{
  "repo_root": "/home/runner/work/app/app",
  "taken_at": "2026-08-20T04:57:59.552Z",
  "engine_version": "0.1.0",
  "constitution_version": "1.1",
  "documents": [
    {
      "number": "00",
      "filename": "00-INDEX.md",
      "title": "KYE Protocol™ — Constitution Index",
      "status": "Adopted 2026-05-29",
      "section_count": 7,
      "sha256": "3856b38fdd2375417688626a3bd0d7ea5dd4ba305d109f98ca001ee02e76a423"
    },
    {
      "number": "01",
      "filename": "01-NAMING.md",
      "title": "KYE Protocol™ — Naming, Rails & Surfaces Lock (v1.0)",
      "status": "locked",
      "section_count": 20,
      "sha256": "d38c77e503c07dd15f33fa3990ca5ac704071583962299aa903a8010d26e3cee"
    },
    {
      "number": "02",
      "filename": "02-INFORMATION-ARCHITECTURE.md",
      "title": "KYE™ Information Architecture (v1.0 — locked blueprint)",
      "status": "locked",
      "section_count": 15,
      "sha256": "acf29890e07c4e4c8159b35cbe47bf4aefd4c2bda75d8fd277614d56fafaa125"
    },
    {
      "number": "03",
      "filename": "03-DESIGN-MIGRATION.md",
      "title": "KYE™ Design-System Migration — multi-week plan",
      "status": "locked",
      "section_count": 4,
      "sha256": "2c867dd851ba51ef83b0b33ce865299a08d138007c4f03335639135020d13b58"
    },
    {
      "number": "04",
      "filename": "04-DESIGN-SYSTEM.md",
      "title": "KYE™ Design System Reference — Portable Kit",
      "status": "locked",
      "section_count": 14,
      "sha256": "bfd788d0b55b43da9cc791a536040ed0fdf9b84cda0933eacca3b724cd93584b"
    },
    {
      "number": "05",
      "filename": "05-GITHUB.md",
      "title": "GitHub Constitution",
      "status": "locked",
      "section_count": 12,
      "sha256": "d437a5ad4619c71a4459e03940643c8f5fbd2f97e40ae5a68ed61dc72721a6d3"
    },
    {
      "number": "06",
      "filename": "06-WEBSITE.md",
      "title": "Website Constitution",
      "status": "locked",
      "section_count": 14,
      "sha256": "f4098bdc8031a8fa9998732538bb9a7a982756e8d06c59c648d52fba1e0bfb95"
    },
    {
      "number": "07",
      "filename": "07-SUBDOMAIN.md",
      "title": "Subdomain Constitution",
      "status": "locked",
      "section_count": 12,
      "sha256": "4696bdf5087905691540f3ae1173b35969fcb1e464b002973748da0e621eeb3f"
    },
    {
      "number": "08",
      "filename": "08-APPS-DASHBOARDS.md",
      "title": "Apps & Dashboards Constitution",
      "status": "locked",
      "section_count": 13,
      "sha256": "8f0bad7a5ef61ef6e10e45511877fe3c458ab0151873d6d434f21a131c08a95d"
    },
    {
      "number": "09",
      "filename": "09-WIDGETS.md",
      "title": "Widgets Constitution",
      "status": "locked",
      "section_count": 11,
      "sha256": "4297aa4d58fa3992f80226b11ba9781e6c0403e042da968a4cc68e0879da7abd"
    },
    {
      "number": "10",
      "filename": "10-PARTNER.md",
      "title": "Partner Constitution",
      "status": "locked",
      "section_count": 11,
      "sha256": "256c2860cd3fed882d45e64426119decaa193b8192c745abc38fea40cf9f87ff"
    },
    {
      "number": "11",
      "filename": "11-CONTENT.md",
      "title": "Content Constitution",
      "status": "locked",
      "section_count": 13,
      "sha256": "a8c1b49da6eb7c1620791c50f01d224de3b9cf6e0cc96ba05eab03cc9606ff16"
    },
    {
      "number": "12",
      "filename": "12-PURPOSE-PERMISSION.md",
      "title": "KYE Protocol™ — Purpose & Scope Rail · Purpose Permission™ (v1.0)",
      "status": "locked",
      "section_count": 11,
      "sha256": "788c23d1864673113366afc21722e606b567a077df3b8130169f45490645bebb"
    },
    {
      "number": "13",
      "filename": "13-RESILIENCE-LOOP.md",
      "title": "KYE Protocol™ — Evidence & Replay Rail · Resilience Loop™ (v1.0)",
      "status": "locked",
      "section_count": 17,
      "sha256": "a1b2d08bc02867c1394dd07cf2d36d95f1459c879f8b985983b7a1c3f83e4de8"
    },
    {
      "number": "14",
      "filename": "14-AGENTS-AND-ENGINES.md",
      "title": "KYE Protocol™ — Agents & Engines (v1.0)",
      "status": "locked",
      "section_count": 12,
      "sha256": "562caf1fb992b8ef6c5da63a6212f6410732f45b2934a98216bca72426258b73"
    },
    {
      "number": "15",
      "filename": "15-MCP-AND-SDK.md",
      "title": "KYE Protocol™ — Developer Surface · KYE™ MCP Server / KYE™ MCP Gateway / KYE SDK™ / KYE Conformance Pack™ (v1.0)",
      "status": "locked",
      "section_count": 19,
      "sha256": "8b83c879c30b2efc5e8468071ff10451eacd73179fc8bb5946814758a9c26cb9"
    },
    {
      "number": "16",
      "filename": "16-EDGE-RUNTIME.md",
      "title": "KYE Protocol™ — Edge Runtime · Cloudflare-Native Topology (v1.0)",
      "status": "locked",
      "section_count": 14,
      "sha256": "13883ebf0f70497c3d6c4df5e88cfe9cbdca158acbcaeb9afea8aa0b8c49ff83"
    },
    {
      "number": "17",
      "filename": "17-DIRECTORY-SEARCH.md",
      "title": "KYE Protocol™ — Directory Rail · Directory Search™ (v1.0)",
      "status": "locked",
      "section_count": 12,
      "sha256": "6f398af61e8c51c677f865de8ffd2164567912c2b13d48f9dbc1eb36bfa2fea0"
    },
    {
      "number": "18",
      "filename": "18-OPERATING-MODEL.md",
      "title": "KYE Protocol™ — Operating Model Rail · Operating Model™ (v1.0)",
      "status": "locked",
      "section_count": 14,
      "sha256": "973717a95a78715c511161edcae0f06b1ec8e1d5b9aeea38274dc5df603f8cd5"
    },
    {
      "number": "19",
      "filename": "19-WIDGETS-EXPANDED.md",
      "title": "KYE Protocol™ — KYE Partner Widgets™ Catalogue (v1.2)",
      "status": "locked",
      "section_count": 10,
      "sha256": "a582abb830a75ab717795329880aea312ab220ca1ddcb416fab6e224e914d6d9"
    },
    {
      "number": "20",
      "filename": "20-ANALYTICS-PLANE.md",
      "title": "KYE Protocol™ — Analytics Plane Lock (v1.0)",
      "status": "locked",
      "section_count": 15,
      "sha256": "4a672807efa4f0d7425ce9d0f8765acd9289c7d440503edf2b649ef8724b46e3"
    },
    {
      "number": "21",
      "filename": "21-DELEGATED-AUDITABILITY.md",
      "title": "KYE Protocol™ — Delegated Auditability Rail · Audit Pilot™ (v1.0)",
      "status": "locked",
      "section_count": 16,
      "sha256": "4bf90e3557215c4aecc832274110b91cc6ac6ed894ce8ef0423d3364dd704f83"
    },
    {
      "number": "22",
      "filename": "22-ONBOARDING.md",
      "title": "KYE Protocol™ — Onboarding Rail · KYE Onboarding Agent™ (v1.0)",
      "status": "locked",
      "section_count": 15,
      "sha256": "d5a458772af08ae191cff5746e739fd8b4374b82f2cb524c620adc8ff3c90fd2"
    },
    {
      "number": "23",
      "filename": "23-BILLING-METERING.md",
      "title": "KYE Protocol™ — Billing & Metering Rail · KYE Billing Meters™ (v1.0)",
      "status": "locked",
      "section_count": 15,
      "sha256": "63d6d51aa2d0a795c9bc24c4fde9bfdc5f7b959d5eeb6f93e44f7a7fe0314ec6"
    },
    {
      "number": "24",
      "filename": "24-DESIGN-DICTIONARY.md",
      "title": "Constitution §24 — Design Dictionary",
      "status": "locked",
      "section_count": 17,
      "sha256": "16dc6e4278cde6b8fdab864f0a42ace24cab297f287dc9c61da00c8d12aa2946"
    },
    {
      "number": "25",
      "filename": "25-EDGE-GOVERNANCE.md",
      "title": "Constitution §25 — KYE Edge Governance™ Rail",
      "status": "locked",
      "section_count": 11,
      "sha256": "02be10644d582f4a09d21e46d9f0128765e2c14b134a0079db1961e2e97e1ad9"
    },
    {
      "number": "26",
      "filename": "26-COMMERCIAL.md",
      "title": "Constitution §26 — Commercial Rail (SKU catalogue + closed-registration disclosure)",
      "status": "locked",
      "section_count": 14,
      "sha256": "e968335d8b16209a8d34cc7041e1318f169c7e9a15f696252e9b00dcb29d2454"
    },
    {
      "number": "27",
      "filename": "27-COMMERCIAL-LIFECYCLE.md",
      "title": "Constitution §27 — Commercial Lifecycle + Dual-Channel Admin + Payment-Gate",
      "status": "locked",
      "section_count": 15,
      "sha256": "0fe2e52eb2f00b3dd09f5f47570fd48cd391768625a3f14d0ebc56cfbd108557"
    },
    {
      "number": "28",
      "filename": "28-CKAN-OPEN-DATA.md",
      "title": "Constitution §28 — CKAN connector + Open Data Portal Rail",
      "status": "locked",
      "section_count": 15,
      "sha256": "df2cce2f36c5a3be5ed384b7b57cd47ac854097aee16761ca7639d42b95970d7"
    },
    {
      "number": "29",
      "filename": "29-PROFILES-LITE.md",
      "title": "Constitution §29 — Profiles-Lite + Rule Packs + Dictionaries + Rules Gateway",
      "status": "locked",
      "section_count": 12,
      "sha256": "24892f80dd0869e0e12efba5d27131e010046a81e6f5aaf9a7042f9b1b52c77d"
    },
    {
      "number": "30",
      "filename": "30-AUDIT-WORM-RETENTION.md",
      "title": "Constitution §30 — Audit WORM + Retention",
      "status": "locked",
      "section_count": 10,
      "sha256": "14bbc06e5fa163d0850b792ae9298408c9152a0a78ff79664acf83cca838c143"
    },
    {
      "number": "31",
      "filename": "31-DATA-GOVERNANCE-PACK.md",
      "title": "Constitution §31 — KYE Data Governance Pack™",
      "status": "locked",
      "section_count": 11,
      "sha256": "b1fb8fbbdeac870b556a5bb41f1142f957f10335fa35913fbfb90790008a2033"
    },
    {
      "number": "32",
      "filename": "32-AGENT-DEV-KIT.md",
      "title": "Constitution §32 — KYE Agent Dev Kit™",
      "status": "locked",
      "section_count": 9,
      "sha256": "245a586921ff22ab0b2a04bff052dbd1f6721653dc8181714ad65f514ab9728d"
    },
    {
      "number": "33",
      "filename": "33-IP-OSS-LINE.md",
      "title": "Constitution §33 — IP/OSS Line (the patent-safety / open-source split)",
      "status": "locked",
      "section_count": 10,
      "sha256": "0600bbfd988d270a2e5614ca8df90b44d86fd8d781c64a3bf4903d572e04a17e"
    },
    {
      "number": "34",
      "filename": "34-RECONCILIATION-ENGINE.md",
      "title": "Reconciliation Engine™",
      "status": "locked",
      "section_count": 16,
      "sha256": "52118e28e774a2b537ebaa38f35873bb926a2cedd7a26f02d5ca89fc141efda8"
    },
    {
      "number": "35",
      "filename": "35-STREAMING-LOGS.md",
      "title": "Streaming Logs Contract™",
      "status": "locked",
      "section_count": 6,
      "sha256": "4388e84e24442fd48ff269722598de73ff81acb2a722c6c233f2bf0cc60130cc"
    },
    {
      "number": "36",
      "filename": "36-GOVERNEDUI.md",
      "title": "KYE GovernedUI™",
      "status": "locked",
      "section_count": 12,
      "sha256": "568b1ffdda10bbecbc9156578d5db9ddec6355b4c88d79e749a49be178e187a3"
    },
    {
      "number": "37",
      "filename": "37-EVENT-ENGINE.md",
      "title": "37 — KYE Event Engine™",
      "status": "locked",
      "section_count": 11,
      "sha256": "4e019faab3103bcd7dfc821d4ba5bd02f2fa5f362d9cee5880ad4fbbd85e8285"
    },
    {
      "number": "38",
      "filename": "38-COMMS-RAIL.md",
      "title": "38 — Comms Rail · KYE Comms Engine™",
      "status": "locked",
      "section_count": 16,
      "sha256": "4ddd5f94224673bcb762c7392efacb61e0bae73ee4d17c53ff6f78c286ce7e57"
    },
    {
      "number": "39",
      "filename": "39-LEARN-RAIL.md",
      "title": "39 — Learn Rail · KYE Learn™",
      "status": "locked",
      "section_count": 8,
      "sha256": "5b5e4ca63a2c04797414bbdd58cf0af0a820eea20aeb2fc1c6e40ab51fc73b39"
    },
    {
      "number": "40",
      "filename": "40-IMPLEMENTATION-CANONICAL.md",
      "title": "40 — Implementation Canonical · KYE Implementation Registry™",
      "status": "locked",
      "section_count": 10,
      "sha256": "6769af0ff3c94fe6f75e011a55590dc9586d8d32b4d0b7842fb63cd6dabcd49c"
    },
    {
      "number": "41",
      "filename": "41-ERROR-HORIZONS.md",
      "title": "41 — Error Horizons · push, then convert-to-rule",
      "status": "locked",
      "section_count": 9,
      "sha256": "bd9f32de7c18422b19ab61d09dd3d8f476391662415de115cbba60ce1c811a8c"
    },
    {
      "number": "42",
      "filename": "42-CONSTITUTION-KIT.md",
      "title": "42 — Constitution Kit · the enforcement toolkit of software/constitution™",
      "status": "locked",
      "section_count": 12,
      "sha256": "12df620c5caeca035c230171a85d9935a174e481024fe5fc9cd15a36fb6a0116"
    },
    {
      "number": "43",
      "filename": "43-MACHINE-READABLE-BY-DEFAULT.md",
      "title": "43 — Machine-Readable by Default",
      "status": "locked",
      "section_count": 10,
      "sha256": "a194b01a6675db804f65c8acc7abef14a8045fcdc0f40f5bf37b87a3d69e2bba"
    },
    {
      "number": "44",
      "filename": "44-LIVENESS-ENGINE.md",
      "title": "44 — KYE Liveness Engine™ · functional-liveness verification",
      "status": "locked",
      "section_count": 10,
      "sha256": "7b990704c325ff420486956164f7e46556cc45d07216b3b31583c0ddc1427bec"
    },
    {
      "number": "45",
      "filename": "45-SELF-DESCRIPTION-GATE.md",
      "title": "45 — The Self-Description Gate",
      "status": "locked",
      "section_count": 11,
      "sha256": "de1be125a1e0411edc2463aeae99a490610fbc742344b2a45acd35ab6bee932a"
    },
    {
      "number": "46",
      "filename": "46-FLOW-CONTRACTS.md",
      "title": "46 — Flow Contracts",
      "status": "locked",
      "section_count": 10,
      "sha256": "d241f236c781e5997624b2fc0bf9e2f9bff65cd1a920cf30a7c51b2927f56057"
    },
    {
      "number": "47",
      "filename": "47-CANONICAL-EVERYTHING.md",
      "title": "Canonical Everything — every concept has manifest + dictionary + schema (v1.0)",
      "status": "locked",
      "section_count": 6,
      "sha256": "443e0b95d3d5c9a5701125e6c81f8e33784415e68d88287710044bfe6da9409c"
    },
    {
      "number": "48",
      "filename": "48-SIGNAL-INGEST-CONTRACT.md",
      "title": "48 — Signal Ingest Contract · the wake-up half of §41",
      "status": "locked",
      "section_count": 7,
      "sha256": "01be9682cec3bb61894b08679b0ee860d5422111542a12c2015cf110e4cbd7c5"
    },
    {
      "number": "49",
      "filename": "49-UNIVERSAL-ENGAGEMENT-RAIL.md",
      "title": "49 — Universal Engagement Rail · one canonical surface for every external party",
      "status": "locked",
      "section_count": 13,
      "sha256": "cacc2a680a381a5c64bfb4e61cf28fcb8bf8701610eead819cf150879a95d694"
    },
    {
      "number": "50",
      "filename": "50-CONTENT-GRAPH-DISCOVERABILITY.md",
      "title": "50 — Canonical Content Graph + Derived Discoverability",
      "status": "locked",
      "section_count": 7,
      "sha256": "5cc214b9f9fce208c830d014efa4d05acc2c7705e7b60b4c3d3fe1852e950776"
    },
    {
      "number": "51",
      "filename": "51-NO-SPOF.md",
      "title": "51 — No Single Point of Failure · the operational counterpart of §0",
      "status": "locked",
      "section_count": 9,
      "sha256": "c9753382c2a7c419e4ad5830bce67ed25ea3ab14f3b96da9dc435398d8d977b0"
    },
    {
      "number": "52",
      "filename": "52-DELEGATED-AGENT-BINDING.md",
      "title": "52 — Constitutional Binding of Delegated Agents · subagents · MCP servers · external tool calls",
      "status": "locked",
      "section_count": 15,
      "sha256": "4c855ea5eb6f1056d5c9c40b060f9d2bf847d58901e807f41788d85928a85ba7"
    },
    {
      "number": "53",
      "filename": "53-COHESION-CASCADE.md",
      "title": "53 — Cohesion Cascade · the repo is a single coherent state, every change ripples coherently throughout",
      "status": "locked",
      "section_count": 14,
      "sha256": "3b6e8661b2141ca051462094d98af539662e2b16cd7f341f7f31c78e474bf464"
    },
    {
      "number": "54",
      "filename": "54-SECTOR-PACK-FOUNDRY.md",
      "title": "54 — KYE Sector Pack Foundry™ · productisation rail for expert governance frameworks",
      "status": "locked",
      "section_count": 16,
      "sha256": "4c36735cf762e957ab0c62e2fa38f060d01792c4600101efb8bdfbff4b96408e"
    },
    {
      "number": "55",
      "filename": "55-EXECUTION-LAYERS-ARCHITECTURE.md",
      "title": "§55 — Execution Layers Architecture (KYE State Engine™ + 10-Layer Stack)",
      "status": "locked",
      "section_count": 10,
      "sha256": "f2534dcb244443ef31fe46dded187f7e6abf857f40331efface39eb565232449"
    },
    {
      "number": "56",
      "filename": "56-N-M-RELATIONSHIPS.md",
      "title": "56 — Canonical N:M Relationships · the relationship root, many projections",
      "status": "locked",
      "section_count": 8,
      "sha256": "f97888c479ba07850ae2b0cb4c9d140e0a817c8398fbc7ebf15c66997ac3eb09"
    },
    {
      "number": "57",
      "filename": "57-CROSS-JURISDICTION-HANDOFF.md",
      "title": "57 — Cross-Jurisdiction Handoff Rail · regulatory acts that cross borders",
      "status": "locked",
      "section_count": 8,
      "sha256": "0847b341c4afe739edf69fe266c844ffb0a83bf15a3299f52e43b12d2d60f4b0"
    },
    {
      "number": "58",
      "filename": "58-GOVERNED-PROMPTS.md",
      "title": "58 — KYE Governed Prompts™ · the prompt is an authority act",
      "status": "locked",
      "section_count": 8,
      "sha256": "2484a62a1e46a91f25c62c5ee4e472c5e13d5210965112126eba9c7089a99af6"
    },
    {
      "number": "59",
      "filename": "59-FRAMEWORK-INGESTION.md",
      "title": "59 — KYE Framework Ingestion Engine · deterministic, no-LLM, replay-proof",
      "status": "locked",
      "section_count": 8,
      "sha256": "6f06460bc63b38f3e3d86798233a22f06d541ee4d7932dc9dcb8939a04b7f847"
    },
    {
      "number": "60",
      "filename": "60-AUTHORITY-AS-CODE.md",
      "title": "60 — KYE Authority-as-Code™ + Authority Harness™ · programmable primitives, deterministic finality",
      "status": "locked",
      "section_count": 9,
      "sha256": "e8f778ead28f430c06a95880ef3313ba4a27f1d0103a4c1ce5c52b724a11f21c"
    },
    {
      "number": "61",
      "filename": "61-RIGHTS-DISPUTES-DISCLOSURE-RAIL.md",
      "title": "61 — KYE Rights, Disputes & Disclosure Rail™",
      "status": "locked",
      "section_count": 8,
      "sha256": "cdb18272fd3bec7009fe4e5799fb1afa495e86d3b0d2270b161157d695de2efb"
    },
    {
      "number": "62",
      "filename": "62-GOVERNED-RESEARCH-RAIL.md",
      "title": "62 — KYE Governed Research Rail™ · publisher of authority and authority for publishing",
      "status": "locked",
      "section_count": 15,
      "sha256": "9cea775352eac326131b59bb66908a886e18717a6419c78ec2f9b3d1bf691d2b"
    },
    {
      "number": "63",
      "filename": "63-MEMORY-AUTHORITY-RAIL.md",
      "title": "63 — KYE Memory Authority Rail™ · agent memory as authority-bearing state",
      "status": "locked",
      "section_count": 12,
      "sha256": "79710e15e437653e9955f044aa9f5b5c202bbd3b3fea6f52112d50db150b5fe9"
    },
    {
      "number": "64",
      "filename": "64-OBLIGATION-AUTHORITY-RAIL.md",
      "title": "64 — KYE Obligation Authority Rail™ · obligations as the governed spine",
      "status": "locked",
      "section_count": 7,
      "sha256": "81354394bf0798afd19c018df817ad94a0e1c8819ca39539136e1a00e94f2613"
    },
    {
      "number": "65",
      "filename": "65-UPDATES-RAIL.md",
      "title": "65 — KYE Updates Rail™ · one feed, the bell, and every announcement",
      "status": "locked",
      "section_count": 8,
      "sha256": "8c55f166cd1b02bb100407d5b26a6ab371eb74eb63a77f66cc3f0fb7cb9e3d27"
    },
    {
      "number": "66",
      "filename": "66-CERTIFICATES-RAIL.md",
      "title": "66 — KYE Certificates Rail™ · the catalog of certificate programs",
      "status": "locked",
      "section_count": 6,
      "sha256": "2dccabf4bc5f9c26fef9be849a10b2e3c376676164c01c7fc4fb2ea1dbb25c4b"
    },
    {
      "number": "67",
      "filename": "67-MODEL-GOVERNANCE-RAIL.md",
      "title": "67 — KYE Model Governance Rail™ · AI-BOM & the Chain of Authority",
      "status": "locked",
      "section_count": 6,
      "sha256": "7a62677fdc99e593c871e84526c69043e972b96dd0a95330901bccbe77f1dfad"
    },
    {
      "number": "68",
      "filename": "68-SECTOR-PRODUCT-RAIL.md",
      "title": "68 — KYE Sector Product Rail™ (Total Productisation Fan-Out)",
      "status": "locked",
      "section_count": 6,
      "sha256": "54fecbccd26366db3fc0255daf26485b0d70a46dd733e3c61546ea4fabe446a5"
    },
    {
      "number": "69",
      "filename": "69-CONTROL-PLANE-MCP.md",
      "title": "69 — KYE Control-Plane MCP™ · the governed inbound operator surface",
      "status": "locked",
      "section_count": 9,
      "sha256": "7aff48f6274064b512ab85e7ff460ba56bb9f587809eb38e9e9e5bf2a5b36637"
    },
    {
      "number": "70",
      "filename": "70-FRAMEWORK-MAPPING-RAIL.md",
      "title": "70 — KYE Framework Mapping Rail™ · the canonical, registry-first deep-mapping track",
      "status": "locked",
      "section_count": 9,
      "sha256": "05eb498972a1f0b343a8a1da23da44371c923106bc30b46e7a28d57ee8712d8c"
    },
    {
      "number": "71",
      "filename": "71-DOCUMENT-INTELLIGENCE-RAIL.md",
      "title": "71 — KYE Document Intelligence Rail™ · navigating, retrieving & citing unstructured documents",
      "status": "locked",
      "section_count": 12,
      "sha256": "c69437b1f23025e18f9827c2f329ed6e445654d271a9fad5591ae7c081333b7d"
    },
    {
      "number": "72",
      "filename": "72-JURISDICTION-DATA-SOVEREIGNTY.md",
      "title": "72 — KYE Jurisdiction & Data-Sovereignty Authority · geography as a first-class dimension of admissibility",
      "status": "locked",
      "section_count": 9,
      "sha256": "902f4fc233d4c7c9ecf33237a3b1699d2c68a35139ef359b33f062c9b2b8f8d2"
    },
    {
      "number": "73",
      "filename": "73-CONTROL-PLANE-INTEROP.md",
      "title": "73 — KYE Control-Plane Interoperability Profile™ · external planes in, KYE decides, planes enforce",
      "status": "locked",
      "section_count": 8,
      "sha256": "d52260e5681ee261bd4fc586e9d2065279af014c653f5a1efccc14e8877126fe"
    },
    {
      "number": "74",
      "filename": "74-TAXONOMY-RAIL.md",
      "title": "74 — KYE Taxonomy Rail™ · the component-graph taxonomy, dogfooded on KYE's own primitives",
      "status": "locked",
      "section_count": 8,
      "sha256": "555bd15803a80ab622861b3927477aeb33201801a2848c28819af9893f7dde9e"
    }
  ],
  "deviations": {
    "active": [],
    "historical_count": 12,
    "sha256": "b10540573203cc1ff3dbea50edf280a601397b9b8dadae202e33e026a9dc63d0"
  },
  "decay_windows": {
    "active": [
      {
        "title": "§0.49 — the entity-class list is hand-copied per schema instead of derived from the canonical id-grammar (registered 2026-08-13, decay_deadline: 2026-11-11)",
        "closure_date": null,
        "gate_path": null,
        "body": "**Owner:** platform\n\n`private/specs/identity/id-grammar.json` declares 588 canonical id classes and is\nthe source of truth for what a KYE-ID may be. No schema derives from it. Instead,\n\"which entity classes may hold or confer authority\" is written out by hand at each\npoint of use, and the copies had already diverged:\n\n```\nkye.authority.grant.v1   ^kye:(ent|prin|org|system|agent|board-member):…      × 4 fields\nkye.purpose_manifest.v1  ^kye:(agent|ent|prin|org|system|board-member):…      × 1 field\n```\n\nNeither admitted `person` or `principal`, both of which ARE valid classes in the\ngrammar and both of which are declared as holders by canonical decision rights\n(`kye:person:acme-bank.cro`, `kye:principal:northwind-bank:jordan-reyes`,\n`kye:principal:acme:human:finance-controller`). The authority issuer refused to\nwrite those records — correctly, against a contract that was itself wrong.\n\nHalf-closed on 2026-08-13: the four copies inside `kye.authority.grant.v1` are\ncollapsed into one `$defs/principalId` and `$ref`'d, so a widening can no longer\nland in three fields and miss the fourth, and both lists were widened to the\nclasses measured in use. **The mechanism is untouched:** the list is still\nauthored by hand, still duplicated across two schemas, and still cannot be\nchecked against the grammar it is supposed to project.\n\nTwo things must happen to close this:\n\n1. **Derive, don't author.** The principal-class pattern becomes a generated\n   artefact of `id-grammar.json` (the §0.20 generate-then-verify shape every other\n   derived artefact already uses), so a class added to the grammar cannot be\n   invisible to the schemas, and a schema cannot admit a class the grammar does\n   not declare.\n\n2. **Resolve the duplicate concepts first**, because generating from the grammar\n   as it stands would enshrine them. Measured across `private/specs`:\n   `kye:ent:` 134 files · `kye:prin:` 19 · `kye:principal:` 8 · `kye:person:` 4.\n   `prin`/`principal` and `ent`/`person` read as two spellings of one concept\n   each — the §0 shape, in the identity grammar itself. Deciding which is\n   canonical is an amendment, not a codemod, and it must precede step 1."
      },
      {
        "title": "§0.43 — a class registry is validated against its ITEM contract, so no row-level defect can surface (registered 2026-08-13, decay_deadline: 2026-11-03)",
        "closure_date": null,
        "gate_path": null,
        "body": "**Owner:** platform\n\n`scripts/validate-schemas.js` pairs every class registry with the contract it\ndeclares, resolved through the §0.51 admission matrix, then runs\n`validate(doc)` where `doc` is the **whole registry document**. For a registry\nwhose declared contract describes a **single instance**, that is a category\nerror: the registry object carries `registry_id`, `display_name`, `version`,\n`decision_rights[]` and so on, none of which the item contract declares, so the\npair fails structurally on the first `additionalProperties` error and every\ngenuine row-level violation inside it is invisible.\n\nMeasured on `origin/main` 2026-08-13:\n`private/specs/decision-rights/decision-right-registry.json` declares\n`kye.decision_right.v1.json`, which sets `additionalProperties: false`, and two\nof its rows carry undeclared fields — `grant_term_note` and `sod_note`. Both\nhave been live and both validated, because the pair was already counted as one\nnonconformance in the decreases-only `registry_schema_nonconformant` ratchet for\nan unrelated structural reason. The ratchet was measuring the category error, not\nthe data.\n\nThose two fields are now declared, so that instance is closed. **The mechanism is\nnot**: any other class registry whose declared contract is an item schema has the\nsame blind spot, and the count of such pairs has never been measured.\n\nClosing this means changing how a class registry resolves and applies its\ncontract — validate `registry[instances_key][]` against the item contract when\nthe admission matrix declares an `instances_key`, and reserve whole-document\nvalidation for registries whose contract really is a document schema. That is a\nchange to the shared pairing convention in `scripts/validate-schemas.js`, not a\nper-registry fix, and it must land with the re-measured\n`registry_schema_nonconformant` ceiling in the same change-set — the number will\nmove in both directions (structural false-failures disappear, real row defects\nappear) and only the combined figure is honest."
      },
      {
        "title": "§0.29 — the regional residency Workers were declared but never built (registered 2026-08-13, decay_deadline: 2026-11-11)",
        "closure_date": null,
        "gate_path": null,
        "body": "**Owner:** platform-ops\n\n`kye-residency-router-{eu,uk,us}` sat in the deploy matrix pointing `main` at\n`private/runtime/data-residency-router/src/index.ts` — the barrel of the\n`@kye/data-residency-router` LIBRARY, which exports policy functions and no\nWorker handler. Wrangler therefore treated the script as service-worker format\nand rejected the D1 binding on every run:\n\n```\nBinding 'DB_EU' of type 'd1' requires a Worker written in ES module format. [code: 100329]\n```\n\nMeasured 2026-08-13 against the live account: 121 Workers, **none** a residency\nrouter. These never deployed. `private/specs/estate/deployed-estate.json` had\nalready recorded that correctly (`lifecycle_stage: \"dead-end\"`, *\"Declared in the\nrepo; the provider of record does not have it\"*) — the estate reconciler was\nright and nothing acted on it, so the job failed daily and the failure became\nbackground noise.\n\nRemoved from the deploy matrix rather than given a stub entry point, because\nwriting one would have created a second residency implementation beside\n`private/runtime/gateway-worker/src/middleware/data-residency.ts`, which already\nenforces residency (§0). No capability is lost — none ever existed.\n\n**What remains open, and why this is a window rather than a fix:** whether\nregion-pinned residency Workers *should* exist is a design decision with\ncompliance weight (the configs cite GDPR Ch. V, DORA Art. 28, Schrems II). The\nthree `regional-bindings/wrangler.{eu,uk,us}.toml` files stay as the ONLY on-disk\nrecord of the provisioned D1/KV/R2 ids — `private/specs/regional-data-plane/manifest.json`\ncarries the resource *names* but not the ids, so deleting them would lose real\nprovisioning state. Decide by the deadline: build the Workers, or fold the ids\ninto the manifest and retire the configs.\n\nThe class is closed regardless: `edge-binding-coverage` half 5 now hard-fails any\ndeploy-matrix target whose `main` is missing or exports no Worker handler, so\nthis cannot be re-introduced silently."
      },
      {
        "title": "§0.44 — `color-canonical` ran advisory at tier \"blocking\"; 270 inline hex + 146 inline `px` font-sizes accumulated behind it (registered 2026-08-12, decay_deadline: 2026-09-15)",
        "closure_date": null,
        "gate_path": null,
        "body": "**Owner:** design-system\n\n`scripts/gate-manifest.json` declared `test:color-canonical` at `tier: \"blocking\"`\nwhile `package.json` invoked it as `color-canonical.mjs --advisory`. Measured\n2026-08-12: exit 0 with the flag, exit 1 without. The manifest said the build\nstops; the command guaranteed it never would — the §0.44 hollow-claim shape. The\ngate was wired and ran on every `npm test`, printed its findings, and could not\nfail, so the debt below accumulated in full view of a signal nobody could trip.\n\nSame change-set closes the *class*: `gate-manifest-fresh` check 2d now hard-fails\nany `tier: \"blocking\"` step whose npm script carries an exit-neutering flag\n(`--advisory`, `--warn-only`, `--soft`, `|| true`, `; exit 0`). Exactly two steps\nviolated it — this one and `test:check-canonical-references` — and both are now\ndeclared `tier: \"consistency\"`, which is the true statement of their behaviour.\nRe-tiering is behaviour-neutral: `run-gates.mjs` filters by tier only under\n`--tier`, so both still run in the default `npm test` chain.\n\nWhat remains, and why it is a window rather than a fix in the same change-set:\n\n| class | measured | notes |\n|---|---|---|\n| inline-style hex/rgb | 270 (was 274; 4 rewritten losslessly) | strict-zero CEO directive 2026-06-16 |\n| inline `font-size` `px` | 146 | regression against the 36 floor set 2026-06-17 |\n| inline `font-size` `clamp()`/`em` | ~46 | recorded as intentionally exempt in the `html_inline_font_size` history |\n\n197 of the 270 hex and 117 of the 146 `px` sit in four standalone pages under\n`public/sdk-domains/` (`agenticopenfinance`, `agenticislamicfinance`,\n`agentmemorysdk`, `agentpaymentsdk`), each carrying its own\n`:root{}` palette — a second colour source-of-truth beside\n`design-system/tokens/color.json`, which is the actual §0 defect. Those pages do\nnot link `public/site/assets/css/tokens.css`, so rewriting their literals to\n`var(--type-N)` / `var(--token)` would resolve to nothing and break rendering on\nfour live external domains. Closing this needs a design decision — adopt the\ncanonical palette (visible redesign) or register these palettes in\n`design-system/tokens/color.json` and generate the block (values unchanged) —\nwhich is the owner's call, not a mechanical rewrite.\n\nRaising `html_inline_font_size` from 36 to 195 was considered and REJECTED: the\nfloor has a recorded 823 → 36 tokenization history and the excess is regression,\nnot new intentional bespoke work. Blessing it with a signed override would make\nthe ratchet lie in the same way the tier did."
      },
      {
        "title": "§0.9 — 90 Worker env reads are declared nowhere, 38 of them signing keys (registered 2026-08-02, decay_deadline: 2026-11-02)",
        "closure_date": null,
        "gate_path": null,
        "body": "**Owner:** platform-ops\n\n**Found 2026-08-02, by the invariant added in the same change-set.**\n`edge-binding-coverage` had two halves — locked bindings, and the Pages-project\nbijection. Neither looked at a **Worker's own** `env.X` reads. So a Worker could\nread a binding declared in no `wrangler.toml` and in no registry, be deployed,\nand every gate in the repo reported clean.\n\n**The instance that matters, and it is on the §13 critical path.** `kye-pdp`\nreads `env.PDP_SIGNING_KEY_SEED_HEX` — the Ed25519 seed that signs\n`decision_map_jws`, the detached signature the entire Replay-Proof™ claim rests\non. It was declared in neither its `wrangler.toml` nor\n`private/specs/secrets/secrets_registry.json`, so the deployed Worker took its\ndocumented fallback: a **random per-cold-start seed** whose `kid` is prefixed\n`ephemeral:` and appears in **no published JWKS**\n(`public/site/trust/self-audit-jwks.json` carries four keys, none of them a PDP\ndecision-map key). The signature was produced, returned, and — as of the\npreceding change-set — stored. It was verifiable by nobody outside the isolate\nthat made it. The same Worker reads `env.AUDIT_CHAIN_BASE_URL`, which the\nregistry declared for fifteen Workers, none of them the PDP, so\n`kye.evidence.pack.v1` never reached the audit chain, `SEARCH_DELTA_MAP` never\nrouted it, and `search_evidence_packs` was never populated from the decision\npath. **Both are fixed here** (92 → 90).\n\n**What remains (the window).** 90 undeclared reads across 49 Workers, of which\n**38 are signing keys or key ids** — 10 × `ED25519_SK_B64`, 9 ×\n`KYE_SIGNING_SEED_BASE64`, 9 × `KYE_SIGNING_KID`, 3 × `KYE_SIGNING_SK`, 2 ×\n`SIGNING_KID`, plus `SELF_AUDIT_SIGNING_JWK`, `DGP_SIGNING_KEY_PEM`,\n`CERT_SIGNING_KEY_SEED_HEX`, `KYE_CASCADE_ED25519_SEED`,\n`KYE_DISPATCHER_ED25519_SEED`. Measured against a canonical secret registry\nwhose own `counts` read **`\"secrets\": 0`** — the inventory of secrets contained\nno secrets.\n\nThey are **not** fixed in this pass. Each needs a secret-management decision —\nwhich key, whose rotation policy, whether it is already set in the Cloudflare\nsecret store — that cannot be made from the repository alone. Inventing registry\nrows for keys whose real handling is unknown would assert facts about production\nthat nobody in this change-set verified, and §70 forbids that more strongly than\n§0.9 demands the row.\n\n**Mechanically enforced meanwhile:** `worker_env_undeclared` in\n`private/specs/ratchets/baselines.json` is a decreases-only baseline of 90. A\n**net-new** undeclared Worker env read hard-fails — negative-tested by removing\nthe `PDP_SIGNING_KEY_SEED_HEX` row and watching the gate reject at 91. Burn-down\nis tracked by `advisory-deadline-not-expired`, so the ceiling cannot sit flat to\nthe deadline.\n\n**The operator action this does not substitute for.** Declaring the seed in the\nregistry does not *set* it. Until `PDP_SIGNING_KEY_SEED_HEX` is present in the\nCloudflare secret store for `kye-pdp` **and** its derived public key is published\nin the JWKS, decision-map signatures remain unverifiable and the `ephemeral:`\n`kid` prefix is the honest signal that they are."
      },
      {
        "title": "§30 §5 — 10 tables are append-only with no declared retention (registered 2026-08-02, decay_deadline: 2026-10-31)",
        "closure_date": null,
        "gate_path": null,
        "body": "**Owner:** platform\n\n**Found 2026-08-02, by the check added in the same change-set.** `audit-worm-enforced`\nhad only ever asked one direction of a two-way binding: *does every table in\n`private/specs/retention/policy.json` have BEFORE UPDATE + BEFORE DELETE\ntriggers?* It never asked the converse — *does every WORM-triggered table have a\nretention policy?* — so a table could be made immutable with no declared\nretention period and no framework justification, and the gate would report the\nwhole thing clean. That is the §0.43 shape exactly.\n\nThe converse tripped immediately on the change-set that added it: migration 099\ngained `decisions_no_update` / `decisions_no_delete`, making the sealed decision\nappend-only, while the retention policy said nothing about how long a decision is\nkept. **That one is fixed here** — `decisions` now carries a 10-year COMPLIANCE\nrow keyed to EU AI Act Art 12 / DORA Art 28 / SOC 2 CC 6.1 / FINRA 4511, matching\n`evidence_packs` so a decision and its proof never expire apart, with\n`destruction_after_retention: keep_indefinitely` because `decision_map_jws` is\nsigned *over* the row and anonymising any field would destroy the §13\nReplay-Proof™ claim.\n\n**What remains (the window).** Ten tables carry WORM triggers and no policy row:\n`agent_memories`, `data_access_events`, `data_classification_assignments`,\n`dsar_request_status_history`, `dsar_requests`, `report_deliveries`, `reports`,\n`risk_assessments`, `rule_conflicts`, `search_query_log`. They are pre-existing —\nthis change-set did not create them — and they are not fixed in this pass because\neach needs a retention period and framework citation grounded in what the table\nactually holds (`agent_memories` under §63 + GDPR; the DSAR pair under GDPR Art\n12/17; `search_query_log` may well be a case where the *trigger* is wrong rather\nthan the policy missing). Manufacturing forty framework justifications to force a\ngreen would be fabrication, and §70 forbids it more strongly than §30 demands the\nrow.\n\n**Mechanically enforced meanwhile:** `worm_tables_without_retention` in\n`private/specs/ratchets/baselines.json` is a decreases-only baseline of 10. A\nnet-new append-only table with no retention policy **hard-fails** — the case the\nconverse was written for. Burn-down is tracked by\n`advisory-deadline-not-expired`, so the ceiling cannot sit flat to the deadline."
      },
      {
        "title": "§0.29/§0.34 — the consumption stage reads a table nothing writes (registered 2026-08-01, decay_deadline: 2026-10-30)",
        "closure_date": null,
        "gate_path": null,
        "body": "**Owner:** platform\n\n**Found 2026-08-01, in the change-set that created it.** The PDP consumption\nstage decides admissibility against `kye.quota_grant.v1` rows, migration 052\ngives those rows a table, and `resolveQuotasFor()` reads them tenant-scoped.\nEvery piece is real and tested. **In production the table will be empty**,\nbecause no deployed surface can create a quota grant: the only `/v1/quotas`\nendpoints in the repo live in `private/runtime/gateway/`, which is an explicitly\nillustrative reference server backed by an in-memory Map, and the deployed\n`kye-gateway-worker` exposes none.\n\nSo the stage resolves zero rows for every request and admits — correctly, since\nnothing bounds the mandate — but it is not yet enforcing anything in prod. That\nis a declared-not-fed capability, and naming it in a task list rather than here\nis precisely the §41 \"flagged note with neither\" this file exists to prevent.\n\n**Why not closed in the same change-set.** The missing piece is a new public API\n(create / reserve / commit / release, tenant-scoped, API-key authed) whose\nreserve path needs an atomic conditional UPDATE — `WHERE current_consumed +\nreserved + ? <= \"limit\"` — because read-then-write lets two concurrent\nreservations both pass. That needs its own §0.18 quintuple and its own tests;\nfolding it into a decision-path change would ship an unreviewed authority-bearing\nAPI alongside it.\n\n**The tempting wrong fix, named so nobody takes it.** Repointing the reference\ngateway's handlers at D1. That server is a documented Node sandbox with no D1\nbinding; its Map is a design choice, not a hollow runtime.\n\n**Closure.** A deployed quota write surface, at which point this entry is\ndeleted. Until then the honest claim is \"the PDP enforces spend bounds where\ngrants exist\", never \"KYE enforces spend bounds\"."
      },
      {
        "title": "§0.29 — the Reporting Engine has a seal path and no trigger that reaches it (registered 2026-08-12, decay_deadline: 2026-11-10)",
        "closure_date": null,
        "gate_path": null,
        "body": "**Owner:** platform\n\n**Found 2026-08-12, while removing a competing writer to `reports`.** `reports`\nholds **zero rows in production** — checked against the live D1, not inferred.\nTracing every way a row could arrive explains why, and the answer is not the\ncompeting writer that was just deleted:\n\n- `sealReport()` in `private/runtime/kye-reporting-worker/src/worker.ts` is\n  real and complete: build envelope → Ed25519-sign → immutable R2 PUT → WORM\n  INSERT → §0.3 emit. It is the one canonical writer.\n- Its only HTTP door is `POST /v1/reports`, behind `requireEntitlement(\"reports.write\")`\n  — an API key hashed against `api_keys` resolving a tenant, plus an active\n  **paid** SKU carrying that capability. Correct for a metered product, and\n  nothing in KYE's own estate holds such a key.\n- The daily cron is `periodCloseSweep()`, and it does not seal. Its body emits\n  one `report.period_close_sweep` audit event and returns; the walk-frameworks /\n  compute-boundary / seal-per-crossing behaviour its own comment describes is\n  written as a parenthetical, not as code.\n\nSo the engine can seal and is never asked to. That is a declared-not-triggered\ncapability of the same family as the quota entry above: every piece tested, the\ncomposition never exercised in prod.\n\n**Why not closed in the same change-set.** Making the sweep real means deciding\nperiod boundaries per framework cadence against `report_delivery_preferences`,\nsealing one report per crossed boundary per (tenant, framework), and doing it\nidempotently — a second run on the same day must not seal twice. That is an\nauthority-bearing scheduled writer to a WORM table and needs its own tests and\nits own review, not a ride-along on a change that deletes UI.\n\n**The tempting wrong fix, named so nobody takes it.** Minting an API key and a\npaid entitlement for KYE's own tenant so the admin console can call\n`POST /v1/reports`. That fabricates commercial state to make an internal button\nlight up, and the entitlement gate it defeats is the correct behaviour.\n\n**Mechanically enforced meanwhile:** the surface no longer claims otherwise. The\nadmin console's \"Seal report\" affordance is gone, and `/api/v1/reports` is\nGET-only, so an empty table now reads as an empty table rather than as reports\nthe operator was told had sealed.\n\n**Closure.** A period-close sweep that seals, or a deployed trigger that calls\nthe canonical seal path with real entitlement — at which point this entry is\ndeleted. Until then the honest claim is \"the Reporting Engine seals when\ninvoked\", never \"KYE issues periodic compliance reports\"."
      },
      {
        "title": "§0.49 — 133 hand-enumerated corpus lists; the class needs triage, not a blunt ratchet (registered 2026-08-05, decay_deadline: 2026-11-03)",
        "closure_date": null,
        "gate_path": "scripts/gates/implementation-canonical.mjs",
        "body": "**Owner:** platform-ops\n\n**Found 2026-08-05, by fixing one instance and asking how many there are.**\n`SCHEMA_DIRS` in `scripts/validate-schemas.js` was a hand-written array of\ndirectories that decided which schemas the canonical validator loads. All 33\n`<name>.schema.json` files under `private/specs/` carry an absolute `$id` in the\ncanonical namespace exactly as CLAUDE.md's Conventions require — and **none of\ntheir directories was in the list**. Their `$id` resolved nowhere, so 15 of the\n33 registries were failing the schema declared beside them with no failure\nreported anywhere. Fixed in that change-set: membership now derives from the\ndeclared `$id`, and the one-file `ajv.addSchema()` hand-patch that had been\npapering over the same gap was deleted (it announced itself immediately — with\nthe derived loader in place it threw `already exists`).\n\nA scan for the same shape found **133 module-level `*_DIRS` / `*_PATHS` /\n`*_ROOTS` / `*_FILES` list literals across `scripts/`.**\n\n**Why this is registered rather than ratcheted now.** 133 is not 133 defects, and\na decreases-only baseline over that population would manufacture false assurance\nin the opposite direction — the failure mode this repo already knows well. Enumerating\nis legitimate when the list IS the specification:\n\n- `REQUIRED_DIRS` / `REQUIRED_FILES` in `github-shape-canonical` — the repo shape\n  being enforced. The enumeration is the rule.\n- `FRAMEWORK_DIRS` in the sector gates — a declared governing scope, which is\n  what §0.43 asks for, not a narrowing.\n\nThe precise defect is narrower and worth stating exactly, because it is what\nmakes the class detectable: **a hand-written list that decides membership of a\ncanonical class whose artefacts already declare that membership themselves.**\n`SCHEMA_DIRS` qualified — schemas declare `$id`, so membership was already\nderivable and the list silently contradicted 33 of them. A framework list does\nnot qualify: no artefact declares \"I am in this gate's scope.\"\n\n**Closure.** Triage the 133 against that test and split them: (a) derivable from\na declaration the artefacts carry → convert to derivation; (b) the list IS the\nspec → declare it as scope in\n`private/specs/enforcement/enforcer-scopes.json`, which already exists for\nexactly this purpose; (c) genuine bespoke need → allowlist with a reason, the\n`SCAN_SCOPE_ALLOWLIST` precedent in `scripts/gates/implementation-canonical.mjs`.\nOnly after (a) and (b) is the residue a number a ratchet can honestly hold.\n\nThe detector then belongs as a fourth pattern in that gate's existing scan-scope\nsection (which already catches hand-rolled **walkers** via patterns A/B/C) — the\nsame concept one shape over, never a new gate. Building the detector before the\ntriage would encode today's false positives as tomorrow's baseline."
      },
      {
        "title": "§0.49 — `interface Quota` is hand-authored beside its generated model (registered 2026-08-01, decay_deadline: 2026-10-30)",
        "closure_date": null,
        "gate_path": null,
        "body": "**Owner:** platform\n\n**Found 2026-08-01.** `private/runtime/gateway/src/handlers/metering.ts` declares\n`interface Quota` by hand, restating the `state` enum of `kye.quota_grant.v1`.\nA generated model already exists at\n`private/types/generated/schemas/quota-grant.ts`, produced from that schema by\n`scripts/codegen/schemas-to-typescript.mjs`. This is the §0.49\nmodel-beside-schema anti-pattern: the copy happens to be correct today, and\nnothing keeps it that way.\n\nThe codegen script's own header records the scope decision — *\"SDK migration is\nOUT OF SCOPE — SDK files keep their manual types until a follow-up Ralph wave\nmigrates them to import from this generated surface.\"* Runtime files are in the\nsame position. This entry is that wave's ledger.\n\n**Closure.** Import the generated type and delete the local interface. Cheap in\nisolation, but it touches the reference server's build and wants its own test\ncycle rather than riding a decision-path change."
      },
      {
        "title": "§0.34 — the apex surface binds the PDP and cannot call it (decay_deadline: 2026-10-29)",
        "closure_date": null,
        "gate_path": null,
        "body": "**Owner:** platform\n\n**Found 2026-07-31.** `kye-protocol` (kyeprotocol.com) has bound `PDP → kye-pdp`\nsince before this date. Nothing on the surface has ever asked it for a decision:\nevery consequential request is authenticated and then simply performed, which is\n§0.33's doctrine ladder exactly — authentication answers *who is this*, never\n*may this happen*.\n\nThe wiring was written and then **withdrawn before shipping**, because\n`POST /decide` requires a Bearer API key with `runtime:write` scope (verified\nagainst D1, tenant resolved from the key row per §0.11) and 404s when the\ntenant has no `policy_sets` row. Verified live:\n\n```\nPOST https://pdp.kyeprotocol.com/decide  (no auth)\n→ 401 {\"ok\":false,\"error\":\"unauthorized\",\"reason\":\"missing_bearer\"}\n```\n\nThe apex holds no such credential, so a fail-closed decision point there would\nhave returned 403 on **every** form submission on the public site. Fail-closed is\ncorrect only when the call can succeed.\n\n**What closes it** — provisioning, not a code change:\n\n1. mint an apex API key with `runtime:write`, stored as a Pages **secret**\n   (never in the repo);\n2. seed a `policy_sets` row for the apex tenant with the public-surface rules\n   bundle — real policy content, authored, not scaffolded;\n3. re-land the middleware call and prove it end to end against the live PDP\n   before it is enforcing;\n4. convert to a rule: a surface that binds a decision point must consult it, the\n   Worker-side counterpart of the Pages bijection now in `edge-binding-coverage`.\n\nUntil then the honest state is: bound, health-probed, never consulted. It is not\nclaimed as governed anywhere.\n\n---"
      },
      {
        "title": "§0.29 — 9 deployed Workers have no activation path (decay_deadline: 2026-10-29)",
        "closure_date": null,
        "gate_path": null,
        "body": "**Owner:** platform\n\n**Found 2026-07-31**, by probing the live Cloudflare account while deriving the\nPages-bindings registry. Of 120 deployed Workers, 21 have **no way to be\ninvoked at all**: no cron trigger, no queue consumer, no route or custom domain,\nno workers.dev subdomain, no service binding from any other Worker, and no\nCloudflare Pages binding. Eleven of those belong to sibling projects in the same\naccount and are not KYE's to govern (§0.28). **Nine are KYE's:**\n\n| worker | in-repo declaration |\n|---|---|\n| `kye-admin-gateway` | none |\n| `kye-clickhouse-backfill` | none |\n| `kye-prior-search-saas-reindexer` | none |\n| `kye-signal-replayer` | none |\n| `kye-evidence-import-worker` | declared, no trigger |\n| `kye-oscal-exporter` | declared, no trigger |\n| `kye-reporting-agent` | declared, no trigger |\n| `kye-transparency-log-appender` | declared, no trigger |\n| `kye-search-indexer` | declares a queue consumer the live deploy does not have |\n\nA tenth, `kye-connector-certifier`, was in this set and is **closed**: the apex\nPages project now binds it (`CONNECTOR_CERTIFIER`), which is what the §44 probe\nset already assumed.\n\n**Why this is a §0.29 finding.** A deployed Worker that nothing can reach is the\n*hollow-runtime* anti-pattern seen from the deployment side: the artefact exists,\npasses every in-repo gate, and executes never. Four of the nine are worse — they\nare deployed with **no wrangler.toml anywhere in the repo**, so the deployed\nfleet is not the declared fleet. The existing `worker-deploy-alive` reconciler\nalready reports that half as advisory drift (\"extra in deploy\"); what it does not\ndo is treat unreachability as a defect.\n\n**Why it is not closed in this change-set.** Each of the nine needs a real\nper-worker decision — wire a caller, add the trigger its purpose implies, or\ndelete it from the platform — and deleting a deployed Worker is not reversible\nfrom the repo. Doing nine of those blind, in a change-set about registry\nconsolidation, is exactly the over-reach that produces broken production; the\nsame detector that reported these was wrong about 18 bindings earlier the same\nday, and the correction is in\n`private/roadmap/reconciliation/2026-07-31-pages-bindings-one-canonical.md`.\n\n**Trajectory.** Resolve each of the nine (wire / trigger / delete), then convert\nto a rule: extend `edge-binding-coverage`'s bijection with the Worker-side\ncounterpart — every deployed KYE Worker resolves to at least one activation path,\nderived from a platform-observed registry the same way the Pages registry now is.\nStrict zero at the deadline; the count may only decrease before it.\n\n---"
      },
      {
        "title": "§0.43 — `no-blind-spots` does not strip comments before matching scope markers (6 markers across 3 enforcers, decay_deadline: 2026-10-29)",
        "closure_date": null,
        "gate_path": "scripts/gates/no-blind-spots.mjs",
        "body": "**Owner:** platform\n\n**Found 2026-07-31**, while fixing an unrelated CI failure. The sibling detector\nin `implementation-canonical` flagged a *comment* that quoted the very\nanti-pattern it detects — a harmless false alarm, but it exposed the same root\ncause pointing the other way in `no-blind-spots`.\n\n`scripts/gates/no-blind-spots.mjs` matches each enforcer's\n`required_scope_markers[]` against the **raw source text**. A marker can\ntherefore be satisfied by a **comment** rather than by live code — so an\nenforcer can be scope-verified, declared `covered`, and counted among the 64,\non the strength of a marker that only narrates what the code does.\n\nOver-matching (implementation-canonical) is a false alarm and safe.\nUnder-matching here is **false assurance**, which is what §0.43 exists to\nprevent — the meta-gate has the defect class it was built to catch.\n\n**Measured, not hypothetical** — 6 markers across 3 of the 64 scope-verified\nenforcers resolve only in comments:\n\n| enforcer | markers |\n|---|---|\n| `audit-consistency` | 4 |\n| `competing-systems-scan` | 1 |\n| `schema-guard-canonical` | 1 |\n\nThis does **not** establish that those three are blind — only that their §0.43\n*proof* is weaker than the registry claims. Each needs its markers re-pointed at\nreal code, which is per-enforcer review rather than a mechanical sweep, hence the\nwindow.\n\n**Closure:** add comment-stripping to `no-blind-spots` by REUSING the existing\n`stripComments()` in `scripts/gates/air-gap-ability.mjs` (§0.49 — derive from the\ncanonical, never write a second stripper), then re-point the 6 markers. Expect\nthe 3 enforcers to flip `covered` → `declared-only` transiently; that ratchet\nmovement is the honest cost of removing a false proof, not a regression to hide.\n\n**Scope fence — do NOT generalise this closure.** Three text-matching enforcers\ntripped on documentation on 2026-07-31 alone (`implementation-canonical` on a\ncomment quoting the anti-pattern; `housekeeping` on a reconciliation note that\ncode-spanned a deliberately-absent path; this entry). They are not one class.\nThe direction decides the fix: where a comment produces a false **PASS** it is\n§0.43 blindness and must be stripped; where prose produces a false **FAIL** the\nenforcer is being conservative, which is the correct failure direction, and the\nauthor's text is what changes. Adding a mention-escape to `housekeeping` or to\nany decreases-only detector would be the §0.20 *verifier-weakening* anti-pattern\n— a genuinely stale path would simply be written inside the escape. Only\n`no-blind-spots` is in scope here.\n\n**decay_deadline:** 2026-10-29"
      },
      {
        "title": "§0.3 — Canonical-First baseline (323 vapor refs at adoption; re-dated by amendment 2026-07-15, decay_deadline: 2026-08-27)",
        "closure_date": "2026-08-27",
        "gate_path": "scripts/gates/canonical-first.mjs",
        "body": "**Amendment 2026-07-15 (honest miss, re-dated + made mechanical).** The\noriginal 2026-07-14 closure passed with the baseline at 328 (registry\n`private/specs/ratchets/baselines.json` `canonical_first__vapor_baseline`),\nand the date existed only in this document's prose — no gate tracked it,\nbecause the phrasing below matched none of the machine-readable deadline\ntokens `advisory-deadline-not-expired` scans for. This amendment (a) re-dates\nthe closure to 2026-08-27 (aligned with the §0.9 strict-flip cluster) with\nan explicit burn-down owner, and (b) phrases it with the enforced\n`decay_deadline:` token above, so the new date is self-enforcing — the day\nafter it, `test:advisory-deadline-not-expired` hard-fails CI until the\nbaseline is 0 or a further dated amendment lands. A silent pass can no\nlonger recur for this window.\n\n**Rule.** §0.3 declares Canonical-First: every `kye.<ns>.*.v<n>`\nreference in code must resolve to a canonical schema, vocabulary\nentry, or constitution-doc declaration. The rule was adopted\n2026-05-15 with a 60-day decay window starting at the historical\nbaseline of vapor refs.\n\n**Current state (2026-05-19).** Baseline 323 vapor refs. Net\ntrajectory decreasing as schemas are authored.\n\n**Gate.** `scripts/gates/canonical-first.mjs` runs in advisory mode\nwhile count ≤ baseline. New vapor refs above baseline block CI\n**immediately** — the window does not protect new debt, only legacy\ndebt being paid down. On 2026-07-14 BASELINE drops to 0 and the gate\nbecomes strict.\n\n**Resolution paths (per family):**\n\n| Vapor family | Resolution |\n|---|---|\n| `kye.evidence.*.v1` | Author the schema under `private/specs/schemas/`, register `$id` |\n| `kye.gateway.key.rotate` and other Gateway events | Add to `private/specs/openapi/kye-core-v1.yaml` operationIds |\n| `kye.connector_manifest.v1`, `kye.connector_profile.v1` | Rename refs to match canonical filename |\n| `kye.purchase_authority.*` (sandbox demo) | Author canonical schemas OR mark demo-internal |\n| `kye.decisions.create`, `kye.delegations.create` (dev portal examples) | Map to OpenAPI operationIds |\n\n**Closure date.** 2026-08-27 (re-dated by the 2026-07-15 amendment; enforced via the `decay_deadline:` token in this entry's heading).\n\n**Owner.** `KYE Protocol™ core team`.\n\n---"
      },
      {
        "title": "§0.3 — CI evidence packs are signed with an ephemeral per-run key (re-measured and re-scoped 2026-08-14, decay_deadline: 2026-11-12)",
        "closure_date": "2026-08-14",
        "gate_path": null,
        "body": "**Owner:** `KYE Protocol™ core team`\n\n**Rule.** §0.3 requires every CI run to emit the canonical\nself-governance evidence-event family\n(`kye.purpose.request.v1`, `kye.purpose.admissibility.v1`,\n`kye.evidence.decision_map.v1`, `kye.replay.context_seal.v1`,\n`kye.evidence.pack.v1`, `kye.replay.proof.v1`,\n`kye.evidence.tool_call.v1`, `kye.resilience.*.v1`,\n`kye.compliance.attestation.v1`).\n\n**This window reached its strict date (2026-08-14) invisibly, and that is the\nfirst thing it records.** Its heading said \"becomes strict 2026-08-14\" and its\nbody said \"**Closure date.** 2026-08-14\" — neither is a form\n`advisory-deadline-not-expired` parses, so of the 18 active windows this was the\none its own enforcer could not see. It reported \"all in the future\" on the\nmorning this one came due. Fixed at the root in the same change-set: the gate now\nhard-fails if any `###` heading under *Active decay windows* carries no\nmachine-readable deadline, so a window can no longer opt out of enforcement by\nhow it words its title (§0.43).\n\n**Re-measured 2026-08-14.** The state above was written 2026-05-19 and two of its\nthree gaps had since closed. Measured, not assumed:\n\n| stated gap (2026-05-19) | measured 2026-08-14 |\n|---|---|\n| `kye.compliance.attestation.v1` per control mapping — \"no emitter\" | **CLOSED.** 420 files under `scripts/` + `private/runtime/` emit it; it is the standard gate attestation. |\n| `kye.resilience.improvement_record.v1` on loop close — \"partial\" | **CLOSED.** `scripts/self-govern-kye-on-kye.mjs` emits it as artefact 11, conditionally (\"only when drift fires\"), which is the correct semantics — an improvement record with no drift to improve on would be a fabricated event. |\n| Ed25519 signing of CI evidence packs — \"uses test seed\" | **OPEN, and the description was wrong.** It does not use a test seed. `scripts/self-govern-kye-on-kye.mjs:219` generates a **fresh Ed25519 keypair per run**. |\n\n**What remains, stated precisely.** An ephemeral key is worse than a test seed\nfor the property that matters: a Replay-Proof™ must be verifiable *from public\nkeys alone*, and the public half of a per-run keypair does not outlive the run\nthat produced it. So a CI evidence pack is internally consistent and externally\nunverifiable — nobody can check tomorrow that today's pack was signed by KYE.\nEvery other part of the family is real, emitted, and schema-valid.\n\n**Why this is a window and not a fix.** Closing it needs a *provisioned\nproduction signing key*, which is the §0.29 admissible external: a credential not\nheld in-repo. The sibling item is already declared in\n`private/specs/compliance/tier1-readiness.json` `external_work_required`\n(`self-audit-daemon-signing-secret` — \"Provision SELF_AUDIT_SIGNING_JWK Worker\nSecret (+ HSM/KMS custody) … 1 day once the HSM/KMS key is exported\"). The CI\nevidence-pack key is the same custody question and rides the same provisioning.\n\n**This is a re-scope, not an extension (§41).** The original deadline is not\nbeing slid: two thirds of the work it covered is done and is recorded as done,\nthe remaining third is correctly described for the first time, and the new date\nis tied to a declared external dependency rather than to more authoring. Option\n(d) — \"extend the date by a one-line edit\" — is what the previous heading would\nhave permitted, which is precisely why it now cannot be worded that way.\n\n---"
      },
      {
        "title": "§0.3/§34 — Per-worker deploy lifecycle dispatches 403 (10 workflows, registered 2026-07-30, decay_deadline: 2026-08-29)",
        "closure_date": null,
        "gate_path": null,
        "body": "**Rule.** §0.3 self-governance + §34 §16 lifecycle coverage: a deploy\nfailure MUST fire the compensating arc. §0.32 binding #6 keeps only\nsingle-shot signals on `repository_dispatch`.\n\n**What was found (2026-07-30, while root-causing the visual-verify deploy\nfailure on `e1646dc`).** All 10 per-worker deploy workflows emit lifecycle\n`repository_dispatch` events via `curl … /dispatches || true`, and every\nemission has been silently failing with HTTP 403 — their `GITHUB_TOKEN`\ncarries `permissions: contents: read`, and POST `/repos/…/dispatches`\nrequires `contents: write`. Two distinct sub-classes:\n\n1. **`kye.lifecycle.compensating.v1` (real, degraded):**\n   `reconciliation.yml` SUBSCRIBES to this type, so a failed per-worker\n   deploy is supposed to trigger the §34 compensating arc — it never has.\n   The `|| true` guard made the degradation invisible (§0.43 subclass:\n   silent-skip emitter).\n2. **`kye.lifecycle.upstream.v1` (vestigial):** the green-path per-item\n   subscription was REMOVED by the §0.32 fan-out fix (2026-06-26); no\n   workflow may subscribe to it, so the emission is a leftover competing\n   signal — the §0 fix is deletion, not repair.\n\n**Closure design.** Delete the vestigial `upstream` emission curls from\nall 10 deploy workflows; keep the `compensating` emission and grant those\nworkflows `contents: write` (the posture `reconciliation.yml` already\ncarries); verify one 204 emission end-to-end (drill or next real\nfailure). `workflow-observer-coverage` + `no-self-perpetuating-loops`\nmust stay green — the fix adds no subscription and no fan-out.\n\n**Why registered rather than fixed in this change-set.** The change-set\nthat surfaced it is the visual-verify ERESOLVE deploy fix (urgent, red on\n`main`); a 10-workflow permission + emission surgery is a separate\nreviewable unit (§0.8), and bundling it would couple a production\nunblock to a governance-plumbing refactor.\n\n**Owner.** `KYE Protocol™ core team`.\n\n---"
      },
      {
        "title": "§0.20/§0.43 — Umbrella generator corpus: 8 generators UNCLASSIFIED (registered 2026-07-30, decay_deadline: 2026-08-29)",
        "closure_date": null,
        "gate_path": "scripts/gates/generator-determinism.mjs",
        "body": "**Rule.** §0.20 Automatic Dynamic Resolution + §0.43 No Blind Enforcers:\n`npm run build:derived-all` is the ONE command that makes the derived tree\nfresh, so every generator on disk must be DECLARED — run by a phase, or\nexcluded for a verified reason. An undeclared generator means the umbrella\ndoes not do what its name claims, and its output drifts with no local\ndetector.\n\n**What was found (2026-07-30, root-causing why adding ONE gate file took six\nred CI runs).** \"The generator set\" was declared five times and the\ndeclarations pairwise disagreed — `scripts/build-derived-all.mjs` (59),\n`scripts/ci/fresh-all.mjs` (+5 the umbrella never ran),\n`scripts/gates/generator-determinism.mjs` (37, 7 outside the umbrella),\n`scripts/ci/cascade-run.mjs` (+4), `.githooks/pre-push` §3 (+4). The\nDETECTOR's corpus was a superset of the REGENERATOR's, so six derived\nartefacts went stale on every net-new artefact and three of the six had no\nlocal detector at all. Fixed in the same change-set: the six now run in the\numbrella's registration phase, `fresh-all` no longer keeps a second list,\nand the umbrella hard-fails on an undeclared `scripts/build-*.mjs`.\n\n**What remains (the honest residue).** Of 79 `scripts/build-*.mjs`, 8 carry a\n**verified** exclusion reason (destructive rewrite · validator-not-generator ·\nAstro engine · raster render · browser capture · OSS-tree mirror) and **8** sit\nin the decreases-only `UNCLASSIFIED` array in `scripts/build-derived-all.mjs`:\n`build-pages-function-manifest`,\n`build-pricing-disclosure-records`, `build-program-registry`,\n`build-registration-authority-diagram`, `build-reverse-lookup`,\n`build-self-audit-forbidden-corpus`, `build-self-audit-snapshot`,\n`build-stakeholder-report-samples`. One of them\n(`build-self-audit-forbidden-corpus`) was measured to produce **no** drift on\nthe current tree — but \"not known to be stale\" is not \"checked\", and it is\nrecorded as the former (§70 honesty).\n\n**First retirement, 9 → 8 (2026-07-30, same day): the distinction earned its\nkeep.** `build-ontology-derivative` was one of the two \"measured, no drift\"\nentries — and it broke within hours. A ruff-0.16 `UP035` autofix rewrote its\ngenerated `private/sdks/python/kye_sdk/vocabulary/ontology.py` (a file whose own\nheader reads DO NOT EDIT), and because the umbrella did not run the generator,\n`npm run build:derived-all` could not re-settle it: `ontology-dictionary-roundtrip`\nfailed while every generator the umbrella DID know about reported fresh. That is\nprecisely the residue this entry exists to name. Fixed at the WRITER, not the\nartefact (§41 §9): the generator now emits `from collections.abc import Mapping`\nso its output is ruff-clean by construction — otherwise the two gates form a\nloop, each undoing the other's fix — and it is folded into `P5a` (in-loop: it\nsplices a `<ul data-cascade-source>` block into a `public/` page that the P3\npage chain reads).\n\n**Closure design.** Read each of the 8 and either fold it into a phase\n(`P1`–`P5b`, position by whether its output feeds the page chain) or give it a\nverified `EXCLUDED` reason. The array may only shrink; the umbrella's corpus\nself-check hard-fails on anything undeclared, so a 10th cannot appear. Widening\nthe on-disk sweep beyond `scripts/build-*.mjs` to `scripts/{codegen,compliance,\nsmoke}/**` is part of the same closure (§0.43 — the pattern is itself a\nnarrowing).\n\n**Why registered rather than fixed in this change-set.** The change-set that\nsurfaced it is the generator-set unification (already 5 red gates deep on one\nroot cause). Classifying 9 more generators means reading and drift-testing each,\nand folding one in changes what the umbrella writes — a separate reviewable unit\n(§0.8). Bundling it would couple an urgent CI unblock to nine independent\njudgement calls.\n\n**Owner.** `KYE Protocol™ core team`.\n\n---"
      },
      {
        "title": "§0.4 — Dependency advisories with NO upstream fix (10 high at adoption 2026-07-28, decay_deadline: 2026-10-26)",
        "closure_date": null,
        "gate_path": null,
        "body": "**Rule.** §0.4 banking-grade requires a clean supply chain; an unpatched\nhigh-severity advisory in a shipped dependency tree is a §0.4 gap.\n\n**What was closed (2026-07-28).** GitHub reported 116 alerts on the default\nbranch. Measured locally, that is **three distinct advisories across 114\ntracked lockfiles**, dominated by repetition: `postcss` (path traversal, dev\ntooling via vitest → vite) appeared in **109** lockfiles, `brace-expansion`\nin 2, `js-yaml` in 2. 108 lockfiles were fixed to zero by\n`npm audit fix --package-lock-only`. Root went 2 → 0 on patch bumps only\n(brace-expansion 5.0.7 → 5.0.8, js-yaml 5.2.1 → 5.2.2).\n\n**What remains and why it is NOT fixable today (the honest part).**\n\n| workspace | count | chain | why unfixed |\n|---|---:|---|---|\n| `private/runtime/key-custody` | 6 | `@google-cloud/kms` → `google-gax` → rimraf → glob → minimatch → brace-expansion | **`google-gax` latest published version is 5.0.8 and the advisory range is `5.0.5 - 5.0.8`** — the newest release is itself vulnerable. Bumping `@google-cloud/kms` 5.5.0 → 5.7.0 was tested and still resolves `google-gax@5.0.6`. |\n| `private/runtime/visual-verify-worker` | 4 | `wrangler` → miniflare / postcss; `sharp` → libvips | `wrangler@latest` was tested and does not clear miniflare/postcss/sharp. |\n\nnpm reports `fixAvailable: true` for these, which is **misleading**: it means\n\"resolvable somewhere in the tree\", not \"an upstream patch exists\". Forcing\nresolution requires overriding `brace-expansion` across a `^2` → `^5` major\nboundary that `minimatch@9` depends on. That was attempted, reverted, and is\nNOT being shipped: forcing a major across the transitive tree of the **key\ncustody / signing** component without its test suite passing would trade a\ntheoretical DoS for a real signing outage.\n\n**Honest exposure assessment (§70).** All ten are DoS / path-traversal in\nbuild- and startup-time path utilities (glob/minimatch/brace-expansion) or in\ndev tooling (postcss, miniflare, wrangler). None is reachable from a deployed\nWorker request path. This is a supply-chain hygiene gap, not a live\nexploitable production vulnerability — and it is recorded as the former, not\ndowngraded away.\n\n**Closure condition.** Upstream `google-gax` publishes a release outside\n`5.0.5 - 5.0.8`, and wrangler/sharp ship non-vulnerable transitives. Re-run\nthe 114-workspace sweep and drive to zero. If upstream has not moved by the\ndeadline, the alternative is an override **plus** a green test run for both\ncomponents, evidenced — never an override alone.\n\n**Owner.** `KYE Protocol™ core team`."
      },
      {
        "title": "§0.7 — Housekeeping baseline (174 dangling refs at adoption; re-dated by amendment 2026-07-15, decay_deadline: 2026-08-28)",
        "closure_date": "2026-08-28",
        "gate_path": "scripts/gates/housekeeping.mjs",
        "body": "**Amendment 2026-07-15 (honest miss, re-dated + made mechanical).** The\noriginal 2026-07-15 closure arrived with the gate baseline at 188 — above\nthe 174 adoption count, after intermediate peaks to 191 — and, like §0.3\nabove, the date lived only in prose invisible to the deadline enforcer.\nRe-dated to 2026-08-28 (aligned with the §0.11/§0.12 strict-flip cluster)\nand phrased with the enforced `decay_deadline:` token, so expiry now\nhard-fails CI. The burn-down starts from the honest current count (188 in\n`scripts/gates/housekeeping.mjs`), not the stale adoption figure.\n\n**Rule.** §0.7 (locked 2026-05-21) requires every concrete repo-path\nreference inside documentation to resolve to a file on disk. Stale\n(removed) and fictional (never built) references are §0-class\nviolations.\n\n**Current state (2026-05-21).** Baseline 174 dangling references across\nthe tracked `.md` corpus, inherited at adoption. The largest clusters\nare constitution docs citing `scripts/check-*-shape.sh` CI scripts that\nwere never built, references into `private/sdks/` source paths, and\n`private/mechanisms/` / `private/runbooks/` placeholder docs.\n\n**Gate.** `scripts/gates/housekeeping.mjs` runs in advisory mode while\nthe dangling-reference count ≤ baseline (174). A new stale/fictional\nreference above baseline blocks CI **immediately** — the window\nprotects only the legacy backlog being paid down, never new debt. When\nthe baseline reaches 0 the gate is permanently strict.\n\n**Resolution paths.**\n\n| Cluster | Resolution |\n|---|---|\n| `scripts/check-*-shape.sh` cited by constitution rails | Build the gate, OR repoint the doc to the real `scripts/gates/*.mjs`, OR drop the claim |\n| `private/sdks/**` source paths | Repoint to the real SDK file, or drop if the SDK module was restructured |\n| `private/mechanisms/**`, `private/runbooks/**` | Create the placeholder doc, or remove the dangling reference |\n| Renamed/moved files | Repoint the reference to the current path |\n\n**Closure date.** 2026-08-28 (re-dated by the 2026-07-15 amendment; enforced via the `decay_deadline:` token in this entry's heading).\n\n**Owner.** `KYE Protocol™ core team`.\n\n---"
      }
    ],
    "closed_count": 6,
    "sha256": "10391b37aa63e0875eee341e274aa33e72b507f1c3ddf14dbd8f3cdc6eac9b62"
  },
  "implementation_registry": {
    "schema": "kye.implementation_registry.v1",
    "version": "1.0",
    "adopted": "2026-05-19",
    "constitution_ref": "constitution/40-IMPLEMENTATION-CANONICAL.md",
    "notes": [
      "Seed manifest. Identified concepts from the 2026-05-19 audit prompted by 'we need to be 10000% certain there is only one implementation'. This file grows with every concept clarified — but the registry is itself canonical: any merge that adds a NEW reimplementation of a registered concept fails CI.",
      "2026-05-21 full runtime drift audit: registry extended from 19 to 46 concepts. Triggered by the prior third-party search SaaS→KYE Native Search Engine drift that CI missed because search/directory were unregistered. Competing-systems smells (gateway-worker consolidation, kye-reporting-worker vs kye-reporting-agent-worker, dead private/runtime/search/) are tracked for the runtime-consolidation PR.",
      "2026-05-23 framework-coverage bidirectional mapping: each concept MAY carry an optional `framework_coverage[]` array of requirement_ids (matching private/specs/compliance/<framework>/*.json). Verified by scripts/gates/framework-coverage-bijection.mjs. The companion framework-requirement registry (private/specs/compliance/<framework>/) provides the OUTBOUND map; framework_coverage[] here provides the INBOUND map. Bijection enforced at CI."
    ],
    "concepts": [
      {
        "concept_id": "agent-dev-kit",
        "name": "KYE Agent Dev Kit (TS + Python — agent SDK + lifecycle hooks)",
        "plane": "runtime",
        "constitution_ref": "constitution/32-AGENT-DEV-KIT.md",
        "ssot_module": "private/runtime/agent-dev-kit",
        "ssot_package": "@kye/agent-dev-kit",
        "ssot_entry_point": "lifecycle hooks + evidence helpers",
        "transport_wrappers": [
          {
            "module": "private/runtime/agent-dev-kit-python",
            "transport": "language-port",
            "note": "Python port (kye-agent-dev-kit) — same contract, separate language; parallel SSOT per §32."
          }
        ],
        "competitor_forbidden_patterns": [
          "function makePurposeAdmissibility(",
          "const makePurposeAdmissibility =",
          "class makePurposeAdmissibility "
        ]
      },
      {
        "concept_id": "agent.demo",
        "name": "Demo Agent — SSOT library",
        "plane": "onboarding",
        "constitution_ref": "constitution/14-AGENTS-AND-ENGINES.md",
        "ssot_module": "private/runtime/demo-agent",
        "ssot_package": "@kye/demo-agent",
        "ssot_entry_point": "DemoAgent",
        "transport_wrappers": [
          {
            "module": "private/runtime/kye-demo-agent",
            "transport": "http",
            "note": "CF Worker — agent_manifest runtime_path for the Demo Agent; imports the SSOT via ../../demo-agent/src/index.js."
          }
        ],
        "competitor_forbidden_patterns": [
          "function CANONICAL_DEMO_SCENARIOS(",
          "const CANONICAL_DEMO_SCENARIOS =",
          "class CANONICAL_DEMO_SCENARIOS "
        ]
      },
      {
        "concept_id": "agent.dsar-evidence",
        "name": "DSAR Evidence Agent — SSOT library",
        "plane": "evidence",
        "constitution_ref": "constitution/14-AGENTS-AND-ENGINES.md",
        "ssot_module": "private/runtime/dsar-evidence-agent",
        "ssot_package": "@kye/dsar-evidence-agent",
        "ssot_entry_point": "DsarEvidenceAgent",
        "transport_wrappers": [
          {
            "module": "private/runtime/kye-dsar-evidence-agent",
            "transport": "http",
            "note": "CF Worker — agent_manifest runtime_path for the DSAR Evidence Agent; imports the SSOT via ../../dsar-evidence-agent/src/index.js."
          }
        ],
        "competitor_forbidden_patterns": [
          "function assembleEvidenceRows(",
          "const assembleEvidenceRows =",
          "class assembleEvidenceRows "
        ]
      },
      {
        "concept_id": "agent.entitlements",
        "name": "Entitlements Agent — SSOT library",
        "plane": "billing",
        "constitution_ref": "constitution/14-AGENTS-AND-ENGINES.md",
        "ssot_module": "private/runtime/entitlements-agent",
        "ssot_package": "@kye/entitlements-agent",
        "ssot_entry_point": "EntitlementsAgent",
        "transport_wrappers": [
          {
            "module": "private/runtime/kye-entitlements-agent",
            "transport": "http",
            "note": "CF Worker — agent_manifest runtime_path for the Entitlements Agent; imports the SSOT via ../../entitlements-agent/src/index.js."
          }
        ],
        "competitor_forbidden_patterns": [
          "function EntitlementsAgent(",
          "const EntitlementsAgent =",
          "class EntitlementsAgent "
        ]
      },
      {
        "concept_id": "agent.ops",
        "name": "Ops Agent — SSOT library",
        "plane": "runtime",
        "constitution_ref": "constitution/14-AGENTS-AND-ENGINES.md",
        "ssot_module": "private/runtime/ops-agent",
        "ssot_package": "@kye/ops-agent",
        "ssot_entry_point": "OpsAgent",
        "transport_wrappers": [
          {
            "module": "private/runtime/kye-ops-agent",
            "transport": "http",
            "note": "CF Worker — agent_manifest runtime_path for the Ops Agent; imports the SSOT via ../../ops-agent/src/index.js."
          }
        ],
        "competitor_forbidden_patterns": [
          "function disabledCapabilityIds(",
          "const disabledCapabilityIds =",
          "class disabledCapabilityIds "
        ]
      },
      {
        "concept_id": "agent.silent-compromise",
        "name": "Silent Compromise Agent — SSOT library",
        "plane": "governance",
        "constitution_ref": "constitution/14-AGENTS-AND-ENGINES.md",
        "ssot_module": "private/runtime/silent-compromise-agent",
        "ssot_package": "@kye/silent-compromise-agent",
        "ssot_entry_point": "SilentCompromiseAgent",
        "transport_wrappers": [
          {
            "module": "private/runtime/kye-silent-compromise-agent",
            "transport": "http",
            "note": "CF Worker — agent_manifest runtime_path for the Silent Compromise Agent; imports the SSOT via ../../silent-compromise-agent/src/index.js."
          }
        ],
        "competitor_forbidden_patterns": [
          "function SilentCompromiseAgent(",
          "const SilentCompromiseAgent =",
          "class SilentCompromiseAgent "
        ]
      },
      {
        "concept_id": "agent.sku-lifecycle",
        "name": "SKU Lifecycle Agent — SSOT library",
        "plane": "billing",
        "constitution_ref": "constitution/14-AGENTS-AND-ENGINES.md",
        "ssot_module": "private/runtime/sku-lifecycle-agent",
        "ssot_package": "@kye/sku-lifecycle-agent",
        "ssot_entry_point": "SkuLifecycleAgent",
        "transport_wrappers": [
          {
            "module": "private/runtime/kye-sku-lifecycle-agent",
            "transport": "http",
            "note": "CF Worker — agent_manifest runtime_path for the SKU Lifecycle Agent; imports the SSOT via ../../sku-lifecycle-agent/src/index.js."
          }
        ],
        "competitor_forbidden_patterns": [
          "function SkuLifecycleAgent(",
          "const SkuLifecycleAgent =",
          "class SkuLifecycleAgent "
        ]
      },
      {
        "concept_id": "agent.trainer",
        "name": "Trainer Agent — SSOT library",
        "plane": "runtime",
        "constitution_ref": "constitution/14-AGENTS-AND-ENGINES.md",
        "ssot_module": "private/runtime/trainer-agent",
        "ssot_package": "@kye/trainer-agent",
        "ssot_entry_point": "TrainerAgent",
        "transport_wrappers": [
          {
            "module": "private/runtime/kye-trainer-agent",
            "transport": "http",
            "note": "CF Worker — agent_manifest runtime_path for the Trainer Agent; imports the SSOT via ../../trainer-agent/src/index.js."
          }
        ],
        "competitor_forbidden_patterns": [
          "function TrainerAgent(",
          "const TrainerAgent =",
          "class TrainerAgent "
        ]
      },
      {
        "concept_id": "analytics.clickhouse-client",
        "name": "Analytics Plane HTTP client for ClickHouse (Worker-compatible)",
        "plane": "runtime",
        "constitution_ref": "constitution/20-ANALYTICS-PLANE.md",
        "ssot_module": "private/runtime/clickhouse-client",
        "ssot_package": "@kye/clickhouse-client",
        "ssot_entry_point": "tenant-token-scoped ClickHouse HTTP client (tables / projections / queries / audit-emit)",
        "transport_wrappers": [],
        "competitor_forbidden_patterns": [
          "function assertTemplateIsTenantSafe(",
          "const assertTemplateIsTenantSafe =",
          "class assertTemplateIsTenantSafe "
        ]
      },
      {
        "concept_id": "audit.chain.append",
        "name": "Audit chain append + the chain id it appends to (§0.3 evidence emission)",
        "plane": "audit",
        "constitution_ref": "constitution/21-DELEGATED-AUDITABILITY.md",
        "ssot_module": "private/runtime/audit-chain",
        "ssot_package": null,
        "ssot_entry_point": "appendEvent(envelope) · workerChainEmitter(baseUrl) · tenantChainId(tenant_id) / platformChainId(component)",
        "transport_wrappers": [
          {
            "module": "private/runtime/audit-chain-worker",
            "transport": "http",
            "note": "HTTP surface; receives the append from every privileged Worker. It is the RECEIVER, so it legitimately owns CHAIN_ID_RE and the /v1/chains/:chain_id/{append,verify} route patterns — a validator has to spell out what it validates. Declared so the enforcer does not accuse the one module whose job is to hold the shape."
          },
          {
            "module": "private/lib/chain-id",
            "transport": "library",
            "note": "The tenant→chain-id derivation. private/lib/chain-id is the SSOT (plain JS so BOTH the TypeScript emitter can import it and the public plane can receive it by byte-projection across §33); the public/site/functions copy is that projection, verified byte-for-byte by this gate."
          },
          {
            "module": "public/site/functions/api/_lib/chain-id.js",
            "transport": "projection",
            "note": "Byte-projection of private/lib/chain-id for the Pages Functions, which cannot import a private/ module across §33. Three of them wrote `kye:audit-chain:${tenantId}` inline with no strip — accepted by the receiver, but a DIFFERENT chain from the stripped form, so a tenant's audit history split in two."
          }
        ],
        "competitor_forbidden_patterns": [
          "function InProcessAuditEmitter(",
          "const InProcessAuditEmitter =",
          "class InProcessAuditEmitter ",
          "`kye:audit-chain:${",
          "function canonicalEmit(",
          "function chainIdForTenant("
        ],
        "competitor_baseline_key": "implementation_canonical__competitors__audit_chain_append",
        "migration": {
          "status": "complete",
          "tracked_in": "private/specs/ratchets/baselines.json#implementation_canonical__competitors__audit_chain_append"
        }
      },
      {
        "concept_id": "audit.replay-run",
        "name": "Audit replay orchestration (re-derive evidence packs on a cadence + emit drift)",
        "plane": "audit",
        "constitution_ref": "constitution/21-DELEGATED-AUDITABILITY.md",
        "ssot_module": "private/runtime/audit-replay-orchestrator",
        "ssot_package": null,
        "ssot_entry_point": "scheduled() — worker.js",
        "transport_wrappers": [],
        "competitor_forbidden_patterns": [
          "function AuditReplayOrchestrator(",
          "const AuditReplayOrchestrator =",
          "class AuditReplayOrchestrator "
        ]
      },
      {
        "concept_id": "authority.grant",
        "name": "Authority Engine (issue/revoke/validate Authority Grants + delegation walk)",
        "plane": "decision",
        "constitution_ref": "constitution/14-AGENTS-AND-ENGINES.md",
        "ssot_module": "private/runtime/authority-engine",
        "ssot_package": "@kye/authority-engine",
        "ssot_entry_point": "grant / revoke / validate + cascade",
        "transport_wrappers": [],
        "competitor_forbidden_patterns": [
          "function verifyGrantViaCustody(",
          "const verifyGrantViaCustody =",
          "class verifyGrantViaCustody "
        ]
      },
      {
        "concept_id": "authority.proof-bundle.assemble",
        "name": "Authority Proof Bundle assembler",
        "plane": "evidence",
        "constitution_ref": "constitution/14-AGENTS-AND-ENGINES.md",
        "ssot_module": "private/runtime/authority-proof-bundle",
        "ssot_package": null,
        "ssot_entry_point": "assembleBundle(...)",
        "transport_wrappers": [
          {
            "module": "private/runtime/authority-proof-bundle-worker",
            "transport": "http",
            "note": "HTTP surface that wraps the assembler"
          }
        ],
        "competitor_forbidden_patterns": [
          "function assembleBundle(",
          "const assembleBundle =",
          "class assembleBundle "
        ]
      },
      {
        "concept_id": "billing.metering",
        "name": "Stripe billing/metering client (BPS calc + meter batcher + webhook verify)",
        "plane": "billing",
        "constitution_ref": "constitution/23-BILLING-METERING.md",
        "ssot_module": "private/runtime/stripe-client",
        "ssot_package": "@kye/stripe-client",
        "ssot_entry_point": "typed Stripe wrapper + meter batcher",
        "transport_wrappers": [
          {
            "module": "private/runtime/stripe-meter",
            "transport": "cron",
            "note": "Hourly Stripe meter Worker (§23)"
          }
        ],
        "competitor_forbidden_patterns": [
          "function BPS_APPLICABLE_ACTION_CLASSES(",
          "const BPS_APPLICABLE_ACTION_CLASSES =",
          "class BPS_APPLICABLE_ACTION_CLASSES "
        ]
      },
      {
        "concept_id": "ci.privileged_op_evidence",
        "name": "Emit the §0.3 evidence family for a privileged CI action",
        "plane": "evidence",
        "constitution_ref": "constitution/00-INDEX.md",
        "ssot_module": "scripts/ci/govern-privileged-op.mjs",
        "ssot_package": null,
        "ssot_entry_point": "node scripts/ci/govern-privileged-op.mjs (env: GOP_CAPABILITY, GOP_PURPOSE, GOP_ALLOWED_EVENTS)",
        "transport_wrappers": [],
        "competitor_forbidden_patterns": [
          "function emitEvidencePack(",
          "const emitEvidencePack ="
        ],
        "competitor_baseline_key": "implementation_canonical__competitors__ci_privileged_op_evidence",
        "migration": {
          "status": "complete",
          "note": "Registered 2026-08-15. Invoked BOTH via the .github/actions/govern-op composite AND directly by workflows such as deploy-cloudflare-pages.yml. An agent grepping only the composite name reported KYE's public landing deploy as ungoverned — a false finding caused by matching the wrapper instead of the mechanism."
        }
      },
      {
        "concept_id": "ci.workflow_privileged_classification",
        "name": "Is a CI workflow privileged, and at what tier?",
        "plane": "governance",
        "constitution_ref": "constitution/00-INDEX.md",
        "ssot_module": "scripts/lib/workflow-classification.mjs",
        "ssot_package": null,
        "ssot_entry_point": "classifyWorkflow({ slug, text, triggers }) -> { kind, risk_tier, privileged_ops, classification_basis }",
        "transport_wrappers": [],
        "competitor_forbidden_patterns": [
          "function classifyWorkflow(",
          "const classifyWorkflow ="
        ],
        "competitor_baseline_key": "implementation_canonical__competitors__ci_workflow_privileged_classification",
        "migration": {
          "status": "complete",
          "note": "Registered 2026-08-15 after an agent hand-rolled a secrets+mutation grep as a THIRD copy of this question. The module's own header already warned: workflow-governance-coverage asks 'is this privileged, and is it governed?' and build-workflow-registry asks 'is this privileged, so what tier?' — same question, one answer. Its HONEST LIMIT is load-bearing: 'mutating' means the canonical privileged-op set, and widening that set is a §0.3 amendment, not a tweak. A grep that widens it silently produces false gaps."
        }
      },
      {
        "concept_id": "ckan.connector",
        "name": "CKAN Connector (read-only CKAN Action API client → canonical KYE entities)",
        "plane": "connector",
        "constitution_ref": "constitution/28-CKAN-OPEN-DATA.md",
        "ssot_module": "private/runtime/ckan-connector",
        "ssot_package": "@kye/ckan-connector",
        "ssot_entry_point": "pull portal/datasets/activity → map to KYE entities",
        "transport_wrappers": [
          {
            "module": "private/runtime/ckan-connector-worker",
            "transport": "cron",
            "note": "Cron-triggered harvester Worker"
          }
        ],
        "competitor_forbidden_patterns": [
          "function mapPortalStatus(",
          "const mapPortalStatus =",
          "class mapPortalStatus "
        ]
      },
      {
        "concept_id": "commercial.lifecycle",
        "name": "Commercial Lifecycle Agent (16-state commercial workflow machine)",
        "plane": "billing",
        "constitution_ref": "constitution/27-COMMERCIAL-LIFECYCLE.md",
        "ssot_module": "private/runtime/commercial-lifecycle-agent",
        "ssot_package": "@kye/commercial-lifecycle-agent",
        "ssot_entry_point": "lifecycle-machine.json runner",
        "transport_wrappers": [
          {
            "module": "private/runtime/commercial-lifecycle-worker",
            "transport": "queue",
            "note": "KYE_LIFECYCLE_QUEUE consumer Worker"
          }
        ],
        "competitor_forbidden_patterns": [
          "function CommercialLifecycleRunner(",
          "const CommercialLifecycleRunner =",
          "class CommercialLifecycleRunner "
        ]
      },
      {
        "concept_id": "comms.delivery.email",
        "name": "Email delivery primitive (CF Email Sending binding)",
        "plane": "comms",
        "constitution_ref": "constitution/38-COMMS-RAIL.md",
        "ssot_module": "private/runtime/mail-sender",
        "ssot_package": null,
        "ssot_entry_point": "POST /send",
        "transport_wrappers": [
          {
            "module": "private/runtime/kye-comms-engine-worker",
            "transport": "service-binding",
            "note": "Comms Engine routes compiled templates through mail-sender via the MAIL_SENDER service binding"
          }
        ],
        "competitor_scan_exemption": {
          "reason": "Delivery is a deployed worker reached over a transport; a competing sender is a second deployed surface, which the delivery gate reconciles and a symbol pattern cannot.",
          "enforced_by": "email-delivery-canonical"
        }
      },
      {
        "concept_id": "comms.dispatch",
        "name": "Outbound communications dispatch",
        "plane": "comms",
        "constitution_ref": "constitution/38-COMMS-RAIL.md",
        "ssot_module": "private/runtime/kye-comms-engine-worker",
        "ssot_package": null,
        "ssot_entry_point": "POST /v1/comms/dispatch",
        "transport_wrappers": [
          {
            "module": "public/site/functions/api/_lib/comms-dispatch.js",
            "transport": "http-client",
            "note": "Pages Functions client (kye-protocol Pages project)"
          },
          {
            "module": "public/admin/functions/api/_lib/comms-dispatch.js",
            "transport": "http-client",
            "note": "Pages Functions client (kye-admin Pages project)"
          },
          {
            "module": "public/status/functions/api/_lib/comms-dispatch.js",
            "transport": "http-client",
            "note": "Pages Functions client (status Pages project)"
          }
        ],
        "competitor_forbidden_patterns": [
          "function compileTemplate(",
          "const compileTemplate =",
          "class compileTemplate "
        ]
      },
      {
        "concept_id": "comms.email-templates",
        "name": "Outbound email template manifest",
        "plane": "comms",
        "constitution_ref": "constitution/38-COMMS-RAIL.md",
        "ssot_module": "private/specs/comms",
        "ssot_package": null,
        "ssot_entry_point": "manifest.json + blocks.json + links.json + providers.json",
        "transport_wrappers": [],
        "competitor_scan_exemption": {
          "reason": "Templates are data files under private/specs/comms; a duplicate is a second template record, not a second exported function.",
          "enforced_by": "comms-manifest-alive"
        }
      },
      {
        "concept_id": "conformance.run",
        "name": "Conformance Runner (Conformance Pack execution against tenant stacks)",
        "plane": "governance",
        "constitution_ref": "constitution/15-MCP-AND-SDK.md",
        "ssot_module": "private/runtime/conformance-runner",
        "ssot_package": "@kye/conformance-runner",
        "ssot_entry_point": "consumeBatch + processMessage",
        "transport_wrappers": [
          {
            "module": "private/runtime/kye-conformance-runner",
            "transport": "queue",
            "note": "Worker shell — wires consumeBatch to the kye-conformance queue"
          },
          {
            "module": "private/runtime/kye-conformance-scheduler-worker",
            "transport": "cron",
            "note": "Periodic re-run scheduler"
          }
        ],
        "competitor_forbidden_patterns": [
          "function canonicalComposite(",
          "const canonicalComposite =",
          "class canonicalComposite "
        ]
      },
      {
        "concept_id": "connector.onboarding-agent",
        "name": "Connector Onboarding Agent",
        "plane": "onboarding",
        "constitution_ref": "constitution/22-ONBOARDING.md",
        "ssot_module": "private/runtime/connector-onboarding-agent",
        "ssot_package": null,
        "ssot_entry_point": "runDiscovery(...)",
        "transport_wrappers": [
          {
            "module": "private/runtime/connector-onboarding-agent-worker",
            "transport": "http",
            "note": "CF Worker HTTP surface"
          }
        ],
        "competitor_forbidden_patterns": [
          "function InMemoryConnectorWorkflowStore(",
          "const InMemoryConnectorWorkflowStore =",
          "class InMemoryConnectorWorkflowStore "
        ]
      },
      {
        "concept_id": "constitution.read",
        "name": "Constitution + manifests + gates → structured snapshot (the Constitution Engine)",
        "plane": "governance",
        "constitution_ref": "constitution/40-IMPLEMENTATION-CANONICAL.md",
        "ssot_module": "private/runtime/constitution-engine",
        "ssot_package": "@kye/constitution-engine",
        "ssot_entry_point": "snapshotConstitution(repoRoot) + checkCompliance(snapshot)",
        "transport_wrappers": [
          {
            "module": "private/runtime/kye-constitution-gateway-worker",
            "transport": "http",
            "must_import": "@kye/constitution-engine",
            "note": "HTTP surface at constitution.kyeprotocol.com — builds the snapshot at deploy time and serves it as JSON"
          }
        ],
        "competitor_forbidden_patterns": [
          "function readImplementationRegistry(",
          "const readImplementationRegistry =",
          "class readImplementationRegistry "
        ]
      },
      {
        "concept_id": "crypto.byok",
        "name": "BYOK envelope encryption (tenant-managed CMK for R2 Evidence Packs + D1 audit logs)",
        "plane": "runtime",
        "constitution_ref": "constitution/30-AUDIT-WORM-RETENTION.md",
        "ssot_module": "private/runtime/byok",
        "ssot_package": "@kye/byok",
        "ssot_entry_point": "RFC 8152 envelope encryption — per-record DEK + customer-KMS-wrapped DEK, re-wrap on KEK rotation",
        "transport_wrappers": [],
        "competitor_forbidden_patterns": [
          "function InMemoryBYOKConfigStore(",
          "const InMemoryBYOKConfigStore =",
          "class InMemoryBYOKConfigStore "
        ]
      },
      {
        "concept_id": "crypto.primitives",
        "name": "Crypto primitives (COSE_Sign1, JWS detached, Evidence Pack / Decision Map signers)",
        "plane": "runtime",
        "constitution_ref": "constitution/16-EDGE-RUNTIME.md",
        "ssot_module": "private/runtime/crypto",
        "ssot_package": "@kye/crypto",
        "ssot_entry_point": "COSE/JWS signers (Ed25519)",
        "transport_wrappers": [],
        "competitor_forbidden_patterns": [
          "function verifyDecisionMapWithPublicJwk(",
          "const verifyDecisionMapWithPublicJwk =",
          "class verifyDecisionMapWithPublicJwk "
        ]
      },
      {
        "concept_id": "d1.schema",
        "name": "D1 migration tree (canonical database schema)",
        "plane": "runtime",
        "constitution_ref": "constitution/16-EDGE-RUNTIME.md",
        "ssot_module": "private/runtime/d1",
        "ssot_package": null,
        "ssot_entry_point": "d1/migrations/ — ordered migration files",
        "transport_wrappers": [],
        "competitor_scan_exemption": {
          "reason": "The schema is SQL DDL in a migration tree; a competing copy is a second CREATE TABLE, which is a shape no JavaScript symbol pattern can match.",
          "enforced_by": "d1-schema-apply"
        }
      },
      {
        "concept_id": "data.classify",
        "name": "Data Classification Engine (canonical data classification assign/enforce)",
        "plane": "decision",
        "constitution_ref": "constitution/31-DATA-GOVERNANCE-PACK.md",
        "ssot_module": "private/runtime/data-classification-engine",
        "ssot_package": "@kye/data-classification-engine",
        "ssot_entry_point": "classify(asset|payload)",
        "transport_wrappers": [
          {
            "module": "private/runtime/kye-data-classification-agent",
            "transport": "http",
            "note": "HTTP Worker — POST /v1/classifications"
          }
        ],
        "competitor_forbidden_patterns": [
          "function DataClassificationEngine(",
          "const DataClassificationEngine =",
          "class DataClassificationEngine "
        ]
      },
      {
        "concept_id": "decision.pipeline",
        "name": "Decision Engine (authority + purpose + rules pipeline → Decision Map)",
        "plane": "decision",
        "constitution_ref": "constitution/14-AGENTS-AND-ENGINES.md",
        "ssot_module": "private/runtime/decision-engine",
        "ssot_package": "@kye/decision-engine",
        "ssot_entry_point": "deterministic decision pipeline",
        "transport_wrappers": [],
        "competitor_forbidden_patterns": [
          "function DECISION_ENGINE_GOVERNANCE_EVENT_FAMILY(",
          "const DECISION_ENGINE_GOVERNANCE_EVENT_FAMILY =",
          "class DECISION_ENGINE_GOVERNANCE_EVENT_FAMILY "
        ]
      },
      {
        "concept_id": "derived.freshness_verify",
        "name": "Verify every generator's committed output matches what it would produce",
        "plane": "governance",
        "constitution_ref": "constitution/00-INDEX.md",
        "ssot_module": "scripts/ci/fresh-all.mjs",
        "ssot_package": null,
        "ssot_entry_point": "npm run -s test:fresh-all",
        "transport_wrappers": [],
        "competitor_forbidden_patterns": [
          "const GENERATORS = ["
        ],
        "competitor_baseline_key": "implementation_canonical__competitors__derived_freshness_verify",
        "migration": {
          "status": "complete",
          "note": "Registered 2026-08-15. It must never maintain a second generator list — that divergence is what let six derived artefacts drift silently. It is also the authority the build-derived-all reverse-check reads: a generator EXCLUDED from the chain whose output fresh-all verifies must say so in its exclusion reason."
        }
      },
      {
        "concept_id": "derived.regeneration",
        "name": "Regenerate the full derived tree to a fixpoint, in dependency order",
        "plane": "governance",
        "constitution_ref": "constitution/00-INDEX.md",
        "ssot_module": "scripts/build-derived-all.mjs",
        "ssot_package": null,
        "ssot_entry_point": "node scripts/build-derived-all.mjs [--check]",
        "transport_wrappers": [],
        "competitor_forbidden_patterns": [
          "const PHASES = [",
          "const P1 = ["
        ],
        "competitor_baseline_key": "implementation_canonical__competitors__derived_regeneration",
        "migration": {
          "status": "complete",
          "note": "Registered 2026-08-15. Membership and order are DATA in private/specs/propagators/propagator-registry.json; this module is the engine. Both .githooks/pre-commit and .githooks/pre-push invoke it — pre-commit generates and stages, pre-push verifies. Importing it for data EXECUTES it (a full fixpoint run); probe it by spawning, never by import()."
        }
      },
      {
        "concept_id": "diagnostic.engine",
        "name": "Authority Finality Diagnostic — gateway handler",
        "plane": "diagnostic",
        "constitution_ref": "constitution/40-IMPLEMENTATION-CANONICAL.md",
        "ssot_module": "private/runtime/gateway/src/handlers/diagnostic.ts",
        "ssot_package": null,
        "ssot_entry_point": "sealDiagnostic / mapDiagnosticFramework / verifyDiagnostic",
        "endpoints": [
          "POST /v1/diagnostic/seal",
          "POST /v1/diagnostic/framework-map",
          "POST /v1/diagnostic/verify"
        ],
        "transport_wrappers": [
          {
            "module": "private/sdks/typescript/src/client.ts",
            "transport": "http-client",
            "note": "client.sealDiagnostic() / client.mapDiagnosticFramework() / client.verifyDiagnostic()"
          },
          {
            "module": "private/sdks/python/kye_sdk/client.py",
            "transport": "http-client",
            "note": "client.diagnostic_seal() / diagnostic_framework_map() / diagnostic_verify()"
          },
          {
            "module": "private/cli/src/cmds/diagnostic.ts",
            "transport": "cli",
            "note": "kye diagnostic seal | framework-map | verify"
          },
          {
            "module": "public/oss/kye-claude-code-plugin/commands/report.md",
            "transport": "plugin",
            "note": "Claude Code /kye:report wraps the seal endpoint"
          },
          {
            "module": "public/oss/kye-claude-code-plugin/commands/framework-map.md",
            "transport": "plugin",
            "note": "Claude Code /kye:framework-map wraps the framework-map endpoint"
          },
          {
            "module": "public/oss/kye-claude-code-plugin/commands/verify.md",
            "transport": "plugin",
            "note": "Claude Code /kye:verify wraps the verify endpoint"
          },
          {
            "module": "public/oss/kye-mcp-server/src/server.ts",
            "transport": "mcp",
            "note": "MCP tools kye_report / kye_framework_map / kye_verify reach every MCP-aware client (Claude Desktop, Claude Code, Cursor, Windsurf, Cline, Zed)"
          }
        ],
        "notes": [
          "Production weighting + canonicalisation + palette MAP + Ed25519 signing live in the proprietary diagnostic-engine reached via KYE_DIAGNOSTIC_ENGINE_URL. Smoke-test fallback in the gateway handler uses the published simple-average reference.",
          "Free-tier quota: 3 sealed envelopes / month / actor_email; enforced via D1 033 sealed_reports + actor_email + month JOIN.",
          "framework-map reads private/specs/compliance/nist-800-53-rev5-hub.json (canonical) with a fallback to the public mirror at public/site/.well-known/nist-800-53-hub.json; 24-hour in-process cache; no authentication required.",
          "verify is an online courtesy lookup against the JWKS at https://kyeprotocol.com/.well-known/jwks.json. Full offline Ed25519 verification of canonical bytes is published in the SDK verifier."
        ],
        "competitor_forbidden_patterns": [
          "function mapDiagnosticFramework(",
          "const mapDiagnosticFramework =",
          "class mapDiagnosticFramework "
        ]
      },
      {
        "concept_id": "directory.index",
        "name": "Directory Engine (entity/authority/evidence index model + federated DirectoryQuery)",
        "plane": "runtime",
        "constitution_ref": "constitution/17-DIRECTORY-SEARCH.md",
        "ssot_module": "private/runtime/directory-engine",
        "ssot_package": "@kye/directory-engine",
        "ssot_entry_point": "IndexClient + DirectoryQuery + AuthoritySearch + EvidenceFinder",
        "transport_wrappers": [],
        "notes": "Owns the index/query MODEL; the query SURFACE is search.query (kye-search-engine).",
        "competitor_forbidden_patterns": [
          "function DirectoryQueryBuilder(",
          "const DirectoryQueryBuilder =",
          "class DirectoryQueryBuilder "
        ]
      },
      {
        "concept_id": "durable-objects.classes",
        "name": "Durable Object class set (rate limiter, audit batcher, drift counter, replay cursor, dual-control broker)",
        "plane": "runtime",
        "constitution_ref": "constitution/16-EDGE-RUNTIME.md",
        "ssot_module": "private/runtime/durable-objects",
        "ssot_package": "@kye/durable-objects",
        "ssot_entry_point": "canonical Durable Object classes",
        "transport_wrappers": [],
        "competitor_forbidden_patterns": [
          "function DualControlBroker(",
          "const DualControlBroker =",
          "class DualControlBroker "
        ]
      },
      {
        "concept_id": "edge.wrangler_config_predicate",
        "name": "Is this filename a wrangler config (any shape the repo uses)?",
        "plane": "runtime",
        "constitution_ref": "constitution/16-EDGE-RUNTIME.md",
        "ssot_module": "scripts/gates/_lib.mjs",
        "ssot_package": null,
        "ssot_entry_point": "isWranglerConfig(name) / WRANGLER_CONFIG_RE",
        "transport_wrappers": [],
        "competitor_forbidden_patterns": [
          "name === \"wrangler.toml\"",
          "=== 'wrangler.toml'",
          "endsWith(\"wrangler.toml\")"
        ],
        "competitor_baseline_key": "implementation_canonical__competitors__edge_wrangler_config_predicate",
        "migration": {
          "status": "complete",
          "note": "Registered 2026-08-15. The literal `name === \"wrangler.toml\"` was re-typed in 18 scripts, which made cf-resource-governance-coverage blind to per-region and prefixed configs while reporting the fleet clean. The canonical existed from 2026-08-11 and one consumer had adopted it; an agent then nearly defined a SECOND copy inside the same file that already exported it."
        }
      },
      {
        "concept_id": "email-action.token",
        "name": "Email-action one-click HMAC token",
        "plane": "auth",
        "constitution_ref": "constitution/27-COMMERCIAL-LIFECYCLE.md",
        "ssot_module": "public/site/functions/api/_lib/email-action-token.js",
        "ssot_package": null,
        "ssot_entry_point": "mintEmailActionToken / verifyEmailActionToken",
        "transport_wrappers": [
          {
            "module": "public/site/functions/api/_lib/admin-action-buttons.js",
            "transport": "render",
            "note": "Canonical button-renderer used by every actionable admin notification (pilot, consultant, expert-review, key-rotation, etc.). Mints via the SSOT lib."
          },
          {
            "module": "public/admin/functions/email-action.js",
            "transport": "dispatcher",
            "note": "Single canonical /email-action endpoint on admin.kyeprotocol.com. Verifies via the SSOT, enforces single-use via email_action_token_used, applies expert-review inline; queues every other domain to the per-domain consumer."
          }
        ],
        "secret_keys": [
          "KYE_EMAIL_ACTION_SECRET_CURRENT",
          "KYE_EMAIL_ACTION_SECRET_PREVIOUS"
        ],
        "removed_competitors": [
          "public/site/functions/api/_lib/expert-action-token.js (deleted 2026-05-23 — parallel HMAC lib with separate EXPERT_ACTION_SECRET)",
          "public/admin/functions/api/v1/expert-reviews/[id]/email-action.js (deleted 2026-05-23 — per-domain dispatcher)"
        ],
        "competitor_forbidden_patterns": [
          "function verifyEmailActionToken(",
          "const verifyEmailActionToken =",
          "class verifyEmailActionToken "
        ]
      },
      {
        "concept_id": "entity.resolve",
        "name": "Entity Engine (entity registry + KYEID parse/format/generate + faceted lookup)",
        "plane": "identity",
        "constitution_ref": "constitution/01-NAMING.md",
        "ssot_module": "private/runtime/entity-engine",
        "ssot_package": "@kye/entity-engine",
        "ssot_entry_point": "KYEID parse/format + entity registry",
        "transport_wrappers": [],
        "competitor_forbidden_patterns": [
          "function EntityRegistryError(",
          "const EntityRegistryError =",
          "class EntityRegistryError "
        ]
      },
      {
        "concept_id": "entity.state",
        "name": "State Engine (six-dimension entity state vector + transitions)",
        "plane": "runtime",
        "constitution_ref": "constitution/18-OPERATING-MODEL.md",
        "ssot_module": "private/runtime/state-engine",
        "ssot_package": "@kye/state-engine",
        "ssot_entry_point": "state vector + deterministic transitions + invariant validation",
        "transport_wrappers": [],
        "competitor_forbidden_patterns": [
          "function StateEngine(",
          "const StateEngine =",
          "class StateEngine "
        ]
      },
      {
        "concept_id": "evidence-import.bridge",
        "name": "Universal evidence importer — connectors → sealed evidence",
        "plane": "evidence",
        "constitution_ref": "constitution/13-RESILIENCE-LOOP.md",
        "ssot_module": "private/runtime/kye-evidence-import-worker",
        "ssot_package": null,
        "ssot_entry_point": "POST /v1/evidence-import",
        "transport_wrappers": [
          {
            "module": "public/app/functions/api/v1/evidence-import.js",
            "transport": "pages-function",
            "note": "kye-app Pages Function that fronts the worker for the customer dashboard's connectors page; auth via tenant session, forwards to the worker with IMPORT_WORKER_BEARER."
          },
          {
            "module": "public/widgets/evidence-import/v1",
            "transport": "embed-widget",
            "note": "Embeddable evidence-import widget (post-message conformant)."
          }
        ],
        "note": "Transport bridge — the worker hosts the canonical /v1/evidence-import HTTP surface that connector adapters and the embed widget post raw evidence batches to; the worker normalises and forwards to the canonical sealing pipeline. Not a stateful engine; no SSOT library because the canonical sealing logic lives downstream in the evidence-pack-assembler.",
        "competitor_forbidden_patterns": [
          "function buildImportBatch(",
          "const buildImportBatch =",
          "class buildImportBatch "
        ]
      },
      {
        "concept_id": "evidence.chain",
        "name": "Evidence Engine (Decision Map builder + Evidence Pack assembler core)",
        "plane": "evidence",
        "constitution_ref": "constitution/13-RESILIENCE-LOOP.md",
        "ssot_module": "private/runtime/evidence-engine",
        "ssot_package": "@kye/evidence-engine",
        "ssot_entry_point": "Decision Map builder + Evidence Pack assembler",
        "transport_wrappers": [],
        "competitor_forbidden_patterns": [
          "function assembleEvidencePackViaCustody(",
          "const assembleEvidencePackViaCustody =",
          "class assembleEvidencePackViaCustody "
        ]
      },
      {
        "concept_id": "evidence.pack.assemble",
        "name": "Evidence Pack assembler",
        "plane": "evidence",
        "constitution_ref": "constitution/13-RESILIENCE-LOOP.md",
        "ssot_module": "private/runtime/evidence-pack-assembler",
        "ssot_package": null,
        "ssot_entry_point": "assemblePack(decisionId, fragments)",
        "transport_wrappers": [
          {
            "module": "private/runtime/evidence-pack-sealer-periodic",
            "transport": "queue",
            "note": "Periodic sealer triggers assembly on a cron-tolerated cadence per §35"
          }
        ],
        "competitor_forbidden_patterns": [
          "function makeAssembleMessage(",
          "const makeAssembleMessage =",
          "class makeAssembleMessage "
        ]
      },
      {
        "concept_id": "gateway.dispatch",
        "name": "Gateway / PEP middleware",
        "plane": "runtime",
        "constitution_ref": "constitution/16-EDGE-RUNTIME.md",
        "ssot_module": "private/runtime/gateway",
        "ssot_package": "@kye/gateway",
        "ssot_entry_point": "createGateway(...)",
        "transport_wrappers": [
          {
            "module": "private/runtime/gateway-worker",
            "transport": "http",
            "note": "Legacy CF Worker — being consolidated to kye-gateway-worker"
          },
          {
            "module": "private/runtime/kye-gateway-worker",
            "transport": "http",
            "note": "Canonical CF Worker hosting the gateway library"
          }
        ],
        "competitor_forbidden_patterns": [
          "function decideCapabilityInvocation(",
          "const decideCapabilityInvocation =",
          "class decideCapabilityInvocation "
        ]
      },
      {
        "concept_id": "generator.write-targets",
        "name": "Generator write-target detection (which canonical paths a generator writes)",
        "plane": "governance",
        "constitution_ref": "constitution/00-INDEX.md#0.49",
        "ssot_module": "scripts/lib/generator-writes.mjs",
        "ssot_entry_point": "writeTargetsIn(text)",
        "transport_wrappers": [
          {
            "module": "scripts/build-cascade-edges.mjs",
            "transport": "import",
            "must_import": "./lib/generator-writes.mjs",
            "note": "Assigns cascade node kind. Previously carried its own matcher that knew writeFileSync + named constants but not the writeJson helper."
          },
          {
            "module": "scripts/gates/generated-not-source.mjs",
            "transport": "import",
            "must_import": "../lib/generator-writes.mjs",
            "note": "Checks the label this builder assigns. Previously carried its own matcher that knew writeJson but could not resolve a named constant."
          }
        ],
        "competitor_forbidden_patterns": [
          "function constPathsFor",
          "const WRITE_IDENT_RE",
          "WRITE_LITERAL_RE"
        ],
        "note": "An x-er/x-or class: 'which paths does a generator write' is a question two consumers ask and MUST NOT answer differently. They did — each had half the matcher — and the gap between the halves was 24 generated artefacts labelled kind=source-of-truth in the cascade graph, the exact set §53 §3.2 could then not protect from a silently-reverted hand-edit. Registered here so a third half-matcher fails the competitor scan instead of quietly becoming the fourth answer."
      },
      {
        "concept_id": "html.escape",
        "name": "HTML escaper (text + quoted-attribute safe)",
        "plane": "surface",
        "constitution_ref": "constitution/00-INDEX.md#0.49",
        "ssot_module": "private/lib/html-escape",
        "ssot_entry_point": "escapeHtml(value)",
        "transport_wrappers": [
          {
            "module": "private/runtime/kye-comms-engine-worker/src/compiler.js",
            "transport": "projection",
            "note": "Byte-projected by scripts/build-html-escape-projection.mjs; equality verified by implementation-canonical."
          },
          {
            "module": "private/runtime/reporting-engine/src/templates.ts",
            "transport": "import",
            "must_import": "@kye/html-escape",
            "note": "STRICT-TS PACKAGE, cannot take the projection. tsconfig sets rootDir 'src' + include 'src/**/*', so a file outside src is not in the program, and noImplicitAny rejects the canonical's untyped parameter. Its current copy is COMPLETE and correct (all five characters, null-safe) — this is a duplicate, not a defect, which is why it is time-boxed rather than rushed. Closure is to publish the SSOT as @kye/html-escape with types and add the dependency."
          },
          {
            "module": "public/admin/functions/api/v1/pilot-applications/[id]/send-sign-in.js",
            "transport": "projection",
            "note": "Byte-projected by scripts/build-html-escape-projection.mjs; equality verified by implementation-canonical."
          },
          {
            "module": "public/admin/functions/email-action.js",
            "transport": "projection",
            "note": "Byte-projected by scripts/build-html-escape-projection.mjs; equality verified by implementation-canonical."
          },
          {
            "module": "public/admin/search.html",
            "transport": "projection",
            "note": "Byte-projected by scripts/build-html-escape-projection.mjs; equality verified by implementation-canonical. Enrolled 2026-08-10 — this copy was introduced by the #1505 security sweep, which is exactly the copy-N+1 this concept exists to prevent."
          },
          {
            "module": "public/app/assets/dashboard-realtime-components.js",
            "transport": "projection",
            "note": "Byte-projected by scripts/build-html-escape-projection.mjs; equality verified by implementation-canonical."
          },
          {
            "module": "public/app/assets/usage-page.js",
            "transport": "projection",
            "note": "Byte-projected by scripts/build-html-escape-projection.mjs; equality verified by implementation-canonical."
          },
          {
            "module": "public/app/coa/_assets/chrome.js",
            "transport": "projection",
            "note": "Byte-projected by scripts/build-html-escape-projection.mjs; equality verified by implementation-canonical."
          },
          {
            "module": "public/app/dashboard.html",
            "transport": "projection",
            "note": "Byte-projected by scripts/build-html-escape-projection.mjs; equality verified by implementation-canonical."
          },
          {
            "module": "public/app/document-governance.html",
            "transport": "projection",
            "note": "Byte-projected by scripts/build-html-escape-projection.mjs; equality verified by implementation-canonical."
          },
          {
            "module": "public/app/entity-passport.html",
            "transport": "projection",
            "note": "Byte-projected by scripts/build-html-escape-projection.mjs; equality verified by implementation-canonical. Enrolled 2026-08-10 — this copy was introduced by the #1505 security sweep, which is exactly the copy-N+1 this concept exists to prevent."
          },
          {
            "module": "public/app/ep/_assets/chrome.js",
            "transport": "projection",
            "note": "Byte-projected by scripts/build-html-escape-projection.mjs; equality verified by implementation-canonical."
          },
          {
            "module": "public/sandbox/estate-planning/assets/console.js",
            "transport": "projection",
            "note": "Byte-projected by scripts/build-html-escape-projection.mjs; equality verified by implementation-canonical. Enrolled 2026-08-10 — this copy was introduced by the #1505 security sweep, which is exactly the copy-N+1 this concept exists to prevent."
          },
          {
            "module": "public/sandbox/main.js",
            "transport": "projection",
            "note": "Byte-projected by scripts/build-html-escape-projection.mjs; equality verified by implementation-canonical."
          },
          {
            "module": "public/site/assets/site-authority-record.js",
            "transport": "projection",
            "note": "Byte-projected by scripts/build-html-escape-projection.mjs; equality verified by implementation-canonical."
          },
          {
            "module": "public/site/functions/api/_lib/admin-action-buttons.js",
            "transport": "projection",
            "note": "Byte-projected by scripts/build-html-escape-projection.mjs; equality verified by implementation-canonical."
          },
          {
            "module": "public/site/functions/api/_lib/consultant-emails.js",
            "transport": "projection",
            "note": "Byte-projected by scripts/build-html-escape-projection.mjs; equality verified by implementation-canonical."
          },
          {
            "module": "public/site/functions/api/_lib/persona-intake.js",
            "transport": "projection",
            "note": "Byte-projected by scripts/build-html-escape-projection.mjs; equality verified by implementation-canonical."
          },
          {
            "module": "public/site/functions/api/audit-pilot.js",
            "transport": "projection",
            "note": "Byte-projected by scripts/build-html-escape-projection.mjs; equality verified by implementation-canonical."
          },
          {
            "module": "public/site/functions/api/consultant-lead.js",
            "transport": "projection",
            "note": "Byte-projected by scripts/build-html-escape-projection.mjs; equality verified by implementation-canonical."
          },
          {
            "module": "public/site/functions/api/contact.js",
            "transport": "projection",
            "note": "Byte-projected by scripts/build-html-escape-projection.mjs; equality verified by implementation-canonical."
          },
          {
            "module": "public/site/functions/api/dsar.js",
            "transport": "projection",
            "note": "Byte-projected by scripts/build-html-escape-projection.mjs; equality verified by implementation-canonical."
          },
          {
            "module": "public/site/functions/api/engage-access.js",
            "transport": "projection",
            "note": "Byte-projected by scripts/build-html-escape-projection.mjs; equality verified by implementation-canonical."
          },
          {
            "module": "public/site/functions/api/expert-review.js",
            "transport": "projection",
            "note": "Byte-projected by scripts/build-html-escape-projection.mjs; equality verified by implementation-canonical."
          },
          {
            "module": "public/site/functions/api/v1/poc/apply.js",
            "transport": "projection",
            "note": "Byte-projected by scripts/build-html-escape-projection.mjs; equality verified by implementation-canonical."
          },
          {
            "module": "public/site/main.js",
            "transport": "projection",
            "note": "Byte-projected by scripts/build-html-escape-projection.mjs; equality verified by implementation-canonical. Enrolled 2026-08-10 — this copy was introduced by the #1505 security sweep, which is exactly the copy-N+1 this concept exists to prevent."
          },
          {
            "module": "public/status/assets/status.js",
            "transport": "projection",
            "note": "Byte-projected by scripts/build-html-escape-projection.mjs; equality verified by implementation-canonical."
          },
          {
            "module": "public/widgets/action-approval/v1/widget.js",
            "transport": "projection",
            "note": "Byte-projected by scripts/build-html-escape-projection.mjs; equality verified by implementation-canonical."
          },
          {
            "module": "public/widgets/authority-scope/v1/widget.js",
            "transport": "projection",
            "note": "Byte-projected by scripts/build-html-escape-projection.mjs; equality verified by implementation-canonical."
          },
          {
            "module": "public/widgets/consultant-card/v1/index.html",
            "transport": "projection",
            "note": "Byte-projected by scripts/build-html-escape-projection.mjs; equality verified by implementation-canonical."
          },
          {
            "module": "public/widgets/critical-point-review/v1/widget.js",
            "transport": "projection",
            "note": "Byte-projected by scripts/build-html-escape-projection.mjs; equality verified by implementation-canonical."
          },
          {
            "module": "public/widgets/entity-passport/v1/widget.js",
            "transport": "projection",
            "note": "Byte-projected by scripts/build-html-escape-projection.mjs; equality verified by implementation-canonical."
          },
          {
            "module": "public/widgets/partner-registry/v1/index.html",
            "transport": "projection",
            "note": "Byte-projected by scripts/build-html-escape-projection.mjs; equality verified by implementation-canonical."
          },
          {
            "module": "scripts/build-ontology-derivative.mjs",
            "transport": "projection",
            "note": "Byte-projected by scripts/build-html-escape-projection.mjs; equality verified by implementation-canonical."
          },
          {
            "module": "site/src/fragments/admin/search.body.html",
            "transport": "projection",
            "note": "Byte-projected by scripts/build-html-escape-projection.mjs; equality verified by implementation-canonical. Enrolled 2026-08-10 — this copy was introduced by the #1505 security sweep, which is exactly the copy-N+1 this concept exists to prevent."
          },
          {
            "module": "site/src/fragments/app/dashboard.body.html",
            "transport": "projection",
            "note": "Byte-projected by scripts/build-html-escape-projection.mjs; equality verified by implementation-canonical."
          },
          {
            "module": "site/src/fragments/app/document-governance.body.html",
            "transport": "projection",
            "note": "Byte-projected by scripts/build-html-escape-projection.mjs; equality verified by implementation-canonical."
          },
          {
            "module": "site/src/fragments/app/entity-passport.body.html",
            "transport": "projection",
            "note": "Byte-projected by scripts/build-html-escape-projection.mjs; equality verified by implementation-canonical. Enrolled 2026-08-10 — this copy was introduced by the #1505 security sweep, which is exactly the copy-N+1 this concept exists to prevent."
          },
          {
            "module": "site/src/fragments/widgets/consultant-card/v1/home.tail.html",
            "transport": "projection",
            "note": "Byte-projected by scripts/build-html-escape-projection.mjs; equality verified by implementation-canonical."
          },
          {
            "module": "site/src/fragments/widgets/partner-registry/v1/home.tail.html",
            "transport": "projection",
            "note": "Byte-projected by scripts/build-html-escape-projection.mjs; equality verified by implementation-canonical."
          },
          {
            "module": "public/site/assets/expert-wall-form.js",
            "transport": "projection",
            "note": "Browser code — cannot import a Node module, so it carries the canonical bytes between the marker comments and implementation-canonical verifies the equality. Enrolled 2026-08-12 replacing a hand-rolled esc() that escaped & < > but NOT the double quote, while all eight of its call sites interpolate into DOUBLE-QUOTED HTML attributes (href, title, aria-label, data-cite, data-embed). `x\" onmouseover=\"alert(1)` passed through it unchanged. CodeQL js/incomplete-html-attribute-sanitization."
          },
          {
            "module": "public/app/assets/apps-page.js",
            "transport": "projection",
            "note": "Byte-projected by scripts/build-html-escape-projection.mjs; equality verified by implementation-canonical. Added 2026-08-14 with the Class-1 sanitization sweep: this page interpolated a DOM-attribute-sourced empty-state string into innerHTML (CodeQL js/xss-through-dom). It carried no escaper, so it is reached through the declared insertion marker."
          },
          {
            "module": "public/app/assets/authorities-page.js",
            "transport": "projection",
            "note": "Byte-projected by scripts/build-html-escape-projection.mjs; equality verified by implementation-canonical. Added 2026-08-14 with the Class-1 sanitization sweep: this page interpolated a DOM-attribute-sourced empty-state string into innerHTML (CodeQL js/xss-through-dom). It carried no escaper, so it is reached through the declared insertion marker."
          },
          {
            "module": "public/app/assets/authority-wallet-page.js",
            "transport": "projection",
            "note": "Byte-projected by scripts/build-html-escape-projection.mjs; equality verified by implementation-canonical. Added 2026-08-14 with the Class-1 sanitization sweep: this page interpolated a DOM-attribute-sourced empty-state string into innerHTML (CodeQL js/xss-through-dom). It carried no escaper, so it is reached through the declared insertion marker."
          },
          {
            "module": "public/app/assets/classification-page.js",
            "transport": "projection",
            "note": "Byte-projected by scripts/build-html-escape-projection.mjs; equality verified by implementation-canonical. Added 2026-08-14 with the Class-1 sanitization sweep: this page interpolated a DOM-attribute-sourced empty-state string into innerHTML (CodeQL js/xss-through-dom). It carried no escaper, so it is reached through the declared insertion marker."
          },
          {
            "module": "public/app/assets/connectors-page.js",
            "transport": "projection",
            "note": "Byte-projected by scripts/build-html-escape-projection.mjs; equality verified by implementation-canonical. Added 2026-08-14 with the Class-1 sanitization sweep: this page interpolated a DOM-attribute-sourced empty-state string into innerHTML (CodeQL js/xss-through-dom). It carried no escaper, so it is reached through the declared insertion marker."
          },
          {
            "module": "public/app/assets/entities-page.js",
            "transport": "projection",
            "note": "Byte-projected by scripts/build-html-escape-projection.mjs; equality verified by implementation-canonical. Added 2026-08-14 with the Class-1 sanitization sweep: this page interpolated a DOM-attribute-sourced empty-state string into innerHTML (CodeQL js/xss-through-dom). It carried no escaper, so it is reached through the declared insertion marker."
          },
          {
            "module": "public/app/assets/plugins-page.js",
            "transport": "projection",
            "note": "Byte-projected by scripts/build-html-escape-projection.mjs; equality verified by implementation-canonical. Added 2026-08-14 with the Class-1 sanitization sweep: this page interpolated a DOM-attribute-sourced empty-state string into innerHTML (CodeQL js/xss-through-dom). It carried no escaper, so it is reached through the declared insertion marker."
          },
          {
            "module": "public/app/assets/purposes-page.js",
            "transport": "projection",
            "note": "Byte-projected by scripts/build-html-escape-projection.mjs; equality verified by implementation-canonical. Added 2026-08-14 with the Class-1 sanitization sweep: this page interpolated a DOM-attribute-sourced empty-state string into innerHTML (CodeQL js/xss-through-dom). It carried no escaper, so it is reached through the declared insertion marker."
          },
          {
            "module": "public/app/assets/replay-page.js",
            "transport": "projection",
            "note": "Byte-projected by scripts/build-html-escape-projection.mjs; equality verified by implementation-canonical. Added 2026-08-14 with the Class-1 sanitization sweep: this page interpolated a DOM-attribute-sourced empty-state string into innerHTML (CodeQL js/xss-through-dom). It carried no escaper, so it is reached through the declared insertion marker."
          },
          {
            "module": "public/app/assets/scopes-page.js",
            "transport": "projection",
            "note": "Byte-projected by scripts/build-html-escape-projection.mjs; equality verified by implementation-canonical. Added 2026-08-14 with the Class-1 sanitization sweep: this page interpolated a DOM-attribute-sourced empty-state string into innerHTML (CodeQL js/xss-through-dom). It carried no escaper, so it is reached through the declared insertion marker."
          }
        ],
        "competitor_forbidden_patterns": [
          "function escapeHtml(",
          "function escapeHTML(",
          "const escapeHtml =",
          "const escapeHTML ="
        ],
        "competitor_scan_extensions": [
          ".html"
        ],
        "migration": {
          "status": "in-progress",
          "advisory_until": "2026-11-08",
          "tracked_in": "constitution/DECAY-WINDOWS.md",
          "wrappers_pending_import": [
            "private/runtime/reporting-engine/src/templates.ts"
          ]
        }
      },
      {
        "concept_id": "key.custody",
        "name": "Key Custody adapter (HSM/KMS-backed signing)",
        "plane": "runtime",
        "constitution_ref": "constitution/16-EDGE-RUNTIME.md",
        "ssot_module": "private/runtime/key-custody",
        "ssot_package": "@kye/key-custody",
        "ssot_entry_point": "AWS/GCP/Azure KMS + PKCS#11 HSM adapters",
        "transport_wrappers": [],
        "competitor_forbidden_patterns": [
          "function CKM_EC_EDWARDS_KEY_PAIR_GEN(",
          "const CKM_EC_EDWARDS_KEY_PAIR_GEN =",
          "class CKM_EC_EDWARDS_KEY_PAIR_GEN "
        ]
      },
      {
        "concept_id": "learn.articles",
        "name": "Education-rail articles + glossary",
        "plane": "surface",
        "constitution_ref": "constitution/39-LEARN-RAIL.md",
        "ssot_module": "private/specs/learn",
        "ssot_package": null,
        "ssot_entry_point": "manifest.json + glossary.json",
        "transport_wrappers": [],
        "competitor_scan_exemption": {
          "reason": "Articles are content records in a manifest, not code; a duplicate is a second manifest entry rather than a second implementation.",
          "enforced_by": "learn-manifest-alive"
        }
      },
      {
        "concept_id": "markdown.cell_escape",
        "name": "Markdown table-cell escaper",
        "plane": "governance",
        "constitution_ref": "constitution/00-INDEX.md#0.49",
        "ssot_module": "private/lib/markdown-cell",
        "ssot_entry_point": "markdownCell(value)",
        "competitor_forbidden_patterns": [
          "replace(/\\|/g",
          "function markdownCell(",
          "const markdownCell ="
        ],
        "competitor_baseline_key": "implementation_canonical__competitors__markdown_cell_escape",
        "transport_wrappers": [],
        "migration": {
          "status": "complete",
          "tracked_in": "private/specs/ratchets/baselines.json#implementation_canonical__competitors__markdown_cell_escape"
        }
      },
      {
        "concept_id": "marketplace.registry",
        "name": "Marketplace Registry (rule-pack marketplace index/filter/trust-score/verify)",
        "plane": "billing",
        "constitution_ref": "constitution/31-DATA-GOVERNANCE-PACK.md",
        "ssot_module": "private/runtime/marketplace-registry",
        "ssot_package": "@kye/marketplace-registry",
        "ssot_entry_point": "index + filter + trust-score + signature-verify",
        "transport_wrappers": [
          {
            "module": "private/runtime/marketplace-worker",
            "transport": "http",
            "note": "HTTP surface (Marketplace Rail)"
          }
        ],
        "competitor_forbidden_patterns": [
          "function MarketplaceRegistry(",
          "const MarketplaceRegistry =",
          "class MarketplaceRegistry "
        ]
      },
      {
        "concept_id": "mcp.tools",
        "name": "KYE MCP Server (locked KYE Protocol tool set over MCP)",
        "plane": "runtime",
        "constitution_ref": "constitution/15-MCP-AND-SDK.md",
        "ssot_module": "private/runtime/mcp-server",
        "ssot_package": "@kye/mcp-server",
        "ssot_entry_point": "MCP server (stdio transport)",
        "transport_wrappers": [
          {
            "module": "private/runtime/kye-mcp-server-worker",
            "transport": "http",
            "note": "Streamable-HTTP MCP server Worker (§15)"
          }
        ],
        "competitor_forbidden_patterns": [
          "function CONTROL_PLANE_TOOL_OUTPUT_SCHEMA(",
          "const CONTROL_PLANE_TOOL_OUTPUT_SCHEMA =",
          "class CONTROL_PLANE_TOOL_OUTPUT_SCHEMA "
        ]
      },
      {
        "concept_id": "oscal.export",
        "name": "OSCAL Exporter (KYE evidence → NIST OSCAL JSON)",
        "plane": "audit",
        "constitution_ref": "constitution/21-DELEGATED-AUDITABILITY.md",
        "ssot_module": "private/runtime/oscal-exporter",
        "ssot_package": "@kye/oscal-exporter",
        "ssot_entry_point": "project evidence → OSCAL component-definition / SSP / assessment-results",
        "transport_wrappers": [
          {
            "module": "private/runtime/kye-oscal-exporter-worker",
            "transport": "http",
            "note": "HTTP Worker (§21)"
          }
        ],
        "competitor_forbidden_patterns": [
          "function exportComponentDefinition(",
          "const exportComponentDefinition =",
          "class exportComponentDefinition "
        ]
      },
      {
        "concept_id": "policy.administration",
        "name": "Policy Administration Point (Operating Model → Compiled Authority Bundle compiler)",
        "plane": "decision",
        "constitution_ref": "constitution/25-EDGE-GOVERNANCE.md",
        "ssot_module": "private/runtime/pap",
        "ssot_package": "@kye/pap",
        "ssot_entry_point": "Control Compiler + signed Review Records",
        "transport_wrappers": [],
        "competitor_forbidden_patterns": [
          "function CONTROL_COMPILER_VERSION(",
          "const CONTROL_COMPILER_VERSION =",
          "class CONTROL_COMPILER_VERSION "
        ]
      },
      {
        "concept_id": "policy.decision",
        "name": "Policy Decision (PDP)",
        "plane": "decision",
        "constitution_ref": "constitution/14-AGENTS-AND-ENGINES.md",
        "ssot_module": "private/runtime/pdp",
        "ssot_package": "@kye/pdp",
        "ssot_entry_point": "DecisionPoint.decide()",
        "transport_wrappers": [
          {
            "module": "private/runtime/kye-pdp-worker",
            "transport": "http",
            "must_import": "@kye/pdp",
            "note": "CF Worker HTTP surface — Phase 1 import (stableHash) complete 2026-05-19; Phase 2 (full DecisionPoint adapter for resolvers + evidence sink) tracked separately"
          },
          {
            "module": "private/runtime/epdp",
            "transport": "embedded",
            "must_import": "@kye/pdp",
            "note": "Embedded wrapper — imports canonicalJsonString from SSOT so HMAC-signed bundles hash bit-identically with central PDP"
          },
          {
            "module": "private/runtime/spdp",
            "transport": "sidecar",
            "must_import": "@kye/pdp",
            "note": "Sidecar — exports adaptKyePdpAsUpstream() bridge so sidecar deployments host the SSOT DecisionPoint in-process"
          }
        ],
        "competitor_forbidden_patterns": [
          "function NativePolicyEngineAdapter(",
          "const NativePolicyEngineAdapter =",
          "class NativePolicyEngineAdapter "
        ]
      },
      {
        "concept_id": "purpose.admit",
        "name": "Purpose & Scope Engine (Purpose Permission admit/issue/revoke)",
        "plane": "decision",
        "constitution_ref": "constitution/12-PURPOSE-PERMISSION.md",
        "ssot_module": "private/runtime/purpose-engine",
        "ssot_package": "@kye/purpose-engine",
        "ssot_entry_point": "admit(grant, request, now, signals)",
        "transport_wrappers": [],
        "competitor_forbidden_patterns": [
          "export function admit("
        ],
        "migration": {
          "status": "in-progress",
          "advisory_until": "2026-08-29",
          "tracked_in": "constitution/DECAY-WINDOWS.md",
          "wrappers_pending_import": [
            "private/runtime/gateway-worker",
            "private/runtime/mcp-server"
          ]
        }
      },
      {
        "concept_id": "rate-limiting.tenant",
        "name": "Tenant rate-limiting (Durable Object backed; in-memory reference for tests)",
        "plane": "runtime",
        "constitution_ref": "constitution/16-EDGE-RUNTIME.md",
        "ssot_module": "private/runtime/gateway-worker",
        "ssot_package": null,
        "ssot_entry_point": "TenantRateLimiter Durable Object + src/middleware/ratelimit.ts",
        "transport_wrappers": [
          {
            "module": "private/runtime/gateway",
            "transport": "library",
            "note": "In-process token-bucket reference for single-process tests at src/middleware/rate-limit.ts. The DO-backed limiter on gateway-worker is the production authority."
          }
        ],
        "competitor_forbidden_patterns": [
          "function analyticsReplayEquivalenceRoute(",
          "const analyticsReplayEquivalenceRoute =",
          "class analyticsReplayEquivalenceRoute "
        ]
      },
      {
        "concept_id": "render.comment_strip",
        "name": "Comment stripping for source scanners (code vs. prose)",
        "plane": "governance",
        "constitution_ref": "constitution/00-INDEX.md",
        "ssot_module": "scripts/lib/strip-comments.mjs",
        "ssot_package": null,
        "ssot_entry_point": "stripComments(src, { dialect, preservePositions })",
        "transport_wrappers": [
          {
            "module": "scripts/gates/_lib.mjs",
            "transport": "library",
            "must_import": "../lib/strip-comments.mjs",
            "note": "stripCodeComments(src, { html }) — the HTML-aware entry point. It adds ONLY the markup branch (blank comments, then lex script bodies as js and style bodies as css) and delegates every code-lexing decision to the canonical. It USED to carry its own lexer, and the two disagreed on 30 of 1200 files: in 14 this one deleted live code because its regex state did not track the character class in /[^/]+/, and in 14 it left whole comments unstripped. The SSOT moved here after that measurement — the more capable implementation (7 dialects, preservePositions, regex-vs-division by value position) wins, and the HTML branch it lacked is preserved by this wrapper."
          }
        ],
        "competitor_forbidden_patterns": [
          "function stripComments(",
          "const stripComments =",
          "/\\/\\*[\\s\\S]*?\\*\\//g"
        ],
        "competitor_baseline_key": "implementation_canonical__competitors__render_comment_strip",
        "migration": {
          "status": "in-progress",
          "tracked_in": "private/specs/ratchets/baselines.json#implementation_canonical__competitors__render_comment_strip"
        }
      },
      {
        "concept_id": "render.html_tag_match",
        "name": "HTML tag + comment matching for scanners (CodeQL js/bad-tag-filter class)",
        "plane": "governance",
        "constitution_ref": "constitution/00-INDEX.md",
        "ssot_module": "public/oss/software-constitution/kit/lib/html-tags.mjs",
        "ssot_package": null,
        "ssot_entry_point": "htmlCommentRe() / rawTextElementRe(tag) / blankHtmlComments() / blankRawTextBodies()",
        "transport_wrappers": [
          {
            "module": "scripts/lib/html-tags.mjs",
            "transport": "library",
            "must_import": "../../public/oss/software-constitution/kit/lib/html-tags.mjs",
            "note": "Re-export only, zero implementation. The canonical lives in the §42 kit because the kit is PUBLISHED and scaffolded into other repos: it imports nothing outside itself, so a copy there would ship its defects to every adopter. must_import is the mechanical proof this path forwards to the canonical instead of re-implementing it."
          }
        ],
        "competitor_forbidden_patterns": [
          "<\\/script>",
          "<\\/style>",
          "<!--[\\s\\S]*?-->"
        ],
        "competitor_baseline_key": "implementation_canonical__competitors__render_html_tag_match",
        "migration": {
          "status": "in-progress",
          "tracked_in": "private/specs/ratchets/baselines.json#implementation_canonical__competitors__render_html_tag_match"
        }
      },
      {
        "concept_id": "replay.derive",
        "name": "Replay Engine (Execution Context Seal + Determinism Proof + Replay Proof)",
        "plane": "evidence",
        "constitution_ref": "constitution/13-RESILIENCE-LOOP.md",
        "ssot_module": "private/runtime/replay-engine",
        "ssot_package": "@kye/replay-engine",
        "ssot_entry_point": "context seal + determinism proof",
        "transport_wrappers": [],
        "competitor_forbidden_patterns": [
          "function DeterminismProver(",
          "const DeterminismProver =",
          "class DeterminismProver "
        ]
      },
      {
        "concept_id": "replay.proof-generation",
        "name": "Replay-Proof™ generation (re-derive a decision from public signatures)",
        "plane": "evidence",
        "constitution_ref": "constitution/13-RESILIENCE-LOOP.md",
        "ssot_module": "private/runtime/replay-proof-generator",
        "ssot_package": null,
        "ssot_entry_point": "POST /v1/replay/derive — worker.js",
        "transport_wrappers": [],
        "competitor_scan_exemption": {
          "reason": "Proof generation is proven by OUTPUT EQUIVALENCE across engines, not by symbol uniqueness — two engines agreeing is the invariant, so a competing-symbol pattern would test the wrong thing.",
          "enforced_by": "engine-replay-equiv"
        }
      },
      {
        "concept_id": "reporting.synthesize",
        "name": "Reporting Engine (per-framework compliance report synthesis)",
        "plane": "audit",
        "constitution_ref": "constitution/21-DELEGATED-AUDITABILITY.md",
        "ssot_module": "private/runtime/reporting-engine",
        "ssot_package": "@kye/reporting-engine",
        "ssot_entry_point": "per-framework report synthesis from the audit chain",
        "transport_wrappers": [
          {
            "module": "private/runtime/kye-reporting-worker",
            "transport": "http",
            "note": "HTTP + cron period-close + auto-delivery Worker"
          },
          {
            "module": "private/runtime/kye-reporting-agent-worker",
            "transport": "http",
            "note": "Reporting Agent Worker (§26 stakeholder reports). Overlap with kye-reporting-worker flagged for runtime-consolidation review."
          }
        ],
        "competitor_forbidden_patterns": [
          "function sampleAuditChainRefs(",
          "const sampleAuditChainRefs =",
          "class sampleAuditChainRefs "
        ]
      },
      {
        "concept_id": "risk.score",
        "name": "Risk Engine (canonical risk tier + 0..100 risk score)",
        "plane": "decision",
        "constitution_ref": "constitution/13-RESILIENCE-LOOP.md",
        "ssot_module": "private/runtime/risk-engine",
        "ssot_package": "@kye/risk-engine",
        "ssot_entry_point": "risk tier + score per EU AI Act floor",
        "transport_wrappers": [
          {
            "module": "private/runtime/kye-risk-agent",
            "transport": "http",
            "note": "HTTP Worker — POST /v1/risk/assess"
          }
        ],
        "competitor_forbidden_patterns": [
          "function RiskEngine(",
          "const RiskEngine =",
          "class RiskEngine "
        ]
      },
      {
        "concept_id": "rules.evaluate",
        "name": "Rules Engine (rights/obligations/prohibitions/stop-conditions evaluator)",
        "plane": "decision",
        "constitution_ref": "constitution/14-AGENTS-AND-ENGINES.md",
        "ssot_module": "private/runtime/rules-engine",
        "ssot_package": "@kye/rules-engine",
        "ssot_entry_point": "evaluate(input, bundle) -> rule_result",
        "transport_wrappers": [],
        "competitor_forbidden_patterns": [
          "function RuleCompileError(",
          "const RuleCompileError =",
          "class RuleCompileError "
        ]
      },
      {
        "concept_id": "rules.gateway",
        "name": "Rules Gateway (rule-pack evaluation surface)",
        "plane": "runtime",
        "constitution_ref": "constitution/29-PROFILES-LITE.md",
        "ssot_module": "private/runtime/rules-gateway",
        "ssot_package": "@kye/rules-gateway",
        "ssot_entry_point": "evaluate(...)",
        "transport_wrappers": [
          {
            "module": "private/runtime/rules-gateway-worker",
            "transport": "http",
            "note": "CF Worker HTTP surface around the rules-gateway library"
          }
        ],
        "competitor_scan_exemption": {
          "reason": "The gateway's uniqueness question is orphan RULES rather than a duplicated symbol — a second rule set, not a second evaluate(). The operating-model gate answers that question directly.",
          "enforced_by": "om-no-orphan-rules"
        }
      },
      {
        "concept_id": "search.query",
        "name": "KYE Native Search Engine™ (D1 FTS5 lexical + Vectorize semantic query surface)",
        "plane": "runtime",
        "constitution_ref": "constitution/17-DIRECTORY-SEARCH.md",
        "ssot_module": "private/runtime/kye-search-engine",
        "ssot_package": "kye-search-engine",
        "ssot_entry_point": "POST /v1/search — worker.ts (F34 entitlement gate + F37 classification floor + F38 risk-tier cap + Ed25519-signed envelope + §0.3 audit emission)",
        "transport_wrappers": [
          {
            "module": "private/runtime/kye-search-indexer-worker",
            "transport": "queue",
            "note": "Index refresher — rebuilds the native D1 FTS5 + Vectorize substrate (cron full/incremental + kye-search-delta queue)."
          }
        ],
        "notes": "Pre-cutover legacy-search dead code at private/runtime/search/ deleted. The three legacy Cloudflare search workers were decommissioned 2026-08-05 (deleted via the Cloudflare API); native D1 FTS5 + Vectorize is the one search substrate.",
        "competitor_forbidden_patterns": [
          "function buildFtsQuery(",
          "const buildFtsQuery =",
          "class buildFtsQuery "
        ]
      },
      {
        "concept_id": "siem.export",
        "name": "SIEM Export (audit-log shipping to Splunk/Sentinel/Elastic/Datadog)",
        "plane": "audit",
        "constitution_ref": "constitution/14-AGENTS-AND-ENGINES.md",
        "ssot_module": "private/runtime/siem-export",
        "ssot_package": "@kye/siem-export",
        "ssot_entry_point": "push/pull SIEM shipping per tenant_siem_targets",
        "transport_wrappers": [
          {
            "module": "private/runtime/kye-siem-export-worker",
            "transport": "http",
            "note": "Streaming Worker (§14)"
          }
        ],
        "competitor_forbidden_patterns": [
          "function sentinelCanonicalString(",
          "const sentinelCanonicalString =",
          "class sentinelCanonicalString "
        ]
      },
      {
        "concept_id": "sql.like_escape",
        "name": "LIKE-pattern escaper for a user-supplied search term",
        "plane": "surface",
        "constitution_ref": "constitution/00-INDEX.md#0.49",
        "ssot_module": "private/lib/sql-like",
        "ssot_entry_point": "escapeLike(value)",
        "competitor_forbidden_patterns": [
          "replace(/[%_]/g",
          "function escapeLike(",
          "const escapeLike ="
        ],
        "competitor_baseline_key": "implementation_canonical__competitors__sql_like_escape",
        "transport_wrappers": [
          {
            "module": "public/app/functions/api/v1/search.js",
            "transport": "projection",
            "note": "Byte-projected by scripts/build-html-escape-projection.mjs; equality verified by implementation-canonical. A Pages Function cannot import from private/ (§33 IP/OSS line), so projection is the transport, exactly as for html.escape and url.safe."
          },
          {
            "module": "public/admin/functions/api/v1/search.js",
            "transport": "projection",
            "note": "Byte-projected by scripts/build-html-escape-projection.mjs; equality verified by implementation-canonical. A Pages Function cannot import from private/ (§33 IP/OSS line), so projection is the transport, exactly as for html.escape and url.safe."
          },
          {
            "module": "public/admin/functions/api/v1/issuers.js",
            "transport": "projection",
            "note": "Byte-projected by scripts/build-html-escape-projection.mjs; equality verified by implementation-canonical. A Pages Function cannot import from private/ (§33 IP/OSS line), so projection is the transport, exactly as for html.escape and url.safe."
          },
          {
            "module": "public/admin/functions/api/v1/evidence-index.js",
            "transport": "projection",
            "note": "Byte-projected by scripts/build-html-escape-projection.mjs; equality verified by implementation-canonical. A Pages Function cannot import from private/ (§33 IP/OSS line), so projection is the transport, exactly as for html.escape and url.safe."
          }
        ],
        "migration": {
          "status": "complete",
          "tracked_in": "private/specs/ratchets/baselines.json#implementation_canonical__competitors__sql_like_escape"
        }
      },
      {
        "concept_id": "toolchain.version_pin",
        "name": "Which exact version of an external toolchain component does KYE run?",
        "plane": "governance",
        "constitution_ref": "constitution/00-INDEX.md",
        "ssot_module": "private/specs/toolchain/deploy-toolchain.json",
        "ssot_package": null,
        "ssot_entry_point": "tools[].channels[].version (exact x.y.z, enforced by scripts/gates/deploy-toolchain-pinned.mjs)",
        "transport_wrappers": [],
        "competitor_forbidden_patterns": [
          "node-version: '2",
          "node-version: \"2"
        ],
        "competitor_baseline_key": "implementation_canonical__competitors__toolchain_version_pin",
        "migration": {
          "status": "complete",
          "note": "Registered 2026-08-15. The registry is tool-generic but held ONE member (wrangler) while node was pinned by hand 38 times across .github/workflows, four of them on an EOL major. Nobody noticed because there was no canonical version to drift FROM — the unpopulated-registry defect."
        }
      },
      {
        "concept_id": "ui.cache-bust",
        "name": "Cache-bust value used on every static asset URL",
        "plane": "surface",
        "constitution_ref": "constitution/06-WEBSITE.md",
        "ssot_module": "scripts/sync-marketing-counters.mjs",
        "ssot_package": null,
        "ssot_entry_point": "rolling value applied via 'npm run fix:consistency'",
        "transport_wrappers": [],
        "competitor_scan_exemption": {
          "reason": "The cache-bust value is a rolling STRING stamped across assets, not a callable symbol, so a second copy is a second value rather than a second function definition — a §40 pattern cannot see it.",
          "enforced_by": "cache-bust-canonical"
        }
      },
      {
        "concept_id": "ui.chrome",
        "name": "Site chrome (top-bar, footer, breadcrumbs, drawer)",
        "plane": "surface",
        "constitution_ref": "constitution/02-INFORMATION-ARCHITECTURE.md",
        "ssot_module": "public/site/assets/components.js",
        "ssot_package": null,
        "ssot_entry_point": "TOP_BAR_HUB_IDS + FOOTER_GROUPS + kyeTopBar() + kyeFooter() + kyeBreadcrumbs() + kyeDrawer()",
        "transport_wrappers": [],
        "competitor_forbidden_patterns": [
          "function kyeCalloutDelegatedAuditability(",
          "const kyeCalloutDelegatedAuditability =",
          "class kyeCalloutDelegatedAuditability "
        ]
      },
      {
        "concept_id": "ui.theme-bootstrap",
        "name": "UI theme bootstrap (dark/light + brand tokens)",
        "plane": "surface",
        "constitution_ref": "constitution/04-DESIGN-SYSTEM.md",
        "ssot_module": "public/site/assets/theme-bootstrap.js",
        "ssot_package": null,
        "ssot_entry_point": "theme-bootstrap.js (default export)",
        "transport_wrappers": [],
        "competitor_scan_exemption": {
          "reason": "theme-bootstrap.js is a browser bootstrap loaded by a script tag with no named export to key on; a competing copy is a second injected script, which the theme freshness gate detects.",
          "enforced_by": "theme-canonical-fresh"
        }
      },
      {
        "concept_id": "url.safe",
        "name": "URL sink guard (scheme allow-list for href/src)",
        "plane": "surface",
        "constitution_ref": "constitution/00-INDEX.md#0.49",
        "ssot_module": "private/lib/safe-url",
        "ssot_entry_point": "safeUrl(value)",
        "competitor_forbidden_patterns": [
          "function safeUrl(",
          "const safeUrl ="
        ],
        "competitor_scan_extensions": [
          ".html"
        ],
        "transport_wrappers": [
          {
            "module": "public/site/assets/video-library.js",
            "transport": "projection",
            "note": "Byte-projected by scripts/build-html-escape-projection.mjs; equality verified by implementation-canonical. Added 2026-08-14: four sinks assigned a DOM-attribute URL straight to href/src (CodeQL js/xss-through-dom), where a javascript: value executes on click."
          },
          {
            "module": "public/site/assets/demos.js",
            "transport": "projection",
            "note": "Byte-projected by scripts/build-html-escape-projection.mjs; equality verified by implementation-canonical. Added 2026-08-14: setAttribute('src', …) from a data- attribute (CodeQL js/xss-through-dom)."
          }
        ]
      },
      {
        "concept_id": "webhook.signature.verify",
        "name": "Inbound webhook signature verification (KYE-Timestamp + KYE-Signature + KYE-Delivery-ID HMAC scheme per private/specs/webhooks/signing.md)",
        "plane": "runtime",
        "constitution_ref": "constitution/06-WEBSITE.md",
        "ssot_module": "private/runtime/webhook-dispatcher",
        "ssot_package": null,
        "ssot_entry_point": "verify({ body, headers, resolveSecret, isDeliveryFresh }) — see src/verify.ts",
        "transport_wrappers": [],
        "notes": "Vendor schemes (Svix in public/site/functions/webhooks/clerk.js, Stripe-Signature in public/admin/functions/webhooks/stripe.js) are vendor-specific and out of scope — they implement the vendor's signing protocol, not the KYE one. Legacy in-process v1 verifier at private/runtime/gateway/src/webhook-verifier.ts was DELETED 2026-05-19 (zero non-test callers; consolidation complete).",
        "competitor_forbidden_patterns": [
          "function parseSignatureHeader(",
          "const parseSignatureHeader =",
          "class parseSignatureHeader "
        ]
      },
      {
        "concept_id": "content.page_facet_similarity",
        "name": "Page relatedness in the §50 content graph (facet vocabulary + similarity)",
        "plane": "governance",
        "constitution_ref": "constitution/50-CONTENT-GRAPH-DISCOVERABILITY.md",
        "ssot_module": "scripts/lib/page-facets.mjs",
        "ssot_package": null,
        "ssot_entry_point": "facetSet(discoverability) / facetSimilarity(a, b)",
        "transport_wrappers": [
          {
            "module": "scripts/build-derived-search.mjs",
            "transport": "library",
            "must_import": "./lib/page-facets.mjs",
            "note": "computeRelated() ranks by score then url. It owned the facet-set construction and the Jaccard body until this concept was registered; the RANKING stays here because it legitimately differs per surface."
          },
          {
            "module": "scripts/lib/archetypes.mjs",
            "transport": "library",
            "must_import": "./page-facets.mjs",
            "note": "renderRouter() ranks by similarity, then §50 buyer-journey stage, then title. It did NOT share the search index's relation — it required an audience match AND an exact kye-topic intersection, and §50 §2 declares kye-topic FREE-FORM, so no two pages share one verbatim. Measured: badges.html scored zero routes on all three of its audiences, the router returned null, and the page kept a disclosure where its kind requires a control. The two relations disagreed silently because an empty route list and an undefined relation are indistinguishable at the call site."
          }
        ],
        "competitor_forbidden_patterns": [
          "new Set\\(\\); *for \\(const a of .*\\) .*add\\(`a:",
          "\\.some\\(\\(t\\) => topics\\.has\\(t\\)\\)"
        ],
        "competitor_baseline_key": "implementation_canonical__competitors__content_page_facet_similarity",
        "migration": {
          "status": "complete",
          "tracked_in": "private/specs/ratchets/baselines.json#implementation_canonical__competitors__content_page_facet_similarity"
        }
      }
    ]
  },
  "gates": [
    {
      "filename": "_generate-purpose-vectors.mjs",
      "purpose": "Generates the locked Purpose Admissibility fixture set",
      "wired_in_npm_test": false
    },
    {
      "filename": "_generate-widget-descriptors.mjs",
      "purpose": "Generate the 14 KYE Partner Widget™ descriptors per",
      "wired_in_npm_test": false
    },
    {
      "filename": "_lib.mjs",
      "purpose": "Shared utilities for the rail-doc CI gates.",
      "wired_in_npm_test": false
    },
    {
      "filename": "account-opening-cdd-canonical.mjs",
      "purpose": "account-opening-cdd-canonical.mjs — §0.30 / §52 / §68 enforcer for the",
      "wired_in_npm_test": false
    },
    {
      "filename": "accounting-governance-canonical.mjs",
      "purpose": "accounting-governance-canonical.mjs — §54 §13 / §68 enforcer for the",
      "wired_in_npm_test": false
    },
    {
      "filename": "action-class-canonical.mjs",
      "purpose": "action-class-canonical.mjs — the ACTION-CLASS ROOT enforcer (§0 + §0.10 + §0.18).",
      "wired_in_npm_test": false
    },
    {
      "filename": "admin-roles-canonical.mjs",
      "purpose": "admin-roles-canonical.mjs — §0.18 enforcer for the admin role registry, and",
      "wired_in_npm_test": false
    },
    {
      "filename": "admission-control.mjs",
      "purpose": "Gate: admission-control  (constitution §0.51)",
      "wired_in_npm_test": false
    },
    {
      "filename": "adopter-directory-canonical.mjs",
      "purpose": "adopter-directory-canonical.mjs — §0.18 Canonical-Absolute enforcer for",
      "wired_in_npm_test": false
    },
    {
      "filename": "advisory-deadline-not-expired.mjs",
      "purpose": "advisory-deadline-not-expired — the §41 §8 meta-gate that prevents",
      "wired_in_npm_test": false
    },
    {
      "filename": "affiliation-disclaimer-canonical.mjs",
      "purpose": "affiliation-disclaimer-canonical.mjs — §0 honesty enforcer.",
      "wired_in_npm_test": false
    },
    {
      "filename": "agent-dev-kit-alive.mjs",
      "purpose": "agent-dev-kit-alive.mjs — §32 (KYE Agent Dev Kit™) enforcer.",
      "wired_in_npm_test": false
    },
    {
      "filename": "agent-envelope-vs-scope.mjs",
      "purpose": "agent-envelope-vs-scope.mjs — §52 Phase 2 post-flight reconciliation gate.",
      "wired_in_npm_test": false
    },
    {
      "filename": "agent-native-principal-canonical.mjs",
      "purpose": "agent-native-principal-canonical.mjs — §0.30 (Agents as First-Class",
      "wired_in_npm_test": false
    },
    {
      "filename": "agent-no-decision-emission.mjs",
      "purpose": "Gate: agent-no-decision-emission",
      "wired_in_npm_test": false
    },
    {
      "filename": "agent-readable-canonical.mjs",
      "purpose": "agent-readable-canonical.mjs — constitution §43 §4d Agent-Readability.",
      "wired_in_npm_test": false
    },
    {
      "filename": "agent-wiring-canonical.mjs",
      "purpose": "agent-wiring-canonical.mjs — enforce that every governed agent is DEEP-WIRED",
      "wired_in_npm_test": false
    },
    {
      "filename": "agentic-delivery-pack-canonical.mjs",
      "purpose": "agentic-delivery-pack-canonical.mjs — §0.18 enforcer for the KYE Certified",
      "wired_in_npm_test": false
    },
    {
      "filename": "agentic-governance-lifecycle-canonical.mjs",
      "purpose": "agentic-governance-lifecycle-canonical.mjs — §0.9/§0.18 Canonical-Absolute",
      "wired_in_npm_test": false
    },
    {
      "filename": "agentic-lending-product-canonical.mjs",
      "purpose": "agentic-lending-product-canonical.mjs — §49 §9 Sector Specialisation +",
      "wired_in_npm_test": false
    },
    {
      "filename": "ai-adoption-navigator-canonical.mjs",
      "purpose": "ai-adoption-navigator-canonical.mjs — KYE AI Adoption Navigator™ enforcer.",
      "wired_in_npm_test": false
    },
    {
      "filename": "ai-solutions-framework-authority-canonical.mjs",
      "purpose": "ai-solutions-framework-authority-canonical.mjs — §54 §13 / §68 / §70 enforcer for",
      "wired_in_npm_test": false
    },
    {
      "filename": "air-gap-ability.mjs",
      "purpose": "Gate: air-gap-ability — Constitution §0.47 Air-Gapped Governance Lifecycle.",
      "wired_in_npm_test": false
    },
    {
      "filename": "aml-financial-crimes-canonical.mjs",
      "purpose": "aml-financial-crimes-canonical.mjs — §54 §13 / §68 enforcer for the",
      "wired_in_npm_test": false
    },
    {
      "filename": "analytics-audit-emitted.mjs",
      "purpose": "Gate: analytics-audit-emitted",
      "wired_in_npm_test": false
    },
    {
      "filename": "analytics-determinism.mjs",
      "purpose": "Gate: analytics-determinism",
      "wired_in_npm_test": false
    },
    {
      "filename": "analytics-schema-validate.mjs",
      "purpose": "Gate: analytics-schema-validate",
      "wired_in_npm_test": false
    },
    {
      "filename": "analytics-tenant-isolation.mjs",
      "purpose": "Gate: analytics-tenant-isolation",
      "wired_in_npm_test": false
    },
    {
      "filename": "anti-stampede-canonical.mjs",
      "purpose": "Gate: anti-stampede-canonical (§13 §14 + §0.9)",
      "wired_in_npm_test": false
    },
    {
      "filename": "api-annotations-canonical.mjs",
      "purpose": "api-annotations-canonical.mjs — §0.18 Canonical-Absolute enforcer for the api-annotations registry.",
      "wired_in_npm_test": false
    },
    {
      "filename": "api-explorers-canonical.mjs",
      "purpose": "api-explorers-canonical.mjs — §0.18 Canonical-Absolute enforcer for the api-explorers registry.",
      "wired_in_npm_test": false
    },
    {
      "filename": "apply-cta-sku-canonical.mjs",
      "purpose": "Gate: apply-cta-sku-canonical",
      "wired_in_npm_test": false
    },
    {
      "filename": "assurance-plane-canonical.mjs",
      "purpose": "Gate: assurance-plane-canonical — Constitution §0.44 Unified Assurance Plane.",
      "wired_in_npm_test": false
    },
    {
      "filename": "attribution-canonical.mjs",
      "purpose": "attribution-canonical — every artefact resolves to exactly ONE actor, by ONE",
      "wired_in_npm_test": false
    },
    {
      "filename": "audience-landing-coverage.mjs",
      "purpose": "Gate: audience-landing-coverage",
      "wired_in_npm_test": false
    },
    {
      "filename": "audit-chain-emission-coverage.mjs",
      "purpose": "Gate: audit-chain-emission-coverage",
      "wired_in_npm_test": false
    },
    {
      "filename": "audit-emission-canonical.mjs",
      "purpose": "audit-emission-canonical — the audit emission path is canonical end to end.",
      "wired_in_npm_test": false
    },
    {
      "filename": "audit-pilot-consent-recorded.mjs",
      "purpose": "Gate: audit-pilot-consent-recorded",
      "wired_in_npm_test": false
    },
    {
      "filename": "audit-retention-policy.mjs",
      "purpose": "Gate: audit-retention-policy",
      "wired_in_npm_test": false
    },
    {
      "filename": "audit-worm-enforced.mjs",
      "purpose": "Gate: audit-worm-enforced",
      "wired_in_npm_test": false
    },
    {
      "filename": "authority-as-code-canonical.mjs",
      "purpose": "authority-as-code-canonical.mjs — §60 (KYE Authority-as-Code™ + Authority",
      "wired_in_npm_test": false
    },
    {
      "filename": "authority-bundle-standalone-canonical.mjs",
      "purpose": "Gate: authority-bundle-standalone-canonical",
      "wired_in_npm_test": false
    },
    {
      "filename": "authority-gap-detector-deterministic.mjs",
      "purpose": "Gate: authority-gap-detector-deterministic",
      "wired_in_npm_test": false
    },
    {
      "filename": "authority-gap-traceable.mjs",
      "purpose": "Gate: authority-gap-traceable",
      "wired_in_npm_test": false
    },
    {
      "filename": "authority-lines-canonical.mjs",
      "purpose": "Gate: authority-lines-canonical (§50 + §0 + §0.3 + §0.9 + §0.12)",
      "wired_in_npm_test": false
    },
    {
      "filename": "authority-risk-signal-canonical.mjs",
      "purpose": "authority-risk-signal-canonical.mjs — KYE Authority Risk Signal™ enforcer",
      "wired_in_npm_test": false
    },
    {
      "filename": "automation-registry-canonical.mjs",
      "purpose": "automation-registry-canonical.mjs",
      "wired_in_npm_test": false
    },
    {
      "filename": "availability-evidence-canonical.mjs",
      "purpose": "availability-evidence-canonical.mjs — engine unavailability is EVIDENCE,",
      "wired_in_npm_test": false
    },
    {
      "filename": "badges-fresh.mjs",
      "purpose": "Gate: badges-fresh — Constitution §0.20 + §0.31 + §17/§54.",
      "wired_in_npm_test": false
    },
    {
      "filename": "baked-count-drift.mjs",
      "purpose": "Gate: baked-count-drift",
      "wired_in_npm_test": false
    },
    {
      "filename": "billing-dunning-canonical.mjs",
      "purpose": "billing-dunning-canonical.mjs — §0.30 / §52 / §68 enforcer for the",
      "wired_in_npm_test": false
    },
    {
      "filename": "billing-schema-validate.mjs",
      "purpose": "Gate: billing-schema-validate",
      "wired_in_npm_test": false
    },
    {
      "filename": "bio-chem-governance-canonical.mjs",
      "purpose": "bio-chem-governance-canonical.mjs — §54 §13 / §68 enforcer for the",
      "wired_in_npm_test": false
    },
    {
      "filename": "biopharma-pv-canonical.mjs",
      "purpose": "biopharma-pv-canonical.mjs — §0.30 / §52 / §68 enforcer for the",
      "wired_in_npm_test": false
    },
    {
      "filename": "boundary-governance-canonical.mjs",
      "purpose": "Gate: boundary-governance-canonical — Constitution §0.39 (Boundary-Agnostic Governance).",
      "wired_in_npm_test": false
    },
    {
      "filename": "bps-calculation-determinism.mjs",
      "purpose": "Gate: bps-calculation-determinism",
      "wired_in_npm_test": false
    },
    {
      "filename": "builder-pep-canonical.mjs",
      "purpose": "Gate: builder-pep-canonical  (constitution §0 Continuous Runtime Self-Governance",
      "wired_in_npm_test": false
    },
    {
      "filename": "bundle-round-trip.mjs",
      "purpose": "Gate: bundle-round-trip",
      "wired_in_npm_test": false
    },
    {
      "filename": "business-flows-canonical.mjs",
      "purpose": "business-flows-canonical.mjs — §0.18 Canonical-Absolute enforcer for the business-flows registry.",
      "wired_in_npm_test": false
    },
    {
      "filename": "buyer-terminology-canonical.mjs",
      "purpose": "Gate: buyer-terminology-canonical (§0.9 + §11 CONTENT)",
      "wired_in_npm_test": false
    },
    {
      "filename": "canada-health-product-canonical.mjs",
      "purpose": "canada-health-product-canonical.mjs — §49 §9 Sector Specialisation",
      "wired_in_npm_test": false
    },
    {
      "filename": "canonical-counts-fresh.mjs",
      "purpose": "Gate: canonical-counts-fresh — Constitution §0 + §0.14.3.",
      "wired_in_npm_test": false
    },
    {
      "filename": "canonical-first.mjs",
      "purpose": "Gate: canonical-first",
      "wired_in_npm_test": false
    },
    {
      "filename": "canonical-gap-audit.mjs",
      "purpose": "Gate: canonical-gap-audit (advisory)",
      "wired_in_npm_test": false
    },
    {
      "filename": "canonical-triple-coverage.mjs",
      "purpose": "Gate: canonical-triple-coverage (§47)",
      "wired_in_npm_test": false
    },
    {
      "filename": "capability-kit-canonical.mjs",
      "purpose": "capability-kit-canonical.mjs — §0.18 enforcer for the KYE Capability Kit™",
      "wired_in_npm_test": false
    },
    {
      "filename": "cascade-coverage.mjs",
      "purpose": "cascade-coverage.mjs — §53 (Cohesion Cascade v1.1) universal enforcer.",
      "wired_in_npm_test": false
    },
    {
      "filename": "cascade-graph-baseline-decay.mjs",
      "purpose": "cascade-graph-baseline-decay.mjs — §53 §12 (Pre-§53 baseline audit",
      "wired_in_npm_test": false
    },
    {
      "filename": "category-ownership-canonical.mjs",
      "purpose": "Gate: category-ownership-canonical  (constitution §0.33)",
      "wired_in_npm_test": false
    },
    {
      "filename": "certificate-rail-canonical.mjs",
      "purpose": "certificate-rail-canonical.mjs — constitution §66 Certificates Rail.",
      "wired_in_npm_test": false
    },
    {
      "filename": "cf-resource-governance-coverage.mjs",
      "purpose": "Gate: cf-resource-governance-coverage — §0.36 Universal Entity Governance +",
      "wired_in_npm_test": false
    },
    {
      "filename": "chain-of-authority-insight-canonical.mjs",
      "purpose": "chain-of-authority-insight-canonical.mjs — §54 §13 / §68 / §70 enforcer for the",
      "wired_in_npm_test": false
    },
    {
      "filename": "channels-canonical.mjs",
      "purpose": "channels-canonical.mjs — §0.18 Canonical-Absolute enforcer for the channels registry.",
      "wired_in_npm_test": false
    },
    {
      "filename": "chargeback-evidence-canonical.mjs",
      "purpose": "chargeback-evidence-canonical.mjs — §54 §13 / §68 / §70 enforcer for",
      "wired_in_npm_test": false
    },
    {
      "filename": "chatbot-authority-canonical.mjs",
      "purpose": "chatbot-authority-canonical.mjs — §54 §13 / §68 / §70 enforcer for the",
      "wired_in_npm_test": false
    },
    {
      "filename": "check-canonical-references.mjs",
      "purpose": "scripts/gates/check-canonical-references.mjs",
      "wired_in_npm_test": false
    },
    {
      "filename": "ci-npm-resilience-canonical.mjs",
      "purpose": "ci-npm-resilience-canonical.mjs — every CI npm install/ci is retry-wrapped.",
      "wired_in_npm_test": false
    },
    {
      "filename": "claims-decision-canonical.mjs",
      "purpose": "claims-decision-canonical.mjs — §0.30 / §52 / §68 enforcer for the",
      "wired_in_npm_test": false
    },
    {
      "filename": "cli-manifest-canonical.mjs",
      "purpose": "cli-manifest-canonical.mjs — §15 CLI Manifest enforcer.",
      "wired_in_npm_test": false
    },
    {
      "filename": "clinical-ai-product-canonical.mjs",
      "purpose": "clinical-ai-product-canonical.mjs — §54 §13 / §68 enforcer for the",
      "wired_in_npm_test": false
    },
    {
      "filename": "clinical-authorization-canonical.mjs",
      "purpose": "clinical-authorization-canonical.mjs — §0.30 / §52 / §68 enforcer for the",
      "wired_in_npm_test": false
    },
    {
      "filename": "clinical-trial-canonical.mjs",
      "purpose": "clinical-trial-canonical.mjs — §0.30 / §52 / §68 enforcer for the",
      "wired_in_npm_test": false
    },
    {
      "filename": "clip-pipeline-canonical.mjs",
      "purpose": "clip-pipeline-canonical — the §0.18 quintuple gate for the kye-clip",
      "wired_in_npm_test": false
    },
    {
      "filename": "clip-registry-canonical.mjs",
      "purpose": "clip-registry-canonical.mjs — a public clip may not say more than its source does.",
      "wired_in_npm_test": false
    },
    {
      "filename": "coherent-integration-mandate.mjs",
      "purpose": "coherent-integration-mandate — Constitution §0.6 enforcement.",
      "wired_in_npm_test": false
    },
    {
      "filename": "color-canonical.mjs",
      "purpose": "Gate: color-canonical (§0.9 Universal Canonicalisation + §43 Machine-Readable)",
      "wired_in_npm_test": false
    },
    {
      "filename": "comms-manifest-alive.mjs",
      "purpose": "comms-manifest-alive — Constitution §38 enforcement.",
      "wired_in_npm_test": false
    },
    {
      "filename": "compliance-attestation.mjs",
      "purpose": "Gate: compliance-attestation",
      "wired_in_npm_test": false
    },
    {
      "filename": "component-contrast-dark.mjs",
      "purpose": "Gate: component-contrast-dark (surface-aware)",
      "wired_in_npm_test": false
    },
    {
      "filename": "component-graph-taxonomy.mjs",
      "purpose": "Gate: component-graph-taxonomy (§74)",
      "wired_in_npm_test": false
    },
    {
      "filename": "component-manifest-canonical.mjs",
      "purpose": "component-manifest-canonical.mjs — §0.18 Canonical-Absolute enforcer for",
      "wired_in_npm_test": false
    },
    {
      "filename": "conformance-levels-canonical.mjs",
      "purpose": "conformance-levels-canonical.mjs — §15 §7.9 Conformance Maturity Ladder (L1–L5) enforcer.",
      "wired_in_npm_test": false
    },
    {
      "filename": "conformance-pack-signed.mjs",
      "purpose": "Gate: conformance-pack-signed",
      "wired_in_npm_test": false
    },
    {
      "filename": "connection-diagrams-canonical.mjs",
      "purpose": "connection-diagrams-canonical.mjs — §0.18 Canonical-Absolute enforcer for the connection-diagrams registry.",
      "wired_in_npm_test": false
    },
    {
      "filename": "consequential-actor-canonical.mjs",
      "purpose": "consequential-actor-canonical.mjs — KYE Consequential Actor Framework™ enforcer.",
      "wired_in_npm_test": false
    },
    {
      "filename": "content-canonical-fresh.mjs",
      "purpose": "content-canonical-fresh.mjs — §0.12 Content Canonicalisation enforcer.",
      "wired_in_npm_test": false
    },
    {
      "filename": "content-graph-coverage.mjs",
      "purpose": "content-graph-coverage.mjs — §50 (Canonical Content Graph + Derived",
      "wired_in_npm_test": false
    },
    {
      "filename": "control-geometry-canonical.mjs",
      "purpose": "control-geometry-canonical — a colour variant owns COLOUR, never geometry.",
      "wired_in_npm_test": false
    },
    {
      "filename": "control-plane-canonical.mjs",
      "purpose": "control-plane-canonical.mjs — constitution §69 KYE Control-Plane MCP™.",
      "wired_in_npm_test": false
    },
    {
      "filename": "control-plane-interop-canonical.mjs",
      "purpose": "control-plane-interop-canonical.mjs — constitution §73 KYE Control-Plane Interoperability Profile™.",
      "wired_in_npm_test": false
    },
    {
      "filename": "control-policy-authority-canonical.mjs",
      "purpose": "control-policy-authority-canonical.mjs — §0.30 / §52 / §68 enforcer for the",
      "wired_in_npm_test": false
    },
    {
      "filename": "converted-page-source-integrity.mjs",
      "purpose": "Gate: converted-page-source-integrity  (§0.43 no-blind-enforcers · §0.18 · §0.46)",
      "wired_in_npm_test": false
    },
    {
      "filename": "coordinate-connectivity.mjs",
      "purpose": "Gate: coordinate-connectivity  (constitution §0.52)",
      "wired_in_npm_test": false
    },
    {
      "filename": "corroboration-canonical.mjs",
      "purpose": "corroboration-canonical.mjs — §0.18 + §39 enforcer for the external",
      "wired_in_npm_test": false
    },
    {
      "filename": "cost-to-serve-canonical.mjs",
      "purpose": "cost-to-serve-canonical.mjs — §0.18 enforcer for the KYE Cost-to-Serve /",
      "wired_in_npm_test": false
    },
    {
      "filename": "coverage-enforcement-proof.mjs",
      "purpose": "Gate: coverage-enforcement-proof",
      "wired_in_npm_test": false
    },
    {
      "filename": "coverage-maturity-canonical.mjs",
      "purpose": "Gate: coverage-maturity-canonical",
      "wired_in_npm_test": false
    },
    {
      "filename": "credit-card-authorization-canonical.mjs",
      "purpose": "credit-card-authorization-canonical.mjs — §0.30 / §52 / §68 enforcer for the",
      "wired_in_npm_test": false
    },
    {
      "filename": "cross-jurisdiction-handoff-canonical.mjs",
      "purpose": "cross-jurisdiction-handoff-canonical.mjs — §57 enforcer.",
      "wired_in_npm_test": false
    },
    {
      "filename": "crypto-authority-canonical.mjs",
      "purpose": "crypto-authority-canonical.mjs — KYE Cryptographic Authority Pack™ enforcer.",
      "wired_in_npm_test": false
    },
    {
      "filename": "customer-journey-canonical.mjs",
      "purpose": "customer-journey-canonical.mjs — §0.18 Canonical-Absolute enforcer for the",
      "wired_in_npm_test": false
    },
    {
      "filename": "cut-contract.mjs",
      "purpose": "cut-contract.mjs — the FINISHED CUT is verified, not just its inputs.",
      "wired_in_npm_test": false
    },
    {
      "filename": "cyber-resilience-authority-canonical.mjs",
      "purpose": "cyber-resilience-authority-canonical.mjs — §54 §13 / §68 / §70 enforcer for the",
      "wired_in_npm_test": false
    },
    {
      "filename": "cypress-canonical.mjs",
      "purpose": "cypress-canonical.mjs — §0 lock: ONE edition per locked design asset.",
      "wired_in_npm_test": false
    },
    {
      "filename": "d1-schema-apply.mjs",
      "purpose": "d1-schema-apply.mjs — validate the REAL Cloudflare D1 (SQLite) schema and",
      "wired_in_npm_test": false
    },
    {
      "filename": "dashboard-tenant-isolation.mjs",
      "purpose": "Gate: dashboard-tenant-isolation",
      "wired_in_npm_test": false
    },
    {
      "filename": "dashboards-canonical.mjs",
      "purpose": "dashboards-canonical.mjs — §0.18 Canonical-Absolute enforcer for the dashboards registry.",
      "wired_in_npm_test": false
    },
    {
      "filename": "data-residency-canonical.mjs",
      "purpose": "Gate: data-residency-canonical",
      "wired_in_npm_test": false
    },
    {
      "filename": "database-tenancy-canonical.mjs",
      "purpose": "database-tenancy-canonical — every CREATE TABLE in the D1 migration tree",
      "wired_in_npm_test": false
    },
    {
      "filename": "decision-pack-bijection.mjs",
      "purpose": "decision-pack-bijection — every decision writer produces a SEALABLE row.",
      "wired_in_npm_test": false
    },
    {
      "filename": "decision-rights-canonical.mjs",
      "purpose": "decision-rights-canonical.mjs — make the decision-STAGE axis of authority",
      "wired_in_npm_test": false
    },
    {
      "filename": "decisions-evidence-pack-canonical.mjs",
      "purpose": "decisions-evidence-pack-canonical — EVERY DECISION CARRIES ITS EVIDENCE PACK,",
      "wired_in_npm_test": false
    },
    {
      "filename": "deeplink-canonical.mjs",
      "purpose": "scripts/gates/deeplink-canonical.mjs",
      "wired_in_npm_test": false
    },
    {
      "filename": "deeplink-internal-anchors.mjs",
      "purpose": "scripts/gates/deeplink-internal-anchors.mjs",
      "wired_in_npm_test": false
    },
    {
      "filename": "delegated-agent-binding-coverage.mjs",
      "purpose": "delegated-agent-binding-coverage.mjs — §52 (Constitutional Binding of",
      "wired_in_npm_test": false
    },
    {
      "filename": "delegated-auditability-schema-validate.mjs",
      "purpose": "Gate: delegated-auditability-schema-validate",
      "wired_in_npm_test": false
    },
    {
      "filename": "demonstrated-effect.mjs",
      "purpose": "demonstrated-effect.mjs — §0.50 enforcer: a mechanism is real only when its",
      "wired_in_npm_test": false
    },
    {
      "filename": "deploy-toolchain-pinned.mjs",
      "purpose": "deploy-toolchain-pinned.mjs — the toolchain that ships production cannot",
      "wired_in_npm_test": false
    },
    {
      "filename": "deployed-estate-canonical.mjs",
      "purpose": "Gate: deployed-estate-canonical (§34 + §0.42 + §0.47)",
      "wired_in_npm_test": false
    },
    {
      "filename": "deployed-import-graph.mjs",
      "purpose": "deployed-import-graph.mjs — every module a deployed Worker imports must",
      "wired_in_npm_test": false
    },
    {
      "filename": "derived-search-index-shape.mjs",
      "purpose": "Gate: derived-search-index-shape",
      "wired_in_npm_test": false
    },
    {
      "filename": "design-partner-program-canonical.mjs",
      "purpose": "design-partner-program-canonical.mjs — §0.18 enforcer for the KYE Design",
      "wired_in_npm_test": false
    },
    {
      "filename": "design-tokens-coherent.mjs",
      "purpose": "Gate: design-tokens-coherent",
      "wired_in_npm_test": false
    },
    {
      "filename": "dev-plane-event-governance.mjs",
      "purpose": "dev-plane-event-governance — Mode 2 gate: every EPHEMERAL dev-plane EVENT emits",
      "wired_in_npm_test": false
    },
    {
      "filename": "directory-audit-emitted.mjs",
      "purpose": "Gate: directory-audit-emitted",
      "wired_in_npm_test": false
    },
    {
      "filename": "directory-determinism.mjs",
      "purpose": "Gate: directory-determinism",
      "wired_in_npm_test": false
    },
    {
      "filename": "directory-schema-validate.mjs",
      "purpose": "async function main() {",
      "wired_in_npm_test": false
    },
    {
      "filename": "directory-tenant-isolation.mjs",
      "purpose": "Gate: directory-tenant-isolation",
      "wired_in_npm_test": false
    },
    {
      "filename": "disputes-canonical.mjs",
      "purpose": "disputes-canonical.mjs — §0.18 Canonical-Absolute enforcer for the disputes registry.",
      "wired_in_npm_test": false
    },
    {
      "filename": "doc-claims-resolve.mjs",
      "purpose": "doc-claims-resolve.mjs — a documented number MUST resolve to its canonical source.",
      "wired_in_npm_test": false
    },
    {
      "filename": "document-governance-canonical.mjs",
      "purpose": "document-governance-canonical.mjs — §31 / §30 / §70 enforcer for the",
      "wired_in_npm_test": false
    },
    {
      "filename": "document-intelligence-rail-canonical.mjs",
      "purpose": "document-intelligence-rail-canonical.mjs — §71 (KYE Document Intelligence Rail™) enforcer.",
      "wired_in_npm_test": false
    },
    {
      "filename": "drift-to-authority-canonical.mjs",
      "purpose": "drift-to-authority-canonical — the §52 drift→authority connector enforcer.",
      "wired_in_npm_test": false
    },
    {
      "filename": "drug-discovery-canonical.mjs",
      "purpose": "drug-discovery-canonical.mjs — §0.30 / §52 / §68 enforcer for the",
      "wired_in_npm_test": false
    },
    {
      "filename": "dual-channel-admin.mjs",
      "purpose": "Gate: dual-channel-admin",
      "wired_in_npm_test": false
    },
    {
      "filename": "edge-binding-coverage.mjs",
      "purpose": "Gate: edge-binding-coverage — every edge binding is declared AND used.",
      "wired_in_npm_test": false
    },
    {
      "filename": "edge-cold-start-budget.mjs",
      "purpose": "Gate: edge-cold-start-budget",
      "wired_in_npm_test": false
    },
    {
      "filename": "edge-latency-budget.mjs",
      "purpose": "Gate: edge-latency-budget",
      "wired_in_npm_test": false
    },
    {
      "filename": "edge-wrangler-validate.mjs",
      "purpose": "Gate: edge-wrangler-validate",
      "wired_in_npm_test": false
    },
    {
      "filename": "email-addresses-canonical.mjs",
      "purpose": "email-addresses-canonical.mjs — §0.18 Canonical-Absolute enforcer for the email-addresses registry.",
      "wired_in_npm_test": false
    },
    {
      "filename": "email-delivery-canonical.mjs",
      "purpose": "email-delivery-canonical.mjs — Constitution §38 enforcement for the",
      "wired_in_npm_test": false
    },
    {
      "filename": "email-legal-compliance.mjs",
      "purpose": "email-legal-compliance.mjs — every outbound email carries its legal bits.",
      "wired_in_npm_test": false
    },
    {
      "filename": "email-signatures-canonical.mjs",
      "purpose": "email-signatures-canonical.mjs — §0.18 Canonical-Absolute enforcer for the email-signatures registry.",
      "wired_in_npm_test": false
    },
    {
      "filename": "engagement-coverage.mjs",
      "purpose": "engagement-coverage — does the page DO anything for the reader who arrived?",
      "wired_in_npm_test": false
    },
    {
      "filename": "engagement-rail-canonical.mjs",
      "purpose": "engagement-rail-canonical.mjs — §49 (Universal Engagement Rail) enforcer.",
      "wired_in_npm_test": false
    },
    {
      "filename": "engine-determinism-test.mjs",
      "purpose": "Gate: engine-determinism-test",
      "wired_in_npm_test": false
    },
    {
      "filename": "engine-replay-equiv.mjs",
      "purpose": "Gate: engine-replay-equiv",
      "wired_in_npm_test": false
    },
    {
      "filename": "engine-workflow-endpoint-canonical.mjs",
      "purpose": "Gate: engine-workflow-endpoint-canonical",
      "wired_in_npm_test": false
    },
    {
      "filename": "entitlement-trace.mjs",
      "purpose": "Gate: entitlement-trace",
      "wired_in_npm_test": false
    },
    {
      "filename": "entity-id-canonical.mjs",
      "purpose": "Gate: entity-id-canonical  (constitution §0.30 / §0.34 — the KYE-ID backbone)",
      "wired_in_npm_test": false
    },
    {
      "filename": "entity-lifecycle-closed.mjs",
      "purpose": "entity-lifecycle-closed — an entity is governed only if its whole chain closes.",
      "wired_in_npm_test": false
    },
    {
      "filename": "entity-register-canonical.mjs",
      "purpose": "Gate: entity-register-canonical",
      "wired_in_npm_test": false
    },
    {
      "filename": "entity-type-registry-canonical.mjs",
      "purpose": "Gate: entity-type-registry-canonical (§0.36/§0.37 — every entity TYPE is a",
      "wired_in_npm_test": false
    },
    {
      "filename": "error-envelope-canonical.mjs",
      "purpose": "Gate: error-envelope-canonical",
      "wired_in_npm_test": false
    },
    {
      "filename": "estate-product-canonical.mjs",
      "purpose": "estate-product-canonical.mjs — Wave-AE Phase 0 (KYE Estate Planning",
      "wired_in_npm_test": false
    },
    {
      "filename": "event-native-coverage.mjs",
      "purpose": "event-native-coverage.mjs — §0.15 Event-Native Architecture (Events-First) enforcer.",
      "wired_in_npm_test": false
    },
    {
      "filename": "event-registry-canonical.mjs",
      "purpose": "event-registry-canonical — SSOT enforcement for the event family.",
      "wired_in_npm_test": false
    },
    {
      "filename": "evidence-pack-standalone-canonical.mjs",
      "purpose": "Gate: evidence-pack-standalone-canonical",
      "wired_in_npm_test": false
    },
    {
      "filename": "evidence-persistence-canonical.mjs",
      "purpose": "evidence-persistence-canonical — emitted evidence MUST be retained.",
      "wired_in_npm_test": false
    },
    {
      "filename": "evidence-portability-canonical.mjs",
      "purpose": "Gate: evidence-portability-canonical",
      "wired_in_npm_test": false
    },
    {
      "filename": "executable-coverage.mjs",
      "purpose": "executable-coverage — the UNIVERSAL executable-governance invariant (CEO",
      "wired_in_npm_test": false
    },
    {
      "filename": "execution-layers-canonical.mjs",
      "purpose": "execution-layers-canonical.mjs — §55 (Execution Layers Architecture) enforcer.",
      "wired_in_npm_test": false
    },
    {
      "filename": "f37-f38-f39-boundary.mjs",
      "purpose": "scripts/gates/f37-f38-f39-boundary.mjs",
      "wired_in_npm_test": false
    },
    {
      "filename": "feature-flag-canonical.mjs",
      "purpose": "feature-flag-canonical — §0.9 (Universal Canonicalisation) enforcer",
      "wired_in_npm_test": false
    },
    {
      "filename": "filesystem-tree-canonical.mjs",
      "purpose": "filesystem-tree-canonical.mjs — §0.18 Canonical-Absolute enforcer for the filesystem-tree registry.",
      "wired_in_npm_test": false
    },
    {
      "filename": "financial-ai-product-canonical.mjs",
      "purpose": "financial-ai-product-canonical.mjs — §49 §9 Sector Specialisation enforcer",
      "wired_in_npm_test": false
    },
    {
      "filename": "first-doctrine-canonical.mjs",
      "purpose": "Gate: first-doctrine-canonical — Constitution §0.45 The \"-First\" Doctrine.",
      "wired_in_npm_test": false
    },
    {
      "filename": "fixture-entity-canonical.mjs",
      "purpose": "Gate: fixture-entity-canonical",
      "wired_in_npm_test": false
    },
    {
      "filename": "flow-contracts.mjs",
      "purpose": "flow-contracts — Constitution §46 enforcement (the Flow Contracts gate).",
      "wired_in_npm_test": false
    },
    {
      "filename": "form-integrity.mjs",
      "purpose": "scripts/gates/form-integrity.mjs — build-time form-control reachability gate",
      "wired_in_npm_test": false
    },
    {
      "filename": "forms-canonical.mjs",
      "purpose": "forms-canonical.mjs — §0.18 Canonical-Absolute enforcer for the forms registry.",
      "wired_in_npm_test": false
    },
    {
      "filename": "foundry-rail-canonical.mjs",
      "purpose": "foundry-rail-canonical.mjs — §54 (KYE Sector Pack Foundry™) enforcer.",
      "wired_in_npm_test": false
    },
    {
      "filename": "framework-coverage-bijection.mjs",
      "purpose": "Gate: framework-coverage-bijection",
      "wired_in_npm_test": false
    },
    {
      "filename": "framework-ingestion-canonical.mjs",
      "purpose": "framework-ingestion-canonical.mjs — §59 enforcer.",
      "wired_in_npm_test": false
    },
    {
      "filename": "framework-mapping-canonical.mjs",
      "purpose": "framework-mapping-canonical.mjs — §70 KYE Framework Mapping Rail™ enforcer.",
      "wired_in_npm_test": false
    },
    {
      "filename": "framework-marketing-coherence.mjs",
      "purpose": "Gate: framework-marketing-coherence",
      "wired_in_npm_test": false
    },
    {
      "filename": "fraud-decision-canonical.mjs",
      "purpose": "fraud-decision-canonical.mjs — §0.30 / §52 / §68 enforcer for the",
      "wired_in_npm_test": false
    },
    {
      "filename": "functional-inventory-coverage.mjs",
      "purpose": "Gate: functional-inventory-coverage (constitution §0.29 Production-Completeness ·",
      "wired_in_npm_test": false
    },
    {
      "filename": "gap-finder-canonical.mjs",
      "purpose": "gap-finder-canonical.mjs — §0.18 Canonical-Absolute drift gate for the",
      "wired_in_npm_test": false
    },
    {
      "filename": "gate-manifest-fresh.mjs",
      "purpose": "gate-manifest-fresh (§0.9 / §0.18 canonical-registry · audit fix #1, 2026-06-11)",
      "wired_in_npm_test": false
    },
    {
      "filename": "gateway-roles-canonical.mjs",
      "purpose": "Gate: gateway-roles-canonical",
      "wired_in_npm_test": false
    },
    {
      "filename": "generated-not-source.mjs",
      "purpose": "generated-not-source.mjs — an edit must survive a full build.",
      "wired_in_npm_test": false
    },
    {
      "filename": "generative-eval-coverage.mjs",
      "purpose": "Gate: generative-eval-coverage (§13 Resilience Loop™ + §62 + §0.8)",
      "wired_in_npm_test": false
    },
    {
      "filename": "generator-determinism.mjs",
      "purpose": "generator-determinism.mjs — §0.20 Automatic Dynamic Resolution precondition.",
      "wired_in_npm_test": false
    },
    {
      "filename": "genetic-sequencing-canonical.mjs",
      "purpose": "genetic-sequencing-canonical.mjs — §0.30 / §52 / §68 enforcer for the",
      "wired_in_npm_test": false
    },
    {
      "filename": "gh-org-canonical.mjs",
      "purpose": "gh-org-canonical.mjs — §0.18 Canonical-Absolute enforcer for the gh-org registry.",
      "wired_in_npm_test": false
    },
    {
      "filename": "github-shape-canonical.mjs",
      "purpose": "github-shape-canonical.mjs — §5 (GitHub Constitution) enforcer.",
      "wired_in_npm_test": false
    },
    {
      "filename": "governed-agents-fresh.mjs",
      "purpose": "Gate: governed-agents-fresh — Constitution §0.20 + §0.31 + §0.12.",
      "wired_in_npm_test": false
    },
    {
      "filename": "governed-demo-canonical.mjs",
      "purpose": "governed-demo-canonical.mjs — §0.18 Canonical-Absolute enforcer for the KYE",
      "wired_in_npm_test": false
    },
    {
      "filename": "governed-invariants-canonical.mjs",
      "purpose": "governed-invariants-canonical.mjs — make the KYE authority-protocol soundness",
      "wired_in_npm_test": false
    },
    {
      "filename": "governed-inventory-coverage.mjs",
      "purpose": "Gate: governed-inventory-coverage (constitution §0.34 Self-Run Governance · §0.3 · §13).",
      "wired_in_npm_test": false
    },
    {
      "filename": "governed-inventory-daemon-canonical.mjs",
      "purpose": "governed-inventory-daemon-canonical (§0.34 Self-Run Governance · §0.3 · §0.43).",
      "wired_in_npm_test": false
    },
    {
      "filename": "governed-knowledge-assistant-canonical.mjs",
      "purpose": "governed-knowledge-assistant-canonical.mjs — KYE Governed Knowledge Assistant™ enforcer.",
      "wired_in_npm_test": false
    },
    {
      "filename": "governed-prompts-canonical.mjs",
      "purpose": "governed-prompts-canonical.mjs — §58 enforcer.",
      "wired_in_npm_test": false
    },
    {
      "filename": "grants-agent-canonical.mjs",
      "purpose": "grants-agent-canonical.mjs — §0.30 / §52 / §68 / §70 enforcer for the",
      "wired_in_npm_test": false
    },
    {
      "filename": "guard-recommendation-ranking-stable.mjs",
      "purpose": "Gate: guard-recommendation-ranking-stable",
      "wired_in_npm_test": false
    },
    {
      "filename": "hardcode-canonical.mjs",
      "purpose": "Gate: hardcode-canonical (§0.9 — the zero-hardcode ratchet)",
      "wired_in_npm_test": false
    },
    {
      "filename": "hardware-electronics-product-canonical.mjs",
      "purpose": "hardware-electronics-product-canonical.mjs — §49 §9 Sector Specialisation",
      "wired_in_npm_test": false
    },
    {
      "filename": "harness-adapter-canonical.mjs",
      "purpose": "harness-adapter-canonical.mjs — §52 Phase 4 (KYE Harness Adapter™) enforcer.",
      "wired_in_npm_test": false
    },
    {
      "filename": "host-platform-adapter-canonical.mjs",
      "purpose": "host-platform-adapter-canonical.mjs — KYE Host-Platform Authority Adapter enforcer.",
      "wired_in_npm_test": false
    },
    {
      "filename": "housekeeping.mjs",
      "purpose": "Gate: housekeeping (stale / fictional reference detector)",
      "wired_in_npm_test": false
    },
    {
      "filename": "hr-recruitment-product-canonical.mjs",
      "purpose": "hr-recruitment-product-canonical.mjs — §49 §9 Sector Specialisation +",
      "wired_in_npm_test": false
    },
    {
      "filename": "hse-safety-pack-canonical.mjs",
      "purpose": "hse-safety-pack-canonical.mjs — KYE HSE Authority Pack™ enforcer (§68 product).",
      "wired_in_npm_test": false
    },
    {
      "filename": "html-sink-safety.mjs",
      "purpose": "Gate: html-sink-safety (§0.4 banking-grade surfaces + §0.49 no hand-rolling)",
      "wired_in_npm_test": false
    },
    {
      "filename": "human-voice-copy.mjs",
      "purpose": "human-voice-copy.mjs — §11 Content · human-voice authenticity gate.",
      "wired_in_npm_test": false
    },
    {
      "filename": "ich-authority-canonical.mjs",
      "purpose": "ich-authority-canonical.mjs — §54 §13 / §68 enforcer for the",
      "wired_in_npm_test": false
    },
    {
      "filename": "icons-canonical.mjs",
      "purpose": "icons-canonical.mjs — §0.18 Canonical-Absolute enforcer for the icons registry.",
      "wired_in_npm_test": false
    },
    {
      "filename": "id-contract-canonical.mjs",
      "purpose": "id-contract-canonical.mjs — an id field must be a contract, and a reference",
      "wired_in_npm_test": false
    },
    {
      "filename": "id-grammar-binding.mjs",
      "purpose": "Gate: id-grammar-binding  (§0.9 zero-hardcode · §43 machine-readable)",
      "wired_in_npm_test": false
    },
    {
      "filename": "implementation-canonical.mjs",
      "purpose": "implementation-canonical — Constitution §40 enforcement.",
      "wired_in_npm_test": false
    },
    {
      "filename": "inbound-outbound-governance.mjs",
      "purpose": "Gate: inbound-outbound-governance — Constitution §0.3 + §0.36 + §0.37 + §0.38 (Governed Boundary).",
      "wired_in_npm_test": false
    },
    {
      "filename": "ingest-canonical.mjs",
      "purpose": "ingest-canonical.mjs — two doors, ONE verifier (§0 · §62 · §70).",
      "wired_in_npm_test": false
    },
    {
      "filename": "insurance-authority-canonical.mjs",
      "purpose": "insurance-authority-canonical.mjs — §54 §13 / §68 / §70 enforcer for the",
      "wired_in_npm_test": false
    },
    {
      "filename": "insurance-authorization-canonical.mjs",
      "purpose": "insurance-authorization-canonical.mjs — §0.30 / §52 / §68 enforcer for the",
      "wired_in_npm_test": false
    },
    {
      "filename": "intake-form-smoke.mjs",
      "purpose": "Gate: intake-form-smoke — every persona-intake form (§49/§62) MUST accept a",
      "wired_in_npm_test": false
    },
    {
      "filename": "integration-canonical.mjs",
      "purpose": "Gate: integration-canonical",
      "wired_in_npm_test": false
    },
    {
      "filename": "inter-project-isolation.mjs",
      "purpose": "inter-project-isolation.mjs — §0.28 Inter-Project Isolation enforcer.",
      "wired_in_npm_test": false
    },
    {
      "filename": "interactivity-required.mjs",
      "purpose": "Gate: interactivity-required",
      "wired_in_npm_test": false
    },
    {
      "filename": "investment-decision-authority-canonical.mjs",
      "purpose": "investment-decision-authority-canonical.mjs — §54 §13 / §68 enforcer for the",
      "wired_in_npm_test": false
    },
    {
      "filename": "invoices-canonical.mjs",
      "purpose": "invoices-canonical.mjs — §0.18 Canonical-Absolute enforcer for the invoices registry.",
      "wired_in_npm_test": false
    },
    {
      "filename": "ip-oss-line.mjs",
      "purpose": "Gate: ip-oss-line",
      "wired_in_npm_test": false
    },
    {
      "filename": "islamic-finance-agents-canonical.mjs",
      "purpose": "islamic-finance-agents-canonical.mjs — §0.30 / §52 / §68 / §70 enforcer for",
      "wired_in_npm_test": false
    },
    {
      "filename": "journey-landing-coverage.mjs",
      "purpose": "Gate: journey-landing-coverage",
      "wired_in_npm_test": false
    },
    {
      "filename": "jurisdiction-authority-canonical.mjs",
      "purpose": "jurisdiction-authority-canonical.mjs — §72 (KYE Jurisdiction & Data-Sovereignty Authority™) enforcer.",
      "wired_in_npm_test": false
    },
    {
      "filename": "kit-orchestration-canonical.mjs",
      "purpose": "kit-orchestration-canonical.mjs — §42 v1.4 (Kit Orchestration) enforcer.",
      "wired_in_npm_test": false
    },
    {
      "filename": "kye-answers-uniqueness.mjs",
      "purpose": "Gate: kye-answers-uniqueness",
      "wired_in_npm_test": false
    },
    {
      "filename": "kye-canonical-everything-sweep.mjs",
      "purpose": "kye-canonical-everything-sweep.mjs — §0.18 Canonical-Absolute meta-gate.",
      "wired_in_npm_test": false
    },
    {
      "filename": "landing-hubs-canonical.mjs",
      "purpose": "landing-hubs-canonical.mjs — #395 Hub-Centric Landing IA enforcer (§06/§0.18).",
      "wired_in_npm_test": false
    },
    {
      "filename": "learn-manifest-alive.mjs",
      "purpose": "learn-manifest-alive — Constitution §39 enforcement.",
      "wired_in_npm_test": false
    },
    {
      "filename": "ledgers-canonical.mjs",
      "purpose": "ledgers-canonical.mjs — §0.18 Canonical-Absolute enforcer for the ledgers registry.",
      "wired_in_npm_test": false
    },
    {
      "filename": "legal-agent-authority-canonical.mjs",
      "purpose": "legal-agent-authority-canonical.mjs — §0 / §0.8 / §0.30 / §52 enforcer for the",
      "wired_in_npm_test": false
    },
    {
      "filename": "legal-authorization-canonical.mjs",
      "purpose": "legal-authorization-canonical.mjs — §0.30 / §52 / §68 enforcer for the",
      "wired_in_npm_test": false
    },
    {
      "filename": "legal-canonical.mjs",
      "purpose": "legal-canonical.mjs — §0.18 Canonical-Absolute enforcer for the legal registry.",
      "wired_in_npm_test": false
    },
    {
      "filename": "lifecycle-state-canonical.mjs",
      "purpose": "Gate: lifecycle-state-canonical",
      "wired_in_npm_test": false
    },
    {
      "filename": "lifecycles-canonical.mjs",
      "purpose": "lifecycles-canonical.mjs — §0.18 Canonical-Absolute enforcer for the lifecycles registry.",
      "wired_in_npm_test": false
    },
    {
      "filename": "link-resolution.mjs",
      "purpose": "scripts/gates/link-resolution.mjs — build-time internal-link integrity gate",
      "wired_in_npm_test": false
    },
    {
      "filename": "litigation-evidence-discovery-canonical.mjs",
      "purpose": "litigation-evidence-discovery-canonical.mjs — §54 §13 / §68 / §70 enforcer for the",
      "wired_in_npm_test": false
    },
    {
      "filename": "machine-readable-coverage.mjs",
      "purpose": "Gate: machine-readable-coverage",
      "wired_in_npm_test": false
    },
    {
      "filename": "manifest-canonical.mjs",
      "purpose": "Gate: manifest-canonical",
      "wired_in_npm_test": false
    },
    {
      "filename": "marketplace-listing-conformance.mjs",
      "purpose": "Gate: marketplace-listing-conformance",
      "wired_in_npm_test": false
    },
    {
      "filename": "mas-mindforge-product-canonical.mjs",
      "purpose": "mas-mindforge-product-canonical.mjs — §49 §9 Sector Specialisation",
      "wired_in_npm_test": false
    },
    {
      "filename": "mcp-schema-validate.mjs",
      "purpose": "Gate: mcp-schema-validate",
      "wired_in_npm_test": false
    },
    {
      "filename": "mcp-tool-coverage.mjs",
      "purpose": "Gate: mcp-tool-coverage",
      "wired_in_npm_test": false
    },
    {
      "filename": "media-publication-canonical.mjs",
      "purpose": "media-publication-canonical.mjs — the §39 media rail enforcer.",
      "wired_in_npm_test": false
    },
    {
      "filename": "memory-authority-canonical.mjs",
      "purpose": "memory-authority-canonical.mjs — §63 (KYE Memory Authority Rail™) enforcer.",
      "wired_in_npm_test": false
    },
    {
      "filename": "menu-tree-canonical.mjs",
      "purpose": "Gate: menu-tree-canonical (§0 / §50 + §02 IA)",
      "wired_in_npm_test": false
    },
    {
      "filename": "meter-event-no-double-count.mjs",
      "purpose": "Gate: meter-event-no-double-count",
      "wired_in_npm_test": false
    },
    {
      "filename": "middleware-canonical.mjs",
      "purpose": "middleware-canonical.mjs — §16.13 (Middleware Manifest) enforcer.",
      "wired_in_npm_test": false
    },
    {
      "filename": "mobile-table-scroll-coherent.mjs",
      "purpose": "Gate: mobile-table-scroll-coherent",
      "wired_in_npm_test": false
    },
    {
      "filename": "modal-wiring-canonical.mjs",
      "purpose": "Gate: modal-wiring-canonical (§0.29 + §0.18 + §0.3)",
      "wired_in_npm_test": false
    },
    {
      "filename": "model-governance-canonical.mjs",
      "purpose": "model-governance-canonical.mjs — constitution §67 Model Governance Rail.",
      "wired_in_npm_test": false
    },
    {
      "filename": "model-risk-data-governance-canonical.mjs",
      "purpose": "model-risk-data-governance-canonical.mjs — §54 §13 / §68 / §70 enforcer for the",
      "wired_in_npm_test": false
    },
    {
      "filename": "module-canonical.mjs",
      "purpose": "module-canonical.mjs — §0.18 Canonical-Absolute enforcer for the module registry.",
      "wired_in_npm_test": false
    },
    {
      "filename": "mortgage-authorization-canonical.mjs",
      "purpose": "mortgage-authorization-canonical.mjs — §0.30 / §52 / §68 enforcer for the",
      "wired_in_npm_test": false
    },
    {
      "filename": "multidirectional-taxonomy.mjs",
      "purpose": "scripts/gates/multidirectional-taxonomy.mjs — Constitution §0.17 enforcer.",
      "wired_in_npm_test": false
    },
    {
      "filename": "nav-label-coverage.mjs",
      "purpose": "Gate: nav-label-coverage",
      "wired_in_npm_test": false
    },
    {
      "filename": "nav-score.mjs",
      "purpose": "Gate: nav-score",
      "wired_in_npm_test": false
    },
    {
      "filename": "no-binary-source.mjs",
      "purpose": "Gate: no-binary-source (§0.43 no blind spots · §0.20 no stray control bytes)",
      "wired_in_npm_test": false
    },
    {
      "filename": "no-blind-spots.mjs",
      "purpose": "Gate: no-blind-spots — Constitution §0.43 No Blind Enforcers.",
      "wired_in_npm_test": false
    },
    {
      "filename": "no-fabricated-customer-claims.mjs",
      "purpose": "no-fabricated-customer-claims (§0.2 + §41)",
      "wired_in_npm_test": false
    },
    {
      "filename": "no-inline-script.mjs",
      "purpose": "no-inline-script.mjs — CSP self-consistency enforcer for EVERY public surface.",
      "wired_in_npm_test": false
    },
    {
      "filename": "no-mask-token-leak.mjs",
      "purpose": "Gate: no-mask-token-leak (§0.11 + §41 recurrence rule)",
      "wired_in_npm_test": false
    },
    {
      "filename": "no-merge-regression.mjs",
      "purpose": "no-merge-regression (§0.3 self-governance · §41 convert-to-rule)",
      "wired_in_npm_test": false
    },
    {
      "filename": "no-native-dialogs-in-banking-grade-surfaces.mjs",
      "purpose": "no-native-dialogs-in-banking-grade-surfaces — flags new uses of native",
      "wired_in_npm_test": false
    },
    {
      "filename": "no-self-perpetuating-loops.mjs",
      "purpose": "Gate: no-self-perpetuating-loops  (constitution §0.32)",
      "wired_in_npm_test": false
    },
    {
      "filename": "no-spof-coverage.mjs",
      "purpose": "no-spof-coverage.mjs — §51 (No Single Point of Failure) enforcer.",
      "wired_in_npm_test": false
    },
    {
      "filename": "no-stubs-placeholders-mocks.mjs",
      "purpose": "Gate: no-stubs-placeholders-mocks",
      "wired_in_npm_test": false
    },
    {
      "filename": "nondisclosure-canonical.mjs",
      "purpose": "nondisclosure-canonical.mjs — Non-Disclosure Registry enforcer (§0 + §0.9 + §33).",
      "wired_in_npm_test": false
    },
    {
      "filename": "notices-canonical.mjs",
      "purpose": "notices-canonical.mjs — §0.18 Canonical-Absolute enforcer for the notices registry.",
      "wired_in_npm_test": false
    },
    {
      "filename": "obligation-rail-canonical.mjs",
      "purpose": "obligation-rail-canonical.mjs — constitution §64 Obligation Authority Rail.",
      "wired_in_npm_test": false
    },
    {
      "filename": "occ-ai-supervision-product-canonical.mjs",
      "purpose": "occ-ai-supervision-product-canonical.mjs — §49 §9 Sector Specialisation",
      "wired_in_npm_test": false
    },
    {
      "filename": "offboarding-canonical.mjs",
      "purpose": "offboarding-canonical.mjs — §0.18 Canonical-Absolute enforcer for the offboarding registry.",
      "wired_in_npm_test": false
    },
    {
      "filename": "om-compiler-determinism.mjs",
      "purpose": "Gate: om-compiler-determinism",
      "wired_in_npm_test": false
    },
    {
      "filename": "om-no-orphan-rules.mjs",
      "purpose": "Gate: om-no-orphan-rules",
      "wired_in_npm_test": false
    },
    {
      "filename": "om-review-signed.mjs",
      "purpose": "Gate: om-review-signed",
      "wired_in_npm_test": false
    },
    {
      "filename": "om-schema-validate.mjs",
      "purpose": "async function main() {",
      "wired_in_npm_test": false
    },
    {
      "filename": "onboarding-consent-required.mjs",
      "purpose": "Gate: onboarding-consent-required",
      "wired_in_npm_test": false
    },
    {
      "filename": "onboarding-no-orphan-state.mjs",
      "purpose": "Gate: onboarding-no-orphan-state",
      "wired_in_npm_test": false
    },
    {
      "filename": "onboarding-schema-validate.mjs",
      "purpose": "Gate: onboarding-schema-validate",
      "wired_in_npm_test": false
    },
    {
      "filename": "onboarding-state-machine-coverage.mjs",
      "purpose": "Gate: onboarding-state-machine-coverage",
      "wired_in_npm_test": false
    },
    {
      "filename": "ontology-coverage.mjs",
      "purpose": "Gate: ontology-coverage (§0.20 + §53 + §0.9)",
      "wired_in_npm_test": false
    },
    {
      "filename": "ontology-crossmap-canonical.mjs",
      "purpose": "ontology-crossmap-canonical.mjs — KYE Bring-Your-Own-Ontology Cross-Map™ (§74/§70 reuse).",
      "wired_in_npm_test": false
    },
    {
      "filename": "ontology-dictionary-roundtrip.mjs",
      "purpose": "ontology-dictionary-roundtrip.mjs — §53 worked example #1 freshness gate.",
      "wired_in_npm_test": false
    },
    {
      "filename": "openapi-functions-bijection.mjs",
      "purpose": "openapi-functions-bijection — RED-LINE gate. Every Pages-Functions",
      "wired_in_npm_test": false
    },
    {
      "filename": "oscal-exports-canonical.mjs",
      "purpose": "oscal-exports-canonical.mjs — §0.18 Canonical-Absolute enforcer for the oscal-exports registry.",
      "wired_in_npm_test": false
    },
    {
      "filename": "oss-software-constitution-canonical.mjs",
      "purpose": "Gate: oss-software-constitution-canonical",
      "wired_in_npm_test": false
    },
    {
      "filename": "outreach-canonical.mjs",
      "purpose": "outreach-canonical.mjs — KYE Outreach Studio™ enforcer (task #182 Phase 1).",
      "wired_in_npm_test": false
    },
    {
      "filename": "package-namespace-canonical.mjs",
      "purpose": "package-namespace-canonical.mjs — the PACKAGE-NAMING ROOT enforcer (§0 + §0.9).",
      "wired_in_npm_test": false
    },
    {
      "filename": "page-markdown-fresh.mjs",
      "purpose": "page-markdown-fresh.mjs — §43 Machine-Readable by Default enforcer for the",
      "wired_in_npm_test": false
    },
    {
      "filename": "page-metadata-canonical.mjs",
      "purpose": "page-metadata-canonical.mjs — §0.18 Canonical-Absolute enforcer for the page-metadata registry.",
      "wired_in_npm_test": false
    },
    {
      "filename": "pages-function-canonical.mjs",
      "purpose": "pages-function-canonical.mjs — THE REVERSE GATE.",
      "wired_in_npm_test": false
    },
    {
      "filename": "pages-functions-syntax-check.mjs",
      "purpose": "pages-functions-syntax-check — blocks PR merge when any Cloudflare",
      "wired_in_npm_test": false
    },
    {
      "filename": "palette-score.mjs",
      "purpose": "Gate: palette-score",
      "wired_in_npm_test": false
    },
    {
      "filename": "panels-canonical.mjs",
      "purpose": "panels-canonical.mjs — §0.18 Canonical-Absolute enforcer for the panels registry.",
      "wired_in_npm_test": false
    },
    {
      "filename": "partner-admin-surface-coverage.mjs",
      "purpose": "partner-admin-surface-coverage.mjs — §10 §8.1 + §49 §3 enforcer.",
      "wired_in_npm_test": false
    },
    {
      "filename": "partner-disclosure-boundary.mjs",
      "purpose": "partner-disclosure-boundary.mjs — §0.19 Contract-Not-Internals enforcer.",
      "wired_in_npm_test": false
    },
    {
      "filename": "partner-programme-alive.mjs",
      "purpose": "partner-programme-alive.mjs — §10 (Partner Constitution) enforcer.",
      "wired_in_npm_test": false
    },
    {
      "filename": "partner-taxonomy-canonical.mjs",
      "purpose": "partner-taxonomy-canonical.mjs — Partner Taxonomy enforcer (§49 §9 + §54 + §0.19).",
      "wired_in_npm_test": false
    },
    {
      "filename": "payment-authorization-canonical.mjs",
      "purpose": "payment-authorization-canonical.mjs — §0.30 / §52 / §68 enforcer for the",
      "wired_in_npm_test": false
    },
    {
      "filename": "payment-gate-enforced.mjs",
      "purpose": "Gate: payment-gate-enforced",
      "wired_in_npm_test": false
    },
    {
      "filename": "pdp-ssot-canonical.mjs",
      "purpose": "pdp-ssot-canonical — Constitution §14 §3.6a enforcement.",
      "wired_in_npm_test": false
    },
    {
      "filename": "pension-liquidity-canonical.mjs",
      "purpose": "pension-liquidity-canonical.mjs — §0.30 / §52 / §68 enforcer for the",
      "wired_in_npm_test": false
    },
    {
      "filename": "pii-authorization-canonical.mjs",
      "purpose": "pii-authorization-canonical.mjs — §0.30 / §52 / §68 enforcer for the",
      "wired_in_npm_test": false
    },
    {
      "filename": "pill-canonical.mjs",
      "purpose": "Gate: pill-canonical (§0 Zero Competing Systems · constitution/04-DESIGN-SYSTEM.md §2.6)",
      "wired_in_npm_test": false
    },
    {
      "filename": "platform-map-canonical.mjs",
      "purpose": "platform-map-canonical.mjs — KYE 3D Platform Map (Phase 1) enforcer.",
      "wired_in_npm_test": false
    },
    {
      "filename": "policy-engine-adapter-canonical.mjs",
      "purpose": "policy-engine-adapter-canonical.mjs — §0.18 Canonical-Absolute enforcer for",
      "wired_in_npm_test": false
    },
    {
      "filename": "policy-lifecycle-canonical.mjs",
      "purpose": "policy-lifecycle-canonical.mjs — §0.30 / §52 / §68 enforcer for the",
      "wired_in_npm_test": false
    },
    {
      "filename": "policy-points-canonical.mjs",
      "purpose": "policy-points-canonical.mjs — §0.18 Canonical-Absolute enforcer for the policy-points registry.",
      "wired_in_npm_test": false
    },
    {
      "filename": "portals-canonical.mjs",
      "purpose": "portals-canonical.mjs — §0.18 Canonical-Absolute enforcer for the portals registry.",
      "wired_in_npm_test": false
    },
    {
      "filename": "portfolio-map-canonical.mjs",
      "purpose": "portfolio-map-canonical — §0.10/§0.25 enforcer for the Portfolio / Surface Map.",
      "wired_in_npm_test": false
    },
    {
      "filename": "positioning-canonical.mjs",
      "purpose": "positioning-canonical.mjs — §0.18 enforcer for the positioning/merchandising rail.",
      "wired_in_npm_test": false
    },
    {
      "filename": "positioning-lock-canonical.mjs",
      "purpose": "positioning-lock-canonical.mjs — §0.16 positioning enforcer",
      "wired_in_npm_test": false
    },
    {
      "filename": "pricing-canonical-fresh.mjs",
      "purpose": "pricing-canonical-fresh.mjs — §26 §13 enforcer for the per-SKU",
      "wired_in_npm_test": false
    },
    {
      "filename": "product-canonical.mjs",
      "purpose": "product-canonical.mjs — the Product Rail membrane (§0.9 + §0.18 + §0.20 + §54).",
      "wired_in_npm_test": false
    },
    {
      "filename": "product-fanout-canonical.mjs",
      "purpose": "product-fanout-canonical.mjs — the §0.27 / §68 Total Productisation Fan-Out membrane.",
      "wired_in_npm_test": false
    },
    {
      "filename": "production-action-authority-canonical.mjs",
      "purpose": "production-action-authority-canonical.mjs — §54 §13 / §68 / §70 enforcer for the",
      "wired_in_npm_test": false
    },
    {
      "filename": "production-completeness.mjs",
      "purpose": "production-completeness.mjs — constitution §0.29 Production-Completeness.",
      "wired_in_npm_test": false
    },
    {
      "filename": "profile-canonical.mjs",
      "purpose": "Gate: profile-canonical",
      "wired_in_npm_test": false
    },
    {
      "filename": "profile-discipline.mjs",
      "purpose": "Gate: profile-discipline",
      "wired_in_npm_test": false
    },
    {
      "filename": "public-mirror-canonical.mjs",
      "purpose": "Gate: public-mirror-canonical (§0.18 canonical-absolute · §0.49 no-hand-rolling · §70 honesty bar).",
      "wired_in_npm_test": false
    },
    {
      "filename": "public-no-internal-leak.mjs",
      "purpose": "Gate: public-no-internal-leak — ZERO-TOLERANCE public IP-track leak scanner.",
      "wired_in_npm_test": false
    },
    {
      "filename": "public-sector-governance-canonical.mjs",
      "purpose": "public-sector-governance-canonical.mjs — §54 §13 / §68 enforcer for the",
      "wired_in_npm_test": false
    },
    {
      "filename": "public-stack-mention.mjs",
      "purpose": "Gate: public-stack-mention",
      "wired_in_npm_test": false
    },
    {
      "filename": "published-apps-canonical.mjs",
      "purpose": "Gate: published-apps-canonical (§0.18 Canonical-Absolute — the KYE",
      "wired_in_npm_test": false
    },
    {
      "filename": "purpose-admissibility-vectors.mjs",
      "purpose": "Gate: purpose-admissibility-vectors",
      "wired_in_npm_test": false
    },
    {
      "filename": "purpose-no-ambient.mjs",
      "purpose": "Gate: purpose-no-ambient",
      "wired_in_npm_test": false
    },
    {
      "filename": "purpose-revocation-cascade.mjs",
      "purpose": "Gate: purpose-revocation-cascade",
      "wired_in_npm_test": false
    },
    {
      "filename": "purpose-schema-validate.mjs",
      "purpose": "Gate: purpose-schema-validate",
      "wired_in_npm_test": false
    },
    {
      "filename": "queue-consumer-uniqueness.mjs",
      "purpose": "queue-consumer-uniqueness.mjs — §16 Edge Runtime + §0 Zero Competing Systems.",
      "wired_in_npm_test": false
    },
    {
      "filename": "queue-wiring-canonical.mjs",
      "purpose": "queue-wiring-canonical.mjs — every declared queue producer has a reachable",
      "wired_in_npm_test": false
    },
    {
      "filename": "quote-bind-canonical.mjs",
      "purpose": "quote-bind-canonical.mjs — §0.30 / §52 / §68 enforcer for the",
      "wired_in_npm_test": false
    },
    {
      "filename": "rag-authorization-canonical.mjs",
      "purpose": "rag-authorization-canonical.mjs — §0.30 / §52 / §68 enforcer for the",
      "wired_in_npm_test": false
    },
    {
      "filename": "ratchet-comparison-canonical.mjs",
      "purpose": "ratchet-comparison-canonical — §0.55: assertRatchet is THE ONE comparison a",
      "wired_in_npm_test": false
    },
    {
      "filename": "rate-limit-canonical.mjs",
      "purpose": "rate-limit-canonical.mjs — §16 §2.3 Rate-Limit Manifest enforcer.",
      "wired_in_npm_test": false
    },
    {
      "filename": "readme-canonical.mjs",
      "purpose": "readme-canonical.mjs — §0.18 Canonical-Absolute enforcer for the readme registry.",
      "wired_in_npm_test": false
    },
    {
      "filename": "receipts-canonical.mjs",
      "purpose": "receipts-canonical.mjs — §0.18 Canonical-Absolute enforcer for the receipts registry.",
      "wired_in_npm_test": false
    },
    {
      "filename": "reference-canonical.mjs",
      "purpose": "reference-canonical.mjs — §0.18 Canonical-Absolute enforcer for the reference registry.",
      "wired_in_npm_test": false
    },
    {
      "filename": "region-ownership-canonical.mjs",
      "purpose": "region-ownership-canonical — a writer may not destroy bytes it does not own.",
      "wired_in_npm_test": false
    },
    {
      "filename": "regulatory-generators-canonical.mjs",
      "purpose": "Gate: regulatory-generators-canonical",
      "wired_in_npm_test": false
    },
    {
      "filename": "relationship-canonical.mjs",
      "purpose": "relationship-canonical.mjs — §56 (N:M Relationships) enforcer.",
      "wired_in_npm_test": false
    },
    {
      "filename": "render-completeness.mjs",
      "purpose": "Gate: render-completeness  (§0.43 No Blind Enforcers · §0.4 banking-grade)",
      "wired_in_npm_test": false
    },
    {
      "filename": "report-templates-canonical.mjs",
      "purpose": "report-templates-canonical.mjs — §0.18 Canonical-Absolute enforcer for the report-templates registry.",
      "wired_in_npm_test": false
    },
    {
      "filename": "research-paywall-integrity.mjs",
      "purpose": "research-paywall-integrity.mjs — §62 (KYE Governed Research Rail™) paywall enforcer.",
      "wired_in_npm_test": false
    },
    {
      "filename": "research-rail-canonical.mjs",
      "purpose": "research-rail-canonical.mjs — §62 (KYE Governed Research Rail™) enforcer.",
      "wired_in_npm_test": false
    },
    {
      "filename": "resilience-improvement-emitted.mjs",
      "purpose": "Gate: resilience-improvement-emitted",
      "wired_in_npm_test": false
    },
    {
      "filename": "resilience-loop-vectors.mjs",
      "purpose": "Gate: resilience-loop-vectors",
      "wired_in_npm_test": false
    },
    {
      "filename": "resilience-no-orphan-drift.mjs",
      "purpose": "Gate: resilience-no-orphan-drift",
      "wired_in_npm_test": false
    },
    {
      "filename": "resilience-schema-validate.mjs",
      "purpose": "Gate: resilience-schema-validate",
      "wired_in_npm_test": false
    },
    {
      "filename": "resolution-canonical.mjs",
      "purpose": "resolution-canonical.mjs — §0.20 Automatic Dynamic Resolution verifier.",
      "wired_in_npm_test": false
    },
    {
      "filename": "retroactive-audit-coverage.mjs",
      "purpose": "retroactive-audit-coverage.mjs — §52 Phase 3 drift gate.",
      "wired_in_npm_test": false
    },
    {
      "filename": "rights-disputes-disclosure-canonical.mjs",
      "purpose": "rights-disputes-disclosure-canonical.mjs — §61 graft-bijection enforcer.",
      "wired_in_npm_test": false
    },
    {
      "filename": "risk-profiler-canonical.mjs",
      "purpose": "risk-profiler-canonical.mjs — §0.18 enforcer for the Authority Risk Profiler.",
      "wired_in_npm_test": false
    },
    {
      "filename": "rule-pack-canonical.mjs",
      "purpose": "Gate: rule-pack-canonical",
      "wired_in_npm_test": false
    },
    {
      "filename": "runtime-decide-smoke.mjs",
      "purpose": "Gate: runtime-decide-smoke (constitution §13 §12 Resilience Loop · §0.3).",
      "wired_in_npm_test": false
    },
    {
      "filename": "sanctions-aml-canonical.mjs",
      "purpose": "sanctions-aml-canonical.mjs — §0.30 / §52 / §68 enforcer for the",
      "wired_in_npm_test": false
    },
    {
      "filename": "schema-authority-canonical.mjs",
      "purpose": "Gate: schema-authority-canonical — Constitution §16 made mechanical.",
      "wired_in_npm_test": false
    },
    {
      "filename": "schema-guard-canonical.mjs",
      "purpose": "schema-guard-canonical.mjs — schema validation is canonical + mechanical,",
      "wired_in_npm_test": false
    },
    {
      "filename": "schema-typegen-fresh.mjs",
      "purpose": "scripts/gates/schema-typegen-fresh.mjs",
      "wired_in_npm_test": false
    },
    {
      "filename": "scientist-tribute-canonical.mjs",
      "purpose": "scientist-tribute-canonical.mjs — §62 'Remembering Scientists' enforcer.",
      "wired_in_npm_test": false
    },
    {
      "filename": "screenshots-canonical.mjs",
      "purpose": "screenshots-canonical.mjs — §0.4/§0.2 honest-product-visual gate.",
      "wired_in_npm_test": false
    },
    {
      "filename": "sdk-cli-coverage.mjs",
      "purpose": "Gate: sdk-cli-coverage",
      "wired_in_npm_test": false
    },
    {
      "filename": "sdk-cross-lang-equiv.mjs",
      "purpose": "Gate: sdk-cross-lang-equiv — EVERY real `admit` implementation, EVERY fixture.",
      "wired_in_npm_test": false
    },
    {
      "filename": "secret-leak-scan.mjs",
      "purpose": "secret-leak-scan.mjs — KYE-native deterministic secret-leak scanner.",
      "wired_in_npm_test": false
    },
    {
      "filename": "sector-kit-canonical.mjs",
      "purpose": "Gate: sector-kit-canonical  (constitution §54 — Sector Kit lock)",
      "wired_in_npm_test": false
    },
    {
      "filename": "sector-pack-parity-canonical.mjs",
      "purpose": "Gate: sector-pack-parity-canonical (§54 + §0.9)",
      "wired_in_npm_test": false
    },
    {
      "filename": "self-description.mjs",
      "purpose": "self-description — Constitution §45 enforcement (the Self-Description Gate).",
      "wired_in_npm_test": false
    },
    {
      "filename": "self-governance-coverage.mjs",
      "purpose": "Gate: self-governance-coverage",
      "wired_in_npm_test": false
    },
    {
      "filename": "separation-of-duties.mjs",
      "purpose": "separation-of-duties — the actor that produces a thing may not be the only",
      "wired_in_npm_test": false
    },
    {
      "filename": "settlement-agent-canonical.mjs",
      "purpose": "settlement-agent-canonical.mjs — §0.30 / §52 / §68 enforcer for the",
      "wired_in_npm_test": false
    },
    {
      "filename": "shadow-mode-non-blocking.mjs",
      "purpose": "Gate: shadow-mode-non-blocking",
      "wired_in_npm_test": false
    },
    {
      "filename": "signal-freshness-canonical.mjs",
      "purpose": "signal-freshness-canonical.mjs — §0.24 Evidence-Over-Headers mechanism.",
      "wired_in_npm_test": false
    },
    {
      "filename": "signal-sources-alive.mjs",
      "purpose": "signal-sources-alive.mjs — §48 (Signal Ingest Contract) enforcer.",
      "wired_in_npm_test": false
    },
    {
      "filename": "signing-key-canonical.mjs",
      "purpose": "signing-key-canonical.mjs — every SIGNING key KYE publishes is governed.",
      "wired_in_npm_test": false
    },
    {
      "filename": "single-decision-seal.mjs",
      "purpose": "Gate: single-decision-seal — Constitution §0 (Zero Competing Systems) +",
      "wired_in_npm_test": false
    },
    {
      "filename": "site-authority-canonical.mjs",
      "purpose": "site-authority-canonical.mjs — KYE Site Authority™ enforcer.",
      "wired_in_npm_test": false
    },
    {
      "filename": "skill-canonical.mjs",
      "purpose": "Gate: skill-canonical (§0.9 + §0.8)",
      "wired_in_npm_test": false
    },
    {
      "filename": "sku-jurisdiction-canonical.mjs",
      "purpose": "Gate: sku-jurisdiction-canonical",
      "wired_in_npm_test": false
    },
    {
      "filename": "sku-manifest-canonical.mjs",
      "purpose": "SKU manifest canonical-first gate.",
      "wired_in_npm_test": false
    },
    {
      "filename": "sku-owner-canonical.mjs",
      "purpose": "sku-owner-canonical.mjs — bidirectional SKU ↔ owner binding (§0.31 reverse half).",
      "wired_in_npm_test": false
    },
    {
      "filename": "smoke-coverage-canonical.mjs",
      "purpose": "smoke-coverage-canonical.mjs — §0.18 Canonical-Absolute enforcer for the",
      "wired_in_npm_test": false
    },
    {
      "filename": "snippets-canonical.mjs",
      "purpose": "snippets-canonical.mjs — §0.18 Canonical-Absolute enforcer for the snippets registry.",
      "wired_in_npm_test": false
    },
    {
      "filename": "social-cards-canonical.mjs",
      "purpose": "social-cards-canonical.mjs — §6 social card contract enforcer.",
      "wired_in_npm_test": false
    },
    {
      "filename": "source-header-canonical.mjs",
      "purpose": "source-header-canonical.mjs — §0.18 Canonical-Absolute enforcer for the source-header registry.",
      "wired_in_npm_test": false
    },
    {
      "filename": "source-registry-canonical.mjs",
      "purpose": "source-registry-canonical.mjs — the citation namespace holds (§62 · §70 · §0).",
      "wired_in_npm_test": false
    },
    {
      "filename": "sql-column-canonical.mjs",
      "purpose": "sql-column-canonical — a SQL string may not name a column that does not exist.",
      "wired_in_npm_test": false
    },
    {
      "filename": "starter-pack-canonical.mjs",
      "purpose": "starter-pack-canonical.mjs — §22 §5 (Starter Packs / Seeds) enforcer.",
      "wired_in_npm_test": false
    },
    {
      "filename": "startup-program-canonical.mjs",
      "purpose": "startup-program-canonical.mjs — §0.18 enforcer for the KYE for Startups™",
      "wired_in_npm_test": false
    },
    {
      "filename": "status-service-coverage.mjs",
      "purpose": "status-service-coverage — the status page surfaces EVERY deployed component.",
      "wired_in_npm_test": false
    },
    {
      "filename": "sticky-chrome-opaque.mjs",
      "purpose": "Gate: sticky-chrome-opaque  (§0.4 banking-grade UI · §41 convert-to-rule)",
      "wired_in_npm_test": false
    },
    {
      "filename": "stripe-canonical.mjs",
      "purpose": "stripe-canonical.mjs — the Stripe Rail membrane (§0.9 + §0.18 + §0.20 + §23 + §26 + §27).",
      "wired_in_npm_test": false
    },
    {
      "filename": "stripe-pci-scope.mjs",
      "purpose": "stripe-pci-scope.mjs — keeps KYE OUT of PCI DSS cardholder-data scope (§26 + §0.4).",
      "wired_in_npm_test": false
    },
    {
      "filename": "subdomain-chrome-canonical.mjs",
      "purpose": "subdomain-chrome-canonical.mjs — Subdomain Chrome Canonicalisation gate",
      "wired_in_npm_test": false
    },
    {
      "filename": "subdomain-registry-canonical.mjs",
      "purpose": "Gate: subdomain-registry-canonical (§0.1 + §07 — OFFLINE consistency half)",
      "wired_in_npm_test": false
    },
    {
      "filename": "subprocessor-manifest-canonical.mjs",
      "purpose": "subprocessor-manifest-canonical — enforce zero drift between the",
      "wired_in_npm_test": false
    },
    {
      "filename": "surface-coverage-canonical.mjs",
      "purpose": "surface-coverage-canonical.mjs — §0.42 6th coverage dimension ('surfaced').",
      "wired_in_npm_test": false
    },
    {
      "filename": "surface-grade-coverage.mjs",
      "purpose": "surface-grade-coverage.mjs — §0.4 per-surface release gate (canonical + mechanical).",
      "wired_in_npm_test": false
    },
    {
      "filename": "svg-render-safety.mjs",
      "purpose": "svg-render-safety.mjs — closes the recurring \"inline-SVG renders as black boxes\"",
      "wired_in_npm_test": false
    },
    {
      "filename": "synthetic-fixtures-canonical.mjs",
      "purpose": "synthetic-fixtures-canonical.mjs — §0.18 Canonical-Absolute enforcer for the",
      "wired_in_npm_test": false
    },
    {
      "filename": "system-blueprint-canonical.mjs",
      "purpose": "system-blueprint-canonical — every e2e system has a machine-readable map,",
      "wired_in_npm_test": false
    },
    {
      "filename": "system-integrator-rail-canonical.mjs",
      "purpose": "system-integrator-rail-canonical.mjs — §49 §9.A enforcer.",
      "wired_in_npm_test": false
    },
    {
      "filename": "tax-governance-canonical.mjs",
      "purpose": "tax-governance-canonical.mjs — §54 §13 / §68 enforcer for the",
      "wired_in_npm_test": false
    },
    {
      "filename": "tech-ai-dd-canonical.mjs",
      "purpose": "Gate: tech-ai-dd-canonical (§13 risk-profiler twin + §70 + §0.8)",
      "wired_in_npm_test": false
    },
    {
      "filename": "tenant-predicate-canonical.mjs",
      "purpose": "tenant-predicate-canonical.mjs — §0.11 Zero Contamination, mechanised.",
      "wired_in_npm_test": false
    },
    {
      "filename": "tender-procurement-product-canonical.mjs",
      "purpose": "tender-procurement-product-canonical.mjs — §49 §9 Sector Specialisation",
      "wired_in_npm_test": false
    },
    {
      "filename": "theme-canonical-fresh.mjs",
      "purpose": "Gate: theme-canonical-fresh (§24 §2.1b + §0 + §0.3 + §0.9 + §0.14)",
      "wired_in_npm_test": false
    },
    {
      "filename": "threat-response-canonical.mjs",
      "purpose": "threat-response-canonical.mjs — §0.30 / §52 / §68 enforcer for the",
      "wired_in_npm_test": false
    },
    {
      "filename": "total-citizenship-canonical.mjs",
      "purpose": "Gate: total-citizenship-canonical  (constitution §0.37 — Total Citizenship & t=0 Governance)",
      "wired_in_npm_test": false
    },
    {
      "filename": "total-coverage-canonical.mjs",
      "purpose": "Gate: total-coverage-canonical — Constitution §0.42 Total Coverage",
      "wired_in_npm_test": false
    },
    {
      "filename": "total-governance-coverage.mjs",
      "purpose": "Gate: total-governance-coverage — Constitution §0.40 Total Governance",
      "wired_in_npm_test": false
    },
    {
      "filename": "training-canonical.mjs",
      "purpose": "training-canonical.mjs — §0.18 Canonical-Absolute enforcer for the training registry.",
      "wired_in_npm_test": false
    },
    {
      "filename": "treasury-authority-canonical.mjs",
      "purpose": "treasury-authority-canonical.mjs — §0.30 / §52 / §68 enforcer for the",
      "wired_in_npm_test": false
    },
    {
      "filename": "ui-component-contract.mjs",
      "purpose": "Gate: ui-component-contract",
      "wired_in_npm_test": false
    },
    {
      "filename": "ui-journey-canonical.mjs",
      "purpose": "ui-journey-canonical.mjs — §0.18 Canonical-Absolute enforcer for the UI Journey",
      "wired_in_npm_test": false
    },
    {
      "filename": "uk-tribunal-pack-canonical.mjs",
      "purpose": "uk-tribunal-pack-canonical.mjs — §0 / §0.8 / §0.18 / §68 enforcer for the",
      "wired_in_npm_test": false
    },
    {
      "filename": "underwriting-authority-canonical.mjs",
      "purpose": "underwriting-authority-canonical.mjs — §0.30 / §52 / §68 enforcer for the",
      "wired_in_npm_test": false
    },
    {
      "filename": "uniqueness-canonical.mjs",
      "purpose": "Gate: uniqueness-canonical",
      "wired_in_npm_test": false
    },
    {
      "filename": "universal-bindings-canonical.mjs",
      "purpose": "universal-bindings-canonical.mjs — §0.31 Universal Bindings enforcer.",
      "wired_in_npm_test": false
    },
    {
      "filename": "universal-entity-governance.mjs",
      "purpose": "Gate: universal-entity-governance  (constitution §0.36)",
      "wired_in_npm_test": false
    },
    {
      "filename": "updates-rail-canonical.mjs",
      "purpose": "updates-rail-canonical.mjs — constitution §65 Updates Rail.",
      "wired_in_npm_test": false
    },
    {
      "filename": "url-inventory-canonical.mjs",
      "purpose": "url-inventory-canonical.mjs — §0.18 Canonical-Absolute enforcer for the url-inventory registry.",
      "wired_in_npm_test": false
    },
    {
      "filename": "user-action-canonical.mjs",
      "purpose": "user-action-canonical.mjs — §0.18 Canonical-Absolute enforcer for the user-action registry.",
      "wired_in_npm_test": false
    },
    {
      "filename": "user-journeys-canonical.mjs",
      "purpose": "user-journeys-canonical.mjs — §0.18 Canonical-Absolute enforcer for the user-journeys registry.",
      "wired_in_npm_test": false
    },
    {
      "filename": "value-based-pricing-coverage.mjs",
      "purpose": "value-based-pricing-coverage.mjs — §27 §12 (KYE Value-Based Pricing",
      "wired_in_npm_test": false
    },
    {
      "filename": "venture-studio-program-canonical.mjs",
      "purpose": "venture-studio-program-canonical.mjs — §0.18 enforcer for the KYE",
      "wired_in_npm_test": false
    },
    {
      "filename": "verify-static-only-clock.mjs",
      "purpose": "Gate: verify-static-only-clock (§34 §11 + §2 — the missing enforcer)",
      "wired_in_npm_test": false
    },
    {
      "filename": "visual-conformance.mjs",
      "purpose": "Gate: visual-conformance — the systematic enforcement of zero CSS /",
      "wired_in_npm_test": false
    },
    {
      "filename": "visual-text-patent-safety.mjs",
      "purpose": "Gate: visual-text-patent-safety",
      "wired_in_npm_test": false
    },
    {
      "filename": "visual-verify.mjs",
      "purpose": "Gate: visual-verify",
      "wired_in_npm_test": false
    },
    {
      "filename": "visualizations-canonical.mjs",
      "purpose": "visualizations-canonical.mjs — §0.18 Canonical-Absolute enforcer for the visualizations registry.",
      "wired_in_npm_test": false
    },
    {
      "filename": "webhook-signature-verified.mjs",
      "purpose": "Gate: webhook-signature-verified",
      "wired_in_npm_test": false
    },
    {
      "filename": "wedge-kit-canonical.mjs",
      "purpose": "wedge-kit-canonical.mjs — §0.18 enforcer for the KYE Wedge Kit™ go-to-market",
      "wired_in_npm_test": false
    },
    {
      "filename": "whistleblower-authority-canonical.mjs",
      "purpose": "whistleblower-authority-canonical.mjs — §54 §13 / §68 / §70 enforcer for the",
      "wired_in_npm_test": false
    },
    {
      "filename": "whitepaper-pdf-fresh.mjs",
      "purpose": "Gate: whitepaper-pdf-fresh — Constitution §0.20 + §0.29.",
      "wired_in_npm_test": false
    },
    {
      "filename": "widget-csp-strict.mjs",
      "purpose": "Gate: widget-csp-strict",
      "wired_in_npm_test": false
    },
    {
      "filename": "widget-descriptor-validate.mjs",
      "purpose": "Gate: widget-descriptor-validate",
      "wired_in_npm_test": false
    },
    {
      "filename": "widget-postmessage-conformance.mjs",
      "purpose": "Gate: widget-postmessage-conformance",
      "wired_in_npm_test": false
    },
    {
      "filename": "widget-purpose-permission-required.mjs",
      "purpose": "Gate: widget-purpose-permission-required",
      "wired_in_npm_test": false
    },
    {
      "filename": "worker-deploy-lockfile-present.mjs",
      "purpose": "Gate: worker-deploy-lockfile-present",
      "wired_in_npm_test": false
    },
    {
      "filename": "workflow-governance-coverage.mjs",
      "purpose": "Gate: workflow-governance-coverage — Constitution §0.3 (self-governance) +",
      "wired_in_npm_test": false
    },
    {
      "filename": "workflow-lint-canonical.mjs",
      "purpose": "workflow-lint-canonical.mjs — the shellcheck class that keeps breaking CI must",
      "wired_in_npm_test": false
    },
    {
      "filename": "workflow-no-protected-main-push-canonical.mjs",
      "purpose": "workflow-no-protected-main-push.mjs — auto-triggered workflows must not push",
      "wired_in_npm_test": false
    },
    {
      "filename": "workflow-observer-coverage.mjs",
      "purpose": "Gate: workflow-observer-coverage  (POLICY REVERSED 2026-06-26 — §0.32 cost-bleed root fix)",
      "wired_in_npm_test": false
    },
    {
      "filename": "workflow-r2-precreate-present.mjs",
      "purpose": "Gate: workflow-r2-precreate-present",
      "wired_in_npm_test": false
    },
    {
      "filename": "workflow-registry-canonical.mjs",
      "purpose": "workflow-registry-canonical.mjs — the gate private/specs/workflows/workflow_registry.json",
      "wired_in_npm_test": false
    },
    {
      "filename": "zero-deviation-mandate.mjs",
      "purpose": "zero-deviation-mandate — Constitution §0.5 enforcement.",
      "wired_in_npm_test": false
    },
    {
      "filename": "zero-hand-authored.mjs",
      "purpose": "Gate: zero-hand-authored  (§0.46 Zero Hand-Authored Surfaces)",
      "wired_in_npm_test": false
    }
  ]
}