 6,
      "sha256": "e4d933a54857cdd6709897fdedd4f0e990782b7b5a58180c4f4b1444cc275ffd"
    },
    {
      "number": "67",
      "filename": "67-MODEL-GOVERNANCE-RAIL.md",
      "title": "67 — KYE Model Governance Rail™ · AI-BOM & the Chain of Authority",
      "status": "locked",
      "section_count": 6,
      "sha256": "8ff6e588fc7468e4451a9368b598bd1475ed8ebb5846bfe271aedd45b16b381b"
    },
    {
      "number": "68",
      "filename": "68-SECTOR-PRODUCT-RAIL.md",
      "title": "68 — KYE Sector Product Rail™ (Total Productisation Fan-Out)",
      "status": "locked",
      "section_count": 6,
      "sha256": "dbc151a783746ddfecad7946a33d10fb36c5b214452cea9baa80da8d06c52c13"
    },
    {
      "number": "69",
      "filename": "69-CONTROL-PLANE-MCP.md",
      "title": "69 — KYE Control-Plane MCP™ · the governed inbound operator surface",
      "status": "locked",
      "section_count": 9,
      "sha256": "ce56fd358680cef06071f1b9b3a2a82770ec88e04793c5fef927f4f932c38811"
    },
    {
      "number": "70",
      "filename": "70-FRAMEWORK-MAPPING-RAIL.md",
      "title": "70 — KYE Framework Mapping Rail™ · the canonical, registry-first deep-mapping track",
      "status": "locked",
      "section_count": 9,
      "sha256": "62d5d03b063e8989c2012a2475bb77f369a7a1426d8601a2ed6b7409726b8d29"
    },
    {
      "number": "71",
      "filename": "71-DOCUMENT-INTELLIGENCE-RAIL.md",
      "title": "71 — KYE Document Intelligence Rail™ · navigating, retrieving & citing unstructured documents",
      "status": "locked",
      "section_count": 12,
      "sha256": "ea2d26d5039af8e10fa0ca40e4fea0cfca2f4782f438f77671e497718fb7f396"
    },
    {
      "number": "72",
      "filename": "72-JURISDICTION-DATA-SOVEREIGNTY.md",
      "title": "72 — KYE Jurisdiction & Data-Sovereignty Authority · geography as a first-class dimension of admissibility",
      "status": "locked",
      "section_count": 9,
      "sha256": "bc963d10cb271c6e75c4acfa648128c3c43863db488394710c699a2a61e3f480"
    },
    {
      "number": "73",
      "filename": "73-CONTROL-PLANE-INTEROP.md",
      "title": "73 — KYE Control-Plane Interoperability Profile™ · external planes in, KYE decides, planes enforce",
      "status": "locked",
      "section_count": 8,
      "sha256": "5c9c25c0da10f6ff7f3342a4f7ad5c84e6cd07e0f0e17cc20fed1d663461f893"
    },
    {
      "number": "74",
      "filename": "74-TAXONOMY-RAIL.md",
      "title": "74 — KYE Taxonomy Rail™ · the component-graph taxonomy, dogfooded on KYE's own primitives",
      "status": "locked",
      "section_count": 8,
      "sha256": "03d328864ca5a34430f2f7233a1329ece38fb3b79b6a87a4eacbd6819bca7f9d"
    },
    {
      "number": "75",
      "filename": "75-FOLLOWABILITY-RAIL.md",
      "title": "75 — KYE Followability Rail™ · Followable-by-Construction + Universal Reach",
      "status": "locked",
      "section_count": 10,
      "sha256": "63158c76cfcfccfcd2461d5e0d17658b016c25aed8a7516d3eb4d0e52661371d"
    }
  ],
  "deviations": {
    "active": [],
    "historical_count": 12,
    "sha256": "1065aea5f9886e61d469788557209c4b09a2ab0c106c6051a1bcf7516f8c3941"
  },
  "decay_windows": {
    "active": [
      {
        "title": "run-gates is serial and the chain is at 88% of its CI budget (registered 2026-09-04, decay_deadline: 2026-12-04)",
        "closure_date": null,
        "gate_path": null,
        "body": "**Owner:** Architecture\n\nMeasured on head 84ebc77d6e: the chain passed ALL 518 steps and failed only the\nduration guard — 37.7 min against a 36.5 min ceiling, which is `warn_fraction`\n0.85 of the 43 min available inside a 45-minute job. Nothing was broken; the\nguard fires early by design, because when the chain exceeds the JOB timeout\nGitHub reports `cancelled`, which reads like a superseded run — that is how six\nconsecutive pushes went unnoticed on 2026-08-11.\n\nThe immediate move was to raise `job_timeout_minutes` 45 → 55 in BOTH\n`.github/workflows/ci.yml` (job `test`) and `scripts/gate-manifest.json`\n`ci_budget` — `workflow-lint-canonical` fails if they disagree, so they cannot\ndrift. That is a POLICY value, not a measurement: nothing derives a timeout from\nthe corpus, so it is declared rather than computed, and raising a kill ceiling\ncosts nothing because GitHub bills actual runtime.\n\n**It is not the fix.** The chain grew because the ESTATE grew — none of the\nslowest gates is new; they walk a corpus that gained schemas, registries and\ngraph nodes, so every future wave pushes the number up again. Measured, the\nslowest four are 19.4 of the 37.7 minutes:\n\n| gate | time |\n|---|---|\n| `test:demonstrated-effect` | 364.1s |\n| `test:html-validate` | 337.7s |\n| `test:generator-determinism` | 262.7s |\n| `test:design-tokens-coherent` | 199.7s |\n\nThe guard's own advice is \"cut the top of this list, not the chain as a whole\",\nand its first named remedy is splitting or parallelising. `scripts/run-gates.mjs`\nis deliberately serial (§0 — one runner, never a parallel), and no manifest step\ndeclares parallel-safety, so parallelising is a real design change: every step\nmust declare whether it can run concurrently, and the ones that write\nattestations or regenerate the tree cannot. That declaration is the work, and it\nis exactly the contract-first shape the estate already uses — a per-step\n`parallel_safe` field on the manifest, derived-verified rather than asserted.\n\nClosing this window means the chain runs inside its budget on merit, not on a\nraised ceiling."
      },
      {
        "title": "§62 §5 — 50 legacy research claims cite a source that was never retrieved (registered 2026-08-31, decay_deadline: 2026-11-30)",
        "closure_date": null,
        "gate_path": null,
        "body": "**Owner:** Architecture\n\nThe dangling-reference half of this is FIXED in the same change-set, not\ndeferred (§41 §9). Measured 2026-08-31: no `kye.evidence.pack.v1` instance\nexisted for any of the 17 reports, so every `evidence_pack_ref` pointed at\nnothing — and a first check was fooled into reporting 14/16 \"resolving\",\nbecause the ref resolves into the library page *rendered from the same report*,\nwhich is circular. The fix is emission, not generation: the sealer\n(`scripts/sign-research-report.mjs`) now EMITS a\n`kye.research_evidence_pack.v1` at the moment it seals, and SETS\n`evidence_pack_ref` from what it emitted, so the reference resolves by\nconstruction. A pack written about a report afterwards would be a document; a\npack emitted by the act of sealing is a byproduct of the work. All 16 refs now\nresolve, and `research-rail-canonical` fails if one does not, if the pack\nevidences a different report, or if its claim count has drifted from the\nreport's citations.\n\n**What remains inside the window** is what the emitted packs made visible:\n**3 claims pinned, 50 unpinned.** An unpinned claim is one whose citation names\nno `source_id`, or names one that was never actually retrieved — it rests on a\nURL string rather than on bytes that were fetched and hashed. The packs record\nthis per claim with a stated reason rather than hiding it, and the gate carries\na decreases-only ceiling of 50: a net-new unpinned claim hard-fails.\n\nClosing it means running the real gather for those 15 legacy reports through\n`scripts/research/acquire-source.mjs`, which fetches, hashes, and refuses when\nthe quote is not present in the retrieved bytes. That is per-report editorial\nwork on other authors' reports, not a mechanical sweep, which is why it is\ntime-boxed rather than done here. It must not be closed by back-filling\nplausible-looking source records: a pin that was not retrieved is worse than an\nhonest gap, because it claims verification that never happened."
      },
      {
        "title": "§0.9 — 9 canonical registry rows bind a patent family to a mechanism doc that has never existed (registered 2026-08-13, decay_deadline: 2026-11-13)",
        "closure_date": null,
        "gate_path": "scripts/gates/housekeeping.mjs",
        "body": "**Owner:** platform-ops\n\n`private/patent/claims-inventory.md` is the canonical per-claim registry: 43\nrows binding a patent family to its mechanism design doc. Nine of those rows —\nF25 through F33 — name a doc that has never existed in this repository.\n`git log --all` returns no commit touching any of the nine paths, so these are\nnot stale names left by a move; the documents were never written.\n\nThis is the AUTHORITATIVE registry being wrong, not claim-file drift. The\nclaim-file half is now enforced at strict zero by the registry-binding class in\n`scripts/gates/housekeeping.mjs`, which is why the two halves are recorded\nseparately: a claim file may no longer disagree with the registry, but the\nregistry may still point at nothing, and folding the second into the first\nwould have produced a strict-zero class that cannot be satisfied without\ninventing the missing documents.\n\n**Why it is not closed here.** Closing it means authoring nine patent mechanism\ndesigns. That is counsel work on a pre-filing track (Hard rule #2), and the two\nshortcuts available to an agent — writing the designs from the claim text, or\ncreating empty files so the count reads zero — are respectively unreviewed\ninvention on a legal artefact and the §0.2 placeholder this repo forbids. The\nnine dangling references remain visible in the §0.5 general backlog in the\nmeantime; they are counted, not hidden.\n\n**To close:** author the nine mechanism designs under counsel review, or amend\nthe nine registry rows to bind a doc that exists, or record the families as\nhaving no separate mechanism doc. Silent extension past the deadline is a §0\nviolation.\n\n**Found by** reconciling the registry against disk after seven claim files were\ndiscovered to contradict it. The reconciliation itself was wrong twice before it\nwas right: a parse that required the mechanism path in a fixed column silently\ndropped every bold-formatted row and reported 14 bindings where there are 43,\nand a second reading conflated this table with the filing-tier table in the same\nfile. The registry is complete at 43/43; only these nine targets are missing."
      },
      {
        "title": "§4 — the constitution-amendment checks are performed by review, not by a gate (registered 2026-08-13, decay_deadline: 2026-11-13)",
        "closure_date": null,
        "gate_path": null,
        "body": "**Owner:** platform-ops\n\n`00-INDEX.md` §4 step 3 stated that CI runs\nscripts/constitution-amendment-check.sh, blocking `LOCKED:`-block changes\nwithout a co-signed approval, blocking renames to any namespace listed in\n`NAMING.md` §§2–6, and requiring the PR body to list downstream adopters. That\nscript has never existed in this repository — `git log --all` returns no commit\ntouching the path — and nothing else enforces those three checks.\n\nThe controls themselves are real and are applied by reviewers under §4 step 4\n(2 owner approvals). What was false was the claim that a gate performed them,\nwhich is the §0.44 hollow-claim shape: an assurance asserted rather than run.\n§4 step 3 now names the review as the control.\n\n**To close:** write the gate, or amend §4 to state permanently that these are\nreview-time controls. Silent extension past the deadline is a §0 violation.\n\n**Found by** `housekeeping` after its enforcer class was widened to all of\n`scripts/` (it had matched only `scripts/gates/` and `scripts/ci/`, so a\ntop-level `scripts/*.sh` citation was not counted as an enforcement claim) and\nits dated-commitment exemption was tightened to require the §41 §9 owner+date\npairing (the bare word `decay_deadline`, appearing three times in 00-INDEX.md's\nown prose about the mechanism, had been exempting this claim from 3,000 lines\naway)."
      },
      {
        "title": "§11 — layout-safety classes are not mechanically enforced (registered 2026-08-13, decay_deadline: 2026-11-13)",
        "closure_date": null,
        "gate_path": null,
        "body": "**Owner:** platform-ops\n\n`11-CONTENT.md` §8 listed \"Layout-safety classes present (§5)\" as a\nmerge-blocking gate implemented by scripts/check-layout-safety.mjs. That\nscript has never existed; the other five rows in that table resolve to\n`scripts/score-content-clarity.mjs` and `scripts/audit-terminology.mjs`, which\ndo. §5 defines a layout-safety contract that nothing checks, and the table said\nit blocked merges.\n\nThe row now reads \"not mechanically enforced\" with Blocks-merge \"no\", which is\nthe true state.\n\n**To close:** write the checker for the §5 contract, or amend §5 to drop the\ncontract. Do not re-mark the row blocking until a gate exists."
      },
      {
        "title": "§0.49 — the entity-class list is hand-copied per schema instead of derived from the canonical id-grammar (registered 2026-08-13, decay_deadline: 2026-11-11)",
        "closure_date": null,
        "gate_path": null,
        "body": "**Owner:** platform\n\n`private/specs/identity/id-grammar.json` declares 588 canonical id classes and is\nthe source of truth for what a KYE-ID may be. No schema derives from it. Instead,\n\"which entity classes may hold or confer authority\" is written out by hand at each\npoint of use, and the copies had already diverged:\n\n```\nkye.authority.grant.v1   ^kye:(ent|prin|org|system|agent|board-member):…      × 4 fields\nkye.purpose_manifest.v1  ^kye:(agent|ent|prin|org|system|board-member):…      × 1 field\n```\n\nNeither admitted `person` or `principal`, both of which ARE valid classes in the\ngrammar and both of which are declared as holders by canonical decision rights\n(`kye:person:acme-bank.cro`, `kye:principal:northwind-bank:jordan-reyes`,\n`kye:principal:acme:human:finance-controller`). The authority issuer refused to\nwrite those records — correctly, against a contract that was itself wrong.\n\nHalf-closed on 2026-08-13: the four copies inside `kye.authority.grant.v1` are\ncollapsed into one `$defs/principalId` and `$ref`'d, so a widening can no longer\nland in three fields and miss the fourth, and both lists were widened to the\nclasses measured in use. **The mechanism is untouched:** the list is still\nauthored by hand, still duplicated across two schemas, and still cannot be\nchecked against the grammar it is supposed to project.\n\nTwo things must happen to close this:\n\n1. **Derive, don't author.** The principal-class pattern becomes a generated\n   artefact of `id-grammar.json` (the §0.20 generate-then-verify shape every other\n   derived artefact already uses), so a class added to the grammar cannot be\n   invisible to the schemas, and a schema cannot admit a class the grammar does\n   not declare.\n\n2. **Resolve the duplicate concepts first**, because generating from the grammar\n   as it stands would enshrine them. Measured across `private/specs`:\n   `kye:ent:` 134 files · `kye:prin:` 19 · `kye:principal:` 8 · `kye:person:` 4.\n   `prin`/`principal` and `ent`/`person` read as two spellings of one concept\n   each — the §0 shape, in the identity grammar itself. Deciding which is\n   canonical is an amendment, not a codemod, and it must precede step 1."
      },
      {
        "title": "§0.43 — a class registry is validated against its ITEM contract, so no row-level defect can surface (registered 2026-08-13, decay_deadline: 2026-11-03)",
        "closure_date": null,
        "gate_path": null,
        "body": "**Owner:** platform\n\n`scripts/validate-schemas.js` pairs every class registry with the contract it\ndeclares, resolved through the §0.51 admission matrix, then runs\n`validate(doc)` where `doc` is the **whole registry document**. For a registry\nwhose declared contract describes a **single instance**, that is a category\nerror: the registry object carries `registry_id`, `display_name`, `version`,\n`decision_rights[]` and so on, none of which the item contract declares, so the\npair fails structurally on the first `additionalProperties` error and every\ngenuine row-level violation inside it is invisible.\n\nMeasured on `origin/main` 2026-08-13:\n`private/specs/decision-rights/decision-right-registry.json` declares\n`kye.decision_right.v1.json`, which sets `additionalProperties: false`, and two\nof its rows carry undeclared fields — `grant_term_note` and `sod_note`. Both\nhave been live and both validated, because the pair was already counted as one\nnonconformance in the decreases-only `registry_schema_nonconformant` ratchet for\nan unrelated structural reason. The ratchet was measuring the category error, not\nthe data.\n\nThose two fields are now declared, so that instance is closed. **The mechanism is\nnot**: any other class registry whose declared contract is an item schema has the\nsame blind spot, and the count of such pairs has never been measured.\n\nClosing this means changing how a class registry resolves and applies its\ncontract — validate `registry[instances_key][]` against the item contract when\nthe admission matrix declares an `instances_key`, and reserve whole-document\nvalidation for registries whose contract really is a document schema. That is a\nchange to the shared pairing convention in `scripts/validate-schemas.js`, not a\nper-registry fix, and it must land with the re-measured\n`registry_schema_nonconformant` ceiling in the same change-set — the number will\nmove in both directions (structural false-failures disappear, real row defects\nappear) and only the combined figure is honest."
      },
      {
        "title": "§0.29 — the regional residency Workers were declared but never built (registered 2026-08-13, decay_deadline: 2026-11-11)",
        "closure_date": null,
        "gate_path": null,
        "body": "**Owner:** platform-ops\n\n`kye-residency-router-{eu,uk,us}` sat in the deploy matrix pointing `main` at\n`private/runtime/data-residency-router/src/index.ts` — the barrel of the\n`@kye/data-residency-router` LIBRARY, which exports policy functions and no\nWorker handler. Wrangler therefore treated the script as service-worker format\nand rejected the D1 binding on every run:\n\n```\nBinding 'DB_EU' of type 'd1' requires a Worker written in ES module format. [code: 100329]\n```\n\nMeasured 2026-08-13 against the live account: 121 Workers, **none** a residency\nrouter. These never deployed. `private/specs/estate/deployed-estate.json` had\nalready recorded that correctly (`lifecycle_stage: \"dead-end\"`, *\"Declared in the\nrepo; the provider of record does not have it\"*) — the estate reconciler was\nright and nothing acted on it, so the job failed daily and the failure became\nbackground noise.\n\nRemoved from the deploy matrix rather than given a stub entry point, because\nwriting one would have created a second residency implementation beside\n`private/runtime/gateway-worker/src/middleware/data-residency.ts`, which already\nenforces residency (§0). No capability is lost — none ever existed.\n\n**What remains open, and why this is a window rather than a fix:** whether\nregion-pinned residency Workers *should* exist is a design decision with\ncompliance weight (the configs cite GDPR Ch. V, DORA Art. 28, Schrems II). The\nthree `regional-bindings/wrangler.{eu,uk,us}.toml` files stay as the ONLY on-disk\nrecord of the provisioned D1/KV/R2 ids — `private/specs/regional-data-plane/manifest.json`\ncarries the resource *names* but not the ids, so deleting them would lose real\nprovisioning state. Decide by the deadline: build the Workers, or fold the ids\ninto the manifest and retire the configs.\n\nThe class is closed regardless: `edge-binding-coverage` half 5 now hard-fails any\ndeploy-matrix target whose `main` is missing or exports no Worker handler, so\nthis cannot be re-introduced silently."
      },
      {
        "title": "§0.9 — 90 Worker env reads are declared nowhere, 38 of them signing keys (registered 2026-08-02, decay_deadline: 2026-11-02)",
        "closure_date": null,
        "gate_path": null,
        "body": "**Owner:** platform-ops\n\n**Found 2026-08-02, by the invariant added in the same change-set.**\n`edge-binding-coverage` had two halves — locked bindings, and the Pages-project\nbijection. Neither looked at a **Worker's own** `env.X` reads. So a Worker could\nread a binding declared in no `wrangler.toml` and in no registry, be deployed,\nand every gate in the repo reported clean.\n\n**The instance that matters, and it is on the §13 critical path.** `kye-pdp`\nreads `env.PDP_SIGNING_KEY_SEED_HEX` — the Ed25519 seed that signs\n`decision_map_jws`, the detached signature the entire Replay-Proof™ claim rests\non. It was declared in neither its `wrangler.toml` nor\n`private/specs/secrets/secrets_registry.json`, so the deployed Worker took its\ndocumented fallback: a **random per-cold-start seed** whose `kid` is prefixed\n`ephemeral:` and appears in **no published JWKS**\n(`public/site/trust/self-audit-jwks.json` carries four keys, none of them a PDP\ndecision-map key). The signature was produced, returned, and — as of the\npreceding change-set — stored. It was verifiable by nobody outside the isolate\nthat made it. The same Worker reads `env.AUDIT_CHAIN_BASE_URL`, which the\nregistry declared for fifteen Workers, none of them the PDP, so\n`kye.evidence.pack.v1` never reached the audit chain, `SEARCH_DELTA_MAP` never\nrouted it, and `search_evidence_packs` was never populated from the decision\npath. **Both are fixed here** (92 → 90).\n\n**What remains (the window).** 90 undeclared reads across 49 Workers, of which\n**38 are signing keys or key ids** — 10 × `ED25519_SK_B64`, 9 ×\n`KYE_SIGNING_SEED_BASE64`, 9 × `KYE_SIGNING_KID`, 3 × `KYE_SIGNING_SK`, 2 ×\n`SIGNING_KID`, plus `SELF_AUDIT_SIGNING_JWK`, `DGP_SIGNING_KEY_PEM`,\n`CERT_SIGNING_KEY_SEED_HEX`, `KYE_CASCADE_ED25519_SEED`,\n`KYE_DISPATCHER_ED25519_SEED`. Measured against a canonical secret registry\nwhose own `counts` read **`\"secrets\": 0`** — the inventory of secrets contained\nno secrets.\n\nThey are **not** fixed in this pass. Each needs a secret-management decision —\nwhich key, whose rotation policy, whether it is already set in the Cloudflare\nsecret store — that cannot be made from the repository alone. Inventing registry\nrows for keys whose real handling is unknown would assert facts about production\nthat nobody in this change-set verified, and §70 forbids that more strongly than\n§0.9 demands the row.\n\n**Mechanically enforced meanwhile:** `worker_env_undeclared` in\n`private/specs/ratchets/baselines.json` is a decreases-only baseline of 90. A\n**net-new** undeclared Worker env read hard-fails — negative-tested by removing\nthe `PDP_SIGNING_KEY_SEED_HEX` row and watching the gate reject at 91. Burn-down\nis tracked by `advisory-deadline-not-expired`, so the ceiling cannot sit flat to\nthe deadline.\n\n**The operator action this does not substitute for.** Declaring the seed in the\nregistry does not *set* it. Until `PDP_SIGNING_KEY_SEED_HEX` is present in the\nCloudflare secret store for `kye-pdp` **and** its derived public key is published\nin the JWKS, decision-map signatures remain unverifiable and the `ephemeral:`\n`kid` prefix is the honest signal that they are."
      },
      {
        "title": "§0.29/§0.34 — the consumption stage reads a table nothing writes (registered 2026-08-01, decay_deadline: 2026-10-30)",
        "closure_date": null,
        "gate_path": null,
        "body": "**Owner:** platform\n\n**Found 2026-08-01, in the change-set that created it.** The PDP consumption\nstage decides admissibility against `kye.quota_grant.v1` rows, migration 052\ngives those rows a table, and `resolveQuotasFor()` reads them tenant-scoped.\nEvery piece is real and tested. **In production the table will be empty**,\nbecause no deployed surface can create a quota grant: the only `/v1/quotas`\nendpoints in the repo live in `private/runtime/gateway/`, which is an explicitly\nillustrative reference server backed by an in-memory Map, and the deployed\n`kye-gateway-worker` exposes none.\n\nSo the stage resolves zero rows for every request and admits — correctly, since\nnothing bounds the mandate — but it is not yet enforcing anything in prod. That\nis a declared-not-fed capability, and naming it in a task list rather than here\nis precisely the §41 \"flagged note with neither\" this file exists to prevent.\n\n**Why not closed in the same change-set.** The missing piece is a new public API\n(create / reserve / commit / release, tenant-scoped, API-key authed) whose\nreserve path needs an atomic conditional UPDATE — `WHERE current_consumed +\nreserved + ? <= \"limit\"` — because read-then-write lets two concurrent\nreservations both pass. That needs its own §0.18 quintuple and its own tests;\nfolding it into a decision-path change would ship an unreviewed authority-bearing\nAPI alongside it.\n\n**The tempting wrong fix, named so nobody takes it.** Repointing the reference\ngateway's handlers at D1. That server is a documented Node sandbox with no D1\nbinding; its Map is a design choice, not a hollow runtime.\n\n**Closure.** A deployed quota write surface, at which point this entry is\ndeleted. Until then the honest claim is \"the PDP enforces spend bounds where\ngrants exist\", never \"KYE enforces spend bounds\"."
      },
      {
        "title": "§0.29 — the Reporting Engine has a seal path and no trigger that reaches it (registered 2026-08-12, decay_deadline: 2026-11-10)",
        "closure_date": null,
        "gate_path": null,
        "body": "**Owner:** platform\n\n**Found 2026-08-12, while removing a competing writer to `reports`.** `reports`\nholds **zero rows in production** — checked against the live D1, not inferred.\nTracing every way a row could arrive explains why, and the answer is not the\ncompeting writer that was just deleted:\n\n- `sealReport()` in `private/runtime/kye-reporting-worker/src/worker.ts` is\n  real and complete: build envelope → Ed25519-sign → immutable R2 PUT → WORM\n  INSERT → §0.3 emit. It is the one canonical writer.\n- Its only HTTP door is `POST /v1/reports`, behind `requireEntitlement(\"reports.write\")`\n  — an API key hashed against `api_keys` resolving a tenant, plus an active\n  **paid** SKU carrying that capability. Correct for a metered product, and\n  nothing in KYE's own estate holds such a key.\n- The daily cron is `periodCloseSweep()`, and it does not seal. Its body emits\n  one `report.period_close_sweep` audit event and returns; the walk-frameworks /\n  compute-boundary / seal-per-crossing behaviour its own comment describes is\n  written as a parenthetical, not as code.\n\nSo the engine can seal and is never asked to. That is a declared-not-triggered\ncapability of the same family as the quota entry above: every piece tested, the\ncomposition never exercised in prod.\n\n**Why not closed in the same change-set.** Making the sweep real means deciding\nperiod boundaries per framework cadence against `report_delivery_preferences`,\nsealing one report per crossed boundary per (tenant, framework), and doing it\nidempotently — a second run on the same day must not seal twice. That is an\nauthority-bearing scheduled writer to a WORM table and needs its own tests and\nits own review, not a ride-along on a change that deletes UI.\n\n**The tempting wrong fix, named so nobody takes it.** Minting an API key and a\npaid entitlement for KYE's own tenant so the admin console can call\n`POST /v1/reports`. That fabricates commercial state to make an internal button\nlight up, and the entitlement gate it defeats is the correct behaviour.\n\n**Mechanically enforced meanwhile:** the surface no longer claims otherwise. The\nadmin console's \"Seal report\" affordance is gone, and `/api/v1/reports` is\nGET-only, so an empty table now reads as an empty table rather than as reports\nthe operator was told had sealed.\n\n**Closure.** A period-close sweep that seals, or a deployed trigger that calls\nthe canonical seal path with real entitlement — at which point this entry is\ndeleted. Until then the honest claim is \"the Reporting Engine seals when\ninvoked\", never \"KYE issues periodic compliance reports\"."
      },
      {
        "title": "§0.49 — 133 hand-enumerated corpus lists; the class needs triage, not a blunt ratchet (registered 2026-08-05, decay_deadline: 2026-11-03)",
        "closure_date": null,
        "gate_path": "scripts/gates/implementation-canonical.mjs",
        "body": "**Owner:** platform-ops\n\n**Found 2026-08-05, by fixing one instance and asking how many there are.**\n`SCHEMA_DIRS` in `scripts/validate-schemas.js` was a hand-written array of\ndirectories that decided which schemas the canonical validator loads. All 33\n`<name>.schema.json` files under `private/specs/` carry an absolute `$id` in the\ncanonical namespace exactly as CLAUDE.md's Conventions require — and **none of\ntheir directories was in the list**. Their `$id` resolved nowhere, so 15 of the\n33 registries were failing the schema declared beside them with no failure\nreported anywhere. Fixed in that change-set: membership now derives from the\ndeclared `$id`, and the one-file `ajv.addSchema()` hand-patch that had been\npapering over the same gap was deleted (it announced itself immediately — with\nthe derived loader in place it threw `already exists`).\n\nA scan for the same shape found **133 module-level `*_DIRS` / `*_PATHS` /\n`*_ROOTS` / `*_FILES` list literals across `scripts/`.**\n\n**Why this is registered rather than ratcheted now.** 133 is not 133 defects, and\na decreases-only baseline over that population would manufacture false assurance\nin the opposite direction — the failure mode this repo already knows well. Enumerating\nis legitimate when the list IS the specification:\n\n- `REQUIRED_DIRS` / `REQUIRED_FILES` in `github-shape-canonical` — the repo shape\n  being enforced. The enumeration is the rule.\n- `FRAMEWORK_DIRS` in the sector gates — a declared governing scope, which is\n  what §0.43 asks for, not a narrowing.\n\nThe precise defect is narrower and worth stating exactly, because it is what\nmakes the class detectable: **a hand-written list that decides membership of a\ncanonical class whose artefacts already declare that membership themselves.**\n`SCHEMA_DIRS` qualified — schemas declare `$id`, so membership was already\nderivable and the list silently contradicted 33 of them. A framework list does\nnot qualify: no artefact declares \"I am in this gate's scope.\"\n\n**Closure.** Triage the 133 against that test and split them: (a) derivable from\na declaration the artefacts carry → convert to derivation; (b) the list IS the\nspec → declare it as scope in\n`private/specs/enforcement/enforcer-scopes.json`, which already exists for\nexactly this purpose; (c) genuine bespoke need → allowlist with a reason, the\n`SCAN_SCOPE_ALLOWLIST` precedent in `scripts/gates/implementation-canonical.mjs`.\nOnly after (a) and (b) is the residue a number a ratchet can honestly hold.\n\nThe detector then belongs as a fourth pattern in that gate's existing scan-scope\nsection (which already catches hand-rolled **walkers** via patterns A/B/C) — the\nsame concept one shape over, never a new gate. Building the detector before the\ntriage would encode today's false positives as tomorrow's baseline."
      },
      {
        "title": "§0.49 — `interface Quota` is hand-authored beside its generated model (registered 2026-08-01, decay_deadline: 2026-10-30)",
        "closure_date": null,
        "gate_path": null,
        "body": "**Owner:** platform\n\n**Found 2026-08-01.** `private/runtime/gateway/src/handlers/metering.ts` declares\n`interface Quota` by hand, restating the `state` enum of `kye.quota_grant.v1`.\nA generated model already exists at\n`private/types/generated/schemas/quota-grant.ts`, produced from that schema by\n`scripts/codegen/schemas-to-typescript.mjs`. This is the §0.49\nmodel-beside-schema anti-pattern: the copy happens to be correct today, and\nnothing keeps it that way.\n\nThe codegen script's own header records the scope decision — *\"SDK migration is\nOUT OF SCOPE — SDK files keep their manual types until a follow-up Ralph wave\nmigrates them to import from this generated surface.\"* Runtime files are in the\nsame position. This entry is that wave's ledger.\n\n**Closure.** Import the generated type and delete the local interface. Cheap in\nisolation, but it touches the reference server's build and wants its own test\ncycle rather than riding a decision-path change."
      },
      {
        "title": "§0.34 — the apex surface binds the PDP and cannot call it (decay_deadline: 2026-10-29)",
        "closure_date": null,
        "gate_path": null,
        "body": "**Owner:** platform\n\n**Found 2026-07-31.** `kye-protocol` (kyeprotocol.com) has bound `PDP → kye-pdp`\nsince before this date. Nothing on the surface has ever asked it for a decision:\nevery consequential request is authenticated and then simply performed, which is\n§0.33's doctrine ladder exactly — authentication answers *who is this*, never\n*may this happen*.\n\nThe wiring was written and then **withdrawn before shipping**, because\n`POST /decide` requires a Bearer API key with `runtime:write` scope (verified\nagainst D1, tenant resolved from the key row per §0.11) and 404s when the\ntenant has no `policy_sets` row. Verified live:\n\n```\nPOST https://pdp.kyeprotocol.com/decide  (no auth)\n→ 401 {\"ok\":false,\"error\":\"unauthorized\",\"reason\":\"missing_bearer\"}\n```\n\nThe apex holds no such credential, so a fail-closed decision point there would\nhave returned 403 on **every** form submission on the public site. Fail-closed is\ncorrect only when the call can succeed.\n\n**What closes it** — provisioning, not a code change:\n\n1. mint an apex API key with `runtime:write`, stored as a Pages **secret**\n   (never in the repo);\n2. seed a `policy_sets` row for the apex tenant with the public-surface rules\n   bundle — real policy content, authored, not scaffolded;\n3. re-land the middleware call and prove it end to end against the live PDP\n   before it is enforcing;\n4. convert to a rule: a surface that binds a decision point must consult it, the\n   Worker-side counterpart of the Pages bijection now in `edge-binding-coverage`.\n\nUntil then the honest state is: bound, health-probed, never consulted. It is not\nclaimed as governed anywhere.\n\n---"
      },
      {
        "title": "§0.29 — 9 deployed Workers have no activation path (decay_deadline: 2026-10-29)",
        "closure_date": null,
        "gate_path": null,
        "body": "**Owner:** platform\n\n**Found 2026-07-31**, by probing the live Cloudflare account while deriving the\nPages-bindings registry. Of 120 deployed Workers, 21 have **no way to be\ninvoked at all**: no cron trigger, no queue consumer, no route or custom domain,\nno workers.dev subdomain, no service binding from any other Worker, and no\nCloudflare Pages binding. Eleven of those belong to sibling projects in the same\naccount and are not KYE's to govern (§0.28). **Nine are KYE's:**\n\n| worker | in-repo declaration |\n|---|---|\n| `kye-admin-gateway` | none |\n| `kye-clickhouse-backfill` | none |\n| `kye-prior-search-saas-reindexer` | none |\n| `kye-signal-replayer` | none |\n| `kye-evidence-import-worker` | declared, no trigger |\n| `kye-oscal-exporter` | declared, no trigger |\n| `kye-reporting-agent` | declared, no trigger |\n| `kye-transparency-log-appender` | declared, no trigger |\n| `kye-search-indexer` | declares a queue consumer the live deploy does not have |\n\nA tenth, `kye-connector-certifier`, was in this set and is **closed**: the apex\nPages project now binds it (`CONNECTOR_CERTIFIER`), which is what the §44 probe\nset already assumed.\n\n**Why this is a §0.29 finding.** A deployed Worker that nothing can reach is the\n*hollow-runtime* anti-pattern seen from the deployment side: the artefact exists,\npasses every in-repo gate, and executes never. Four of the nine are worse — they\nare deployed with **no wrangler.toml anywhere in the repo**, so the deployed\nfleet is not the declared fleet. The existing `worker-deploy-alive` reconciler\nalready reports that half as advisory drift (\"extra in deploy\"); what it does not\ndo is treat unreachability as a defect.\n\n**Why it is not closed in this change-set.** Each of the nine needs a real\nper-worker decision — wire a caller, add the trigger its purpose implies, or\ndelete it from the platform — and deleting a deployed Worker is not reversible\nfrom the repo. Doing nine of those blind, in a change-set about registry\nconsolidation, is exactly the over-reach that produces broken production; the\nsame detector that reported these was wrong about 18 bindings earlier the same\nday, and the correction is in\n`private/roadmap/reconciliation/2026-07-31-pages-bindings-one-canonical.md`.\n\n**Trajectory.** Resolve each of the nine (wire / trigger / delete), then convert\nto a rule: extend `edge-binding-coverage`'s bijection with the Worker-side\ncounterpart — every deployed KYE Worker resolves to at least one activation path,\nderived from a platform-observed registry the same way the Pages registry now is.\nStrict zero at the deadline; the count may only decrease before it.\n\n---"
      },
      {
        "title": "§0.43 — `no-blind-spots` does not strip comments before matching scope markers (6 markers across 3 enforcers, decay_deadline: 2026-10-29)",
        "closure_date": null,
        "gate_path": "scripts/gates/no-blind-spots.mjs",
        "body": "**Owner:** platform\n\n**Found 2026-07-31**, while fixing an unrelated CI failure. The sibling detector\nin `implementation-canonical` flagged a *comment* that quoted the very\nanti-pattern it detects — a harmless false alarm, but it exposed the same root\ncause pointing the other way in `no-blind-spots`.\n\n`scripts/gates/no-blind-spots.mjs` matches each enforcer's\n`required_scope_markers[]` against the **raw source text**. A marker can\ntherefore be satisfied by a **comment** rather than by live code — so an\nenforcer can be scope-verified, declared `covered`, and counted among the 64,\non the strength of a marker that only narrates what the code does.\n\nOver-matching (implementation-canonical) is a false alarm and safe.\nUnder-matching here is **false assurance**, which is what §0.43 exists to\nprevent — the meta-gate has the defect class it was built to catch.\n\n**Measured, not hypothetical** — 6 markers across 3 of the 64 scope-verified\nenforcers resolve only in comments:\n\n| enforcer | markers |\n|---|---|\n| `audit-consistency` | 4 |\n| `competing-systems-scan` | 1 |\n| `schema-guard-canonical` | 1 |\n\nThis does **not** establish that those three are blind — only that their §0.43\n*proof* is weaker than the registry claims. Each needs its markers re-pointed at\nreal code, which is per-enforcer review rather than a mechanical sweep, hence the\nwindow.\n\n**Closure:** add comment-stripping to `no-blind-spots` by REUSING the existing\n`stripComments()` in `scripts/gates/air-gap-ability.mjs` (§0.49 — derive from the\ncanonical, never write a second stripper), then re-point the 6 markers. Expect\nthe 3 enforcers to flip `covered` → `declared-only` transiently; that ratchet\nmovement is the honest cost of removing a false proof, not a regression to hide.\n\n**Scope fence — do NOT generalise this closure.** Three text-matching enforcers\ntripped on documentation on 2026-07-31 alone (`implementation-canonical` on a\ncomment quoting the anti-pattern; `housekeeping` on a reconciliation note that\ncode-spanned a deliberately-absent path; this entry). They are not one class.\nThe direction decides the fix: where a comment produces a false **PASS** it is\n§0.43 blindness and must be stripped; where prose produces a false **FAIL** the\nenforcer is being conservative, which is the correct failure direction, and the\nauthor's text is what changes. Adding a mention-escape to `housekeeping` or to\nany decreases-only detector would be the §0.20 *verifier-weakening* anti-pattern\n— a genuinely stale path would simply be written inside the escape. Only\n`no-blind-spots` is in scope here.\n\n**decay_deadline:** 2026-10-29"
      },
      {
        "title": "§0.3 — Canonical-First baseline (323 vapor refs at adoption; re-dated by amendment 2026-07-15, then amendment 2026-08-28, decay_deadline: 2026-11-26)",
        "closure_date": "2026-11-26",
        "gate_path": "scripts/gates/canonical-first.mjs",
        "body": "**Amendment 2026-07-15 (honest miss, re-dated + made mechanical).** The\noriginal 2026-07-14 closure passed with the baseline at 328 (registry\n`private/specs/ratchets/baselines.json` `canonical_first__vapor_baseline`),\nand the date existed only in this document's prose — no gate tracked it,\nbecause the phrasing below matched none of the machine-readable deadline\ntokens `advisory-deadline-not-expired` scans for. This amendment (a) re-dates\nthe closure to 2026-08-27 (aligned with the §0.9 strict-flip cluster) with\nan explicit burn-down owner, and (b) phrases it with the enforced\n`decay_deadline:` token above, so the new date is self-enforcing — the day\nafter it, `test:advisory-deadline-not-expired` hard-fails CI until the\nbaseline is 0 or a further dated amendment lands. A silent pass can no\nlonger recur for this window.\n\n**Rule.** §0.3 declares Canonical-First: every `kye.<ns>.*.v<n>`\nreference in code must resolve to a canonical schema, vocabulary\nentry, or constitution-doc declaration. The rule was adopted\n2026-05-15 with a 60-day decay window starting at the historical\nbaseline of vapor refs.\n\n**Current state (2026-05-19).** Baseline 323 vapor refs. Net\ntrajectory decreasing as schemas are authored.\n\n**Gate.** `scripts/gates/canonical-first.mjs` runs in advisory mode\nwhile count ≤ baseline. New vapor refs above baseline block CI\n**immediately** — the window does not protect new debt, only legacy\ndebt being paid down. On 2026-07-14 BASELINE drops to 0 and the gate\nbecomes strict.\n\n**Resolution paths (per family):**\n\n| Vapor family | Resolution |\n|---|---|\n| `kye.evidence.*.v1` | Author the schema under `private/specs/schemas/`, register `$id` |\n| `kye.gateway.key.rotate` and other Gateway events | Add to `private/specs/openapi/kye-core-v1.yaml` operationIds |\n| `kye.connector_manifest.v1`, `kye.connector_profile.v1` | Rename refs to match canonical filename |\n| `kye.purchase_authority.*` (sandbox demo) | Author canonical schemas OR mark demo-internal |\n| `kye.decisions.create`, `kye.delegations.create` (dev portal examples) | Map to OpenAPI operationIds |\n\n**Closure date.** 2026-11-26 (re-dated by the 2026-07-15 amendment, then by amendment 2026-08-28; enforced via the `decay_deadline:` token in this entry's heading).\n\n**Amendment 2026-08-28 (§41(b) justified re-date, not silent).** The 2026-08-27\ndeadline arrived with `canonical_first__vapor_baseline` still at its declared\ncount (registry `private/specs/ratchets/baselines.json`), not 0 — the\ndeclaration-derived harvest (schemas by `$id`, class ids via the §0.51 admission\nmatrix, self-declaring artefacts, markdown front-matter) is the honest measure and\nthe remaining vapor refs are a real, still-open burn-down, not a fiction. The\nwindow is extended 90 days to continue that burn-down under the decreases-only\nratchet; recorded here per §41(b) so the extension is explicit, never silent.\n\n**Owner.** `KYE Protocol™ core team`.\n\n---"
      },
      {
        "title": "§0.3 — CI evidence packs are signed with an ephemeral per-run key (re-measured and re-scoped 2026-08-14, decay_deadline: 2026-11-12)",
        "closure_date": "2026-08-14",
        "gate_path": null,
        "body": "**Owner:** `KYE Protocol™ core team`\n\n**Rule.** §0.3 requires every CI run to emit the canonical\nself-governance evidence-event family\n(`kye.purpose.request.v1`, `kye.purpose.admissibility.v1`,\n`kye.evidence.decision_map.v1`, `kye.replay.context_seal.v1`,\n`kye.evidence.pack.v1`, `kye.replay.proof.v1`,\n`kye.evidence.tool_call.v1`, `kye.resilience.*.v1`,\n`kye.compliance.attestation.v1`).\n\n**This window reached its strict date (2026-08-14) invisibly, and that is the\nfirst thing it records.** Its heading said \"becomes strict 2026-08-14\" and its\nbody said \"**Closure date.** 2026-08-14\" — neither is a form\n`advisory-deadline-not-expired` parses, so of the 18 active windows this was the\none its own enforcer could not see. It reported \"all in the future\" on the\nmorning this one came due. Fixed at the root in the same change-set: the gate now\nhard-fails if any `###` heading under *Active decay windows* carries no\nmachine-readable deadline, so a window can no longer opt out of enforcement by\nhow it words its title (§0.43).\n\n**Re-measured 2026-08-14.** The state above was written 2026-05-19 and two of its\nthree gaps had since closed. Measured, not assumed:\n\n| stated gap (2026-05-19) | measured 2026-08-14 |\n|---|---|\n| `kye.compliance.attestation.v1` per control mapping — \"no emitter\" | **CLOSED.** 420 files under `scripts/` + `private/runtime/` emit it; it is the standard gate attestation. |\n| `kye.resilience.improvement_record.v1` on loop close — \"partial\" | **CLOSED.** `scripts/self-govern-kye-on-kye.mjs` emits it as artefact 11, conditionally (\"only when drift fires\"), which is the correct semantics — an improvement record with no drift to improve on would be a fabricated event. |\n| Ed25519 signing of CI evidence packs — \"uses test seed\" | **OPEN, and the description was wrong.** It does not use a test seed. `scripts/self-govern-kye-on-kye.mjs:219` generates a **fresh Ed25519 keypair per run**. |\n\n**What remains, stated precisely.** An ephemeral key is worse than a test seed\nfor the property that matters: a Replay-Proof™ must be verifiable *from public\nkeys alone*, and the public half of a per-run keypair does not outlive the run\nthat produced it. So a CI evidence pack is internally consistent and externally\nunverifiable — nobody can check tomorrow that today's pack was signed by KYE.\nEvery other part of the family is real, emitted, and schema-valid.\n\n**Why this is a window and not a fix.** Closing it needs a *provisioned\nproduction signing key*, which is the §0.29 admissible external: a credential not\nheld in-repo. The sibling item is already declared in\n`private/specs/compliance/tier1-readiness.json` `external_work_required`\n(`self-audit-daemon-signing-secret` — \"Provision SELF_AUDIT_SIGNING_JWK Worker\nSecret (+ HSM/KMS custody) … 1 day once the HSM/KMS key is exported\"). The CI\nevidence-pack key is the same custody question and rides the same provisioning.\n\n**This is a re-scope, not an extension (§41).** The original deadline is not\nbeing slid: two thirds of the work it covered is done and is recorded as done,\nthe remaining third is correctly described for the first time, and the new date\nis tied to a declared external dependency rather than to more authoring. Option\n(d) — \"extend the date by a one-line edit\" — is what the previous heading would\nhave permitted, which is precisely why it now cannot be worded that way.\n\n---"
      },
      {
        "title": "§0.4 — Dependency advisories with NO upstream fix (10 high at adoption 2026-07-28, decay_deadline: 2026-10-26)",
        "closure_date": null,
        "gate_path": null,
        "body": "**Rule.** §0.4 banking-grade requires a clean supply chain; an unpatched\nhigh-severity advisory in a shipped dependency tree is a §0.4 gap.\n\n**What was closed (2026-07-28).** GitHub reported 116 alerts on the default\nbranch. Measured locally, that is **three distinct advisories across 114\ntracked lockfiles**, dominated by repetition: `postcss` (path traversal, dev\ntooling via vitest → vite) appeared in **109** lockfiles, `brace-expansion`\nin 2, `js-yaml` in 2. 108 lockfiles were fixed to zero by\n`npm audit fix --package-lock-only`. Root went 2 → 0 on patch bumps only\n(brace-expansion 5.0.7 → 5.0.8, js-yaml 5.2.1 → 5.2.2).\n\n**What remains and why it is NOT fixable today (the honest part).**\n\n| workspace | count | chain | why unfixed |\n|---|---:|---|---|\n| `private/runtime/key-custody` | 6 | `@google-cloud/kms` → `google-gax` → rimraf → glob → minimatch → brace-expansion | **`google-gax` latest published version is 5.0.8 and the advisory range is `5.0.5 - 5.0.8`** — the newest release is itself vulnerable. Bumping `@google-cloud/kms` 5.5.0 → 5.7.0 was tested and still resolves `google-gax@5.0.6`. |\n| `private/runtime/visual-verify-worker` | 4 | `wrangler` → miniflare / postcss; `sharp` → libvips | `wrangler@latest` was tested and does not clear miniflare/postcss/sharp. |\n\nnpm reports `fixAvailable: true` for these, which is **misleading**: it means\n\"resolvable somewhere in the tree\", not \"an upstream patch exists\". Forcing\nresolution requires overriding `brace-expansion` across a `^2` → `^5` major\nboundary that `minimatch@9` depends on. That was attempted, reverted, and is\nNOT being shipped: forcing a major across the transitive tree of the **key\ncustody / signing** component without its test suite passing would trade a\ntheoretical DoS for a real signing outage.\n\n**Honest exposure assessment (§70).** All ten are DoS / path-traversal in\nbuild- and startup-time path utilities (glob/minimatch/brace-expansion) or in\ndev tooling (postcss, miniflare, wrangler). None is reachable from a deployed\nWorker request path. This is a supply-chain hygiene gap, not a live\nexploitable production vulnerability — and it is recorded as the former, not\ndowngraded away.\n\n**Closure condition.** Upstream `google-gax` publishes a release outside\n`5.0.5 - 5.0.8`, and wrangler/sharp ship non-vulnerable transitives. Re-run\nthe 114-workspace sweep and drive to zero. If upstream has not moved by the\ndeadline, the alternative is an override **plus** a green test run for both\ncomponents, evidenced — never an override alone.\n\n**Owner.** `KYE Protocol™ core team`."
      },
      {
        "title": "§40 — 57 of 58 concepts declare no competitor pattern (registered 2026-07-30, decay_deadline: 2026-10-28)",
        "closure_date": null,
        "gate_path": null,
        "body": "**Rule.** §40 check (4) can only protect a concept that declares\n`competitor_forbidden_patterns`. An undeclared concept is not scanned at all.\n\n**What was found.** Before 2026-07-30 the field was empty for **all 58** concepts,\nso the duplicate-implementation scan had nothing to scan anywhere in the repo\nwhile the gate reported clean — §0.43 at the registry level. `purpose.admit` is\nnow declared (1 of 58).\n\n**Closure design.** Declare a competitor pattern per concept, highest-risk first\n(decision-path and evidence-path concepts before presentation ones). Tracked by\nthe decreases-only ratchet\n`implementation_canonical__concepts_without_competitor_patterns` (57 → 0) in\n`private/specs/ratchets/baselines.json`; the gate hard-fails if the count rises.\n\n**Owner.** `KYE Protocol™ core team`.\n\n---"
      },
      {
        "title": "§39/§0.44 — the warm-contact readability judge has never once reviewed a beat (registered 2026-08-08, decay_deadline: 2026-11-06)",
        "closure_date": null,
        "gate_path": null,
        "body": "**Rule.** §0.44 property (2): a control that is declared but never effective is a\nhollow claim, not assurance. §0.29: a component that never reaches its stated\nfunction is not shipped, whatever its status says.\n\n**What was found.** `readabilityReasons()` in `scripts/build-warm-contact-journey.mjs`\nis the only check on the English of a beat that will be SPOKEN ALOUD to a warm\ncontact. On every round of every observed run it rejected the MAJORITY of beats\nand its verdict was therefore discarded by the `> beats.length / 2` guard — so\nthe English has been reviewed on exactly zero runs while the pipeline reported\nsuccess. The pipeline exits 0 either way, because a discarded verdict is not a\nfailure anywhere downstream.\n\n**Why the existing explanation is not the diagnosis.** The guard's comment\nattributes this to a miscalibrated judge. Probed directly on 2026-08-08 through\nthe same `sonar` call the function makes:\n\n| input | flagged |\n|---|---|\n| 5 deliberately garbled sentences | **5/5**, reasons accurate (\"garbled word order\", \"does not parse\") |\n| 5 clean grammatical sentences | **2/5**, both false positives citing *style* (\"awkward and incomplete in meaning\") — the category the prompt explicitly forbids |\n\nThe judge discriminates. It has a high false-positive rate on clean text, and its\nfalse positives are precisely the style judgements it was told not to make. That\ninverts the guard's logic: majority-rejection is what a CORRECT judge returns on a\ngenuinely broken batch, so the discard throws away the case the judge gets right,\nwhile what actually triggers it in production is the false-positive rate.\n\n**Why registered rather than fixed in this change-set.** One probe is a sample of\none. Redesigning a governed control on it — filtering findings by their stated\nreason, inverting the majority rule, or swapping the model — would be the same\nguessing the mechanical guardrails in that file exist to prevent, shipped into the\npath that decides what a recipient hears. The measurement is the precondition for\nthe fix, and it ships now.\n\n**Closure design.** Run the judge N≥20 times against beats of known quality\n(clean production beats, and beats with injected grammatical defects) to get a\nreal false-positive and false-negative rate. Then either (a) filter its findings\nby the criterion it was given, keeping only reasons that assert a parse failure,\n(b) replace `sonar` — a web-search research model reached through the §62 GATHER\npath — with a model suited to judging text, or (c) delete the control and say so,\nsince no check is more honest than one that never fires. Whichever is chosen must\nbe verified in BOTH directions, as above: a judge that cannot be shown to catch\nbroken English is not a judge.\n\n**Owner.** `KYE Protocol™ core team`.\n\n---"
      },
      {
        "title": "§0.29 — nine workers do not compile, and a stale ledger hid it on main (registered 2026-08-09, decay_deadline: 2026-11-07)",
        "closure_date": null,
        "gate_path": null,
        "body": "`functional-inventory-coverage` reads a COMMITTED ledger\n(`_diagnostics/functional-inventory.json`) that is regenerated only on demand.\nThe last regeneration was 2026-08-04 and recorded `unbootable: 6`. The live\nscan returns **11**, against a gate baseline of 10 — so `main` has been failing\nthis gate, and the staleness of the ledger was the thing concealing it. That\nmakes ledger staleness a correctness problem, not hygiene: a decreases-only\nratchet whose input is refreshed by hand can be breached silently for as long\nas nobody refreshes it.\n\n**Measured, not inferred.** A git worktree at `origin/main`, with no branch\nchanges present, runs the gate and fails identically: `unbootable: 11 > baseline\n10`, total 1790. The change-set that surfaced it contributes +1 to TOTAL (one new\nscript) and +0 to `unbootable`. It surfaced only because that change added an\nentity type, which made the ledger stale enough to force a regeneration.\n\n**What is actually broken.** Seven workers fail to compile, all in the same\ndocumented unresolved-import class, plus two that boot but fail closed without\nprovisioned runtime state:\n\n| Worker | Unresolved |\n|---|---|\n| `gateway-worker` | `@kye/clickhouse-client` |\n| `kye-pdp-worker` | `@kye/pdp` |\n| `kye-audit-pilot-agent-worker` | `@kye/authority-gap-detector` |\n| `visual-verify-worker` | `@cloudflare/puppeteer` |\n| `self-audit-daemon`, `commercial-lifecycle-worker`, `kye-reporting-worker` | entry not resolvable from the declared path |\n\n**Why registered rather than fixed in that change-set.** The fix is installing or\nlinking missing workspace and npm dependencies across nine workers — a toolchain\nchange with broad blast radius, in a change-set about a citation registry and an\nattestation ratchet. Absorbing it would bury both. Raising the baseline 10 → 11\nwithout this registration would be exactly the baseline-drift the gate's own\nheader warns against, so the raise and this entry ship together.\n\n**Closure design.** Install/link the missing deps so the seven compile-failures\ncompile and boot, taking `unbootable` to 4 (the 2 provisioned-state workers + 2\n`.test.js` fixtures), then lower the baseline to match. Separately, make the\nledger's freshness self-enforcing — a ratchet input that only refreshes when\nsomeone remembers is a ratchet that can be breached in silence, which is the\ndefect this entry exists to record.\n\n**Owner.** `KYE Protocol™ core team`.\n\n---"
      },
      {
        "title": "§16/§0 — `conformance_runs` is two different tables under one name (registered 2026-08-11, decay_deadline: 2026-11-09)",
        "closure_date": null,
        "gate_path": null,
        "body": "**Owner:** `KYE Protocol™ core team`\n\n`conformance_runs` is declared twice, with incompatible shapes, and which one\nexists on a given D1 depends on execution order:\n\n| Declared in | Shape |\n|---|---|\n| `private/runtime/d1/migrations/005_init_conformance_certification_self_audit.sql` | `run_id` PK, `implementation_id` NOT NULL, `test_suite_version` NOT NULL, `started_at`, `completed_at`, `result`, `findings_json`, … |\n| `private/runtime/kye-conformance-scheduler-worker/src/index.ts` `ensure()` (runtime DDL) | `id` PK, `tenant_id`, `kind`, `triggered_at`, `completed_at`, `result` |\n\nBoth use `CREATE TABLE IF NOT EXISTS`, so **whichever runs first wins and the\nother silently does nothing**. The scheduler then writes\n`INSERT INTO conformance_runs (id, tenant_id, kind, triggered_at)` — against the\nmigration-005 shape that INSERT cannot succeed: `id` is not a column, and\n`implementation_id` / `test_suite_version` are `NOT NULL` with no default. So on\nany D1 where the migration ran first, every scheduled and manual conformance run\nhas been failing at the insert.\n\n**Why it was invisible.** `schema-authority-canonical` scans deployed code for\nruntime DDL. Its comment stripper read the `/*` inside a `\"*/*\"` Accept-header\ncheck as a block-comment open and deleted 12,772 characters of the scheduler\nworker — this DDL included. The stripper is now canonical\n(`scripts/lib/strip-comments.mjs`, §0.49) and the gate sees the whole file,\nwhich is what surfaced this. The sibling half of the same defect —\n`policy_sets` runtime DDL in the PDP worker — is fixed in the same change-set\n(`063_policy_sets.sql`, renumbered from 062 on merge), because it had no competing declaration and needed no\ndesign decision.\n\n**Why this one is registered rather than fixed here.** The two shapes are not a\ndrifted copy of one concept; they are two concepts colliding on a name. The\nmigration models a §15 Conformance Pack **result** (which implementation, which\nsuite version, what findings). The worker models a **scheduling record** (which\ntenant, cron or manual, when triggered) — and it carries the `tenant_id` that\n§0.11 requires and the migration never declared. Resolving that means either\nsplitting the scheduling concept onto its own canonical table or retyping\n`NOT NULL` columns on the shared one (a SQLite table rebuild, not an additive\nmigration). Either is a schema decision about a **deployed** worker, and making\nit silently inside a change-set whose subject is enforcer visibility would be\nthe §0 move this entry exists to prevent.\n\n**Acceptance criteria.** One declaration per table name; the scheduler's INSERT\nand SELECT resolve against migration-declared columns; no `CREATE TABLE` remains\nin `kye-conformance-scheduler-worker`; `schema-authority-canonical` counts one\nfewer, and the corresponding `sql-column-canonical` backlog rows for\n`conformance_runs` clear with it.\n\n---"
      }
    ],
    "closed_count": 8,
    "sha256": "b846bcb3d48a67c150e1f0296ef884cb92d27b22972f32634fab5ec21c3e920e"
  },
  "implementation_registry": {
    "schema": "kye.implementation_registry.v1",
    "registry_id": "kye:registry:implementation-registry",
    "version": "1.0",
    "adopted": "2026-05-19",
    "constitution_ref": "constitution/40-IMPLEMENTATION-CANONICAL.md",
    "notes": [
      "Seed manifest. Identified concepts from the 2026-05-19 audit prompted by 'we need to be 10000% certain there is only one implementation'. This file grows with every concept clarified — but the registry is itself canonical: any merge that adds a NEW reimplementation of a registered concept fails CI.",
      "2026-05-21 full runtime drift audit: registry extended from 19 to 46 concepts. Triggered by the prior third-party search SaaS→KYE Native Search Engine drift that CI missed because search/directory were unregistered. Competing-systems smells (gateway-worker consolidation, kye-reporting-worker vs kye-reporting-agent-worker, dead private/runtime/search/) are tracked for the runtime-consolidation PR.",
      "2026-05-23 framework-coverage bidirectional mapping: each concept MAY carry an optional `framework_coverage[]` array of requirement_ids (matching private/specs/compliance/<framework>/*.json). Verified by scripts/gates/framework-coverage-bijection.mjs. The companion framework-requirement registry (private/specs/compliance/<framework>/) provides the OUTBOUND map; framework_coverage[] here provides the INBOUND map. Bijection enforced at CI."
    ],
    "concepts": [
      {
        "concept_id": "agent-dev-kit",
        "entity_class": "concept",
        "name": "KYE Agent Dev Kit (TS + Python — agent SDK + lifecycle hooks)",
        "plane": "runtime",
        "constitution_ref": "constitution/32-AGENT-DEV-KIT.md",
        "ssot_module": "private/runtime/agent-dev-kit",
        "ssot_package": "@kye/agent-dev-kit",
        "ssot_entry_point": "lifecycle hooks + evidence helpers",
        "transport_wrappers": [
          {
            "module": "private/runtime/agent-dev-kit-python",
            "transport": "language-port",
            "note": "Python port (kye-agent-dev-kit) — same contract, separate language; parallel SSOT per §32."
          }
        ],
        "competitor_forbidden_patterns": [
          "function makePurposeAdmissibility(",
          "const makePurposeAdmissibility =",
          "class makePurposeAdmissibility "
        ]
      },
      {
        "concept_id": "agent.demo",
        "entity_class": "concept",
        "name": "Demo Agent — SSOT library",
        "plane": "onboarding",
        "constitution_ref": "constitution/14-AGENTS-AND-ENGINES.md",
        "ssot_module": "private/runtime/demo-agent",
        "ssot_package": "@kye/demo-agent",
        "ssot_entry_point": "DemoAgent",
        "transport_wrappers": [
          {
            "module": "private/runtime/kye-demo-agent",
            "transport": "http",
            "note": "CF Worker — agent_manifest runtime_path for the Demo Agent; imports the SSOT via ../../demo-agent/src/index.js."
          }
        ],
        "competitor_forbidden_patterns": [
          "function CANONICAL_DEMO_SCENARIOS(",
          "const CANONICAL_DEMO_SCENARIOS =",
          "class CANONICAL_DEMO_SCENARIOS "
        ]
      },
      {
        "concept_id": "agent.dsar-evidence",
        "entity_class": "concept",
        "name": "DSAR Evidence Agent — SSOT library",
        "plane": "evidence",
        "constitution_ref": "constitution/14-AGENTS-AND-ENGINES.md",
        "ssot_module": "private/runtime/dsar-evidence-agent",
        "ssot_package": "@kye/dsar-evidence-agent",
        "ssot_entry_point": "DsarEvidenceAgent",
        "transport_wrappers": [
          {
            "module": "private/runtime/kye-dsar-evidence-agent",
            "transport": "http",
            "note": "CF Worker — agent_manifest runtime_path for the DSAR Evidence Agent; imports the SSOT via ../../dsar-evidence-agent/src/index.js."
          }
        ],
        "competitor_forbidden_patterns": [
          "function assembleEvidenceRows(",
          "const assembleEvidenceRows =",
          "class assembleEvidenceRows "
        ]
      },
      {
        "concept_id": "agent.entitlements",
        "entity_class": "concept",
        "name": "Entitlements Agent — SSOT library",
        "plane": "billing",
        "constitution_ref": "constitution/14-AGENTS-AND-ENGINES.md",
        "ssot_module": "private/runtime/entitlements-agent",
        "ssot_package": "@kye/entitlements-agent",
        "ssot_entry_point": "EntitlementsAgent",
        "transport_wrappers": [
          {
            "module": "private/runtime/kye-entitlements-agent",
            "transport": "http",
            "note": "CF Worker — agent_manifest runtime_path for the Entitlements Agent; imports the SSOT via ../../entitlements-agent/src/index.js."
          }
        ],
        "competitor_forbidden_patterns": [
          "function EntitlementsAgent(",
          "const EntitlementsAgent =",
          "class EntitlementsAgent "
        ]
      },
      {
        "concept_id": "agent.ops",
        "entity_class": "concept",
        "name": "Ops Agent — SSOT library",
        "plane": "runtime",
        "constitution_ref": "constitution/14-AGENTS-AND-ENGINES.md",
        "ssot_module": "private/runtime/ops-agent",
        "ssot_package": "@kye/ops-agent",
        "ssot_entry_point": "OpsAgent",
        "transport_wrappers": [
          {
            "module": "private/runtime/kye-ops-agent",
            "transport": "http",
            "note": "CF Worker — agent_manifest runtime_path for the Ops Agent; imports the SSOT via ../../ops-agent/src/index.js."
          }
        ],
        "competitor_forbidden_patterns": [
          "function disabledCapabilityIds(",
          "const disabledCapabilityIds =",
          "class disabledCapabilityIds "
        ]
      },
      {
        "concept_id": "agent.silent-compromise",
        "entity_class": "concept",
        "name": "Silent Compromise Agent — SSOT library",
        "plane": "governance",
        "constitution_ref": "constitution/14-AGENTS-AND-ENGINES.md",
        "ssot_module": "private/runtime/silent-compromise-agent",
        "ssot_package": "@kye/silent-compromise-agent",
        "ssot_entry_point": "SilentCompromiseAgent",
        "transport_wrappers": [
          {
            "module": "private/runtime/kye-silent-compromise-agent",
            "transport": "http",
            "note": "CF Worker — agent_manifest runtime_path for the Silent Compromise Agent; imports the SSOT via ../../silent-compromise-agent/src/index.js."
          }
        ],
        "competitor_forbidden_patterns": [
          "function SilentCompromiseAgent(",
          "const SilentCompromiseAgent =",
          "class SilentCompromiseAgent "
        ]
      },
      {
        "concept_id": "agent.sku-lifecycle",
        "entity_class": "concept",
        "name": "SKU Lifecycle Agent — SSOT library",
        "plane": "billing",
        "constitution_ref": "constitution/14-AGENTS-AND-ENGINES.md",
        "ssot_module": "private/runtime/sku-lifecycle-agent",
        "ssot_package": "@kye/sku-lifecycle-agent",
        "ssot_entry_point": "SkuLifecycleAgent",
        "transport_wrappers": [
          {
            "module": "private/runtime/kye-sku-lifecycle-agent",
            "transport": "http",
            "note": "CF Worker — agent_manifest runtime_path for the SKU Lifecycle Agent; imports the SSOT via ../../sku-lifecycle-agent/src/index.js."
          }
        ],
        "competitor_forbidden_patterns": [
          "function SkuLifecycleAgent(",
          "const SkuLifecycleAgent =",
          "class SkuLifecycleAgent "
        ]
      },
      {
        "concept_id": "agent.trainer",
        "entity_class": "concept",
        "name": "Trainer Agent — SSOT library",
        "plane": "runtime",
        "constitution_ref": "constitution/14-AGENTS-AND-ENGINES.md",
        "ssot_module": "private/runtime/trainer-agent",
        "ssot_package": "@kye/trainer-agent",
        "ssot_entry_point": "TrainerAgent",
        "transport_wrappers": [
          {
            "module": "private/runtime/kye-trainer-agent",
            "transport": "http",
            "note": "CF Worker — agent_manifest runtime_path for the Trainer Agent; imports the SSOT via ../../trainer-agent/src/index.js."
          }
        ],
        "competitor_forbidden_patterns": [
          "function TrainerAgent(",
          "const TrainerAgent =",
          "class TrainerAgent "
        ]
      },
      {
        "concept_id": "analytics.clickhouse-client",
        "entity_class": "concept",
        "name": "Analytics Plane HTTP client for ClickHouse (Worker-compatible)",
        "plane": "runtime",
        "constitution_ref": "constitution/20-ANALYTICS-PLANE.md",
        "ssot_module": "private/runtime/clickhouse-client",
        "ssot_package": "@kye/clickhouse-client",
        "ssot_entry_point": "tenant-token-scoped ClickHouse HTTP client (tables / projections / queries / audit-emit)",
        "transport_wrappers": [],
        "competitor_forbidden_patterns": [
          "function assertTemplateIsTenantSafe(",
          "const assertTemplateIsTenantSafe =",
          "class assertTemplateIsTenantSafe "
        ]
      },
      {
        "concept_id": "audit.chain.append",
        "entity_class": "concept",
        "name": "Audit chain append + the chain id it appends to (§0.3 evidence emission)",
        "plane": "audit",
        "constitution_ref": "constitution/21-DELEGATED-AUDITABILITY.md",
        "ssot_module": "private/runtime/audit-chain",
        "ssot_package": null,
        "ssot_entry_point": "appendEvent(envelope) · workerChainEmitter(baseUrl) · tenantChainId(tenant_id) / platformChainId(component)",
        "transport_wrappers": [
          {
            "module": "private/runtime/audit-chain-worker",
            "transport": "http",
            "note": "HTTP surface; receives the append from every privileged Worker. It is the RECEIVER, so it legitimately owns CHAIN_ID_RE and the /v1/chains/:chain_id/{append,verify} route patterns — a validator has to spell out what it validates. Declared so the enforcer does not accuse the one module whose job is to hold the shape."
          },
          {
            "module": "private/lib/chain-id",
            "transport": "library",
            "note": "The tenant→chain-id derivation. private/lib/chain-id is the SSOT (plain JS so BOTH the TypeScript emitter can import it and the public plane can receive it by byte-projection across §33); the public/site/functions copy is that projection, verified byte-for-byte by this gate."
          },
          {
            "module": "public/site/functions/api/_lib/chain-id.js",
            "transport": "projection",
            "note": "Byte-projection of private/lib/chain-id for the Pages Functions, which cannot import a private/ module across §33. Three of them wrote `kye:audit-chain:${tenantId}` inline with no strip — accepted by the receiver, but a DIFFERENT chain from the stripped form, so a tenant's audit history split in two."
          }
        ],
        "competitor_forbidden_patterns": [
          "function InProcessAuditEmitter(",
          "const InProcessAuditEmitter =",
          "class InProcessAuditEmitter ",
          "`kye:audit-chain:${",
          "function canonicalEmit(",
          "function chainIdForTenant("
        ],
        "competitor_baseline_key": "implementation_canonical__competitors__audit_chain_append",
        "migration": {
          "status": "complete",
          "tracked_in": "private/specs/ratchets/baselines.json#implementation_canonical__competitors__audit_chain_append"
        },
        "projection_anchor": {
          "begin": "// >>> canonical chain-id — generated from private/lib/chain-id/index.js; do not edit",
          "end": "// <<< canonical chain-id",
          "anchor_bearers": [
            {
              "path": "scripts/lib/projection-specs.mjs",
              "role": "definition",
              "reason": "Declares the anchor strings as data for both the generator and the verifier, so it necessarily contains every token. It was split out of the generator in 2026-08-14 precisely because importing a SCRIPT for its data executed its write — the verifier repaired the drift it existed to detect, then passed."
            }
          ]
        }
      },
      {
        "concept_id": "audit.replay-run",
        "entity_class": "concept",
        "name": "Audit replay orchestration (re-derive evidence packs on a cadence + emit drift)",
        "plane": "audit",
        "constitution_ref": "constitution/21-DELEGATED-AUDITABILITY.md",
        "ssot_module": "private/runtime/audit-replay-orchestrator",
        "ssot_package": null,
        "ssot_entry_point": "scheduled() — worker.js",
        "transport_wrappers": [],
        "competitor_forbidden_patterns": [
          "function AuditReplayOrchestrator(",
          "const AuditReplayOrchestrator =",
          "class AuditReplayOrchestrator "
        ]
      },
      {
        "concept_id": "audit.self-audit-daemon",
        "entity_class": "concept",
        "name": "Self-Audit Daemon — live self-governance library",
        "plane": "audit",
        "constitution_ref": "constitution/00-INDEX.md",
        "ssot_module": "private/runtime/self-audit-daemon/src",
        "ssot_package": null,
        "ssot_entry_point": "worker.js (scheduled + fetch)",
        "note": "The ONE implementation of §0.3 self-governance proven on production/live: the governed-inventory lane (governed-inventory.js), the patent-safe live bundle built and Ed25519-signed with the production key (live-bundle.js), the GitHub Actions OIDC door that admits a workflow run of this repository to start a cycle (github-oidc.js), and the cycle itself, which records its outcome as public evidence beside the bundle (worker.js). Judged 2026-09-25 when github-oidc.js became the third shared module of this directory: live-bundle.js and governed-inventory.js sat in unregistered_backlog[] since 2026-09-10 as measurements not yet judged — this row is that judgement, and their backlog entries are removed with it. A second verifier of GitHub's OIDC, a second live-bundle signer or a second governed-inventory walker anywhere in the estate is a competing implementation of this concept.",
        "competitor_forbidden_patterns": [
          "function verifyGithubActionsToken(",
          "function buildAndSignLiveBundle(",
          "function runGovernedInventory(",
          "function publishLiveBundle("
        ]
      },
      {
        "concept_id": "authority.grant",
        "entity_class": "concept",
        "name": "Authority Engine (issue/revoke/validate Authority Grants + delegation walk)",
        "plane": "decision",
        "constitution_ref": "constitution/14-AGENTS-AND-ENGINES.md",
        "ssot_module": "private/runtime/authority-engine",
        "ssot_package": "@kye/authority-engine",
        "ssot_entry_point": "grant / revoke / validate + cascade",
        "transport_wrappers": [],
        "competitor_forbidden_patterns": [
          "function verifyGrantViaCustody(",
          "const verifyGrantViaCustody =",
          "class verifyGrantViaCustody "
        ]
      },
      {
        "concept_id": "authority.proof-bundle.assemble",
        "entity_class": "concept",
        "name": "Authority Proof Bundle assembler",
        "plane": "evidence",
        "constitution_ref": "constitution/14-AGENTS-AND-ENGINES.md",
        "ssot_module": "private/runtime/authority-proof-bundle",
        "ssot_package": null,
        "ssot_entry_point": "assembleBundle(...)",
        "transport_wrappers": [
          {
            "module": "private/runtime/authority-proof-bundle-worker",
            "transport": "http",
            "note": "HTTP surface that wraps the assembler"
          }
        ],
        "competitor_forbidden_patterns": [
          "function assembleBundle(",
          "const assembleBundle =",
          "class assembleBundle "
        ]
      },
      {
        "concept_id": "billing.metering",
        "entity_class": "concept",
        "name": "Stripe billing/metering client (BPS calc + meter batcher + webhook verify)",
        "plane": "billing",
        "constitution_ref": "constitution/23-BILLING-METERING.md",
        "ssot_module": "private/runtime/stripe-client",
        "ssot_package": "@kye/stripe-client",
        "ssot_entry_point": "typed Stripe wrapper + meter batcher",
        "transport_wrappers": [
          {
            "module": "private/runtime/stripe-meter",
            "transport": "cron",
            "note": "Hourly Stripe meter Worker (§23)"
          }
        ],
        "competitor_forbidden_patterns": [
          "function BPS_APPLICABLE_ACTION_CLASSES(",
          "const BPS_APPLICABLE_ACTION_CLASSES =",
          "class BPS_APPLICABLE_ACTION_CLASSES "
        ]
      },
      {
        "concept_id": "chain.input_fingerprint",
        "entity_class": "concept",
        "name": "Which tree did the gate chain actually pass on? (the falsifiable already-ran proof)",
        "plane": "governance",
        "constitution_ref": "constitution/00-INDEX.md",
        "ssot_module": "scripts/lib/chain-input-fingerprint.mjs",
        "ssot_package": null,
        "ssot_entry_point": "inputFingerprint() · scopedFingerprint(paths) · inputsClean() · freshness() · isChainOutput(path) · CHAIN_OUTPUT_PATHSPEC / CHAIN_OUTPUT_ROOTS",
        "transport_wrappers": [],
        "migration": {
          "status": "complete",
          "note": "Registered 2026-09-10 by the same tree-side inverse that found git-env. Nine distinct importers — run-gates records the fingerprint, .githooks/pre-push verifies it, and build-derived-all, fresh-all, merge-authority, devplane-pep, canonical-first, ip-oss-line, scoped-chain and prove-read-backs all resolve CHAIN_OUTPUT_PATHSPEC through it. That pathspec is the estate's ONE declaration of which paths are the chain's own outputs rather than its inputs, which is why a second copy would be silently catastrophic: a hand-rolled exclusion list that disagrees by one path makes a green chain unprovable or, worse, provable on a tree that moved. HONEST LIMIT: the fingerprint covers the TRACKED tree minus the chain's own outputs, via git ls-files -s, so it moves on content/mode/rename/add/delete of an input and does NOT see unstaged working-tree edits — which is why inputsClean() exists beside it and the skip requires both."
        },
        "competitor_forbidden_patterns": [
          "function inputFingerprint(",
          "const inputFingerprint =",
          "function isChainOutput(",
          "const isChainOutput =",
          ":(exclude)_diagnostics"
        ]
      },
      {
        "concept_id": "ci.privileged_op_evidence",
        "entity_class": "concept",
        "name": "Emit the §0.3 evidence family for a privileged CI action",
        "plane": "evidence",
        "constitution_ref": "constitution/00-INDEX.md",
        "ssot_module": "scripts/ci/govern-privileged-op.mjs",
        "ssot_package": null,
        "ssot_entry_point": "node scripts/ci/govern-privileged-op.mjs (env: GOP_CAPABILITY, GOP_PURPOSE, GOP_ALLOWED_EVENTS)",
        "transport_wrappers": [],
        "competitor_forbidden_patterns": [
          "function emitEvidencePack(",
          "const emitEvidencePack ="
        ],
        "competitor_baseline_key": "implementation_canonical__competitors__ci_privileged_op_evidence",
        "migration": {
          "status": "complete",
          "note": "Registered 2026-08-15. Invoked BOTH via the .github/actions/govern-op composite AND directly by workflows such as deploy-cloudflare-pages.yml. An agent grepping only the composite name reported KYE's public landing deploy as ungoverned — a false finding caused by matching the wrapper instead of the mechanism."
        }
      },
      {
        "concept_id": "ci.workflow_privileged_classification",
        "entity_class": "concept",
        "name": "Is a CI workflow privileged, and at what tier?",
        "plane": "governance",
        "constitution_ref": "constitution/00-INDEX.md",
        "ssot_module": "scripts/lib/workflow-classification.mjs",
        "ssot_package": null,
        "ssot_entry_point": "classifyWorkflow({ slug, text, triggers }) -> { kind, risk_tier, privileged_ops, classification_basis }",
        "transport_wrappers": [],
        "competitor_forbidden_patterns": [
          "function classifyWorkflow(",
          "const classifyWorkflow ="
        ],
        "competitor_baseline_key": "implementation_canonical__competitors__ci_workflow_privileged_classification",
        "migration": {
          "status": "complete",
          "note": "Registered 2026-08-15 after an agent hand-rolled a secrets+mutation grep as a THIRD copy of this question. The module's own header already warned: workflow-governance-coverage asks 'is this privileged, and is it governed?' and build-workflow-registry asks 'is this privileged, so what tier?' — same question, one answer. Its HONEST LIMIT is load-bearing: 'mutating' means the canonical privileged-op set, and widening that set is a §0.3 amendment, not a tweak. A grep that widens it silently produces false gaps."
        }
      },
      {
        "concept_id": "ckan.connector",
        "entity_class": "concept",
        "name": "CKAN Connector (read-only CKAN Action API client → canonical KYE entities)",
        "plane": "connector",
        "constitution_ref": "constitution/28-CKAN-OPEN-DATA.md",
        "ssot_module": "private/runtime/ckan-connector",
        "ssot_package": "@kye/ckan-connector",
        "ssot_entry_point": "pull portal/datasets/activity → map to KYE entities",
        "transport_wrappers": [
          {
            "module": "private/runtime/ckan-connector-worker",
            "transport": "cron",
            "note": "Cron-triggered harvester Worker"
          }
        ],
        "competitor_forbidden_patterns": [
          "function mapPortalStatus(",
          "const mapPortalStatus =",
          "class mapPortalStatus "
        ]
      },
      {
        "concept_id": "commerce.sku_boot",
        "entity_class": "concept",
        "name": "The declared SKU set, and booting one SKU from the canonical manifest — what counts as a SKU that exists",
        "plane": "commerce",
        "constitution_ref": "constitution/26-COMMERCIAL.md",
        "ssot_module": "scripts/lib/sku-families.mjs",
        "ssot_package": null,
        "ssot_entry_point": "skuFamiliesOf(schema) · skuRowsOf(manifest, families) · undeclaredSkuArrays(manifest, families) · assertKeyedByFamily(map, families, label) — loaded from disk by the node wrapper as skuFamilies() · allSkus() · allSkuIds() · intakeSkuIds(surface) · bootSku(skuId) · isSkuCallable(skuId) · skuLifecycleEvent(skuId)",
        "transport_wrappers": [
          {
            "module": "scripts/lib/sku-eval.mjs",
            "transport": "import",
            "must_import": "./sku-families.mjs",
            "note": "Reads the manifest and its contract from disk through canonical-paths and delegates every decision to the pure SSOT; scripts, gates and the reconciler import this. The bundled commercial-lifecycle worker imports the SSOT directly, because a Worker cannot read files."
          }
        ],
        "note": "DECLARED 2026-10-01 because a second consumer arrived, not because a second implementation did. The module has existed as the boot of kye:registry:skus (private/specs/skus/sku_manifest.json) for the executable-coverage gate; apply-cta-sku-canonical became the second importer when it was rewritten to resolve every ?sku= deep link against the declared set instead of merely testing that a parameter is present, and implementation-canonical correctly refused the commit until the shared implementation had a concept row (§0.9 — an artefact referenced from more than one file belongs to a canonical registry). The SSOT is the one place that knows the eight declared families (pilot_skus · annual_skus · sector_packs · assurance_addons · edge_addons · developer_skus · engagement_skus · consultant_skus) sum to the declared SKU set; a consumer asks for the set and never re-types the family list. MIGRATED THE SAME DAY. The family set is no longer known here either: it is DECLARED once, in the manifest's contract (kye.commercial.sku_manifest.v1 — an array property whose items reference #/$defs/sku_row is a family), and read through scripts/lib/sku-families.mjs — the pure SSOT since that day (no I/O, no Node imports), imported by the bundled commercial-lifecycle worker directly and by everything else through scripts/lib/sku-eval.mjs, its node loader. All twelve inline copies now ask this module (skuFamilies() · allSkus() · allSkuIds()), and three of them had lost engagement_skus: the canonical graph (so the published SKU count read 161 of 300), the sku-manifest-alive reconciler, and the worker's SKU lookup, which resolved no entitlement for any of the 139 §49 tiers. Maps keyed by family (cost ratios, disclosure owners, offering owner rails) are asserted to cover exactly the declared families. The inline enumeration is therefore now a forbidden pattern too: with zero copies left there is nothing to hold, and a thirteenth fails at once. sku-manifest-canonical verifies the declaration from the other end — SKU rows outside a declared family are refused. THE PATTERN SET FOUND A REAL COMPETITOR ON ITS FIRST RUN, which is why it is declared rather than exempted: scripts/gates/sku-owner-canonical.mjs built its own `const allSkuIds = new Set()` by walking EVERY array in the manifest (Object.values) instead of its eight declared families — so it would have silently absorbed any future array that is not a SKU family, and it carried no family classification. Measured before changing it: both forms yield the same 300 ids on this tree, so importing the SSOT was behaviour-preserving (the gate reports the same 300 SKUs, 7 owner rails, 0 unowned, 0 dangling product refs), and it is now correct for the manifest it will meet tomorrow. The patterns forbid a second DEFINITION of the SSOT exports, which is the established style on this registry (compare chain.input_fingerprint), and — since the migration above — a typed family enumeration in any of its three written forms. SIX MORE COPIES FOUND BY THE NEW PATTERNS on their first run: four gates (ai-adoption-navigator-canonical, governed-knowledge-assistant-canonical, product-canonical, product-fanout-canonical) built `const allSkus` by walking EVERY array of the manifest — the shape sku-owner-canonical had — and one of them walked it a second time with Object.values(...).flat() to find a row. All five read through the SSOT now.",
        "competitor_forbidden_patterns": [
          "function allSkuIds(",
          "const allSkuIds =",
          "function bootSku(",
          "const bootSku =",
          "function isSkuCallable(",
          "const isSkuCallable =",
          "function skuLifecycleEvent(",
          "const skuLifecycleEvent =",
          "function skuFamilies(",
          "const skuFamilies =",
          "function allSkus(",
          "const allSkus =",
          "function intakeSkuIds(",
          "const intakeSkuIds =",
          "\"pilot_skus\", \"annual_skus\"",
          "'pilot_skus', 'annual_skus'",
          ".pilot_skus, "
        ]
      },
      {
        "concept_id": "commercial.lifecycle",
        "entity_class": "concept",
        "name": "Commercial Lifecycle Agent (16-state commercial workflow machine)",
        "plane": "billing",
        "constitution_ref": "constitution/27-COMMERCIAL-LIFECYCLE.md",
        "ssot_module": "private/runtime/commercial-lifecycle-agent",
        "ssot_package": "@kye/commercial-lifecycle-agent",
        "ssot_entry_point": "lifecycle-machine.json runner",
        "transport_wrappers": [
          {
            "module": "private/runtime/commercial-lifecycle-worker",
            "transport": "queue",
            "note": "KYE_LIFECYCLE_QUEUE consumer Worker"
          }
        ],
        "competitor_forbidden_patterns": [
          "function CommercialLifecycleRunner(",
          "const CommercialLifecycleRunner =",
          "class CommercialLifecycleRunner "
        ]
      },
      {
        "concept_id": "comms.delivery.email",
        "entity_class": "concept",
        "name": "Email delivery primitive (CF Email Sending binding)",
        "plane": "comms",
        "constitution_ref": "constitution/38-COMMS-RAIL.md",
        "ssot_module": "private/runtime/mail-sender",
        "ssot_package": null,
        "ssot_entry_point": "POST /send",
        "transport_wrappers": [
          {
            "module": "private/runtime/kye-comms-engine-worker",
            "transport": "service-binding",
            "note": "Comms Engine routes compiled templates through mail-sender via the MAIL_SENDER service binding"
          }
        ],
        "competitor_scan_exemption": {
          "reason": "Delivery is a deployed worker reached over a transport; a competing sender is a second deployed surface, which the delivery gate reconciles and a symbol pattern cannot.",
          "enforced_by": "email-delivery-canonical"
        }
      },
      {
        "concept_id": "comms.dispatch",
        "entity_class": "concept",
        "name": "Outbound communications dispatch",
        "plane": "comms",
        "constitution_ref": "constitution/38-COMMS-RAIL.md",
        "ssot_module": "private/runtime/kye-comms-engine-worker",
        "ssot_package": null,
        "ssot_entry_point": "POST /v1/comms/dispatch",
        "transport_wrappers": [
          {
            "module": "public/site/functions/api/_lib/comms-dispatch.js",
            "transport": "http-client",
            "note": "Pages Functions client (kye-protocol Pages project)"
          },
          {
            "module": "public/admin/functions/api/_lib/comms-dispatch.js",
            "transport": "http-client",
            "note": "Pages Functions client (kye-admin Pages project)"
          },
          {
            "module": "public/status/functions/api/_lib/comms-dispatch.js",
            "transport": "http-client",
            "note": "Pages Functions client (status Pages project)"
          }
        ],
        "competitor_forbidden_patterns": [
          "function compileTemplate(",
          "const compileTemplate =",
          "class compileTemplate "
        ]
      },
      {
        "concept_id": "comms.email-templates",
        "entity_class": "concept",
        "name": "Outbound email template manifest",
        "plane": "comms",
        "constitution_ref": "constitution/38-COMMS-RAIL.md",
        "ssot_module": "private/specs/comms",
        "ssot_package": null,
        "ssot_entry_point": "manifest.json + blocks.json + links.json + providers.json",
        "transport_wrappers": [],
        "competitor_scan_exemption": {
          "reason": "Templates are data files under private/specs/comms; a duplicate is a second template record, not a second exported function.",
          "enforced_by": "comms-manifest-alive"
        }
      },
      {
        "concept_id": "conformance.run",
        "entity_class": "concept",
        "name": "Conformance Runner (Conformance Pack execution against tenant stacks)",
        "plane": "governance",
        "constitution_ref": "constitution/15-MCP-AND-SDK.md",
        "ssot_module": "private/runtime/conformance-runner",
        "ssot_package": "@kye/conformance-runner",
        "ssot_entry_point": "consumeBatch + processMessage",
        "transport_wrappers": [
          {
            "module": "private/runtime/kye-conformance-runner",
            "transport": "queue",
            "note": "Worker shell — wires consumeBatch to the kye-conformance queue"
          },
          {
            "module": "private/runtime/kye-conformance-scheduler-worker",
            "transport": "cron",
            "note": "Periodic re-run scheduler"
          }
        ],
        "competitor_forbidden_patterns": [
          "function canonicalComposite(",
          "const canonicalComposite =",
          "class canonicalComposite "
        ]
      },
      {
        "concept_id": "connector.onboarding-agent",
        "entity_class": "concept",
        "name": "Connector Onboarding Agent",
        "plane": "onboarding",
        "constitution_ref": "constitution/22-ONBOARDING.md",
        "ssot_module": "private/runtime/connector-onboarding-agent",
        "ssot_package": null,
        "ssot_entry_point": "runDiscovery(...)",
        "transport_wrappers": [
          {
            "module": "private/runtime/connector-onboarding-agent-worker",
            "transport": "http",
            "note": "CF Worker HTTP surface"
          }
        ],
        "competitor_forbidden_patterns": [
          "function InMemoryConnectorWorkflowStore(",
          "const InMemoryConnectorWorkflowStore =",
          "class InMemoryConnectorWorkflowStore "
        ]
      },
      {
        "concept_id": "constitution.read",
        "entity_class": "concept",
        "name": "Constitution + manifests + gates → structured snapshot (the Constitution Engine)",
        "plane": "governance",
        "constitution_ref": "constitution/40-IMPLEMENTATION-CANONICAL.md",
        "ssot_module": "private/runtime/constitution-engine",
        "ssot_package": "@kye/constitution-engine",
        "ssot_entry_point": "snapshotConstitution(repoRoot) + checkCompliance(snapshot)",
        "transport_wrappers": [
          {
            "module": "private/runtime/kye-constitution-gateway-worker",
            "transport": "http",
            "must_import": "@kye/constitution-engine",
            "note": "HTTP surface at constitution.kyeprotocol.com — builds the snapshot at deploy time and serves it as JSON"
          }
        ],
        "competitor_forbidden_patterns": [
          "function readImplementationRegistry(",
          "const readImplementationRegistry =",
          "class readImplementationRegistry "
        ]
      },
      {
        "concept_id": "content.page_facet_similarity",
        "entity_class": "concept",
        "name": "Page relatedness in the §50 content graph (facet vocabulary + similarity)",
        "plane": "governance",
        "constitution_ref": "constitution/50-CONTENT-GRAPH-DISCOVERABILITY.md",
        "ssot_module": "scripts/lib/page-facets.mjs",
        "ssot_package": null,
        "ssot_entry_point": "facetSet(discoverability) / facetSimilarity(a, b)",
        "transport_wrappers": [
          {
            "module": "scripts/build-derived-search.mjs",
            "transport": "library",
            "must_import": "./lib/page-facets.mjs",
            "note": "computeRelated() ranks by score then url. It owned the facet-set construction and the Jaccard body until this concept was registered; the RANKING stays here because it legitimately differs per surface."
          },
          {
            "module": "scripts/lib/archetypes.mjs",
            "transport": "library",
            "must_import": "./page-facets.mjs",
            "note": "renderRouter() ranks by similarity, then §50 buyer-journey stage, then title. It did NOT share the search index's relation — it required an audience match AND an exact kye-topic intersection, and §50 §2 declares kye-topic FREE-FORM, so no two pages share one verbatim. Measured: badges.html scored zero routes on all three of its audiences, the router returned null, and the page kept a disclosure where its kind requires a control. The two relations disagreed silently because an empty route list and an undefined relation are indistinguishable at the call site."
          }
        ],
        "competitor_forbidden_patterns": [
          "new Set\\(\\); *for \\(const a of .*\\) .*add\\(`a:",
          "\\.some\\(\\(t\\) => topics\\.has\\(t\\)\\)"
        ],
        "competitor_baseline_key": "implementation_canonical__competitors__content_page_facet_similarity",
        "migration": {
          "status": "complete",
          "tracked_in": "private/specs/ratchets/baselines.json#implementation_canonical__competitors__content_page_facet_similarity"
        }
      },
      {
        "concept_id": "crypto.byok",
        "entity_class": "concept",
        "name": "BYOK envelope encryption (tenant-managed CMK for R2 Evidence Packs + D1 audit logs)",
        "plane": "runtime",
        "constitution_ref": "constitution/30-AUDIT-WORM-RETENTION.md",
        "ssot_module": "private/runtime/byok",
        "ssot_package": "@kye/byok",
        "ssot_entry_point": "RFC 8152 envelope encryption — per-record DEK + customer-KMS-wrapped DEK, re-wrap on KEK rotation",
        "transport_wrappers": [],
        "competitor_forbidden_patterns": [
          "function InMemoryBYOKConfigStore(",
          "const InMemoryBYOKConfigStore =",
          "class InMemoryBYOKConfigStore "
        ]
      },
      {
        "concept_id": "crypto.primitives",
        "entity_class": "concept",
        "name": "Crypto primitives (COSE_Sign1, JWS detached, Evidence Pack / Decision Map signers)",
        "plane": "runtime",
        "constitution_ref": "constitution/16-EDGE-RUNTIME.md",
        "ssot_module": "private/runtime/crypto",
        "ssot_package": "@kye/crypto",
        "ssot_entry_point": "COSE/JWS signers (Ed25519)",
        "transport_wrappers": [],
        "competitor_forbidden_patterns": [
          "function verifyDecisionMapWithPublicJwk(",
          "const verifyDecisionMapWithPublicJwk =",
          "class verifyDecisionMapWithPublicJwk "
        ]
      },
      {
        "concept_id": "d1.schema",
        "entity_class": "concept",
        "name": "D1 migration tree (canonical database schema)",
        "plane": "runtime",
        "constitution_ref": "constitution/16-EDGE-RUNTIME.md",
        "ssot_module": "private/runtime/d1",
        "ssot_package": null,
        "ssot_entry_point": "d1/migrations/ — ordered migration files",
        "transport_wrappers": [],
        "competitor_scan_exemption": {
          "reason": "The schema is SQL DDL in a migration tree; a competing copy is a second CREATE TABLE, which is a shape no JavaScript symbol pattern can match.",
          "enforced_by": "d1-schema-apply"
        }
      },
      {
        "concept_id": "d1.migration_apply",
        "entity_class": "concept",
        "name": "Apply the D1 migration tree — one drift-repair declaration + one error grammar, two executors (from-empty gate · live runner)",
        "plane": "runtime",
        "constitution_ref": "constitution/16-EDGE-RUNTIME.md",
        "ssot_module": "scripts/lib/d1-migrations.mjs",
        "ssot_package": null,
        "ssot_entry_point": "driftRepairDeclarations(root) · applyWithDriftRepair({ file, sql, driftRepair, exec }) · stripColumnStatement(sql, col) · columnOfDriftError(text) · classifyMigrationError(text) · IDEMPOTENT_NOISE_RE / TRANSIENT_RE · listMigrationFiles(dir)",
        "transport_wrappers": [
          {
            "module": "scripts/ci/apply-d1-migrations.mjs",
            "transport": "cli",
            "must_import": "../lib/d1-migrations.mjs",
            "note": "The LIVE runner (wrangler d1 execute --remote) behind deploy-cloudflare-pages · deploy-all-surfaces · deploy-workers-fleet. Owns the executor (atomic remote batch + transient retry) and the verdict; the loop and the grammar are imported."
          },
          {
            "module": "scripts/gates/d1-schema-apply.mjs",
            "transport": "library",
            "must_import": "../lib/d1-migrations.mjs",
            "note": "The from-EMPTY replay (node:sqlite). Owns the executor (SAVEPOINT per attempt); the loop and the declaration reader are imported."
          }
        ],
        "migration": {
          "status": "complete",
          "note": "Registered 2026-09-25 when the two executors were found answering one question — is this apply error the migration saying it already ran? — with two grammars: a DECLARED drift-repair constant in the gate, and ~90 lines of bash inlined verbatim in two deploy workflows with a tolerance regex of their own. Migration 059 (a DROP COLUMN, redundant on any database it already ran on) replayed clean from empty and hard-failed on kye-prod on every deploy after the one that applied it, unseen behind continue-on-error; 064 and 066–071 never reached production. The declaration now lives on the migration's manifest row (drift_repair.reason) and both executors read it here (§0.61)."
        },
        "competitor_forbidden_patterns": [
          "function stripAddColumn(",
          "function stripColumnStatement(",
          "apply_one_migration()",
          "IDEMPOTENT_RE='",
          "function classifyMigrationError("
        ]
      },
      {
        "concept_id": "pricing.review_clock",
        "entity_class": "concept",
        "name": "Where a pricing record stands on its §26 §13(c) review clock — one classifier + one lead window, read by the enforcer and by the governed review door",
        "plane": "commerce",
        "constitution_ref": "constitution/26-COMMERCIAL.md",
        "ssot_module": "scripts/lib/pricing-cadence.mjs",
        "ssot_package": null,
        "ssot_entry_point": "reviewState({ rec, cadenceClasses, schema, now }) · classifyCadence(cadenceClasses, mode, banded) · cadenceClassesOf(dict) · hasInternalBand(rec) · ageDays(lastReviewed, now)",
        "transport_wrappers": [
          {
            "module": "scripts/gates/pricing-canonical-fresh.mjs",
            "transport": "library",
            "must_import": "../lib/pricing-cadence.mjs",
            "note": "The ENFORCER. Owns the totality proof over the disclosure-mode enum, the (d) cadence-limit and due_lead_days validation, and the verdict; the clock position is imported."
          },
          {
            "module": "scripts/govern/pricing-review-pep.mjs",
            "transport": "cli",
            "must_import": "../lib/pricing-cadence.mjs",
            "note": "The governed DOOR (the only writer of review_record). Owns the engine decision and the write; --due / --all-due select records by the same imported clock the gate fails them on, so the door opens inside the lead window rather than after the breach."
          }
        ],
        "migration": {
          "status": "complete",
          "note": "Registered 2026-09-26 when the gate and the door were found computing one clock two ways: the gate classified by exposure from kye:dictionary:pricing while the door read review_cadence_days off the record with no class, and the door's only bulk verb (--all-expired) opened only after the gate had already failed — every review post-facto by construction (§0.37), main red on an unchanged tree four times in eleven days. The lead window (due_lead_days per class) and the shared computation land together."
        },
        "competitor_forbidden_patterns": [
          "function isExpired(doc, now)",
          "function hasInternalBand(",
          "const classifyCadence = (mode, banded) => cadenceClasses.filter("
        ]
      },
      {
        "concept_id": "declared-source.merge",
        "entity_class": "concept",
        "name": "Merge of a kye.declared_source.v1 sidecar onto the rows a generator derives — the decided half of a derived registry, applied by identity",
        "plane": "governance",
        "constitution_ref": "constitution/00-INDEX.md",
        "ssot_module": "scripts/lib/declared-source.mjs",
        "ssot_package": null,
        "ssot_entry_point": "readDeclaredSource(absPath) · declaredRowsByKey(src) · mergeDeclaredRows(rows, src, key)",
        "transport_wrappers": [
          {
            "module": "scripts/build-edge-runtime-manifests.mjs",
            "transport": "library",
            "must_import": "./lib/declared-source.mjs",
            "note": "Six concepts (queues · kv · r2 · secrets · sector-packs · rule-packs); owns declared_only[] handling and the one-row-per-key assertion."
          },
          {
            "module": "scripts/build-workflow-registry.mjs",
            "transport": "library",
            "must_import": "./lib/declared-source.mjs",
            "note": "Workflows; owns the default_owner rule and the unclassified count."
          },
          {
            "module": "scripts/build-deployed-estate.mjs",
            "transport": "library",
            "must_import": "./lib/declared-source.mjs",
            "note": "Deployed estate; merges each off-lifecycle resource's disposition by resource_id (2026-09-29)."
          }
        ],
        "migration": {
          "status": "complete",
          "note": "Registered 2026-09-29 when a third generator needed the merge: it existed as a private map-and-spread in the edge-runtime and workflow generators, and the estate disposition sidecar would have been the third copy of one concept (§0.49 point-of-use). The three now import one implementation."
        },
        "competitor_forbidden_patterns": [
          "new Map(Object.entries(src.rows || {}))"
        ]
      },
      {
        "concept_id": "data.classify",
        "entity_class": "concept",
        "name": "Data Classification Engine (canonical data classification assign/enforce)",
        "plane": "decision",
        "constitution_ref": "constitution/31-DATA-GOVERNANCE-PACK.md",
        "ssot_module": "private/runtime/data-classification-engine",
        "ssot_package": "@kye/data-classification-engine",
        "ssot_entry_point": "classify(asset|payload)",
        "transport_wrappers": [
          {
            "module": "private/runtime/kye-data-classification-agent",
            "transport": "http",
            "note": "HTTP Worker — POST /v1/classifications"
          }
        ],
        "competitor_forbidden_patterns": [
          "function DataClassificationEngine(",
          "const DataClassificationEngine =",
          "class DataClassificationEngine "
        ]
      },
      {
        "concept_id": "decision.pipeline",
        "entity_class": "concept",
        "name": "Decision Engine (authority + purpose + rules pipeline → Decision Map)",
        "plane": "decision",
        "constitution_ref": "constitution/14-AGENTS-AND-ENGINES.md",
        "ssot_module": "private/runtime/decision-engine",
        "ssot_package": "@kye/decision-engine",
        "ssot_entry_point": "deterministic decision pipeline",
        "transport_wrappers": [],
        "competitor_forbidden_patterns": [
          "function DECISION_ENGINE_GOVERNANCE_EVENT_FAMILY(",
          "const DECISION_ENGINE_GOVERNANCE_EVENT_FAMILY =",
          "class DECISION_ENGINE_GOVERNANCE_EVENT_FAMILY "
        ]
      },
      {
        "concept_id": "derived.freshness_verify",
        "entity_class": "concept",
        "name": "Verify every generator's committed output matches what it would produce",
        "plane": "governance",
        "constitution_ref": "constitution/00-INDEX.md",
        "ssot_module": "scripts/ci/fresh-all.mjs",
        "ssot_package": null,
        "ssot_entry_point": "npm run -s test:fresh-all",
        "transport_wrappers": [],
        "competitor_forbidden_patterns": [
          "const GENERATORS = ["
        ],
        "competitor_baseline_key": "implementation_canonical__competitors__derived_freshness_verify",
        "migration": {
          "status": "complete",
          "note": "Registered 2026-08-15. It must never maintain a second generator list — that divergence is what let six derived artefacts drift silently. It is also the authority the build-derived-all reverse-check reads: a generator EXCLUDED from the chain whose output fresh-all verifies must say so in its exclusion reason."
        }
      },
      {
        "concept_id": "derived.regeneration",
        "entity_class": "concept",
        "name": "Regenerate the full derived tree to a fixpoint, in dependency order",
        "plane": "governance",
        "constitution_ref": "constitution/00-INDEX.md",
        "ssot_module": "scripts/build-derived-all.mjs",
        "ssot_package": null,
        "ssot_entry_point": "node scripts/build-derived-all.mjs [--check]",
        "transport_wrappers": [],
        "competitor_forbidden_patterns": [
          "const PHASES = [",
          "const P1 = ["
        ],
        "competitor_baseline_key": "implementation_canonical__competitors__derived_regeneration",
        "migration": {
          "status": "complete",
          "note": "Registered 2026-08-15. Membership and order are DATA in private/specs/propagators/propagator-registry.json; this module is the engine. Both .githooks/pre-commit and .githooks/pre-push invoke it — pre-commit generates and stages, pre-push verifies. Importing it for data EXECUTES it (a full fixpoint run); probe it by spawning, never by import()."
        }
      },
      {
        "concept_id": "diagnostic.engine",
        "entity_class": "concept",
        "name": "Authority Finality Diagnostic — gateway handler",
        "plane": "diagnostic",
        "constitution_ref": "constitution/40-IMPLEMENTATION-CANONICAL.md",
        "ssot_module": "private/runtime/gateway/src/handlers/diagnostic.ts",
        "ssot_package": null,
        "ssot_entry_point": "sealDiagnostic / mapDiagnosticFramework / verifyDiagnostic",
        "endpoints": [
          "POST /v1/diagnostic/seal",
          "POST /v1/diagnostic/framework-map",
          "POST /v1/diagnostic/verify"
        ],
        "transport_wrappers": [
          {
            "module": "private/sdks/typescript/src/client.ts",
            "transport": "http-client",
            "note": "client.sealDiagnostic() / client.mapDiagnosticFramework() / client.verifyDiagnostic()"
          },
          {
            "module": "private/sdks/python/kye_sdk/client.py",
            "transport": "http-client",
            "note": "client.diagnostic_seal() / diagnostic_framework_map() / diagnostic_verify()"
          },
          {
            "module": "private/cli/src/cmds/diagnostic.ts",
            "transport": "cli",
            "note": "kye diagnostic seal | framework-map | verify"
          },
          {
            "module": "public/oss/kye-claude-code-plugin/commands/report.md",
            "transport": "plugin",
            "note": "Claude Code /kye:report wraps the seal endpoint"
          },
          {
            "module": "public/oss/kye-claude-code-plugin/commands/framework-map.md",
            "transport": "plugin",
            "note": "Claude Code /kye:framework-map wraps the framework-map endpoint"
          },
          {
            "module": "public/oss/kye-claude-code-plugin/commands/verify.md",
            "transport": "plugin",
            "note": "Claude Code /kye:verify wraps the verify endpoint"
          },
          {
            "module": "public/oss/kye-mcp-server/src/server.ts",
            "transport": "mcp",
            "note": "MCP tools kye_report / kye_framework_map / kye_verify reach every MCP-aware client (Claude Desktop, Claude Code, Cursor, Windsurf, Cline, Zed)"
          }
        ],
        "note": "Production weighting + canonicalisation + palette MAP + Ed25519 signing live in the proprietary diagnostic-engine reached via KYE_DIAGNOSTIC_ENGINE_URL. Smoke-test fallback in the gateway handler uses the published simple-average reference. Free-tier quota: 3 sealed envelopes / month / actor_email; enforced via D1 033 sealed_reports + actor_email + month JOIN. framework-map reads private/specs/compliance/nist-800-53-rev5-hub.json (canonical) with a fallback to the public mirror at public/site/.well-known/nist-800-53-hub.json; 24-hour in-process cache; no authentication required. verify is an online courtesy lookup against the JWKS at https://kyeprotocol.com/.well-known/jwks.json. Full offline Ed25519 verification of canonical bytes is published in the SDK verifier.",
        "competitor_forbidden_patterns": [
          "function mapDiagnosticFramework(",
          "const mapDiagnosticFramework =",
          "class mapDiagnosticFramework "
        ]
      },
      {
        "concept_id": "directory.index",
        "entity_class": "concept",
        "name": "Directory Engine (entity/authority/evidence index model + federated DirectoryQuery)",
        "plane": "runtime",
        "constitution_ref": "constitution/17-DIRECTORY-SEARCH.md",
        "ssot_module": "private/runtime/directory-engine",
        "ssot_package": "@kye/directory-engine",
        "ssot_entry_point": "IndexClient + DirectoryQuery + AuthoritySearch + EvidenceFinder",
        "transport_wrappers": [],
        "note": "Owns the index/query MODEL; the query SURFACE is search.query (kye-search-engine).",
        "competitor_forbidden_patterns": [
          "function DirectoryQueryBuilder(",
          "const DirectoryQueryBuilder =",
          "class DirectoryQueryBuilder "
        ]
      },
      {
        "concept_id": "durable-objects.classes",
        "entity_class": "concept",
        "name": "Durable Object class set (rate limiter, audit batcher, drift counter, replay cursor, dual-control broker)",
        "plane": "runtime",
        "constitution_ref": "constitution/16-EDGE-RUNTIME.md",
        "ssot_module": "private/runtime/durable-objects",
        "ssot_package": "@kye/durable-objects",
        "ssot_entry_point": "canonical Durable Object classes",
        "transport_wrappers": [],
        "competitor_forbidden_patterns": [
          "function DualControlBroker(",
          "const DualControlBroker =",
          "class DualControlBroker "
        ]
      },
      {
        "concept_id": "edge.wrangler_config_predicate",
        "entity_class": "concept",
        "name": "Is this filename a wrangler config (any shape the repo uses)?",
        "plane": "runtime",
        "constitution_ref": "constitution/16-EDGE-RUNTIME.md",
        "ssot_module": "scripts/gates/_lib.mjs",
        "ssot_package": null,
        "ssot_entry_point": "isWranglerConfig(name) / WRANGLER_CONFIG_RE",
        "transport_wrappers": [],
        "competitor_forbidden_patterns": [
          "name === \"wrangler.toml\"",
          "=== 'wrangler.toml'",
          "endsWith(\"wrangler.toml\")"
        ],
        "competitor_baseline_key": "implementation_canonical__competitors__edge_wrangler_config_predicate",
        "migration": {
          "status": "complete",
          "note": "Registered 2026-08-15. The literal `name === \"wrangler.toml\"` was re-typed in 18 scripts, which made cf-resource-governance-coverage blind to per-region and prefixed configs while reporting the fleet clean. The canonical existed from 2026-08-11 and one consumer had adopted it; an agent then nearly defined a SECOND copy inside the same file that already exported it."
        }
      },
      {
        "concept_id": "email-action.token",
        "entity_class": "concept",
        "name": "Email-action one-click HMAC token",
        "plane": "auth",
        "constitution_ref": "constitution/27-COMMERCIAL-LIFECYCLE.md",
        "ssot_module": "public/site/functions/api/_lib/email-action-token.js",
        "ssot_package": null,
        "ssot_entry_point": "mintEmailActionToken / verifyEmailActionToken",
        "transport_wrappers": [
          {
            "module": "public/site/functions/api/_lib/admin-action-buttons.js",
            "transport": "render",
            "note": "Canonical button-renderer used by every actionable admin notification (pilot, consultant, expert-review, key-rotation, etc.). Mints via the SSOT lib."
          },
          {
            "module": "public/admin/functions/email-action.js",
            "transport": "dispatcher",
            "note": "Single canonical /email-action endpoint on admin.kyeprotocol.com. Verifies via the SSOT, enforces single-use via email_action_token_used, applies expert-review inline; queues every other domain to the per-domain consumer."
          }
        ],
        "secret_keys": [
          "KYE_EMAIL_ACTION_SECRET_CURRENT",
          "KYE_EMAIL_ACTION_SECRET_PREVIOUS"
        ],
        "removed_competitors": [
          "public/site/functions/api/_lib/expert-action-token.js (deleted 2026-05-23 — parallel HMAC lib with separate EXPERT_ACTION_SECRET)",
          "public/admin/functions/api/v1/expert-reviews/[id]/email-action.js (deleted 2026-05-23 — per-domain dispatcher)"
        ],
        "competitor_forbidden_patterns": [
          "function verifyEmailActionToken(",
          "const verifyEmailActionToken =",
          "class verifyEmailActionToken "
        ]
      },
      {
        "concept_id": "entity.resolve",
        "entity_class": "concept",
        "name": "Entity Engine (entity registry + KYEID parse/format/generate + faceted lookup)",
        "plane": "identity",
        "constitution_ref": "constitution/01-NAMING.md",
        "ssot_module": "private/runtime/entity-engine",
        "ssot_package": "@kye/entity-engine",
        "ssot_entry_point": "KYEID parse/format + entity registry",
        "transport_wrappers": [],
        "competitor_forbidden_patterns": [
          "function EntityRegistryError(",
          "const EntityRegistryError =",
          "class EntityRegistryError "
        ]
      },
      {
        "concept_id": "entity.state",
        "entity_class": "concept",
        "name": "State Engine (six-dimension entity state vector + transitions)",
        "plane": "runtime",
        "constitution_ref": "constitution/18-OPERATING-MODEL.md",
        "ssot_module": "private/runtime/state-engine",
        "ssot_package": "@kye/state-engine",
        "ssot_entry_point": "state vector + deterministic transitions + invariant validation",
        "transport_wrappers": [],
        "competitor_forbidden_patterns": [
          "function StateEngine(",
          "const StateEngine =",
          "class StateEngine "
        ]
      },
      {
        "concept_id": "estate.resolve",
        "entity_class": "concept",
        "name": "Declared Estate Resolver (which Cloudflare account and zones KYE is authorised to touch)",
        "plane": "governance",
        "constitution_ref": "constitution/00-INDEX.md#0.28",
        "ssot_module": "scripts/lib/cf-estate.mjs",
        "ssot_entry_point": "declaredAccount / assertAccount / declaredZone / declaredZones / accountIsShared",
        "transport_wrappers": [],
        "competitor_forbidden_patterns": [
          "process.env.CLOUDFLARE_ACCOUNT_ID",
          "process.env.CF_ACCOUNT_ID",
          "process.env.CLOUDFLARE_ZONE_ID",
          "process.env.CF_ZONE_ID"
        ]
      },
      {
        "concept_id": "evidence-import.bridge",
        "entity_class": "concept",
        "name": "Universal evidence importer — connectors → sealed evidence",
        "plane": "evidence",
        "constitution_ref": "constitution/13-RESILIENCE-LOOP.md",
        "ssot_module": "private/runtime/kye-evidence-import-worker",
        "ssot_package": null,
        "ssot_entry_point": "POST /v1/evidence-import",
        "transport_wrappers": [
          {
            "module": "public/app/functions/api/v1/evidence-import.js",
            "transport": "pages-function",
            "note": "kye-app Pages Function that fronts the worker for the customer dashboard's connectors page; auth via tenant session, forwards to the worker with IMPORT_WORKER_BEARER."
          },
          {
            "module": "public/widgets/evidence-import/v1",
            "transport": "embed-widget",
            "note": "Embeddable evidence-import widget (post-message conformant)."
          }
        ],
        "note": "Transport bridge — the worker hosts the canonical /v1/evidence-import HTTP surface that connector adapters and the embed widget post raw evidence batches to; the worker normalises and forwards to the canonical sealing pipeline. Not a stateful engine; no SSOT library because the canonical sealing logic lives downstream in the evidence-pack-assembler.",
        "competitor_forbidden_patterns": [
          "function buildImportBatch(",
          "const buildImportBatch =",
          "class buildImportBatch "
        ]
      },
      {
        "concept_id": "evidence.chain",
        "entity_class": "concept",
        "name": "Evidence Engine (Decision Map builder + Evidence Pack assembler core)",
        "plane": "evidence",
        "constitution_ref": "constitution/13-RESILIENCE-LOOP.md",
        "ssot_module": "private/runtime/evidence-engine",
        "ssot_package": "@kye/evidence-engine",
        "ssot_entry_point": "Decision Map builder + Evidence Pack assembler",
        "transport_wrappers": [],
        "competitor_forbidden_patterns": [
          "function assembleEvidencePackViaCustody(",
          "const assembleEvidencePackViaCustody =",
          "class assembleEvidencePackViaCustody "
        ]
      },
      {
        "concept_id": "evidence.pack.assemble",
        "entity_class": "concept",
        "name": "Evidence Pack assembler",
        "plane": "evidence",
        "constitution_ref": "constitution/13-RESILIENCE-LOOP.md",
        "ssot_module": "private/runtime/evidence-pack-assembler",
        "ssot_package": null,
        "ssot_entry_point": "assemblePack(decisionId, fragments)",
        "transport_wrappers": [
          {
            "module": "private/runtime/evidence-pack-sealer-periodic",
            "transport": "queue",
            "note": "Periodic sealer triggers assembly on a cron-tolerated cadence per §35"
          }
        ],
        "competitor_forbidden_patterns": [
          "function makeAssembleMessage(",
          "const makeAssembleMessage =",
          "class makeAssembleMessage "
        ]
      },
      {
        "concept_id": "gateway.dispatch",
        "entity_class": "concept",
        "name": "Gateway / PEP middleware",
        "plane": "runtime",
        "constitution_ref": "constitution/16-EDGE-RUNTIME.md",
        "ssot_module": "private/runtime/gateway",
        "ssot_package": "@kye/gateway",
        "ssot_entry_point": "createGateway(...)",
        "transport_wrappers": [
          {
            "module": "private/runtime/gateway-worker",
            "transport": "http",
            "note": "Legacy CF Worker — being consolidated to kye-gateway-worker"
          },
          {
            "module": "private/runtime/kye-gateway-worker",
            "transport": "http",
            "note": "Canonical CF Worker hosting the gateway library"
          }
        ],
        "competitor_forbidden_patterns": [
          "function decideCapabilityInvocation(",
          "const decideCapabilityInvocation =",
          "class decideCapabilityInvocation "
        ]
      },
      {
        "concept_id": "generator.write-targets",
        "entity_class": "concept",
        "name": "Generator write-target detection (which canonical paths a generator writes)",
        "plane": "governance",
        "constitution_ref": "constitution/00-INDEX.md#0.49",
        "ssot_module": "scripts/lib/generator-writes.mjs",
        "ssot_entry_point": "writeTargetsIn(text)",
        "transport_wrappers": [
          {
            "module": "scripts/build-cascade-edges.mjs",
            "transport": "import",
            "must_import": "./lib/generator-writes.mjs",
            "note": "Assigns cascade node kind. Previously carried its own matcher that knew writeFileSync + named constants but not the writeJson helper."
          },
          {
            "module": "scripts/gates/generated-not-source.mjs",
            "transport": "import",
            "must_import": "../lib/generator-writes.mjs",
            "note": "Checks the label this builder assigns. Previously carried its own matcher that knew writeJson but could not resolve a named constant."
          }
        ],
        "competitor_forbidden_patterns": [
          "function constPathsFor",
          "const WRITE_IDENT_RE",
          "WRITE_LITERAL_RE"
        ],
        "note": "An x-er/x-or class: 'which paths does a generator write' is a question two consumers ask and MUST NOT answer differently. They did — each had half the matcher — and the gap between the halves was 24 generated artefacts labelled kind=source-of-truth in the cascade graph, the exact set §53 §3.2 could then not protect from a silently-reverted hand-edit. Registered here so a third half-matcher fails the competitor scan instead of quietly becoming the fourth answer."
      },
      {
        "concept_id": "git.out_of_tree_env",
        "entity_class": "concept",
        "name": "What environment does OUT-OF-TREE git work run under? (the hook-injected GIT_* scrub)",
        "plane": "diagnostic",
        "constitution_ref": "constitution/00-INDEX.md",
        "ssot_module": "scripts/lib/git-env.mjs",
        "ssot_package": null,
        "ssot_entry_point": "gitEnvWithoutHookState() -> env without GIT_INDEX_FILE · GIT_DIR · GIT_WORK_TREE · GIT_PREFIX · GIT_COMMON_DIR (the set is exported as HOOK_GIT_VARS)",
        "transport_wrappers": [],
        "migration": {
          "status": "complete",
          "note": "Registered 2026-09-10, when main's #1619 added the tree-side inverse of this registry (scripts/lib/shared-implementations.mjs) and it correctly reported this module as a shared implementation with no concept row. The module was extracted on 2026-09-09 from a private function inside generator-determinism because prove-read-backs had independently re-made the same mistake — so the extraction was the §0.49 fix and this row is the declaration that should have landed WITH it. The obligation was readable before the edit (§0.9: an artefact referenced from more than one file belongs to a canonical registry); it was not read, and the chain found it afterwards. HONEST LIMIT, and it is load-bearing: this is the SCRUB half only. A command that must read THE CHANGE UNDER REVIEW (git write-tree, git diff HEAD) inherits the hook's index deliberately — scrubbing those would substitute the on-disk index for the one being committed and the verifier would judge a tree nobody asked about. The module's header declares the split; a caller must not re-derive it."
        },
        "competitor_forbidden_patterns": [
          "delete env.GIT_INDEX_FILE",
          "delete e.GIT_INDEX_FILE",
          "GIT_INDEX_FILE: undefined",
          "GIT_WORK_TREE: undefined"
        ]
      },
      {
        "concept_id": "governance-envelope",
        "entity_class": "concept",
        "name": "KYE Governance Envelope (the transport envelope every §0.3 event crosses a boundary in)",
        "plane": "runtime",
        "constitution_ref": "constitution/00-INDEX.md",
        "ssot_module": "public/app/functions/api/_lib/governance-envelope.js",
        "ssot_package": "(none — a Pages Functions module, imported by relative path)",
        "ssot_entry_point": "governanceEnvelope() — the ONE guarded constructor; envelopeId(); resolveEngagementId(); ENGAGEMENT_ID_PATTERN",
        "transport_wrappers": [],
        "competitor_forbidden_patterns": [
          "an inline `{ schema: \"kye.governance_envelope.v1\", … }` object literal at an emit site — the sixteen that existed across six files are what left this class undeclared and unvalidated",
          "a second import of the compiled kye.governance_envelope.v1 validator outside this module — three Workers did exactly that, each hand-rolling its own relative depth, and all three got it wrong"
        ]
      },
      {
        "concept_id": "html.escape",
        "entity_class": "concept",
        "name": "HTML escaper (text + quoted-attribute safe)",
        "plane": "surface",
        "constitution_ref": "constitution/00-INDEX.md#0.49",
        "ssot_module": "private/lib/html-escape",
        "ssot_entry_point": "escapeHtml(value)",
        "transport_wrappers": [
          {
            "module": "private/runtime/kye-comms-engine-worker/src/compiler.js",
            "transport": "projection",
            "note": "Byte-projected by scripts/build-html-escape-projection.mjs; equality verified by implementation-canonical."
          },
          {
            "module": "private/runtime/reporting-engine/src/templates.ts",
            "transport": "import",
            "must_import": "@kye/html-escape",
            "note": "STRICT-TS PACKAGE, cannot take the projection. tsconfig sets rootDir 'src' + include 'src/**/*', so a file outside src is not in the program, and noImplicitAny rejects the canonical's untyped parameter. Its current copy is COMPLETE and correct (all five characters, null-safe) — this is a duplicate, not a defect, which is why it is time-boxed rather than rushed. Closure is to publish the SSOT as @kye/html-escape with types and add the dependency."
          },
          {
            "module": "public/admin/functions/api/v1/pilot-applications/[id]/send-sign-in.js",
            "transport": "projection",
            "note": "Byte-projected by scripts/build-html-escape-projection.mjs; equality verified by implementation-canonical."
          },
          {
            "module": "public/admin/functions/email-action.js",
            "transport": "projection",
            "note": "Byte-projected by scripts/build-html-escape-projection.mjs; equality verified by implementation-canonical."
          },
          {
            "module": "public/admin/search.html",
            "transport": "projection",
            "note": "Byte-projected by scripts/build-html-escape-projection.mjs; equality verified by implementation-canonical. Enrolled 2026-08-10 — this copy was introduced by the #1505 security sweep, which is exactly the copy-N+1 this concept exists to prevent."
          },
          {
            "module": "public/app/assets/dashboard-realtime-components.js",
            "transport": "projection",
            "note": "Byte-projected by scripts/build-html-escape-projection.mjs; equality verified by implementation-canonical."
          },
          {
            "module": "public/app/assets/usage-page.js",
            "transport": "projection",
            "note": "Byte-projected by scripts/build-html-escape-projection.mjs; equality verified by implementation-canonical."
          },
          {
            "module": "public/app/coa/_assets/chrome.js",
            "transport": "projection",
            "note": "Byte-projected by scripts/build-html-escape-projection.mjs; equality verified by implementation-canonical."
          },
          {
            "module": "public/app/dashboard.html",
            "transport": "projection",
            "note": "Byte-projected by scripts/build-html-escape-projection.mjs; equality verified by implementation-canonical."
          },
          {
            "module": "public/app/document-governance.html",
            "transport": "projection",
            "note": "Byte-projected by scripts/build-html-escape-projection.mjs; equality verified by implementation-canonical."
          },
          {
            "module": "public/app/entity-passport.html",
            "transport": "projection",
            "note": "Byte-projected by scripts/build-html-escape-projection.mjs; equality verified by implementation-canonical. Enrolled 2026-08-10 — this copy was introduced by the #1505 security sweep, which is exactly the copy-N+1 this concept exists to prevent."
          },
          {
            "module": "public/app/ep/_assets/chrome.js",
            "transport": "projection",
            "note": "Byte-projected by scripts/build-html-escape-projection.mjs; equality verified by implementation-canonical."
          },
          {
            "module": "public/sandbox/estate-planning/assets/console.js",
            "transport": "projection",
            "note": "Byte-projected by scripts/build-html-escape-projection.mjs; equality verified by implementation-canonical. Enrolled 2026-08-10 — this copy was introduced by the #1505 security sweep, which is exactly the copy-N+1 this concept exists to prevent."
          },
          {
            "module": "public/sandbox/main.js",
            "transport": "projection",
            "note": "Byte-projected by scripts/build-html-escape-projection.mjs; equality verified by implementation-canonical."
          },
          {
            "module": "public/site/assets/site-authority-record.js",
            "transport": "projection",
            "note": "Byte-projected by scripts/build-html-escape-projection.mjs; equality verified by implementation-canonical."
          },
          {
            "module": "public/site/functions/api/_lib/admin-action-buttons.js",
            "transport": "projection",
            "note": "Byte-projected by scripts/build-html-escape-projection.mjs; equality verified by implementation-canonical."
          },
          {
            "module": "public/site/functions/api/_lib/consultant-emails.js",
            "transport": "projection",
            "note": "Byte-projected by scripts/build-html-escape-projection.mjs; equality verified by implementation-canonical."
          },
          {
            "module": "public/site/functions/api/_lib/persona-intake.js",
            "transport": "projection",
            "note": "Byte-projected by scripts/build-html-escape-projection.mjs; equality verified by implementation-canonical."
          },
          {
            "module": "public/site/functions/api/audit-pilot.js",
            "transport": "projection",
            "note": "Byte-projected by scripts/build-html-escape-projection.mjs; equality verified by implementation-canonical."
          },
          {
            "module": "public/site/functions/api/consultant-lead.js",
            "transport": "projection",
            "note": "Byte-projected by scripts/build-html-escape-projection.mjs; equality verified by implementation-canonical."
          },
          {
            "module": "public/site/functions/api/contact.js",
            "transport": "projection",
            "note": "Byte-projected by scripts/build-html-escape-projection.mjs; equality verified by implementation-canonical."
          },
          {
            "module": "public/site/functions/api/dsar.js",
            "transport": "projection",
            "note": "Byte-projected by scripts/build-html-escape-projection.mjs; equality verified by implementation-canonical."
          },
          {
            "module": "public/site/functions/api/engage-access.js",
            "transport": "projection",
            "note": "Byte-projected by scripts/build-html-escape-projection.mjs; equality verified by implementation-canonical."
          },
          {
            "module": "public/site/functions/api/expert-review.js",
            "transport": "projection",
            "note": "Byte-projected by scripts/build-html-escape-projection.mjs; equality verified by implementation-canonical."
          },
          {
            "module": "public/site/functions/api/v1/poc/apply.js",
            "transport": "projection",
            "note": "Byte-projected by scripts/build-html-escape-projection.mjs; equality verified by implementation-canonical."
          },
          {
            "module": "public/site/main.js",
            "transport": "projection",
            "note": "Byte-projected by scripts/build-html-escape-projection.mjs; equality verified by implementation-canonical. Enrolled 2026-08-10 — this copy was introduced by the #1505 security sweep, which is exactly the copy-N+1 this concept exists to prevent."
          },
          {
            "module": "public/status/assets/status.js",
            "transport": "projection",
            "note": "Byte-projected by scripts/build-html-escape-projection.mjs; equality verified by implementation-canonical."
          },
          {
            "module": "public/widgets/consultant-card/v1/index.html",
            "transport": "projection",
            "note": "Byte-projected by scripts/build-html-escape-projection.mjs; equality verified by implementation-canonical."
          },
          {
            "module": "public/widgets/partner-registry/v1/index.html",
            "transport": "projection",
            "note": "Byte-projected by scripts/build-html-escape-projection.mjs; equality verified by implementation-canonical."
          },
          {
            "module": "scripts/build-ontology-derivative.mjs",
            "transport": "projection",
            "note": "Byte-projected by scripts/build-html-escape-projection.mjs; equality verified by implementation-canonical."
          },
          {
            "module": "site/src/fragments/admin/search.body.html",
            "transport": "projection",
            "note": "Byte-projected by scripts/build-html-escape-projection.mjs; equality verified by implementation-canonical. Enrolled 2026-08-10 — this copy was introduced by the #1505 security sweep, which is exactly the copy-N+1 this concept exists to prevent."
          },
          {
            "module": "site/src/fragments/app/dashboard.body.html",
            "transport": "projection",
            "note": "Byte-projected by scripts/build-html-escape-projection.mjs; equality verified by implementation-canonical."
          },
          {
            "module": "site/src/fragments/app/document-governance.body.html",
            "transport": "projection",
            "note": "Byte-projected by scripts/build-html-escape-projection.mjs; equality verified by implementation-canonical."
          },
          {
            "module": "site/src/fragments/app/entity-passport.body.html",
            "transport": "projection",
            "note": "Byte-projected by scripts/build-html-escape-projection.mjs; equality verified by implementation-canonical. Enrolled 2026-08-10 — this copy was introduced by the #1505 security sweep, which is exactly the copy-N+1 this concept exists to prevent."
          },
          {
            "module": "site/src/fragments/widgets/consultant-card/v1/home.tail.html",
            "transport": "projection",
            "note": "Byte-projected by scripts/build-html-escape-projection.mjs; equality verified by implementation-canonical."
          },
          {
            "module": "site/src/fragments/widgets/partner-registry/v1/home.tail.html",
            "transport": "projection",
            "note": "Byte-projected by scripts/build-html-escape-projection.mjs; equality verified by implementation-canonical."
          },
          {
            "module": "public/site/assets/expert-wall-form.js",
            "transport": "projection",
            "note": "Browser code — cannot import a Node module, so it carries the canonical bytes between the marker comments and implementation-canonical verifies the equality. Enrolled 2026-08-12 replacing a hand-rolled esc() that escaped & < > but NOT the double quote, while all eight of its call sites interpolate into DOUBLE-QUOTED HTML attributes (href, title, aria-label, data-cite, data-embed). `x\" onmouseover=\"alert(1)` passed through it unchanged. CodeQL js/incomplete-html-attribute-sanitization."
          },
          {
            "module": "public/app/assets/apps-page.js",
            "transport": "projection",
            "note": "Byte-projected by scripts/build-html-escape-projection.mjs; equality verified by implementation-canonical. Added 2026-08-14 with the Class-1 sanitization sweep: this page interpolated a DOM-attribute-sourced empty-state string into innerHTML (CodeQL js/xss-through-dom). It carried no escaper, so it is reached through the declared insertion marker."
          },
          {
            "module": "public/app/assets/authorities-page.js",
            "transport": "projection",
            "note": "Byte-projected by scripts/build-html-escape-projection.mjs; equality verified by implementation-canonical. Added 2026-08-14 with the Class-1 sanitization sweep: this page interpolated a DOM-attribute-sourced empty-state string into innerHTML (CodeQL js/xss-through-dom). It carried no escaper, so it is reached through the declared insertion marker."
          },
          {
            "module": "public/app/assets/authority-wallet-page.js",
            "transport": "projection",
            "note": "Byte-projected by scripts/build-html-escape-projection.mjs; equality verified by implementation-canonical. Added 2026-08-14 with the Class-1 sanitization sweep: this page interpolated a DOM-attribute-sourced empty-state string into innerHTML (CodeQL js/xss-through-dom). It carried no escaper, so it is reached through the declared insertion marker."
          },
          {
            "module": "public/app/assets/classification-page.js",
            "transport": "projection",
            "note": "Byte-projected by scripts/build-html-escape-projection.mjs; equality verified by implementation-canonical. Added 2026-08-14 with the Class-1 sanitization sweep: this page interpolated a DOM-attribute-sourced empty-state string into innerHTML (CodeQL js/xss-through-dom). It carried no escaper, so it is reached through the declared insertion marker."
          },
          {
            "module": "public/app/assets/connectors-page.js",
            "transport": "projection",
            "note": "Byte-projected by scripts/build-html-escape-projection.mjs; equality verified by implementation-canonical. Added 2026-08-14 with the Class-1 sanitization sweep: this page interpolated a DOM-attribute-sourced empty-state string into innerHTML (CodeQL js/xss-through-dom). It carried no escaper, so it is reached through the declared insertion marker."
          },
          {
            "module": "public/app/assets/entities-page.js",
            "transport": "projection",
            "note": "Byte-projected by scripts/build-html-escape-projection.mjs; equality verified by implementation-canonical. Added 2026-08-14 with the Class-1 sanitization sweep: this page interpolated a DOM-attribute-sourced empty-state string into innerHTML (CodeQL js/xss-through-dom). It carried no escaper, so it is reached through the declared insertion marker."
          },
          {
            "module": "public/app/assets/plugins-page.js",
            "transport": "projection",
            "note": "Byte-projected by scripts/build-html-escape-projection.mjs; equality verified by implementation-canonical. Added 2026-08-14 with the Class-1 sanitization sweep: this page interpolated a DOM-attribute-sourced empty-state string into innerHTML (CodeQL js/xss-through-dom). It carried no escaper, so it is reached through the declared insertion marker."
          },
          {
            "module": "public/app/assets/purposes-page.js",
            "transport": "projection",
            "note": "Byte-projected by scripts/build-html-escape-projection.mjs; equality verified by implementation-canonical. Added 2026-08-14 with the Class-1 sanitization sweep: this page interpolated a DOM-attribute-sourced empty-state string into innerHTML (CodeQL js/xss-through-dom). It carried no escaper, so it is reached through the declared insertion marker."
          },
          {
            "module": "public/app/assets/replay-page.js",
            "transport": "projection",
            "note": "Byte-projected by scripts/build-html-escape-projection.mjs; equality verified by implementation-canonical. Added 2026-08-14 with the Class-1 sanitization sweep: this page interpolated a DOM-attribute-sourced empty-state string into innerHTML (CodeQL js/xss-through-dom). It carried no escaper, so it is reached through the declared insertion marker."
          },
          {
            "module": "public/app/assets/scopes-page.js",
            "transport": "projection",
            "note": "Byte-projected by scripts/build-html-escape-projection.mjs; equality verified by implementation-canonical. Added 2026-08-14 with the Class-1 sanitization sweep: this page interpolated a DOM-attribute-sourced empty-state string into innerHTML (CodeQL js/xss-through-dom). It carried no escaper, so it is reached through the declared insertion marker."
          }
        ],
        "competitor_forbidden_patterns": [
          "function escapeHtml(",
          "function escapeHTML(",
          "const escapeHtml =",
          "const escapeHTML ="
        ],
        "competitor_scan_extensions": [
          ".html"
        ],
        "migration": {
          "status": "in-progress",
          "advisory_until": "2026-11-08",
          "tracked_in": "constitution/DECAY-WINDOWS.md",
          "wrappers_pending_import": [
            "private/runtime/reporting-engine/src/templates.ts"
          ]
        },
        "projection_anchor": {
          "begin": "// >>> canonical escaper — generated from private/lib/html-escape/index.js; do not edit",
          "end": "// <<< canonical escaper",
          "anchor_bearers": [
            {
              "path": "scripts/lib/projection-specs.mjs",
              "role": "definition",
              "reason": "Declares the anchor strings as data for both the generator and the verifier, so it necessarily contains every token. It was split out of the generator in 2026-08-14 precisely because importing a SCRIPT for its data executed its write — the verifier repaired the drift it existed to detect, then passed."
            }
          ],
          "retired_begins": [
            {
              "text": "// >>> canonical escaper — generated from the canonical html-escape library; do not edit",
              "superseded_on": "2026-08-13",
              "reason": "Superseded when the token was rewritten to name the canonical's PATH rather than 'the library'. The old line was left behind in 26 files, where it opened nothing and was emitted by nothing — measured 2026-09-06 when grepping the token to find the consumer set returned a list 13% false, which is how it was found."
            }
          ]
        }
      },
      {
        "concept_id": "key.custody",
        "entity_class": "concept",
        "name": "Key Custody adapter (HSM/KMS-backed signing)",
        "plane": "runtime",
        "constitution_ref": "constitution/16-EDGE-RUNTIME.md",
        "ssot_module": "private/runtime/key-custody",
        "ssot_package": "@kye/key-custody",
        "ssot_entry_point": "AWS/GCP/Azure KMS + PKCS#11 HSM adapters",
        "transport_wrappers": [],
        "competitor_forbidden_patterns": [
          "function CKM_EC_EDWARDS_KEY_PAIR_GEN(",
          "const CKM_EC_EDWARDS_KEY_PAIR_GEN =",
          "class CKM_EC_EDWARDS_KEY_PAIR_GEN "
        ]
      },
      {
        "concept_id": "learn.articles",
        "entity_class": "concept",
        "name": "Education-rail articles + glossary",
        "plane": "surface",
        "constitution_ref": "constitution/39-LEARN-RAIL.md",
        "ssot_module": "private/specs/learn",
        "ssot_package": null,
        "ssot_entry_point": "manifest.json + glossary.json",
        "transport_wrappers": [],
        "competitor_scan_exemption": {
          "reason": "Articles are content records in a manifest, not code; a duplicate is a second manifest entry rather than a second implementation.",
          "enforced_by": "learn-manifest-alive"
        }
      },
      {
        "concept_id": "markdown.cell_escape",
        "entity_class": "concept",
        "name": "Markdown table-cell escaper",
        "plane": "governance",
        "constitution_ref": "constitution/00-INDEX.md#0.49",
        "ssot_module": "private/lib/markdown-cell",
        "ssot_entry_point": "markdownCell(value)",
        "competitor_forbidden_patterns": [
          "replace(/\\|/g",
          "function markdownCell(",
          "const markdownCell ="
        ],
        "competitor_baseline_key": "implementation_canonical__competitors__markdown_cell_escape",
        "transport_wrappers": [],
        "migration": {
          "status": "complete",
          "tracked_in": "private/specs/ratchets/baselines.json#implementation_canonical__competitors__markdown_cell_escape"
        }
      },
      {
        "concept_id": "marketplace.registry",
        "entity_class": "concept",
        "name": "Marketplace Registry (rule-pack marketplace index/filter/trust-score/verify)",
        "plane": "billing",
        "constitution_ref": "constitution/31-DATA-GOVERNANCE-PACK.md",
        "ssot_module": "private/runtime/marketplace-registry",
        "ssot_package": "@kye/marketplace-registry",
        "ssot_entry_point": "index + filter + trust-score + signature-verify",
        "transport_wrappers": [
          {
            "module": "private/runtime/marketplace-worker",
            "transport": "http",
            "note": "HTTP surface (Marketplace Rail)"
          }
        ],
        "competitor_forbidden_patterns": [
          "function MarketplaceRegistry(",
          "const MarketplaceRegistry =",
          "class MarketplaceRegistry "
        ]
      },
      {
        "concept_id": "mcp.tools",
        "entity_class": "concept",
        "name": "KYE MCP Server (locked KYE Protocol tool set over MCP)",
        "plane": "runtime",
        "constitution_ref": "constitution/15-MCP-AND-SDK.md",
        "ssot_module": "private/runtime/mcp-server",
        "ssot_package": "@kye/mcp-server",
        "ssot_entry_point": "MCP server (stdio transport)",
        "transport_wrappers": [
          {
            "module": "private/runtime/kye-mcp-server-worker",
            "transport": "http",
            "note": "Streamable-HTTP MCP server Worker (§15)"
          }
        ],
        "competitor_forbidden_patterns": [
          "function CONTROL_PLANE_TOOL_OUTPUT_SCHEMA(",
          "const CONTROL_PLANE_TOOL_OUTPUT_SCHEMA =",
          "class CONTROL_PLANE_TOOL_OUTPUT_SCHEMA "
        ]
      },
      {
        "concept_id": "oscal.export",
        "entity_class": "concept",
        "name": "OSCAL Exporter (KYE evidence → NIST OSCAL JSON)",
        "plane": "audit",
        "constitution_ref": "constitution/21-DELEGATED-AUDITABILITY.md",
        "ssot_module": "private/runtime/oscal-exporter",
        "ssot_package": "@kye/oscal-exporter",
        "ssot_entry_point": "project evidence → OSCAL component-definition / SSP / assessment-results",
        "transport_wrappers": [
          {
            "module": "private/runtime/kye-oscal-exporter-worker",
            "transport": "http",
            "note": "HTTP Worker (§21)"
          }
        ],
        "competitor_forbidden_patterns": [
          "function exportComponentDefinition(",
          "const exportComponentDefinition =",
          "class exportComponentDefinition "
        ]
      },
      {
        "concept_id": "parse.engine",
        "entity_class": "concept",
        "name": "Parse engine — the ONE door every governed parse goes through (grammar resolved from kye:dictionary:parse-engine, decided as kye:action-class:parse, dispatched to the declared implementation)",
        "plane": "governance",
        "constitution_ref": "constitution/40-IMPLEMENTATION-CANONICAL.md",
        "ssot_module": "scripts/lib/parse-engine.mjs",
        "ssot_package": null,
        "ssot_entry_point": "parse(grammarId, input, { target })",
        "transport_wrappers": [],
        "competitor_forbidden_patterns": [
          "actionClass: \"kye:action-class:parse\""
        ],
        "migration": {
          "status": "complete",
          "note": "Adopted 2026-09-08 with zero competitors: the two call sites that decided a parse directly (scripts/gates/region-ownership-canonical.mjs, scripts/prove-read-backs.mjs) were routed through the engine in the same change-set. The pattern is the DECISION literal — a parse decided anywhere but through the engine is a second door, whatever grammar it parses under."
        }
      },
      {
        "concept_id": "policy.administration",
        "entity_class": "concept",
        "name": "Policy Administration Point (Operating Model → Compiled Authority Bundle compiler)",
        "plane": "decision",
        "constitution_ref": "constitution/25-EDGE-GOVERNANCE.md",
        "ssot_module": "private/runtime/pap",
        "ssot_package": "@kye/pap",
        "ssot_entry_point": "Control Compiler + signed Review Records",
        "transport_wrappers": [],
        "competitor_forbidden_patterns": [
          "function CONTROL_COMPILER_VERSION(",
          "const CONTROL_COMPILER_VERSION =",
          "class CONTROL_COMPILER_VERSION "
        ]
      },
      {
        "concept_id": "policy.decision",
        "entity_class": "concept",
        "name": "Policy Decision (PDP)",
        "plane": "decision",
        "constitution_ref": "constitution/14-AGENTS-AND-ENGINES.md",
        "ssot_module": "private/runtime/pdp",
        "ssot_package": "@kye/pdp",
        "ssot_entry_point": "DecisionPoint.decide()",
        "transport_wrappers": [
          {
            "module": "private/runtime/kye-pdp-worker",
            "transport": "http",
            "must_import": "@kye/pdp",
            "note": "CF Worker HTTP surface — Phase 1 import (stableHash) complete 2026-05-19; Phase 2 (full DecisionPoint adapter for resolvers + evidence sink) tracked separately"
          },
          {
            "module": "private/runtime/epdp",
            "transport": "embedded",
            "must_import": "@kye/pdp",
            "note": "Embedded wrapper — imports canonicalJsonString from SSOT so HMAC-signed bundles hash bit-identically with central PDP"
          },
          {
            "module": "private/runtime/spdp",
            "transport": "sidecar",
            "must_import": "@kye/pdp",
            "note": "Sidecar — exports adaptKyePdpAsUpstream() bridge so sidecar deployments host the SSOT DecisionPoint in-process"
          },
          {
            "module": "private/runtime/gateway-worker",
            "transport": "http",
            "must_import": "@kye/decision-engine",
            "note": "HTTP front-end for /v1/decide. Read in full 2026-09-06: decideHandler() reaches NO verdict of its own — it loads a compiled rule bundle from D1, calls decide() from @kye/decision-engine (itself a pure adapter over @kye/pdp DecisionPoint.decide() since the 2026-08-27 collapse recorded below), persists a decision_records row and shadow-runs the canonical evaluator. It surfaced as an UNDECLARED core only when the entry predicate was widened to `decide\\w*`, which is the correct outcome: a transport that was never declared is indistinguishable from a second decider until someone reads it. Declared here rather than as an unconsolidated core because it imports the chain to the SSOT rather than re-implementing it."
          }
        ],
        "competitor_forbidden_patterns": [
          "function NativePolicyEngineAdapter(",
          "const NativePolicyEngineAdapter =",
          "class NativePolicyEngineAdapter "
        ],
        "decision_entry_patterns": [
          "export\\s+(async\\s+)?function\\s+(decide|arbitrate)\\b",
          "(^|[^.\\w$])(async\\s+)?function\\s+arbitrate\\b",
          "export\\s+class\\s+\\w*(DecisionPoint|Arbiter|EmbeddedPdp)\\b",
          "export\\s+(async\\s+)?function\\s+decide\\w*",
          "export\\s+(async\\s+)?function\\s+authoriz\\w*"
        ],
        "decision_entry_patterns_note": "Constitution §0.58 — the decision-SSOT domain of pdp-ssot-canonical is EVERY module under decision_corpus_roots that reaches an admissibility verdict, DERIVED from disk with these signatures (§0.43 no blind enforcers), not only the declared transport_wrappers. A disk hit that is neither ssot_module, a transport_wrapper, nor a declared unconsolidated_decision_core is an UNDECLARED parallel decision core and HARD-FAILS.\n\nWIDENED 2026-09-06, and the old note is why. It read: 'These signatures matched exactly four surfaces at adoption — precise, zero false positives.' Both halves were true and the conclusion was false: measured across the declared corpus, THIRTY-THREE modules export a verdict-producing symbol and these patterns saw THREE. `function\\s+(decide|arbitrate)\\b` matches `decide` exactly, so `decideAuthority`, `decideRecovery`, `decideCapabilityInvocation`, `decideRuntime` and `authorize` all fell outside it. The live cost: private/runtime/gateway/src/pdp.ts — 189 lines of deny-by-default admissibility with its own PolicyDecision type and its own `kye:pdc:reference:` id namespace — was an undeclared second decision core, in a file named pdp.ts, while this gate reported the domain clean. Precision without coverage is the §0.43 blind enforcer: a narrow predicate has zero false positives BY CONSTRUCTION and tells you nothing about what it cannot see.",
        "decision_corpus_roots": [
          "private/runtime",
          "public/app/functions",
          "public/site/functions"
        ],
        "decision_corpus_extensions": [
          ".ts",
          ".mjs",
          ".js"
        ],
        "decision_corpus_note": "§0.43 — the corpus ROOTS and EXTENSIONS are declared here because the gate had them hardcoded: `const RUNTIME_ROOT = \"private/runtime\"` with a `.ts`-only filter. Measured 2026-09-06 that was a LIVE blind spot, not a theoretical one — public/app/functions/api/coa/_lib/engine.js exports decideAuthority(), a real custody-to-authority decision core minting its own decision_map and reason_codes, and it sat outside the corpus while the gate reported the decision-SSOT domain clean. A root typed into an enforcer is a domain nobody declared: the gate can then only be widened by editing the gate, never by declaring the estate, which is the shape §0.43 forbids. Deciders live wherever the estate runs code, so the roots name the homes the estate actually has and the extensions cover the JS family as well as TypeScript.",
        "unconsolidated_decision_cores": [
          {
            "module": "private/runtime/decision-engine",
            "decision_symbol": "decide",
            "must_import": "@kye/pdp",
            "imports_core": true,
            "consumers": [
              "private/runtime/gateway-worker",
              "private/runtime/mcp-server"
            ],
            "constitution_ref": "constitution/00-INDEX.md §0.58",
            "burn_down": "COLLAPSED 2026-08-27 (user-approved full migration to pdp). decide() is now a PURE ADAPTER over @kye/pdp DecisionPoint.decide() — zero independent admissibility logic (rulesEngine deleted; hash.ts re-exports @kye/pdp's canonicalJsonString; decision_id is now the pdp fingerprint). gateway-worker + mcp-server re-pointed (await the now-async decide). Behaviour-preserving: all suites (decision-engine 28, mcp-server 98, gateway decide-handler 12/12) pass unchanged — pdp's rule/outcome derivation is semantically identical for the mapped inputs; decision_id values change (nothing pins them, and it is MORE replay-stable). Still declared here (it exports decide, a disk decision-surface) but imports the core, so the ratchet no longer counts it. Remaining: edge-arbiter (§25 edge tier).",
            "declared_at": "2026-08-27",
            "collapsed": true,
            "collapse_verified": "Verified 2026-08-27 and re-read 2026-09-06: decide() is a pure adapter over @kye/pdp DecisionPoint.decide() with zero independent admissibility logic — rulesEngine deleted, hash.ts re-exports the SSOT canonicalJsonString, decision_id is the pdp fingerprint. The VERDICT routes through the SSOT, which an import check cannot establish and a reader can."
          },
          {
            "module": "private/runtime/edge-arbiter",
            "decision_symbol": "arbitrate",
            "must_import": "@kye/pdp",
            "consumers": [],
            "constitution_ref": "constitution/00-INDEX.md §0.58",
            "burn_down": "§25 edge compiled-bundle evaluator; reimplements the verdict standalone (a legitimately-different edge tier — §0.47 already declares pdp + edge-arbiter one spine). Extract the shared bundle-evaluation core so pdp's rules-stage and the edge tier import ONE verdict logic. Larger §25 work; tracked toward zero, not a same-commit collapse.",
            "declared_at": "2026-08-27"
          },
          {
            "module": "private/runtime/gateway",
            "decision_symbol": "authorize",
            "must_import": "@kye/pdp",
            "consumers": [
              "private/runtime/gateway/src/handlers/capabilities.ts",
              "private/runtime/gateway/src/handlers/recovery.ts",
              "private/runtime/gateway/src/payments-spdp.ts"
            ],
            "constitution_ref": "constitution/00-INDEX.md §0.58",
            "burn_down": "A COMPLETE SECOND POLICY DECISION POINT, read in full 2026-09-06: private/runtime/gateway/src/pdp.ts is 189 lines of deny-by-default admissibility — actor status and stop signals, delegation resolution with expiry and subject matching, scope intersection, access-right grants, credential and attestation verification including Ed25519, high-risk escalation to RequireApproval, obligations and stop conditions — returning its own PolicyDecision type under its own id namespace `kye:pdc:reference:`. It imports shortFingerprint from @kye/pdp for IDENTITY only; the VERDICT is entirely its own. Its header calls it an 'illustrative reference' that 'does not implement' the decision algorithm, and 189 lines of live, gateway-imported admissibility logic is a decision algorithm whatever the header says. Undeclared until now for one mechanical reason: the entry predicate matched `decide` and `arbitrate` exactly, and this symbol is `authorize`. Collapse to a thin @kye/pdp adapter, behaviour-preserved against the gateway suites.",
            "declared_at": "2026-09-06"
          },
          {
            "module": "private/runtime/insight-authority-engine",
            "decision_symbol": "decideAuthority",
            "must_import": "@kye/pdp",
            "consumers": [
              "public/app/functions/api/coa"
            ],
            "constitution_ref": "constitution/00-INDEX.md §0.58",
            "burn_down": "The pure custody→authority core for the Iron Mountain InSight sector pack: mapCdvToDecisionInputs → evaluateRules → decideAuthority over the four kye:rule-pack:chain-of-authority-insight rules, deterministic and dependency-free. It is a real second decider — allow / refuse / advisory-hold without @kye/pdp — and it is HALF of a §0 duplication measured 2026-09-06: public/app/functions/api/coa/_lib/engine.js re-implements the SAME FOUR RULE IDS (insight_custody_to_authority_binding · insight_due_diligence_before_action · insight_named_authority · insight_signoff_gate) with the same two symbol names, importing nothing from this module. This file's own header asserts it is 'the single canonical implementation … no other module re-implements the decision', which was false when written and stayed false because no enforcer could see either copy. Collapse: the public COA lane imports THIS module, and this module's rule evaluation moves onto @kye/pdp's rules stage.",
            "declared_at": "2026-09-06"
          },
          {
            "module": "public/app/functions/api",
            "decision_symbol": "decideRuntime",
            "must_import": "@kye/pdp",
            "consumers": [
              "public/app/functions/api/coa",
              "public/app/functions/api/v1/runtime"
            ],
            "constitution_ref": "constitution/00-INDEX.md §0.58",
            "burn_down": "The Pages-Function decision plane, carrying TWO deciders. _lib/runtime-evaluate-engine.js exports validateEvaluateRequest → evaluateDeclaredRules → decideRuntime → runEvaluatePipeline, a full evaluate-and-seal pipeline over DERIVED_RULE_PACKS with its own decisionIdFromSeed() identity. coa/_lib/engine.js exports evaluateRules + decideAuthority, the §0 duplicate of private/runtime/insight-authority-engine described on that row. Neither reaches @kye/pdp. Both were outside every enforcer until 2026-09-06, because this gate's corpus root was hardcoded to `private/runtime` — a Pages Function is where the app plane actually decides, and no declaration could reach it. Collapse: the runtime pipeline routes through the PDP transport, and the COA lane imports the IP-track core instead of copying it.",
            "declared_at": "2026-09-06"
          }
        ],
        "unconsolidated_decision_cores_baseline_key": "pdp_ssot__unconsolidated_cores",
        "decision_identity": {
          "note": "§39/§0.49 — the decision-identity derivation is a CANONICAL CONTRACT, not a hand-rolled literal. pdp DERIVES its id prefixes from generated constants (private/runtime/pdp/src/generated/decision-identity.ts, regenerated from THIS block by scripts/build-decision-identity.mjs and verified against private/specs/identity/id-grammar.json per §0.43). Identity is PORTABLE: another entity re-derives it from the declared inputs + algorithm (§38).",
          "producer": "private/runtime/pdp/src/decision-point.ts",
          "generated_constant": "private/runtime/pdp/src/generated/decision-identity.ts",
          "generator": "scripts/build-decision-identity.mjs",
          "algorithm": "shortFingerprint",
          "id_classes": {
            "decision": "decision",
            "decision_map_fragment": "decision-map-fragment",
            "evidence_pack": "evidence-pack"
          },
          "identity_inputs": [
            "semantic_request",
            "compilation_seal",
            "decision",
            "reasons",
            "matched_rules"
          ],
          "t0_invariant": "identity covers the SEMANTIC request only; evaluated_at is excluded so an identical request re-derives an identical decision_id (§13/§0.20)."
        }
      },
      {
        "concept_id": "purpose.admit",
        "entity_class": "concept",
        "name": "Purpose & Scope Engine (Purpose Permission admit/issue/revoke)",
        "plane": "decision",
        "constitution_ref": "constitution/12-PURPOSE-PERMISSION.md",
        "ssot_module": "private/runtime/purpose-engine",
        "ssot_package": "@kye/purpose-engine",
        "ssot_entry_point": "admit(grant, request, now, signals)",
        "transport_wrappers": [
          {
            "module": "private/runtime/gateway-worker/src/lib/admit.ts",
            "transport": "http",
            "must_import": "@kye/purpose-engine",
            "note": "CF Worker hot path (POST /v1/purpose/admit). Owns transport only: the Worker-local grant/request types its schema validates, the 3-arg signature with `now` inside signals, and the wire decision shape (decided_by, verbatim decided_at, FNV-1a admissibility_decision_id, detail-free reasons so a detail wording change never moves a replay hash, §13). Verdict comes from the SSOT.",
            "entry_point": "admit(grant, request, signals)"
          },
          {
            "module": "private/runtime/mcp-server/src/stores.ts",
            "transport": "mcp",
            "must_import": "@kye/purpose-engine",
            "note": "MCP tool surface. Declared transport precondition: principal_in_session is REQUIRED in the purpose_admit tool input schema and in AdmitRequest — an MCP call with no identified session principal is rejected at the schema boundary, before the engine; the engine's own absent-principal semantics (corpus vector 085) are unchanged. The 2026-08-30 swap also closed two fail-opens in the old local copy, pinned by vector 086: not_revoked now reads lifecycle state (superseded/expired inside the window is denied), and omitting `resource` no longer bypasses a resource restriction.",
            "entry_point": "admit(grant, request, now)",
            "fixture_adapter": {
              "_why": "This wrapper owns the MCP wire shape: the canonical conformance fixture is projected into it so the gate compares VERDICTS, not field names. Declared here (§0.49) so the harness applies it generically instead of branching per wrapper.",
              "request_rename": {
                "id": "request_id"
              },
              "request_nest_signals": "signals",
              "grant_signature_object": {
                "alg": "EdDSA",
                "kid": "kye:key:mcp-conformance-fixture",
                "field": "sig_b64"
              }
            }
          }
        ],
        "competitor_forbidden_patterns": [
          "export function admit("
        ]
      },
      {
        "concept_id": "rate-limiting.tenant",
        "entity_class": "concept",
        "name": "Tenant rate-limiting (Durable Object backed; in-memory reference for tests)",
        "plane": "runtime",
        "constitution_ref": "constitution/16-EDGE-RUNTIME.md",
        "ssot_module": "private/runtime/gateway-worker",
        "ssot_package": null,
        "ssot_entry_point": "TenantRateLimiter Durable Object + src/middleware/ratelimit.ts",
        "transport_wrappers": [
          {
            "module": "private/runtime/gateway",
            "transport": "library",
            "note": "In-process token-bucket reference for single-process tests at src/middleware/rate-limit.ts. The DO-backed limiter on gateway-worker is the production authority."
          }
        ],
        "competitor_forbidden_patterns": [
          "function analyticsReplayEquivalenceRoute(",
          "const analyticsReplayEquivalenceRoute =",
          "class analyticsReplayEquivalenceRoute "
        ]
      },
      {
        "concept_id": "render.comment_strip",
        "entity_class": "concept",
        "name": "Comment stripping for source scanners (code vs. prose)",
        "plane": "governance",
        "constitution_ref": "constitution/00-INDEX.md",
        "ssot_module": "scripts/lib/strip-comments.mjs",
        "ssot_package": null,
        "ssot_entry_point": "stripComments(src, { dialect, preservePositions })",
        "transport_wrappers": [
          {
            "module": "scripts/gates/_lib.mjs",
            "transport": "library",
            "must_import": "../lib/strip-comments.mjs",
            "note": "stripCodeComments(src, { html }) — the HTML-aware entry point. It adds ONLY the markup branch (blank comments, then lex script bodies as js and style bodies as css) and delegates every code-lexing decision to the canonical. It USED to carry its own lexer, and the two disagreed on 30 of 1200 files: in 14 this one deleted live code because its regex state did not track the character class in /[^/]+/, and in 14 it left whole comments unstripped. The SSOT moved here after that measurement — the more capable implementation (7 dialects, preservePositions, regex-vs-division by value position) wins, and the HTML branch it lacked is preserved by this wrapper."
          }
        ],
        "competitor_forbidden_patterns": [
          "function stripComments(",
          "const stripComments =",
          "/\\/\\*[\\s\\S]*?\\*\\//g"
        ],
        "competitor_baseline_key": "implementation_canonical__competitors__render_comment_strip",
        "migration": {
          "status": "in-progress",
          "tracked_in": "private/specs/ratchets/baselines.json#implementation_canonical__competitors__render_comment_strip"
        }
      },
      {
        "concept_id": "render.html_tag_match",
        "entity_class": "concept",
        "name": "HTML tag + comment matching for scanners (CodeQL js/bad-tag-filter class)",
        "plane": "governance",
        "constitution_ref": "constitution/00-INDEX.md",
        "ssot_module": "public/oss/software-constitution/kit/lib/html-tags.mjs",
        "ssot_package": null,
        "ssot_entry_point": "htmlCommentRe() / rawTextElementRe(tag) / blankHtmlComments() / blankRawTextBodies()",
        "transport_wrappers": [
          {
            "module": "scripts/lib/html-tags.mjs",
            "transport": "library",
            "must_import": "../../public/oss/software-constitution/kit/lib/html-tags.mjs",
            "note": "Re-export only, zero implementation. The canonical lives in the §42 kit because the kit is PUBLISHED and scaffolded into other repos: it imports nothing outside itself, so a copy there would ship its defects to every adopter. must_import is the mechanical proof this path forwards to the canonical instead of re-implementing it."
          }
        ],
        "competitor_forbidden_patterns": [
          "<\\/script>",
          "<\\/style>",
          "<!--[\\s\\S]*?-->"
        ],
        "competitor_baseline_key": "implementation_canonical__competitors__render_html_tag_match",
        "migration": {
          "status": "in-progress",
          "tracked_in": "private/specs/ratchets/baselines.json#implementation_canonical__competitors__render_html_tag_match"
        }
      },
      {
        "concept_id": "replay.derive",
        "entity_class": "concept",
        "name": "Replay Engine (Execution Context Seal + Determinism Proof + Replay Proof)",
        "plane": "evidence",
        "constitution_ref": "constitution/13-RESILIENCE-LOOP.md",
        "ssot_module": "private/runtime/replay-engine",
        "ssot_package": "@kye/replay-engine",
        "ssot_entry_point": "context seal + determinism proof",
        "transport_wrappers": [],
        "competitor_forbidden_patterns": [
          "function DeterminismProver(",
          "const DeterminismProver =",
          "class DeterminismProver "
        ]
      },
      {
        "concept_id": "replay.proof-generation",
        "entity_class": "concept",
        "name": "Replay-Proof™ generation (re-derive a decision from public signatures)",
        "plane": "evidence",
        "constitution_ref": "constitution/13-RESILIENCE-LOOP.md",
        "ssot_module": "private/runtime/replay-proof-generator",
        "ssot_package": null,
        "ssot_entry_point": "POST /v1/replay/derive — worker.js",
        "transport_wrappers": [],
        "competitor_scan_exemption": {
          "reason": "Proof generation is proven by OUTPUT EQUIVALENCE across engines, not by symbol uniqueness — two engines agreeing is the invariant, so a competing-symbol pattern would test the wrong thing.",
          "enforced_by": "engine-replay-equiv"
        }
      },
      {
        "concept_id": "reporting.synthesize",
        "entity_class": "concept",
        "name": "Reporting Engine (per-framework compliance report synthesis)",
        "plane": "audit",
        "constitution_ref": "constitution/21-DELEGATED-AUDITABILITY.md",
        "ssot_module": "private/runtime/reporting-engine",
        "ssot_package": "@kye/reporting-engine",
        "ssot_entry_point": "per-framework report synthesis from the audit chain",
        "transport_wrappers": [
          {
            "module": "private/runtime/kye-reporting-worker",
            "transport": "http",
            "note": "HTTP + cron period-close + auto-delivery Worker"
          },
          {
            "module": "private/runtime/kye-reporting-agent-worker",
            "transport": "http",
            "note": "Reporting Agent Worker (§26 stakeholder reports). Overlap with kye-reporting-worker flagged for runtime-consolidation review."
          }
        ],
        "competitor_forbidden_patterns": [
          "function sampleAuditChainRefs(",
          "const sampleAuditChainRefs =",
          "class sampleAuditChainRefs "
        ]
      },
      {
        "concept_id": "risk.score",
        "entity_class": "concept",
        "name": "Risk Engine (canonical risk tier + 0..100 risk score)",
        "plane": "decision",
        "constitution_ref": "constitution/13-RESILIENCE-LOOP.md",
        "ssot_module": "private/runtime/risk-engine",
        "ssot_package": "@kye/risk-engine",
        "ssot_entry_point": "risk tier + score per EU AI Act floor",
        "transport_wrappers": [
          {
            "module": "private/runtime/kye-risk-agent",
            "transport": "http",
            "note": "HTTP Worker — POST /v1/risk/assess"
          }
        ],
        "competitor_forbidden_patterns": [
          "function RiskEngine(",
          "const RiskEngine =",
          "class RiskEngine "
        ]
      },
      {
        "concept_id": "rules.evaluate",
        "entity_class": "concept",
        "name": "Rules Engine (rights/obligations/prohibitions/stop-conditions evaluator)",
        "plane": "decision",
        "constitution_ref": "constitution/14-AGENTS-AND-ENGINES.md",
        "ssot_module": "private/runtime/rules-engine",
        "ssot_package": "@kye/rules-engine",
        "ssot_entry_point": "evaluate(input, bundle) -> rule_result",
        "transport_wrappers": [],
        "competitor_forbidden_patterns": [
          "function RuleCompileError(",
          "const RuleCompileError =",
          "class RuleCompileError "
        ]
      },
      {
        "concept_id": "rules.gateway",
        "entity_class": "concept",
        "name": "Rules Gateway (rule-pack evaluation surface)",
        "plane": "runtime",
        "constitution_ref": "constitution/29-PROFILES-LITE.md",
        "ssot_module": "private/runtime/rules-gateway",
        "ssot_package": "@kye/rules-gateway",
        "ssot_entry_point": "evaluate(...)",
        "transport_wrappers": [
          {
            "module": "private/runtime/rules-gateway-worker",
            "transport": "http",
            "note": "CF Worker HTTP surface around the rules-gateway library"
          }
        ],
        "competitor_scan_exemption": {
          "reason": "The gateway's uniqueness question is orphan RULES rather than a duplicated symbol — a second rule set, not a second evaluate(). The operating-model gate answers that question directly.",
          "enforced_by": "om-no-orphan-rules"
        }
      },
      {
        "concept_id": "search.query",
        "entity_class": "concept",
        "name": "KYE Native Search Engine™ (D1 FTS5 lexical + Vectorize semantic query surface)",
        "plane": "runtime",
        "constitution_ref": "constitution/17-DIRECTORY-SEARCH.md",
        "ssot_module": "private/runtime/kye-search-engine",
        "ssot_package": "kye-search-engine",
        "ssot_entry_point": "POST /v1/search — worker.ts (F34 entitlement gate + F37 classification floor + F38 risk-tier cap + Ed25519-signed envelope + §0.3 audit emission)",
        "transport_wrappers": [
          {
            "module": "private/runtime/kye-search-indexer-worker",
            "transport": "queue",
            "note": "Index refresher — rebuilds the native D1 FTS5 + Vectorize substrate (cron full/incremental + kye-search-delta queue)."
          }
        ],
        "note": "Pre-cutover legacy-search dead code at private/runtime/search/ deleted. The three legacy Cloudflare search workers were decommissioned 2026-08-05 (deleted via the Cloudflare API); native D1 FTS5 + Vectorize is the one search substrate.",
        "competitor_forbidden_patterns": [
          "function buildFtsQuery(",
          "const buildFtsQuery =",
          "class buildFtsQuery "
        ]
      },
      {
        "concept_id": "siem.export",
        "entity_class": "concept",
        "name": "SIEM Export (audit-log shipping to Splunk/Sentinel/Elastic/Datadog)",
        "plane": "audit",
        "constitution_ref": "constitution/14-AGENTS-AND-ENGINES.md",
        "ssot_module": "private/runtime/siem-export",
        "ssot_package": "@kye/siem-export",
        "ssot_entry_point": "push/pull SIEM shipping per tenant_siem_targets",
        "transport_wrappers": [
          {
            "module": "private/runtime/kye-siem-export-worker",
            "transport": "http",
            "note": "Streaming Worker (§14)"
          }
        ],
        "competitor_forbidden_patterns": [
          "function sentinelCanonicalString(",
          "const sentinelCanonicalString =",
          "class sentinelCanonicalString "
        ]
      },
      {
        "concept_id": "sql.like_escape",
        "entity_class": "concept",
        "name": "LIKE-pattern escaper for a user-supplied search term",
        "plane": "surface",
        "constitution_ref": "constitution/00-INDEX.md#0.49",
        "ssot_module": "private/lib/sql-like",
        "ssot_entry_point": "escapeLike(value)",
        "competitor_forbidden_patterns": [
          "replace(/[%_]/g",
          "function escapeLike(",
          "const escapeLike ="
        ],
        "competitor_baseline_key": "implementation_canonical__competitors__sql_like_escape",
        "transport_wrappers": [
          {
            "module": "public/app/functions/api/v1/search.js",
            "transport": "projection",
            "note": "Byte-projected by scripts/build-html-escape-projection.mjs; equality verified by implementation-canonical. A Pages Function cannot import from private/ (§33 IP/OSS line), so projection is the transport, exactly as for html.escape and url.safe."
          },
          {
            "module": "public/admin/functions/api/v1/search.js",
            "transport": "projection",
            "note": "Byte-projected by scripts/build-html-escape-projection.mjs; equality verified by implementation-canonical. A Pages Function cannot import from private/ (§33 IP/OSS line), so projection is the transport, exactly as for html.escape and url.safe."
          },
          {
            "module": "public/admin/functions/api/v1/issuers.js",
            "transport": "projection",
            "note": "Byte-projected by scripts/build-html-escape-projection.mjs; equality verified by implementation-canonical. A Pages Function cannot import from private/ (§33 IP/OSS line), so projection is the transport, exactly as for html.escape and url.safe."
          },
          {
            "module": "public/admin/functions/api/v1/evidence-index.js",
            "transport": "projection",
            "note": "Byte-projected by scripts/build-html-escape-projection.mjs; equality verified by implementation-canonical. A Pages Function cannot import from private/ (§33 IP/OSS line), so projection is the transport, exactly as for html.escape and url.safe."
          }
        ],
        "migration": {
          "status": "complete",
          "tracked_in": "private/specs/ratchets/baselines.json#implementation_canonical__competitors__sql_like_escape"
        },
        "projection_anchor": {
          "begin": "// >>> canonical sql-like — generated from private/lib/sql-like/index.js; do not edit",
          "end": "// <<< canonical sql-like",
          "anchor_bearers": [
            {
              "path": "scripts/lib/projection-specs.mjs",
              "role": "definition",
              "reason": "Declares the anchor strings as data for both the generator and the verifier, so it necessarily contains every token. It was split out of the generator in 2026-08-14 precisely because importing a SCRIPT for its data executed its write — the verifier repaired the drift it existed to detect, then passed."
            }
          ]
        }
      },
      {
        "concept_id": "toolchain.version_pin",
        "entity_class": "concept",
        "name": "Which exact version of an external toolchain component does KYE run?",
        "plane": "governance",
        "constitution_ref": "constitution/00-INDEX.md",
        "ssot_module": "private/specs/toolchain/deploy-toolchain.json",
        "ssot_package": null,
        "ssot_entry_point": "tools[].channels[].version (exact x.y.z, enforced by scripts/gates/deploy-toolchain-pinned.mjs)",
        "transport_wrappers": [],
        "competitor_forbidden_patterns": [
          "node-version: '2",
          "node-version: \"2"
        ],
        "competitor_baseline_key": "implementation_canonical__competitors__toolchain_version_pin",
        "migration": {
          "status": "complete",
          "note": "Registered 2026-08-15. The registry is tool-generic but held ONE member (wrangler) while node was pinned by hand 38 times across .github/workflows, four of them on an EOL major. Nobody noticed because there was no canonical version to drift FROM — the unpopulated-registry defect."
        }
      },
      {
        "concept_id": "ui.cache-bust",
        "entity_class": "concept",
        "name": "Cache-bust value used on every static asset URL",
        "plane": "surface",
        "constitution_ref": "constitution/06-WEBSITE.md",
        "ssot_module": "scripts/sync-marketing-counters.mjs",
        "ssot_package": null,
        "ssot_entry_point": "rolling value applied via 'npm run fix:consistency'",
        "transport_wrappers": [],
        "competitor_scan_exemption": {
          "reason": "The cache-bust value is a rolling STRING stamped across assets, not a callable symbol, so a second copy is a second value rather than a second function definition — a §40 pattern cannot see it.",
          "enforced_by": "cache-bust-canonical"
        }
      },
      {
        "concept_id": "ui.chrome",
        "entity_class": "concept",
        "name": "Site chrome (top-bar, footer, breadcrumbs, drawer)",
        "plane": "surface",
        "constitution_ref": "constitution/02-INFORMATION-ARCHITECTURE.md",
        "ssot_module": "public/site/assets/components.js",
        "ssot_package": null,
        "ssot_entry_point": "TOP_BAR_HUB_IDS + FOOTER_GROUPS + kyeTopBar() + kyeFooter() + kyeBreadcrumbs() + kyeDrawer()",
        "transport_wrappers": [],
        "competitor_forbidden_patterns": [
          "function kyeCalloutDelegatedAuditability(",
          "const kyeCalloutDelegatedAuditability =",
          "class kyeCalloutDelegatedAuditability "
        ]
      },
      {
        "concept_id": "ui.theme-bootstrap",
        "entity_class": "concept",
        "name": "UI theme bootstrap (dark/light + brand tokens)",
        "plane": "surface",
        "constitution_ref": "constitution/04-DESIGN-SYSTEM.md",
        "ssot_module": "public/site/assets/theme-bootstrap.js",
        "ssot_package": null,
        "ssot_entry_point": "theme-bootstrap.js (default export)",
        "transport_wrappers": [],
        "competitor_scan_exemption": {
          "reason": "theme-bootstrap.js is a browser bootstrap loaded by a script tag with no named export to key on; a competing copy is a second injected script, which the theme freshness gate detects.",
          "enforced_by": "theme-canonical-fresh"
        }
      },
      {
        "concept_id": "url.safe",
        "entity_class": "concept",
        "name": "URL sink guard (scheme allow-list for href/src)",
        "plane": "surface",
        "constitution_ref": "constitution/00-INDEX.md#0.49",
        "ssot_module": "private/lib/safe-url",
        "ssot_entry_point": "safeUrl(value)",
        "competitor_forbidden_patterns": [
          "function safeUrl(",
          "const safeUrl ="
        ],
        "competitor_scan_extensions": [
          ".html"
        ],
        "transport_wrappers": [
          {
            "module": "public/site/assets/video-library.js",
            "transport": "projection",
            "note": "Byte-projected by scripts/build-html-escape-projection.mjs; equality verified by implementation-canonical. Added 2026-08-14: four sinks assigned a DOM-attribute URL straight to href/src (CodeQL js/xss-through-dom), where a javascript: value executes on click."
          },
          {
            "module": "public/site/assets/demos.js",
            "transport": "projection",
            "note": "Byte-projected by scripts/build-html-escape-projection.mjs; equality verified by implementation-canonical. Added 2026-08-14: setAttribute('src', …) from a data- attribute (CodeQL js/xss-through-dom)."
          }
        ],
        "projection_anchor": {
          "begin": "// >>> canonical safe-url — generated from private/lib/safe-url/index.js; do not edit",
          "end": "// <<< canonical safe-url",
          "anchor_bearers": [
            {
              "path": "scripts/lib/projection-specs.mjs",
              "role": "definition",
              "reason": "Declares the anchor strings as data for both the generator and the verifier, so it necessarily contains every token. It was split out of the generator in 2026-08-14 precisely because importing a SCRIPT for its data executed its write — the verifier repaired the drift it existed to detect, then passed."
            }
          ]
        }
      },
      {
        "concept_id": "webhook.signature.verify",
        "entity_class": "concept",
        "name": "Inbound webhook signature verification (KYE-Timestamp + KYE-Signature + KYE-Delivery-ID HMAC scheme per private/specs/webhooks/signing.md)",
        "plane": "runtime",
        "constitution_ref": "constitution/06-WEBSITE.md",
        "ssot_module": "private/runtime/webhook-dispatcher",
        "ssot_package": null,
        "ssot_entry_point": "verify({ body, headers, resolveSecret, isDeliveryFresh }) — see src/verify.ts",
        "transport_wrappers": [],
        "note": "Vendor schemes (Svix in public/site/functions/webhooks/clerk.js, Stripe-Signature in public/admin/functions/webhooks/stripe.js) are vendor-specific and out of scope — they implement the vendor's signing protocol, not the KYE one. Legacy in-process v1 verifier at private/runtime/gateway/src/webhook-verifier.ts was DELETED 2026-05-19 (zero non-test callers; consolidation complete).",
        "competitor_forbidden_patterns": [
          "function parseSignatureHeader(",
          "const parseSignatureHeader =",
          "class parseSignatureHeader "
        ]
      },
      {
        "concept_id": "declared-agent-set",
        "entity_class": "concept",
        "name": "The DECLARED agent set at the runtime boundary — which kye:agent:<name> ids KYE declares",
        "plane": "identity",
        "constitution_ref": "constitution/00-INDEX.md",
        "ssot_module": "public/app/functions/api/_lib/declared-agents.generated.js",
        "ssot_package": "(none — a GENERATED Pages Functions module imported by relative path; written by scripts/build-declared-agents.mjs from kye:registry:agents-manifest, never hand-edited)",
        "ssot_entry_point": "isDeclaredAgent(id) — the ONE membership test; DECLARED_AGENT_IDS is the set it closes over",
        "transport_wrappers": [],
        "competitor_forbidden_patterns": [
          "AGENT_PRINCIPAL_RE"
        ],
        "removed_competitors": [
          "public/app/functions/api/_lib/api-key-auth.js AGENT_PRINCIPAL_RE (deleted 2026-09-10 — a point-of-use copy of the ^kye:agent:…$ pattern kye.agent.exchange.v1 declares for sender.agent_entity_id, standing in for a membership test. Measured before deleting: the shape test returned kye:agent:ghost-agent — an agent nobody declares — as an authoritative actor, and it could not see an agent REMOVED from the manifest, so undeclaring an agent revoked nothing. Membership returns null for both.)"
        ],
        "note": "Two consumers need one answer to 'is this a declared agent': api-keys/agent/issue.js at issuance (may this key be minted) and _lib/api-key-auth.js at verification (does this key act as an agent KYE declares NOW). Both ends check on purpose and it is not a §0 duplicate — only the second moves when the manifest does — but they must answer through ONE set, which is why the second importer is what made this a registered concept. A Worker cannot read the repo, so the declaration reaches the boundary as a projection rather than a re-listing.\n\nONE pattern, and the honest reason there is not a second. AGENT_PRINCIPAL_RE names the competitor that actually existed here and measures 0 hits, so zero-tolerance is the right posture and no ceiling is declared (the ratchet index is CLOSED, §0.62). The other competitor class — a hand-written list of agent ids at a point of use — was left WITHOUT a pattern deliberately: the candidates were measured, and the only literal that would catch it (a specific agent id in quotes) hits nothing but the SSOT today while a future test naming that agent would fire falsely. A verifier that fails on a correct tree is the same defect as one that passes on a broken one, so the risk is recorded here rather than shipped as a rule. The projection itself is the structural defence: it is generated, and scripts/build-declared-agents.mjs refuses to emit an id kye.agent.exchange.v1 cannot carry, so there is nothing for a hand-written list to be more convenient than."
      },
      {
        "concept_id": "sandbox.govern_core",
        "entity_class": "concept",
        "name": "Sandbox act decision loop — the ONE loop every sandbox provider act is decided through (masterblueprint §11 S-8)",
        "plane": "governance",
        "constitution_ref": "constitution/00-INDEX.md",
        "ssot_module": "scripts/lib/sandbox-govern-core.mjs",
        "ssot_package": null,
        "ssot_entry_point": "buildSandboxDP(pdp, {tenant, evidenceSink}) · decideAct(dp, act) · sandboxBundle() · SANDBOX_ACTIONS / CLASS_OF · DECISION_BUDGET / ATTACH_BUDGET_MS · decisionSummary()",
        "transport_wrappers": [
          {
            "module": "private/runtime/sandbox-runtime/src/govern.ts",
            "transport": "import",
            "note": "Worker lane: static @kye/pdp import + a retaining evidence sink (kye-evidence-seal queue + §0.3 chain); decides nothing itself."
          },
          {
            "module": "scripts/smoke/sandbox-runtime.mjs",
            "transport": "cli",
            "note": "Node smoke: measures the verdict path against DECISION_BUDGET and exercises the deployed substrate with --live."
          },
          {
            "module": "scripts/smoke/freestyle-sandbox.mjs",
            "transport": "cli",
            "note": "Node smoke for the comparator provider (Freestyle) behind the same five-verb port."
          }
        ],
        "migration": {
          "status": "complete",
          "note": "Registered 2026-09-15 with the S-8 phase 2 runtime. Sibling of governed-run-core (the §0.34 inventory loop, one self-run action) — NOT a fork of it: this bundle admits exactly the five sandbox actions. Four importers at registration (the Worker, two smokes, the Worker test)."
        },
        "competitor_forbidden_patterns": [
          "function sandboxBundle(",
          "function decideAct(",
          "export const SANDBOX_ACTIONS"
        ]
      },
      {
        "concept_id": "surface.rendered_shell_verify",
        "entity_class": "concept",
        "name": "Rendered-shell verification — the ONE page→shell-class resolution and the ONE measurement of a rendered shell (selector counts + computed styles) that every verifier of the compulsory visual inspection reads (CLAUDE.md 2026-09-15/16)",
        "plane": "surface",
        "constitution_ref": "constitution/13-RESILIENCE-LOOP.md",
        "ssot_module": "scripts/lib/ui-boot-core.mjs",
        "ssot_package": null,
        "ssot_entry_point": "shellClassFor(pagePath, {smokeManifest, affordanceContract}) · measureRenderedShell(page, shell) · startStaticServer · answerApi · setSurface",
        "transport_wrappers": [
          {
            "module": "scripts/smoke/surface-smoke.mjs",
            "transport": "import",
            "note": "--rendered arm: opens every page of every class and calls measureRenderedShell; measures nothing itself."
          },
          {
            "module": "scripts/smoke/ui-journey-run.mjs",
            "transport": "import",
            "note": "The customer/admin journey: resolves each walked page through shellClassFor and asserts through measureRenderedShell (shell-mismatch); keeps no copy of either."
          },
          {
            "module": "scripts/gates/subdomain-chrome-canonical.mjs",
            "transport": "import",
            "note": "Check (e): the estate-chrome population for the theme bootstrap is resolved through shellClassFor; the gate keys on no private page→class rule."
          }
        ],
        "migration": {
          "status": "complete",
          "note": "Registered 2026-09-16 with the shell-stylesheet cure. Measured 2026-09-16: the page→class resolution lived twice (the journeys runner and the theme-bootstrap gate each keyed on a private copy) and the count probe lived twice (the rendered arm and the journeys runner); both unified here the same day the computed-style assertion was added."
        },
        "competitor_forbidden_patterns": [
          "function shellClassFor(",
          "function measureRenderedShell(",
          "export async function measureRenderedShell("
        ]
      },
      {
        "concept_id": "entity_class.stamp",
        "entity_class": "concept",
        "name": "Entity-class stamp — the ONE implementation of the §0.36 limb (c) instance self-declaration rule for GENERATED registries (scope, value and key position), read by the late P5b writer and by every owning generator's --check projection",
        "plane": "governance",
        "constitution_ref": "constitution/40-IMPLEMENTATION-CANONICAL.md",
        "ssot_module": "scripts/lib/entity-class-stamp.mjs",
        "ssot_package": null,
        "ssot_entry_point": "stampClassFor(path, raw) / applyEntityClassStamp(path, doc, raw) / projectEntityClassStamp(path, bytes)",
        "transport_wrappers": [],
        "competitor_forbidden_patterns": [
          "entries.splice(idIdx >= 0 ? idIdx + 1 : 0, 0, [\"entity_class\""
        ],
        "migration": {
          "status": "complete",
          "note": "Adopted 2026-09-17 with zero competitors. A generated registry has TWO declared writers by design — the generator that owns its content, and build-entity-class-stamps.mjs at P5b/85 (after build-admission-matrix at P5b/82, which is what makes the stamp value derivable rather than typed). A P3 generator cannot read that matrix without depending backwards on P5b, so its raw byte-equality --check is false of a CORRECT tree the moment its class enters the matrix. The cure is the 2026-09-07 verifier rule: compare against the PROJECTED bytes, through the writer's own implementation. Three hand-rolled copies of the splice were routed through the SSOT in the same change-set (build-edge-runtime-manifests.mjs, build-workflow-registry.mjs, and the writer's own private block, now deleted); build-component-graph.mjs and build-ontology-crossmap-browser.mjs — the two of 12 candidate emitters MEASURED to be failing — call the projection."
        }
      },
      {
        "concept_id": "egress.decision",
        "entity_class": "concept",
        "name": "May this outbound crossing happen? (the one egress decision: URL host → declared counterparty row → kye:action-class:egress through the real PDP; credential resolved at the boundary)",
        "plane": "decision",
        "constitution_ref": "constitution/00-INDEX.md",
        "ssot_module": "scripts/govern/egress-decision.mjs",
        "ssot_package": null,
        "ssot_entry_point": "counterparties() · resolveCrossing(url) · decideEgress({row, purpose, carriesTenantData}) · notACrossing() · credentialFor(row)",
        "transport_wrappers": [
          {
            "module": "scripts/govern/egress-pep.mjs",
            "transport": "cli",
            "entry_point": "egress-pep.mjs <subprocessor-id> <purpose> [tenant-data] | --list",
            "must_import": "./egress-decision.mjs",
            "note": "A governed caller asks by counterparty name before it makes the call. Thin over decideEgress(); carries no decision of its own (boundary-governance-canonical (a2) + this row's competitor patterns)."
          },
          {
            "module": "scripts/lib/egress-gateway.mjs",
            "transport": "http-client",
            "entry_point": "install() via --import scripts/lib/egress-gateway.preload.mjs",
            "must_import": "../govern/egress-decision.mjs",
            "note": "The process's HTTP client, governed: Every connection the process makes asks by URL, BEFORE the socket: undici Agent({connect}) + compose interceptor, node:http/https Agent.createConnection + request() header injection. Loopback read from not_a_crossing[] through notACrossing(), never restated."
          }
        ],
        "competitor_forbidden_patterns": [
          "function decideEgress(",
          "const decideEgress =",
          "function resolveCrossing(",
          "const resolveCrossing =",
          "function counterparties("
        ],
        "migration": {
          "status": "complete",
          "note": "Registered 2026-09-22 with the interceptor. The decision used to live inline in scripts/govern/egress-pep.mjs, a CLI a caller had to invoke; the interceptor (undici connect + node:http createConnection) needed the SAME decision before a socket, so it was extracted to one module both call (§0.49/§0.61). The two wrappers are the CLI (a governed caller asks by name) and the runtime interceptor (every connection the process makes asks by URL); a third copy of resolveCrossing or decideEgress anywhere is the competitor this row forbids. Loopback exemption is READ from not_a_crossing[] on the boundary row through notACrossing(), never restated (boundary-governance-canonical (a2))."
        }
      },
      {
        "concept_id": "storage.projection",
        "entity_class": "concept",
        "name": "Storage projection reader — store objects, contract↔column comparison, writer coverage (the one measurement of what the runtime corpus declares, inserts, updates and reads per table)",
        "plane": "diagnostic",
        "constitution_ref": "constitution/16-EDGE-RUNTIME.md",
        "ssot_module": "scripts/lib/storage-projection.mjs",
        "ssot_package": null,
        "ssot_entry_point": "loadStoreObjects() · compareRow() · writerCoverage() · phantomColumns() · fleetSites() · fleetTableNames()",
        "transport_wrappers": [],
        "competitor_forbidden_patterns": [
          "function loadStoreObjects(",
          "function compareRow(",
          "function writerCoverage(",
          "function phantomColumns(",
          "function fleetTableNames("
        ]
      },
      {
        "concept_id": "followability.served-block",
        "entity_class": "concept",
        "name": "Follow-surface served block (what a §75 pull endpoint carries: surfaces × state classes × recorded transitions)",
        "plane": "surface",
        "constitution_ref": "constitution/75-FOLLOWABILITY-RAIL.md#section-2",
        "ssot_module": "scripts/lib/follow-surfaces.mjs",
        "ssot_entry_point": "deriveFollowSurfaces() · renderFollowSurfacesBlock(surfaces)",
        "transport_wrappers": [
          {
            "module": "scripts/build-derived-follow-surfaces.mjs",
            "transport": "import",
            "must_import": "./lib/follow-surfaces.mjs",
            "note": "Writes the block into the Astro source fragments and the public sidecar. The writer never re-derives."
          },
          {
            "module": "scripts/gates/followability-canonical.mjs",
            "transport": "import",
            "must_import": "../lib/follow-surfaces.mjs",
            "note": "Check 3a asserts the RENDERED pull page carries every surface id, state class and item decision id the same derivation yields (§0.61: writer and checker share one implementation)."
          }
        ],
        "competitor_forbidden_patterns": [
          "function deriveFollowSurfaces",
          "function renderFollowSurfacesBlock",
          "data-follow-state-class=\\\""
        ],
        "note": "Measured 2026-09-30: the followability gate's served check was existsSync(<page>) and /directory.html carried none of the Armenia surface's declared state; a second derivation of 'what the pull page serves' in the gate would be the §0.49 copy that drifts from the block it checks. One derivation, imported by both ends."
      }
    ],
    "projection_anchor_scan_exclusions": [
      {
        "prefix": "site/dist",
        "reason": "Astro's own output directory, ignored by site/.gitignore and written by scripts/build-astro-pages.mjs. It cannot be declared as a wrapper because nothing can declare an untracked artefact; its anchor block is a third copy of a pair already governed on both tracked sides, and keeping it in step is build-astro-pages --check's freshness contract (§53 vertical-down)."
      }
    ],
    "unregistered_backlog": {
      "scripts/lib/canonical-paths.mjs": {
        "importers_at_measurement": 575,
        "measured_at": "2026-09-10",
        "note": "Measured as a shared implementation: imported from 575 distinct files, which is the §0.9 trigger (an artefact referenced from more than one file belongs to a canonical registry). No §40 concept row names it. What concept it implements, and therefore what a competing copy of it would look like, has not been judged — that judgement is the registration this entry is owed."
      },
      "scripts/lib/baseline.mjs": {
        "importers_at_measurement": 146,
        "measured_at": "2026-09-10",
        "note": "Measured as a shared implementation: imported from 146 distinct files, which is the §0.9 trigger (an artefact referenced from more than one file belongs to a canonical registry). No §40 concept row names it. What concept it implements, and therefore what a competing copy of it would look like, has not been judged — that judgement is the registration this entry is owed."
      },
      "scripts/lib/public-redaction.mjs": {
        "importers_at_measurement": 36,
        "measured_at": "2026-09-10",
        "note": "Measured as a shared implementation: imported from 36 distinct files, which is the §0.9 trigger (an artefact referenced from more than one file belongs to a canonical registry). No §40 concept row names it. What concept it implements, and therefore what a competing copy of it would look like, has not been judged — that judgement is the registration this entry is owed."
      },
      "public/admin/functions/api/v1/_lib/scenario-testing.js": {
        "importers_at_measurement": 29,
        "measured_at": "2026-09-10",
        "note": "Measured as a shared implementation: imported from 29 distinct files, which is the §0.9 trigger (an artefact referenced from more than one file belongs to a canonical registry). No §40 concept row names it. What concept it implements, and therefore what a competing copy of it would look like, has not been judged — that judgement is the registration this entry is owed."
      },
      "scripts/reconciliation/lib.mjs": {
        "importers_at_measurement": 29,
        "measured_at": "2026-09-10",
        "note": "Measured as a shared implementation: imported from 29 distinct files, which is the §0.9 trigger (an artefact referenced from more than one file belongs to a canonical registry). No §40 concept row names it. What concept it implements, and therefore what a competing copy of it would look like, has not been judged — that judgement is the registration this entry is owed."
      },
      "scripts/lib/no-parallel-definition.mjs": {
        "importers_at_measurement": 27,
        "measured_at": "2026-09-10",
        "note": "Measured as a shared implementation: imported from 27 distinct files, which is the §0.9 trigger (an artefact referenced from more than one file belongs to a canonical registry). No §40 concept row names it. What concept it implements, and therefore what a competing copy of it would look like, has not been judged — that judgement is the registration this entry is owed."
      },
      "scripts/lib/admission.mjs": {
        "importers_at_measurement": 26,
        "measured_at": "2026-09-10",
        "note": "Measured as a shared implementation: imported from 26 distinct files, which is the §0.9 trigger (an artefact referenced from more than one file belongs to a canonical registry). No §40 concept row names it. What concept it implements, and therefore what a competing copy of it would look like, has not been judged — that judgement is the registration this entry is owed."
      },
      "scripts/lib/browser.mjs": {
        "importers_at_measurement": 26,
        "measured_at": "2026-09-10",
        "note": "Measured as a shared implementation: imported from 26 distinct files, which is the §0.9 trigger (an artefact referenced from more than one file belongs to a canonical registry). No §40 concept row names it. What concept it implements, and therefore what a competing copy of it would look like, has not been judged — that judgement is the registration this entry is owed."
      },
      "scripts/lib/pdp-bootstrap.mjs": {
        "importers_at_measurement": 24,
        "measured_at": "2026-09-10",
        "note": "Measured as a shared implementation: imported from 24 distinct files, which is the §0.9 trigger (an artefact referenced from more than one file belongs to a canonical registry). No §40 concept row names it. What concept it implements, and therefore what a competing copy of it would look like, has not been judged — that judgement is the registration this entry is owed."
      },
      "scripts/research/lib/html-text.mjs": {
        "importers_at_measurement": 22,
        "measured_at": "2026-09-10",
        "note": "Measured as a shared implementation: imported from 22 distinct files, which is the §0.9 trigger (an artefact referenced from more than one file belongs to a canonical registry). No §40 concept row names it. What concept it implements, and therefore what a competing copy of it would look like, has not been judged — that judgement is the registration this entry is owed."
      },
      "scripts/lib/asset-version.mjs": {
        "importers_at_measurement": 17,
        "measured_at": "2026-09-10",
        "note": "Measured as a shared implementation: imported from 17 distinct files, which is the §0.9 trigger (an artefact referenced from more than one file belongs to a canonical registry). No §40 concept row names it. What concept it implements, and therefore what a competing copy of it would look like, has not been judged — that judgement is the registration this entry is owed."
      },
      "scripts/lib/governed-run-core.mjs": {
        "importers_at_measurement": 17,
        "measured_at": "2026-09-10",
        "note": "Measured as a shared implementation: imported from 17 distinct files, which is the §0.9 trigger (an artefact referenced from more than one file belongs to a canonical registry). No §40 concept row names it. What concept it implements, and therefore what a competing copy of it would look like, has not been judged — that judgement is the registration this entry is owed."
      },
      "public/admin/functions/api/v1/_lib/reality-coupling.js": {
        "importers_at_measurement": 16,
        "measured_at": "2026-09-10",
        "note": "Measured as a shared implementation: imported from 16 distinct files, which is the §0.9 trigger (an artefact referenced from more than one file belongs to a canonical registry). No §40 concept row names it. What concept it implements, and therefore what a competing copy of it would look like, has not been judged — that judgement is the registration this entry is owed."
      },
      "scripts/lib/default-theme.mjs": {
        "importers_at_measurement": 16,
        "measured_at": "2026-09-10",
        "note": "Measured as a shared implementation: imported from 16 distinct files, which is the §0.9 trigger (an artefact referenced from more than one file belongs to a canonical registry). No §40 concept row names it. What concept it implements, and therefore what a competing copy of it would look like, has not been judged — that judgement is the registration this entry is owed."
      },
      "public/admin/functions/api/v1/_lib/consultant.js": {
        "importers_at_measurement": 15,
        "measured_at": "2026-09-10",
        "note": "Measured as a shared implementation: imported from 15 distinct files, which is the §0.9 trigger (an artefact referenced from more than one file belongs to a canonical registry). No §40 concept row names it. What concept it implements, and therefore what a competing copy of it would look like, has not been judged — that judgement is the registration this entry is owed."
      },
      "private/lib/schema-guard/assert.mjs": {
        "importers_at_measurement": 14,
        "measured_at": "2026-09-10",
        "note": "Measured as a shared implementation: imported from 14 distinct files, which is the §0.9 trigger (an artefact referenced from more than one file belongs to a canonical registry). No §40 concept row names it. What concept it implements, and therefore what a competing copy of it would look like, has not been judged — that judgement is the registration this entry is owed."
      },
      "scripts/lib/framework-eval.mjs": {
        "importers_at_measurement": 14,
        "measured_at": "2026-09-10",
        "note": "Measured as a shared implementation: imported from 14 distinct files, which is the §0.9 trigger (an artefact referenced from more than one file belongs to a canonical registry). No §40 concept row names it. What concept it implements, and therefore what a competing copy of it would look like, has not been judged — that judgement is the registration this entry is owed."
      },
      "public/site/functions/api/_lib/public-evidence.js": {
        "importers_at_measurement": 13,
        "measured_at": "2026-09-10",
        "note": "Measured as a shared implementation: imported from 13 distinct files, which is the §0.9 trigger (an artefact referenced from more than one file belongs to a canonical registry). No §40 concept row names it. What concept it implements, and therefore what a competing copy of it would look like, has not been judged — that judgement is the registration this entry is owed."
      },
      "private/runtime/estate-engine/src/governance.ts": {
        "importers_at_measurement": 12,
        "measured_at": "2026-09-10",
        "note": "Measured as a shared implementation: imported from 12 distinct files, which is the §0.9 trigger (an artefact referenced from more than one file belongs to a canonical registry). No §40 concept row names it. What concept it implements, and therefore what a competing copy of it would look like, has not been judged — that judgement is the registration this entry is owed."
      },
      "private/runtime/estate-engine/src/routes/_deferral.ts": {
        "importers_at_measurement": 11,
        "measured_at": "2026-09-10",
        "note": "Measured as a shared implementation: imported from 11 distinct files, which is the §0.9 trigger (an artefact referenced from more than one file belongs to a canonical registry). No §40 concept row names it. What concept it implements, and therefore what a competing copy of it would look like, has not been judged — that judgement is the registration this entry is owed."
      },
      "scripts/lib/chrome-fragments.mjs": {
        "importers_at_measurement": 11,
        "measured_at": "2026-09-10",
        "note": "Measured as a shared implementation: imported from 11 distinct files, which is the §0.9 trigger (an artefact referenced from more than one file belongs to a canonical registry). No §40 concept row names it. What concept it implements, and therefore what a competing copy of it would look like, has not been judged — that judgement is the registration this entry is owed."
      },
      "private/runtime/estate-engine/src/auth.ts": {
        "importers_at_measurement": 10,
        "measured_at": "2026-09-10",
        "note": "Measured as a shared implementation: imported from 10 distinct files, which is the §0.9 trigger (an artefact referenced from more than one file belongs to a canonical registry). No §40 concept row names it. What concept it implements, and therefore what a competing copy of it would look like, has not been judged — that judgement is the registration this entry is owed."
      },
      "private/runtime/estate-engine/src/index.ts": {
        "importers_at_measurement": 10,
        "measured_at": "2026-09-10",
        "note": "Measured as a shared implementation: imported from 10 distinct files, which is the §0.9 trigger (an artefact referenced from more than one file belongs to a canonical registry). No §40 concept row names it. What concept it implements, and therefore what a competing copy of it would look like, has not been judged — that judgement is the registration this entry is owed."
      },
      "scripts/liveness/lib.mjs": {
        "importers_at_measurement": 10,
        "measured_at": "2026-09-10",
        "note": "Measured as a shared implementation: imported from 10 distinct files, which is the §0.9 trigger (an artefact referenced from more than one file belongs to a canonical registry). No §40 concept row names it. What concept it implements, and therefore what a competing copy of it would look like, has not been judged — that judgement is the registration this entry is owed."
      },
      "public/app/functions/api/coa/_lib/engine.js": {
        "importers_at_measurement": 9,
        "measured_at": "2026-09-10",
        "note": "Measured as a shared implementation: imported from 9 distinct files, which is the §0.9 trigger (an artefact referenced from more than one file belongs to a canonical registry). No §40 concept row names it. What concept it implements, and therefore what a competing copy of it would look like, has not been judged — that judgement is the registration this entry is owed."
      },
      "scripts/lib/generated-marker.mjs": {
        "importers_at_measurement": 9,
        "measured_at": "2026-09-10",
        "note": "Measured as a shared implementation: imported from 9 distinct files, which is the §0.9 trigger (an artefact referenced from more than one file belongs to a canonical registry). No §40 concept row names it. What concept it implements, and therefore what a competing copy of it would look like, has not been judged — that judgement is the registration this entry is owed."
      },
      "scripts/lib/warm-contact-profile-locations.mjs": {
        "importers_at_measurement": 9,
        "measured_at": "2026-09-10",
        "note": "Measured as a shared implementation: imported from 9 distinct files, which is the §0.9 trigger (an artefact referenced from more than one file belongs to a canonical registry). No §40 concept row names it. What concept it implements, and therefore what a competing copy of it would look like, has not been judged — that judgement is the registration this entry is owed."
      },
      "private/lib/canonical-json/index.mjs": {
        "importers_at_measurement": 8,
        "measured_at": "2026-09-10",
        "note": "Measured as a shared implementation: imported from 8 distinct files, which is the §0.9 trigger (an artefact referenced from more than one file belongs to a canonical registry). No §40 concept row names it. What concept it implements, and therefore what a competing copy of it would look like, has not been judged — that judgement is the registration this entry is owed."
      },
      "scripts/govern/_pdp-lib.mjs": {
        "importers_at_measurement": 8,
        "measured_at": "2026-09-10",
        "note": "Measured as a shared implementation: imported from 8 distinct files, which is the §0.9 trigger (an artefact referenced from more than one file belongs to a canonical registry). No §40 concept row names it. What concept it implements, and therefore what a competing copy of it would look like, has not been judged — that judgement is the registration this entry is owed."
      },
      "private/lib/schema-guard/generated/kye.compliance.attestation.v1.mjs": {
        "importers_at_measurement": 7,
        "measured_at": "2026-09-10",
        "note": "Measured as a shared implementation: imported from 7 distinct files, which is the §0.9 trigger (an artefact referenced from more than one file belongs to a canonical registry). No §40 concept row names it. What concept it implements, and therefore what a competing copy of it would look like, has not been judged — that judgement is the registration this entry is owed."
      },
      "public/admin/functions/api/v1/admin/partners/_lib/partner-actions.js": {
        "importers_at_measurement": 7,
        "measured_at": "2026-09-10",
        "note": "Measured as a shared implementation: imported from 7 distinct files, which is the §0.9 trigger (an artefact referenced from more than one file belongs to a canonical registry). No §40 concept row names it. What concept it implements, and therefore what a competing copy of it would look like, has not been judged — that judgement is the registration this entry is owed."
      },
      "public/app/functions/api/_lib/meter-events.js": {
        "importers_at_measurement": 7,
        "measured_at": "2026-09-10",
        "note": "Measured as a shared implementation: imported from 7 distinct files, which is the §0.9 trigger (an artefact referenced from more than one file belongs to a canonical registry). No §40 concept row names it. What concept it implements, and therefore what a competing copy of it would look like, has not been judged — that judgement is the registration this entry is owed."
      },
      "public/app/functions/api/_lib/runtime-evaluate-engine.js": {
        "importers_at_measurement": 7,
        "measured_at": "2026-09-10",
        "note": "Measured as a shared implementation: imported from 7 distinct files, which is the §0.9 trigger (an artefact referenced from more than one file belongs to a canonical registry). No §40 concept row names it. What concept it implements, and therefore what a competing copy of it would look like, has not been judged — that judgement is the registration this entry is owed."
      },
      "public/app/functions/api/v1/onboarding/_lib.js": {
        "importers_at_measurement": 7,
        "measured_at": "2026-09-10",
        "note": "Measured as a shared implementation: imported from 7 distinct files, which is the §0.9 trigger (an artefact referenced from more than one file belongs to a canonical registry). No §40 concept row names it. What concept it implements, and therefore what a competing copy of it would look like, has not been judged — that judgement is the registration this entry is owed."
      },
      "public/mobile/authority-wallet-demo/src/data/seed.ts": {
        "importers_at_measurement": 7,
        "measured_at": "2026-09-10",
        "note": "Measured as a shared implementation: imported from 7 distinct files, which is the §0.9 trigger (an artefact referenced from more than one file belongs to a canonical registry). No §40 concept row names it. What concept it implements, and therefore what a competing copy of it would look like, has not been judged — that judgement is the registration this entry is owed."
      },
      "scripts/lib/publication-conventions.mjs": {
        "importers_at_measurement": 7,
        "measured_at": "2026-09-10",
        "note": "Measured as a shared implementation: imported from 7 distinct files, which is the §0.9 trigger (an artefact referenced from more than one file belongs to a canonical registry). No §40 concept row names it. What concept it implements, and therefore what a competing copy of it would look like, has not been judged — that judgement is the registration this entry is owed."
      },
      "scripts/lib/trademark-prose.mjs": {
        "importers_at_measurement": 7,
        "measured_at": "2026-09-10",
        "note": "Measured as a shared implementation: imported from 7 distinct files, which is the §0.9 trigger (an artefact referenced from more than one file belongs to a canonical registry). No §40 concept row names it. What concept it implements, and therefore what a competing copy of it would look like, has not been judged — that judgement is the registration this entry is owed."
      },
      "public/mobile/authority-wallet-demo/src/lib/decision.ts": {
        "importers_at_measurement": 6,
        "measured_at": "2026-09-10",
        "note": "Measured as a shared implementation: imported from 6 distinct files, which is the §0.9 trigger (an artefact referenced from more than one file belongs to a canonical registry). No §40 concept row names it. What concept it implements, and therefore what a competing copy of it would look like, has not been judged — that judgement is the registration this entry is owed."
      },
      "public/widgets/_shared/dom.js": {
        "importers_at_measurement": 6,
        "measured_at": "2026-09-10",
        "note": "Measured as a shared implementation: imported from 6 distinct files, which is the §0.9 trigger (an artefact referenced from more than one file belongs to a canonical registry). No §40 concept row names it. What concept it implements, and therefore what a competing copy of it would look like, has not been judged — that judgement is the registration this entry is owed."
      },
      "scripts/lib/custody.mjs": {
        "importers_at_measurement": 6,
        "measured_at": "2026-09-10",
        "note": "Measured as a shared implementation: imported from 6 distinct files, which is the §0.9 trigger (an artefact referenced from more than one file belongs to a canonical registry). No §40 concept row names it. What concept it implements, and therefore what a competing copy of it would look like, has not been judged — that judgement is the registration this entry is owed."
      },
      "scripts/lib/run-state.mjs": {
        "importers_at_measurement": 6,
        "measured_at": "2026-09-10",
        "note": "Measured as a shared implementation: imported from 6 distinct files, which is the §0.9 trigger (an artefact referenced from more than one file belongs to a canonical registry). No §40 concept row names it. What concept it implements, and therefore what a competing copy of it would look like, has not been judged — that judgement is the registration this entry is owed."
      },
      "private/runtime/mow-soc-collector/lib/classify.mjs": {
        "importers_at_measurement": 5,
        "measured_at": "2026-09-10",
        "note": "Measured as a shared implementation: imported from 5 distinct files, which is the §0.9 trigger (an artefact referenced from more than one file belongs to a canonical registry). No §40 concept row names it. What concept it implements, and therefore what a competing copy of it would look like, has not been judged — that judgement is the registration this entry is owed."
      },
      "private/runtime/research-gather/src/types.ts": {
        "importers_at_measurement": 5,
        "measured_at": "2026-09-10",
        "note": "Measured as a shared implementation: imported from 5 distinct files, which is the §0.9 trigger (an artefact referenced from more than one file belongs to a canonical registry). No §40 concept row names it. What concept it implements, and therefore what a competing copy of it would look like, has not been judged — that judgement is the registration this entry is owed."
      },
      "private/sdks/typescript/src/types.ts": {
        "importers_at_measurement": 5,
        "measured_at": "2026-09-10",
        "note": "Measured as a shared implementation: imported from 5 distinct files, which is the §0.9 trigger (an artefact referenced from more than one file belongs to a canonical registry). No §40 concept row names it. What concept it implements, and therefore what a competing copy of it would look like, has not been judged — that judgement is the registration this entry is owed."
      },
      "public/admin/functions/api/v1/_lib/queue-handler.js": {
        "importers_at_measurement": 5,
        "measured_at": "2026-09-10",
        "note": "Measured as a shared implementation: imported from 5 distinct files, which is the §0.9 trigger (an artefact referenced from more than one file belongs to a canonical registry). No §40 concept row names it. What concept it implements, and therefore what a competing copy of it would look like, has not been judged — that judgement is the registration this entry is owed."
      },
      "public/app/functions/api/_lib/attestation.js": {
        "importers_at_measurement": 5,
        "measured_at": "2026-09-10",
        "note": "Measured as a shared implementation: imported from 5 distinct files, which is the §0.9 trigger (an artefact referenced from more than one file belongs to a canonical registry). No §40 concept row names it. What concept it implements, and therefore what a competing copy of it would look like, has not been judged — that judgement is the registration this entry is owed."
      },
      "public/app/functions/api/_lib/dashboard-envelopes.js": {
        "importers_at_measurement": 5,
        "measured_at": "2026-09-10",
        "note": "Measured as a shared implementation: imported from 5 distinct files, which is the §0.9 trigger (an artefact referenced from more than one file belongs to a canonical registry). No §40 concept row names it. What concept it implements, and therefore what a competing copy of it would look like, has not been judged — that judgement is the registration this entry is owed."
      },
      "public/app/functions/api/v1/api-keys/_lib.js": {
        "importers_at_measurement": 5,
        "measured_at": "2026-09-10",
        "note": "Measured as a shared implementation: imported from 5 distinct files, which is the §0.9 trigger (an artefact referenced from more than one file belongs to a canonical registry). No §40 concept row names it. What concept it implements, and therefore what a competing copy of it would look like, has not been judged — that judgement is the registration this entry is owed."
      },
      "scripts/lib/astro-page-map.mjs": {
        "importers_at_measurement": 5,
        "measured_at": "2026-09-10",
        "note": "Measured as a shared implementation: imported from 5 distinct files, which is the §0.9 trigger (an artefact referenced from more than one file belongs to a canonical registry). No §40 concept row names it. What concept it implements, and therefore what a competing copy of it would look like, has not been judged — that judgement is the registration this entry is owed."
      },
      "private/lib/authority-bundle/index.mjs": {
        "importers_at_measurement": 4,
        "measured_at": "2026-09-10",
        "note": "Measured as a shared implementation: imported from 4 distinct files, which is the §0.9 trigger (an artefact referenced from more than one file belongs to a canonical registry). No §40 concept row names it. What concept it implements, and therefore what a competing copy of it would look like, has not been judged — that judgement is the registration this entry is owed."
      },
      "private/runtime/insight-authority-engine/src/governance.ts": {
        "importers_at_measurement": 4,
        "measured_at": "2026-09-10",
        "note": "Measured as a shared implementation: imported from 4 distinct files, which is the §0.9 trigger (an artefact referenced from more than one file belongs to a canonical registry). No §40 concept row names it. What concept it implements, and therefore what a competing copy of it would look like, has not been judged — that judgement is the registration this entry is owed."
      },
      "public/app/functions/api/_lib/api-key-auth.js": {
        "importers_at_measurement": 4,
        "measured_at": "2026-09-10",
        "note": "Measured as a shared implementation: imported from 4 distinct files, which is the §0.9 trigger (an artefact referenced from more than one file belongs to a canonical registry). No §40 concept row names it. What concept it implements, and therefore what a competing copy of it would look like, has not been judged — that judgement is the registration this entry is owed."
      },
      "public/oss/software-constitution/kit/lib/admission-core.mjs": {
        "importers_at_measurement": 4,
        "measured_at": "2026-09-10",
        "note": "Measured as a shared implementation: imported from 4 distinct files, which is the §0.9 trigger (an artefact referenced from more than one file belongs to a canonical registry). No §40 concept row names it. What concept it implements, and therefore what a competing copy of it would look like, has not been judged — that judgement is the registration this entry is owed."
      },
      "public/oss/software-constitution/kit/orchestration/lib.mjs": {
        "importers_at_measurement": 4,
        "measured_at": "2026-09-10",
        "note": "Measured as a shared implementation: imported from 4 distinct files, which is the §0.9 trigger (an artefact referenced from more than one file belongs to a canonical registry). No §40 concept row names it. What concept it implements, and therefore what a competing copy of it would look like, has not been judged — that judgement is the registration this entry is owed."
      },
      "scripts/git/assert-remote-admissible.mjs": {
        "importers_at_measurement": 4,
        "measured_at": "2026-09-10",
        "note": "Measured as a shared implementation: imported from 4 distinct files, which is the §0.9 trigger (an artefact referenced from more than one file belongs to a canonical registry). No §40 concept row names it. What concept it implements, and therefore what a competing copy of it would look like, has not been judged — that judgement is the registration this entry is owed."
      },
      "scripts/lib/bound-notices.mjs": {
        "importers_at_measurement": 4,
        "measured_at": "2026-09-10",
        "note": "Measured as a shared implementation: imported from 4 distinct files, which is the §0.9 trigger (an artefact referenced from more than one file belongs to a canonical registry). No §40 concept row names it. What concept it implements, and therefore what a competing copy of it would look like, has not been judged — that judgement is the registration this entry is owed."
      },
      "scripts/lib/functional-boot-core.mjs": {
        "importers_at_measurement": 4,
        "measured_at": "2026-09-10",
        "note": "Measured as a shared implementation: imported from 4 distinct files, which is the §0.9 trigger (an artefact referenced from more than one file belongs to a canonical registry). No §40 concept row names it. What concept it implements, and therefore what a competing copy of it would look like, has not been judged — that judgement is the registration this entry is owed."
      },
      "scripts/lib/governed-inventory-enum.mjs": {
        "importers_at_measurement": 4,
        "measured_at": "2026-09-10",
        "note": "Measured as a shared implementation: imported from 4 distinct files, which is the §0.9 trigger (an artefact referenced from more than one file belongs to a canonical registry). No §40 concept row names it. What concept it implements, and therefore what a competing copy of it would look like, has not been judged — that judgement is the registration this entry is owed."
      },
      "scripts/lib/media-join.mjs": {
        "importers_at_measurement": 4,
        "measured_at": "2026-09-10",
        "note": "Measured as a shared implementation: imported from 4 distinct files, which is the §0.9 trigger (an artefact referenced from more than one file belongs to a canonical registry). No §40 concept row names it. What concept it implements, and therefore what a competing copy of it would look like, has not been judged — that judgement is the registration this entry is owed."
      },
      "scripts/lib/npm-script-target.mjs": {
        "importers_at_measurement": 4,
        "measured_at": "2026-09-10",
        "note": "Measured as a shared implementation: imported from 4 distinct files, which is the §0.9 trigger (an artefact referenced from more than one file belongs to a canonical registry). No §40 concept row names it. What concept it implements, and therefore what a competing copy of it would look like, has not been judged — that judgement is the registration this entry is owed."
      },
      "scripts/lib/registry-projection.mjs": {
        "importers_at_measurement": 4,
        "measured_at": "2026-09-10",
        "note": "Measured as a shared implementation: imported from 4 distinct files, which is the §0.9 trigger (an artefact referenced from more than one file belongs to a canonical registry). No §40 concept row names it. What concept it implements, and therefore what a competing copy of it would look like, has not been judged — that judgement is the registration this entry is owed."
      },
      "scripts/lib/scoped-chain.mjs": {
        "importers_at_measurement": 4,
        "measured_at": "2026-09-10",
        "note": "Measured as a shared implementation: imported from 4 distinct files, which is the §0.9 trigger (an artefact referenced from more than one file belongs to a canonical registry). No §40 concept row names it. What concept it implements, and therefore what a competing copy of it would look like, has not been judged — that judgement is the registration this entry is owed."
      },
      "private/lib/schema-guard/generated/kye.agent.completion.v1.mjs": {
        "importers_at_measurement": 3,
        "measured_at": "2026-09-10",
        "note": "Measured as a shared implementation: imported from 3 distinct files, which is the §0.9 trigger (an artefact referenced from more than one file belongs to a canonical registry). No §40 concept row names it. What concept it implements, and therefore what a competing copy of it would look like, has not been judged — that judgement is the registration this entry is owed."
      },
      "private/lib/schema-guard/generated/kye.agent.governance.v1.mjs": {
        "importers_at_measurement": 3,
        "measured_at": "2026-09-10",
        "note": "Measured as a shared implementation: imported from 3 distinct files, which is the §0.9 trigger (an artefact referenced from more than one file belongs to a canonical registry). No §40 concept row names it. What concept it implements, and therefore what a competing copy of it would look like, has not been judged — that judgement is the registration this entry is owed."
      },
      "private/lib/schema-guard/generated/kye.billing.meter_event.v1.mjs": {
        "importers_at_measurement": 3,
        "measured_at": "2026-09-10",
        "note": "Measured as a shared implementation: imported from 3 distinct files, which is the §0.9 trigger (an artefact referenced from more than one file belongs to a canonical registry). No §40 concept row names it. What concept it implements, and therefore what a competing copy of it would look like, has not been judged — that judgement is the registration this entry is owed."
      },
      "private/lib/seal-custody/index.mjs": {
        "importers_at_measurement": 3,
        "measured_at": "2026-09-10",
        "note": "Measured as a shared implementation: imported from 3 distinct files, which is the §0.9 trigger (an artefact referenced from more than one file belongs to a canonical registry). No §40 concept row names it. What concept it implements, and therefore what a competing copy of it would look like, has not been judged — that judgement is the registration this entry is owed."
      },
      "private/lib/text-extraction/index.mjs": {
        "importers_at_measurement": 3,
        "measured_at": "2026-09-10",
        "note": "Measured as a shared implementation: imported from 3 distinct files, which is the §0.9 trigger (an artefact referenced from more than one file belongs to a canonical registry). No §40 concept row names it. What concept it implements, and therefore what a competing copy of it would look like, has not been judged — that judgement is the registration this entry is owed."
      },
      "private/runtime/insight-authority-engine/src/decision.ts": {
        "importers_at_measurement": 3,
        "measured_at": "2026-09-10",
        "note": "Measured as a shared implementation: imported from 3 distinct files, which is the §0.9 trigger (an artefact referenced from more than one file belongs to a canonical registry). No §40 concept row names it. What concept it implements, and therefore what a competing copy of it would look like, has not been judged — that judgement is the registration this entry is owed."
      },
      "private/runtime/research-gather/src/pin.ts": {
        "importers_at_measurement": 3,
        "measured_at": "2026-09-10",
        "note": "Measured as a shared implementation: imported from 3 distinct files, which is the §0.9 trigger (an artefact referenced from more than one file belongs to a canonical registry). No §40 concept row names it. What concept it implements, and therefore what a competing copy of it would look like, has not been judged — that judgement is the registration this entry is owed."
      },
      "private/sdks/typescript/src/types/v3/entities.ts": {
        "importers_at_measurement": 3,
        "measured_at": "2026-09-10",
        "note": "Measured as a shared implementation: imported from 3 distinct files, which is the §0.9 trigger (an artefact referenced from more than one file belongs to a canonical registry). No §40 concept row names it. What concept it implements, and therefore what a competing copy of it would look like, has not been judged — that judgement is the registration this entry is owed."
      },
      "private/sdks/typescript/src/types/v3/library.ts": {
        "importers_at_measurement": 3,
        "measured_at": "2026-09-10",
        "note": "Measured as a shared implementation: imported from 3 distinct files, which is the §0.9 trigger (an artefact referenced from more than one file belongs to a canonical registry). No §40 concept row names it. What concept it implements, and therefore what a competing copy of it would look like, has not been judged — that judgement is the registration this entry is owed."
      },
      "private/sdks/typescript/src/types/v3/state.ts": {
        "importers_at_measurement": 3,
        "measured_at": "2026-09-10",
        "note": "Measured as a shared implementation: imported from 3 distinct files, which is the §0.9 trigger (an artefact referenced from more than one file belongs to a canonical registry). No §40 concept row names it. What concept it implements, and therefore what a competing copy of it would look like, has not been judged — that judgement is the registration this entry is owed."
      },
      "public/mobile/authority-wallet-demo/src/components/Card.tsx": {
        "importers_at_measurement": 3,
        "measured_at": "2026-09-10",
        "note": "Measured as a shared implementation: imported from 3 distinct files, which is the §0.9 trigger (an artefact referenced from more than one file belongs to a canonical registry). No §40 concept row names it. What concept it implements, and therefore what a competing copy of it would look like, has not been judged — that judgement is the registration this entry is owed."
      },
      "scripts/compliance/_parquet-snapshot.mjs": {
        "importers_at_measurement": 3,
        "measured_at": "2026-09-10",
        "note": "Measured as a shared implementation: imported from 3 distinct files, which is the §0.9 trigger (an artefact referenced from more than one file belongs to a canonical registry). No §40 concept row names it. What concept it implements, and therefore what a competing copy of it would look like, has not been judged — that judgement is the registration this entry is owed."
      },
      "scripts/lib/authority-issuance.mjs": {
        "importers_at_measurement": 3,
        "measured_at": "2026-09-10",
        "note": "Measured as a shared implementation: imported from 3 distinct files, which is the §0.9 trigger (an artefact referenced from more than one file belongs to a canonical registry). No §40 concept row names it. What concept it implements, and therefore what a competing copy of it would look like, has not been judged — that judgement is the registration this entry is owed."
      },
      "scripts/lib/cascade-inverse.mjs": {
        "importers_at_measurement": 3,
        "measured_at": "2026-09-10",
        "note": "Measured as a shared implementation: imported from 3 distinct files, which is the §0.9 trigger (an artefact referenced from more than one file belongs to a canonical registry). No §40 concept row names it. What concept it implements, and therefore what a competing copy of it would look like, has not been judged — that judgement is the registration this entry is owed."
      },
      "scripts/lib/coordinates.mjs": {
        "importers_at_measurement": 3,
        "measured_at": "2026-09-10",
        "note": "Measured as a shared implementation: imported from 3 distinct files, which is the §0.9 trigger (an artefact referenced from more than one file belongs to a canonical registry). No §40 concept row names it. What concept it implements, and therefore what a competing copy of it would look like, has not been judged — that judgement is the registration this entry is owed."
      },
      "scripts/lib/decision-right-authority.mjs": {
        "importers_at_measurement": 3,
        "measured_at": "2026-09-10",
        "note": "Measured as a shared implementation: imported from 3 distinct files, which is the §0.9 trigger (an artefact referenced from more than one file belongs to a canonical registry). No §40 concept row names it. What concept it implements, and therefore what a competing copy of it would look like, has not been judged — that judgement is the registration this entry is owed."
      },
      "scripts/lib/foreign-matter.mjs": {
        "importers_at_measurement": 3,
        "measured_at": "2026-09-10",
        "note": "Measured as a shared implementation: imported from 3 distinct files, which is the §0.9 trigger (an artefact referenced from more than one file belongs to a canonical registry). No §40 concept row names it. What concept it implements, and therefore what a competing copy of it would look like, has not been judged — that judgement is the registration this entry is owed."
      },
      "scripts/lib/generated-paths.mjs": {
        "importers_at_measurement": 3,
        "measured_at": "2026-09-10",
        "note": "Measured as a shared implementation: imported from 3 distinct files, which is the §0.9 trigger (an artefact referenced from more than one file belongs to a canonical registry). No §40 concept row names it. What concept it implements, and therefore what a competing copy of it would look like, has not been judged — that judgement is the registration this entry is owed."
      },
      "scripts/lib/github-credential.mjs": {
        "importers_at_measurement": 3,
        "measured_at": "2026-09-10",
        "note": "Measured as a shared implementation: imported from 3 distinct files, which is the §0.9 trigger (an artefact referenced from more than one file belongs to a canonical registry). No §40 concept row names it. What concept it implements, and therefore what a competing copy of it would look like, has not been judged — that judgement is the registration this entry is owed."
      },
      "scripts/lib/id-grammar.mjs": {
        "importers_at_measurement": 3,
        "measured_at": "2026-09-10",
        "note": "Measured as a shared implementation: imported from 3 distinct files, which is the §0.9 trigger (an artefact referenced from more than one file belongs to a canonical registry). No §40 concept row names it. What concept it implements, and therefore what a competing copy of it would look like, has not been judged — that judgement is the registration this entry is owed."
      },
      "scripts/lib/propagator-classification.mjs": {
        "importers_at_measurement": 3,
        "measured_at": "2026-09-10",
        "note": "Measured as a shared implementation: imported from 3 distinct files, which is the §0.9 trigger (an artefact referenced from more than one file belongs to a canonical registry). No §40 concept row names it. What concept it implements, and therefore what a competing copy of it would look like, has not been judged — that judgement is the registration this entry is owed."
      },
      "scripts/lib/qr.mjs": {
        "importers_at_measurement": 3,
        "measured_at": "2026-09-10",
        "note": "Measured as a shared implementation: imported from 3 distinct files, which is the §0.9 trigger (an artefact referenced from more than one file belongs to a canonical registry). No §40 concept row names it. What concept it implements, and therefore what a competing copy of it would look like, has not been judged — that judgement is the registration this entry is owed."
      },
      "private/lib/css-declaration/index.mjs": {
        "importers_at_measurement": 2,
        "measured_at": "2026-09-10",
        "note": "Measured as a shared implementation: imported from 2 distinct files, which is the §0.9 trigger (an artefact referenced from more than one file belongs to a canonical registry). No §40 concept row names it. What concept it implements, and therefore what a competing copy of it would look like, has not been judged — that judgement is the registration this entry is owed."
      },
      "private/lib/schema-guard/generated/kye.agent.refusal.v1.mjs": {
        "importers_at_measurement": 2,
        "measured_at": "2026-09-10",
        "note": "Measured as a shared implementation: imported from 2 distinct files, which is the §0.9 trigger (an artefact referenced from more than one file belongs to a canonical registry). No §40 concept row names it. What concept it implements, and therefore what a competing copy of it would look like, has not been judged — that judgement is the registration this entry is owed."
      },
      "private/lib/schema-guard/generated/kye.clip_run.v1.mjs": {
        "importers_at_measurement": 2,
        "measured_at": "2026-09-10",
        "note": "Measured as a shared implementation: imported from 2 distinct files, which is the §0.9 trigger (an artefact referenced from more than one file belongs to a canonical registry). No §40 concept row names it. What concept it implements, and therefore what a competing copy of it would look like, has not been judged — that judgement is the registration this entry is owed."
      },
      "private/lib/schema-guard/generated/kye.lifecycle.compensating.v1.mjs": {
        "importers_at_measurement": 2,
        "measured_at": "2026-09-10",
        "note": "Measured as a shared implementation: imported from 2 distinct files, which is the §0.9 trigger (an artefact referenced from more than one file belongs to a canonical registry). No §40 concept row names it. What concept it implements, and therefore what a competing copy of it would look like, has not been judged — that judgement is the registration this entry is owed."
      },
      "private/lib/schema-guard/generated/kye.onboarding.workflow.v1.mjs": {
        "importers_at_measurement": 2,
        "measured_at": "2026-09-10",
        "note": "Measured as a shared implementation: imported from 2 distinct files, which is the §0.9 trigger (an artefact referenced from more than one file belongs to a canonical registry). No §40 concept row names it. What concept it implements, and therefore what a competing copy of it would look like, has not been judged — that judgement is the registration this entry is owed."
      },
      "private/lib/text-extraction/engines.mjs": {
        "importers_at_measurement": 2,
        "measured_at": "2026-09-10",
        "note": "Measured as a shared implementation: imported from 2 distinct files, which is the §0.9 trigger (an artefact referenced from more than one file belongs to a canonical registry). No §40 concept row names it. What concept it implements, and therefore what a competing copy of it would look like, has not been judged — that judgement is the registration this entry is owed."
      },
      "private/runtime/document-governance/src/clause-mapping.js": {
        "importers_at_measurement": 2,
        "measured_at": "2026-09-10",
        "note": "Measured as a shared implementation: imported from 2 distinct files, which is the §0.9 trigger (an artefact referenced from more than one file belongs to a canonical registry). No §40 concept row names it. What concept it implements, and therefore what a competing copy of it would look like, has not been judged — that judgement is the registration this entry is owed."
      },
      "private/runtime/document-governance/src/content-safety.js": {
        "importers_at_measurement": 2,
        "measured_at": "2026-09-10",
        "note": "Measured as a shared implementation: imported from 2 distinct files, which is the §0.9 trigger (an artefact referenced from more than one file belongs to a canonical registry). No §40 concept row names it. What concept it implements, and therefore what a competing copy of it would look like, has not been judged — that judgement is the registration this entry is owed."
      },
      "private/runtime/drift-to-authority/map.mjs": {
        "importers_at_measurement": 2,
        "measured_at": "2026-09-10",
        "note": "Measured as a shared implementation: imported from 2 distinct files, which is the §0.9 trigger (an artefact referenced from more than one file belongs to a canonical registry). No §40 concept row names it. What concept it implements, and therefore what a competing copy of it would look like, has not been judged — that judgement is the registration this entry is owed."
      },
      "private/runtime/governed-capture/emulate-narration.mjs": {
        "importers_at_measurement": 2,
        "measured_at": "2026-09-10",
        "note": "Measured as a shared implementation: imported from 2 distinct files, which is the §0.9 trigger (an artefact referenced from more than one file belongs to a canonical registry). No §40 concept row names it. What concept it implements, and therefore what a competing copy of it would look like, has not been judged — that judgement is the registration this entry is owed."
      },
      "private/runtime/insight-authority-engine/src/seal.ts": {
        "importers_at_measurement": 2,
        "measured_at": "2026-09-10",
        "note": "Measured as a shared implementation: imported from 2 distinct files, which is the §0.9 trigger (an artefact referenced from more than one file belongs to a canonical registry). No §40 concept row names it. What concept it implements, and therefore what a competing copy of it would look like, has not been judged — that judgement is the registration this entry is owed."
      },
      "private/runtime/research-gather/src/fallback.ts": {
        "importers_at_measurement": 2,
        "measured_at": "2026-09-10",
        "note": "Measured as a shared implementation: imported from 2 distinct files, which is the §0.9 trigger (an artefact referenced from more than one file belongs to a canonical registry). No §40 concept row names it. What concept it implements, and therefore what a competing copy of it would look like, has not been judged — that judgement is the registration this entry is owed."
      },
      "private/runtime/research-gather/src/hash.ts": {
        "importers_at_measurement": 2,
        "measured_at": "2026-09-10",
        "note": "Measured as a shared implementation: imported from 2 distinct files, which is the §0.9 trigger (an artefact referenced from more than one file belongs to a canonical registry). No §40 concept row names it. What concept it implements, and therefore what a competing copy of it would look like, has not been judged — that judgement is the registration this entry is owed."
      },
      "private/runtime/research-gather/src/index.ts": {
        "importers_at_measurement": 2,
        "measured_at": "2026-09-10",
        "note": "Measured as a shared implementation: imported from 2 distinct files, which is the §0.9 trigger (an artefact referenced from more than one file belongs to a canonical registry). No §40 concept row names it. What concept it implements, and therefore what a competing copy of it would look like, has not been judged — that judgement is the registration this entry is owed."
      },
      "private/runtime/research-gather/src/perplexity.ts": {
        "importers_at_measurement": 2,
        "measured_at": "2026-09-10",
        "note": "Measured as a shared implementation: imported from 2 distinct files, which is the §0.9 trigger (an artefact referenced from more than one file belongs to a canonical registry). No §40 concept row names it. What concept it implements, and therefore what a competing copy of it would look like, has not been judged — that judgement is the registration this entry is owed."
      },
      "private/runtime/stripe-chargeback-app/evidence-pack.mjs": {
        "importers_at_measurement": 2,
        "measured_at": "2026-09-10",
        "note": "Measured as a shared implementation: imported from 2 distinct files, which is the §0.9 trigger (an artefact referenced from more than one file belongs to a canonical registry). No §40 concept row names it. What concept it implements, and therefore what a competing copy of it would look like, has not been judged — that judgement is the registration this entry is owed."
      },
      "private/sdks/typescript/src/client-v3.ts": {
        "importers_at_measurement": 2,
        "measured_at": "2026-09-10",
        "note": "Measured as a shared implementation: imported from 2 distinct files, which is the §0.9 trigger (an artefact referenced from more than one file belongs to a canonical registry). No §40 concept row names it. What concept it implements, and therefore what a competing copy of it would look like, has not been judged — that judgement is the registration this entry is owed."
      },
      "private/sdks/typescript/src/types/v3/relationships.ts": {
        "importers_at_measurement": 2,
        "measured_at": "2026-09-10",
        "note": "Measured as a shared implementation: imported from 2 distinct files, which is the §0.9 trigger (an artefact referenced from more than one file belongs to a canonical registry). No §40 concept row names it. What concept it implements, and therefore what a competing copy of it would look like, has not been judged — that judgement is the registration this entry is owed."
      },
      "private/sdks/typescript/src/zod.ts": {
        "importers_at_measurement": 2,
        "measured_at": "2026-09-10",
        "note": "Measured as a shared implementation: imported from 2 distinct files, which is the §0.9 trigger (an artefact referenced from more than one file belongs to a canonical registry). No §40 concept row names it. What concept it implements, and therefore what a competing copy of it would look like, has not been judged — that judgement is the registration this entry is owed."
      },
      "public/app/functions/api/_lib/entity-tenant.js": {
        "importers_at_measurement": 2,
        "measured_at": "2026-09-10",
        "note": "Measured as a shared implementation: imported from 2 distinct files, which is the §0.9 trigger (an artefact referenced from more than one file belongs to a canonical registry). No §40 concept row names it. What concept it implements, and therefore what a competing copy of it would look like, has not been judged — that judgement is the registration this entry is owed."
      },
      "public/app/functions/api/_lib/evidence-source.js": {
        "importers_at_measurement": 2,
        "measured_at": "2026-09-10",
        "note": "Measured as a shared implementation: imported from 2 distinct files, which is the §0.9 trigger (an artefact referenced from more than one file belongs to a canonical registry). No §40 concept row names it. What concept it implements, and therefore what a competing copy of it would look like, has not been judged — that judgement is the registration this entry is owed."
      },
      "public/mobile/authority-wallet-demo/src/types/index.ts": {
        "importers_at_measurement": 2,
        "measured_at": "2026-09-10",
        "note": "Measured as a shared implementation: imported from 2 distinct files, which is the §0.9 trigger (an artefact referenced from more than one file belongs to a canonical registry). No §40 concept row names it. What concept it implements, and therefore what a competing copy of it would look like, has not been judged — that judgement is the registration this entry is owed."
      },
      "public/site/functions/api/_lib/entity-register.js": {
        "importers_at_measurement": 2,
        "measured_at": "2026-09-10",
        "note": "Measured as a shared implementation: imported from 2 distinct files, which is the §0.9 trigger (an artefact referenced from more than one file belongs to a canonical registry). No §40 concept row names it. What concept it implements, and therefore what a competing copy of it would look like, has not been judged — that judgement is the registration this entry is owed."
      },
      "scripts/build-enforcer-scope-paths.mjs": {
        "importers_at_measurement": 2,
        "measured_at": "2026-09-10",
        "note": "Measured as a shared implementation: imported from 2 distinct files, which is the §0.9 trigger (an artefact referenced from more than one file belongs to a canonical registry). No §40 concept row names it. What concept it implements, and therefore what a competing copy of it would look like, has not been judged — that judgement is the registration this entry is owed."
      },
      "scripts/lib/anti-stampede.mjs": {
        "importers_at_measurement": 2,
        "measured_at": "2026-09-10",
        "note": "Measured as a shared implementation: imported from 2 distinct files, which is the §0.9 trigger (an artefact referenced from more than one file belongs to a canonical registry). No §40 concept row names it. What concept it implements, and therefore what a competing copy of it would look like, has not been judged — that judgement is the registration this entry is owed."
      },
      "scripts/lib/canonical-linkify.mjs": {
        "importers_at_measurement": 2,
        "measured_at": "2026-09-10",
        "note": "Measured as a shared implementation: imported from 2 distinct files, which is the §0.9 trigger (an artefact referenced from more than one file belongs to a canonical registry). No §40 concept row names it. What concept it implements, and therefore what a competing copy of it would look like, has not been judged — that judgement is the registration this entry is owed."
      },
      "scripts/lib/canonical-schema-corpus.cjs": {
        "importers_at_measurement": 2,
        "measured_at": "2026-09-10",
        "note": "Measured as a shared implementation: imported from 2 distinct files, which is the §0.9 trigger (an artefact referenced from more than one file belongs to a canonical registry). No §40 concept row names it. What concept it implements, and therefore what a competing copy of it would look like, has not been judged — that judgement is the registration this entry is owed."
      },
      "scripts/lib/color-class-scan.mjs": {
        "importers_at_measurement": 2,
        "measured_at": "2026-09-10",
        "note": "Measured as a shared implementation: imported from 2 distinct files, which is the §0.9 trigger (an artefact referenced from more than one file belongs to a canonical registry). No §40 concept row names it. What concept it implements, and therefore what a competing copy of it would look like, has not been judged — that judgement is the registration this entry is owed."
      },
      "scripts/lib/credential-custody-authority.mjs": {
        "importers_at_measurement": 2,
        "measured_at": "2026-09-10",
        "note": "Measured as a shared implementation: imported from 2 distinct files, which is the §0.9 trigger (an artefact referenced from more than one file belongs to a canonical registry). No §40 concept row names it. What concept it implements, and therefore what a competing copy of it would look like, has not been judged — that judgement is the registration this entry is owed."
      },
      "scripts/lib/d1-schema.mjs": {
        "importers_at_measurement": 2,
        "measured_at": "2026-09-10",
        "note": "Measured as a shared implementation: imported from 2 distinct files, which is the §0.9 trigger (an artefact referenced from more than one file belongs to a canonical registry). No §40 concept row names it. What concept it implements, and therefore what a competing copy of it would look like, has not been judged — that judgement is the registration this entry is owed."
      },
      "scripts/lib/declared-audit-events.mjs": {
        "importers_at_measurement": 2,
        "measured_at": "2026-09-10",
        "note": "Measured as a shared implementation: imported from 2 distinct files, which is the §0.9 trigger (an artefact referenced from more than one file belongs to a canonical registry). No §40 concept row names it. What concept it implements, and therefore what a competing copy of it would look like, has not been judged — that judgement is the registration this entry is owed."
      },
      "scripts/lib/detect-handrolled.mjs": {
        "importers_at_measurement": 2,
        "measured_at": "2026-09-10",
        "note": "Measured as a shared implementation: imported from 2 distinct files, which is the §0.9 trigger (an artefact referenced from more than one file belongs to a canonical registry). No §40 concept row names it. What concept it implements, and therefore what a competing copy of it would look like, has not been judged — that judgement is the registration this entry is owed."
      },
      "scripts/lib/dev-plane-evidence.mjs": {
        "importers_at_measurement": 2,
        "measured_at": "2026-09-10",
        "note": "Measured as a shared implementation: imported from 2 distinct files, which is the §0.9 trigger (an artefact referenced from more than one file belongs to a canonical registry). No §40 concept row names it. What concept it implements, and therefore what a competing copy of it would look like, has not been judged — that judgement is the registration this entry is owed."
      },
      "scripts/lib/edge-purpose.mjs": {
        "importers_at_measurement": 2,
        "measured_at": "2026-09-10",
        "note": "Measured as a shared implementation: imported from 2 distinct files, which is the §0.9 trigger (an artefact referenced from more than one file belongs to a canonical registry). No §40 concept row names it. What concept it implements, and therefore what a competing copy of it would look like, has not been judged — that judgement is the registration this entry is owed."
      },
      "scripts/lib/kit-mirrors.mjs": {
        "importers_at_measurement": 2,
        "measured_at": "2026-09-10",
        "note": "Measured as a shared implementation: imported from 2 distinct files, which is the §0.9 trigger (an artefact referenced from more than one file belongs to a canonical registry). No §40 concept row names it. What concept it implements, and therefore what a competing copy of it would look like, has not been judged — that judgement is the registration this entry is owed."
      },
      "scripts/lib/kye-id-for-path.mjs": {
        "importers_at_measurement": 2,
        "measured_at": "2026-09-10",
        "note": "Measured as a shared implementation: imported from 2 distinct files, which is the §0.9 trigger (an artefact referenced from more than one file belongs to a canonical registry). No §40 concept row names it. What concept it implements, and therefore what a competing copy of it would look like, has not been judged — that judgement is the registration this entry is owed."
      },
      "scripts/lib/pages-function-corpus.mjs": {
        "importers_at_measurement": 2,
        "measured_at": "2026-09-10",
        "note": "Measured as a shared implementation: imported from 2 distinct files, which is the §0.9 trigger (an artefact referenced from more than one file belongs to a canonical registry). No §40 concept row names it. What concept it implements, and therefore what a competing copy of it would look like, has not been judged — that judgement is the registration this entry is owed."
      },
      "scripts/lib/projection-specs.mjs": {
        "importers_at_measurement": 2,
        "measured_at": "2026-09-10",
        "note": "Measured as a shared implementation: imported from 2 distinct files, which is the §0.9 trigger (an artefact referenced from more than one file belongs to a canonical registry). No §40 concept row names it. What concept it implements, and therefore what a competing copy of it would look like, has not been judged — that judgement is the registration this entry is owed."
      },
      "scripts/lib/r2-sigv4.mjs": {
        "importers_at_measurement": 2,
        "measured_at": "2026-09-10",
        "note": "Measured as a shared implementation: imported from 2 distinct files, which is the §0.9 trigger (an artefact referenced from more than one file belongs to a canonical registry). No §40 concept row names it. What concept it implements, and therefore what a competing copy of it would look like, has not been judged — that judgement is the registration this entry is owed."
      },
      "scripts/lib/right-sized-exception.mjs": {
        "importers_at_measurement": 2,
        "measured_at": "2026-09-10",
        "note": "Measured as a shared implementation: imported from 2 distinct files, which is the §0.9 trigger (an artefact referenced from more than one file belongs to a canonical registry). No §40 concept row names it. What concept it implements, and therefore what a competing copy of it would look like, has not been judged — that judgement is the registration this entry is owed."
      },
      "scripts/lib/risk-profiler-score.mjs": {
        "importers_at_measurement": 2,
        "measured_at": "2026-09-10",
        "note": "Measured as a shared implementation: imported from 2 distinct files, which is the §0.9 trigger (an artefact referenced from more than one file belongs to a canonical registry). No §40 concept row names it. What concept it implements, and therefore what a competing copy of it would look like, has not been judged — that judgement is the registration this entry is owed."
      },
      "scripts/lib/tech-dd-resolve.mjs": {
        "importers_at_measurement": 2,
        "measured_at": "2026-09-10",
        "note": "Measured as a shared implementation: imported from 2 distinct files, which is the §0.9 trigger (an artefact referenced from more than one file belongs to a canonical registry). No §40 concept row names it. What concept it implements, and therefore what a competing copy of it would look like, has not been judged — that judgement is the registration this entry is owed."
      },
      "scripts/lib/whitepaper-freshness.mjs": {
        "importers_at_measurement": 2,
        "measured_at": "2026-09-10",
        "note": "Measured as a shared implementation: imported from 2 distinct files, which is the §0.9 trigger (an artefact referenced from more than one file belongs to a canonical registry). No §40 concept row names it. What concept it implements, and therefore what a competing copy of it would look like, has not been judged — that judgement is the registration this entry is owed."
      }
    }
  },
  "gates": [
    {
      "filename": "_generate-purpose-vectors.mjs",
      "purpose": "Generates the locked Purpose Admissibility fixture set",
      "wired_in_npm_test": false
    },
    {
      "filename": "_generate-widget-descriptors.mjs",
      "purpose": "Generate the 14 KYE Partner Widget™ descriptors per",
      "wired_in_npm_test": false
    },
    {
      "filename": "_lib.mjs",
      "purpose": "Shared utilities for the rail-doc CI gates.",
      "wired_in_npm_test": false
    },
    {
      "filename": "account-opening-cdd-canonical.mjs",
      "purpose": "account-opening-cdd-canonical.mjs — §0.30 / §52 / §68 enforcer for the",
      "wired_in_npm_test": false
    },
    {
      "filename": "accounting-governance-canonical.mjs",
      "purpose": "accounting-governance-canonical.mjs — §54 §13 / §68 enforcer for the",
      "wired_in_npm_test": false
    },
    {
      "filename": "action-class-canonical.mjs",
      "purpose": "action-class-canonical.mjs — the ACTION-CLASS ROOT enforcer (§0 + §0.10 + §0.18).",
      "wired_in_npm_test": false
    },
    {
      "filename": "admin-roles-canonical.mjs",
      "purpose": "admin-roles-canonical.mjs — §0.18 enforcer for the admin role registry, and",
      "wired_in_npm_test": false
    },
    {
      "filename": "admission-control.mjs",
      "purpose": "Gate: admission-control  (constitution §0.51)",
      "wired_in_npm_test": false
    },
    {
      "filename": "adopter-directory-canonical.mjs",
      "purpose": "adopter-directory-canonical.mjs — §0.18 Canonical-Absolute enforcer for",
      "wired_in_npm_test": false
    },
    {
      "filename": "advisory-deadline-not-expired.mjs",
      "purpose": "advisory-deadline-not-expired — the §41 §8 meta-gate that prevents",
      "wired_in_npm_test": false
    },
    {
      "filename": "affiliation-disclaimer-canonical.mjs",
      "purpose": "affiliation-disclaimer-canonical.mjs — §0 honesty enforcer.",
      "wired_in_npm_test": false
    },
    {
      "filename": "agent-commerce-canonical.mjs",
      "purpose": "agent-commerce-canonical.mjs — §0.18 enforcer for the Agent-Commerce Interop",
      "wired_in_npm_test": false
    },
    {
      "filename": "agent-dev-kit-alive.mjs",
      "purpose": "agent-dev-kit-alive.mjs — §32 (KYE Agent Dev Kit™) enforcer.",
      "wired_in_npm_test": false
    },
    {
      "filename": "agent-envelope-vs-scope.mjs",
      "purpose": "agent-envelope-vs-scope.mjs — §52 Phase 2 post-flight reconciliation gate.",
      "wired_in_npm_test": false
    },
    {
      "filename": "agent-native-principal-canonical.mjs",
      "purpose": "agent-native-principal-canonical.mjs — §0.30 (Agents as First-Class",
      "wired_in_npm_test": false
    },
    {
      "filename": "agent-no-decision-emission.mjs",
      "purpose": "Gate: agent-no-decision-emission",
      "wired_in_npm_test": false
    },
    {
      "filename": "agent-readable-canonical.mjs",
      "purpose": "agent-readable-canonical.mjs — constitution §43 §4d Agent-Readability.",
      "wired_in_npm_test": false
    },
    {
      "filename": "agent-wiring-canonical.mjs",
      "purpose": "agent-wiring-canonical.mjs — enforce that every governed agent is DEEP-WIRED",
      "wired_in_npm_test": false
    },
    {
      "filename": "agentic-delivery-pack-canonical.mjs",
      "purpose": "agentic-delivery-pack-canonical.mjs — §0.18 enforcer for the KYE Certified",
      "wired_in_npm_test": false
    },
    {
      "filename": "agentic-governance-lifecycle-canonical.mjs",
      "purpose": "agentic-governance-lifecycle-canonical.mjs — §0.9/§0.18 Canonical-Absolute",
      "wired_in_npm_test": false
    },
    {
      "filename": "agentic-lending-product-canonical.mjs",
      "purpose": "agentic-lending-product-canonical.mjs — §49 §9 Sector Specialisation +",
      "wired_in_npm_test": false
    },
    {
      "filename": "ai-adoption-navigator-canonical.mjs",
      "purpose": "ai-adoption-navigator-canonical.mjs — KYE AI Adoption Navigator™ enforcer.",
      "wired_in_npm_test": false
    },
    {
      "filename": "ai-solutions-framework-authority-canonical.mjs",
      "purpose": "ai-solutions-framework-authority-canonical.mjs — §54 §13 / §68 / §70 enforcer for",
      "wired_in_npm_test": false
    },
    {
      "filename": "air-gap-ability.mjs",
      "purpose": "Gate: air-gap-ability — Constitution §0.47 Air-Gapped Governance Lifecycle.",
      "wired_in_npm_test": false
    },
    {
      "filename": "aml-financial-crimes-canonical.mjs",
      "purpose": "aml-financial-crimes-canonical.mjs — §54 §13 / §68 enforcer for the",
      "wired_in_npm_test": false
    },
    {
      "filename": "analytics-audit-emitted.mjs",
      "purpose": "Gate: analytics-audit-emitted",
      "wired_in_npm_test": false
    },
    {
      "filename": "analytics-determinism.mjs",
      "purpose": "Gate: analytics-determinism",
      "wired_in_npm_test": false
    },
    {
      "filename": "analytics-schema-validate.mjs",
      "purpose": "Gate: analytics-schema-validate",
      "wired_in_npm_test": false
    },
    {
      "filename": "analytics-tenant-isolation.mjs",
      "purpose": "Gate: analytics-tenant-isolation",
      "wired_in_npm_test": false
    },
    {
      "filename": "anti-stampede-canonical.mjs",
      "purpose": "Gate: anti-stampede-canonical (§13 §14 + §0.9)",
      "wired_in_npm_test": false
    },
    {
      "filename": "api-annotations-canonical.mjs",
      "purpose": "api-annotations-canonical.mjs — §0.18 Canonical-Absolute enforcer for the api-annotations registry.",
      "wired_in_npm_test": false
    },
    {
      "filename": "api-explorers-canonical.mjs",
      "purpose": "api-explorers-canonical.mjs — §0.18 Canonical-Absolute enforcer for the api-explorers registry.",
      "wired_in_npm_test": false
    },
    {
      "filename": "apply-cta-sku-canonical.mjs",
      "purpose": "Gate: apply-cta-sku-canonical",
      "wired_in_npm_test": false
    },
    {
      "filename": "artefact-size-canonical.mjs",
      "purpose": "ARTEFACT SIZE IS A GOVERNED PROPERTY (§0.20 · §0.43 · §0.50).",
      "wired_in_npm_test": false
    },
    {
      "filename": "assurance-plane-canonical.mjs",
      "purpose": "Gate: assurance-plane-canonical — Constitution §0.44 Unified Assurance Plane.",
      "wired_in_npm_test": false
    },
    {
      "filename": "attribution-canonical.mjs",
      "purpose": "attribution-canonical — every artefact resolves to exactly ONE actor, by ONE",
      "wired_in_npm_test": false
    },
    {
      "filename": "audience-landing-coverage.mjs",
      "purpose": "Gate: audience-landing-coverage",
      "wired_in_npm_test": false
    },
    {
      "filename": "audit-chain-emission-coverage.mjs",
      "purpose": "Gate: audit-chain-emission-coverage",
      "wired_in_npm_test": false
    },
    {
      "filename": "audit-emission-canonical.mjs",
      "purpose": "audit-emission-canonical — the audit emission path is canonical end to end.",
      "wired_in_npm_test": false
    },
    {
      "filename": "audit-pilot-consent-recorded.mjs",
      "purpose": "Gate: audit-pilot-consent-recorded",
      "wired_in_npm_test": false
    },
    {
      "filename": "audit-retention-policy.mjs",
      "purpose": "Gate: audit-retention-policy",
      "wired_in_npm_test": false
    },
    {
      "filename": "audit-worm-enforced.mjs",
      "purpose": "Gate: audit-worm-enforced",
      "wired_in_npm_test": false
    },
    {
      "filename": "authority-as-code-canonical.mjs",
      "purpose": "authority-as-code-canonical.mjs — §60 (KYE Authority-as-Code™ + Authority",
      "wired_in_npm_test": false
    },
    {
      "filename": "authority-bundle-standalone-canonical.mjs",
      "purpose": "Gate: authority-bundle-standalone-canonical",
      "wired_in_npm_test": false
    },
    {
      "filename": "authority-gap-detector-deterministic.mjs",
      "purpose": "Gate: authority-gap-detector-deterministic",
      "wired_in_npm_test": false
    },
    {
      "filename": "authority-gap-traceable.mjs",
      "purpose": "Gate: authority-gap-traceable",
      "wired_in_npm_test": false
    },
    {
      "filename": "authority-lines-canonical.mjs",
      "purpose": "Gate: authority-lines-canonical (§50 + §0 + §0.3 + §0.9 + §0.12)",
      "wired_in_npm_test": false
    },
    {
      "filename": "authority-risk-signal-canonical.mjs",
      "purpose": "authority-risk-signal-canonical.mjs — KYE Authority Risk Signal™ enforcer",
      "wired_in_npm_test": false
    },
    {
      "filename": "automation-registry-canonical.mjs",
      "purpose": "automation-registry-canonical.mjs",
      "wired_in_npm_test": false
    },
    {
      "filename": "availability-evidence-canonical.mjs",
      "purpose": "availability-evidence-canonical.mjs — engine unavailability is EVIDENCE,",
      "wired_in_npm_test": false
    },
    {
      "filename": "badges-fresh.mjs",
      "purpose": "Gate: badges-fresh — Constitution §0.20 + §0.31 + §17/§54.",
      "wired_in_npm_test": false
    },
    {
      "filename": "baked-count-drift.mjs",
      "purpose": "Gate: baked-count-drift",
      "wired_in_npm_test": false
    },
    {
      "filename": "billing-dunning-canonical.mjs",
      "purpose": "billing-dunning-canonical.mjs — §0.30 / §52 / §68 enforcer for the",
      "wired_in_npm_test": false
    },
    {
      "filename": "billing-schema-validate.mjs",
      "purpose": "Gate: billing-schema-validate",
      "wired_in_npm_test": false
    },
    {
      "filename": "bio-chem-governance-canonical.mjs",
      "purpose": "bio-chem-governance-canonical.mjs — §54 §13 / §68 enforcer for the",
      "wired_in_npm_test": false
    },
    {
      "filename": "biopharma-pv-canonical.mjs",
      "purpose": "biopharma-pv-canonical.mjs — §0.30 / §52 / §68 enforcer for the",
      "wired_in_npm_test": false
    },
    {
      "filename": "boundary-governance-canonical.mjs",
      "purpose": "Gate: boundary-governance-canonical — Constitution §0.39 (Boundary-Agnostic Governance).",
      "wired_in_npm_test": false
    },
    {
      "filename": "bps-calculation-determinism.mjs",
      "purpose": "Gate: bps-calculation-determinism",
      "wired_in_npm_test": false
    },
    {
      "filename": "builder-pep-canonical.mjs",
      "purpose": "Gate: builder-pep-canonical  (constitution §0 Continuous Runtime Self-Governance",
      "wired_in_npm_test": false
    },
    {
      "filename": "bundle-round-trip.mjs",
      "purpose": "Gate: bundle-round-trip",
      "wired_in_npm_test": false
    },
    {
      "filename": "business-flows-canonical.mjs",
      "purpose": "business-flows-canonical.mjs — §0.18 Canonical-Absolute enforcer for the business-flows registry.",
      "wired_in_npm_test": false
    },
    {
      "filename": "buyer-terminology-canonical.mjs",
      "purpose": "Gate: buyer-terminology-canonical (§0.9 + §11 CONTENT)",
      "wired_in_npm_test": false
    },
    {
      "filename": "canada-health-product-canonical.mjs",
      "purpose": "canada-health-product-canonical.mjs — §49 §9 Sector Specialisation",
      "wired_in_npm_test": false
    },
    {
      "filename": "canonical-counts-fresh.mjs",
      "purpose": "Gate: canonical-counts-fresh — Constitution §0 + §0.14.3.",
      "wired_in_npm_test": false
    },
    {
      "filename": "canonical-first.mjs",
      "purpose": "Gate: canonical-first",
      "wired_in_npm_test": false
    },
    {
      "filename": "canonical-gap-audit.mjs",
      "purpose": "Gate: canonical-gap-audit (advisory)",
      "wired_in_npm_test": false
    },
    {
      "filename": "canonical-triple-coverage.mjs",
      "purpose": "Gate: canonical-triple-coverage (§47)",
      "wired_in_npm_test": false
    },
    {
      "filename": "capability-kit-canonical.mjs",
      "purpose": "capability-kit-canonical.mjs — §0.18 enforcer for the KYE Capability Kit™",
      "wired_in_npm_test": false
    },
    {
      "filename": "cascade-coverage.mjs",
      "purpose": "cascade-coverage.mjs — §53 (Cohesion Cascade v1.1) universal enforcer.",
      "wired_in_npm_test": false
    },
    {
      "filename": "cascade-graph-baseline-decay.mjs",
      "purpose": "cascade-graph-baseline-decay.mjs — §53 §12 (Pre-§53 baseline audit",
      "wired_in_npm_test": false
    },
    {
      "filename": "category-ownership-canonical.mjs",
      "purpose": "Gate: category-ownership-canonical  (constitution §0.33)",
      "wired_in_npm_test": false
    },
    {
      "filename": "certificate-rail-canonical.mjs",
      "purpose": "certificate-rail-canonical.mjs — constitution §66 Certificates Rail.",
      "wired_in_npm_test": false
    },
    {
      "filename": "cf-resource-governance-coverage.mjs",
      "purpose": "Gate: cf-resource-governance-coverage — §0.36 Universal Entity Governance +",
      "wired_in_npm_test": false
    },
    {
      "filename": "chain-of-authority-insight-canonical.mjs",
      "purpose": "chain-of-authority-insight-canonical.mjs — §54 §13 / §68 / §70 enforcer for the",
      "wired_in_npm_test": false
    },
    {
      "filename": "channels-canonical.mjs",
      "purpose": "channels-canonical.mjs — §0.18 Canonical-Absolute enforcer for the channels registry.",
      "wired_in_npm_test": false
    },
    {
      "filename": "chargeback-evidence-canonical.mjs",
      "purpose": "chargeback-evidence-canonical.mjs — §54 §13 / §68 / §70 enforcer for",
      "wired_in_npm_test": false
    },
    {
      "filename": "chatbot-authority-canonical.mjs",
      "purpose": "chatbot-authority-canonical.mjs — §54 §13 / §68 / §70 enforcer for the",
      "wired_in_npm_test": false
    },
    {
      "filename": "check-canonical-references.mjs",
      "purpose": "scripts/gates/check-canonical-references.mjs",
      "wired_in_npm_test": false
    },
    {
      "filename": "ci-npm-resilience-canonical.mjs",
      "purpose": "ci-npm-resilience-canonical.mjs — every network-fragile CI install is",
      "wired_in_npm_test": false
    },
    {
      "filename": "claims-decision-canonical.mjs",
      "purpose": "claims-decision-canonical.mjs — §0.30 / §52 / §68 enforcer for the",
      "wired_in_npm_test": false
    },
    {
      "filename": "class-declaration-canonical.mjs",
      "purpose": "class-declaration-canonical — §0.9 / §0.55, the CLASS-MEANING case.",
      "wired_in_npm_test": false
    },
    {
      "filename": "class-must-resolve.mjs",
      "purpose": "class-must-resolve — §0.56 / §0.20, the CSS-layer case.",
      "wired_in_npm_test": false
    },
    {
      "filename": "cli-manifest-canonical.mjs",
      "purpose": "cli-manifest-canonical.mjs — §15 CLI Manifest enforcer.",
      "wired_in_npm_test": false
    },
    {
      "filename": "clinical-ai-product-canonical.mjs",
      "purpose": "clinical-ai-product-canonical.mjs — §54 §13 / §68 enforcer for the",
      "wired_in_npm_test": false
    },
    {
      "filename": "clinical-authorization-canonical.mjs",
      "purpose": "clinical-authorization-canonical.mjs — §0.30 / §52 / §68 enforcer for the",
      "wired_in_npm_test": false
    },
    {
      "filename": "clinical-trial-canonical.mjs",
      "purpose": "clinical-trial-canonical.mjs — §0.30 / §52 / §68 enforcer for the",
      "wired_in_npm_test": false
    },
    {
      "filename": "clip-pipeline-canonical.mjs",
      "purpose": "clip-pipeline-canonical — the §0.18 quintuple gate for the kye-clip",
      "wired_in_npm_test": false
    },
    {
      "filename": "clip-registry-canonical.mjs",
      "purpose": "clip-registry-canonical.mjs — a public clip may not say more than its source does.",
      "wired_in_npm_test": false
    },
    {
      "filename": "coherent-integration-mandate.mjs",
      "purpose": "coherent-integration-mandate — Constitution §0.6 enforcement.",
      "wired_in_npm_test": false
    },
    {
      "filename": "color-canonical.mjs",
      "purpose": "Gate: color-canonical (§0.9 Universal Canonicalisation + §43 Machine-Readable)",
      "wired_in_npm_test": false
    },
    {
      "filename": "comms-manifest-alive.mjs",
      "purpose": "comms-manifest-alive — Constitution §38 enforcement.",
      "wired_in_npm_test": false
    },
    {
      "filename": "compliance-attestation.mjs",
      "purpose": "Gate: compliance-attestation",
      "wired_in_npm_test": false
    },
    {
      "filename": "component-contrast-dark.mjs",
      "purpose": "Gate: component-contrast-dark (surface-aware)",
      "wired_in_npm_test": false
    },
    {
      "filename": "component-graph-taxonomy.mjs",
      "purpose": "Gate: component-graph-taxonomy (§74)",
      "wired_in_npm_test": false
    },
    {
      "filename": "component-manifest-canonical.mjs",
      "purpose": "component-manifest-canonical.mjs — §0.18 Canonical-Absolute enforcer for",
      "wired_in_npm_test": false
    },
    {
      "filename": "conformance-levels-canonical.mjs",
      "purpose": "conformance-levels-canonical.mjs — §15 §7.9 Conformance Maturity Ladder (L1–L5) enforcer.",
      "wired_in_npm_test": false
    },
    {
      "filename": "conformance-pack-signed.mjs",
      "purpose": "Gate: conformance-pack-signed",
      "wired_in_npm_test": false
    },
    {
      "filename": "connection-diagrams-canonical.mjs",
      "purpose": "connection-diagrams-canonical.mjs — §0.18 Canonical-Absolute enforcer for the connection-diagrams registry.",
      "wired_in_npm_test": false
    },
    {
      "filename": "consequential-actor-canonical.mjs",
      "purpose": "consequential-actor-canonical.mjs — KYE Consequential Actor Framework™ enforcer.",
      "wired_in_npm_test": false
    },
    {
      "filename": "content-canonical-fresh.mjs",
      "purpose": "content-canonical-fresh.mjs — §0.12 Content Canonicalisation enforcer.",
      "wired_in_npm_test": false
    },
    {
      "filename": "content-graph-coverage.mjs",
      "purpose": "content-graph-coverage.mjs — §50 (Canonical Content Graph + Derived",
      "wired_in_npm_test": false
    },
    {
      "filename": "control-geometry-canonical.mjs",
      "purpose": "control-geometry-canonical — a colour variant owns COLOUR, never geometry.",
      "wired_in_npm_test": false
    },
    {
      "filename": "control-plane-canonical.mjs",
      "purpose": "control-plane-canonical.mjs — constitution §69 KYE Control-Plane MCP™.",
      "wired_in_npm_test": false
    },
    {
      "filename": "control-plane-interop-canonical.mjs",
      "purpose": "control-plane-interop-canonical.mjs — constitution §73 KYE Control-Plane Interoperability Profile™.",
      "wired_in_npm_test": false
    },
    {
      "filename": "control-policy-authority-canonical.mjs",
      "purpose": "control-policy-authority-canonical.mjs — §0.30 / §52 / §68 enforcer for the",
      "wired_in_npm_test": false
    },
    {
      "filename": "converted-page-source-integrity.mjs",
      "purpose": "Gate: converted-page-source-integrity  (§0.43 no-blind-enforcers · §0.18 · §0.46)",
      "wired_in_npm_test": false
    },
    {
      "filename": "coordinate-connectivity.mjs",
      "purpose": "Gate: coordinate-connectivity  (constitution §0.52)",
      "wired_in_npm_test": false
    },
    {
      "filename": "corroboration-canonical.mjs",
      "purpose": "corroboration-canonical.mjs — §0.18 + §39 enforcer for the external",
      "wired_in_npm_test": false
    },
    {
      "filename": "cost-to-serve-canonical.mjs",
      "purpose": "cost-to-serve-canonical.mjs — §0.18 enforcer for the KYE Cost-to-Serve /",
      "wired_in_npm_test": false
    },
    {
      "filename": "coverage-enforcement-proof.mjs",
      "purpose": "Gate: coverage-enforcement-proof",
      "wired_in_npm_test": false
    },
    {
      "filename": "coverage-maturity-canonical.mjs",
      "purpose": "Gate: coverage-maturity-canonical",
      "wired_in_npm_test": false
    },
    {
      "filename": "credit-card-authorization-canonical.mjs",
      "purpose": "credit-card-authorization-canonical.mjs — §0.30 / §52 / §68 enforcer for the",
      "wired_in_npm_test": false
    },
    {
      "filename": "cross-jurisdiction-handoff-canonical.mjs",
      "purpose": "cross-jurisdiction-handoff-canonical.mjs — §57 enforcer.",
      "wired_in_npm_test": false
    },
    {
      "filename": "crypto-authority-canonical.mjs",
      "purpose": "crypto-authority-canonical.mjs — KYE Cryptographic Authority Pack™ enforcer.",
      "wired_in_npm_test": false
    },
    {
      "filename": "css-declaration-grammar-fresh.mjs",
      "purpose": "css-declaration-grammar-fresh — the VERIFIER half of the derived CSS",
      "wired_in_npm_test": false
    },
    {
      "filename": "customer-journey-canonical.mjs",
      "purpose": "customer-journey-canonical.mjs — §0.18 Canonical-Absolute enforcer for the",
      "wired_in_npm_test": false
    },
    {
      "filename": "cut-contract.mjs",
      "purpose": "cut-contract.mjs — the FINISHED CUT is verified, not just its inputs.",
      "wired_in_npm_test": false
    },
    {
      "filename": "cyber-resilience-authority-canonical.mjs",
      "purpose": "cyber-resilience-authority-canonical.mjs — §54 §13 / §68 / §70 enforcer for the",
      "wired_in_npm_test": false
    },
    {
      "filename": "cypress-canonical.mjs",
      "purpose": "cypress-canonical.mjs — §0 lock: ONE edition per locked design asset.",
      "wired_in_npm_test": false
    },
    {
      "filename": "d1-schema-apply.mjs",
      "purpose": "d1-schema-apply.mjs — validate the REAL Cloudflare D1 (SQLite) schema and",
      "wired_in_npm_test": false
    },
    {
      "filename": "dashboard-tenant-isolation.mjs",
      "purpose": "Gate: dashboard-tenant-isolation",
      "wired_in_npm_test": false
    },
    {
      "filename": "dashboards-canonical.mjs",
      "purpose": "dashboards-canonical.mjs — §0.18 Canonical-Absolute enforcer for the dashboards registry.",
      "wired_in_npm_test": false
    },
    {
      "filename": "data-residency-canonical.mjs",
      "purpose": "Gate: data-residency-canonical",
      "wired_in_npm_test": false
    },
    {
      "filename": "database-tenancy-canonical.mjs",
      "purpose": "database-tenancy-canonical — every CREATE TABLE in the D1 migration tree",
      "wired_in_npm_test": false
    },
    {
      "filename": "decision-pack-bijection.mjs",
      "purpose": "decision-pack-bijection — every decision writer produces a SEALABLE row.",
      "wired_in_npm_test": false
    },
    {
      "filename": "decision-rights-canonical.mjs",
      "purpose": "decision-rights-canonical.mjs — make the decision-STAGE axis of authority",
      "wired_in_npm_test": false
    },
    {
      "filename": "decisions-evidence-pack-canonical.mjs",
      "purpose": "decisions-evidence-pack-canonical — EVERY DECISION CARRIES ITS EVIDENCE PACK,",
      "wired_in_npm_test": false
    },
    {
      "filename": "deeplink-canonical.mjs",
      "purpose": "scripts/gates/deeplink-canonical.mjs",
      "wired_in_npm_test": false
    },
    {
      "filename": "deeplink-internal-anchors.mjs",
      "purpose": "scripts/gates/deeplink-internal-anchors.mjs",
      "wired_in_npm_test": false
    },
    {
      "filename": "delegated-agent-binding-coverage.mjs",
      "purpose": "delegated-agent-binding-coverage.mjs — §52 (Constitutional Binding of",
      "wired_in_npm_test": false
    },
    {
      "filename": "delegated-auditability-schema-validate.mjs",
      "purpose": "Gate: delegated-auditability-schema-validate",
      "wired_in_npm_test": false
    },
    {
      "filename": "demo-scenario-canonical.mjs",
      "purpose": "demo-scenario-canonical.mjs — §0.18 Canonical-Absolute enforcer for the KYE",
      "wired_in_npm_test": false
    },
    {
      "filename": "demonstrated-effect.mjs",
      "purpose": "demonstrated-effect.mjs — §0.50 enforcer: a mechanism is real only when its",
      "wired_in_npm_test": false
    },
    {
      "filename": "dependency-canonical.mjs",
      "purpose": "dependency-canonical.mjs — ONE declared version per dependency, estate-wide,",
      "wired_in_npm_test": false
    },
    {
      "filename": "deploy-toolchain-pinned.mjs",
      "purpose": "deploy-toolchain-pinned.mjs — the toolchain that ships production cannot",
      "wired_in_npm_test": false
    },
    {
      "filename": "deployed-estate-canonical.mjs",
      "purpose": "Gate: deployed-estate-canonical (§34 + §0.42 + §0.47)",
      "wired_in_npm_test": false
    },
    {
      "filename": "deployed-import-graph.mjs",
      "purpose": "deployed-import-graph.mjs — every module a deployed Worker imports must",
      "wired_in_npm_test": false
    },
    {
      "filename": "derived-search-index-shape.mjs",
      "purpose": "Gate: derived-search-index-shape",
      "wired_in_npm_test": false
    },
    {
      "filename": "design-partner-program-canonical.mjs",
      "purpose": "design-partner-program-canonical.mjs — §0.18 enforcer for the KYE Design",
      "wired_in_npm_test": false
    },
    {
      "filename": "design-tokens-coherent.mjs",
      "purpose": "Gate: design-tokens-coherent",
      "wired_in_npm_test": false
    },
    {
      "filename": "dev-plane-event-governance.mjs",
      "purpose": "dev-plane-event-governance — Mode 2 gate: every EPHEMERAL dev-plane EVENT emits",
      "wired_in_npm_test": false
    },
    {
      "filename": "devplane-t0-enforced.mjs",
      "purpose": "devplane-t0-enforced.mjs — the dev-plane t=0 enforcement gate (§0.37 + §0.3 +",
      "wired_in_npm_test": false
    },
    {
      "filename": "directory-audit-emitted.mjs",
      "purpose": "Gate: directory-audit-emitted",
      "wired_in_npm_test": false
    },
    {
      "filename": "directory-determinism.mjs",
      "purpose": "Gate: directory-determinism",
      "wired_in_npm_test": false
    },
    {
      "filename": "directory-schema-validate.mjs",
      "purpose": "async function main() {",
      "wired_in_npm_test": false
    },
    {
      "filename": "directory-tenant-isolation.mjs",
      "purpose": "Gate: directory-tenant-isolation",
      "wired_in_npm_test": false
    },
    {
      "filename": "disputes-canonical.mjs",
      "purpose": "disputes-canonical.mjs — §0.18 Canonical-Absolute enforcer for the disputes registry.",
      "wired_in_npm_test": false
    },
    {
      "filename": "doc-claims-resolve.mjs",
      "purpose": "doc-claims-resolve.mjs — a documented number MUST resolve to its canonical source.",
      "wired_in_npm_test": false
    },
    {
      "filename": "document-governance-canonical.mjs",
      "purpose": "document-governance-canonical.mjs — §31 / §30 / §70 enforcer for the",
      "wired_in_npm_test": false
    },
    {
      "filename": "document-intelligence-rail-canonical.mjs",
      "purpose": "document-intelligence-rail-canonical.mjs — §71 (KYE Document Intelligence Rail™) enforcer.",
      "wired_in_npm_test": false
    },
    {
      "filename": "drift-to-authority-canonical.mjs",
      "purpose": "drift-to-authority-canonical — the §52 drift→authority connector enforcer.",
      "wired_in_npm_test": false
    },
    {
      "filename": "drug-discovery-canonical.mjs",
      "purpose": "drug-discovery-canonical.mjs — §0.30 / §52 / §68 enforcer for the",
      "wired_in_npm_test": false
    },
    {
      "filename": "dual-channel-admin.mjs",
      "purpose": "Gate: dual-channel-admin",
      "wired_in_npm_test": false
    },
    {
      "filename": "edge-binding-coverage.mjs",
      "purpose": "Gate: edge-binding-coverage — every edge binding is declared AND used.",
      "wired_in_npm_test": false
    },
    {
      "filename": "edge-cold-start-budget.mjs",
      "purpose": "Gate: edge-cold-start-budget",
      "wired_in_npm_test": false
    },
    {
      "filename": "edge-direction-canonical.mjs",
      "purpose": "edge-direction-canonical — an edge's DIRECTION is the contract's answer, and",
      "wired_in_npm_test": false
    },
    {
      "filename": "edge-latency-budget.mjs",
      "purpose": "Gate: edge-latency-budget",
      "wired_in_npm_test": false
    },
    {
      "filename": "edge-wrangler-validate.mjs",
      "purpose": "Gate: edge-wrangler-validate",
      "wired_in_npm_test": false
    },
    {
      "filename": "email-addresses-canonical.mjs",
      "purpose": "email-addresses-canonical.mjs — §0.18 Canonical-Absolute enforcer for the email-addresses registry.",
      "wired_in_npm_test": false
    },
    {
      "filename": "email-delivery-canonical.mjs",
      "purpose": "email-delivery-canonical.mjs — Constitution §38 enforcement for the",
      "wired_in_npm_test": false
    },
    {
      "filename": "email-legal-compliance.mjs",
      "purpose": "email-legal-compliance.mjs — every outbound email carries its legal bits.",
      "wired_in_npm_test": false
    },
    {
      "filename": "email-signatures-canonical.mjs",
      "purpose": "email-signatures-canonical.mjs — §0.18 Canonical-Absolute enforcer for the email-signatures registry.",
      "wired_in_npm_test": false
    },
    {
      "filename": "engagement-coverage.mjs",
      "purpose": "engagement-coverage — does the page DO anything for the reader who arrived?",
      "wired_in_npm_test": false
    },
    {
      "filename": "engagement-rail-canonical.mjs",
      "purpose": "engagement-rail-canonical.mjs — §49 (Universal Engagement Rail) enforcer.",
      "wired_in_npm_test": false
    },
    {
      "filename": "engine-determinism-test.mjs",
      "purpose": "Gate: engine-determinism-test",
      "wired_in_npm_test": false
    },
    {
      "filename": "engine-replay-equiv.mjs",
      "purpose": "Gate: engine-replay-equiv",
      "wired_in_npm_test": false
    },
    {
      "filename": "engine-workflow-endpoint-canonical.mjs",
      "purpose": "Gate: engine-workflow-endpoint-canonical",
      "wired_in_npm_test": false
    },
    {
      "filename": "entitlement-trace.mjs",
      "purpose": "Gate: entitlement-trace",
      "wired_in_npm_test": false
    },
    {
      "filename": "entity-id-canonical.mjs",
      "purpose": "Gate: entity-id-canonical  (constitution §0.30 / §0.34 — the KYE-ID backbone)",
      "wired_in_npm_test": false
    },
    {
      "filename": "entity-lifecycle-closed.mjs",
      "purpose": "entity-lifecycle-closed — an entity is governed only if its whole chain closes.",
      "wired_in_npm_test": false
    },
    {
      "filename": "entity-register-canonical.mjs",
      "purpose": "Gate: entity-register-canonical",
      "wired_in_npm_test": false
    },
    {
      "filename": "entity-type-registry-canonical.mjs",
      "purpose": "Gate: entity-type-registry-canonical (§0.36/§0.37 — every entity TYPE is a",
      "wired_in_npm_test": false
    },
    {
      "filename": "envelope-canonical.mjs",
      "purpose": "Gate: envelope-canonical — constitution/00-INDEX.md §0.66.",
      "wired_in_npm_test": false
    },
    {
      "filename": "error-envelope-canonical.mjs",
      "purpose": "Gate: error-envelope-canonical",
      "wired_in_npm_test": false
    },
    {
      "filename": "estate-product-canonical.mjs",
      "purpose": "estate-product-canonical.mjs — Wave-AE Phase 0 (KYE Estate Planning",
      "wired_in_npm_test": false
    },
    {
      "filename": "event-native-coverage.mjs",
      "purpose": "event-native-coverage.mjs — §0.15 Event-Native Architecture (Events-First) enforcer.",
      "wired_in_npm_test": false
    },
    {
      "filename": "event-registry-canonical.mjs",
      "purpose": "event-registry-canonical — SSOT enforcement for the event family.",
      "wired_in_npm_test": false
    },
    {
      "filename": "evidence-pack-standalone-canonical.mjs",
      "purpose": "Gate: evidence-pack-standalone-canonical",
      "wired_in_npm_test": false
    },
    {
      "filename": "evidence-persistence-canonical.mjs",
      "purpose": "evidence-persistence-canonical — emitted evidence MUST be retained.",
      "wired_in_npm_test": false
    },
    {
      "filename": "evidence-portability-canonical.mjs",
      "purpose": "Gate: evidence-portability-canonical",
      "wired_in_npm_test": false
    },
    {
      "filename": "executable-coverage.mjs",
      "purpose": "executable-coverage — the UNIVERSAL executable-governance invariant (CEO",
      "wired_in_npm_test": false
    },
    {
      "filename": "execution-layers-canonical.mjs",
      "purpose": "execution-layers-canonical.mjs — §55 (Execution Layers Architecture) enforcer.",
      "wired_in_npm_test": false
    },
    {
      "filename": "f37-f38-f39-boundary.mjs",
      "purpose": "scripts/gates/f37-f38-f39-boundary.mjs",
      "wired_in_npm_test": false
    },
    {
      "filename": "feature-flag-canonical.mjs",
      "purpose": "feature-flag-canonical — §0.9 (Universal Canonicalisation) enforcer",
      "wired_in_npm_test": false
    },
    {
      "filename": "filesystem-tree-canonical.mjs",
      "purpose": "filesystem-tree-canonical.mjs — §0.18 Canonical-Absolute enforcer for the filesystem-tree registry.",
      "wired_in_npm_test": false
    },
    {
      "filename": "financial-ai-product-canonical.mjs",
      "purpose": "financial-ai-product-canonical.mjs — §49 §9 Sector Specialisation enforcer",
      "wired_in_npm_test": false
    },
    {
      "filename": "first-doctrine-canonical.mjs",
      "purpose": "Gate: first-doctrine-canonical — Constitution §0.45 The \"-First\" Doctrine.",
      "wired_in_npm_test": false
    },
    {
      "filename": "fixture-entity-canonical.mjs",
      "purpose": "Gate: fixture-entity-canonical",
      "wired_in_npm_test": false
    },
    {
      "filename": "flow-contracts.mjs",
      "purpose": "flow-contracts — Constitution §46 enforcement (the Flow Contracts gate).",
      "wired_in_npm_test": false
    },
    {
      "filename": "followability-canonical.mjs",
      "purpose": "followability-canonical.mjs — §0.59 (Followable-by-Construction + Universal",
      "wired_in_npm_test": false
    },
    {
      "filename": "forbid-must-supply.mjs",
      "purpose": "forbid-must-supply — §0.56.",
      "wired_in_npm_test": false
    },
    {
      "filename": "form-integrity.mjs",
      "purpose": "scripts/gates/form-integrity.mjs — build-time form-control reachability gate",
      "wired_in_npm_test": false
    },
    {
      "filename": "forms-canonical.mjs",
      "purpose": "forms-canonical.mjs — §0.18 Canonical-Absolute enforcer for the forms registry.",
      "wired_in_npm_test": false
    },
    {
      "filename": "foundry-rail-canonical.mjs",
      "purpose": "foundry-rail-canonical.mjs — §54 (KYE Sector Pack Foundry™) enforcer.",
      "wired_in_npm_test": false
    },
    {
      "filename": "framework-coverage-bijection.mjs",
      "purpose": "Gate: framework-coverage-bijection",
      "wired_in_npm_test": false
    },
    {
      "filename": "framework-ingestion-canonical.mjs",
      "purpose": "framework-ingestion-canonical.mjs — §59 enforcer.",
      "wired_in_npm_test": false
    },
    {
      "filename": "framework-mapping-canonical.mjs",
      "purpose": "framework-mapping-canonical.mjs — §70 KYE Framework Mapping Rail™ enforcer.",
      "wired_in_npm_test": false
    },
    {
      "filename": "framework-marketing-coherence.mjs",
      "purpose": "Gate: framework-marketing-coherence",
      "wired_in_npm_test": false
    },
    {
      "filename": "fraud-decision-canonical.mjs",
      "purpose": "fraud-decision-canonical.mjs — §0.30 / §52 / §68 enforcer for the",
      "wired_in_npm_test": false
    },
    {
      "filename": "functional-inventory-coverage.mjs",
      "purpose": "Gate: functional-inventory-coverage (constitution §0.29 Production-Completeness ·",
      "wired_in_npm_test": false
    },
    {
      "filename": "gap-finder-canonical.mjs",
      "purpose": "gap-finder-canonical.mjs — §0.18 Canonical-Absolute drift gate for the",
      "wired_in_npm_test": false
    },
    {
      "filename": "gate-manifest-fresh.mjs",
      "purpose": "gate-manifest-fresh (§0.9 / §0.18 canonical-registry · audit fix #1, 2026-06-11)",
      "wired_in_npm_test": false
    },
    {
      "filename": "gateway-roles-canonical.mjs",
      "purpose": "Gate: gateway-roles-canonical",
      "wired_in_npm_test": false
    },
    {
      "filename": "generated-not-source.mjs",
      "purpose": "generated-not-source.mjs — an edit must survive a full build.",
      "wired_in_npm_test": false
    },
    {
      "filename": "generative-eval-coverage.mjs",
      "purpose": "Gate: generative-eval-coverage (§13 Resilience Loop™ + §62 + §0.8)",
      "wired_in_npm_test": false
    },
    {
      "filename": "generator-determinism.mjs",
      "purpose": "generator-determinism.mjs — §0.20 Automatic Dynamic Resolution precondition.",
      "wired_in_npm_test": false
    },
    {
      "filename": "genetic-sequencing-canonical.mjs",
      "purpose": "genetic-sequencing-canonical.mjs — §0.30 / §52 / §68 enforcer for the",
      "wired_in_npm_test": false
    },
    {
      "filename": "gh-org-canonical.mjs",
      "purpose": "gh-org-canonical.mjs — §0.18 Canonical-Absolute enforcer for the gh-org registry.",
      "wired_in_npm_test": false
    },
    {
      "filename": "github-shape-canonical.mjs",
      "purpose": "github-shape-canonical.mjs — §5 (GitHub Constitution) enforcer.",
      "wired_in_npm_test": false
    },
    {
      "filename": "governance-plurality-canonical.mjs",
      "purpose": "Gate: governance-plurality-canonical — \"no governance axis may be singular.\"",
      "wired_in_npm_test": false
    },
    {
      "filename": "governed-agents-fresh.mjs",
      "purpose": "Gate: governed-agents-fresh — Constitution §0.20 + §0.31 + §0.12.",
      "wired_in_npm_test": false
    },
    {
      "filename": "governed-demo-canonical.mjs",
      "purpose": "governed-demo-canonical.mjs — §0.18 Canonical-Absolute enforcer for the KYE",
      "wired_in_npm_test": false
    },
    {
      "filename": "governed-invariants-canonical.mjs",
      "purpose": "governed-invariants-canonical.mjs — make the KYE authority-protocol soundness",
      "wired_in_npm_test": false
    },
    {
      "filename": "governed-inventory-coverage.mjs",
      "purpose": "Gate: governed-inventory-coverage (constitution §0.34 Self-Run Governance · §0.3 · §13).",
      "wired_in_npm_test": false
    },
    {
      "filename": "governed-inventory-daemon-canonical.mjs",
      "purpose": "governed-inventory-daemon-canonical (§0.34 Self-Run Governance · §0.3 · §0.43).",
      "wired_in_npm_test": false
    },
    {
      "filename": "governed-knowledge-assistant-canonical.mjs",
      "purpose": "governed-knowledge-assistant-canonical.mjs — KYE Governed Knowledge Assistant™ enforcer.",
      "wired_in_npm_test": false
    },
    {
      "filename": "governed-prompts-canonical.mjs",
      "purpose": "governed-prompts-canonical.mjs — §58 enforcer.",
      "wired_in_npm_test": false
    },
    {
      "filename": "governed-step-canonical.mjs",
      "purpose": "governed-step-canonical — §0.43 pointed one level down, at DERIVERS.",
      "wired_in_npm_test": false
    },
    {
      "filename": "grants-agent-canonical.mjs",
      "purpose": "grants-agent-canonical.mjs — §0.30 / §52 / §68 / §70 enforcer for the",
      "wired_in_npm_test": false
    },
    {
      "filename": "guard-recommendation-ranking-stable.mjs",
      "purpose": "Gate: guard-recommendation-ranking-stable",
      "wired_in_npm_test": false
    },
    {
      "filename": "hardcode-canonical.mjs",
      "purpose": "Gate: hardcode-canonical (§0.9 — the zero-hardcode ratchet)",
      "wired_in_npm_test": false
    },
    {
      "filename": "hardware-electronics-product-canonical.mjs",
      "purpose": "hardware-electronics-product-canonical.mjs — §49 §9 Sector Specialisation",
      "wired_in_npm_test": false
    },
    {
      "filename": "harness-adapter-canonical.mjs",
      "purpose": "harness-adapter-canonical.mjs — §52 Phase 4 (KYE Harness Adapter™) enforcer.",
      "wired_in_npm_test": false
    },
    {
      "filename": "host-platform-adapter-canonical.mjs",
      "purpose": "host-platform-adapter-canonical.mjs — KYE Host-Platform Authority Adapter enforcer.",
      "wired_in_npm_test": false
    },
    {
      "filename": "housekeeping.mjs",
      "purpose": "Gate: housekeeping (stale / fictional reference detector)",
      "wired_in_npm_test": false
    },
    {
      "filename": "hr-recruitment-product-canonical.mjs",
      "purpose": "hr-recruitment-product-canonical.mjs — §49 §9 Sector Specialisation +",
      "wired_in_npm_test": false
    },
    {
      "filename": "hse-safety-pack-canonical.mjs",
      "purpose": "hse-safety-pack-canonical.mjs — KYE HSE Authority Pack™ enforcer (§68 product).",
      "wired_in_npm_test": false
    },
    {
      "filename": "html-sink-safety.mjs",
      "purpose": "Gate: html-sink-safety (§0.4 banking-grade surfaces + §0.49 no hand-rolling)",
      "wired_in_npm_test": false
    },
    {
      "filename": "human-voice-copy.mjs",
      "purpose": "human-voice-copy.mjs — §11 Content · human-voice authenticity gate.",
      "wired_in_npm_test": false
    },
    {
      "filename": "ich-authority-canonical.mjs",
      "purpose": "ich-authority-canonical.mjs — §54 §13 / §68 enforcer for the",
      "wired_in_npm_test": false
    },
    {
      "filename": "icons-canonical.mjs",
      "purpose": "icons-canonical.mjs — §0.18 Canonical-Absolute enforcer for the icons registry.",
      "wired_in_npm_test": false
    },
    {
      "filename": "id-contract-canonical.mjs",
      "purpose": "id-contract-canonical.mjs — an id field must be a contract, and a reference",
      "wired_in_npm_test": false
    },
    {
      "filename": "id-grammar-binding.mjs",
      "purpose": "Gate: id-grammar-binding  (§0.9 zero-hardcode · §43 machine-readable)",
      "wired_in_npm_test": false
    },
    {
      "filename": "implementation-canonical.mjs",
      "purpose": "implementation-canonical — Constitution §40 enforcement.",
      "wired_in_npm_test": false
    },
    {
      "filename": "inbound-outbound-governance.mjs",
      "purpose": "Gate: inbound-outbound-governance — Constitution §0.3 + §0.36 + §0.37 + §0.38 (Governed Boundary).",
      "wired_in_npm_test": false
    },
    {
      "filename": "ingest-canonical.mjs",
      "purpose": "ingest-canonical.mjs — two doors, ONE verifier (§0 · §62 · §70).",
      "wired_in_npm_test": false
    },
    {
      "filename": "insurance-authority-canonical.mjs",
      "purpose": "insurance-authority-canonical.mjs — §54 §13 / §68 / §70 enforcer for the",
      "wired_in_npm_test": false
    },
    {
      "filename": "insurance-authorization-canonical.mjs",
      "purpose": "insurance-authorization-canonical.mjs — §0.30 / §52 / §68 enforcer for the",
      "wired_in_npm_test": false
    },
    {
      "filename": "intake-form-smoke.mjs",
      "purpose": "Gate: intake-form-smoke — every persona-intake form (§49/§62) MUST accept a",
      "wired_in_npm_test": false
    },
    {
      "filename": "integration-canonical.mjs",
      "purpose": "Gate: integration-canonical",
      "wired_in_npm_test": false
    },
    {
      "filename": "inter-project-isolation.mjs",
      "purpose": "inter-project-isolation.mjs — §0.28 Inter-Project Isolation enforcer.",
      "wired_in_npm_test": false
    },
    {
      "filename": "interactivity-required.mjs",
      "purpose": "Gate: interactivity-required",
      "wired_in_npm_test": false
    },
    {
      "filename": "investment-decision-authority-canonical.mjs",
      "purpose": "investment-decision-authority-canonical.mjs — §54 §13 / §68 enforcer for the",
      "wired_in_npm_test": false
    },
    {
      "filename": "invoices-canonical.mjs",
      "purpose": "invoices-canonical.mjs — §0.18 Canonical-Absolute enforcer for the invoices registry.",
      "wired_in_npm_test": false
    },
    {
      "filename": "ip-oss-line.mjs",
      "purpose": "Gate: ip-oss-line",
      "wired_in_npm_test": false
    },
    {
      "filename": "islamic-finance-agents-canonical.mjs",
      "purpose": "islamic-finance-agents-canonical.mjs — §0.30 / §52 / §68 / §70 enforcer for",
      "wired_in_npm_test": false
    },
    {
      "filename": "journey-landing-coverage.mjs",
      "purpose": "Gate: journey-landing-coverage",
      "wired_in_npm_test": false
    },
    {
      "filename": "jurisdiction-authority-canonical.mjs",
      "purpose": "jurisdiction-authority-canonical.mjs — §72 (KYE Jurisdiction & Data-Sovereignty Authority™) enforcer.",
      "wired_in_npm_test": false
    },
    {
      "filename": "kit-orchestration-canonical.mjs",
      "purpose": "kit-orchestration-canonical.mjs — §42 v1.4 (Kit Orchestration) enforcer.",
      "wired_in_npm_test": false
    },
    {
      "filename": "kye-answers-uniqueness.mjs",
      "purpose": "Gate: kye-answers-uniqueness",
      "wired_in_npm_test": false
    },
    {
      "filename": "kye-canonical-everything-sweep.mjs",
      "purpose": "kye-canonical-everything-sweep.mjs — §0.18 Canonical-Absolute meta-gate.",
      "wired_in_npm_test": false
    },
    {
      "filename": "landing-hubs-canonical.mjs",
      "purpose": "landing-hubs-canonical.mjs — #395 Hub-Centric Landing IA enforcer (§06/§0.18).",
      "wired_in_npm_test": false
    },
    {
      "filename": "learn-manifest-alive.mjs",
      "purpose": "learn-manifest-alive — Constitution §39 enforcement.",
      "wired_in_npm_test": false
    },
    {
      "filename": "ledgers-canonical.mjs",
      "purpose": "ledgers-canonical.mjs — §0.18 Canonical-Absolute enforcer for the ledgers registry.",
      "wired_in_npm_test": false
    },
    {
      "filename": "legal-agent-authority-canonical.mjs",
      "purpose": "legal-agent-authority-canonical.mjs — §0 / §0.8 / §0.30 / §52 enforcer for the",
      "wired_in_npm_test": false
    },
    {
      "filename": "legal-authorization-canonical.mjs",
      "purpose": "legal-authorization-canonical.mjs — §0.30 / §52 / §68 enforcer for the",
      "wired_in_npm_test": false
    },
    {
      "filename": "legal-canonical.mjs",
      "purpose": "legal-canonical.mjs — §0.18 Canonical-Absolute enforcer for the legal registry.",
      "wired_in_npm_test": false
    },
    {
      "filename": "lifecycle-coverage-canonical.mjs",
      "purpose": "lifecycle-coverage-canonical.mjs — §0.42 coverage applied to LIFECYCLE.",
      "wired_in_npm_test": false
    },
    {
      "filename": "lifecycle-state-canonical.mjs",
      "purpose": "Gate: lifecycle-state-canonical",
      "wired_in_npm_test": false
    },
    {
      "filename": "lifecycles-canonical.mjs",
      "purpose": "lifecycles-canonical.mjs — §0.18 Canonical-Absolute enforcer for the lifecycles registry.",
      "wired_in_npm_test": false
    },
    {
      "filename": "link-resolution.mjs",
      "purpose": "scripts/gates/link-resolution.mjs — build-time internal-link integrity gate",
      "wired_in_npm_test": false
    },
    {
      "filename": "litigation-evidence-discovery-canonical.mjs",
      "purpose": "litigation-evidence-discovery-canonical.mjs — §54 §13 / §68 / §70 enforcer for the",
      "wired_in_npm_test": false
    },
    {
      "filename": "liveness-manifest-canonical.mjs",
      "purpose": "liveness-manifest-canonical — §0.65 obligation 9: a fault that cannot fail.",
      "wired_in_npm_test": false
    },
    {
      "filename": "machine-readable-coverage.mjs",
      "purpose": "Gate: machine-readable-coverage",
      "wired_in_npm_test": false
    },
    {
      "filename": "manifest-canonical.mjs",
      "purpose": "Gate: manifest-canonical",
      "wired_in_npm_test": false
    },
    {
      "filename": "marketplace-listing-conformance.mjs",
      "purpose": "Gate: marketplace-listing-conformance",
      "wired_in_npm_test": false
    },
    {
      "filename": "mas-mindforge-product-canonical.mjs",
      "purpose": "mas-mindforge-product-canonical.mjs — §49 §9 Sector Specialisation",
      "wired_in_npm_test": false
    },
    {
      "filename": "mcp-schema-validate.mjs",
      "purpose": "Gate: mcp-schema-validate",
      "wired_in_npm_test": false
    },
    {
      "filename": "mcp-tool-coverage.mjs",
      "purpose": "Gate: mcp-tool-coverage",
      "wired_in_npm_test": false
    },
    {
      "filename": "media-publication-canonical.mjs",
      "purpose": "media-publication-canonical.mjs — the §39 media rail enforcer.",
      "wired_in_npm_test": false
    },
    {
      "filename": "memory-authority-canonical.mjs",
      "purpose": "memory-authority-canonical.mjs — §63 (KYE Memory Authority Rail™) enforcer.",
      "wired_in_npm_test": false
    },
    {
      "filename": "menu-tree-canonical.mjs",
      "purpose": "Gate: menu-tree-canonical (§0 / §50 + §02 IA)",
      "wired_in_npm_test": false
    },
    {
      "filename": "merge-authority.mjs",
      "purpose": "merge-authority — the SERVER-SIDE required check for kye:action-class:merge.",
      "wired_in_npm_test": false
    },
    {
      "filename": "meter-event-no-double-count.mjs",
      "purpose": "Gate: meter-event-no-double-count",
      "wired_in_npm_test": false
    },
    {
      "filename": "middleware-canonical.mjs",
      "purpose": "middleware-canonical.mjs — §16.13 (Middleware Manifest) enforcer.",
      "wired_in_npm_test": false
    },
    {
      "filename": "mobile-table-scroll-coherent.mjs",
      "purpose": "Gate: mobile-table-scroll-coherent",
      "wired_in_npm_test": false
    },
    {
      "filename": "modal-wiring-canonical.mjs",
      "purpose": "Gate: modal-wiring-canonical (§0.29 + §0.18 + §0.3)",
      "wired_in_npm_test": false
    },
    {
      "filename": "model-governance-canonical.mjs",
      "purpose": "model-governance-canonical.mjs — constitution §67 Model Governance Rail.",
      "wired_in_npm_test": false
    },
    {
      "filename": "model-risk-data-governance-canonical.mjs",
      "purpose": "model-risk-data-governance-canonical.mjs — §54 §13 / §68 / §70 enforcer for the",
      "wired_in_npm_test": false
    },
    {
      "filename": "module-canonical.mjs",
      "purpose": "module-canonical.mjs — §0.18 Canonical-Absolute enforcer for the module registry.",
      "wired_in_npm_test": false
    },
    {
      "filename": "mortgage-authorization-canonical.mjs",
      "purpose": "mortgage-authorization-canonical.mjs — §0.30 / §52 / §68 enforcer for the",
      "wired_in_npm_test": false
    },
    {
      "filename": "multidirectional-taxonomy.mjs",
      "purpose": "scripts/gates/multidirectional-taxonomy.mjs — Constitution §0.17 enforcer.",
      "wired_in_npm_test": false
    },
    {
      "filename": "nav-label-coverage.mjs",
      "purpose": "Gate: nav-label-coverage",
      "wired_in_npm_test": false
    },
    {
      "filename": "nav-score.mjs",
      "purpose": "Gate: nav-score",
      "wired_in_npm_test": false
    },
    {
      "filename": "no-binary-source.mjs",
      "purpose": "Gate: no-binary-source (§0.43 no blind spots · §0.20 no stray control bytes)",
      "wired_in_npm_test": false
    },
    {
      "filename": "no-blind-spots.mjs",
      "purpose": "Gate: no-blind-spots — Constitution §0.43 No Blind Enforcers.",
      "wired_in_npm_test": false
    },
    {
      "filename": "no-fabricated-customer-claims.mjs",
      "purpose": "no-fabricated-customer-claims (§0.2 + §41)",
      "wired_in_npm_test": false
    },
    {
      "filename": "no-inline-script.mjs",
      "purpose": "no-inline-script.mjs — CSP self-consistency enforcer for EVERY public surface.",
      "wired_in_npm_test": false
    },
    {
      "filename": "no-mask-token-leak.mjs",
      "purpose": "Gate: no-mask-token-leak (§0.11 + §41 recurrence rule)",
      "wired_in_npm_test": false
    },
    {
      "filename": "no-merge-regression.mjs",
      "purpose": "no-merge-regression (§0.3 self-governance · §41 convert-to-rule)",
      "wired_in_npm_test": false
    },
    {
      "filename": "no-native-dialogs-in-banking-grade-surfaces.mjs",
      "purpose": "no-native-dialogs-in-banking-grade-surfaces — flags new uses of native",
      "wired_in_npm_test": false
    },
    {
      "filename": "no-self-perpetuating-loops.mjs",
      "purpose": "Gate: no-self-perpetuating-loops  (constitution §0.32)",
      "wired_in_npm_test": false
    },
    {
      "filename": "no-spof-coverage.mjs",
      "purpose": "no-spof-coverage.mjs — §51 (No Single Point of Failure) enforcer.",
      "wired_in_npm_test": false
    },
    {
      "filename": "no-stubs-placeholders-mocks.mjs",
      "purpose": "Gate: no-stubs-placeholders-mocks",
      "wired_in_npm_test": false
    },
    {
      "filename": "nondisclosure-canonical.mjs",
      "purpose": "nondisclosure-canonical.mjs — Non-Disclosure Registry enforcer (§0 + §0.9 + §33).",
      "wired_in_npm_test": false
    },
    {
      "filename": "notices-canonical.mjs",
      "purpose": "notices-canonical.mjs — §0.18 Canonical-Absolute enforcer for the notices registry.",
      "wired_in_npm_test": false
    },
    {
      "filename": "obligation-matrix-canonical.mjs",
      "purpose": "Gate: obligation-matrix-canonical — constitution/00-INDEX.md §0.65.",
      "wired_in_npm_test": false
    },
    {
      "filename": "obligation-rail-canonical.mjs",
      "purpose": "obligation-rail-canonical.mjs — constitution §64 Obligation Authority Rail.",
      "wired_in_npm_test": false
    },
    {
      "filename": "occ-ai-supervision-product-canonical.mjs",
      "purpose": "occ-ai-supervision-product-canonical.mjs — §49 §9 Sector Specialisation",
      "wired_in_npm_test": false
    },
    {
      "filename": "offboarding-canonical.mjs",
      "purpose": "offboarding-canonical.mjs — §0.18 Canonical-Absolute enforcer for the offboarding registry.",
      "wired_in_npm_test": false
    },
    {
      "filename": "om-compiler-determinism.mjs",
      "purpose": "Gate: om-compiler-determinism",
      "wired_in_npm_test": false
    },
    {
      "filename": "om-no-orphan-rules.mjs",
      "purpose": "Gate: om-no-orphan-rules",
      "wired_in_npm_test": false
    },
    {
      "filename": "om-review-signed.mjs",
      "purpose": "Gate: om-review-signed",
      "wired_in_npm_test": false
    },
    {
      "filename": "om-schema-validate.mjs",
      "purpose": "async function main() {",
      "wired_in_npm_test": false
    },
    {
      "filename": "onboarding-consent-required.mjs",
      "purpose": "Gate: onboarding-consent-required",
      "wired_in_npm_test": false
    },
    {
      "filename": "onboarding-no-orphan-state.mjs",
      "purpose": "Gate: onboarding-no-orphan-state",
      "wired_in_npm_test": false
    },
    {
      "filename": "onboarding-schema-validate.mjs",
      "purpose": "Gate: onboarding-schema-validate",
      "wired_in_npm_test": false
    },
    {
      "filename": "onboarding-state-machine-coverage.mjs",
      "purpose": "Gate: onboarding-state-machine-coverage",
      "wired_in_npm_test": false
    },
    {
      "filename": "ontology-coverage.mjs",
      "purpose": "Gate: ontology-coverage (§0.20 + §53 + §0.9)",
      "wired_in_npm_test": false
    },
    {
      "filename": "ontology-crossmap-canonical.mjs",
      "purpose": "ontology-crossmap-canonical.mjs — KYE Bring-Your-Own-Ontology Cross-Map™ (§74/§70 reuse).",
      "wired_in_npm_test": false
    },
    {
      "filename": "ontology-dictionary-roundtrip.mjs",
      "purpose": "ontology-dictionary-roundtrip.mjs — §53 worked example #1 freshness gate.",
      "wired_in_npm_test": false
    },
    {
      "filename": "openapi-functions-bijection.mjs",
      "purpose": "openapi-functions-bijection — RED-LINE gate. Every Pages-Functions",
      "wired_in_npm_test": false
    },
    {
      "filename": "oscal-exports-canonical.mjs",
      "purpose": "oscal-exports-canonical.mjs — §0.18 Canonical-Absolute enforcer for the oscal-exports registry.",
      "wired_in_npm_test": false
    },
    {
      "filename": "oss-software-constitution-canonical.mjs",
      "purpose": "Gate: oss-software-constitution-canonical",
      "wired_in_npm_test": false
    },
    {
      "filename": "outreach-canonical.mjs",
      "purpose": "outreach-canonical.mjs — KYE Outreach Studio™ enforcer (task #182 Phase 1).",
      "wired_in_npm_test": false
    },
    {
      "filename": "pack-chain-canonical.mjs",
      "purpose": "Gate: pack-chain-canonical",
      "wired_in_npm_test": false
    },
    {
      "filename": "package-namespace-canonical.mjs",
      "purpose": "package-namespace-canonical.mjs — the PACKAGE-NAMING ROOT enforcer (§0 + §0.9).",
      "wired_in_npm_test": false
    },
    {
      "filename": "page-markdown-fresh.mjs",
      "purpose": "page-markdown-fresh.mjs — §43 Machine-Readable by Default enforcer for the",
      "wired_in_npm_test": false
    },
    {
      "filename": "page-metadata-canonical.mjs",
      "purpose": "page-metadata-canonical.mjs — §0.18 Canonical-Absolute enforcer for the page-metadata registry.",
      "wired_in_npm_test": false
    },
    {
      "filename": "pages-function-canonical.mjs",
      "purpose": "pages-function-canonical.mjs — THE REVERSE GATE.",
      "wired_in_npm_test": false
    },
    {
      "filename": "pages-functions-syntax-check.mjs",
      "purpose": "pages-functions-syntax-check — blocks PR merge when any Cloudflare",
      "wired_in_npm_test": false
    },
    {
      "filename": "palette-score.mjs",
      "purpose": "Gate: palette-score",
      "wired_in_npm_test": false
    },
    {
      "filename": "panels-canonical.mjs",
      "purpose": "panels-canonical.mjs — §0.18 Canonical-Absolute enforcer for the panels registry.",
      "wired_in_npm_test": false
    },
    {
      "filename": "partner-admin-surface-coverage.mjs",
      "purpose": "partner-admin-surface-coverage.mjs — §10 §8.1 + §49 §3 enforcer.",
      "wired_in_npm_test": false
    },
    {
      "filename": "partner-disclosure-boundary.mjs",
      "purpose": "partner-disclosure-boundary.mjs — §0.19 Contract-Not-Internals enforcer.",
      "wired_in_npm_test": false
    },
    {
      "filename": "partner-programme-alive.mjs",
      "purpose": "partner-programme-alive.mjs — §10 (Partner Constitution) enforcer.",
      "wired_in_npm_test": false
    },
    {
      "filename": "partner-taxonomy-canonical.mjs",
      "purpose": "partner-taxonomy-canonical.mjs — Partner Taxonomy enforcer (§49 §9 + §54 + §0.19).",
      "wired_in_npm_test": false
    },
    {
      "filename": "payment-authorization-canonical.mjs",
      "purpose": "payment-authorization-canonical.mjs — §0.30 / §52 / §68 enforcer for the",
      "wired_in_npm_test": false
    },
    {
      "filename": "payment-gate-enforced.mjs",
      "purpose": "Gate: payment-gate-enforced",
      "wired_in_npm_test": false
    },
    {
      "filename": "pdp-ssot-canonical.mjs",
      "purpose": "pdp-ssot-canonical — Constitution §14 §3.6a enforcement.",
      "wired_in_npm_test": false
    },
    {
      "filename": "pension-liquidity-canonical.mjs",
      "purpose": "pension-liquidity-canonical.mjs — §0.30 / §52 / §68 enforcer for the",
      "wired_in_npm_test": false
    },
    {
      "filename": "pii-authorization-canonical.mjs",
      "purpose": "pii-authorization-canonical.mjs — §0.30 / §52 / §68 enforcer for the",
      "wired_in_npm_test": false
    },
    {
      "filename": "pill-canonical.mjs",
      "purpose": "Gate: pill-canonical (§0 Zero Competing Systems · constitution/04-DESIGN-SYSTEM.md §2.6)",
      "wired_in_npm_test": false
    },
    {
      "filename": "platform-map-canonical.mjs",
      "purpose": "platform-map-canonical.mjs — KYE 3D Platform Map (Phase 1) enforcer.",
      "wired_in_npm_test": false
    },
    {
      "filename": "policy-engine-adapter-canonical.mjs",
      "purpose": "policy-engine-adapter-canonical.mjs — §0.18 Canonical-Absolute enforcer for",
      "wired_in_npm_test": false
    },
    {
      "filename": "policy-lifecycle-canonical.mjs",
      "purpose": "policy-lifecycle-canonical.mjs — §0.30 / §52 / §68 enforcer for the",
      "wired_in_npm_test": false
    },
    {
      "filename": "policy-points-canonical.mjs",
      "purpose": "policy-points-canonical.mjs — §0.18 Canonical-Absolute enforcer for the policy-points registry.",
      "wired_in_npm_test": false
    },
    {
      "filename": "portals-canonical.mjs",
      "purpose": "portals-canonical.mjs — §0.18 Canonical-Absolute enforcer for the portals registry.",
      "wired_in_npm_test": false
    },
    {
      "filename": "portfolio-map-canonical.mjs",
      "purpose": "portfolio-map-canonical — §0.10/§0.25 enforcer for the Portfolio / Surface Map.",
      "wired_in_npm_test": false
    },
    {
      "filename": "positioning-canonical.mjs",
      "purpose": "positioning-canonical.mjs — §0.18 enforcer for the positioning/merchandising rail.",
      "wired_in_npm_test": false
    },
    {
      "filename": "positioning-lock-canonical.mjs",
      "purpose": "positioning-lock-canonical.mjs — §0.16 positioning enforcer",
      "wired_in_npm_test": false
    },
    {
      "filename": "pricing-canonical-fresh.mjs",
      "purpose": "pricing-canonical-fresh.mjs — §26 §13 enforcer for the per-SKU",
      "wired_in_npm_test": false
    },
    {
      "filename": "product-canonical.mjs",
      "purpose": "product-canonical.mjs — the Product Rail membrane (§0.9 + §0.18 + §0.20 + §54).",
      "wired_in_npm_test": false
    },
    {
      "filename": "product-fanout-canonical.mjs",
      "purpose": "product-fanout-canonical.mjs — the §0.27 / §68 Total Productisation Fan-Out membrane.",
      "wired_in_npm_test": false
    },
    {
      "filename": "production-action-authority-canonical.mjs",
      "purpose": "production-action-authority-canonical.mjs — §54 §13 / §68 / §70 enforcer for the",
      "wired_in_npm_test": false
    },
    {
      "filename": "production-completeness.mjs",
      "purpose": "production-completeness.mjs — constitution §0.29 Production-Completeness.",
      "wired_in_npm_test": false
    },
    {
      "filename": "profile-canonical.mjs",
      "purpose": "Gate: profile-canonical",
      "wired_in_npm_test": false
    },
    {
      "filename": "profile-discipline.mjs",
      "purpose": "Gate: profile-discipline",
      "wired_in_npm_test": false
    },
    {
      "filename": "public-mirror-canonical.mjs",
      "purpose": "Gate: public-mirror-canonical (§0.18 canonical-absolute · §0.49 no-hand-rolling · §70 honesty bar).",
      "wired_in_npm_test": false
    },
    {
      "filename": "public-no-internal-leak.mjs",
      "purpose": "Gate: public-no-internal-leak — ZERO-TOLERANCE public IP-track leak scanner.",
      "wired_in_npm_test": false
    },
    {
      "filename": "public-sector-governance-canonical.mjs",
      "purpose": "public-sector-governance-canonical.mjs — §54 §13 / §68 enforcer for the",
      "wired_in_npm_test": false
    },
    {
      "filename": "public-stack-mention.mjs",
      "purpose": "Gate: public-stack-mention",
      "wired_in_npm_test": false
    },
    {
      "filename": "publication-canonical.mjs",
      "purpose": "publication-canonical.mjs — §62 §17 (governed book publishing) enforcer.",
      "wired_in_npm_test": false
    },
    {
      "filename": "published-apps-canonical.mjs",
      "purpose": "Gate: published-apps-canonical (§0.18 Canonical-Absolute — the KYE",
      "wired_in_npm_test": false
    },
    {
      "filename": "purpose-admissibility-vectors.mjs",
      "purpose": "Gate: purpose-admissibility-vectors",
      "wired_in_npm_test": false
    },
    {
      "filename": "purpose-no-ambient.mjs",
      "purpose": "Gate: purpose-no-ambient",
      "wired_in_npm_test": false
    },
    {
      "filename": "purpose-revocation-cascade.mjs",
      "purpose": "Gate: purpose-revocation-cascade",
      "wired_in_npm_test": false
    },
    {
      "filename": "purpose-schema-validate.mjs",
      "purpose": "Gate: purpose-schema-validate",
      "wired_in_npm_test": false
    },
    {
      "filename": "queue-consumer-uniqueness.mjs",
      "purpose": "queue-consumer-uniqueness.mjs — §16 Edge Runtime + §0 Zero Competing Systems.",
      "wired_in_npm_test": false
    },
    {
      "filename": "queue-wiring-canonical.mjs",
      "purpose": "queue-wiring-canonical.mjs — every declared queue producer has a reachable",
      "wired_in_npm_test": false
    },
    {
      "filename": "quote-bind-canonical.mjs",
      "purpose": "quote-bind-canonical.mjs — §0.30 / §52 / §68 enforcer for the",
      "wired_in_npm_test": false
    },
    {
      "filename": "rag-authorization-canonical.mjs",
      "purpose": "rag-authorization-canonical.mjs — §0.30 / §52 / §68 enforcer for the",
      "wired_in_npm_test": false
    },
    {
      "filename": "ratchet-comparison-canonical.mjs",
      "purpose": "ratchet-comparison-canonical — §0.55: assertRatchet is THE ONE comparison a",
      "wired_in_npm_test": false
    },
    {
      "filename": "rate-limit-canonical.mjs",
      "purpose": "rate-limit-canonical.mjs — §16 §2.3 Rate-Limit Manifest enforcer.",
      "wired_in_npm_test": false
    },
    {
      "filename": "readme-canonical.mjs",
      "purpose": "readme-canonical.mjs — §0.18 Canonical-Absolute enforcer for the readme registry.",
      "wired_in_npm_test": false
    },
    {
      "filename": "receipts-canonical.mjs",
      "purpose": "receipts-canonical.mjs — §0.18 Canonical-Absolute enforcer for the receipts registry.",
      "wired_in_npm_test": false
    },
    {
      "filename": "reference-canonical.mjs",
      "purpose": "reference-canonical.mjs — §0.18 Canonical-Absolute enforcer for the reference registry.",
      "wired_in_npm_test": false
    },
    {
      "filename": "region-ownership-canonical.mjs",
      "purpose": "region-ownership-canonical — a writer may not destroy bytes it does not own.",
      "wired_in_npm_test": false
    },
    {
      "filename": "regulatory-generators-canonical.mjs",
      "purpose": "Gate: regulatory-generators-canonical",
      "wired_in_npm_test": false
    },
    {
      "filename": "relationship-canonical.mjs",
      "purpose": "relationship-canonical.mjs — §56 (N:M Relationships) enforcer.",
      "wired_in_npm_test": false
    },
    {
      "filename": "render-completeness.mjs",
      "purpose": "Gate: render-completeness  (§0.43 No Blind Enforcers · §0.4 banking-grade)",
      "wired_in_npm_test": false
    },
    {
      "filename": "report-templates-canonical.mjs",
      "purpose": "report-templates-canonical.mjs — §0.18 Canonical-Absolute enforcer for the report-templates registry.",
      "wired_in_npm_test": false
    },
    {
      "filename": "research-paywall-integrity.mjs",
      "purpose": "research-paywall-integrity.mjs — §62 (KYE Governed Research Rail™) paywall enforcer.",
      "wired_in_npm_test": false
    },
    {
      "filename": "research-rail-canonical.mjs",
      "purpose": "research-rail-canonical.mjs — §62 (KYE Governed Research Rail™) enforcer.",
      "wired_in_npm_test": false
    },
    {
      "filename": "resilience-improvement-emitted.mjs",
      "purpose": "Gate: resilience-improvement-emitted",
      "wired_in_npm_test": false
    },
    {
      "filename": "resilience-loop-vectors.mjs",
      "purpose": "Gate: resilience-loop-vectors",
      "wired_in_npm_test": false
    },
    {
      "filename": "resilience-no-orphan-drift.mjs",
      "purpose": "Gate: resilience-no-orphan-drift",
      "wired_in_npm_test": false
    },
    {
      "filename": "resilience-schema-validate.mjs",
      "purpose": "Gate: resilience-schema-validate",
      "wired_in_npm_test": false
    },
    {
      "filename": "resolution-canonical.mjs",
      "purpose": "resolution-canonical.mjs — §0.20 Automatic Dynamic Resolution verifier.",
      "wired_in_npm_test": false
    },
    {
      "filename": "retroactive-audit-coverage.mjs",
      "purpose": "retroactive-audit-coverage.mjs — §52 Phase 3 drift gate.",
      "wired_in_npm_test": false
    },
    {
      "filename": "rights-disputes-disclosure-canonical.mjs",
      "purpose": "rights-disputes-disclosure-canonical.mjs — §61 graft-bijection enforcer.",
      "wired_in_npm_test": false
    },
    {
      "filename": "risk-method-pinned.mjs",
      "purpose": "Gate: risk-method-pinned",
      "wired_in_npm_test": false
    },
    {
      "filename": "risk-profiler-canonical.mjs",
      "purpose": "risk-profiler-canonical.mjs — §0.18 enforcer for the Authority Risk Profiler.",
      "wired_in_npm_test": false
    },
    {
      "filename": "routing-canonical.mjs",
      "purpose": "routing-canonical — the enforcer of the KYE route contract (§0.67 routing leg).",
      "wired_in_npm_test": false
    },
    {
      "filename": "rule-pack-canonical.mjs",
      "purpose": "Gate: rule-pack-canonical",
      "wired_in_npm_test": false
    },
    {
      "filename": "runtime-decide-smoke.mjs",
      "purpose": "Gate: runtime-decide-smoke (constitution §13 §12 Resilience Loop · §0.3).",
      "wired_in_npm_test": false
    },
    {
      "filename": "sanctions-aml-canonical.mjs",
      "purpose": "sanctions-aml-canonical.mjs — §0.30 / §52 / §68 enforcer for the",
      "wired_in_npm_test": false
    },
    {
      "filename": "schema-authority-canonical.mjs",
      "purpose": "Gate: schema-authority-canonical — Constitution §16 made mechanical.",
      "wired_in_npm_test": false
    },
    {
      "filename": "schema-guard-canonical.mjs",
      "purpose": "schema-guard-canonical.mjs — schema validation is canonical + mechanical,",
      "wired_in_npm_test": false
    },
    {
      "filename": "schema-typegen-fresh.mjs",
      "purpose": "scripts/gates/schema-typegen-fresh.mjs",
      "wired_in_npm_test": false
    },
    {
      "filename": "scientist-tribute-canonical.mjs",
      "purpose": "scientist-tribute-canonical.mjs — §62 'Remembering Scientists' enforcer.",
      "wired_in_npm_test": false
    },
    {
      "filename": "screenshots-canonical.mjs",
      "purpose": "screenshots-canonical.mjs — §0.4/§0.2 honest-product-visual gate.",
      "wired_in_npm_test": false
    },
    {
      "filename": "sdk-cli-coverage.mjs",
      "purpose": "Gate: sdk-cli-coverage",
      "wired_in_npm_test": false
    },
    {
      "filename": "sdk-cross-lang-equiv.mjs",
      "purpose": "Gate: sdk-cross-lang-equiv — EVERY real `admit` implementation, EVERY fixture.",
      "wired_in_npm_test": false
    },
    {
      "filename": "seal-lifecycle-canonical.mjs",
      "purpose": "Modelled on scripts/gates/air-gap-ability.mjs (§0.10 graft): the corpus is",
      "wired_in_npm_test": false
    },
    {
      "filename": "secret-leak-scan.mjs",
      "purpose": "secret-leak-scan.mjs — KYE-native deterministic secret-leak scanner.",
      "wired_in_npm_test": false
    },
    {
      "filename": "sector-kit-canonical.mjs",
      "purpose": "Gate: sector-kit-canonical  (constitution §54 — Sector Kit lock)",
      "wired_in_npm_test": false
    },
    {
      "filename": "sector-pack-parity-canonical.mjs",
      "purpose": "Gate: sector-pack-parity-canonical (§54 + §0.9)",
      "wired_in_npm_test": false
    },
    {
      "filename": "self-description.mjs",
      "purpose": "self-description — Constitution §45 enforcement (the Self-Description Gate).",
      "wired_in_npm_test": false
    },
    {
      "filename": "self-governance-coverage.mjs",
      "purpose": "Gate: self-governance-coverage",
      "wired_in_npm_test": false
    },
    {
      "filename": "separation-of-duties.mjs",
      "purpose": "separation-of-duties — the actor that produces a thing may not be the only",
      "wired_in_npm_test": false
    },
    {
      "filename": "settlement-agent-canonical.mjs",
      "purpose": "settlement-agent-canonical.mjs — §0.30 / §52 / §68 enforcer for the",
      "wired_in_npm_test": false
    },
    {
      "filename": "shadow-mode-non-blocking.mjs",
      "purpose": "Gate: shadow-mode-non-blocking",
      "wired_in_npm_test": false
    },
    {
      "filename": "signal-freshness-canonical.mjs",
      "purpose": "signal-freshness-canonical.mjs — §0.24 Evidence-Over-Headers mechanism.",
      "wired_in_npm_test": false
    },
    {
      "filename": "signal-sources-alive.mjs",
      "purpose": "signal-sources-alive.mjs — §48 (Signal Ingest Contract) enforcer.",
      "wired_in_npm_test": false
    },
    {
      "filename": "signing-key-canonical.mjs",
      "purpose": "signing-key-canonical.mjs — every SIGNING key KYE publishes is governed.",
      "wired_in_npm_test": false
    },
    {
      "filename": "single-decision-seal.mjs",
      "purpose": "Gate: single-decision-seal — Constitution §0 (Zero Competing Systems) +",
      "wired_in_npm_test": false
    },
    {
      "filename": "site-authority-canonical.mjs",
      "purpose": "site-authority-canonical.mjs — KYE Site Authority™ enforcer.",
      "wired_in_npm_test": false
    },
    {
      "filename": "skill-canonical.mjs",
      "purpose": "Gate: skill-canonical (§0.9 + §0.8)",
      "wired_in_npm_test": false
    },
    {
      "filename": "sku-jurisdiction-canonical.mjs",
      "purpose": "Gate: sku-jurisdiction-canonical",
      "wired_in_npm_test": false
    },
    {
      "filename": "sku-manifest-canonical.mjs",
      "purpose": "SKU manifest canonical-first gate.",
      "wired_in_npm_test": false
    },
    {
      "filename": "sku-owner-canonical.mjs",
      "purpose": "sku-owner-canonical.mjs — bidirectional SKU ↔ owner binding (§0.31 reverse half).",
      "wired_in_npm_test": false
    },
    {
      "filename": "smoke-coverage-canonical.mjs",
      "purpose": "smoke-coverage-canonical.mjs — §0.18 Canonical-Absolute enforcer for the",
      "wired_in_npm_test": false
    },
    {
      "filename": "snippets-canonical.mjs",
      "purpose": "snippets-canonical.mjs — §0.18 Canonical-Absolute enforcer for the snippets registry.",
      "wired_in_npm_test": false
    },
    {
      "filename": "social-cards-canonical.mjs",
      "purpose": "social-cards-canonical.mjs — §6 social card contract enforcer.",
      "wired_in_npm_test": false
    },
    {
      "filename": "source-header-canonical.mjs",
      "purpose": "source-header-canonical.mjs — §0.18 Canonical-Absolute enforcer for the source-header registry.",
      "wired_in_npm_test": false
    },
    {
      "filename": "source-registry-canonical.mjs",
      "purpose": "source-registry-canonical.mjs — the citation namespace holds (§62 · §70 · §0).",
      "wired_in_npm_test": false
    },
    {
      "filename": "sql-column-canonical.mjs",
      "purpose": "sql-column-canonical — a SQL string may not name a column that does not exist.",
      "wired_in_npm_test": false
    },
    {
      "filename": "starter-pack-canonical.mjs",
      "purpose": "starter-pack-canonical.mjs — §22 §5 (Starter Packs / Seeds) enforcer.",
      "wired_in_npm_test": false
    },
    {
      "filename": "startup-program-canonical.mjs",
      "purpose": "startup-program-canonical.mjs — §0.18 enforcer for the KYE for Startups™",
      "wired_in_npm_test": false
    },
    {
      "filename": "status-service-coverage.mjs",
      "purpose": "status-service-coverage — the status page surfaces EVERY deployed component.",
      "wired_in_npm_test": false
    },
    {
      "filename": "sticky-chrome-opaque.mjs",
      "purpose": "Gate: sticky-chrome-opaque  (§0.4 banking-grade UI · §41 convert-to-rule)",
      "wired_in_npm_test": false
    },
    {
      "filename": "storage-projection-canonical.mjs",
      "purpose": "storage-projection-canonical — every store is a projection of ONE contract,",
      "wired_in_npm_test": false
    },
    {
      "filename": "stripe-canonical.mjs",
      "purpose": "stripe-canonical.mjs — the Stripe Rail membrane (§0.9 + §0.18 + §0.20 + §23 + §26 + §27).",
      "wired_in_npm_test": false
    },
    {
      "filename": "stripe-pci-scope.mjs",
      "purpose": "stripe-pci-scope.mjs — keeps KYE OUT of PCI DSS cardholder-data scope (§26 + §0.4).",
      "wired_in_npm_test": false
    },
    {
      "filename": "subdomain-chrome-canonical.mjs",
      "purpose": "subdomain-chrome-canonical.mjs — Subdomain Chrome Canonicalisation gate",
      "wired_in_npm_test": false
    },
    {
      "filename": "subdomain-registry-canonical.mjs",
      "purpose": "Gate: subdomain-registry-canonical (§0.1 + §07 — OFFLINE consistency half)",
      "wired_in_npm_test": false
    },
    {
      "filename": "subprocessor-manifest-canonical.mjs",
      "purpose": "subprocessor-manifest-canonical — enforce zero drift between the",
      "wired_in_npm_test": false
    },
    {
      "filename": "surface-coverage-canonical.mjs",
      "purpose": "surface-coverage-canonical.mjs — §0.42 6th coverage dimension ('surfaced').",
      "wired_in_npm_test": false
    },
    {
      "filename": "surface-grade-coverage.mjs",
      "purpose": "surface-grade-coverage.mjs — §0.4 per-surface release gate (canonical + mechanical).",
      "wired_in_npm_test": false
    },
    {
      "filename": "svg-render-safety.mjs",
      "purpose": "svg-render-safety.mjs — closes the recurring \"inline-SVG renders as black boxes\"",
      "wired_in_npm_test": false
    },
    {
      "filename": "synthetic-fixtures-canonical.mjs",
      "purpose": "synthetic-fixtures-canonical.mjs — §0.18 Canonical-Absolute enforcer for the",
      "wired_in_npm_test": false
    },
    {
      "filename": "system-blueprint-canonical.mjs",
      "purpose": "system-blueprint-canonical — every e2e system has a machine-readable map,",
      "wired_in_npm_test": false
    },
    {
      "filename": "system-integrator-rail-canonical.mjs",
      "purpose": "system-integrator-rail-canonical.mjs — §49 §9.A enforcer.",
      "wired_in_npm_test": false
    },
    {
      "filename": "t0-decision-recorded.mjs",
      "purpose": "t0-decision-recorded — every commit carries proof that a t=0 decision was MADE",
      "wired_in_npm_test": false
    },
    {
      "filename": "tax-governance-canonical.mjs",
      "purpose": "tax-governance-canonical.mjs — §54 §13 / §68 enforcer for the",
      "wired_in_npm_test": false
    },
    {
      "filename": "tech-ai-dd-canonical.mjs",
      "purpose": "Gate: tech-ai-dd-canonical (§13 risk-profiler twin + §70 + §0.8)",
      "wired_in_npm_test": false
    },
    {
      "filename": "tenant-predicate-canonical.mjs",
      "purpose": "tenant-predicate-canonical.mjs — §0.11 Zero Contamination, mechanised.",
      "wired_in_npm_test": false
    },
    {
      "filename": "tender-procurement-product-canonical.mjs",
      "purpose": "tender-procurement-product-canonical.mjs — §49 §9 Sector Specialisation",
      "wired_in_npm_test": false
    },
    {
      "filename": "theme-canonical-fresh.mjs",
      "purpose": "Gate: theme-canonical-fresh (§24 §2.1b + §0 + §0.3 + §0.9 + §0.14)",
      "wired_in_npm_test": false
    },
    {
      "filename": "threat-response-canonical.mjs",
      "purpose": "threat-response-canonical.mjs — §0.30 / §52 / §68 enforcer for the",
      "wired_in_npm_test": false
    },
    {
      "filename": "total-citizenship-canonical.mjs",
      "purpose": "Gate: total-citizenship-canonical  (constitution §0.37 — Total Citizenship & t=0 Governance)",
      "wired_in_npm_test": false
    },
    {
      "filename": "total-coverage-canonical.mjs",
      "purpose": "Gate: total-coverage-canonical — Constitution §0.42 Total Coverage",
      "wired_in_npm_test": false
    },
    {
      "filename": "total-governance-coverage.mjs",
      "purpose": "Gate: total-governance-coverage — Constitution §0.40 Total Governance",
      "wired_in_npm_test": false
    },
    {
      "filename": "training-canonical.mjs",
      "purpose": "training-canonical.mjs — §0.18 Canonical-Absolute enforcer for the training registry.",
      "wired_in_npm_test": false
    },
    {
      "filename": "treasury-authority-canonical.mjs",
      "purpose": "treasury-authority-canonical.mjs — §0.30 / §52 / §68 enforcer for the",
      "wired_in_npm_test": false
    },
    {
      "filename": "ui-component-contract.mjs",
      "purpose": "Gate: ui-component-contract",
      "wired_in_npm_test": false
    },
    {
      "filename": "ui-journey-canonical.mjs",
      "purpose": "ui-journey-canonical.mjs — §0.18 Canonical-Absolute enforcer for the UI Journey",
      "wired_in_npm_test": false
    },
    {
      "filename": "uk-tribunal-pack-canonical.mjs",
      "purpose": "uk-tribunal-pack-canonical.mjs — §0 / §0.8 / §0.18 / §68 enforcer for the",
      "wired_in_npm_test": false
    },
    {
      "filename": "underwriting-authority-canonical.mjs",
      "purpose": "underwriting-authority-canonical.mjs — §0.30 / §52 / §68 enforcer for the",
      "wired_in_npm_test": false
    },
    {
      "filename": "uniqueness-canonical.mjs",
      "purpose": "Gate: uniqueness-canonical",
      "wired_in_npm_test": false
    },
    {
      "filename": "universal-bindings-canonical.mjs",
      "purpose": "universal-bindings-canonical.mjs — §0.31 Universal Bindings enforcer.",
      "wired_in_npm_test": false
    },
    {
      "filename": "universal-entity-governance.mjs",
      "purpose": "Gate: universal-entity-governance  (constitution §0.36)",
      "wired_in_npm_test": false
    },
    {
      "filename": "updates-rail-canonical.mjs",
      "purpose": "updates-rail-canonical.mjs — constitution §65 Updates Rail.",
      "wired_in_npm_test": false
    },
    {
      "filename": "url-inventory-canonical.mjs",
      "purpose": "url-inventory-canonical.mjs — §0.18 Canonical-Absolute enforcer for the url-inventory registry.",
      "wired_in_npm_test": false
    },
    {
      "filename": "user-action-canonical.mjs",
      "purpose": "user-action-canonical.mjs — §0.18 Canonical-Absolute enforcer for the user-action registry.",
      "wired_in_npm_test": false
    },
    {
      "filename": "user-journeys-canonical.mjs",
      "purpose": "user-journeys-canonical.mjs — §0.18 Canonical-Absolute enforcer for the user-journeys registry.",
      "wired_in_npm_test": false
    },
    {
      "filename": "value-based-pricing-coverage.mjs",
      "purpose": "value-based-pricing-coverage.mjs — §27 §12 (KYE Value-Based Pricing",
      "wired_in_npm_test": false
    },
    {
      "filename": "venture-studio-program-canonical.mjs",
      "purpose": "venture-studio-program-canonical.mjs — §0.18 enforcer for the KYE",
      "wired_in_npm_test": false
    },
    {
      "filename": "verify-static-only-clock.mjs",
      "purpose": "Gate: verify-static-only-clock (§34 §11 + §2 — the missing enforcer)",
      "wired_in_npm_test": false
    },
    {
      "filename": "visual-conformance.mjs",
      "purpose": "Gate: visual-conformance — the systematic enforcement of zero CSS /",
      "wired_in_npm_test": false
    },
    {
      "filename": "visual-text-patent-safety.mjs",
      "purpose": "Gate: visual-text-patent-safety",
      "wired_in_npm_test": false
    },
    {
      "filename": "visual-verify.mjs",
      "purpose": "Gate: visual-verify",
      "wired_in_npm_test": false
    },
    {
      "filename": "visualizations-canonical.mjs",
      "purpose": "visualizations-canonical.mjs — §0.18 Canonical-Absolute enforcer for the visualizations registry.",
      "wired_in_npm_test": false
    },
    {
      "filename": "webhook-signature-verified.mjs",
      "purpose": "Gate: webhook-signature-verified",
      "wired_in_npm_test": false
    },
    {
      "filename": "wedge-kit-canonical.mjs",
      "purpose": "wedge-kit-canonical.mjs — §0.18 enforcer for the KYE Wedge Kit™ go-to-market",
      "wired_in_npm_test": false
    },
    {
      "filename": "whistleblower-authority-canonical.mjs",
      "purpose": "whistleblower-authority-canonical.mjs — §54 §13 / §68 / §70 enforcer for the",
      "wired_in_npm_test": false
    },
    {
      "filename": "whitepaper-pdf-fresh.mjs",
      "purpose": "Gate: whitepaper-pdf-fresh — Constitution §0.20 + §0.29.",
      "wired_in_npm_test": false
    },
    {
      "filename": "widget-csp-strict.mjs",
      "purpose": "Gate: widget-csp-strict",
      "wired_in_npm_test": false
    },
    {
      "filename": "widget-descriptor-validate.mjs",
      "purpose": "Gate: widget-descriptor-validate",
      "wired_in_npm_test": false
    },
    {
      "filename": "widget-postmessage-conformance.mjs",
      "purpose": "Gate: widget-postmessage-conformance",
      "wired_in_npm_test": false
    },
    {
      "filename": "widget-purpose-permission-required.mjs",
      "purpose": "Gate: widget-purpose-permission-required",
      "wired_in_npm_test": false
    },
    {
      "filename": "worker-deploy-lockfile-present.mjs",
      "purpose": "Gate: worker-deploy-lockfile-present",
      "wired_in_npm_test": false
    },
    {
      "filename": "workflow-governance-coverage.mjs",
      "purpose": "Gate: workflow-governance-coverage — Constitution §0.3 (self-governance) +",
      "wired_in_npm_test": false
    },
    {
      "filename": "workflow-lint-canonical.mjs",
      "purpose": "workflow-lint-canonical.mjs — the shellcheck class that keeps breaking CI must",
      "wired_in_npm_test": false
    },
    {
      "filename": "workflow-no-protected-main-push-canonical.mjs",
      "purpose": "workflow-no-protected-main-push.mjs — auto-triggered workflows must not push",
      "wired_in_npm_test": false
    },
    {
      "filename": "workflow-observer-coverage.mjs",
      "purpose": "Gate: workflow-observer-coverage  (POLICY REVERSED 2026-06-26 — §0.32 cost-bleed root fix)",
      "wired_in_npm_test": false
    },
    {
      "filename": "workflow-r2-precreate-present.mjs",
      "purpose": "Gate: workflow-r2-precreate-present",
      "wired_in_npm_test": false
    },
    {
      "filename": "workflow-registry-canonical.mjs",
      "purpose": "workflow-registry-canonical.mjs — the gate private/specs/workflows/workflow_registry.json",
      "wired_in_npm_test": false
    },
    {
      "filename": "zero-deviation-mandate.mjs",
      "purpose": "zero-deviation-mandate — Constitution §0.5 enforcement.",
      "wired_in_npm_test": false
    },
    {
      "filename": "zero-hand-authored.mjs",
      "purpose": "Gate: zero-hand-authored  (§0.46 Zero Hand-Authored Surfaces)",
      "wired_in_npm_test": false
    }
  ]
}